Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“This works extremely poorly—in fact, it stopped working altogether.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
43d63fe0fe8b79fb35fcd2c3871415651d3b4f075a5a0183da8963579d7301f3
Signature (Ed25519, base64)
UQ1xjEpz2XrAxZk+aiMTbBZWI0z2jorBgr51C1uUer9dHU9r9rEcVriSE1CaY0si8sV8IF1evcP+Uzaya+Q1Dg==
Merkle root
8c6268a14330d1a3403c561e774645b0671f81571ec1735d4674ebe1de7502e8
Merkle path
["43dcee743ad18feb87ecd075c21b530d3c129c2808d38f9bf2591b3df483bb03","cb97e256a9ad45501962bf99734fc0699bf8bfd156afafef5f76d2859b3d8260","31f3dd193f1067a445ec05ae9c0cbe5ac906558b9530c6934341509c61477029","e50e6559f421308cc8bb255a753eb2e644c4dd7792690e5477e7f948d5ca55f3","c3996346df16a698eebb85d61614f1e3bf049436c5d8df0cc311da0835ff3d39","0efe662484b50866c103b8e228cbd37f1393d0c71acbbb964f5e8c73d1c23664","db72198f905dde8f562f696e941b41dc7db1a8d3373ced2aec9004332246f8f7","7c560287f932c810b47da71a83d19665a0e3494a07daee0940ab0e728c8e02aa","6593c9c4b80999a7f349d6d6802b97e68c5533dea351848069acb85a9f1b9959","695a8291d96941d53e0ebe748f383b3328716127bfdf502dd45072397c6844cd","ce19839241ac0eaadcd29c2faae5c03add149288fd6c9a34fa63038534ef7590","bbd81ce977b62d941970a51d978795d1ca8d2e3dac3434c43899db8d20191a9b","a130748e37a17fa29f4013443a16c6ba5d7fca63733ddc833e40182a59b453a9","894fb50f273584bf006781fb08f5958320d3e5510a31da0d6339bcf63d847254","f548939ab1bb46e2c6638c372c3e2eef0d561ad18c63c15229fececc951e0b3f"]
Anchored
2026-08-19
Public log entry
search.sigstore.dev, log index 2515439294 · entry 108e9186e8c5677a4f15…
Expected log hash
128701fddbb19410bf57cdb2d04d7a0278d13bcfda6410d76f176fa58341e1c9 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1787141082461","kind":"published-quote","locale":"en","page":"theme:sevdesk/fit/en","quote":"This works extremely poorly—in fact, it stopped working altogether.","rating":1,"review_date":"2025-07-03","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=de.sevdesk.sevdeskgo","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (8c6268a14330…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.