Announcing my resignation from the ZOMG

Not Hudson’s fault, but I think the sexist thing set off some things. Part of that’s a good thing, we should all make sure we’re not being unconsciously sexist. It’s really easy to do and not ok. And that may have happened to Sarah, for example in her candidacy thread for ZOMG when discussions about zero-days came up. But that has nothing to do with @adityapk00’s response. And I’m afraid he’s going to get tarred with it unfairly. That would be wrong and a disservice to adityapk00’s contributions.

For those of you who don’t know, @sarahjamielewis publicly announced a vulnerability in zec wallet some time ago without really notifying @adityapk00. There are reasons to do this and reasons not to, its a debated topic in infosec with no resolution. And some of the sexism I saw in this forum was over debating Sarah on this and basically concern trolling what is a totally valid security stance. But, when you publicly disclose a vulnerability with no notice, you are going to make life a pain for the developer and they are not going to like you at all. Not in some pretty personal way, but in a “you intentionally made my life harder and stressful and wronged me professionally” kinda way. Particularly if your justification is

“My reasons for ethically disclosing this via a tweet and not a private email is that I’m very high and I found and created a PoC to this in 20 minutes and so it’s inevitable that any dedicated attacker has found and is exploiting this in the 8 hours this app has been released.”"
https://twitter.com/SarahJamieLewis/status/1236139783711121408"

So, there’s bad blood between @adityapk00 and Sarah for completely valid reasons. Even if no one was in the wrong.

And Sarah is the one who announces that ZOMG isn’t funding zecwallet long term. (edit: but suggests long term funding might be available later, here’s 2 months of funding now. There’s some room for interpretation here on how much of a rejection this was, but it’s clear how it was taken.)
And it’s done for concerns about “duplication” of work @adityapk00 is already doing and no one else is. I actually can understand what ZOMG was getting at here and I suggested what I still think is a good compromise , but the announcement was tone deaf and pretty much guaranteed to cause problems . As were some of the clarifications. This whole thing would probably have been resolved better with a phone call. But it wasn’t. So Sarah resigned, which I think was the right call because it helps resolve the issue, and here we all are.

13 Likes