Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“C'est une bonne application de double authentification.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
262a34612769065cf48b9dcad922e84e540695438438f2391fc3555f56998ea5
Signature (Ed25519, base64)
vwLyMD8jhFw6IsASrg6XIH/QiBqkrvsrsTs3fSdeBV04ajEIWs37Q23iiX+c/Ogtb2ZdRu7VTuM7ARwbT8NzBA==
Merkle root
172a3e0b3c9f8b02f52318e01ba6beb899404e00e91c15eebc4dea38467e1404
Merkle path
["2627fa8372aa3cfa1155764b16eb0418347dae1e47dad1833c9c108b00722cc6","33e643bdd9edfd699835d5942305540362d1be5c6565bb5f4e3abb8d8bb4a077","05d918924ed527f9520877527b68cceb55b2562a5225afe8f7b61c0deadaace3","73e92f002cbd13bdbacdb781f3910e6a9682fabca8d688ef66e2811f21cc4eed","b940aa8e4bc0b971342e2a38cbdd85085f7c1a5ca9fde4c7246b472e4e0dcb1f","445a19a45bd9e54cb7777d36786ae2d1fd9debd989c41f653e8c442c3cd06399","28c2d29ea05a1f1b3c3594f97772d91a2c89f66deaf29d04e246fdb72a475769","d72ef675e92b502d42ca4610de5aae29bb5252684e2532b0f1fda8c7762855c0","f704d3044bc9e4513b0e7ae27bf7daf9377c86c0f24c8fd0f9c9abd8562ae559","b6caa320708c11593a9049a33b7a7f18ee2a9859b917bd1637cfed341d384daa","6c00714d769caf6c32a865a27efd0b604aeebdce40d36d37bfbf277e62b503b5","22df7ea858840ae6ab19a461f259a5dc1cbc4b2b8da70f18525901770d369726","6582b4bd72409a5334905e80c9e3aeb7c43a20c5eb4c139595bd990bb777102a","b2e250a62b44b0b9c303f91afd3aac8852fa6af504d7d68ed736141a3dd71161","7731d0ded4f51d151ea3e84474d1e27a6279e8756420c93cf5fec0abf7f11add"]
Anchored
2026-08-21
Public log entry
search.sigstore.dev, log index 2543025731 · entry 108e9186e8c5677a8971…
Expected log hash
19ecbe4a66d8adbd7c6057dbf6ed9be73485c248dba1e0c595279a908b3e8bea The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1787283443958","kind":"published-quote","locale":"fr","page":"product:proton/proton-authenticator/fr","quote":"C'est une bonne application de double authentification.","rating":5,"review_date":"2026-07-29","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=proton.android.authenticator","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (172a3e0b3c9f…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.