Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“Aucune option pour exporter via un code QR, contrairement à Google Authenticator.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
0853a63e744a5172b1a8dfe7b90ffc6241cc979b21f68c53a10c6611376c4366
Signature (Ed25519, base64)
qzGPYgcA5bmPb6EFnjq/+X0XpJ69umV5aNmGg9liG+ynFEQZQpo1BI3LOv4J3dELIHPRljUdpAPhAuCQT05NAw==
Merkle root
5c4849a28e8624d6f6d3204e1f81a6b24f2188b6690e8b122801054617ca25d8
Merkle path
["08531817547e6c1d38a46f35e86bc2dcd5b8bc67fde17a04ccfe04ce10aa0d5f","6329915fb4cd3989908211c82f028ba18fe357100885eae24ea54e0250e5656e","5680023234ba8ab0b061ec9dbe8fa74201df5b6e0b63b947b3bc8ddcf88cf97a","0d78a2e2606d32d5e857655875f6b499dfabe50a676fe899356666bc332a9714","47c1e91b15c3fd7d666e588d32b6750d9bb5f471a63a9be15d8e1ed8000c3e7f","0586dba60bfdbe049d469db3d364295f9aaa4938b966c5cc4a2863c497fdf879","26b9dd59fb043c9253b8c1a87bcf89a1a3d3133621978ac70c4342c058565244","13ee15b6ebd725092bc0c405b80c6c988a8d8f6a2a38c8093d95f60845fa0efe","fbf9263491a9cabd8296399cbbe08e782f844ccccbf7d26381cb8f6b7501fa2b","0e5298d35649bed24099ac4ffa626d4f0c235dea3a39ddf43717656eb0e46e79","8cef1282d89fcd10de1a19b4daa5e03655fb959f1b6dc4e7d26ff03551b4f386","d4188d2c80932f475c810ced976fef9d816f34d9a371db67d8b88d0e2c021c71","294fbe7fed0fa3af8e60ca01a3a05891e9e1266a19028060f205705712eb6e96","9693116cb745ecfbff942949993950a2efc72f3f48b394aa6516ac43c745a9a2","649f189ed3a422a3ffceae7f7673f3e683a1fac940fd27a4d89bce585dd48e49"]
Anchored
2026-08-20
Public log entry
search.sigstore.dev, log index 2524617489 · entry 108e9186e8c5677ab139…
Expected log hash
2051fcd76f2ba790414bb1c15fd4d3d064889742ea46f8e55b5028f1f571c27b The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1787193158162","kind":"published-quote","locale":"fr","page":"product:proton/proton-authenticator/fr","quote":"Aucune option pour exporter via un code QR, contrairement à Google Authenticator.","rating":3,"review_date":"2026-06-28","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=proton.android.authenticator","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (5c4849a28e86…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.