Suppose that most software should at some point come with a SBOM that includes all the components it requires and some sort of checksum on the file(s) so that a security solution could see that this software uses these 34 components, requires this in the OS, registry, this from the network, what ports in/out, etc.
Anything that it does beyond that needs to be flagged.
Obviously that will not be a 100% solution but at least then you’d have the vendor supplied information (until they get hit by another supply chain attack) of what the app is supposed to do - and more importantly the users can see from this file what the app does, who it will communicate with, etc.
So not as a replacement for the current, but as an added verification/checkpoint i’m thinking.
Cloudflare Warp works with CIS. I have used it in the past.
Cloudflare Warp is a DNS service to set in Windows and works with CIS. It is not a VPN driver and is not related to CIS only supporting a limited number of VPN drivers.
I installed CIS 2025 on the wife’s new laptop PC and then on mine. Sadly, still no support for Wintun. However, I’ve found that if I monkey with the settings in the VPN to “coax” the PC into using the Wi-Fi adapter instead of ethernet, it appears to work fine since the Comodo Firewall Driver shows up in the Wi-Fi adapter properties. Every once in a while it will switch to Tun>Ethernet and I just refresh the VPN connection to bring back Wi-Fi.
Answer to my own question - NO.
In v12.3.4.8162 issue with windivert is not resolved. There is no “Comodo Internet Security Firewall Driver” added to “Cloudflare WARP Interface Tunnel”. Once Cloudflare WARP is active Comodo Firewall becomes useless, every program can freely connect to internet, unless they are blocked by Windows Firewall rules.
I unfortunately had to move on from using Comodo after so many good years because the ‘COMODO Internet Security Firewall Driver’ doesn’t function with a TUN adapter, which are the most commonly used virtual adapters with VPN clients. And as previously mentioned, this incompatibility makes the Firewall completely useless and basically obsolete for many VPN users.
The following thread started Jun 2022 is about this and my post from earlier this year has a video demonstration to play showing how the incompatibility with a TUN adapter makes the Firewall completely defenseless.
Also my own OpenEDR fork for COMODO uses (abuse able by malware according to Kaspersky but there no good alternative.) WinDivert via my firewall project. I think integrating my one to his ones should not be hard.
CIS only supports TAP and IKEv2/IPSec protocols. It does not support any of the more modern ones like f.e. Tun and Wireguard . There have been many requests over the years to support more protocols until this far without success.
Like it or not, I’ll have to join you. This is truly the final straw for me. Thanks for this discovery. I would never have discovered it myself or paid attention to it. I’ll now cancel my subscription and replace CIS with other software.
Well, I’ve been using Comodo for a very, very long time. But I’m not going to pay for software that I can only use for 1/5 or even less. And above all, I trusted in their safety – so far successfully.
Should I upgrade?
I have an aging laptop (circa 2011) that is running Comodo Firewall 12.2.2.8012 with Cruel Sister’s config. I was hoping that the Dev’s would release an auto upgrage option within the software, but it never materialized. Am I missing out on any compatible protections in the latest version, or am I exposed to any vulnerabilities in the older version that would make upgrading necessary?
It wouldn’t be a bad thing to update. Just be sure to first save your current configuration!
After installing 8162, you can hit the Update button (even before the initial reboot) as a further update will appear.
Then reboot and once the app loads import the previously saved Configuration.