Verify the manifest.
This site's PROVENANCE.json lists every file with its SHA-256 hash. Verify it here in your browser: nothing is uploaded, nothing is installed.
If you downloaded this site (the public ZIP), this page verifies two things against the manifest:
- The manifest was not altered: the hash of
PROVENANCE.jsonmust match the published fingerprint (sealed declaration + layer-1 card). - The files were not altered: the hash of each file listed in the manifest must match the recorded one.
Honest scope: this verifies that the files match the manifest. It does not verify Bitcoin anchoring (that needs ots verify), and it does not prove who wrote the content — only that the package is intact.
Step 1 — Drop the PROVENANCE.json
Drag the PROVENANCE.json file from the package you downloaded into here.
Step 2 — Drop the site files
Drag all the package files (the same ones the manifest lists). Each file is re-hashed in your browser and compared against the recorded hash.
No computer handy
If you prefer the classic route: the manifest fingerprint is published on the method page and on the sealed declaration card. Compare hashes by hand or with sha256sum.
Mathvsmyth