These do look like serious problems, but it seems to me that all or at least most of them can be fixed. (Are there any "deal breakers"?) What they need is cryptography experts to do more than comment publicly (which is commendable, I am not criticizing), but also contribute some fixes. It is open source after all.
To say that the whole thing is a waste of effort and money is a little strong-worded I think.
To say that the whole thing is a waste of effort and money is a little strong-worded I think.