@angristan Oh yeah I read the overview for this.

So AES is very popular and good, but it's slow without hardware acceleration, and that costs money.

ChaCha is faster on CPUs, but it changes the length of disk blocks when you encrypt (makes them longer) which screws up a lot of assumptions for disk drivers that want one block == one block.

So they found a clever way to combine ChaCha with just a little bit of AES so that one block == one block but most of the crypto is still ChaCha.

