Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“device verification failed”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
3162369ac739ff7142110733409670b49827f24e859e3007863f05bba4a63ef0
Signature (Ed25519, base64)
gcN7kIKb841oQxWcVYtC88Z8+JCJ80CzHMbj09aKuZcN8SQhaUJn4OnwkSKEstskSwD9YtmoVuKOi9SaM0VyDg==
Merkle root
e299bf38720a5a91bdf63bbc0205245bccdf3432ab1652c69342549658b7a9ef
Merkle path
["3162e16406150c6f9241d2ba3a55688e15a3333d7fb2b15646976df8bea8f5dd","1ace75f94f48529ed9d70fdcd52b7d16930b66379dc1895bfd6165528d7ace04","d5255ca01b39be8420a2b20ef4cc0c38dd91f204bddf0925350d4c1fd438ac03","534cd3bbbad905f30146636d1efbd5ac5677ceabc9d9d3420e8c9ce60fa004dd","8fbd24a19199afe1affc486702445cff2d9c586f2980b1d82a1167a2c649181f","1e6e8b2bf7958783ce477420897d5be3d47d902b58bb6d803ff5cb3f395a15fc","caf12f6b06a8952e5ce2263451b1678e91b73cc77d9fb4ee7b444fd1105d6948","f814410318da6bc7b44980f2d4f5fdc2a5fdb32e0cf5fcd205cd51e16d04e62f","187d51a80a48145885d7da5100cd9a5ec8a689c9d514270568543fe6a055a451","c6c4fc2af6ba1eefe809afd91778f4d6e85ff37fa661537f3b877227c5bd0a39","22f7f790928f056a4acdc3634db989dc19836ddd154c7a9b49ec17a860d185f6","357edf8b8b42fe4c3b552e7406b8bc0a14039d1d547cc663e39b36a74f79f52b","b296372665f7c3838922f5e4d88b25d49437a77f990ac53d0dda027dc9495fe8","2e838893ef313b8ef0f87568e1e691fc197dfcee84413640a12968493decac73","bce5d442c07de6307e5ea8947098e74ce88c2246eda5e5fc1015a6d7519228a8"]
Anchored
2026-09-21
Public log entry
search.sigstore.dev, log index 2904877428 · entry 108e9186e8c5677ab408…
Expected log hash
d020708737f55ccdf49203f373fcbcefe8158cc388605556fbfda3c365de7360 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1789881486272","kind":"published-quote","locale":"en","page":"brand:worldline","quote":"device verification failed","rating":1,"review_date":"2025-10-29","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=eu.softpos.softposwrapper.wl","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (e299bf38720a…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.