There's no way this is legit, but if it is, what other kind of cross-platform solution is available? I need to be able to encrypt/decrypt on all 3 major OSes.
They didn't seem that severe to me, they seemed pretty minor actually. Especially if your attack vector is solely a read attack rather than a read-write attack.
Which one got you worried?
Which, seeing as my current major use case is to lock down Dropbox, kind of renders it useless for me.
However you should not use XTS with Dropbox http://sockpuppet.org/blog/2014/04/30/you-dont-want-xts/