Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“QR scanner doesn't work.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
0910693978947073693e93b0e7d4dd478e7c5c3fc69c6fa474c15ca3087f8152
Signature (Ed25519, base64)
VtdC6adkIZAUJc2lfRwBNvKevhDQqMHbx1WDWC0dAPhGCeqXIlME5MGTT+RyuDFrf8keS/QIf8cDQjjlEWi+CA==
Merkle root
ba3b9ee3c1a764a237c6d9f59e08a5448370e387ee4aa25688e1baa9900bb7c8
Merkle path
["0910177f98848354246ec79db394abef5ddefa94877c64b13ecd9010958451da","e2df2fcfa21258a8beeb9cb74554df94d297a7457a9cc9409d2cf12084376819","2dc45354cd05a76f549b63999d425de06e29681f720d9a5fab5ca8ad407caaa0","843031dee7f8ae35de265c0aff76ac5ffe48658835ea857cad991f6718c41dde","4f779ebb437f4e5c66b0cfa905ea7315a12799453dd875d924db1b2e6f4073a6","88f2f8e8de1a1a47a58400061724d75854416418cbff389947514e38f6ec0a4e","0342e31f352b03025c1a89af84c1bfc17593a55db8de768b63b09d5a82cecf58","b73b3d71098d945db83dad8f7ac63455d7cc76567db538c31ac953f618d47fbc","d014f2c70ae70478986470edc04899d0c71b68274a2e87ae029b9c4be4d0859d","5d7704ab591d046948f40835c319cde688f425f8c045e5137f0eb7bc45b78e8b","8d1df0fe3635e03396299a41b20b0d6e8c2fff2b60c04e182ede3a19bfde5327","10ffc2a9a8cf6a1229f8a8903830ff0227fbe846a1c267cba735937e7ff243d6","bf9dda6cb63d4e43e061a12eb4c0603f6e05cc0296b47362e9aaa0373a392f18","461c98f5765895f7eba79033993e171a1c62b0f447b3c3e83ae0eeec3170f91d","105ed454c1d199fd4c49602b8c5ad04e94f166fbbc654d60a1759dc1a6618062"]
Anchored
2026-09-02
Public log entry
search.sigstore.dev, log index 2682016602 · entry 108e9186e8c5677a5d51…
Expected log hash
1226b40d95efc02c2bebef5ba710e31f8d38836dd3aa942fa2cf212191019dae The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1788311625248","kind":"published-quote","locale":"en","page":"product:proton/proton-authenticator/en","quote":"QR scanner doesn't work.","rating":1,"review_date":"2026-07-11","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=proton.android.authenticator","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (ba3b9ee3c1a7…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.