HiBit still works fine. It’s just any added Bells, Whistles, or enriched Uranium have been paused while Life proceeds.
When it does come back online (hope) it may be wise NOT to immediately update the application until the new version has been fully vetted (because One Never Knows, do One?).
I consulted with AI, who offered the following explanation:
Why is the Comodo driver only in the TAP adapter?
Comodo Internet Security (CIS) uses its own virtual network filter driver (often cmdguard.sys or similar - (it delves into the intricacies of a PC) that integrates into the network stack to inspect traffic.
Many third-party firewalls (including older Comodo versions) have difficulty seamlessly injecting their filter driver into the specific WireGuard adapter.
2. Is this a security issue?
No, quite the opposite. It’s actually a sign that WireGuard works more efficiently.
The scenario with TAP (where Comodo “sees”): If Comodo has the driver in the TAP adapter, it can theoretically inspect traffic before encryption. This is good for malware detection, but it also means that the traffic is briefly “unencrypted” in the adapter’s RAM before it goes to the VPN process.
The WireGuard scenario (where Comodo “doesn’t see”): WireGuard is extremely lightweight and encrypts traffic almost instantly at a low level within the kernel. If Comodo’s driver isn’t “built in” there, it doesn’t mean the traffic is insecure. It simply means that Comodo’s firewall is unable to inspect the encrypted WireGuard tunnel.
This is a good thing: If a firewall could inspect the encrypted tunnel, it would need the key or decrypt the traffic (man-in-the-middle attack), which would compromise privacy.
The reality: WireGuard encrypts traffic so deeply within the system that an external firewall (like Comodo) often can’t even “grasp” it without breaking the encryption. Therefore, Comodo’s “not seeing” anything there is evidence of the strength of WireGuard’s encryption, not of a leak.
Conclusion
TAP adapter: Comodo has access (filter driver installed).
WireGuard adapter: Comodo has no access (driver not installed/compatible).
…No security risk for you. Your connection is secure.
And once again, this uncertainty following by a hasty decision. .
OK, I have completed the upgrade. I decided to use the Windows uninstaller, as I’m not as brave as CS to use software from enriched uranium countries. A few observations:
My sandboxed browsers coundn’t reach the Internet, so I used Gemini to help me find the restrictions in HIPS, so I could remove them
I also used Gemini to help me ensure my config was fully locked down according to Cruel Sister’s settings. It did make me aware that my auto-containment list was configured incorrectly. I should have had the all applications run virtually rule at the top of the list; it was at the bottom, below the 3 block rules. So, that was good. However, Gemini’s knowledge of the GUI is terrible! It either makes things up or has no clue how the options have changed from version to version. Huge time waster.
For the last year or so, with version 12.2.2.8012, I had to reboot Windows before clearing the sandbox or I would get a BSOD. That issue seems to be resolved in the new version…Yay!!!
Also on 8012, when I would click the Update icon, the Check for websites database updates would fail. It’s nice to have it working again.
Overall, not too painful an experience (except for Gemini’s knowledge of the GUI). Thanks again to my CIS Sensei for all her fabulous contributions to this community!!!
I wholeheartedly agree, as do several others who also belong to this group.
I myself lack this knowledge and will henceforth only adhere to these guidelines before making such decisions. The complexity is quite a challenge. My last decision, which I didn’t actually implement, showed me how quickly one can make an unnecessary or even wrong decision. Even AI is better “informed” than one can be oneself. Not everyone can know everything.
I find it odd that in the AI’s answers it brings in WireGuard driver where there is neither mention in your summary nor in the questions. Therefor I can’t help but wonder whether you have provided us with all of the questions and conversation you had with AI preceding what you posted.
AI is using two security perspectives: malware detection and encryption and favors encryption as more important than malware detection. That is an arbitrary judgement based upon unknown considerations. In my view both are important and mandatory.
CIS Inspect filter driver IS running in the kernel as a fact; there is no IF.
It is totally conceivable that encrypted traffic is malicious traffic from a malicious application. Yes the transmission is secured by Wireguard encryption but the payload can still have malicious intent. AI does not disambiguate between the two types of security.
The metaphor is incorrect. Inspect driver runs in the kernel as does the Wireguard driver. Both have the same rights and access; there is nothing deeper than the kernel.
It is not evidence of the strength of WireGuard’s protection but it simply means Inspect driver is not able to inspect Wireguard driver. Inspect has not been keeping up with supported VPN protocols.
Again AI favors encryption as more secure where I will argue that both are important and mandatory. Because CIS is not able to filter WireGuard traffic CIS is not able to intercept traffic of a possible malware. Hence why you I do not use WireGuard in combination with CIS.
