Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
October 07, 2008, 07:57:34 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
197812
Posts
22766
Topics
54719
Members
Latest Member:
endomurat
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Learn about Computer Security and Interact with Security Experts
Computer Firewalls
Is this a serious issue? or not? your views are appreciated.
« previous
next »
Pages:
1
2
[
3
]
4
Author
Topic: Is this a serious issue? or not? your views are appreciated. (Read 5871 times)
Matty_R
Global Moderator
Comodo's Hero
Offline
Posts: 1016
Nice to see you,to see you nice!
Re: Is this a serious issue? or not? your views are appreciated.
«
Reply #30 on:
May 01, 2008, 12:02:04 PM »
I think this is really just a prank which has gone wrong.We have all done something along these lines when growing up,sometimes it is human nature to do things like this.
I work on quite a lot of building sites and there are various pranks going on all the time(cling film on the bog,etc) but there is allways a line which most know should not be crossed.In this case given the type of program it is,i think that the line has been crossed,but lets not get to carried away.The person responsible has by the sound of it been given both barrells by Mike from OA and lets hope has learnt a valuable lesson.
We all make mistakes,its when we dont learn from them that problems arise,i reckon QC at OA will improve know and the staff will surely not make this kind of mistake again.
Regards Matty
Also this reminds me of bricklayers
they like putting messages on every wall they build
Logged
Apart from......what did the "ROMANS" ever do for us........!!!
salmonela
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 445
Spy...nah...sorry but I am just a bot
Re: Is this a serious issue? or not? your views are appreciated.
«
Reply #31 on:
May 01, 2008, 12:35:43 PM »
Serious code inspection should be taken before public appearance, it is not about what is it in the code (easter egg or something else), just not knowing by Mike whats happening is problem here, there is no quality assurance in Tall Emu I guess.
In such environment I can only imagine what would happen to code when somebody from developers have some disagreements or differences or even fight.
That simple "birthday PoC" can tell us much more than their software is not even in alpha phase...
Logged
XP Pro SP3, Pentium4-3Ghz, 4×512Mb DDR, Ralink RT61 WLAN PCI adapter, ZyXEL P-660HW-D3 WLAN Router DSL modem
Bad English, I know...
Thanks
PLEASE DO NOT REPLY DUMB QUESTIONS/ANSWERS
sded
Global Moderator
Comodo's Hero
Online
Posts: 1919
Re: Is this a serious issue? or not? your views are appreciated.
«
Reply #32 on:
May 01, 2008, 02:50:51 PM »
I guess I am surprised that anyone would try to wrap this prank into software QA issues. With the degree of breakage in new releases, lack of regression testing that implies, lack of formal beta testing (at least any that the mods or users know about), the cavalier treatment of the bugreports, the outstanding major problems with the installer, the significant bugs with no known workoff and retest schedule, ... Comodo certainly doesn't stand out for its QA program. But this is also not really a QA issue. Go read
http://en.wikipedia.org/wiki/Software_quality_assurance
for example. Perhaps a breakdown in development process discipline that Mike has vowed to fix would be more appropriate. And yes, I have worked for SEI level 3 and 4 companies and enforced software QA policies on them, not just read the article.
Logged
CIS Firewall .411, Vista Ultimate x32 + SP1 - UAC, Avast! 4.8, Windows Defender. SAS offline. Acronis True Image just in case.
Rafel
Comodo's Hero
Offline
Posts: 291
I use only the best, I use Comodo firewall
Re: Is this a serious issue? or not? your views are appreciated.
«
Reply #33 on:
May 01, 2008, 03:07:27 PM »
Quote from: Vettetech on May 01, 2008, 10:21:52 AM
I think you need spell check. Can you type it again so it makes sense. Sorry.
Melih knows about he is telling.
Ho sent molt, però jo no parle anglés. I'm sorry, but i don't speak english.
Logged
salmonela
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 445
Spy...nah...sorry but I am just a bot
Re: Is this a serious issue? or not? your views are appreciated.
«
Reply #34 on:
May 01, 2008, 03:16:12 PM »
Ok, then
software quality control
Logged
XP Pro SP3, Pentium4-3Ghz, 4×512Mb DDR, Ralink RT61 WLAN PCI adapter, ZyXEL P-660HW-D3 WLAN Router DSL modem
Bad English, I know...
Thanks
PLEASE DO NOT REPLY DUMB QUESTIONS/ANSWERS
Melih
Comodo's Hero
Administrator
Comodo's Hero
Offline
Posts: 5644
Re: Is this a serious issue? or not? your views are appreciated.
