I'd expect very few clients to negotiate using SHA-384. It's widely viewed as overkill compared to SHA-256, and it hurts performance.
I'm not saying it invalidates the benchmark results or anything—I just wanted to address your "not used" question.
I'm not saying it invalidates the benchmark results or anything—I just wanted to address your "not used" question.
The speed advantage of SHA-512 and the advantage of truncation is why some more exotic variants like SHA-512/256 (SHA-512 truncated to 256 bits) are used in newer protocols.