Why 1.3? Most sites today are using TLSv1.2 at best, not 1.3.
One argument it is/was "security theater"[1] is that there were/are numerous programs that "added support for SSL/TLS" under pressure to conform but did not bother to add authenticaton measures such as hostname checking and validation, which was not even a function of the OpenSSL library until 2015.
1. Adopting SSL/TLS for accessibility reasons instead of security reasons.