The one you should use, AES-GCM, wasn't even in the original box, but was MacGyvered later.
The one you should use, AES-GCM, wasn't even in the original box, but was MacGyvered later.
GCM wasn't "MacGyvered" any more than ChaChaPoly. ChaCha doesn't give you authentication by itself, and you need authentication. You could in theory do ChaCha/GMAC or AES-CTR/Poly1305 and be okay if you engineered it properly. I think NaCl already has AES-CTR/Poly1305 in it.
There are definitely ways in which GCM is more brittle than ChaCha; in particular, you can use random nonces with XChaCha, and you technically can't safely do that with GCM. But really, throw a dart, your outcome will be the same either way.
https://crypto.stackexchange.com/questions/42982/safety-of-r...
I personally prefer the SIV modes, but using a sequential nonce within a session is pretty much always better due to birthday attack stuff.
Cryptography does advance over time. When GCM was introduced it was when everyone realized that you must always have authentication and they wanted a faster auth mode than HMAC.
Makes me wonder what new understandings might be coming down the road other than the obvious quantum computing factor. The most recent one I remember is the risk of combining compression with crypto if the attacker can influence anything in the compressed data.