I think cryptography engineers increasingly agree with this take, but it's also a different world: it would be straightforward to do XAES and modern P-curve implementations (now that they've been worked out with complete addition and stuff like that) now, but that was less the case when WireGuard was first published.