Welcome, Guest. Please login or register.
November 20, 2009, 06:45:21 PM

Login with username, password and session length

336374 Posts
37211 Topics
84365 Members

Latest Member: lukankata

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Internet Security - CIS
| | |-+  Help - CIS
| | | |-+  Install / Setup / Configuration Help
| | | | |-+  Using Installation Mode and other Operational Questions
« previous next »
Pages: 1 [2] Go Down Print
Author Topic: Using Installation Mode and other Operational Questions  (Read 5470 times)
Divine
Newbie
*
Offline Offline

Posts: 5


« Reply #15 on: February 24, 2009, 10:05:15 AM »

Permit me to reply in this thread - just delete if this is inappropriate (I'm a newbie and find it difficult to find or get access to the right forum to ask newbie questions).

What is a firewall? If it's software, it ought to work without requiring me to be the firewall. <g> Otherwise the software is nothing more than an alert system, requiring me to do the firewalling (?).

Here's a case in point. (Again, please delete if this is an inappropriate comment or inappropriately placed. I.e., act as firewall. <g>) Yesterday MS released SP 3.5 of .net - a big update. For the first half hour, I responded to each of Comodo's alerts - orange and red - to items such as svchost and rundll (!) and accepted everything until acceptance got to be just automatic. So what was the firewall (me) doing? At that point I exited from Comodo and ran for the additional hour of download and installation (which also required on-line access: don't you love MS security?!).

Never - ever - have I run without a firewall before. No one should have to do that or have that as an option to standing in front of a computer keyboard incessantly repeating the "accept" click.

Something seems really wrong with my setup or with my understanding of the philosophy of Comodo. What did I do wrong. It was I the firewall, not Comodo. Is there a "sensible only" alert configuration that I haven't yet found (yes, I downloaded and have read (most of) the docs.) Is there a way to exclude omnipresent rundll or svchost alerts? (Not in the docs). Is there a way to have Comodo use an intelligent selection of what gets alerted using a database acquired from other users and that can spot the difference between normal and potentially dangerous activity? I want to use and trust Comodo and hope the answer to these questions is _not_: let it run in training mode for a couple of days... Because then it is me that's the firewall, not Comodo.


Moderator's Note:  Several Posts relating to CIS Operations have been moved from Melih's Corner, here so that the user's questions can be answered without disrupting the previous thread.



=======================================================================

 Hi Carls2
Kewl

***This solution is based on XP (sp2 or higher).

**VIEW:

Imagine you are at home and a number of people press on your door bell. It will be up to you to either allow or disallow them into your home (better more, in the case of a sales representative).

Well, you have just acted as a firewall by allowing or disallowing whoever. You will need to answer the door when alerted by the door bell.

**UNDERSTANDING CIS:

- Whenever you are installing a new application, CIS alerts you if either allow or disallow the application;
- but because you know that the application is not armful to your system, you thereby allow the application the first time and
- when prompted a second time, simply drop down the menu and selcet "Trusted Application" and "Ok".
- CIS will from therefort, treat your application as a trusted application, whereby refraining from alerting you every now and again through the installation process.

**P/N:
The above also applies to all alerts that you get, as long as you know that the application is save for you. If you are unsure of the application, click the top left link on the alert panel for more information regarding the application or file.

Base on CIS Version 3.8.64739.471: You can use this as a guide if you have a different version.
You can find more information by using the CIS Help file by clicking miscellaneous, and then open Introduction to Comodo Internet Security then selcet Understanding Alerts.

**COMMENT:

If I may mention, that you proberbly need to take some time off to read CIS Help documentation to further familarise yourself with CIS environment and usage. I hope you find this helpfull..Stay possitive and good luck!

