[merged topic]CIS feedback

To get information about what some settings are, in the settings you can click the question mark next to the normal “Minimize Window”, “Maximize Window” and “Close Window” The Question Mark will lead you to the help files which are indeed very helpful, but I do agree that more of that information should be available already in the GUI.

Let me try and help you by answering your questions.

To get the full 64 bit protection you need to check “enable enhanced protection mode” in the defense + settings this will have additional protection for 64 bit users. It gets enabled when you switch your configuration to proactive.

So earlier today i upgraded to version 6, my first thoughts:

i can tell the new design and default settings are meant to make it easier for stupid people to use your product, umm i mean ‘casuals’ this i understand as i see it right across the board regards other similar software and computers in general.

i can no longer submit a file to you guys for analysis unless it is already in quarantine? why is this?

You can submit files still, hit the tasks button on the main screen then click advanced tasks, there is a submit file option.

where is the network traffic monitor? did you remove it? if so why?

It was removed from CIS but its in killswitch which is integrated with CIS. just go to tasks-> advanced tasks → watch activity

Seems the sandbox features have been built on alot, this is something i never used as i have sandboxie installed and even it i dont use alot.

Documentation seems alot less unless you go online.

The basic settings seem very basic, you need to use the advanced settings to do pretty much anything.

what is “trustconnect” i cant see any documentation on this or alerts regarding it.

Trustconnect was used in the v5 series so its nothing new. CIS will detect when your connected to a unsecured network (not password protected) and it will display a popup asking if you want to use trustconnect. What trustconnect will do is encrypt your data so nobody can sniff or track your data when on the unsecured network. Trustconnect is a paid service however, you can disable it in the firewall settings if you prefer not to see these alerts.

Under firewall settings: "set alert freq. level" i have the 5 settings and no documentation telling me what each one is, luckily from version 5.10 i kinda remember this is related to general rules such as 'allow/block all outgoing' 'allow/block outgoing to this ip' 'allow/block outgoing to this ip and port' where is the documentation telling me exactly what these 5 settings do?

Here is what i found in the online help file about the alert frequency

Very High: The firewall shows separate alerts for outgoing and incoming connection requests for both TCP and UDP protocols on specific ports and for specific IP addresses, for an application. This setting provides the highest degree of visibility to inbound and outbound connection attempts but leads to a proliferation of firewall alerts. For example, using a browser to connect to your Internet home-page may generate as many as 5 separate alerts for an outgoing TCP connection alone.

High: The firewall shows separate alerts for outgoing and incoming connection requests for both TCP and UDP protocols on specific ports for an application.

Medium: The firewall shows alerts for outgoing and incoming connection requests for both TCP and UDP protocols for an application.

Low: The firewall shows alerts for outgoing and incoming connection requests for an application. This is the setting recommended by Comodo and is suitable for the majority of users.

Very Low: The firewall shows only one alert for an application.

On a related note i always found the popup windows the weakest point of Comodo compared to ESET smart security.. i should be able to decide if i want to allow/block all, specify a certain ip/port only etc from the popup like in ESET instead of having to go into the menu later.

CIS is still in the early stages and improvements will be made. i suggest you add this to the wishlist so you can get votes from the other members. if comodo sees a big demand for the wish they usually will add it.

Under the enable firewall setting, i understand training mode will allow all rules without user interaction but what is the difference between safe mode and custom ruleset? it should tell you this in the writing under the option when you change it.

safe mode will allow ‘safe’ applications, comodo has a few different ways of deeming a file safe (ie cloud whitelist, trusted vendors list etc) so only unknown programs will generate firewall alerts. with custom ruleset CIS only follows the rules under application rules and global rules. Anything that doesnt have a rule in the settings will create an alert. This allows the user much more security and flexibility at the cost of more alerts.

In general you should be able to right click on each option and select a "what is this?" to find out more info... eg. in the antivirus setttings, what is "enable cache builder" and in the enable HIPS there is 4 different modes, it should detail to you what each mode is when you change it in the writing underneath but it does not..

there is a small ‘?’ mark at the top right of most/all of the windows in CIS. when you click it, it will open the online help to the appropriate section to give more info (see my attached screenshot)

Thats my thoughts for now, i will post more in a few days when im more used to this version but so far i think its a mixed bag compared to version 5.10

I agree v6 is a totally different beast but once you learn your ways around it, its pretty powerful and has many useful features. I hope my answers make things easier for you in some way. If you have more questions dont be afraid to ask.

[attachment deleted by admin]

THanks guys, especially wasgij6, thats really helpful. I figured out a couple of the things i mentioned after posting but that covers everything.

I like killswitch, looks very detailed. i did have a similar programmed installed from a third party so i guess its not really needed now.

i will add to the wishlist later, that one little feature regarding better control over firewall creation rules from the popup would really help Comodo more than any other in my opinion.

Some of us have complained about the excessively complicated GUI, so here is what a security software should look like!

http://www.softpedia.com/progScreenshots/Baidu-Antivirus-Screenshot-231364.html

Now there’s a GUI I can live with! :slight_smile:

Of course Baidu is only an AV and behavior scanner (no FW or Sandbox) and is in beta. But you get the idea.

I would uninstall comodo if it displayed a combination of these sentences:
“Your computer is safe!”
“Weekly virus scans are recommended!”

:smiley:

I think not that we must discuss about this sentences ^^ - sure, its ■■■■■■■■! But the Gui is really nice and clear and easy to use.

Yea, the GUI is all I was talking about. Sorry I didn’t make that perfectly clear.

As for Baidu being rubbish, it’s where Comodo was a couple of years back.

Am i the only one that like the widget? it shows easy enough inbound and outbound connection activity, it showed when CIS is doing a task (such as updating or scanning), the number if unrecognized files CIS has, and if something is active in the sandbox. With the common task toolbar i can an do an action without opening the main GUI, i think people give to less credit to those features.

I really like the widget as well. I personally prefer it to the summary screen of V5, but apparently I’m in the minority.

I find the widget annoying so I have it turned off.

I like the widget too.Fits in just nicely with the desktop. ;D

Do not like CIS the widget, or any widget. I don’t like anything I have to squint to be able to see it. ;D

I like the widget. It gives you an instant “eye summary”. Unlike the Windows Widget, it is security proof (no hole). I’d use it for sure!!! In future editions… :slight_smile:

Loving the widget too!
For those who do not, include an on/off option during install.
Primary using it for visual download/upload, green secure, accessing Killswitch and resetting the sandbox, reviewing unknown/sandboxed processes and task overview!
70% of the time I am there on the widget!

As soon as I realized right clicking the tray icon brings the widget forward I started using it to access CIS 90% of the time.
I like it but would still like more detail/data on the GUI as well :slight_smile:

No, you are not in the minority at all, i support you! :wink: i want the widget in the summery screen too! But on the Desktop i dont like it, but i still use it sometimes.

Im sorry but what on earth do you mean by wanting the widget in the summary screen.???..

I mean the info´s of the widget. :wink: … the widget itself would be ugly in the summary screen :wink:

  • inbound/outbound traffic
  • how many applications running in sandbox
  • tasks running
  • unrecognized files pending analysis

… and the info´s of the old summary screen in V5

Yes ive got you now and i fully agree with you.excellent idea.question is…Will it ever happen. :slight_smile: