Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“Please allow local control without requiring a cloud account.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
918ef6b5acb8d3bacd4a9ea40798eb8930c9b62e627ee3e18fbec2fd4a3fbf79
Signature (Ed25519, base64)
/cbHiMMcadI8I7iWkWb40oRJtB6tjnVAkh4iqAiDV7IoYqJptd93u/sb07CLyXhDifK9XgKyugOdIyuT2BQHAA==
Merkle root
e299bf38720a5a91bdf63bbc0205245bccdf3432ab1652c69342549658b7a9ef
Merkle path
["918f0748ba7e1cae398baaf568070b63483191a3541a58784a2665451c416ac4","0c19f6dc5abc29b7db03d9c543e86de3428e886648b124bae5a8d440aba33733","775fb89f84d3daf052b77dca82577a6740e040d38325ea21648df495610cf9b0","010cb5ea832dd5064e7de06986883223007061cc1623384a74d8204c508da896","92a51a09f1a45f8e0586aa1e030ab235054cb56396ae3d4a17540fbd2e054482","5f893f21bf0b343f3bf0a9684f0dedafb4857be0b02f05f5648e95d3aac5d468","4ffff9c3141bd75558ff5e07ff86264f7aa04d1218e3936063e6a924c2d7abed","6365cbeac4ec4d481c8e74b7c2ffde4e55f046b27d343c772e47a66e63625259","9b6536fabb68fa8278e7ff71b4985eb405c2107370a47403868995ca9eeef9c3","ff1ac9526ebfebfae03ffcd9a5d8cdd3e896f2f805d0aa8b855b0f87c72e07cd","808361c2cc11d1d62da97f81cb8537cc3a8a9e7c2b553285d63cecf18a95be4f","81ae0d98613af401743ec4987802323d53d8fda24ce374cdf2d369d04f6e8e3d","b5d03b72964f911025dbd61c2eea673598b47768b7619e9a279966a44a138147","e3714293de39ce3c6e3cb9d5ea7711343b19d2be532c75504682d8ef52e8f91e","2a462314156907e42d6f0d96eed96123f1d79516aef73ed189d9f5466556b638"]
Anchored
2026-09-21
Public log entry
search.sigstore.dev, log index 2904877428 · entry 108e9186e8c5677ab408…
Expected log hash
d020708737f55ccdf49203f373fcbcefe8158cc388605556fbfda3c365de7360 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1789881486272","kind":"published-quote","locale":"de","page":"theme:v-zug/service/de","quote":"Please allow local control without requiring a cloud account.","rating":1,"review_date":"2025-06-10","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=com.vzug.home","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (e299bf38720a…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.