Why does TLS make you twitch? Does that apply to TLS 1.3?
[1]: https://loup-vaillant.fr/articles/rolling-your-own-crypto
But frankly I trust my ability -- both now and in 2007 -- to use standard cryptographic algorithms to build a new protocol far more than I trust my ability to remove all the crap from TLS 1.1.
(Did you deliberately not mention heartbleed?)
The threshold question is, "could this vulnerability be reasonably expected to recur in independent implementations of the protocol?"
As for stripping back TLS 1.1 --- it wouldn't take much more than simply picking a single ciphersuite and requiring TLS 1.1. You wouldn't need to know, for instance, about export ciphers.
I get why you didn't use OpenSSL. The normal thing for someone like you to do in 2022 would be to use Noise.
Quick search shows WireGuard protocol, but I am not sure if how much of the WireGuard protocol is the same as the Noise Protocol.
https://www.wireguard.com/formal-verification/ https://www.wireguard.com/papers/wireguard-formal-verificati...
The WireGuard protocol is extensively detailed in [2], which itself is based on the NoiseIK [3] handshake.https://duo.com/labs/tech-notes/noise-protocol-framework-int...
Noise is used today in several high-profile projects:
WhatsApp uses the "Noise Pipes" construction from the specification to perform encryption of client-server communications
WireGuard, a modern VPN, uses the Noise IK pattern to establish encrypted channels between clients
Slack's Nebula project, an overlay networking tool, uses Noise
The Lightning Network uses Noise
I2P uses Noise