Jon Callas jon at callas.org
Sat Aug 17 14:23:54 EDT 2013

> Apologies, ack -- I noticed that in your post.
> (And I think for crypto/security products, the BSD-licence variant is more important for getting it out there than any OSI grumbles.)

Thanks. I agree with your comments in other parts of those notes that I removed about issues with open versus closed source. I often wish I didn't believe in open source, because the people doing closed source get much less flak than we do.

> Ah ok.  Will they be writing an audit report?  Something that will give us trust that more people are sticking their name to it?

I get regular audit reports, and have since last fall. :-)

I haven't been putting them out because it felt like argument from authority. Hey, don't audit this yourself, trust these guys!

Moreover, those reports are guidance we have from an independent party on what to do next. I want those to be raw and unvarnished. If they're going to get varnished, I lose guidance and I also lose speed. A report that's made for the public is definitionally sanitized. I don't want to encourage sanitizing.

It's a hard problem. I understand what you want, but my goal is to provide a good service, not a good report.


