Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“Aucune option pour exporter via un code QR, contrairement à Google Authenticator.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
257778ac23fe1ea33804b0fc69dcf566ef5302e65041b969eef0e26d9b56ba42
Signature (Ed25519, base64)
b8jdAm8qxdbKkN1kpUu5ZycuSMgO8BHrJyJN8fCQ4drEC42A6+bpLTOReI4UCGxyXdMXXZakFn046VRayso8Dg==
Merkle root
aacc11945f125ee3fcdef86ba030016c440bcc608f4e51f0ffffdb4cdc5e9321
Merkle path
["257633e972e2e1fee989a413f0f86ca1ce2ef0e178735c81aad0edd86b552f72","939eeab3ef451f558e0c9e162f91840a36df0e28cf875cb713a6ff2657362736","378e271b7a9e9ea34ad246c3a4d10b1350f24499ce77b63d8b17252f5d652bcc","5f419cb1c168a6ce9920c57d91746f8141566a528e7554fd414b58404e732c06","448605350a09b0c58177ef3d09b3a293f36bc3981b2de2e0c9e1fdd54d0983e8","47cbc64cf3a37ee21e741106144a7ad738158ea2d712b2610fe6725527db5fcf","a1e7bc28b9615fa129ff6c623457561e5feaf5520e0b678ea81713d0ada6c0c0","ded785b5d9570557eb7bb5937eeaba4711b61c03c25bcfb4775a696c6c13e41c","18bb2da06be520686b9cb425a12bd1c4c18d6c8e7643ef97aa8809e3cec467b6","b6291cb5ec4e9825966adfbf8839f94bbc42fbce4c8657fa3a0f60186162058a","e18bf79390a9d5dddfa09130e3000ef092da83b997cb7bc96d44e2e4340f5e54","7b8ded1b49351694655c52a46b67cd12e02f2a4c9ca9c29916bfa197957ebfc1","24192d1fe3fa8596b225aa5d8055e7e92d26709ec190f1226b913a3e227f64c3","5366af6eb1ce50b0f459da15c1d7eb12649d0477ecd930804e506d3f2ff66aa2","2309962142b16600f7fc4d57273f3042f382acb91be89aac7f00112f61b58f1d"]
Anchored
2026-08-21
Public log entry
search.sigstore.dev, log index 2543547848 · entry 108e9186e8c5677a921a…
Expected log hash
bb93f13ee7a4a636e28586b842e19662b148eb18166a89b3ae7d189bb8e81689 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1787286345433","kind":"published-quote","locale":"fr","page":"product:proton/proton-authenticator/fr","quote":"Aucune option pour exporter via un code QR, contrairement à Google Authenticator.","rating":3,"review_date":"2026-06-28","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=proton.android.authenticator","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (aacc11945f12…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.