The Comodogate problem stinks, and not just for the  reasons you already know. InfoWorld Tech Watch. (Update: this article has just been Slashdotted.
[See the full post at: Dear Comodo: You gave WHAT to WHOM?]
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
Dear Comodo: You gave WHAT to WHOM?
Home » Forums » Newsletter and Homepage topics » Dear Comodo: You gave WHAT to WHOM?
- This topic has 5 replies, 3 voices, and was last updated 14 years, 2 months ago.
AuthorTopicViewing 4 reply threadsAuthorReplies-
ado
GuestMarch 25, 2011 at 11:17 am #57082Woody,
“take over DNS infrastructure” – well, if you are government, I’d say you can do it for your country, right? And that’s the point – easily to spy on your own people. Why to bother to ask google to hand over mails of someone? That person will give you full access as soon as he’ll login. Pretty scary. -
woody
Manager -
EP
AskWoody_MVP -
rc primak
GuestMarch 26, 2011 at 12:16 am #57085First, let me point out that none of this controversy over Certificates is about the security or reliability of Comodo’s Internet Security or Firewall products. Entirely different stuff, and a different division of the company.
Comodo has been doing secure DNS services for a few years now, and I think they got their hands on Certificate issuing by buying another company which was an established Certificates Registrar before Comodo acquired them. I could be wrong about this.
Rightly or wrongly, I do trust the Comodo Firewall, and Defense Plus, at least on my Windows XP laptop. I also do use the included Comodo DNS Service on my Windows XP laptop, and I have been saved from more than a few rogue sites and drive-by downloads when Comodo DNS either blocked sites, or warned that “something is not right here” (invalid certificates, etc.). So the basic Comodo security infrastructure seems to me to be working very well.
What is lacking is adequate controls over who issues Security Certificates, and to whom. There seems to be no International Standards Bureau, or whatever, to regulate and enforce the process. And revoking Certificates via browser version updates and security patches? Give me a break!! (BTW, when the MS-IE patch does come out, will we get to apply it without applying the other outstanding March MS Updates?)
My point about the process is that it is not Comodo’s fault, and I slightly resent Comodo being singled out for criticism. Hasn’t this sort of thing happened to Thawt, or other issuers of Certificates (and did they fail to notify anyone)? Is Comodo uniquely negligent, or is it the entire process which should be criticized and changed? And finally, does anyone have a better, concrete idea of how to manage the myriads of Certificate requests which are made in the average year? There’s a LOT of “secure” web sites out there! And a lot of Certificate issuers. Too many issuers.
If Microsoft’s own Certificates ever became compromised, would we ever be told? I doubt it!
So now that I know all of this, how do I determine that I really am at my bank’s secure log-in page? And that this page is actually really secure?
-
woody
ManagerMarch 29, 2011 at 1:48 pm #57086@RC –
Absolutely true, this has nothing to do with Comodo products. It’s a major screw-up with Comodo’s control over the issuance of SSL certs.
On the other hand, I disagree about this being Comodo’s fault. They’re being trusted to provide a service – an expensive service – and in this particular case they failed miserably. The process is flawed, yes. But Comodo has been uniquely remiss in this case.
IF MS’s certs were compromised, we probably would find out about it because the certs would have to be withdrawn with all of the major browser manufacturers – and somebody would, no doubt, spill the beans.
Viewing 4 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Windows Spotlight broken on Enterprise and Pro for Workstations?
by
steeviebops
5 hours, 5 minutes ago -
Denmark wants to dump Microsoft for Linux + LibreOffice
by
Alex5723
6 hours, 32 minutes ago -
How to get Microsoft Defender to honor Group Policy Setting
by
Ralph
5 hours, 41 minutes ago -
Apple : Paragon’s iOS Mercenary Spyware Finds Journalists Target
by
Alex5723
15 hours, 50 minutes ago -
Music : The Rose Room – It’s Been A Long, Long Time album
by
Alex5723
16 hours, 56 minutes ago -
Disengage Bitlocker
by
CWBillow
6 hours, 54 minutes ago -
Mac Mini M2 Service Program for No Power Issue
by
Alex5723
18 hours, 55 minutes ago -
New Win 11 Pro Geekom Setup questions
by
Deo
3 hours, 36 minutes ago -
Windows 11 Insider Preview build 26200.5651 released to DEV
by
joep517
1 day, 2 hours ago -
Windows 11 Insider Preview build 26120.4441 (24H2) released to BETA
by
joep517
1 day, 2 hours ago -
iOS 26,, MacOS 26 : Create your own AI chatbot
by
Alex5723
1 day, 6 hours ago -
New PC transfer program recommendations?
by
DaveBoston
1 hour, 29 minutes ago -
Windows 11 Insider Preview Build 22631.5545 (23H2) released to Release Preview
by
joep517
1 day, 10 hours ago -
Windows 10 Build 19045.6029 (22H2) to Release Preview Channel
by
joep517
1 day, 10 hours ago -
Best tools for upgrading a Windows 10 to an 11
by
Susan Bradley
22 hours, 32 minutes ago -
The end of Windows 10 is approaching, consider Linux and LibreOffice
by
Alex5723
2 hours, 35 minutes ago -
Extended Windows Built-in Disk Cleanup Utility
by
bbearren
11 hours, 29 minutes ago -
Win 11 24H2 June 2025 Update breaks WIFI
by
dportenlanger
2 days, 5 hours ago -
Update from WinPro 10 v. 1511 on T460p?
by
CatoRenasci
1 day, 3 hours ago -
System Restore and Updates Paused
by
veteran
2 days, 7 hours ago -
Windows 10/11 clock app
by
Kathy Stevens
1 day, 18 hours ago -
Turn off right-click draw
by
Charles Billow
2 days, 10 hours ago -
Introducing ChromeOS M137 to The Stable Channel
by
Alex5723
2 days, 14 hours ago -
Brian Wilson (The Beach Boys) R.I.P
by
Alex5723
1 day, 8 hours ago -
Master patch listing for June 10, 2025
by
Susan Bradley
2 days, 16 hours ago -
Suggestions for New All in One Printer and a Photo Printer Windows 10
by
Win7and10
1 day, 18 hours ago -
Purchasing New Printer. Uninstall old Printer Software First?
by
Win7and10
2 days, 22 hours ago -
KB5060842 Issue (Minor)
by
AC641
1 day, 10 hours ago -
EchoLeak : Zero Click M365 Copilot leak sensitive information
by
Alex5723
3 days, 5 hours ago -
24H2 may not be offered June updates
by
Susan Bradley
1 day, 21 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.