Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“No option to export via QR code even though Google authenticator has that.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
0b4cf83c2f571a04824d3545f31bae7e04488aada9b6c0a79d1f47f86ccba602
Signature (Ed25519, base64)
wk76LO9OIhmVH4JsrcUP4KkqkI2jtFqsqetYx9N75s0e7JjzopPlkNNXJRWPVkbDRF1HitJMUj7JhZz05VuYBw==
Merkle root
653f52f612dd7654074ec2f50a8258d24363de118d24fd3fbb293c3f9466146a
Merkle path
["0b4de2b0523fd5620069ad2afc192e8886e68137ba80ef34ffd17894bb183775","014783319ff82d558edcdc48bd41be9c62c6f49b86eaf48927aea930d385c211","abd38b7607fcc1d120062fe5e2bc9eea78a132d32260173e08d5133c00996836","90ddb0fd224cabf2f1e68548ba38997f5e589377a15725fcd2f60bb2b254ec81","86c170cb755e9742dc2d9f3922fd02782c58a373f2579bd7e844fa54cfa10f5b","05206244a2fcd3bdcb3951107bd17a2e8148c8a3d7ef20d688538010adb198a2","8f244ac4ba550ba3c51c0ea44dd0314c1c5445894be5140c31802d66bc16cbd7","364a6f2c16168969cdfb99eacfb91790e69d635911a97eee8ea44c1022e6f3c4","3a9ed3daaa9e61e950a7fcb83c556f5900ce5f05ccbd9fb450d53f68500db546","6fc6e7592732ca5bddba993395de6ae96c1bfe6e70807602b228978a1fa30748","e56204f1821ef0eb64f6695ae10ec59c473b495ccd38e242384b49da4e461f80","f20b68e10c9d60c824a39dc128151a5fb0347bced725edc264111d1392a6f092","9fcd88f1beaa69d65dea3d04b431d43ad97368c1462c24ff050124283ec46f78","88e03340b0b23badae5a3021870a121b2e386f6ec4446eb6072186f7c59cabf0","5fdd4fb85b0ec398c42530ef65e986b74edce2f5c14068ba5fbe6a72c94b89c8"]
Anchored
2026-08-25
Public log entry
search.sigstore.dev, log index 2582700609 · entry 108e9186e8c5677a119a…
Expected log hash
db705c1ce83f047166ef3ebf3406f1398f685221ea16db9703eceb49a1163aa7 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1787633403760","kind":"published-quote","locale":"en","page":"product:proton/proton-authenticator/en","quote":"No option to export via QR code even though Google authenticator has that.","rating":3,"review_date":"2026-06-28","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=proton.android.authenticator","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (653f52f612dd…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.