Re: Comodo Personal Firewall
- From: Volker Birk <bumens@xxxxxxxxxxx>
- Date: 5 Apr 2006 07:20:20 +0200
melih@xxxxxxxxxxxxxxx wrote:
Do you do this in kernel space? Because, if you're doing this withCome on Volker, lets leave somethings to imagination ;-) Just try our
hooks, it's very easy to crawl up the hook chain and kick out your
controlling hooks.
firewall and see :-)
Hm... if I have a look on to your software, then afterwards probably
nothing is left to the imagination ;-)
Yes, surely by now you know we know more than that :)How do you implement that then? Why not using the system of privilieges| If so, are you using ACLs for it?Not applicable in our architecture
and ACLs Windows' kernel is offering?
Are you aware of the security concepts of the Windows kernel?
Why don't you use then these concepts?
Some you control some you detect. I never said you can control code atBy design (and this is true for every classical operting system) you| Is your "Personal Firewall" enforcing the user not to work with adminThere are alwasy more than one way of solving the same problem, yes you
| rights?
can solve some of the problem by forcing the user to do things like not
work in admin mode, but we belive in providing security without forcing
user's into different experiences. Watch this space to see how we have
solved some of these issues in our next versions :-)
cannot control code which is running in ring 0 of the CPU. I cannot see
how you want to control such code. If a user has administrative rights,
she/he may start code in ring 0. And then you lose.
ring 0. Thats the whole point about what I am saying. Nothing about a
PC is secure (threat model of hacker has access to your pc)
But it is possible to control all other code. So why not enforcing a
user not to work as Administrator, if this is the only way to help with
security? Therefore your "nothing about a PC is secure" is wrong.
May I suggest, that you will enforce users not to work with privilegedwe will implement something interesting in the next version. not what
rights?
you are asking but i am sure you will like :)
Why not just using what the operating system is offering?
Yours,
VB.
--
At first there was the word. And the word was Content-type: text/plain
.
- Follow-Ups:
- Re: Comodo Personal Firewall
- From: melih
- Re: Comodo Personal Firewall
- References:
- Comodo Personal Firewall
- From: melih
- Re: Comodo Personal Firewall
- From: Volker Birk
- Re: Comodo Personal Firewall
- From: melih
- Re: Comodo Personal Firewall
- From: Volker Birk
- Re: Comodo Personal Firewall
- From: melih
- Re: Comodo Personal Firewall
- From: Volker Birk
- Re: Comodo Personal Firewall
- From: melih
- Re: Comodo Personal Firewall
- From: Volker Birk
- Re: Comodo Personal Firewall
- From: melih
- Re: Comodo Personal Firewall
- From: Volker Birk
- Re: Comodo Personal Firewall
- From: melih
- Comodo Personal Firewall
- Prev by Date: Re: Product Standard
- Next by Date: Re: Comodo Personal Firewall
- Previous by thread: Re: Comodo Personal Firewall
- Next by thread: Re: Comodo Personal Firewall
- Index(es):
Relevant Pages
|