Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
October 06, 2008, 04:55:56 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
197676
Posts
22756
Topics
54687
Members
Latest Member:
moreonpats
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Learn about Computer Security and Interact with Security Experts
Computer Firewalls
Is this a serious issue? or not? your views are appreciated.
« previous
next »
Pages:
[
1
]
2
3
4
Author
Topic: Is this a serious issue? or not? your views are appreciated. (Read 5856 times)
Melih
Comodo's Hero
Administrator
Comodo's Hero
Offline
Posts: 5644
Is this a serious issue? or not? your views are appreciated.
«
on:
April 30, 2008, 12:13:42 PM »
I was alerted to this
post at wilders
Just wanted to get your views on this.
Is it an important issue?
Does not having enough QA to catch these kind of things from coders is a serious flaw in the development process especially for a "security product"?
thanks
Melih
Logged
Visit Melih's Blog
Vettetech
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 4631
Re: Is this a serious issue? or not? your views are appreciated.
«
Reply #1 on:
April 30, 2008, 01:15:59 PM »
Thats a joke...................no wonder OA is losing people. There web site is still wrong also.
Logged
Little Mac
Global Moderator
Comodo's Hero
Offline
Posts: 6017
Re: Is this a serious issue? or not? your views are appreciated.
«
Reply #2 on:
April 30, 2008, 01:21:24 PM »
Looks like TallEmu's apologized for it as an inappropriate coding; apparently the user provides b-day info at some point and the app reminds them about it. Doesn't seem it's phoning home, so I would say it's not an issue as relating to security. Annoying and undesirable, perhaps, but not a security issue.
I also note that Stem feels quite strongly about it, and is speaking rather harshly of OA in that regard. I wouldn't get involved, as that would drag Comodo's name into it, and the ripples from the last spat are still being felt...
LM
Logged
date
dcfldd split=2G conv=noerror hashwindow=0 hash=md5 bs=32768 hashlog=/mnt/sda1/images/hash.log if=/dev/hda of=/mnt/sda1/images/LM.dd
date
cat LM.dd.* | md5sum > verify.log
date
Melih
Comodo's Hero
Administrator
Comodo's Hero
Offline
Posts: 5644
Re: Is this a serious issue? or not? your views are appreciated.
«
Reply #3 on:
April 30, 2008, 01:28:04 PM »
Is it an alert that gets generated automatically on the date?
or
the user has to do something about it?
thanks
Melih
Logged
Visit Melih's Blog
sded
Global Moderator
Comodo's Hero
Online
Posts: 1919
Re: Is this a serious issue? or not? your views are appreciated.
«
Reply #4 on:
April 30, 2008, 01:40:14 PM »
I don't think Stem has much of a sense of humor, based on previous interactions with him. Probably not a good idea for OA to do such things in security software, but still just a joke. I am not a fan of the CFP3 built in "hint of the day" that I can't turn off, or the "announcements" area that does phone home either, but they are also no big deal.
Logged
CIS Firewall .411, Vista Ultimate x32 + SP1 - UAC, Avast! 4.8, Windows Defender. SAS offline. Acronis True Image just in case.
Frosty Port
Comodo Family Member
Offline
Posts: 54
Re: Is this a serious issue? or not? your views are appreciated.
«
Reply #5 on:
April 30, 2008, 01:52:48 PM »
I find it to be a big security issue!! if they allowed that kind of stuff and did not bother to check there coding to me that shows security is at the back of the line. I have many and used many security programs and NONE of them ever did a thing like that. whats next to pop up game of pac-man? in any case it's a security product not a calender of up coming events.
Logged
{XP-PRO-SP2} {FireFox} {Avast-Pro AV} {Comodo FW pro3}
Frosty Port
Comodo Family Member
Offline
Posts: 54
Re: Is this a serious issue? or not? your views are appreciated.
«
Reply #6 on:
April 30, 2008, 02:00:31 PM »
Quote from: Melih on April 30, 2008, 01:28:04 PM
Is it an alert that gets generated automatically on the date?
or
the user has to do something about it?
thanks
Melih
from the talk on OA forum & Wilders it was hard coded and Mike said that all that stuff would be removed from next releases.
Logged
{XP-PRO-SP2} {FireFox} {Avast-Pro AV} {Comodo FW pro3}
Soyabeaner
Global Moderator
Comodo's Hero
Offline
Posts: 7354
Re: Is this a serious issue? or not? your views are appreciated.
