Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
June 19, 2013, 08:26:39 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
668875
Posts
71129
Topics
145737
Members
Latest Member:
Buscador
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Archived Boards
Discontinued Products
Comodo Firewall
Feedback/Comments/Announcements/News
CFP v3 (un)usability opinion
« previous
next »
Pages:
[
1
]
2
Author
Topic: CFP v3 (un)usability opinion (Read 7488 times)
VitRom
Comodo Family Member
Offline
Posts: 62
CFP v3 (un)usability opinion
«
on:
September 02, 2008, 11:38:46 AM »
Well, after two days of gaming with v3 I have some words to say.
Xcuse me if it's already said in other topics but I don't wanna read all 40+ topiclist pages.
0. Common feelings.
Making products for housewifes ain't good way in security area. It's some low level of complexity here and falling below it makes more problems than that complexity by self.
Unfortunately seems like COMODO in they tries to make things "very easy" goes too far and got absolutely different result.
How said somebody of IT-Gurus (unexact quote): "make a system that can b used even by fool and only fool will use it".
1. HIPS rules too hard to understand (to read).
Here is no way to see that some additional data filled into app rules except stupid way to open "App Rules" than "Access Rights" and then clicks on every "Modify..." button and than on every of two tabs. What's more - in a case of "mass" exploring app rules - after closing "Modify" dialog last clicked button doesn't marked (even by std dotted "focus" frame) and user can't see which button was clicked last and which details should b opened next.
IMHO it isn't too hard to mark settings that contains additional details. For example by bolding that silly "Modify..." text. Or by changing it to "Edit" or "Set" followed with something simple text symbols like "...[o] [o]" / "...[+] [o]" / "...[+] [-]". Sure that hidden sacral meaning of that symbols understable even for interface designers. Again it isn't too hard to marks an app rules in a main list ("computer sec. policy") according to presence of such settings. And again it can b done by simple "+" after app name.
2. The "skins" too slow in some cases.
And when protection set to manual confirmation sometimes CFP makes two jobs - grabs and stacksrequests from program that waits for user decision and draws thiese cool coloured, flawored and smelled bells and wristles like three-four-five-etc-state checkboxes and buttons. This noticeable especially with some programs that uses on-screen effects like transparent windows and popups or even when opened a SysInternals ProcessExplorer (that hooks screen too). And this looks, ughm.. strange and makes feelings of too expensive program (i mean CFP) - for example checkbox "remember" are clicked already but a text drawn "skinned" while check sign still not coloured but plain old black, and wents greenish after some delay only. Pls note that my PC are fast enough for many everyday programs.
3. Configuration editors doesn't shows real configuration.
When a config editor window opened they shows just "snapshot" at a time of opening. And if CFP pops up some request and user confirms it and sets up "remember" flag than config edit window doesn't reflect changes. Moreover when a config editor closed with saving (via "Apply") so just that displayed config are writen back and result of user answer onto popup are lost.
4. Config saved too lazzy and some changes losts on reboot.
I was tired when three or four times after every reboots I've seen goddamned popus abt connections with addresses or ports that was already added as groups. And only when I've looks into "my net groups" I've seen that may groupnames are reverted back to std. And of cause all rules that refers to "LAN" group goes invalid because here is no such group but std "Local Area..." are here.
Looks stupid by I've got my custom netgroup names
only
after editing them then shutting down firewall than starting it again.
5. FW and HIPS rules (and politics) doesn't related no way
For example, it's impossible to create rule like "Advanced file manager" that allows direct disk access but denies any network.
=================================================================
2b continued. May b.
«
Last Edit: September 02, 2008, 12:48:04 PM by VitRom
»
Logged
VitRom
Comodo Family Member
Offline
Posts: 62
Re: CFP v3 (un)usability opinion
«
Reply #1 on:
September 02, 2008, 01:08:41 PM »
OK, show does go on.
