> For sure, you can do PGP, but if it's decades old, you have to ask yourself: Why hasn't public key cryptography taken off as a sign in solution in the same way that email or Google or Facebook have been?
For the same reason a Metamask extension to do so won't take off outside of specialized applications.
Since users have not yet authenticated, this is part of a conversation process of potential users to registered, authenticated users. Only options which will increase that will be supported.
People to some very high double-digit percentage understand what a "Sign in with Google" button does, what will happen if they hit it. Because of that, there is high likelyhood if someone hits that button that they will return successfully authenticated.
PGP never had a website-based authentication option. Mutual TLS did, but other than a few certificate authorities I've never seen it out of the enterprise space - the compatibility and user experience were never even close to sufficient to offer as a broader option.
As optimized as the sign in with Google experience is, there are still sites which will not support it because they want to make sure the user does not get 'lost' on another site if there are failures. They simply will not outsource their funnel.