> True, but the insidiousness of the attack is that - once the attacker
> has analyzed the merging procedure of a particular software - that the
> recipient has very high computational costs.
> You can protect yourself from it by limiting the size of the
> interchanged fragment, though.

Yes, and by restricting who can add fragments to your topic map.

I think the conclusion to this debate is that the somewhat rough and  
ragged consensus is that while there are security concerns attached  
to the <mergeMap/> element, they are not strong enough to warrant  
leaving it out.

