* Does not require X.509 processing, which is a huge source of TLS implementation bugs.
* Uses secure-by-default ciphersuite which, unlike TLS's, was designed after the most important work in authenticated encryption was published.
* Does not include legacy ciphersuites with known flaws.
* Mutually authenticated without invoking TLS corner case subprotocols like client certificates and session resumption.
* Small enough to be auditable.
spipes builds upon well-understood primitives and provides a simple, clear, and likely to be correct implementation.
TLS and spiped are simply two different tools, for two different purposes. Control only one of the endpoints? You'll have to use TLS. Want to secure communication between infrastructure you control? Check out spiped.
What are your thoughts now on not exposing yourself to all of the complexity of OpenSLL?