We don't have robust discussion infrastructure available within OSS as it's spread through various end-to-end encrypted ones (we use Matrix) but also shared infrastructure like Discord or Slack which are extremely leaky. We do need some sort of web-of-trust to distinguish the good guys from the bad in a particular project context.
Om rykten om en bug är allt en kraftfull modell behöver för att kunna bygga en exploit krävs stängda rum där betrodda parter diskuterar potentiella säkerhetshål. Security by obscurity, i någon mening.
Vidare till källan: anil.recoil.org
