For all $\ell > 0$ and $t < \ell$, the string $0^{\ell-1} 1$ does not
$t$-slide.
\end{remark}
+
+%% Thinking about the probability that a random l-bit string t-slides...
+%%
+%%
\subsection{Security of CFB mode}
\section{Acknowledgements}
-Thanks to Clive Jones for his suggestions on notation, and his help in
-structuring the proofs.
+Thanks are due to David Wagner for pointing me at \cite{Alkassar:2001:OSS}
+and warning me of the dangers of sliding IVs in CFB mode. Thanks also to
+Clive Jones for his suggestions on notation, and his help in structuring the
+proofs.
%%%----- That's all, folks --------------------------------------------------