With Regards
Divine
 Wave

Logged
tormod
Comodo Loves me
****
Offline Offline

Posts: 113


« Reply #16 on: March 11, 2009, 06:32:12 PM »

IMHO, the HIPS D+ needs to be highlighted as a new functionality that requires a "willing suspension of disbelief" while the (annoying) alerts are handled. Secondly, there needs to be something in the alert that says: "this isn't the Firewall, stupid - it's a whole new concept of HIPS," or words to that effect. <g> Just look at the comments about Comodo in the major download sites: it's clear that a lot of us missed that distinction and blamed the firewall.
Just a note regarding this: the alert pop-ups actually say "Defense+ Alert" or "Firewall Alert" in the title bar to let you know which component of CIS was triggered.
Logged
Carls2
Comodo Member
**
Offline Offline

Posts: 32


« Reply #17 on: March 12, 2009, 02:03:50 PM »

Just a note regarding this: the alert pop-ups actually say "Defense+ Alert" or "Firewall Alert" in the title bar to let you know which component of CIS was triggered.

Of course you're right - but you might have missed my point. Not to labor it, but I really think it's important. So let me try once more, please.

My experience, as a new user, was to be overwhelmed - confronted by a blizzard of warnings the first days of running Comodo. I didn't notices the difference - just the warning screens and the prompts to accept or not.

This reaction turns out to be not that uncommon (from reading reviews and user rants). So my message was meant to be helpful to Comodo. Hopefully the experiences of new users can be used to inform the design. Especially from those like myself who are new to HIPS. That there might be a significant difference between the firewall and Defense+ never occurred to me - and only because I really wanted to make this work did I stay for the show.<g>

IMHO, there really needs to be a bigger difference in the firewall and D+ warning screens. And along with that, there needs to be a distinction in expected user response. Just ticking "accept" time after time doesn't really accomplish any sense of security...

A new user trying Comodo for the first time needs bigger clues as to what's going on behind the scenes and how this security system is _really_ different from the firewall that has been the previous experience.

So thanks for your instructions - I think I'm past them now. Tho I still wonder from time to time how my initial uninformed "Accept" responses might still be compromising my system...
Logged
Little Mac
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 6254



« Reply #18 on: March 13, 2009, 09:02:41 PM »

Hey, Carls2,

If you did not check the box to "Remember"  your choice, no new rules are created.  The allowance is only on a per-instance basis (thus, the next time you ran the application, you'd get the same alert).

There are a couple ways to get rid of any unwanted rules (or just in case you're concerned you might have created some unwittingly).
1.  Go into D+ / Advanced / Computer Security Policy and delete rules for applications.  Then you'll be prompted again...
2.  Go to Miscellaneous / Manage my Configurations / Select.  You'll have 4 options, 1 will be active already.  If you take a different one, it will automatically reset all rules for both Firewall and D+.  By default it's set to Internet Security.  Proactive Security has higher-strength settings (and will thus get more popups).

HTH,

LM
Logged

You read my sig block.  That's enough personal interaction for one day. Kewl
Carls2
Comodo Member
**
Offline Offline

Posts: 32


« Reply #19 on: March 15, 2009, 09:50:17 PM »

Hey, Carls2,

If you did not check the box to "Remember"  your choice, no new rules are created.  The allowance is only on a per-instance basis (thus, the next time you ran the application, you'd get the same alert).

I was going to toss off a slightly snotty reply, since I thought meself pretty advanced... then I read the rest!

There are a couple ways to get rid of any unwanted rules (or just in case you're concerned you might have created some unwittingly).
1.  Go into D+ / Advanced / Computer Security Policy and delete rules for applications.  Then you'll be prompted again...

What a find! Easy to re-do those that seem debatable. This time I'll read before I "accept." Thanks.


2.  Go to Miscellaneous / Manage my Configurations / Select.  You'll have 4 options, 1 will be active already.  If you take a different one, it will automatically reset all rules for both Firewall and D+.  By default it's set to Internet Security.  Proactive Security has higher-strength settings (and will thus get more popups).

Now I'm really humble. And thankful I didn't toss off a superior-sounding reply. My "select" was set to antivirus upgrade. What does this imply? Anyway, it's now properly set to what ought to have been the default: internet security.

And more thanks!

Carls
Logged
Tags: installation mode  safe mode  svchost 
Pages: 1 [2] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.044 seconds with 18 queries.
Powered by SMF 1.1.10 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com