Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
May 25, 2013, 06:20:42 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
664041
Posts
70630
Topics
145257
Members
Latest Member:
nltdbsss
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Security Products & Services
Comodo Dragon - CD
News / Announcements / Feedback - CD
Browserscope security test - Chrome beats CD
« previous
next »
Pages:
[
1
]
2
Author
Topic: Browserscope security test - Chrome beats CD (Read 7929 times)
n01paranoid
Comodo Family Member
Offline
Posts: 51
Browserscope security test - Chrome beats CD
«
on:
February 21, 2012, 03:20:55 PM »
I've just run the Browserscope security test and Google Chrome scored 16/17 and CD 15/17. They both failed the toStaticHTML test, but CD also failed the Strict Transport Security test but Chrome passed. Can either of these be rectified in CD?
Logged
Sal Amander
Comodo Staff
Comodo's Hero
Offline
Posts: 607
Re: Browserscope security test - Chrome beats CD
«
Reply #1 on:
February 21, 2012, 04:41:59 PM »
Quote from: n01paranoid on February 21, 2012, 03:20:55 PM
I've just run the Browserscope security test and Google Chrome scored 16/17 and CD 15/17. They both failed the toStaticHTML test, but CD also failed the Strict Transport Security test but Chrome passed. Can either of these be rectified in CD?
Dragon doesn't ship with a pre-loaded list for Strict Transport like Chrome does, but you're more than welcome to add them yourself via: dragon://net-internals/#hsts (This is only for power/adv. users)
Since Chrome doesn't even support 'toStaticHTML', chances are Dragon will have it when Chromium/Chrome does.
Logged
brightness
Comodo Loves me
Offline
Posts: 153
Re: Browserscope security test - Chrome beats CD
«
Reply #2 on:
February 23, 2012, 01:04:02 AM »
Quote from: Sal Amander on February 21, 2012, 04:41:59 PM
Dragon doesn't ship with a pre-loaded list for Strict Transport like Chrome does, but you're more than welcome to add them yourself via: dragon://net-internals/#hsts (This is only for power/adv. users)
Since Chrome doesn't even support 'toStaticHTML', chances are Dragon will have it when Chromium/Chrome does.
How about preloading Strict Transport list into CD?
Logged
n01paranoid
Comodo Family Member
Offline
Posts: 51
Re: Browserscope security test - Chrome beats CD
«
Reply #3 on:
February 25, 2012, 01:24:57 PM »
Quote from: Sal Amander on February 21, 2012, 04:41:59 PM
Dragon doesn't ship with a pre-loaded list for Strict Transport like Chrome does, but you're more than welcome to add them yourself via: dragon://net-internals/#hsts (This is only for power/adv. users)
Could someone explain how to in non power user terms so I can do it myself?. Thanks
Logged
Chiron
Global Moderator
Comodo's Hero
Offline
Posts: 5588
Re: Browserscope security test - Chrome beats CD
«
Reply #4 on:
February 26, 2012, 01:29:09 AM »
Quote from: Sal Amander on February 21, 2012, 04:41:59 PM
Dragon doesn't ship with a pre-loaded list for Strict Transport like Chrome does, but you're more than welcome to add them yourself via: dragon://net-internals/#hsts (This is only for power/adv. users)
I'm wondering then, why doesn't CD include these by default when Chrome does? What is the downside of including this?
Thanks.
Logged
How To Install Comodo Firewall
How To Stay Safe While Online
Radaghast
Star Group
Comodo's Hero
Offline
Posts: 4040
Re: Browserscope security test - Chrome beats CD
«
Reply #5 on:
February 26, 2012, 02:29:26 AM »
The pre-loaded list of sites in chrome can be found
here
The link at the bottom of that page takes you to the ongoing code review for additional sites.
To manage HSTS sites in Dragon, open:
about:net-internals then select HSTS
You can check if a site is pre-loaded by using the Query domain option and you can add sites by using the Add domain. Be careful selecting the 'include sub-domains' option. Also remember, for HSTS to work, the web site has to have a HSTS policy enabled.
Logged
“Don’t worry if it doesn’t work right. If everything did, you’d be out of a job.”
n01paranoid
Comodo Family Member
Offline
Posts: 51
Re: Browserscope security test - Chrome beats CD
«
Reply #6 on:
February 26, 2012, 04:54:24 AM »
1) I've entered all the sites on the preloaded Chrome HSTS list but Dragon still fails the Browserscope Strict Transport Security test.
2) I have the add on Use HTTPS enabled. Does this not perform a similar function as HSTS and, if so, why does CD still fail the test?
Logged
Sal Amander
Comodo Staff
Comodo's Hero
Offline
Posts: 607
Re: Browserscope security test - Chrome beats CD
«
Reply #7 on:
February 26, 2012, 07:51:04 PM »
Quote from: n01paranoid on February 26, 2012, 04:54:24 AM
2) I have the add on Use HTTPS enabled. Does this not perform a similar function as HSTS and, if so, why does CD still fail the test?