«
Reply #7 on:
April 30, 2008, 02:05:55 PM »
Quote from: sded on April 30, 2008, 01:40:14 PM
I am not a fan of the CFP3 built in "hint of the day" that I can't turn off, or the "announcements" area that does phone home either, but they are also no big deal.
Those can be removed / edited in the C:\Program Files\COMODO\Firewall\cfpinfo.ini file
Logged
Frosty Port
Comodo Family Member
Offline
Posts: 54
Re: Is this a serious issue? or not? your views are appreciated.
«
Reply #8 on:
April 30, 2008, 02:41:25 PM »
IMHO this is why crackers,hacker are so successful!! programmers that has to add a little bit of code to get recension for there work. and in the end there's a back door opened and the hacker just walks right in. it may have been hard coded but imo it is a possible vector for exploiting.
Logged
{XP-PRO-SP2} {FireFox} {Avast-Pro AV} {Comodo FW pro3}
Coolio10
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 461
Re: Is this a serious issue? or not? your views are appreciated.
«
Reply #9 on:
April 30, 2008, 03:02:41 PM »
It not too bad since it does not phone home for this information (false alarm).
But stem doesn't seem too happy
.
Logged
(\__/)
(='.'=)
('')_('')
Melih
Comodo's Hero
Administrator
Comodo's Hero
Offline
Posts: 5644
Re: Is this a serious issue? or not? your views are appreciated.
«
Reply #10 on:
April 30, 2008, 04:44:35 PM »
Quote from: Coolio10 on April 30, 2008, 03:02:41 PM
It not too bad since it does not phone home for this information (false alarm).
But stem doesn't seem too happy
.
Correct me if i am wrong, but the issue they are concentrating is NOT that it phones home etc but lack of QA and code review for such an important security application? As Stem rightly pointed out, this is NOT an action that is "user initiated" like easter eggs where the user has to find a combination of keystroke etc to find something, but this is forced upon the user on a specific date. Does this raise the quality of software development process as an issue?
BTW: Happy belated birthday to the OA developer
and pls do tell us what else is hiding there if any
Melih
Logged
Visit Melih's Blog
Pedro*
Comodo's Hero
Offline
Posts: 787
Re: Is this a serious issue? or not? your views are appreciated.
«
Reply #11 on:
April 30, 2008, 05:35:48 PM »
Do you want my honest opinion Melih? :/
Logged
panic
Global Moderator
Comodo's Hero
Online
Posts: 5451
... and I say to myself, "What a wonderful world"
Re: Is this a serious issue? or not? your views are appreciated.
«
Reply #12 on:
April 30, 2008, 05:38:26 PM »
"We do not need them to fail for us to succeed".
It's a bit of egg on the face for Mike and the team, but not much beyond that. They goofed.
To err is human .....
Logged
As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the
Comodo Forum Policy
.
If you don't like it, don't use the forum.
Vettetech
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 4631
Re: Is this a serious issue? or not? your views are appreciated.
«
Reply #13 on:
April 30, 2008, 07:40:32 PM »
Personally if that was me I would be pissed. Then I would uninstall OA and be done with it. Very unprofessional for a firewall that seems to think the are "The Best There Is" according to there web site. Blah,Blah,Blah.
Logged
Coolio10
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 461
Re: Is this a serious issue? or not? your views are appreciated.
«
Reply #14 on:
April 30, 2008, 08:42:59 PM »
Ya, security applications should not have easter eggs beacause it might make the user think it just got hacked or something.
Logged
(\__/)
(='.'=)
('')_('')
Tags:
Pages:
[
1
]
2
3
4
« previous
next »
Jump to:
Please select a destination:
-----------------------------
** New to the Comodo Forum? Start Here! **
-----------------------------
=> New Member Information
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Leak Testing/Attacks/Vulnerability Research
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
===> Virus/Malware Removal Assistance
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Instant Malware Analysis - Online (CIMA)
=> Comodo DiskShield
=> Comodo Disk Encryption
=> Comodo Secure Email (CSE) Product
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo SafeSurf and (Comodo's own toolbar)
=> Backup
===> FAQ for Comodo Backup
===> Help
=> Verification Engine (allows you to verify what you see on the Internet)
=> Comodo Vulnerability Analyzer
=> AntiSpam
=> i-Vault
=> Launch Pad
=> Trusttoolbar
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo Registry Cleaner
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> User Anywhere (Remote Access product)
=> Comodo Meet (Web Conferencing Product)
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Infrastructure Products
-----------------------------
=> ZTL
=> Trustix Enterprise Firewall
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
Page created in 0.956 seconds with 19 queries.
Powered by SMF 1.1.5
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com