After the big openssl bug, wasn't there some intent among some of the existing foundations to try to identify open source keystone projects and get them additional attention & support? It seems like the privacy advocacy groups might route some spending to GPG just as a pragmatic matter.