Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“Für mich ist ein Authenticator sicherer als Passkeys”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
0a48bac207e9dc6b31f62c193d753537ca7851807b7a8758b06410d28c9c2a8d
Signature (Ed25519, base64)
vKid3VMhIvDU8KD8Jb8R5R0qkV42QiEf1oItm6wBYurJ6Zdx8FT6ii3Bz8vaCahuXA6e0sl5N/nYnV07+cGZBg==
Merkle root
f9a030a573da3b674a3e48c677288390a434ca97a740d63af7477bb9b0087dd5
Merkle path
["0a472dd7b9f2bf4276f9728578ffb6717206ec5fdf280b2c4406c7c728b981c3","8ae60059e75120a8c7d7fce5e5c45b043b5301927b77748f143c6f64f7a90b31","b42529eb69bc4fb0bf310c03b70a4f0e7e669907be62806c5ca80e09e8877a88","8ea16c92cfa2e7de91d9e95ae6e1710d64a2ca8ac48189af0506d33e94c61276","d1a1c6be10c1bcbab0d98bd8522c52dcc78730643534cf6017f20050446374d5","d0db224cf0c7e5dfc116d3e427bae2f6a805ef1dd7edb1ad64bf241bd9ebb1a5","90445ca9c4fb41dd91e8bc96253e48a61d1f887990695f54d90364242d7a729e","cd57c6a631a88fc6b6dede7619189b9ac53737994bc472926e686125ef165dce","f87c6f7d7ab55601e3cccc85dfb79289e04a23cdb27b839861e3405f4d6b975a","d26ead21839bce1d0f4a610c0ae3a4b04c3763899f27a0cf62ef04600205714c","a7268e3a2e4a304c8ba3aadc5b4a98bbf743395e23b9fecb4fbc48e95e9fc55f","0092e78b615c9d228c03e53096ae4361365857530df283c6dfbf776a613c6526","4ef2bda7f26eed09474d0de127a9ffbf5b18c0b39b7ca05e262a0cf569ba9981","123f459bb0d221b9be08e494016e3b59946d910cadbe6bacd03f308db88ffcd7","e08301f62b5ff22d13e806e4fd3e64913f665178fce99d41471461eca04be078"]
Anchored
2026-09-01
Public log entry
search.sigstore.dev, log index 2671180029 · entry 108e9186e8c5677a15e7…
Expected log hash
0c7ea517d47f4c8d05e0565112b0ba6c031576195cb596b9212fca396bc97897 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1788233488301","kind":"published-quote","locale":"de","page":"product:proton/proton-authenticator/de","quote":"Für mich ist ein Authenticator sicherer als Passkeys","rating":5,"review_date":"2026-08-05","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=proton.android.authenticator","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (f9a030a573da…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.