Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“Still zero reaction when I point the camera towards a Google Authenticator export QR code”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
0b7dba267ad5a9301e85cc99a0d7367e13fadff2570303ae4e8fe899c1df8241
Signature (Ed25519, base64)
XvqnW2yvfRN39rY6RIitqzv/12ndpT4O9qbbLQjomm9bFwytc70GiGonR2Lfh6wExXVBMHLNy9aToKy9J1YZCQ==
Merkle root
2f068f3de56bebe7a575ba4a979c9244445d2350140e36238e088fa40fbfdd88
Merkle path
["0b802b356198dadf38f83679da87577c8bb1f1d83685b3441b043cec3415b156","a75cb5e905da077fba3dfba8471eae4b03da550afb791a1366fc2f3dd451cf21","3f740254c212df2ce4a5dcc8d8dbccd88c25da96efbd9be6f686e8535f42c2a2","91deb3b8b8a4398c7dc16a2f008ebaffbd7b363a0945ff52cb2cae42e8698470","b78c8dc18fbc4412fe80de26679cd73462308c6965e88f7c5372ca5f70891213","da0a9e03c58b59b972c023f0ebd8f1fe38f21a52aae7cfcf025c079d6159cd37","2f2f96882dd00d482a28c46d878057bb3ebcf50cf7291d6cea87471c05688a18","3fbad2f001c3e19fed3c59b93c3341c5b116444845f014be39a1a1b593439c7c","c3cd392d7de9c46144ecff91217171202b5a103bb7a5927e325e4d7def305c08","00773705a8b069bb275032e53a7ffd9252b67489945ee0b61d37499624b2e877","6019f800aecafc41616ce9573ff1b4f5115ee1aaeb4f1bc33ce4d0bfcb8a2579","db8b9402749163dd7028471f175d7d75f6482cc73467c43e4ddee59d4a6d5020","3b092fa48a78448b4db01d94e347dbde2c39988a6fba76ec91ab78b6f236682c","03c5fc675733b417d9af5e071de3aba38ae7f09fa5781cbd0133ff9d4e234e36","98191c82333f4385e47f318835e01d44ca8835262c6d0df40edfd5f6a4dc5c19"]
Anchored
2026-09-20
Public log entry
search.sigstore.dev, log index 2893887498 · entry 108e9186e8c5677af79f…
Expected log hash
90099e0300c6e23b62e79318296ebab91bff130379d248ada57f044f77e72ccd The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1789796056710","kind":"published-quote","locale":"en","page":"product:proton/proton-authenticator/en","quote":"Still zero reaction when I point the camera towards a Google Authenticator export QR code","rating":3,"review_date":"2026-07-11","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=proton.android.authenticator","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (2f068f3de56b…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.