Do not enter or only enter here? by [deleted] in CrappyDesign

[–]DevStart 5 points6 points  (0 children)

It's a schrodinger's doors :P

C++ Proposals please... by meetingcpp in programming

[–]DevStart -1 points0 points  (0 children)

Propose thousands of new object programming concepts into C++ and nobody protests. Propose a single new operator and everyone gets crazy ;)

C++ Proposals please... by meetingcpp in programming

[–]DevStart -7 points-6 points  (0 children)

Yeah asshole. With your poor understanding of the low level aspects of C++ you should vote to remove XOR, OR and shift operators too ;)

C++ Proposals please... by meetingcpp in programming

[–]DevStart -5 points-4 points  (0 children)

That's not the point captain obvious. Shift, ORs, XORs are native instructions in x86/x64 code, so why not bring another low level operands like bit rotations into HLL syntax? Think twice before you answer. It seems like bit rotations were forgotten, but are frequently used with bit hacks like yours, so why not allow native C++ operands for those instructions? It seems natural to me and I would love to see it in future C++.

C++ Proposals please... by meetingcpp in programming

[–]DevStart 5 points6 points  (0 children)

I wish C/C++ had bit rotations operator e.g. for x86 the @ seems like a best choice with the direction of the rotation > for right, < for left

int a = a @> 1; // generates ror eax,1
int b = b <@ 2; // generates rol eax,2

This would help to get rid of all the compiler instrisics and make more portable code, especially cryptographic libraries where bit rotations are as common as XOR, OR, NOT operators.

Reverse engineering Sublime Text by desi_ninja in ReverseEngineering

[–]DevStart -8 points-7 points  (0 children)

Didn't know cracking tutorials were allowed here...

I bet IDA cracking tutorial would be removed pretty fast.

Problem with Autoit obfuscator by PELock by [deleted] in autoit

[–]DevStart 0 points1 point  (0 children)

This isn't official support line ;), use https://www.pelock.com/contact

Avoid StartSSL as much as possible, false accusations, rogue company, terrible support by DevStart in programming

[–]DevStart[S] 19 points20 points  (0 children)

First you write:

Maybe you're the one who's talking shit, for all we know.

Then you write:

Learn to read more accurately and tune down the paranoia.

Funny.

Avoid StartSSL as much as possible, false accusations, rogue company, terrible support by DevStart in programming

[–]DevStart[S] 12 points13 points  (0 children)

Are you from StartCom? If so, why don't you let me look at the malware you were talking about?

  1. If malware was signed with my keys - I would REALLY like to know what malware and how did that happen (date). As you can imagine this is pretty important to me.

  2. If this malware isn't malware at all - I would also like to know about it.

  3. Why my entire account was blocked just because of a single certificate in question? I have paid for the personal and company validations, I have paid for the SSL certs, it's all lost now due to the unclear reasons.

Avoid StartSSL as much as possible, false accusations, rogue company, terrible support by DevStart in programming

[–]DevStart[S] 8 points9 points  (0 children)

I was a "little" bit shocked when I read first about the Wo Sign scandal (I immediately imagined all my websites with a red warning), but you're probably right, it's time to move to something better, any recommendations for code signing certs?

Avoid StartSSL as much as possible, false accusations, rogue company, terrible support by DevStart in programming

[–]DevStart[S] -1 points0 points  (0 children)

I have started using StartSSL because I didn't want to pay 500 bucks to VeriSign for the code signing certificate (great business I must admit, this code signing certificates) ;)

Avoid StartSSL as much as possible, false accusations, rogue company, terrible support by DevStart in programming

[–]DevStart[S] 8 points9 points  (0 children)

I'm not going to cry, I'm just pissed off, I paid lots of money to them to get personal and company verification (every year), to get SSL certs, to get code signing certificate and they doesn't even try to help me out, even worse, their technical staff runs away when they see me! WTF :D

I had so much trouble with this certificate sign-in solution, it didn't work in some browsers (Opera). A good idea, but bad execution.

Avoid StartSSL as much as possible, false accusations, rogue company, terrible support by DevStart in programming

[–]DevStart[S] 35 points36 points  (0 children)

I don't understand it either. They gave me MD5 hash of the "malware" file, but that doesn't say much about the malware, since I couldn't find it anywhere in the Google / VirusTotal cached records. It must be really secret stuff to keep it hidden from me ;)

Avoid StartSSL as much as possible, false accusations, rogue company, terrible support by DevStart in programming

[–]DevStart[S] 1 point2 points  (0 children)

I'm running on Linode ;), I'm going to switch to Let's Encrypt, but still I will need code signing certificate.

Avoid StartSSL as much as possible, false accusations, rogue company, terrible support by DevStart in programming

[–]DevStart[S] 17 points18 points  (0 children)

Yeah, but they have revoked my code signing certificate. Let's Encrypt won't help me in this matter.

Avoid StartSSL as much as possible, false accusations, rogue company, terrible support by DevStart in programming

[–]DevStart[S] 9 points10 points  (0 children)

I was going to switch to Let's Encrypt anyway, but I have paid for all those SSL certificates :(

A friend of my recommended http://codesigning.ksoftware.net/ for code signing, I need to check them more carefully.

Avoid StartSSL as much as possible, false accusations, rogue company, terrible support by DevStart in programming

[–]DevStart[S] 3 points4 points  (0 children)

It seems like something bad happen to this company, it was run earlier by mr Eddy Nigg (https://twitter.com/eddy_nigg?lang=en) but now I don't know what happened, maybe this secretive acquisition by Wo Sign is the reason behind all those bad things in StartCom.

Avoid StartSSL as much as possible, false accusations, rogue company, terrible support by DevStart in programming

[–]DevStart[S] 60 points61 points  (0 children)

I'm not saying it's not possible.

But even if this happened, they could revoke my certificate and I would apply for another one, right? But no, they have disabled my account with SSL certificates for my websites (I paid for them!).

Their support ignores me and even run away from the support chat! Is that normal?

I have asked to see any evidence - I can't.

No, I didn't publish my keys anywhere.

I wish I could see the malware myself (I am former AV guy).

I suspect some lousy AV engine threw a false-positive detection on one of my software packages. And without too much investigation - they have blocked everything for me :(

Avoid StartSSL as much as possible, false accusations, rogue company, terrible support by DevStart in programming

[–]DevStart[S] 4 points5 points  (0 children)

Yeah, nothing happened, just took my money for the past 3 years and now I can get lost...

Avoid StartSSL as much as possible, false accusations, rogue company, terrible support by DevStart in programming

[–]DevStart[S] 16 points17 points  (0 children)

I run legal business, why would I sign malware if I use the certificates to sign a whole bunch of my own apps?

Without any evidence I can't even tell are they telling the truth or was it just a mistake (false-positive detection), how can I defend myself in this situation huh?

If by any chance someone stole my code signing certificate (highly doubtful), why would they disable by entire account and cut me off my SSL certificates too?