6. "Direct disk acces"
Well, I've reivewed my config and disabled "direct disk acces" for explorer.exe. Nothing strange, isn't it? Unfortunately, I've seen that COMODO devels assumes under this words something different from me.
After a few minutes I was shocked with a bunch (4000+) of "suspicious attempts" on a Summary screen. WTF?
OK, I'll dispose a secret: log says that "explorer.exe tries direct disk acces to..." Any versions? Ansver quickly! Well, U are wrong! To "\Device\LanmanRedirector"! I'm on LAN and of course my explorer looks for some net-resources, it's normal. But name this "DIRECT disk access"...
Up to now I've understand under "direct disk access" a something like really direct sector reading/writing and/or ATAPI commands (WinHex, a lot of tools for surface testing or SMART check) but it seems that I was wrong...
Logged
Kyle
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 3678
Re: CFP v3 (un)usability opinion
«
Reply #2 on:
September 02, 2008, 01:26:27 PM »
Hello VitRom, Welcome to the forums.
Thank you for your opinion, I'm sure that someone from comodo will listen to you
The Comodo team in the near future are going to work on making CPF as user friendly as possible without sacrificing security.
Can you please tell us What mode you are running Fire Wall and Defense+ in?
Logged
Windows 7 x64
AMD FX 8120, 8gb ram, ATI 6870 1gb
Kyle
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 3678
Re: CFP v3 (un)usability opinion
«
Reply #3 on:
September 02, 2008, 01:28:45 PM »
You might like to read this;
Quote from: Melih on August 30, 2008, 10:32:02 PM
Thank you for your feedback. much appreciated..
we are working on making CFP a mass market product!
Our strategy to first make sure we build a product that protects people by building one of the most secure apps around and then start making it user friendly without sacrificing its security.
You will see gradual improvements in the coming months. Please keep the suggestions coming.
thanks
melih
Quote can be found here:
http://forums.comodo.com/feedbackcommentsannouncementsnews/suggestions_for_cpf-t26598.0.html;msg193739#msg193739
Logged
Windows 7 x64
AMD FX 8120, 8gb ram, ATI 6870 1gb
VitRom
Comodo Family Member
Offline
Posts: 62
Re: CFP v3 (un)usability opinion
«
Reply #4 on:
September 02, 2008, 04:34:16 PM »
Quote from: Kyle on September 02, 2008, 01:26:27 PM
as user friendly as possible
it's exactly that thing that makes me nervous
Again it's a brilliant phrase (referred sometimes as "Show's Principle", and exists in an any "Murphy's laws" collection) - "Build a system that even a fool can use and only a fool will want to use it"
It isn't my first
girl
HIPS and firewall
so of course I'm in Safe mode and moreover set "allert freq" to "high" - to produce a big number of detailed rules and then analyze it and manually convert into less detailed port-host-etc-groups-based.
Logged
Whoop-dee-doo
Cave Dweller
Global Moderator
Comodo's Hero
Offline
Posts: 1095
What are you staring at?
Re: CFP v3 (un)usability opinion
«
Reply #5 on:
September 02, 2008, 11:59:01 PM »
Making a program user friendly and intuitive does not mean that effectiveness and configurability are compomised.
Quote from: VitRom on September 02, 2008, 04:34:16 PM
"Build a system that even a fool can use and only a fool will want to use it"
If we followed this logic, no one would have bothered to develop windows and similar user freindly operating systems. In fact, no one would have developed user friendly systems such as iphone, ipod, Tom-tom, etc.
A good program should increase the knowledge and proficiency of novice user through a clear and intuitive interface (how many computer naive people learned how to use computers when windows came out? It was a simple interface that allowed more people to become proficient with computers!). Making a product easier to use does not reduce the program to a "fool's" level, but rather it elevates the novice user to a more proficient level.
