Should Comodo users stop using Comodo?

Status
Not open for further replies.
@Halp2001,

Look at the above post.:)
I do not neglect the Comodo security flaws, but rather show that the proposed solution does not guarantee more security.
Another problem can be usability bugs, but this was skipped in your analogy.(y)

In my analogy, the bugs are not so important for Bob, as his way of using skis avoided the problems that happened for other users.
@andy, I just wanted to add a bit of humor with that little story. I truly value your opinion and your work, as well as the contributions from others here who have far more experience than I do in web security. You've all helped me tremendously on this forum (MalwareTips) to better understand and improve my limited knowledge on the subject.

I'm genuinely grateful to those who test security software and share their findings with the community, and also to those who offer well-reasoned opinions. But sometimes, you all dive into discussions that leave me a bit lost—especially when the language gets super technical for a humble mortal like me.
 
It is possible that my comments on the posts in this thread made by critics of Comodo might be misunderstood.
My comments mainly denied the validity of those posts due to breaking rule 2 in the OP. I noted a few times that those posts (with some exceptions) can be valuable in other threads about Comodo.

I would like to recall my opinion about Comodo.
The problem of bugs in the new CIS is open; however, there is no evidence for panic, especially for those who have used CIS 2025 for months/years.
There is no evidence that the users of CIS 2025 should skip it for another Home AV. The new solution will probably not be better for them.
I would not recommend Comodo to most (new) users, especially to average users. The exceptions are Home Administrators.
If a Comodo user wants to skip it, I can recommend the hybrid setup: Comodo Firewall + popular AV.
 
Last edited:
@andy, I just wanted to add a bit of humor with that little story. I truly value your opinion and your work, as well as the contributions from others here who have far more experience than I do in web security. You've all helped me tremendously on this forum (MalwareTips) to better understand and improve my limited knowledge on the subject.

I'm genuinely grateful to those who test security software and share their findings with the community, and also to those who offer well-reasoned opinions. But sometimes, you all dive into discussions that leave me a bit lost—especially when the language gets super technical for a humble mortal like me.
But I was give a minimal and supporting role!!! I am not happy! I should the the main character 😨
 
@Andy Ful

You see, Alice is that brilliant, charismatic piece of proprietary software with a few... let's call them "undocumented features." Her developers insist the gaping security holes are just "charming quirks." "That's not a vulnerability," they say with a dismissive wave, "it's a feature that adds character! You just need to use it correctly." Users who complain are just holding it wrong. Alice is perfect, you see, and any perceived flaws are simply a failure of your imagination.

Then there's Bob. Bob is the earnest, open-source project. He lives and breathes for user feedback. Every vulnerability report is a love letter, every pull request a sonnet. He patches, he updates, he evolves. He's a fortress of community-driven security, a testament to the power of listening to your users. He's everything Alice isn't.

And that's the punchline you've so cleverly stumbled upon.

We all thought they were opposites, two warring philosophies of development. But it was a long con. Alice's "vulnerabilities" were never flaws, they were encrypted love notes, backdoors left open only for Bob. And Bob, with his army of well-meaning users, wasn't just patching his own code. He was crowdsourcing the perfect key.

Every "user recommendation" he implemented was another piece of the puzzle, another step toward exploiting Alice's "charming quirks." He let us, the community, do the heavy lifting. We were the unpaid QA team for their hostile takeover of reality.

So when they finally merge, it won't be a simple connection. It will be the ultimate patch. Bob, using the very tools we gave him, will exploit Alice's "features" on a global scale. They won't just be a secure couple, they'll be a single, terrifyingly efficient entity. The beautiful, flawed, "it's-not-a-bug" framework merged with the impenetrable, user-hardened fortress.

They're not just getting together. They're releasing the final, stable version of our world. And we, the users, just gave them a 5-star rating on the way out.

Alice's backdoor left open only for Bob. I swear that sounds very wrong on any aspects lmao.
 
  • Like
Reactions: simmerskool
Sorry if I'm writing something else and even repeating myself. Of course, here are posts to read from users who are more knowledgeable about the subject matter, more technically, and can therefore argue more professionally. I haven't read through all of the posts yet, but I'll pick up on the example with the skiers, and this is the reality:
I've been driving a car brand for 13 years now, which I was actually very, very averse to based on my own family experience (repeated repairs, expensive). My partner has been driving this brand for a long time without any problems, as have friends and family. Compared to other models, this one was much more customer-friendly in terms of price. So I bought this brand: great driving experience, no significant repairs, customer-friendly workshop, etc. I've read a lot of negative things about this model. But I have experience with it and will even stick with this brand from now on.

