Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“The application hasn't worked on my Chromebook for about two weeks.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
dbc4eca70ceda0b860c789aec53a1fe3e16e2001a560ccb5d19b9a8cc216d24b
Signature (Ed25519, base64)
Ldu367Ggv8WNBdA2dw5gRQ6FTorQf3gExvtcqCzgDzIy58zzrDjrMZZ3pPLDVynMeaR8rF/ztQTm1CTNoEF9Bw==
Merkle root
4dc0bd79ba3e9442f7f1feb21f347e2f6fdbc72e99098aa5164776a6202654a8
Merkle path
["dbc4a76ef7025fcbdf669a73b31243363ff1456f8f9e41a0bae60151b2337025","8e5f3e0acc44e990ff4cb67ef777efd9f6fbcb447e1b9317ef22a4ce013c27b6","eb3199a0bdb727c2be947333f9ec2040fdfe287d0c23d8850691c3717ff91577","978c8111deb8f00943189bd0271879639e5a21807301a6e799ae91463e610abb","8112acdbaef5a080277ec5eb3f06016d41a76de94de8cf28c1442dffaa8e02a2","7fb364fbd7a922bb9b4c4c586d4cbd267ce6097080188162e8bad673e1fa0c17","8d7f263994d294f9cc5e1bd64474af75aa4fcc38907a708e1f1ebe36dddb2c4f","a88cd462553f82dd6ed52f5591ac36bec85d7dfc5145a65dd5fbdde259b49ec2","cd997f3291837072e156c7984013190f3beef17b7f980c498bee156b42527b5a","db6238ff79600f3cce5aa8abe1efc17745536e568bde32eaa444e33bf99c33cd","187a1f07030b8b125801665ce22924bc0738652ba583a5ee68704d61a48de763","482bdf1391d0b24847060d923fe2ccef8409f6ecea289eb781f1c7381a2d2a53","92ce7b112a5230537628edf62c10d3699180f9c58135530242c50c3d07cb3a9c","6ca8568b4e7c7e4e3b794231ecbe4a3822994a26c5f3f7fd0671946fee25f414","66f93059eee3676095d6925b7cc2fe3b97c348e816a4d3ce47c4b00902d3a227"]
Anchored
2026-09-10
Public log entry
search.sigstore.dev, log index 2776103867 · entry 108e9186e8c5677acd4f…
Expected log hash
2498329b7eaf275d309293dfbac35d05dfb8a55c65956add8448561c05945f28 The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1788848066028","kind":"published-quote","locale":"en","page":"theme:bitwarden/delivery/en","quote":"The application hasn't worked on my Chromebook for about two weeks.","rating":1,"review_date":"2025-03-14","source":"Google Play","source_url":"https://play.google.com/store/apps/details?id=com.x8bit.bitwarden","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (4dc0bd79ba3e…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.