Thanks for the tip, DDT.

I guess it does not matter which program someone uses since AES is a standardized encryption format, right?
Also, there are rumors that NSA and CIA do know some kind of backdoor to AES. Does someone know more about the probability of such a backdoor?
Indeed, AES is a publicly known algorithm. Everyone who studies the definition of AES can write his/her own program implementing it. I hadn't heard there were rumors about backdoors in AES, but here is an
article debunking that, echoing my thoughts about it.
There had been persistent rumors about a backdoor in
DES, the predecessor of AES as the US standard for (symmetric) encryption, and they were based on the fact that DES was based on a previously published encryption method, but with some steps added of which nobody really knew what they were good for. AES, however, is the result of a
public contest organized by NIST. The winner of that contest, Rijndael, was created by two Belgian cryptographers working, then, at the University of Leuven, and has been adopted unchanged.
And while the NSA might have gotten away with a backdoor 30 years ago, when DES was adopted, it can't now. Back then, the cryptography field was relatively small. Now, it is big business and many bright cryptographers work in academia or in business. There are many eyeballs scrutinizing encryption algorithms, especially widely used ones as AES. There are regular news reports about (teams of) cryptographers discovering weaknesses in encryption algorithms - typically saying that they found a way to cut a few bits off the key space.
The basic concept around modern-day cryptography is that you can just publish the encryption algorithm, because the strength lies in devising an algorithm that is so strong that the only way to attack it is brute-force trial and error. Symmetric encryption algorithms as DES and AES make use of a single key, which is used both for encryption and for decryption. A brute-force attack means trying out all possible keys and look if something sensible comes out of it. DES has a key of 56 bits, which gives 2^56 possible keys. That was huge in the 1970s, but as you can see from the wiki-page, in 1999 it was possible to brute-force decrypt it within a day - that was done by a SETI-like network of hobbyists who all donated a bit of their computer time.
The number of keys of DES is already huge - 2^56 is a 17-digit number. When you increase the key length with a single bit, however, it means that you
double the number of possible keys. Adding two bits means that the key space increases four-fold. Etcetera. AES comes in two variants: with a key length of 128 and with a key length of 256. That means that the number of possible keys is a 39-digit number, resp. a 77-digit number. That's huge. To imagine how huge, let's go with those 1999 numbers - cracking a 56-bit key in a day. The number of possible keys for AES-128 is a number that has 21 more digits (in decimal) than DES. So that means that you need 10^21 days to crack AES in 1999 terms. That is in the order of 10^18 years. Computers have become faster - let's very generously say they have doubled in computational power each year (
Moore's law). That means they have become faster by a factor of 1,000 in 10 years. Then you're still left with 10^15 years to crack AES-128. The universe is 10^10 years old.
It's very unlikely that an aes256 encrypted file can be brute-forced during the lifetime of our solar system, with current technology. They key space is just too big.
As I already said in post #7 in this thread:
And AES is state-of-the-art encryption, you can't even begin to try to decrypt that - with the current technology, the world earlier comes to an end than you have decrypted it (brute force).
and quantified above. And that was for AES-128, whereas the Wikileaks-file is suggested to be encrypted in AES-256.
What I said about increasing key length applies in the reverse direction for weaknesses discovered, Those discoveries are typically of the form that "key A is equivalent to key B" in a regular pattern over all keys, and thus, the key space is halved - or quartered when the discovery knocks off two bits of the key space. They have always involved knocking off only a few bits off the key space thus far. And I'm not aware of such weaknesses with AES. And while obviously, the NSA has some smart cookies on the payroll, it might be possible that the NSA has discovered a weakness and keeps it secret, eventually another smart cookie working outside the NSA discovers it. I really don't believe the NSA knew about a weakness 10 years ago when AES was standardized and nobody outside the NSA has yet discovered it.
But there are other ways to attack a cipher.
Sometimes the key strength is compromised in a way that exponentially reduces search time.
You need to knock off quite a few bits off the key length in order to get into the realm of the feasible, as my calculations above show.
Enough computing power and you do not need a back door.
This is a bit off-tangent, but who has the most computing power nowadays: the NSA or a network like SETI or
distributed.net? We're in the internet age, and anyone with enough marketing can harness the power of millions of people around the world, who all have Gigahertz processors in their desktops and laptops now. Reliability or robustness or speed of peripheral devices is not interesting, cracking ciphers is a purely computational task where only the CPU speed is important and that can be excellently distributed among gazillions of different computers.
Remember that it is entirely likely that NSA has bleeding edge technology you and I can only dream of.
Which is where quantum computing will come in when we have it.
As far as I know, quantum computing is still very much in its infancy, and successful calculations have only involved a handful of qubits. Evidence that the NSA is in the frontline of this?
Moreover, the article I linked to above has Whit Diffie say that, even when it is fully functional, quantum computing will render cracking AES-256 to the order of magnitude of AES-128 with conventional computers.