Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“Unfortunately, it is really very, very bad when it comes to connectivity.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
76ff55a9b5e64a29cf6c92804c74e3dd365dec0988fa397882bc5c6e1de004f6
Signature (Ed25519, base64)
9uLqjFqy4edpnRTW212z5PAjE5XTH+ZQFJI7oCxQ2C1FDjmlkLLCHkhe98Q04BUz30ucJpVjb0YF5PCVwGd/Aw==
Merkle root
e299bf38720a5a91bdf63bbc0205245bccdf3432ab1652c69342549658b7a9ef
Merkle path
["770172bc1a4248953dd65f269de54fefbe03f5abfbba21723b65c22353ee49f3","35a8cbfdee24005193988636471a6996d3a1499a1c7801eeb53a9641ed51346c","4c73d8b7fcafcf5771094a4094abd95e0acc3b9b436a3a69798f005645a60cc2","615458caa48bd4a920c298c64ad1d389cfae434bafece6937d536443930df219","adb390791b6a4ad88c1c58bab0b176cbc812ce8d5b24b6defb703c25956b8164","1c3516ff8675927e1a2120b4b45d88d6720623d28b6ad02e91f461b1dc666f15","57998c93260276c1a74feb257fddc9c8d6c876374fef9866451bfad65babe2c7","a3ef67218d14f0e319ae76eec1484bd909d69314f67ef48a90ec696f8f0f1e09","5be0b075a850df589944700f5851b763311e427bc912e6534f7dd7e513089c41","339e9c7e5cfe79d94f03e02a3ed2b23c0fa30bb8507ac0bf87c58ee3cc943b98","9db404732a39eb43edeacc7dc2dbb2572a6988edc1ff946ef933a8584aa70600","f1529d9d8d0b27350c2152458e297d9406b31a0ee9c50579b35f35e84480df87","3fdd31064998e61048d534909957bf68a4f9bbe35571f6d185756d8acc2a5420","aa4bbeb87247c2797626ab02a549451da6dfce4dcb854a36fdcc601e3e788772","bce5d442c07de6307e5ea8947098e74ce88c2246eda5e5fc1015a6d7519228a8"]
Anchored
2026-09-21
Public log entry
search.sigstore.dev, log index 2904877428 · entry 108e9186e8c5677ab408…
Expected log hash
d020708737f55ccdf49203f373fcbcefe8158cc388605556fbfda3c365de7360 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1789881486272","kind":"published-quote","locale":"en","page":"theme:v-zug/quality/en","quote":"Unfortunately, it is really very, very bad when it comes to connectivity.","rating":1,"review_date":"2026-01-30","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=com.vzug.home","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (e299bf38720a…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.