CD fails most likely due to a bug within whomever created the test. You may want to inquire with them for resolution.
Logged
Radaghast
Star Group
Comodo's Hero
Offline
Posts: 4040
Re: Browserscope security test - Chrome beats CD
«
Reply #8 on:
February 26, 2012, 08:28:58 PM »
Quote from: Sal Amander on February 26, 2012, 07:51:04 PM
CD fails most likely due to a bug within whomever created the test. You may want to inquire with them for resolution.
That's a bit thin Sal, every other Chrome clone passes the test, even Rockmelt. Dragon is the only clone to fail.
gc.jpg
(76.4 KB, 637x267 - viewed 14 times.)
cp.jpg
(83.4 KB, 604x275 - viewed 13 times.)
si.jpg
(72.67 KB, 635x254 - viewed 13 times.)
rm.jpg
(74.55 KB, 560x251 - viewed 12 times.)
cd.jpg
(75.76 KB, 539x271 - viewed 13 times.)
Logged
“Don’t worry if it doesn’t work right. If everything did, you’d be out of a job.”
Sal Amander
Comodo Staff
Comodo's Hero
Offline
Posts: 607
Re: Browserscope security test - Chrome beats CD
«
Reply #9 on:
February 26, 2012, 10:59:42 PM »
Quote from: Radaghast on February 26, 2012, 08:28:58 PM
That's a bit thin Sal, every other Chrome clone passes the test, even Rockmelt. Dragon is the only clone to fail.
I'm sorry what is your point? Bugs exist in all software. According to everything I have seen and tested this appears to be a bug within BrowserScope and not Dragon. Other than this 'test' do you have any formidable proof that Dragon has a problem?
Logged
Radaghast
Star Group
Comodo's Hero
Offline
Posts: 4040
Re: Browserscope security test - Chrome beats CD
«
Reply #10 on:
February 26, 2012, 11:21:20 PM »
Quote from: Sal Amander on February 26, 2012, 10:59:42 PM
I'm sorry what is your point? Bugs exist in all software. According to everything I have seen and tested this appears to be a bug within BrowserScope and not Dragon. Other than this 'test' do you have any formidable proof that Dragon has a problem?
Ok! The fact that all the other clones pass and Dragon doesn't, obviously points to a bug in their software. Perhaps i should also point out that firefox and Opera 12 also pass the test, but you'll probably dismiss that too.
Logged
“Don’t worry if it doesn’t work right. If everything did, you’d be out of a job.”
Sal Amander
Comodo Staff
Comodo's Hero
Offline
Posts: 607
Re: Browserscope security test - Chrome beats CD
«
Reply #11 on:
February 27, 2012, 12:23:31 AM »
Quote from: Radaghast on February 26, 2012, 11:21:20 PM
Ok! The fact that all the other clones pass and Dragon doesn't, obviously points to a bug in their software. Perhaps i should also point out that firefox and Opera 12 also pass the test, but you'll probably dismiss that too.
Honestly that's not enough to go on as it isn't solid enough. (Clones pass but one such clone [ Dragon ] doesn't.) You have NO concrete proof other than this 'test' to back up your claim. Have you performed your own tests based on W3C spec or anything else?
The test that browserscope uses in its test is:
https://www.pwdhash.com/browserscope/set-sts.php
, which has a header of 'Strict-Transport-Security: max-age=5' set for that page.
This is an independent 3rd party who has created the test. It is wise that one raise issues with the test with those who created it (BrowserScope). If indeed it is Dragon that is the problem then those at 'BrowserScope' would be the ones to contact us.
Logged
Radaghast
Star Group
Comodo's Hero
Offline
Posts: 4040
Re: Browserscope security test - Chrome beats CD
«
Reply #12 on:
February 27, 2012, 12:51:11 AM »
Quote from: Sal Amander on February 27, 2012, 12:23:31 AM
Honestly that's not enough to go on as it isn't solid enough. (Clones pass but one such clone [ Dragon ] doesn't.) You have NO concrete proof other than this 'test' to back up your claim. Have you performed your own tests based on W3C spec or anything else?
I'm not "claiming" anything, nor is it my place to perform additional tests, to either prove or disprove, the validity of the test that Dragon fails. I'm merely pointing out that every other browser, currently supporting Strict Transport security, passes.
Quote
The test that browserscope uses in its test is:
https://www.pwdhash.com/browserscope/set-sts.php
, which has a header of 'Strict-Transport-Security: max-age=5' set for that page.
Which clearly is irrelevant for every other browser passing the test.
Quote
This is an independent 3rd party who has created the test. It is wise that one raise issues with the test with those who created it (BrowserScope). If indeed it is Dragon that is the problem then those at 'BrowserScope' would be the ones to contact us.
