WinZip offers two kinds of encryption: standard Zip 2.0 encryption and strong encryption using the Advanced Encryption Standard (AES).
The Zip 2.0 encryption format is supported by most other Zip file utilities. Password protecting a Zip file (.zip or .zipx) with Zip 2.0 encryption provides a measure of protection against a casual user who does not have the password and is trying to determine the contents of the files. However, the Zip 2.0 encryption format is known to be relatively weak, and cannot be expected to provide protection from individuals with access to specialized password recovery tools.
Do not rely on Zip 2.0 encryption to provide strong data security.
If you have important security requirements for your data, you should use WinZip's AES encryption. AES is the Advanced Encryption Standard, which is the result of a three-year competition sponsored by the U.S. Government's National Institute of Standards and Technology (NIST). This encryption method, also known as Rijndael, has been adopted by NIST as a Federal Information Processing Standard.
WinZip supports AES encryption in two different strengths: 128-bit AES and 256-bit AES. These numbers refer to the size of the encryption keys that are used to encrypt the data. 256-bit AES is stronger than 128-bit AES, but both of them can provide significantly greater security than the standard Zip 2.0 method described above. An advantage of 128-bit AES over the 256-bit AES is that it is slightly faster, that is, it takes less time to encrypt or decrypt a file.
The security of your data depends not only on the strength of the encryption method but also on the strength of your password, including factors such as length and composition of the password, and the measures you take to ensure that your password is not disclosed to unauthorized third parties.
Note that the Zip file format extension used by WinZip to store AES-encrypted files is not supported by versions of WinZip earlier than version 9.0. Also, it is supported by some other Zip file utilities (but not all). In order to extract a file encrypted with AES, WinZip 9.0 or higher may be required. Because the full technical specification for WinZip's AES format extension is available on the WinZip web site other Zip file utilities can add and have added support for this format extension.