Hacker News new | ask | show | jobs
by pjscott 4959 days ago
There's an entertaining article about one such attack here:

http://blog.cryptographyengineering.com/2011/10/attack-of-we...

For some mind-boggling reason, the designers of the XML Encryption standard decided to make authentication optional, so an attacker can simply avoid sending an incorrect MAC.