«
Reply #35 on:
May 01, 2008, 05:15:03 PM »
Quote from: salmonela on May 01, 2008, 03:16:12 PM
Ok, then
software quality control
I think we are playing with semantics....
Salmonela has identified a good link that describes the issue. I think Salmonela has nailed the issue on the head!!
Here is what the above link goes to (for easier reading)
******
Software Quality Control (also known as Verification and Validation (software)) consists of a means of controlling the quality of software engineering products. It does this by means of tests of the software system. These tests can be unit tests, integration tests, or system tests.
It also includes the formal proof of individual pieces of code, and the review of documents and code.
It is distinct from software quality assurance which includes audits of the quality management system against a standard
. Whereas software quality control is a control of products, software quality assurance is a control of processes.
***********
I have marked the important bits in bold.
thanks
Melih
Logged
Visit Melih's Blog
sded
Global Moderator
Comodo's Hero
Online
Posts: 1919
Re: Is this a serious issue? or not? your views are appreciated.
«
Reply #36 on:
May 01, 2008, 05:52:37 PM »
When I use a word,' Humpty Dumpty said, in a rather scornful tone,' it means just what I choose it to mean, neither more nor less.' per Alice in Wonderland.
Quote from earlier reference:
"It (SQA) is distinct from software quality control which includes reviewing requirements documents, and software testing. SQA encompasses the entire software development process, which includes processes such as software design, coding, source code control, code reviews, change management, configuration management, and release management. Whereas software quality control is a control of products, software quality assurance is a control of processes."
You can decide whether you think OA wasn't tested against its requirements (QC problem) or you are claiming the processes are flawed (QA problem)-or perhaps there was a temporary breakdown in development process discipline as I suggested above. But saying "Does not having enough QA to catch these kind of things from coders is a serious flaw in the development process especially for a "security product?" seems to try to imply that no one (especially Comodo) makes mistakes, and if one is made then the whole process is flawed (a very serious accusation). And is meant to be inflammatory.
Logged
CIS Firewall .411, Vista Ultimate x32 + SP1 - UAC, Avast! 4.8, Windows Defender. SAS offline. Acronis True Image just in case.
Melih
Comodo's Hero
Administrator
Comodo's Hero
Offline
Posts: 5644
Re: Is this a serious issue? or not? your views are appreciated.
«
Reply #37 on:
May 01, 2008, 06:09:49 PM »
As to what it is "meant" to be is very subjective.
having seen basic mistakes over and over from OA team does certainly raise questions. Noone is implying that anyone is 100% fool proof. However there are certain expectation depending on your professional level. for example: if you are a world class football player I expect you to be able to kick the ball
. As they say: Action speaks louder! The issue is not picking this single incident and dwelling on it as such but taking a look at a string of what could be considered to be basic mistakes that has surfaced over last few months and coming to one's own conclusion, thats all.
Melih
«
Last Edit: May 01, 2008, 07:39:06 PM by Melih
»
Logged
Visit Melih's Blog
Little Mac
Global Moderator
Comodo's Hero
Offline
Posts: 6017
Re: Is this a serious issue? or not? your views are appreciated.
«
Reply #38 on:
May 01, 2008, 08:59:37 PM »
Quote from: Melih on May 01, 2008, 06:09:49 PM
having seen basic mistakes over and over from OA team does certainly raise questions. Noone is implying that anyone is 100% fool proof. However there are certain expectation depending on your professional level.
But if we take that position, and look back at all the huff from the public release of various Comodo products, it might be quite easy for folks to reach the same/similar conclusions. Not the same issues, no, but what could appear to be a decided lack of QA or QC (depending on the exact usage thereof). That's not saying that the products are bad! I wouldn't say that at all, but there have been significant issues well after final public release.
I honestly don't think it's fair to call OA on the public carpet for this as an example of bad coding, poor QA, QC, etc. A programmer got a little carried away (wouldn't be the first!), OA has publicly owned it and stated categorically that it's been addressed and won't happen again. That should, IMO, be enough and be the end of it.
Just my $.02 ~
LM
Logged
date
dcfldd split=2G conv=noerror hashwindow=0 hash=md5 bs=32768 hashlog=/mnt/sda1/images/hash.log if=/dev/hda of=/mnt/sda1/images/LM.dd
date
cat LM.dd.* | md5sum > verify.log
date
panic
Global Moderator
Comodo's Hero
Offline
Posts: 5451
... and I say to myself, "What a wonderful world"
Re: Is this a serious issue? or not? your views are appreciated.
