I am interested in auditing cryptographic source code on my spare time.
Some of the projects I am considering auditing include GNUPG, Sequoia-PGP, Mullvad, and Rustls.
For those of you who have experience auditing cryptographic source code what advice would you give?
I thank all in advance for any responses.