SecurityDriven.Inferno library is nonce-misuse-resistant by design (http://securitydriven.net/inferno/).
SecurityDriven.Inferno library is nonce-misuse-resistant by design (http://securitydriven.net/inferno/).
My main criticism would be that it supports AES256-CBC-HMAC. Encrypt-then-MAC should protect against CBC padding oracles, but CTS mode instead of CBC mode would be more conservative. I understand using CBC instead of CTR mode if you're afraid you might possibly have a flaw that reuses nonces (CBC and CTS modes leak less information than CTR if you have a nonce reuse bug). CTS mode is a slight tweak on CBC mode that modifies the final two blocks in a way that makes it immune to padding oracle attacks. Encrypt-then-MAC should also protect against padding oracle attacks, but CTS mode fits better with the belt-and-suspenders philosophy of Inferno.
Granted, this scenario requires multiple cascading bugs, but that's kind of the point of Inferno. In general, one is well advised to use the most well-tested and standard algorithms, but CTS is very close to CBC. Have you specifically seen any CTS implementation bugs?