Earlier quoted context omitted.
> how do you possibly deal with refactoring that for consistency when so many other projects are consuming OpenSSL as a library? You split your project into two components: 1. a new, clean, minimal core with a nice, shiny, new API; and 2. an "OpenSSL emulation layer" that loads your core library, and wraps it in OpenSSL-compatible cruft. It'd be very similar to, say, replacing Direct3D with OpenGL, and then writing a…
it sounds so easy when you break it out like that but it is a considerable investment of time and money. Convincing people to spend either of those on refactoring vs adding new features is a constant battle. No one ever really understands it and typically responds with "you want to go back and do what you already did, just differently?"
Unless there's an actual federation behind the project that can fund it and keep it stocked with talent and oversight, something Mozilla or Apache could do, it will continue to be an unmitigated disaster.