cd gnupg-2.4.0; find . -name '.c' | xargs wc -l
350949 total
cd ../age; find . -name '.go' | xargs wc -l
5089 total
There are all kinds of differences between C and Go code, and it's also not fair to compare newer and older projects. But the reality is that I can take an afternoon stroll through Age and see pretty quickly what it is doing and how. As an aside, the very thing I find useful about Monocypher. Hat tips to Loup and Filippo on the way out.
Which is exactly why I use age, the thing’s so simple there’s no way I can fuck it up, and I can plug in an ssh pubkey straight from github.
And I say that even though I'd rather write my own file encryption tool than spend even a minute learning how to use GPG.
This is the kicker. Modern versions of GPG have sane defaults, but if I were a new developer who knew nothing about encryption, I would be very scared of GPG, it's aged documentation, and multitude of encryption and signing methods.
Following the wrong stackoverflow answer, or an out-of-date blog post could easily get you a GPG configuration that is insecure in the year 2023.
The same cannot be said for age, it has no knobs that you can dial to an insecure setting. If you'll forgive the expression, it is "idiot proof".
Like you said though, GPG works, as long as you have that safe workflow.
This doesn't even attempt to replace PGP in cases where you need to deal with webs of trust or signatures, though you can build your own signature scheme by encrypting twice (after reading up on your cryptography of course).
I don't really understand what you mean by "10x better". It encrypts fast and securely, based on a readable specification. I don't know what it needs to do better to cover its intended use case.