CPF Sandbox: discussions

Seriously though, there were posts originally about CFP 3 with HIPS and Sandbox (I just don’t have the incentive to search them). I can understand why the latter feature won’t be implemented or considered until later because devs thought HIPS would be more important. One step at a time is better than to have everything and stumble

.

Can I have my whopper now?

Fix the search feature so I can do my power searches again, and I’ll have the incentive to look for it myself. Then I’ll mail you a Whopper (should only take a week or two to get there)…

LM

I thought I’d help you two out, seen as you’re too lazy to search… ;D

This is the start of the thread:
https://forums.comodo.com/index.php/topic,512.msg3105.html#msg3105

And this is Melih’s reply:
https://forums.comodo.com/index.php/topic,512.msg25575.html#msg25575

Mike

Well, I didn’t need the 2nd like, but thanks anyway, Mike. I just read down thru the posts until I got to it. Doesn’t take that much effort… unlike a forum search, lol.

I used to search here all the time to find relevant posts & stuff; now it just gives me bogus results and misses things it should have returned (for example, I searched the various FW boards earlier today for text “non-routable” and it gave me nothing I could use, in 36 pages of results. I finally found one of the posts I was looking for in my post history, and voila! “non-routable” was right there in the text.

So now I’m too lazy. :wink: I sure wish SB would fix it!

LM

Wow! I wouldn’t have reach those results even if I was motivated. I think the first is too far back lol. It was another annoucment from Melih sometime near the end of last year.

Something like this: https://forums.comodo.com/index.php/topic,159.msg35949.html#msg35949

Can’t seem to find it. Maybe those posts were just rumours or misconceptions by users afterall 88).

And LM, pestering me about fixing the search function isn’t going to make it happen sooner >:(

;D (CLY)

twl845’s thread?

And from there, looks like maybe this is what we’re looking for, as a start…

https://forums.comodo.com/index.php/topic,4883.msg39020.html#msg39020

LM

But the closest Melih posted about it is it’s on the drawing board. He never did officially and explicitly announced it, did he? It’s all been a dream…this conversation never happened. We were all hypnotized. :o

He is a space alien, after all…

And you wonder why I’m paranoid…

You never know who’s watching. You never know who’s waiting to erase history. You’ll never know if you’ve been erased from history. (:KWL) (:KWL) (:KWL)

;D LM

Well umm, cough cough, he said ermm, he said maybe, and that it was open to discussion, so i discussed…

Maybe a dream, but i see more advantages in a sandbox than a HIPS per se. I’m probably the only one…
To me it’s another firewall between the system and browser/P2P/Messenger/Skype… A complement to a firewall. HIPS is good, but but… :stuck_out_tongue: how do i answer a pop-up? I tried SSM and got fed up.
POP: “screwyou.exe is trying to inject adrenaline in Windows”; Allow? Deny? - Deny - BSOD/error- uninstall - error “safemon failed to initialize”- regclean - “safemon etc.” - regedit - AH sweet, it’s gone!

Oh, we should always allow adrenaline to be injected into Windows! Either that or :■■■■

LM

LM, stop posting about ■■■■.

Back on topic:
Based on Melih’s posts, the HIPS will be similar to Prevx because it’s whitelist-based. This means you won’t see many alerts. Ideally, the only alerts are malware. That or you’re running an obscure program not yet whitelisted.

We should also try not to post about HIPS since this is about (Sand) Boxing. (Now where’s my punching bag?)

Prevx1 is on my system, and will never leave as long as i’m in Windows. So, i should ask this:
Will Comodo have automated malware analysis with a central database, and so on?
Don’t take me the wrong way, i’m all for Comodo, but i never saw anything like Prevx1.

My status right now: i look at the systray, and Prevx1 is green, which means all is known and safe.
Priceless.

You can continue the PrevX and HIPS discussion here: https://forums.comodo.com/index.php/topic,6454.0.html

Ok, an update on my opinion: i’ll probably use the HIPS, because all things considered, all programs that are essential are probably in the safelist, so the pop-ups should be good.

I also realize that Comodo doesn’t need sandbox, not that bad. Comparing to HIPS, the advantage is no pop-ups, everything is redirected to a sandbox, and later deleted. I have SandboxIE for that. I can wait years until Comodo does this, because the HIPS should provide the same security, if not more. It’s more user-dependant, but more complete.

Using CPF3 and SandboxIE should be good, but Comodo providing all these features could very well be conflicting (or in my head they are…).

Maybe drop this, and concentrate on the FW+HIPS?

Which do you think is less cpu/performance intensive?

Don’t know. SandboxIE sure is light.
Once the HIPS and Firewall are mature and working perfect, a sandbox would be nice still. Everything could be run inside, with no pop-ups, and isolated from the system- rights restricted. The HIPS taking care of every left over (buffer overflows etc.) and control processes, dll’s and all that.
But one thing at a time.

One thing: maybe i’ll just use CPF3 in future. In Windows that is :slight_smile:

Off-Topic: I wonder if it’s because of BOClean’s influence that is now attracting people who have previously neglected or were doubtful of Comodo…

To add in something to be On-Topic: So sandbox is more first-lined defensive because malware is at the browser level. E.g. if a browser is sandboxed and someone downloads a virus file, but this interacts at the browser level first and then HIPS afterwards?

Off-topic: i’m not even talking about BOClean or CAVS. This is me maturing my ideas. (there’s another reason for another day, or pm’s).
But yes, once BOClean is available, i’ll install it right there ;D

On-topic: Everything from browser is redirected to the sandbox (in case of virtualization sandbox, the one i prefer). Everything in the sandbox has restricted rights, which is primarily the intent of the sandbox.
A virus, for instance, cannot do anything, unless to other files inside the sandbox. It can read from the system (depending on what program, read all, read except some parts defined by you etc.). But everything it writes, is to a fake registry, fake file system, etc.
When you want, you delete the sandbox, and everything is gone. Before that, you can save what you want from the sandbox (if you feel it’s all right).