This seems pretty inaccurate.
* Lots of software projects sign their releases with PGP.
* Almost all Linux distributions sign their software with PGP. If you use Linux, your security relies critically PGP.
* Github has support for PGP, and I see people use it.
* My random server hoster happens to sign all their emails with PGP.
You could claim that all these systems are run "by the most hard core of nerds", but at that point the statement loses its relevance.