2011 Passwords: BPKDF2-HMAC-SHA1 with 1000 iterations
2011 Passwords: BPKDF2-HMAC-SHA1 with 600 iterations
2011 768 bit RSA
2011 512 bit RSA
2011 600 bit RSA
2011 1280 bit RSA
2011 1024 bit RSA
2011 1048 bit RSA
2011 1536/1152 bit RSA (Chrome/other)
2011 1536/1024 bit RSA (Chrome/other)
2011 "3072 bit" D-H
2011 "3072 bit" D-H
2011 "4096 bit" D-H
2012 ECC Curve25519
(edited for clarity)Major red flag. The difference between symmetric-keyed password-based encryption, RSA, Diffie-Hellman and ECC (presuming ECDH?) isn't minor; it isn't a feature-level distinction. These are radically different designs. I'm not sure I've ever seen a system as popular as this so quickly take a tour of so much of cryptography. How could anyone have any kind of grip on the safety of a system that fundamentally changes its crypto constructions so often?
A lesson here: if you have to implement cryptography --- and you and your users would be much better off if you didn't, and rather relied on a standard implementation like PGP --- do one thing and stick with it. Think of it like being a little kid lost in a shopping mall. Don't make it harder to get found.