A journalist in Istanbul saves a sensitive source document to her laptop. An activist in Minsk sends a message to a colleague abroad. A human rights worker in Cairo uploads field notes to the cloud. In each case, one invisible process stands between their work and the people who want to stop them. That process is encryption. At the heart of most tools they use sits a single standard called AES, the Advanced Encryption Standard. It has no logo, no marketing campaign, and no press releases. But it has protected more lives than most privacy tools ever will.
Encrypted Essentials
- AES powers the encryption inside most secure messaging apps, VPNs, and encrypted storage tools used by at-risk communicators today.
- AES-256 is the strongest variant of the standard and is widely considered appropriate for users facing serious surveillance threats.
- Understanding how your tools use AES helps you ask better questions and make smarter choices about what to trust with sensitive work.
Why Your Data Is a Target Before You Even Know It
When you send a message or upload a file without encryption, that data travels across cables, routers, and servers as plain text. Anyone positioned along that route can read it. That includes internet service providers, government monitoring systems, and anyone who has managed to compromise a network you are using.
For most people, that is an acceptable risk. For a journalist communicating with a government whistleblower, or an activist coordinating across a heavily monitored border, it is not. The stakes are prison. Sometimes they are worse.
Encryption changes the math completely. Even if someone intercepts the data, they see scrambled noise instead of readable content. AES is what does the scrambling, and it does it well enough that no practical attack against the algorithm itself has ever succeeded in the wild.
What Symmetric Encryption Actually Does
There are two main families of encryption. Asymmetric encryption uses two different keys, one to lock and one to unlock. Symmetric encryption uses the same key for both. AES is symmetric.
Think of it as a padlock where the same physical key both locks and unlocks the box. This approach is fast and efficient, which is why it gets used for large transfers like files, disk partitions, and streaming VPN traffic. The challenge with symmetric encryption is always the same: both parties need to share that key securely. Modern apps solve this by using asymmetric encryption briefly to exchange the AES key, then switching to AES for the actual data. The result is speed without sacrificing security.
How AES Scrambles Data Without the Math
AES works by breaking your data into fixed-size blocks of 128 bits. It then runs each block through a series of transformation rounds. Each round applies four operations: substituting bytes through a lookup table, shifting rows in a grid, mixing columns using arithmetic, and combining the result with portions of the key. After enough rounds, the output looks nothing like the input.
The number of rounds depends on the key size. A 128-bit key runs 10 rounds. A 192-bit key runs 12. A 256-bit key runs 14. The longer the key, the more rounds, the harder it is to crack by trying every possible combination. Below is a comparison of the three key sizes defined in the AES standard.
AES Key Sizes and Their Practical Implications
| Key Size | Encryption Rounds | Threat Resistance | Where You See It |
|---|---|---|---|
| AES-128 | 10 | Very strong; secure against all known attacks | Commercial apps, TLS connections, streaming services |
| AES-192 | 12 | Stronger, rarely used in practice | Some government and enterprise configurations |
| AES-256 | 14 | Strongest variant; recommended for high-risk users | Secure messaging, VPNs, full-disk encryption, classified data |
NIST formalized AES as FIPS 197 in 2001, publishing a detailed AES specification that replaced the older Data Encryption Standard after it became clear DES could not survive modern computing power. The standard has since been adopted by governments, militaries, and security researchers worldwide as the baseline for symmetric encryption.
Where AES Appears in the Tools At-Risk Communicators Already Use
AES is not something you install separately. It runs inside the applications you already use. Knowing where it appears helps you understand what protection you already have and where gaps might exist.
Encrypted Messaging Apps
Several widely used secure messaging apps rely on AES-256 as part of their encryption protocols. When you send a message through one of these apps, the content is encrypted on your device before it ever leaves. The server relays the encrypted data without being able to read it. Even if someone intercepts the transmission, they see nothing useful without your key.
The meaningful differences between these apps lie in how they handle metadata, whether they store message histories, and what their data-sharing policies look like. The underlying cipher is not where most of them diverge.
Secure File Storage and Full-Disk Encryption
Many operating systems and third-party tools use AES to encrypt files or entire disk partitions. A laptop seized at a border crossing or confiscated during a raid yields nothing if the disk is encrypted and the correct key is not present. The data is physically there. It is simply unreadable without authorization.
This matters enormously for field journalists and NGO workers who carry devices across borders regularly. The question is not whether encryption can be broken. It generally cannot. The question is whether it was turned on.
