Great points. Crypto articles written by non-experts always make me shudder. To baldly assert that AES 256 is better than AES 128 without discussing related key attacks is to miss a critical point, as is simply asserting "CBC good" without considering how AES is used; cf expert guidance to use AES CTR in SSH instead, given plaintext-recovery-based attacks.
Note: I'm not an expert, just a better-than-average-informed worker near the field. I've had the joy and privilege of working with two expert cryptographers and an expert cryptanalyst, and it was a humbling experience: Brains the size of planets and three of nicest, most decent people you'd ever meet.
Side-note: I was working late on a design doc based in part on one of the first PKIX drafts when I came upon something that struck me as odd. The cryptographer responsible for the draft was also working late, so I wandered over to his office and asked about it. Long story short, after we'd drawn and erased a few diagrams on/from his whiteboard, this affable, sweet man fixed me with what I can only describe as a "Cylon stare" and said "So you're saying the lifetime should apply to the key, not the certificate?" When I said "yes", rather more meekly than I'd meant to, the Cylon disappeared and he said offhandedly "OK, I'll update the draft!"
I love working with really smart people. Working with smart nice people is sublime.