It can be done. The questions are, should it be done, and if so , where and how?
If it should be done at all I'd suggest that the place to do it is only in the Admin. Most customers are unlikely to want to take the time to format these comments, and adding it customer side would open up another vulnerability point for SQL injection.
Just what did you have in mind?