the infosec scene is in a place the OSS scene was in ˜13-14 years ago, before the formal introduction of the gnome foundation, kde reorg. guess what both of those projects have?
outreach programmes and ombudsmän.<p>now, guess what the tor project lacks.<p>as you're probably thinking right now "but how in the f..." simple, OSS has had to deal with toxic enviroments and individuals.
one of the cornerstones is, listen, corroborate, recommend, act.<p>the infosec community as a whole lack formal mature organisations to deal with these kinds of situations.<p>what we're still lacking in the witness accounts are timeframes, we have something of a picture from very vague details from leaked emails, these can be regarding pretty much anything, aside from one which is about _unspecified_ misconduct at a conference.<p>the sad thing here is that people can change, victims with trauma live with the trauma, so listen, validate, no-shame or pre-judgement.<p>but the infosec scene isnt a special snowflake exempt from the social contract of society, we all co-sign it by living in a nationstate, so we need to uphold it because the alternative is chaos.<p>if there is a legitimate grievance, report it, go through the system. hell, even brokep says as much, and he trusts the system on this, even though the process he has been forced to endure.