«
Reply #39 on:
May 01, 2008, 10:58:00 PM »
Well said.
I'll see your $0.02 and raise it $0.02
Logged
As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the
Comodo Forum Policy
.
If you don't like it, don't use the forum.
Pedro*
Comodo's Hero
Offline
Posts: 787
Re: Is this a serious issue? or not? your views are appreciated.
«
Reply #40 on:
May 02, 2008, 07:59:38 AM »
$0.06
I don't think there's any gain in all this.
Logged
Melih
Comodo's Hero
Administrator
Comodo's Hero
Offline
Posts: 5644
Re: Is this a serious issue? or not? your views are appreciated.
«
Reply #41 on:
May 02, 2008, 08:14:48 AM »
Quote from: Little Mac on May 01, 2008, 08:59:37 PM
But if we take that position, and look back at all the huff from the public release of various Comodo products, it might be quite easy for folks to reach the same/similar conclusions. Not the same issues, no, but what could appear to be a decided lack of QA or QC (depending on the exact usage thereof). That's not saying that the products are bad! I wouldn't say that at all, but there have been significant issues well after final public release.
I honestly don't think it's fair to call OA on the public carpet for this as an example of bad coding, poor QA, QC, etc. A programmer got a little carried away (wouldn't be the first!), OA has publicly owned it and stated categorically that it's been addressed and won't happen again. That should, IMO, be enough and be the end of it.
Just my $.02 ~
LM
I appreciate your point of view, but once again, this example is not being singled out. My view was reached after seeing the following basic mistakes:
1)auto allow if alert is not answered
2)crashing the firewall in flooding
3)allowing rootkit installation
4)allowing ICMP attacks
5)birthday message from the coder
etc etc..
There is a big difference between V3 being such a powerful product and having compatibility issues on its launch on a brand new OS platform for 32 and 64 bit systems and making the above basic mistakes! Hope you can see that point of view..
Again to recap: Making basic mistakes about security over and over on a 2 year old product on a mature OS is totally different than a brand new product having bugs/compatibility issues on a Brand New OS with such huge integration with that particular OS for security...
So I will see and raise to $2
Melih
Logged
Visit Melih's Blog
panic
Global Moderator
Comodo's Hero
Offline
Posts: 5451
... and I say to myself, "What a wonderful world"
Re: Is this a serious issue? or not? your views are appreciated.
«
Reply #42 on:
May 02, 2008, 08:57:55 AM »
Quote from: Melih on May 02, 2008, 08:14:48 AM
So I will see and raise to $2
I call, but I'm still in.
Logged
As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the
Comodo Forum Policy
.
If you don't like it, don't use the forum.
Pedro*
Comodo's Hero
Offline
Posts: 787
Re: Is this a serious issue? or not? your views are appreciated.
«
Reply #43 on:
May 02, 2008, 09:17:01 AM »
My poker knowledge is so bad. If you call aren't you in anyway
Logged
panic
Global Moderator
Comodo's Hero
Offline
Posts: 5451
... and I say to myself, "What a wonderful world"
Re: Is this a serious issue? or not? your views are appreciated.
«
Reply #44 on:
May 02, 2008, 09:19:53 AM »
Making allowances for non-players.
Logged
As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the
Comodo Forum Policy
.
If you don't like it, don't use the forum.
Tags:
Pages:
1
2
[
3
]
4
« previous
next »
Jump to:
Please select a destination:
-----------------------------
** New to the Comodo Forum? Start Here! **
-----------------------------
=> New Member Information
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Leak Testing/Attacks/Vulnerability Research
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
===> Virus/Malware Removal Assistance
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Instant Malware Analysis - Online (CIMA)
=> Comodo DiskShield
=> Comodo Disk Encryption
=> Comodo Secure Email (CSE) Product
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo SafeSurf and (Comodo's own toolbar)
=> Backup
===> FAQ for Comodo Backup
===> Help
=> Verification Engine (allows you to verify what you see on the Internet)
=> Comodo Vulnerability Analyzer
=> AntiSpam
=> i-Vault
=> Launch Pad
=> Trusttoolbar
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo Registry Cleaner
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> User Anywhere (Remote Access product)
=> Comodo Meet (Web Conferencing Product)
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Infrastructure Products
-----------------------------
=> ZTL
=> Trustix Enterprise Firewall
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
Page created in 0.6 seconds with 19 queries.
Powered by SMF 1.1.5
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com