I absolutely am in favor of just using libsodium box/secretbox instead of having to understand this sort of nuance.
> Who is a laddered recommendation of different signing algorithms really helping?
People who ask me nitpicky questions about whether or not they should opt for 3072-bit RSA keys instead of 2048-bit RSA keys. The main purpose of the post was the first half (the "it doesn't matter" point).
This could happen if they're relaxing their recommendations to double down on post-quantum cryptography.
This could happen if they had a mathematical breakthrough that invalidated all ECDLP security estimates.
I'll never know which it is. The pragmatic thing is to research PQCrypto and make sure the next generation of asymmetric primitives are as good as they can be.