Compliments to Tibor and Juraj of RUB and Thomas on the excellent work they've done describing this issue and its potential remedies.

Ed
-------- Original Message --------
Subject: XML Encryption CBC attack
From: <Frederick.Hirsch@nokia.com>
Date: Sat, October 29, 2011 11:24 am
To: <public-xmlsec@w3.org>
Cc: <Frederick.Hirsch@nokia.com>

The paper describing the CBC attack on XML Encryption is available at http://www.nds.rub.de/research/publications/breaking-xml-encryption/

A blog post from Thomas related to this is at: http://www.w3.org/QA/2011/10/some_notes_on_the_recent_xml_e.html

regards, Frederick

Frederick Hirsch, Nokia
Chair XML Security WG