* The massive fundraising drive for an audit did not contribute back to the project in any way. I think half, or at least 25%, of a fundraiser tangential to a project should go back to the project itself. If something is valuable enough to audit, it should be valuable enough to pay for. It seems like a massive slap in the face to developers to directly compete with them in the donations pool in such a way.
* As far as I can tell, the audit project began without the consent of the Truecrypt developers. You can argue that this is necessary for some security reason, but it is also a rude gesture to an open-source project.
* The crowdfunding drive contained no provisions for handling the results of the audit such as developer resources, etc.. The existing developers were assumed to be both capable and motivated to drop whatever they were spending their free time working on to fix things that auditors found.
* The atmosphere around the audit push from the beginning seemed very negative. There was a distinct "Truecrypt is super sketchy" vibe in the HN comments, etc., surrounding it initially. I think that this was a good thing for the audit, which meant helping the audit directly hurt the Truecrypt brand. This dovetails with...
* Singling out Truecrypt as the target of an extensive, expensive audit seems somewhat absurd. There are several projects that could have benefited much more from an audit that weren't audited, such as OpenSSL, Linux's RNG, OpenVPN, any other TLS implementation, Tor, maybe TextSecure (though I don't know if TextSecure had enough of a userbase at the time to justify it, it certainly does now). Why were these projects not audited? I think it's because the Truecrypt devs tried to be anonymous, and low-profile, whereas these other projects are all backed by people with faces who are much harder to throw something at than Truecrypt was.
istruecryptauditedyet.com is a real page now, but what was it before? A giant NO on the screen? Is there an 'istextsecureauditedyet.com' even though TS uses novel protocols and crypto? Why not?
So, I think:
* The fundraiser should have supported Truecrypt while raising money for an audit
* The fundraiser should have incorporated costs to fix anything found as a result of an audit, with money going back to Truecrypt if nothing substantial was found
* The audit push should have been conducted with the consent, or better yet, solicitation, from Truecrypt developers
* The audit should have been conducted in a more respectful way, emphasizing the positive gain from auditing specifically Truecrypt rather than the negative aspects of Truecrypt's existing development style
In general, open source is a massive donation of time and effort and should be treated like the gift that it is instead of being taken for granted. I think that people took Truecrypt for granted and that's probably a part of the reason why its developer quit, because that is a very common reason for open-source developers to quit and I find it impossible to believe that it was not at all a factor in their quitting.
If you would truly feel happy if your project was shit on, donations effectively stolen from you, and a ton of work dumped on you that you did not ask for, but now must immediately address lest you be attacked for "ignoring the results of the audit," you are a special type of human to say the least.