VPN Tunnels
A VPN creates an encrypted tunnel between your device and a server in another location. Inside that tunnel, your traffic is protected by AES. An observer on your local network, including your internet provider or a government monitoring a regional exchange point, sees only encrypted traffic heading toward the VPN server. The destinations you visit and the content you transmit are hidden from that observer.
VPNs are not a complete solution on their own, and they shift rather than eliminate trust. But the AES layer inside them means the traffic itself cannot be read in transit, which matters a great deal in environments where local network monitoring is common.
Thinking About Threats Before Choosing a Tool
Knowing that your messaging app uses AES-256 is useful. Knowing whether that matters for your specific situation is more useful. Threat modeling is the process of thinking clearly about who might target you, what they want, and what resources they have available.
Before you decide which encryption tools to prioritize, consider these questions:
- Who is most likely to try to access your communications: a criminal network, a private company, or a government agency?
- What is the most sensitive data you handle: source identities, location data, organizational plans, or financial records?
- What legal protections exist in your jurisdiction, and how reliably are they enforced in practice?
- Do the people you communicate with have access to the same tools and the same operational habits around security?
- What happens if your device is physically seized rather than remotely compromised?
A freelance journalist covering local corruption in a country with functioning rule of law faces a different threat landscape than a dissident exchanging messages across a closed border. AES-256 can protect both of them. But the rest of their security setup needs to match their actual risk, not a generic checklist.
EFF publishes a plain-language threat modeling primer written specifically for people who are not security professionals, covering exactly this kind of thinking in accessible detail.
Why the Key Itself Matters as Much as the Algorithm
AES-256 is only as strong as the key used with it. If the key is weak, predictable, or reused across different sessions, the encryption can be broken by attacking the key rather than the cipher. The algorithm itself has no known practical weaknesses. Real-world attacks against AES-protected data almost always target the key or the implementation, not the math behind it.
What makes a good AES key? It needs to be genuinely random, full-length, and never reused across different contexts or sessions. Most secure apps handle key generation automatically and correctly. But if you are manually configuring encrypted storage, creating containers for sensitive files, or testing a security setup, you need a cryptographically secure source of randomness, not something derived from a short passphrase or a predictable timestamp.
Using a dedicated tool for AES encryption key generation ensures the output meets the randomness requirements the standard depends on. This matters most when you are building an encrypted file container or configuring encryption manually, rather than relying entirely on an app to handle it for you.
Even with correct tools in place, operational habits still matter. A journalist who encrypts their files but writes the passphrase on a notepad left on their desk has not gained meaningful protection. The key must be kept with the same level of care as the data it protects.
Modes of Operation and What They Mean in Practice
AES does not behave identically in every application. It runs in different modes depending on what the software needs. You do not need to choose between these yourself in most cases, but understanding that they exist explains why two tools can both claim AES-256 while behaving quite differently under the hood.
- AES-GCM (Galois/Counter Mode): Used in most modern secure messaging apps and the current version of TLS. It encrypts data and authenticates it simultaneously, meaning any tampering is detectable by the recipient before they even read the message.
- AES-CBC (Cipher Block Chaining): An older mode still present in some VPN configurations and file encryption tools. Each block depends on the previous one, which adds structure but requires careful implementation to avoid certain classes of attack.
- AES-CTR (Counter Mode): Turns the block cipher into something that behaves like a stream cipher. Efficient for large amounts of sequential data and used in some disk encryption systems where speed matters.
If you are evaluating a tool and the documentation mentions which AES mode it uses, GCM is generally the most preferred for secure communications. The presence of authenticated encryption means data cannot be silently altered in transit without detection.
The Invisible Line Between a Source and Their Safety
There is something almost philosophical about strong encryption. It takes information that belongs to someone and makes it meaningless to everyone else. For a journalist protecting a whistleblower, that meaninglessness is the entire point. The source trusted them with something dangerous. Encryption is how they honor that trust even after the device leaves their hands.
AES is not new. It is not experimental. It has been tested by cryptographers for over two decades, adopted by governments and militaries, and built into billions of devices across every continent. The fact that it runs invisibly inside most secure tools is intentional. The best security does not announce itself.
What matters for activists, journalists, and anyone operating under surveillance is not whether encryption sounds impressive. It is whether the tools they rely on implement it correctly, whether the keys are handled with discipline, and whether the rest of their habits match the strength of the algorithm underneath. AES-256 can protect a source from a nation-state adversary. It cannot protect a passphrase scrawled on a sticky note attached to a screen.
That combination of strong cryptography and careful practice is what actually keeps people safe. The algorithm does its part. The rest depends on the person using it.