I guess 'passing the buck' is one approach
Logged
“Don’t worry if it doesn’t work right. If everything did, you’d be out of a job.”
dicks
Comodo Member
Offline
Posts: 26
Re: Browserscope security test - Chrome beats CD
«
Reply #13 on:
February 27, 2012, 03:05:48 AM »
I'm really shocked to read this thread and the way Comodo reacts to it. This is definitely the WRONG attitude guys.
Take ownership and show that you care instead of sending users away with a "it is not our fault" reply. Clearly something is not right (if the test results are as quoted).
Very very weak Comodo, you can't do better than this?
Logged
Sal Amander
Comodo Staff
Comodo's Hero
Offline
Posts: 607
Re: Browserscope security test - Chrome beats CD
«
Reply #14 on:
February 27, 2012, 08:11:09 AM »
Quote from: dicks on February 27, 2012, 03:05:48 AM
I'm really shocked to read this thread and the way Comodo reacts to it. This is definitely the WRONG attitude guys.
Just because I work for Comodo, doesn't make me Comodo.
Quote from: dicks on February 27, 2012, 03:05:48 AM
Take ownership and show that you care instead of sending users away with a "it is not our fault" reply. Clearly something is not right (if the test results are as quoted).
Very very weak Comodo, you can't do better than this?
How do you know that 'BrowserScope' isn't the one flawed here? They're the ones that created the test, not Comodo. They have their own bug reporting system for a reason. If their system is broken, they need to know about it!
See this 'Issue' reported to the Chromium Devs for
BrowserScope
.
Logged
Tags:
Pages:
[
1
]
2
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Reports - CIS
===> AV False Positive/Negative Detection Reporting
=> Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
===> News / Announcements / Feedback - CCE
=====> Wishlist - CCE
===> Help - CCE
===> Bug Reports - CCE
=> Comodo Antivirus for Mac OS X - CAVM
=> Comodo Antivirus for Linux - CAVL
=> Comodo Mobile Security - CMS
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> COMODO IceDragon - CID
===> News / Announcements / Feedback – CID
=====> Wishlist - CID
===> Help – CID
===> Bug Reports - CID
===> Beta Corner – CID
=> Comodo LoginPRO
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
=> Comodo Secure DNS - DNS
===> News / Announcements / Feedback - DNS
===> Help - DNS
=> Comodo Unite (EasyVPN) - CUnite
===> News / Announcements / Feedback - CUnite
===> Help - CUnite
=====> FAQ - CUnite
===> Bug reports - CUnite
=> Comodo TrustConnect - CTC
=> Comodo SiteInspector - CSI
=> Comodo Valkyrie - FLS
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Rescue Disk - CRD
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Utilities - CSU
===> News / Announcements / Feedback - CSU
===> Help - CSU
=====> FAQ - CSU
===> Wishlist - CSU
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Cloud
===> Help - CB
=====> FAQ - CB
===> Wishlist - CB
=> Comodo Programs Manager - CPM
===> News / Announcements / Feedback – CPM
===> Help - CPM
===> Wishlist - CPM
=> GeekBuddy & Live PC Support
=> GeekBuddy PC Health Check - PCHC
===> News/ Announcements / Feedback – PCHC
===> Help - PCHC
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
===> Endpoint Security Manager 1.6
===> Endpoint Security Manager 2.0 Business Edition
===> Endpoint Security Manager 2.1
===> Endpoint Security Manager 3.0
=====> CESM 3.0 Beta
===> ESM Console for Windows Phone
===> Earlier versions of CESM
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
=> Comodo Network Center - CNC
=> Comodo AntiSpam Gateway - Hosted Anti Spam Service
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
=====> News & FAQ
=====> Оффтоп (OFFTOP)
=====> Архив / Archive
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
===> Estonian
===> Arabic
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Web Application Firewall - CWAF
===> Comodo HopSurf - CHS
===> Comodo AntiSpam - CAS
=====> Help - CAS
=======> FAQ - CAS
=====> News / Announcements / Feedback - CAS
=======> Wishlist - CAS
=====> Bug Reports - CAS
===> Verification Engine - CVE
===> Comodo Secure Email - CSE
=====> News / Announcements / Feedback - CSE
=====> Help - CSE
=======> FAQ - CSE
=====> Bug Reports - CSE
===> Comodo Cloud Scanner - CCS
=====> News / Announcements / Feedback - CCS
=====> FAQ - CCS
=====> Beta Corner - CCS
=====> Wishlist - CCS
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
=====> CAVS BETA Corner
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> CFP BETA Corner
=======> 32 bit bug reports
=======> 64 bit bug reports
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
=> Comodo Wiki Project
Page created in 0.054 seconds with 22 queries.
Powered by SMF 1.1.18
|
SMF © 2006, Simple Machines
Design by
7dana.com