Which is stronger: Threefish 1024-bit, SHACAL-2 512-bit, or AES-256? Note that "compliance with FIPS 197" doesn't mean _anything_ for security, it just means that they managed to correctly implement the standard (ie it functionally works). Not to mention the caveats to XTS mode.

SHAKAL-2 512 - i have read that this algorithm was something like "partly hacked for 50%" but for now considered as solid and unhackable.
Can you actually pose an argument in favor of Threefish? The Twofish algorithm by design is complex and makes use of 16 rounds no matter the key length being used.

TKIP is actually an older encryption protocol introduced with WPA to replace the very-insecure WEP encryption at the time. If a flaw is found the data is no longer protected. People wanted something that worked like a stream cipher, and didn't have better alternatives (unless they were themselves cryptographers). I updated my Notepad++ and the first line of change.log was: "Fix CIA Hacking Notepad++ issue (" It is marketing thing about paying for PRO version which offers "better" Threefish 1024bit, SHACAL-2 512bit which are really not better than AES 256.

Note that "compliance with FIPS 197" doesn't mean anything for security, it just means that they managed to correctly implement the standard (ie it functionally works). The other and equally important question is how was the encryption algorithm implemented? It should always be recommended to use an authenticated encryption mode (such as GCM). So, as of today, I think that benefit outweighs the possible risk of Threefish being found weak (and keep in mind that Threefish is specifically designed to resist analysis by using a large number of rounds). But Threefish has more designers. I brought up Threefish not in conflict with the top parent's suggestion of using ChaCha20, but rather to suggest its place alongside ChaCha20, Poly1305, Curve25519, etc. Only using CBC mode is really bad advice and will not protect against all sorts of standard attacks, especially against chosen-ciphertext attacks. I updated my Notepad++ and the first line of change.log was: "Fix CIA Hacking Notepad++ issue (" AES vs. TKIP. RC4 was the first cipher I ever successfully worked with (in my defense, I was a teenager). However the 7Zip dll file they were using was over 10 years old, what does that say about a software company who has continued to use a version of software which is that old. And, Skein was one of the top SHA3 choices. What is the security loss from reducing Rijndael to 128 bits block size from 256 bits?

