# Gloria Zhao became a Bitcoin Core maintainer

**URL:** https://forum.zcashcommunity.com/t/gloria-zhao-became-a-bitcoin-core-maintainer/42557
**Category:** Off Topic Lounge
**Created:** [July 19, 2022, 8:58pm UTC](https://forum.zcashcommunity.com/t/gloria-zhao-became-a-bitcoin-core-maintainer/42557 "2022-07-19T20:58:43Z")
**Posts on this page:** 1
**Page:** 1

<div class="post-metadata">

### Author: ![nullius](https://sea2.discourse-cdn.com/zcash/user_avatar/forum.zcashcommunity.com/nullius/32/20935_2.png) [@nullius](https://forum.zcashcommunity.com/u/nullius)
#### Post date: [July 19, 2022, 8:58pm UTC](https://forum.zcashcommunity.com/t/gloria-zhao-became-a-bitcoin-core-maintainer/42557/1 "2022-07-19T20:58:43Z")

</div>

Big news recently in the Zcash’s [upstream codebase](https://forum.zcashcommunity.com/t/cherry-picking-tor-onion-v3-and-other-overlay-networks-from-bitcoin/42421): Gloria Zhao ([glozow](https://github.com/glozow)) was added to trusted-keys on 2022-07-07, thus making her a Bitcoin Core maintainer.

https://www.youtube.com/embed/te-2ke6g3lU?feature=oembed&wmode=opaque

By happenstance, this occurred when Pieter Wuille (sipa) stepped down from maintainership.

> <https://twitter.com/peterktodd/status/1545533963317411842>
>
> Namcios @namcios

Naturally, I want to know what someone in such a responsible position thinks about important issues. On one of the most important subjects, I notice something that Gloria wrote for _Blockchain at Berkeley_ while she was still an undergrad at U.C. Berkeley:

> **[Digital Panopticon: Why Privacy is a Human Right](https://medium.com/blockchain-at-berkeley/digital-panopticon-why-privacy-is-a-human-right-2ab6dae77433)**
>
> A design for efficient digital oppression, and an argument for why you should care about your privacy.

So, her influences include **Edward Snowden, Virgil, Bruce Schneier, and Julian Assange.** I like her way of thinking.

> > “Privacy and censorship resistance should be the default. We can’t keep measuring technologies or applications based on how convenient they are or how cheap they are.  
> > We need to start thinking about how private they are.” – Gloria Zhao [[source](https://bitcoinundco.com/en/gloria-zhao/)]

#### Who pays?

After she graduated, Gloria entered a [fellowship at Brink](https://brink.dev/blog/2020/12/01/gloria/)—a paid full-time position working on Bitcoin Core—supported by grants from [the Human Rights Foundation](https://hrf.org/hrf-announces-two-bitcoin-development-fund-updates-new-gift-to-gloria-zhao-and-partnership-with-gemini/) and from Jack Dorsey’s [Square Crypto (now Spiral)](https://spiral.xyz/#grants). As I have repeatedly observed, developers need to be paid _somehow;_ and all of Bitcoin Core, **including Zcash’s foundational upstream codebase,** is MIT-licensed code funded by grants from businesses, nonprofits, and altruistic individuals.

Food for thought: [**Bitcoin Core’s funding is decentralized.**](https://forum.zcashcommunity.com/t/on-cooperation-and-competition-plus-my-disclosure-of-interests/42477#heading--bitcoin-and-zcash) No one party holds the purse strings—nobody can exercise financial control of the whole process, or even of a too-large proportion of it. The people who pay, choose to pay because they expect results. The results: The reference node is a well-maintained masterpiece of world-class financial software engineering, the ecosystem is thriving—and even in a deep bear market, BTC is still up about 23x over its price at the beginning of 2017.

When I want to succeed, I learn from success.

### This is crypto.

Since she started full-time work on Bitcoin Core, Gloria has established herself as an expert in [mempool policy and transaction propagation](https://gist.github.com/glozow/dc4e9d5c5b14ade7cdfac40f43adb18a), contributed code, and participated in code reviews. And now, her PGP key has been entrusted with maintainership responsibilities:

> <https://github.com/bitcoin/bitcoin/pull/25524>
>
> For maintaining mempool and policy areas of the codebase, as discussed yesterday…'s meeting: https://gnusha.org/bitcoin-core-dev/2022-06-30.log

Trusting **PGP keys** means not trusting Github, not trusting Github accounts, not trusting passwords/2FA and other insecure nonsense.

**This is a part of the security process assuring the integrity of software that’s ready for trillion-dollar financial usage. This is the [magic](https://forum.zcashcommunity.com/t/self-custody-self-hosted/42027/10#heading--magic) of crypto:**

[![glozow](https://global.discourse-cdn.com/zcash/original/3X/6/0/6048f86d3bba2b753aff77c440d552f9116c7e96.png)](https://github.com/bitcoin/bitcoin/pull/25524/commits/ebe106a754d2da567702e60185142d9e381bf1cd)

Aside, I advocate a strict policy of PGP signatures, enforced by automated scripts. That is called using _crypto_. [Bitcoin and PGP share DNA](https://bitcointalk.org/index.php?topic=155054.0), so I’m not surprised that Bitcoin Core engineered a secure development process with a cryptographically verifiable audit trail (not to mention that Bitcoin Core was [a pioneer](https://gitian.org/) in the practice of [reproducible builds](https://reproducible-builds.org/who/projects/)). Especially in defi and smart contract chains, I am stunned to see “crypto” codebases proliferating from developers who seem never even to have heard of crypto; any project that lacks a cryptographically authenticatable audit trail of commits is not ready for ~~high-value financial usage~~ _any sane usage_. And I never trust as credible the “crypto” opinions of anyone who doesn’t use PGP.

My motto: [**If you don’t do PGP, you don’t do crypto!**](https://forum.zcashcommunity.com/t/show-your-id-kyc-for-the-zcash-forum/42532)

This is important for _any_ software:

> **[How (and why) to sign Git commits | With Blue Ink](https://withblue.ink/2020/05/17/how-and-why-to-sign-git-commits.html)**
>
> Authenticate your commits, plus get them the "Verified" badge on GitHub

[https://mikegerwitz.com/2012/05/a-git-horror-story-repository-integrity-with-signed-commits](https://mikegerwitz.com/2012/05/a-git-horror-story-repository-integrity-with-signed-commits)

Gloria _gets_ crypto—I mean, the practice of applied cryptography. Bitcoin Core welcomes her to trusted-keys. 😺

[![glozow.2021-09-10.132856734-fc17da75-f875-44bb-b954-cb7a1725cc0d](https://global.discourse-cdn.com/zcash/original/3X/c/8/c874a629664b00910ea14236ca3f74419fde3ec7.png)](https://gist.github.com/glozow/dc4e9d5c5b14ade7cdfac40f43adb18a)  
(Image source: Gloria Zhao.)