The same goes for Comodo. I'll keep it short:
Laptops, PCs, almost all Windows versions, Comodo has always been tested as dangerous, experiences ranging from very good to crap.
As I already wrote: I'm a multiple person, so to speak, with x PCs, laptops, and Windows versions. At some point and somehow, in all the years I've used Comodo (Comodo almost since its inception), I should have realized that Comodo had let me down, had failed me. Nothing of the sort! I'm writing this because it's been pointed out here again that it's nonsense (not literally) to say I've never been hacked, etc. Some people don't even notice, so that's absolutely not true. With all the versions, the different devices, the diverse activities on the internet, in over 20 years of use of comodo there should have been some indication SOMETIME and SOMEHOW that my devices had been hacked.
Thanks to the truly neutral discussion being conducted here, I'm still staying with Comodo, even though I was only one step away from switching, especially through the discussion here.

That's an honest answer. I'm not getting anything from Melih, I'm not affiliated with Comodo, and of course I can't provide proof, it's impossible.

Comodo with HIPS with its own rules, now settings according to cruelsister's suggestion – have I just been lucky over these 20 years or more? Have I won a jackpot in a game of chance with millions every day? Nobody believes that.

Believe me, it's an honest statement. I don't want to harm anyone. I don't recommend Comodo to anyone. Just like I don't recommend my car brand to anyone.
 
Your criticism follows from "dark" period of Comodo management a few years ago (no new versions for a long time).
Another reason is the lack of clear information about removing bugs, even when some silent fixes were confirmed.
Only time can show if your high criticism is justified. After six months, there is no evidence for that (may be too short period).
People who use CIS 2025 are far less sceptical.
Your arguments would be much more convincing if you could use/test Comodo by yourself (as some others and I did).
You want me to check over 100 bugs and report each of them on Comodo forum and experience the same Comodo Staff feedback which I have been getting and reading for years on the Comodo forum saying no more than things like "We have send it to our team", "Thank you for reporting", "May I know your CIS version", "The team is working on it", blah, blah, blah, etc.
Never did I get or read anything like "We have fixed this issue could you please check updated CIS version if the issue has been fixed on your end too?". Those kind of phrases is unknown to Comodo Staff.

Which "dark" period? Has there ever been light in Comodo software department?
Nothing has changed from then till now. Oh wait, something did change over the past years, Comodo got rid of its Comodo Star Group on the Comodo forum which did CIS software usability testing. Why did Comodo get rid of this group? Simple, because Comodo doesn't care about CIS usability.
 

Attachments

  • Screenshot_20250929-160406_(1).png
    Screenshot_20250929-160406_(1).png
    1.3 MB · Views: 46
@Pico,

I refuted most of your posts, but you did lose your cool. :)
Your posts were noted, even if not compatible with rule 2.
Thanks for helping me find the bug lists related to CIS 2025.
I refuted your claim that Comodo had fixed 40 old bugs.
You seem to haven't found the List Of Bugs with the Comodo Staff FIXED labels on some bugs.
Apologies for "polluting" this court with information that nobody except a few wants to hear about.
Thanks for taking your time reading my posts and replying to them.
 
@AndyFul and others who know more than I do, based on what you have been analyzing and discussing about CIS, I have devised this configuration strategy to use only the Comodo Firewall component. In an environment where FUD (Fully Undetectable) malware is constantly evolving to evade modern security layers, a traditional defense is no longer sufficient. This guide presents a hybrid strategy that combines next-generation technologies with local containment and operating system hardening, based on tools developed by Andy Ful and configurations recommended by experts such as CruelSister and Vitao Tek.
I would like to know what the experts think about this, as your help is very valuable to me, and I thank you in advance. I hope I have not strayed from the topic of this thread, and if I have, it was not my intention, for which I apologize.

View attachment 291374

It seems to be kinda overkill. If you need some advice, please post on the WHHLight forum.(y)
 
Last edited:
It seems that on the English Comodo forum, it is hard to find information about bug fixing. However, it is possible on the Russian Comodo forum (search the webpage with "fixe" without "d" at the end):

v11.0.0.6744
v11.0.0.6778
v12.0.0.6810
v12.0.0.6818
v12.1.0.6914
v12.2.1.6950
v12.2.2.7062
v12.2.2.7098
v12.2.2.8012
12.2.2.8026
v12.3.1.8104
v12.3.2.8124
12.2.4.8032

Some other bugs were fixed with v12.3.4.8162
 
Last edited:
Status
Not open for further replies.