Real encryption in the browser, and the fix that made it usable
The browser can now actually encrypt and decrypt data on your own machine. crypto.subtle gained real AES (the symmetric cipher the whole web runs on) in both the CTR and CBC modes, for 128, 192 and 256-bit keys, with key generation and import - all hand-written and checked byte-for-byte against the official NIST test vectors, the same way the hashing was. That is the path client-side encryption, sealed local storage and end-to-end features take, and it now works without a server. While wiring it up we found and fixed a real gap that had been quietly breaking it: reading the bytes back out of a crypto result with Array.from, the spread operator, or a for-of loop returned nothing, because those never actually walked a typed array. That is the single most common way to read binary data in JavaScript, so fixing it does far more than help encryption. Deliberately NOT included: AES-GCM, whose authentication tag is a separate primitive a vector test would not fully catch, so it is left absent (a page detects that and falls back) rather than shipped unverified. The Web API figure moves one point for the real capability added.