Verify a report
Check an AttackLedger report yourself: its evidence chain, receipts, signatures, key and change history, and timestamps. The checks run in this browser. The file is not uploaded.
Check a report
The JSON or HTML file AttackLedger exports. It stays on your computer.
Or paste the report
Result
No report checked yet.
How this works
Nothing is uploaded
Your browser reads the file and the script in this page checks it. The page cannot send it anywhere: its
Content-Security-Policy, sent with the page and repeated in it, sets connect-src 'none' and
default-src 'none', so the browser refuses every connection the page might try after it has
loaded, to us or to anyone. The script, styles and fonts are all inside this one file; nothing else is
fetched. To see it for yourself, open your browser's developer tools on the Network tab while you check a
report, or save this page and open it offline.
The policy this page is served with
default-src 'none'; script-src 'sha256-Sot8gDT9N6sdzvpLqn2EeHiRWI0n0JlFGAc24qPnszU='; style-src 'sha256-xV/22ns6SUj4Gi9JkzwvZEuo11QeHYLGxEQFdC3cMjg='; font-src data:; img-src data:; connect-src 'none'; form-action 'none'; base-uri 'none'; require-trusted-types-for 'script'; trusted-types 'none'
The same checks as the command line
The checks are a line-for-line port of verify_report.py, the
offline verifier, and give the same verdicts and messages: the two are compared on the sample report, the
demo exports and dozens of tampered copies. Signatures and hashes use your browser's WebCrypto.
If you would rather not trust this page, run the verifier yourself. It needs only Python and no AttackLedger install:
python3 verify_report.py report.json \
--tsa-root digicert-trusted-root-g4.pem
Download verify_report.py and digicert-trusted-root-g4.pem, or try it on the sample report.
Browser support
Any current browser. Ed25519 signatures use WebCrypto where the browser has it (Chrome and Edge 137, Firefox 129, Safari 17 and later); elsewhere the page uses the verifier's own RFC 8032 code, so they are checked either way.
What each check means
A skipped check neither passes nor fails: there was nothing for it to check. A signature proves the key holder signed; to tie a key to a person, compare its fingerprint with the one the signer gives you.