Logged
"The best way to have a good idea is to have a lot of ideas." - Linus Pauling
"Don't find fault. Find a remedy." - Henry Ford
frogger
Comodo's Hero
Offline
Posts: 399
Re: CFP v3 (un)usability opinion
«
Reply #6 on:
September 03, 2008, 12:23:10 AM »
I'm enjoying the learning curve myself i would not want it any other whey after all if it was so easy to use there would be no point to it. one has to learn and experiment to figure things out just my 2 cent here.
Logged
God Bless
VitRom
Comodo Family Member
Offline
Posts: 62
Re: CFP v3 (un)usability opinion
«
Reply #7 on:
September 04, 2008, 06:04:55 AM »
Well, another one unexpected "test".
7. Yesterday I was set an option "block all reqs when closed", set HIPS to "paranoid" then exited from GUI and went of to my clients. All desktop progs still running. After some time on client PC I was need to check something at CFP PC. I've connects via RDP over 128k ADSL and starts to do something. And at sometime I've got a bunch of "a some.dll isn't win32 image" etc. Well, this dll is a simple hooker that's part of some ui improvement app.
OK, it's simple quiestion and all that I need is only launch CFP gui and set another policy or unset "block when closed", isn't it?
Well, I do it and... GUI window opens and... And over entire half-hour RDP session I can't see a Def+ button drawed properly and can't click on it. At the same time a 5-6 other progs been worked absolutely fine (except I've been forced move them into corners, away from CFP gui occuped area)!
BTW after killing a problem app (and stopping an events flow) switching from one gui area to another was slow too - up to 4-5 secs for full redraw. At the same time... (c abowe).
====================================================================
Whoop-dee-doo
, regardless U want a "classic"-style HIPS (CFP is one of them) CAN NOT BE maked simple enough without making some security holes. It's by definition of that style.
I've seen only one simple enough and secure (in minds at least) simultaneously product - GeSWall. It's MAC-based. Unfortunately it doesn't secure in real life - for example it can be killed by taskman 8-( If someone (I mean COMODO. Hey, devels!) brings together a CFP low-level integration and stability and a GeSWall point of view onto protected objects classification and roules structure this can b a brilliant product. Ouh, dreams...
PS. BTW to b closely to PC world complexity Ur analogy must looks like "a GRID from iphones, a GRID from ipods, etc."
Logged
Whoop-dee-doo
Cave Dweller
Global Moderator
Comodo's Hero
Offline
Posts: 1095
What are you staring at?
Re: CFP v3 (un)usability opinion
«
Reply #8 on:
September 04, 2008, 03:34:20 PM »
Okay folks...I cannot believe what I am reading. So, are you saying that a you cannot make a robust security program intuitive to use? That is total non-sense. This is the "you can't do that" mentality that everyone applied to Michael Phelps before he proved them wrong. Programs like Turbo-tax and Quicken have made filling out your tax return more simple! If you can make taxes simple, you can certainly make a firewall and HIPS simple. Robustness of the defense does not have to be compromised for ease of use.
Also, it seems like some are saying "let's keep it complicated so the less sophisticated won't use it?" A program can certainly be made configurable so more advanced users can have exquisite control over things, but a less advanced user can have certain things automated.
Sounds like to some of you want CFP to be a complicated Rube Goldberg contraption!.
I am sure Comodo is filled with talented "can do" people who can accomplish what you guys think is impossible:
Strong defense, but more intuitive interface.
Logged
"The best way to have a good idea is to have a lot of ideas." - Linus Pauling
"Don't find fault. Find a remedy." - Henry Ford
Melih
CEO - Comodo
Administrator
Comodo's Hero
Offline
Posts: 12944
Re: CFP v3 (un)usability opinion
«
Reply #9 on:
September 04, 2008, 07:19:19 PM »
I think we have to look towards new innovations to create security and usability!
As I always said, we concentrated in security first! our next stage is usability. We have lots of innovation that we will be bringing into CFP/CIS that will give the security without comprimise! Only Nothing is impossible!
Melih
Logged
Who is Melih? What is he trying to do?
