Dev.to Security 🔐 Cybersecurity 👁 0 📖 3 min read

1,000 downloads. I'm 13. I made you a promise. 🔓

A few weeks ago I wrote this on dev.to: "ATLOCK v5 ships when Akhouri Systems crosses 1,000 downloads." At the time we were at 959. Then 967. I kept refreshing like a maniac. 😅 Today I can say it: 1,000 do

A few weeks ago I wrote this on dev.to:

"ATLOCK v5 ships when Akhouri Systems crosses 1,000 downloads."

At the time we were at 959. Then 967. I kept refreshing like a maniac. 😅

Today I can say it:

1,000 downloads. In 5 months. Thank you. 🫵

🙏 First, the thank-you

I'm Anmol, I'm 13, and I build free Windows software alone, on an HP 240 G9, usually at 12 AM.

Every download is a person who trusted a kid's .exe on their own PC. Every comment, bug report, and roast made the code better. Here's what you did for me:

  • You downloaded ATLOCK, ANOTE, ACALCU, and APIC.
  • You told me what was broken. I once posted "I have 511 users and almost zero feedback," and you answered.
  • You read my code and found problems I'd missed, and I fixed them.

Nobody handed me an audience. You built it, one download at a time.

🔐 So... ATLOCK v5

v4 was the version where I stopped trusting my own encryption and rebuilt it. v5 is the version where I rebuilt almost everything underneath. Here's what's in the development build:

🧱 A new crypto core

  • AES-256-GCM encryption
  • Argon2id password-based key derivation (memory-hard, so brute-forcing is expensive)
  • HKDF domain separation, plus stricter KDF limits so a malicious file can't burn your CPU or RAM
  • Optional TPM-backed Windows CNG key support
  • A controlled Vault Recovery Key system

🔑 Real second factors

  • TOTP and FIDO2 / YubiKey-class hardware keys
  • Panic / decoy vault concept

🛡️ Security Guard

  • Windows Defender dashboard integration
  • VirusTotal hash lookup
  • Startup-persistence watchdog
  • A ransomware "canary" concept that watches decoy files

🧰 Under the hood

  • Anti-tamper and rollback protection, plus debugger checks
  • Locked and zeroed memory buffers for key material
  • Automatic migration from older ATLOCK formats, so nothing you protected in v1–v4 gets left behind
  • A real CLI (--selftest, --shred, --vault-audit, and more)
  • Quick Lock, a Windows Explorer integration so you don't have to open the app to lock a file

All of this comes from the current development build. Features can still change before release, and I'll tell you honestly what ships.

🐛 The part nobody posts about: I audited myself

While building v5 I hunted bugs in my own tool, and I found six that looked fine until they weren't, including:

  • an infinite loop in chunked AEAD
  • a 2FA lockout
  • a file shredder that wrote one byte 😬

I also pasted 8,500 lines into an AI for review. It confidently reported a bug that didn't exist, and grep proved it. My lesson: demand line numbers, and verify everything.

Security software isn't trustworthy because the author says so. It's trustworthy because people break it and the author fixes it in public. That's why I want you to try to break v5.

📦 What happens next

  • ✅ Milestone hit: 1,000 downloads
  • 🔨 v5: final testing and cleanup
  • 📣 Release: [It is not fixed but high chances are that ATLOCK v5 is set to be released publicly in 12october, 2026]
  • 🟢 ATLOCK v4 is still available and free if you want to start now

Download v4 here: https://fn6qtj.s.gy/ATLOCK-v4

🫵 Your mission (yes, you)

  1. Try v4 and tell me what feels slow, confusing, or breakable.
  2. Open an issue or leave a comment with your roast. I read every one.
  3. Tell me: which v5 feature do you want to test first?

Unsigned apps may get a SmartScreen warning. That's a known false positive for indie PyInstaller builds.

🔗 Find me

1,000 was never the goal. It was the unlock. 🔓

Thank you. v5 is next. ⚡

— Anmol, Akhouri Systems

📰 Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.