AttackLedger

Verify a report

Check an AttackLedger report yourself: its evidence chain, receipts, signatures, key and change history, and timestamps. The checks run in this browser. The file is not uploaded.

Check a report

The JSON or HTML file AttackLedger exports. It stays on your computer.

Or paste the report

Options

As --require-signatures: a receipt that carries only a name fails the signature check.

Trusted roots

Timestamps must chain to a root you trust. This page trusts the roots that verify_report.py trusts by default:

    As --tsa-root, for a timestamp authority other than DigiCert. Check its fingerprint with the authority first.

    Result

    No report checked yet.

    How this works

    Nothing is uploaded

    Your browser reads the file and the script in this page checks it. The page cannot send it anywhere: its Content-Security-Policy, sent with the page and repeated in it, sets connect-src 'none' and default-src 'none', so the browser refuses every connection the page might try after it has loaded, to us or to anyone. The script, styles and fonts are all inside this one file; nothing else is fetched. To see it for yourself, open your browser's developer tools on the Network tab while you check a report, or save this page and open it offline.

    The policy this page is served with

    default-src 'none'; script-src 'sha256-Sot8gDT9N6sdzvpLqn2EeHiRWI0n0JlFGAc24qPnszU='; style-src 'sha256-xV/22ns6SUj4Gi9JkzwvZEuo11QeHYLGxEQFdC3cMjg='; font-src data:; img-src data:; connect-src 'none'; form-action 'none'; base-uri 'none'; require-trusted-types-for 'script'; trusted-types 'none'

    The same checks as the command line

    The checks are a line-for-line port of verify_report.py, the offline verifier, and give the same verdicts and messages: the two are compared on the sample report, the demo exports and dozens of tampered copies. Signatures and hashes use your browser's WebCrypto.

    If you would rather not trust this page, run the verifier yourself. It needs only Python and no AttackLedger install:

    python3 verify_report.py report.json \
        --tsa-root digicert-trusted-root-g4.pem

    Download verify_report.py and digicert-trusted-root-g4.pem, or try it on the sample report.

    Browser support

    Any current browser. Ed25519 signatures use WebCrypto where the browser has it (Chrome and Edge 137, Firefox 129, Safari 17 and later); elsewhere the page uses the verifier's own RFC 8032 code, so they are checked either way.

    What each check means

      A skipped check neither passes nor fails: there was nothing for it to check. A signature proves the key holder signed; to tie a key to a person, compare its fingerprint with the one the signer gives you.