I have no idea what you are trying to say. Could you rephrase?
No, I didn’t; it would have been too extensive. But this was the most important point.
First of all, thank you very much for this detailed explanation. It’s not so easy to understand everything in its context and implications. A little basic knowledge isn’t enough anymore.
Therefore, I am now following this advice based on your competent knowledge:
I was referring to this statement:
Side note:
I've noticed that Google Translate sometimes doesn't translate correctly, which can lead to misunderstandings. For example, "in my" is incorrectly translated as "your." This has happened to me before. DeepL is more accurate, but not as lenient.
I've now had this passage translated a second time, and the translation is more accurate this time.
There isn’t a file. The videos on her YouTube channel demonstrate how to configure things through the GUI. Her videos are here. And, this is her latest config video.
for the system I use to make the videos I use AVG secure VPN. It gives the choice of WireGuard, Mimic, and Open VPN. I normally select WireGuard (like in this video) and have made no changes in the Firewall settings at all.
Although this video is restricted to a single malicious file that attempts to connect out, many of my previous Comodo videos use a wide range of malware connecting out in diverse ways, all of which present no issues to a default Firewall config.
Sorry to see you go. I was surprised to learn you had not picked up on the limited support for VPN protocols because you have been around for a long time. If memory serves me well I remember the first requests to support TUN adapter were made in 2016 which later would get followed by requests to also support WireGuard.
CruelSister, I just rewatched your Comodo Firewall 2025 Setup and Commentary video. Contrary to what Gemini told me, you didn’t move the All Applications Run Virtually rule to the top of the auto-containment list. Gemini told me that CF applies the rules in the order that they are listed, so putting it below the 3 default block rules would have meant the Run Virtually rule would never have been reached. Is this incorrect?
Also, you recommend unchecking the box Do not virtualize access to the specified files/folders. For those of us that run our browsers in the sandbox, what do you recommend we do if we want to download files from the Internet? Would it be any safer to choose a folder other than the Downloads folder?
Therefore, I am now following this advice based on your competent knowledge:
very good translation with deepl - google’s translation :
From now on, I will only follow advice based on expert knowledge. Anything else can be misleading and lead to dangerous attitudes. So, following your advice, I have now switched to OpenVPN (TCP) and and thus integrates the Comodo firewall driver.
I know I can get flustered very quickly when it comes to safety. I should actually choose Paranoid for HIPS, but that’s not recommended. Well, as I understand AI, this means that when a new driver “breaks” into the kernel, even if it comes from the firewall, the security that VPN provides is broken. Statement from AI:
2. Is this a security issue?
No, quite the opposite. It’s actually a sign that WireGuard works more efficiently.
a) The scenario with TAP (where Comodo “sees”): If Comodo has the driver in the TAP adapter, it can theoretically inspect traffic before encryption. This is good for malware detection, but it also means that the traffic is briefly “unencrypted” in the adapter’s RAM before it goes to the VPN process.
b) The WireGuard scenario (where Comodo “doesn’t see”): WireGuard is extremely lightweight and encrypts traffic almost instantly at a low level within the kernel. If Comodo’s driver isn’t “built in” there, it doesn’t mean the traffic is insecure. It simply means that Comodo’s firewall is unable to inspect the encrypted WireGuard tunnel.
Every driver runs at kernel level which means it has access to all OS resources and is capable of accessing and terminating all processes. This includes all processes (drivers) running in the kernel. F.e., once a malware runs in the kernel it is able to take down processes belonging to security programs. That is why when using a HIPS it will give the strongest of warning when installing a driver to make the user triple check the driver that is about to get installed is legit.
Comodo’s firewall driver Inspect runs in the kernel which means it also has full access to a VPN driver and will be able to intercept the traffic going through the VPN. We trust CIS, or other security program of choice, so by extension of that trust the fact that CIS is capable of intercepting the traffic of the VPN driver it is not a security risk.
Although CIS firewall can decide about the routing of encrypted packets (hold/allow/block inbound or outbound traffic), regardless of the transport mechanism used (VPN or other), it does not break encryption intercepting them for inspection of their actual contents, and that is a good thing. See here why: Exciting News: Comodo Internet Security 2024 Beta Now Open for Testing! - #465 by infosec
In addition to the extra safety layer that CIS HIPS can provide as @Citizen_K already wrote, CIS’ powerful containment system automatically prevents malware, even when it is signed, from running (for example trying to intercept traffic for decryption and exfiltration).