Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“IT DOES NOT SPECIFY THAT SYNC NEEDS A 2ND DEVICE TO DO ANYTHING.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
0a2ae795fde0f63502fb412c51b658c6421ec330ec6afc2ae5e89c045244fdfb
Signature (Ed25519, base64)
TYHpcNh27kvES4l774xkl2o/AtQJpelC3WGvccc3VutZiK7n1Pt+linbzfZyxr8IK4Y5Za6JaDBaHrsbVkNACw==
Merkle root
b839fc90680d59ef42f94824bc47a43844eda063a2dc78e98d04cc6ddfcb474c
Merkle path
["0a312d01ca9a3a393544a884ac49558ce00e4c7d14e9f276cd590065ad6f1eb4","4e31c2af5e4d7b48797d6d7053c953bdc73aa5fa123f0632bfa753081f0c51fb","b84d96290933389445fb9b2248c1dbd5c172b391f90be81dffcb73889fc1be4c","0c4ebe4ea0ac3499f294374bc4eff264aefa3f317f071fe2b30e58f2029108b2","c0dcac181c41089e97cdff4e723883b8319f4bc6023f813d2651dc13e98a930b","d601771c27ab878825c14724072ae8667c0bdaca2ea07239b63438df03264233","87c39326e8680bbc0d49da5d761811c2443c6cd4d2b04b1dbd350cd8870c70d4","be431a29cc6bb3ec575f804eb6aeb53fdf38c074fe66955db8286fed6aa3df28","3c5f477e45948f2702afa3a57c394a9851582c13f4b5258fbd5b738b22fa17d3","7f31e77f58de8a43ef26b91683492cdbec3702007c43096c5a97f3baac77aee0","9ee71af0e0202bff3db5ceb8906e346af79c56ede3a8d502ae51684b1bf2d693","da3f18db4275ea305f12e1c8c0800014ede0f36037fddca212d2e67d33301687","93cff867a371eca67187fa18f29672e43dc122f1a11ead8ce02d295afdc520fe","2d44a3f2a338515d5139d8c4d918da71ecf66353dbaf922a6fd5c33bea9ae2dd","53cddda7a1b6beb992bf062aa34497189c716ec3be3251f7e5db0dca344b1a73"]
Anchored
2026-08-26
Public log entry
search.sigstore.dev, log index 2594765087 · entry 108e9186e8c5677ad8ef…
Expected log hash
2b2c4baead5a20e634c42acc5e7cfc8d7389892f0fc879f3c38d7eee1c04ecac The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1787715994367","kind":"published-quote","locale":"en","page":"product:proton/proton-authenticator/en","quote":"IT DOES NOT SPECIFY THAT SYNC NEEDS A 2ND DEVICE TO DO ANYTHING.","rating":1,"review_date":"2026-08-04","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=proton.android.authenticator","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (b839fc90680d…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.