I'm giving comodo a chance again

So a few years ago I totally stopped using all comodo/xcitium products because they kept causing bluescreens on my machines. Instead I used VoodooCyberlock and DefenderUI. But then more recently I heard about the microsoft GDID. I did some searching and found out that the GDID gets sent along with all the data MSDefender sends to microsoft

So since MSDefender sucks and almost always gets disabled by malware in real world malware infections anyway, I tried bitdefender free edition, but that ate a ton of my ram even when my systems were barely doing anything. Then I thought back to that test JITech did on youtube back in 2023 where he turned the cloud lookup off

See here’s the thing, comodo will allow a lot of PUPs and sometimes straight up malware if the cloud lookup is turned on, the antivirus will also become very lazy if the cloud lookup is on.

So I decided to try comodo again and so far it’s working okay. I downloaded the full database and every time I start doing my daily activities I do a lookup of all the vendor names listed as “trusted” just in case any on the list are labeled as “unrecognized” now, which many of them turn out to be and then I just let that run until I shut down at the end of my evenings

What I ask of the devs is just one thing that they should already be doing anyway…Hire some Q/A testers and penetration testers. I deferred my windows updates by as long as the group policy lets me, so please xcitium devs, make sure comodo won’t break anything when new updates for windows come out.

and be more attentive to people here on this forum or when people email you about issues they’re having, be sure to take any reports of whitelisted malware very seriously

also, one of the things I don’t like about the paid version of comodo is that I can’t use just comodo firewall, it makes me use the antivirus always. Right now I’m currently using comodo IS with the full database and no cloud, so hopefully that will help with detection like it used to. Oh that’s another thing the devs need to work on. Detection.

Comodo will protect your system very well…as long as the cloud is turned off, but even though the AV will detect way more stuff with the cloud turned off, it’s still not as good at detecting as avast/avg or bitdefender…actually now that avast/avg is owned by norton, it probably doesn’t do as well anymore

I’m torn again after the update. In a statement (after testing and evaluating the new version, the conclusion in response to a user’s inquiry was cynical: “My computer survived. It’s still alive”), on the Malwaretips forum, it’s time for comodo users to consider switching (for security reasons). There, the only result of the update after such a long time is a name change.

While Andy Ful, in particular, sees things differently. Yes, comodo doesn’t make it easy, at least not for me as a relative novice who still relies on my experience with comodo. But times change, and especially dangerous methods become more sophisticated.

A rather sober and neutral example (Page 1 #16 by Divine_Barakah):

Comodo was heavily promoted by some members here and they shared their config. I bet 99% of users who followed the hype knew nothing about the config nor how it worked. Comodo gave them a false sense of security and control.

The product is no longer actively maintained and this is catastrophic for a security solution. Other vendors are much more active, yet every once in a while we see headlines about discovered vulnerabilities. I just wonder how things are for Comodo.

I’m staying with Comodo (for security reasons).

hi,
After trying out various security software, firewalls, and the like, I had to make a choice. You see the same recommendations across many sites and forums—TinyWall, SimpleWall, Windows Firewall Control, etc. Sure, they exist and do their job, but consider a novice, a child, or anyone with no technical knowledge—or simply someone who eventually gets fed up with endless notifications. The point is, in the hands of a novice, these programs are a recipe for breaking Windows functionality. Even with lists covering the bare minimum for connectivity, everything else is left to guesswork; I doubt the fact that lsass.exe is requesting a connection means much to the average user. The result is often either allowing everything (creating a security risk) or blocking things (including vital Windows processes). It’s a vicious circle: you can stick with native Windows tools (Firewall, Defender, etc.), but when a firewall asks a question, what is a novice supposed to answer? They don’t necessarily know—or care—that it’s an incoming connection; they just want to use their computer, not spend their time deciding what should or shouldn’t connect. Alternatively, you could buy a paid suite that makes those decisions for you. Comodo has the advantage of being suitable for both novices and power users; configurations like “CruelSister’s” (and variations thereof) make it accessible to anyone, requiring little to no input from the user thanks to whitelisting and cloud-based checks, while a sandbox allows for automatic or manual isolation. It offers multiple layers of defense while keeping the computer easy to use, so you don’t have to spend your time acting as a network administrator. I tested a single piece of malware in a VM using ZoneAlarm with its antivirus component: the antivirus didn’t detect it—fair enough—but regarding the firewall (which their site claims will stop unknown malware), ZoneAlarm simply automatically allowed the malware through. There was no prompt, nothing—and naturally, we know what happens next. The point is that Comodo succeeds where others fail; you get a highly modular and effective suite without needing to be a computer expert. Despite a few bugs, I haven’t yet found a viable alternative that is just as simple to use once configured. For a child, you just apply the “Cruelsister” settings and silent mode, add a password for security, and then you can just forget about it.

Giving an average user a “yes/no” alert is just going to cause a malware infection. And because they’re stupid, they’ll blame the security app they didn’t know how to use for “missing” the malware

You can configure comodo to auto-block all of those alerts for unknown apps and known malware, which helps whenever my girlfriend needs to use my PC for something. I use a variation of cruelsister1’s way of doing it. but instead of sandboxing the unknown, I set the container to block the unknown and I make the EDR automatically block anything it would ever ask the user about

as for simple wall, you can password protect the UAC and then disable the option in simplewall for it to skip the UAC, then just leave the filters on and make sure CIS is in silent mode with it set to block all unknown files and a guest user won’t be able to mess up your computer

but most users won’t do that, they don’t even know what anything I just mentioned even is, they don’t know what windows is they don’t know what bitdefender is and will just call it “defender” even though there’s like 10 security products in the world with the word “defender” in them somewhere

it’s why I NEVER recommend comodo to anyone who’s not tech savvy., because they’ll ruin their computers if they use it.

for most people an alert from your antivirus that says “if you click allow on this alert your system will be ruined forever” and the average user will click “allow” without even looking at it or thinking about it

One issue that is inexcusable is that Xcitium has a long history of accidentally whitelisting PUPs and malware and why I tell everyone if they’re going to use comodo they NEED to turn the cloud lookup off and download the full malware database it goes back to when I was in highschool using comodo 3.X. when there was malware going around with verified signatures from Verisign

this is why comodo REALLY needs to hire some penetration testers and Q/A testers. Nothing is infallible, so you need to be constantly trying to poke holes in your apps to see if anything is wrong and then release an update to fix any issues that get discovered.

whether it be an issue that causes a bluescreen or an issue with malware that can get past CIS