--
Follow me on Twitter
weaker
Usability Study Member
Comodo's Hero
Offline
Posts: 505
Re: CFP v3 (un)usability opinion
«
Reply #10 on:
September 05, 2008, 03:09:12 AM »
I want to say that I strongly disagree with the OP. I think that an easy and clear UI is absolutely paramount in order to not pi** everyone off.
It is hard to make such a complex software easy enough for being useable by "housewives" but this has to be the aim: Security for everyone. And there is still lots of room for improvement in the UI part alone.
Logged
VitRom
Comodo Family Member
Offline
Posts: 62
Re: CFP v3 (un)usability opinion
«
Reply #11 on:
September 05, 2008, 05:22:28 AM »
Whoop-dee-doo
and
All
, let me explain:
a "classic style" HIPS it's:
1) a list of apps,
2) a list of permissions,
3) a list of protected areas and
4) a relational web betwen them.
It can't b simplified
not because "menthality" but because "a nature of things"
. Sorry, but it's reality where we lives.
All U can do to "simlify" (in quotes) that -- is to group some "list items" together and make user to make decision not about
every
relation item but
a group of relations
instead. It's just one more level of abstraction. But when U abstract something U drop out some details, isn't it? And all this dropped details fails into categ. "
potential
hole" (two words in a one term, read them together). Will this "potentials" b promoted into "real" -- it's other talk, but
they are exists
anyway.
A good sample of abowe it's CFP "Alert Freq"
It's only
groups many
possible decisions
into one
. Yes it's simplifies a decision making
but
for a price of creating potential holes. If U didn't agreed then reread the previous paragraph again.
For example when U r in a default "allert freq" mode and runs some... well, "the some" that needs a bit of network
and U plans use this "some" again - U allows it activity, "remembers" it and... Welcome, BackOrifice and Co - I have a bunch of allowed ports and addresses!..
A way to
really
simplify CFP config is
1) a
nested
roules hierarchy
Here under "rule" i mean
a set
of "elementhary rules" created according to real world activity templates (mix together udp/tcp/icmp and different addresses regardless "simplification"
level)
2) a turns from total control of a system to something like MAC-based
And
allows
almost any prog almost
everything
(of course while still watching for it
)
until
they really tries to do something wrong
Melih
, it's good that Mods reads this -- I hope they can give something to devels. Pls note that all my opinions abowe are based on a many competetive products from DefenceWall and Symantec to Kerio and ProSecurity (and many other). And all the best things in that set (regardelss users group they are aimed to) are never mix flies and beefs and focuses entirely on that aimed in general regardless what it is -- a simplest isolation (DW) or totally detailed contorl of everything (PS).
PS. Currently CFP tries to sit on two chairs simultaneously. May b it's better to create two completely different UI modes (housewife-mode and geek-mode
) and devel them independedly?
Logged
3xist
Guest
Re: CFP v3 (un)usability opinion
«
Reply #12 on:
September 05, 2008, 05:30:55 AM »
A Classical HIPS can be developed in about 2 weeks by an above-average developer. New Innovations end of this year and next year are going to be introduced to really improve the usability off CFP 3! (Less quite, etc without reducing security). Sandboxing looks interesting too (Due out after CIS is launched).
Josh
Logged
VitRom
Comodo Family Member
Offline
Posts: 62
Re: CFP v3 (un)usability opinion
«
Reply #13 on:
September 05, 2008, 07:05:49 AM »
Quote from: 3xist on September 05, 2008, 05:30:55 AM
A Classical HIPS can be developed in about 2 weeks by an above-average developer.
