Matze, I’d like to correct you on your assertion that AES-128 is not broken, it is. Cryptographers consider the whole suite of AES implementations to be broken: AES-128, AES-196 and AES-256 to be broken. For most practical purposes it still is the best cipher.

128-bit is more than sufficient for most people – indeed Apple use 128 in their FileVault product, Microsoft’s default is 128 in BitLocker and it’s the default in Microsoft Office.

Why does AES-256 exist? To satisfy “bureaucratic lassitude” and to make people who don’t know any better feel happy. Ignorance is bliss.