> started.  It is just that AES-256 is NOT necessarily twice
> as secure as AES-128.

That would be really strange - if you define "twice as secure" as
meaning "it will take on avarage twice as long to crack the crypto",
than adding one byte to the keylength should do that for symetric
algorithms (for pubkey algorighms like RSA / ElGamal / ECC it works

If there were no algorithmic weaknesses AES256 would be 2^128 times as
secure as AES128. In this case I read is that this number is less, but I
assume still very, very large.

