AES Encryption & Decryption
AES-GCM/CBC text encryption with PBKDF2-derived keys and a self-describing ciphertext format.
You want a connection string in a config file that is not readable at a glance, or a private note between two devices — symmetric encryption's standard answer is AES, but "using it correctly" is where things go wrong: how does the key come from a password, should the IV be random, why can CBC be tampered with undetected. This tool does the details right and shows them to you.
The flow: the passphrase is stretched through PBKDF2-HMAC-SHA256 at 150,000 iterations into a 256-bit key; salt and IV are freshly random per encryption; the ciphertext is packed in a self-describing format (AES1 magic + version + mode + salt + IV + data) and Base64-encoded. Decryption reads the parameters back from the header — you remember the passphrase and nothing else. GCM authenticates integrity: flipping one ciphertext byte fails the whole decryption.
GCM vs CBC
GCM is authenticated encryption — decryption verifies integrity and refuses tampered data, which is why TLS 1.3 permits only the GCM family; it is the default here. CBC is confidential but not tamper-evident, and history's padding-oracle holes all live in CBC misuse — use it only to interoperate with legacy systems that cannot do otherwise.
Passphrase vs key
AES wants 256 random bits; human passphrases carry far less entropy. PBKDF2 raises brute-force cost by making every guess perform 150,000 hashes, and the salt ensures the same passphrase derives different keys for different ciphertexts. The price is a short wait on both encrypt and decrypt — that is the cost of security, not a performance bug.
Frequently asked questions
- Can I recover data if I forget the passphrase?
- No. The key derives solely from the passphrase with no backdoor and no storage. That is the feature: anyone holding the ciphertext — including us — cannot read it without the passphrase.
- Can other tools decrypt this output?
- Yes. The format is self-describing (header + salt + IV + data), so any standard PBKDF2-SHA256 (150k) + AES-GCM/CBC implementation can decrypt it, including OpenSSL from the command line.
- How much content can it handle?
- Text and small config files, comfortably up to a few megabytes of browser memory. Bulk file encryption is outside a browser tool's lane.