Just throwing it out there, but WireGuard does more than just make strong crypto "default". Instead of separating, say, transport from encryption (transformation) they tightly couple them. It's intentionally limiting this flexibility for the sake of performance and administration simplicity...in their own words:
> It intentionally lacks cipher and protocol agility. If
holes are found in the underlying primitives, all endpoints will be required to update.
(https://www.wireguard.com/papers/wireguard.pdf)
Just skimming their whitepaper it seems this is done to cram everything into Layer 3 which has administrative and performance benefits. But comes with a significant tradeoff to flexibility.
They follow up that statement with something that slightly confuses me:
> As shown by the continuing
torrent of SSL/TLS vulnerabilities, cipher agility increases complexity monumentally.
But the general sense I am getting is WireGuard is strongly opinionated and limited...and one way of spinning that is less vulnerable to user error. Personally, I have trouble equating that to meaning WireGuard is more secure. For similar reasons I have trouble equating OpenVPN configuration to "requiring hardening".
That said WireGuard's approach and lower layer, like IPsec, has some serious performance advantages over OpenVPN. Their whitepaper also seems to indicate that it performs better the IPsec, but I would have to see more benchmarks from other sources before making a definitive conclusion on that.
Judging from this article and the comments in this overall thread though, it appears that WireGuard has some zealous (perhaps a bit over-zealous) evangelists though.