Serious Discussion Comodo Internet Security 2025 was obliterated by an exploit!

Vitali Ortzi

Level 24
Verified
Top Poster
Well-known
Dec 12, 2016
1,311
Comodo does not market CIS\CFW. Please do not provide a link to a URL because that is not marketing.


Because the software has $0 revenue and therefore nobody in their right mind would ever spend a lot on fixing issues. CIS\CFW is in perpetual maintenance or out-of-date. And that is fine because it generates $0 revenue. There are no dedicated Comodo staff to support, bug fix, or further develop it. Melih gets his programmers to look at it once every three or four years. This is fine.

It is freeware. You accept what Comodo gives you and if you cannot, Melih wants you to go use something else. He is so happy to see you go use something else. He does not want you using his product.
i replayed to to vitao comment about Xcitium EDR Client he bypassed and it is marketed with false claims to enterprises (comodo is the same base but less updated and has less rules etc) and regardless it is important that severe bypasses are fixed in security software free or paid
 
  • Like
Reactions: simmerskool

vitao

Level 1
Thread author
Mar 12, 2024
32
guys, please, dont fight. comodo is not fighting... they released a new 2025 edition fixing the certi issue and it only took 2 months... maybe another 2 years they fix the exploit/poc thing in cis and xcitium... lets have faith :)

btw, a new video showing every fcking options in cis 2025 is on the way. in fact its already at the channel but the video is long... 1h20min mor ou less... ill try to bring subs for it but maybe its not worth it as many will not watch it anyway...
 

bazang

Level 6
Jul 3, 2024
270
regardless it is important that severe bypasses are fixed in security software free
Nope. Not if there is $0 revenue supporting the product.

All free software - ALL PAID SOFTWARE - is offered "As Is." No developer has any obligation to fix bugs or patch its software. At least not a contractual obligation since every software EULA absolves the developer of any liability. The only instance where a developer is liable is if their software causes physical or bodily damage. Then that is no longer about the EULA, but gets into the realm of product negligence and liability.

Everybody that uses software - whether home user, enterprise, or government - does so at their own risk. If anybody uses security software and ends up infected, it is always 100% on them. That is an established rule of global law for security software as a product.
 

bazang

Level 6
Jul 3, 2024
270
guys, please, dont fight. comodo is not fighting... they released a new 2025 edition fixing the certi issue and it only took 2 months... maybe another 2 years they fix the exploit/poc thing in cis and xcitium... lets have faith :)
Melih will never fix it. There is no dedicated development staff for the Comodo code base. The developers at Comodo are shuffled around from project to project. That is how it has always been. For CIS\CFW a few developers are given a window of a few months to work on it. Because they are needed elsewhere - on projects that bring in revenue dollars. This makes perfect economic sense.

There for a while Melih hired China-based Haibo Zhang to be the Comodo Product\Project Manager, but he left years back and has never been replaced. Right about the time that CIS\CFW developed stopped 3 or 4 years ago.

For the price that Melih is charging for Xcitium, he will never have enough revenue to make the Comodo code-base any better than it is right now. A software product has to generate at least $1 MM USD for every 3 to 4 full-time personnel that support it (only 1 of those 3 or 4 people are software engineers). Comodo earns $0 and Xcitium might generate $500,000 per year. So you get 1.5 or 2 full-time people to support the product. Of those 1.5 or 2 people, you get 3/8ths to 1/2 of a developer. That translates to 1 developer working 780 to 1020 hours per year on a software code base. At Comodo companies, that developer has to do everything. Fix bugs. Develop new features. Unit test. Fix driver issues. Configure and maintain all of the supporting infrastructure. Create install packages. Perform all QA\QC. They have to do the entire supporting sysadmin of the infrastructure, software engineering, and the entire DevOps. Maybe in 10 years that developer can get around to fixing all the bugs and other problems, assuming that the underlying operating system remains essentially static over that same time period.

¯\_(ツ)_/¯
 
Last edited:
  • Like
Reactions: simmerskool

Andy Ful

From Hard_Configurator Tools
Verified
Honorary Member
Top Poster
Developer
Well-known
Dec 23, 2014
8,472
Killing Comodo with disabled LUA:
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top