Windows Annex: what to do if Windows blocks the launch

Note

The following applies to Windows 10 and 11 operating systems.

Windows now requires software publishing companies or independent software developers to digitally certify their applications, or even distribute them via the Windows Store. It is therefore recommended to turn to external companies to obtain a digital certificate, which costs several hundred euros (see, for example, https://learn.microsoft.com/en-us/archive/blogs/ie_fr/certificats-de-signature-de-code-ev-extended-validation-et-microsoft-smartscreen).

Since I am offering blunderDB for free, I do not wish to pursue these costly options. A free avenue reserved for open-source software (the SignPath Foundation, https://signpath.org/) was explored, but the application was unsuccessful; the Windows binaries are therefore not digitally signed. Consequently, it is very likely that Windows will warn you of a potential threat or even block the execution of blunderDB entirely. The following sections explain the steps to bypass Windows’ reluctance, and how to verify the integrity of the downloaded binary.

Windows SmartScreen Warning

After downloading blunderDB, when you run it, Windows may display a warning such as:

_images/smartscreen_en.png

Note

This screenshot comes from an English-language Windows. On a French-language Windows, the same screen is titled Windows a protégé votre ordinateur (Windows protected your PC); the link to click is Informations supplémentaires (More info, or Informations complémentaires depending on the Windows version), and the button that appears next is Exécuter quand même (Run anyway).

Two clicks are enough in almost every case — More Info, then Run anyway — and there is nothing else to do: no antivirus exclusion, no setting to change. The following section only covers the rare cases where the block did not come from SmartScreen.

If you want to allow a specific executable blocked by SmartScreen:

  1. Try running the executable:

    • When you attempt to launch the executable, SmartScreen may block it and display a warning.

  2. Click on “More Info”:

    • In the SmartScreen warning window, click on More Info.

  3. Select “Run anyway”:

    • If you trust the executable, click Run anyway to bypass the SmartScreen warning for this instance.

Windows Defender Blocking

This section is a last resort, to be followed only if the block did not come from SmartScreen. For certain security settings, it does happen that despite the unblocking described above, Windows Defender still prevents blunderDB from running, with messages such as:

_images/blunderdb_potential_virus.png

or even:

_images/threat_found_action_needed.png

or even place it in quarantine.

Windows Defender is known to trigger false positives. This issue is explicitly mentioned in the FAQ on the official Golang website ( https://go.dev/doc/faq#virus ) or in GitHub tickets for some projects programmed in Go ( https://github.com/golang/vscode-go/issues/3182 ).

Warning

Excluding a file from antivirus scanning is not a trivial action: the exclusion applies to a path, and any file later placed at that location will also escape scanning. First check the SHA-256 fingerprint of the downloaded file (next section): it is that fingerprint, not the exclusion, that proves you are running the published binary.

If you want to prevent Windows Security from scanning blunderDB:

  1. Open Windows Security:

    • Go to Start and type Windows Security.

_images/win1.png
  1. Go to “Virus & Threat Protection”:

    • Click on Virus & Threat Protection.

_images/win2.png
  1. Manage Settings:

    • Scroll down and click on Manage settings under Virus & Threat Protection settings.

_images/win3.png
  1. Add or remove exclusions:

    • Scroll down to the Exclusions section and click on Add or remove exclusions.

_images/win4.png
  1. Add an exclusion:

    • Click on Add an exclusion and select File. Then, navigate to the executable you want to exclude and select it.

_images/win5.png
_images/win6.png
_images/win7.png

Verify the download integrity (SHA256)

Each binary published on the releases page comes with a .sha256 file containing its cryptographic fingerprint. Checking this fingerprint ensures that the downloaded file is authentic and has not been tampered with, which is a useful guarantee in the absence of code signing.

On Windows (PowerShell), in the download folder:

Get-FileHash .\blunderDB-windows-<version>.exe -Algorithm SHA256

Compare the displayed value with the one in the blunderDB-windows-<version>.exe.sha256 file. The two must be identical.

On Linux or macOS:

sha256sum -c blunderDB-linux-<version>.sha256      # Linux
shasum -a 256 -c blunderDB-macos-<version>.zip.sha256   # macOS