Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“device verification failed”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
af27831c071fba8a3dc07471b089a7a58113c091a7a86139bdbc9f215888bf3a
Signature (Ed25519, base64)
faTtTXUxDeZxyNFY0qGKGz18gPgAtElEEdYX0l7s+MUbN9scnvnSH3vvDLlCOPzF6jH4LMIpvrlocm3ifrpKAg==
Merkle root
0148d24ff6e9c2ab4d5b200cf436fcaf811faf144951e67c277e5df63df916ac
Merkle path
["af2611f05ab8218ecf80daeafa25a9962b53b9ec649a7103869befac347bec69","7e68a548ab30b31a4f070ad6c8221f081e1cc90e1df33fe9253039430399e66c","bdcb518954a3f63781f36c7c8742e583506db0cb64b5d9a8e4fca37d1ca87ef0","3d5e079b8bf373fd5c32f7633f6a29e2c5d714b01bc87d6acc44e7829b95f37c","cf241df4698430c0fd0e2cdef2dc8e737b1b2355d3ec6d938525b491ec028ac8","7b0f3200bfcddd2ca8e97e32dc92466a7cb7265db8cca0983a98f27254994b3d","5191e94246e79a84b4b2b954a85b04c4641e9739ebd17125b57fb5b19a578f7c","47feef31b5215ae6a93557f56917feabe9e9128ad0e7a1aa1b6acf56c710b2b6","f5f6034a08ddaf879d0bb37f02e96e1e3323796fe55e10fc3381837672bbacac","005d47186773cb90cba3958a299bb4f0f1b0f0e10b768eb56bc080c0dca8a40c","76407709d0f9985fa7fb190c1374348a31db67350f0c885d04c7f7f8e0e1f4f1","a5f0ec91f46ac3797cef88189e211a861682c8419e4ebba5530830f50113f579","5431f2ffa151ac603a0278b62f4ee6e7f4364f90760c7ba184669d801da84cda","921869a075628557d48c5285732233ca6fda8483cd0012c7895889f659ad236c","eefb32e3ef6dc5b176b5121ed7a7991ded7d89d0f08c50d4493143d001bfb6b2"]
Anchored
2026-08-19
Public log entry
search.sigstore.dev, log index 2513934798 · entry 108e9186e8c5677abbfa…
Expected log hash
4398d73a28baccf419c99b11cbeb8ef2e4242701bb0cc17960e1b5f329faf480 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1787122088277","kind":"published-quote","locale":"en","page":"brand:worldline","quote":"device verification failed","rating":1,"review_date":"2025-10-29","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=eu.softpos.softposwrapper.wl","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (0148d24ff6e9…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.