Advice Request Question regarding Trusted Vendors List (TVL)

Please provide comments and solutions that are helpful to the author of this topic.

Status
Not open for further replies.

Ryushi

New Member
Thread author
Mar 6, 2016
4
Hey guys,
I would like to clear the trusted vendors list, would it have any conflict with my system stability?
 
Last edited:
  • Like
Reactions: Der.Reisende

Online_Sword

Level 12
Verified
Honorary Member
Top Poster
Well-known
Mar 23, 2015
555
Theoretically, I think it would be fine if you enable Cloud Lookup and "Trust files installed by trusted installers".

However, "theory" can be different from "practice". So, I think reserving Microsoft and vendors of the drivers in your TVL could be a good practice.

Please note that, when the Cloud Lookup is enabled and you execute a signed file that is recognized as "Trusted" by Comodo Cloud, then the digital sign will be automatically added to TVL. :)
 
H

hjlbx

The method you use might cause CIS to treat some files as Unrecognized.

In that case, all you have to do is change rating from Unrecognized to Trusted.
 
  • Like
Reactions: Der.Reisende
H

hjlbx

Thank you, I just checked CIS file list and you are right, it did gave a few files an unrecognized rating, assuming I don't install new software each day and I change the file rating to trusted, can it conflict with anything on my system and cause any issue? and does CIS update still restore all the TVL back to default?

If there is any Unrecognized file that is executed, CIS will treat it according to your settings. At default, it will auto-sandbox. It has happened to me rarely, and never caused an issue on Intel systems. On AMD systems it caused problems with graphics drivers.

All you have to do is change the file rating from Unrecognized to Trusted. This should fix almost all problems.

As files are loaded into memory, CIS will perform a cloud query and rebuild the local TVL - specific to what is on your system. This is the recommended practice as it eliminates all unneeded vendors from the list. It is the most secure method.

COMODO updates do not restore the TVL.
 
  • Like
Reactions: Der.Reisende
D

Deleted member 2913

Are Local & Cloud TVL different? I know Cloud TVL is like full TVL or huge TVL.

I mean whatever Vendors are in Local TVL, are not in Cloud TVL?
 
  • Like
Reactions: Der.Reisende
H

hjlbx

  • CIS scans files on your system and obtains digital certificate infos.
  • Then it compares those signatures to all the signatures in the TVL.
  • If there is a match between the local and cloud digital certificates, then CIS will treat as Trusted and add vendor to local TVL.

So, in a nutshell, whatever is on local TVL is in cloud TVL - UNLESS you manually add a vendor to the local TVL that is not in the cloud TVL.

User can manually add vendors to their local TVL and this will not be added to the cloud TVL. One must submit a digitally signed file to COMODO for the vendor to be added to the TVL. The vendor is not added to the cloud TVL until the file(s) are manually analyzed by a COMODO technician. It is done this way for maximum possible security.

The huge local TVL when you first install CIS is for convenience.
 
D

Deleted member 2913

So if whatever is on local TVL is on cloud TVL, then whats the benefit of removing vendors from local TVL?

I mean suppose you are removing vendors that you think shouldn't be there for some reasons but if the cloud TVL has all the local TVL vendors too then wont the product from those vendors still be trusted with cloud checkup?
 
  • Like
Reactions: Der.Reisende
H

hjlbx

So if whatever is on local TVL is on cloud TVL, then whats the benefit of removing vendors from local TVL?

I mean suppose you are removing vendors that you think shouldn't be there for some reasons but if the cloud TVL has all the local TVL vendors too then wont the product from those vendors still be trusted with cloud checkup?

Of course. They will be trusted with cloud checkup.

You remove vendors on local TVL because you intend to never install applications from those vendors.

CIS will check the local TVL 1st, then the cloud TVL 2nd. CIS also detects installers and compares digital signature to cloud. The CIS algorithm to detect installers doesn't always recognize installers - so sometimes they are not treated as trusted even if they are in cloud TVL.

At least that is my understanding and the way it has always worked on my system.
 
Last edited by a moderator:
D

Deleted member 2913

You remove vendors on local TVL because you intend to never install applications from those vendors. If any files from the removed vendors are introduced to your system, then HIPS will generate "Digitally signed, but not on TVL" alerts. Of course, you have to have HIPS enabled for the HIPS alerts to appear.

Also, file will be auto-sandboxed since CIS will treat the file (even if digitally signed - because you removed the vendor from local TVL) as Unrecognized.
Why the file will be autosandboxed for the removed vendors?
Wont the file be checked with cloud on run & vendor be found on cloud TVL?
 
  • Like
Reactions: Der.Reisende
H

hjlbx

I personally think customizing the local TVL is a waste of time since there is no clear infos on how it works under all circumstances.
 
  • Like
Reactions: Der.Reisende
D

Deleted member 2913

Not always.

I have asked about why this is the case and received no technical infos.
Not always, do you mean sometimes file is correctly trusted as found in cloud TVL? I say correctly trusted coz this is the way it should work if cloud has full TVL i.e local TVL too, right?
 
  • Like
Reactions: Der.Reisende
H

hjlbx

Not always, do you mean sometimes file is correctly trusted as found in cloud TVL? I say correctly trusted coz this is the way it should work if cloud has full TVL i.e local TVL too, right?

Sometimes digitally signed files by a vendor in cloud TVL are not treated as Trusted and vendor is not added to local TVL.

It has been reported for a long while by now.

For example, some Windows files will not be treated as Trusted, even though digitally signed by Microsoft (even with Microsoft in local TVL).

There are various bugs that affect TVL.
 
  • Like
Reactions: Der.Reisende
D

Deleted member 2913

Sometimes digitally signed files by a vendor in cloud TVL are not treated as Trusted and vendor is not added to local TVL.

It has been reported for a long while by now.

For example, some Windows files will not be treated as Trusted, even though digitally signed by Microsoft (even with Microsoft in local TVL).

There are various bugs that affect TVL.
Ok, got it
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top