Windows security software. Rebuilt from scratch, in progress.
A measurement tool we are asking a small number of people to run. It looks at the software already installed on a PC and records what our detection engine would have said about each program, so we can find out where it gets things wrong on real computers rather than only on ours.
It does not block, quarantine or change anything, installs nothing, and leaves nothing running. It is not antivirus and provides no protection — anyone running it should keep using their existing security software. It sends one report, after asking, and writes a copy to the Desktop so you can read exactly what was sent.
Chrome will say “this file isn't commonly downloaded and it may be dangerous”, and then Windows will show a blue “Windows protected your PC” screen calling it an unrecognised app. Both are worth understanding rather than clicking past.
The Windows one gives you the best check available. Click More info on that blue screen and it will show:
That is our certificate, and the number is our Companies House registration. Nobody else can make that line appear — an impostor can name themselves anything, but they cannot obtain a certificate that Microsoft will render as a verified UK private organisation with our registration number. If you see that line, the file came from us. If you see Unknown publisher, it did not: stop, and tell us.
Both warnings are about popularity, not content. Neither Google nor Microsoft has examined this file and found something wrong with it. They are saying hardly anyone has downloaded it yet — which is true, because we published it days ago and are only asking a handful of people to run it. Every new program gets these until enough people have run one without incident. They go away with time and use, not with anything we can do to the file.
We could have avoided them by disguising how the program is delivered. We have not, and will not: the techniques that quiet those warnings early are the same ones malware uses, and we would rather you saw an honest warning about a new file than a suspiciously quiet install from a security company.
We are not going to tell you to ignore a security warning. We would rather give you two ways to check for yourself:
The README explains what it does, what it sends, and how to verify all
of that yourself rather than taking our word for it. If you would rather it
sent nothing at all, it takes a --no-upload switch and will keep
the report entirely on your machine.
The report arrives with no name on it, which is deliberate — we ask for nothing about you. But it does mean that if we find something genuinely nasty on your machine, we have no way to tell you. That has already happened once: a report showed a cryptominer that 55 antivirus engines recognise, still running on the machine that sent it.
So if you are happy to be known, email support@smithyforge.com and say which machine was yours. Then we can warn you if something turns up, and ask you about anything odd we see.