Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“Still doesn't automatically connect consistently”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
1bf0dc01056faa22e9797bab9f7899801f35d3eaa077f6fdc6087123ec87cdb9
Signature (Ed25519, base64)
XWlGEueDVydN2o3QHSzamJORdFflio4EzxzK68oS3T8vrN7S0flMcaJlPY+HLxJZgpGF7kHertOOEI+T2YQgDQ==
Merkle root
0fdf8a945cf322eba60395065bdb38bb3eeb32c52e065b6c93c48bb56aa3bb91
Merkle path
["1bfa44e9cda19512e4d54ab89a929fa5143f7faebeebb6b1d4f3beda1bf644c5","1982aad8e9df868796c61d42164f7caf80468de150adf2913feb0a2522d61ad6","789f2c117f36c2eb1773f4428e8964def024fa7b9c2917479c4ffa2d0921d157","17ee4d48a47bf9585293329de538471979d02cd3c773eff4b2e1345984a8c5cf","a5c861285fbec81572a6240a52b4f2cb13cc2bfb34bef60f73a0650d2529108b","3040aa20e20a1946ca64d67988cdce78cb4557b6f47f61f7744841273519c4ce","f0db5f28e93099a3f39215895ae5fd8d435123219db8a0addc12c9f127be0b8e","10e57ef283cc30a238b3eaa76c3136d43aa05fb9b17c4006d87de8f30cd853ad","959692639973b787b998af4537f3248311d19dde1f5165fdb8f907f10efb3b8f","4b7289908aa82ef6cbc6e12e70d40199d9b9a46335c483c324ebab2f94c325cc","857c7b77d0ff1b44e582ab75ce587e041ff951ecd549da4c8488052255f2addf","f53de120e1726fe9db2d4486352b37fd1aff512fbb85358f81e6249de2ae3d7b","193dd7819b5cc0893cd3620ab02042348a20821938045af5a341e160ec2e8bda","d97c31a576cd351fb66ddffaddfc87228fbf93ecf06301d5b8aec9b37e0fda68","31e60baa9fb8f672f686fd126d7dc82498bbfeaa38bc676e67691bf1c2c7c210"]
Anchored
2026-08-21
Public log entry
search.sigstore.dev, log index 2541942774 · entry 108e9186e8c5677ae0bd…
Expected log hash
4825ba618d3c3368179be13912e101812df871de37f30b1ec256ca6d987713ec The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1787277864570","kind":"published-quote","locale":"en","page":"brand:proton","quote":"Still doesn't automatically connect consistently","rating":2,"review_date":"2026-08-13","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=ch.protonvpn.android","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (0fdf8a945cf3…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.