Sure
...And according to "90/90" rule from Murphy's Laws the next 18 weeks (at least) shall b spent by a team of nine high-average devels onto hardening this product and protecting it from a misc tricks used by malware ("unhooking" for example)
Well, still watching and waiting for "Innovations end of next year"
Logged
Kyle
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 3678
Re: CFP v3 (un)usability opinion
«
Reply #14 on:
September 05, 2008, 07:08:28 AM »
Quote from: VitRom on September 05, 2008, 07:05:49 AM
Sure
...And according to "90/90" rule from Murphy's Laws the next 18 weeks (at least) shall b spent by a team of nine high-average devels onto hardening this product and protecting it from a misc tricks used by malware ("unhooking" for example)
Well, still watching and waiting for "Innovations end of next year"
Melih has his priority's
1, Security
2, User Friendly
I don't think this really needs to be discussed anymore.
Logged
Windows 7 x64
AMD FX 8120, 8gb ram, ATI 6870 1gb
Tags:
CFP 3
interface
Pages:
[
1
]
2
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Reports - CIS
===> AV False Positive/Negative Detection Reporting
=> Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
===> News / Announcements / Feedback - CCE
=====> Wishlist - CCE
===> Help - CCE
===> Bug Reports - CCE
=> Comodo Antivirus for Mac OS X - CAVM
=> Comodo Antivirus for Linux - CAVL
=> Comodo Mobile Security - CMS
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> COMODO IceDragon - CID
===> News / Announcements / Feedback – CID
=====> Wishlist - CID
===> Help – CID
===> Bug Reports - CID
===> Beta Corner – CID
=> Comodo LoginPRO
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
=> Comodo Secure DNS - DNS
===> News / Announcements / Feedback - DNS
===> Help - DNS
=> Comodo Unite (EasyVPN) - CUnite
===> News / Announcements / Feedback - CUnite
===> Help - CUnite
=====> FAQ - CUnite
===> Bug reports - CUnite
=> Comodo TrustConnect - CTC
=> Comodo SiteInspector - CSI
=> Comodo Valkyrie - FLS
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Rescue Disk - CRD
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Utilities - CSU
===> News / Announcements / Feedback - CSU
===> Help - CSU
=====> FAQ - CSU
===> Wishlist - CSU
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Cloud
===> Help - CB
=====> FAQ - CB
===> Wishlist - CB
=> Comodo Programs Manager - CPM
===> News / Announcements / Feedback – CPM
===> Help - CPM
===> Wishlist - CPM
=> GeekBuddy & Live PC Support
=> GeekBuddy PC Health Check - PCHC
===> News/ Announcements / Feedback – PCHC
===> Help - PCHC
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
===> Endpoint Security Manager 1.6
===> Endpoint Security Manager 2.0 Business Edition
===> Endpoint Security Manager 2.1
===> Endpoint Security Manager 3.0
=====> CESM 3.0 Beta
===> ESM Console for Windows Phone
===> Earlier versions of CESM
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
=> Comodo Network Center - CNC
=> Comodo AntiSpam Gateway - Hosted Anti Spam Service
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
=====> News & FAQ
=====> Оффтоп (OFFTOP)
=====> Архив / Archive
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
===> Estonian
===> Arabic
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Web Application Firewall - CWAF
===> Comodo HopSurf - CHS
===> Comodo AntiSpam - CAS
=====> Help - CAS
=======> FAQ - CAS
=====> News / Announcements / Feedback - CAS
=======> Wishlist - CAS
=====> Bug Reports - CAS
===> Verification Engine - CVE
===> Comodo Secure Email - CSE
=====> News / Announcements / Feedback - CSE
=====> Help - CSE
=======> FAQ - CSE
=====> Bug Reports - CSE
===> Comodo Cloud Scanner - CCS
=====> News / Announcements / Feedback - CCS
=====> FAQ - CCS
=====> Beta Corner - CCS
=====> Wishlist - CCS
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
=====> CAVS BETA Corner
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> CFP BETA Corner
=======> 32 bit bug reports
=======> 64 bit bug reports
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
=> Comodo Wiki Project
Page created in 0.078 seconds with 22 queries.
Powered by SMF 1.1.18
|
SMF © 2006, Simple Machines
Design by
7dana.com