Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“the lack of the above makes it very unfriendly and frustrating to use.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
0b2b0b56e67087508ddd2ae279330fcdb100919cd8185f2e2d20039be3d59519
Signature (Ed25519, base64)
nPWjqDNbh7Imw1N0FJ/h5PWvgXhnA5RmuBc2ka3T1Cll1fBfgz0BHxMRhXGGvvMwPSgZfJ5QA5mABc62k7z+DQ==
Merkle root
d9909e7ff193b610d96d9930fa8111baf2fdaa08b732478b03ded2b9e1e52914
Merkle path
["0b2a667256684ab6d27811fd087826bfbdf09bb77bd9e854399dc5c96f1bdfb3","fdb5a1779a1c86df597908f47336926e0a5cab6be90b085c22d09e3a58c2f252","305dc8b1096f3f8b7e23ead95e40a69f0e559c2718ce396c82e6088bbdaed7cd","d721d6548954981efff861eed39e1fcca600eacc282244a59cc1d804d61dfe61","d0be5c96d7a0be5cb7e1fcc07e35160cdf5f25861a99a627fef4f10d0b4e130c","9d40bd37f2479bd3f7edf9bfeca678422e169cd46f50e11ca2595eb90ade538f","1dc424d91824b73cbfad8e5e5c952bea0e14f7096f1d4d397728778f10ffa2fb","7b7198caca6c668accd315bbf54a42c421e5e335d89ab77784e1823c9ca09edb","363b32d9fca24467f169156bc513b14f75c536a9025f7aa0ed76e64799c78973","a50e2c0ef16d37fb37879fcb4e8467072e3228347f7e39c1dc9ffd1ca8460642","6dc4788b7bfa91d0a3acacb71f48e44e367fe199cd81119c5bda79c28e8ab3f1","d0c545501ec6b40886bbd7f01a63b389d170722a1f58d9eb61157cf85e3ef9bf","717fc4742794be36cf72805fd12ab627b31b870eb5c244ddb55c2504c3c85510","c8967a31c6292f2cfc7ed9c390f7083b1880ea886157cf89b881616d7130d93d","2aa33c224957c89d7d414cc43142ae7c4368efde4f1a1b6051ee910ab17bf997"]
Anchored
2026-08-19
Public log entry
search.sigstore.dev, log index 2515095234 · entry 108e9186e8c5677a299c…
Expected log hash
6f0abb2e15f57da153d99eb9fe756fd2540bcac51fcddbf7ac60c4be3cfb5f7f The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1787136684512","kind":"published-quote","locale":"en","page":"product:proton/proton-drive/en","quote":"the lack of the above makes it very unfriendly and frustrating to use.","rating":2,"review_date":"2026-08-04","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=me.proton.android.drive","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (d9909e7ff193…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.