Being on social media is very relevant due to both content discovery algorithms being able to connect people who may be interested in the project with the project itself and because social media sites can have things go viral outside of your own personal reach. Your post can reposted or spread by other accounts easier if its originating from the platform itself instead of hopping someone sees it and copies onto the platform.
Holing up in mailing lists definitely isn't going to help with pulling in users or devs.
[1] although it was maybe specifically just me they weren’t trying to attract.
[2] to the point where I actually worked with someone in my day job who was a debian dev and he wouldn’t sign my key without me producing physical official ID like a passport or something. Just really bizarre level of paranoia like a government kyc process or something.
People should only sign a key under at least two conditions:
The key owner convinces the signer that the identity in the UID is indeed their own identity by whatever evidence the signer is willing to accept as convincing. Usually this means the key owner must present a government issued ID with a picture and information that match up with the key owner. (Some signers know that government issued ID's are easily forged and that the trustability of the issuing authorities is often suspect and so they may require additional and/or alternative evidence of identity).
The key owner verifies that the fingerprint and the length of the key about to be signed is indeed their own.
--
...debian is INDEED old-school and slightly derpy (see their use of the condorcet voting method), but it has boded extremely well for their longevity. Debian exists for its users, and its users are generally developers.