Another thing that can be done is more crowdfunded bounty programs.
5 here: https://cybersecuritynews.com/bug-bounty-platforms/
The issue are "bugs" could be randomly distributed, even across the same version number of some device.
Sample sizes and statistics come into play at that point.
Whistleblower protections are an avenue, but people can still be dealt with harshly (Schulte) and degree-of-protection can come down to motive. But motive itself is multivariate, is it not? A local-first Fediverse, with some type of "guaranteed anonymity" would work, though. But anonymity doesn't mean something can't be a hoax either, so it becomes a signal vs noise issue at that point. Yet, "nothing totally secure ever really is."
Source information can be embedded in the period of a printed sentence too.
A moral world is the answer to many problems. Something to ponder. People are said to only see the errors in their ways after death in the "hall of mirrors."
-- https://web.archive.org/web/20060102095331/http://maitreya-e...
Economic espionage is something to also think about. You may be doing everything right and that's what makes you a target. "If I'm not top dog, target anyone that is."
Perfect anonymity in crypto can also aid whistleblowing so that dump data = get paid.