What are the arguments against RSA OAEP?
(There are attacks against OAEP, but they're less common and not intrinsic to the design the way PKCS1v15's are).
My impression is that RSA never really got the "djb treatment". The people designing OAEP and friends were mostly theorists concerned with security reductions, not implementation issues. I think an idiot-proof RSA scheme could be devised, but it is now way too late for that.