Withdraw witness

Trails, so you can check them yourself

Every measurement run of the withdraw witness writes an append-only log: each entry carries the hash of the one before, checkpoints are signed, and checkpoint roots are timestamped by a third party (DigiCert, RFC 3161). The runs below are published in full — log, checkpoints, tokens — together with the public key that was published before each run.

The step-by-step guide is at /.well-known/logsiegel-verify.txt (German); the keys are at /.well-known/logsiegel-pubkey.txt.

RunPurposeKeyFiles
2026-09-18-fra1Experiment Nr. 1, Lauf 1 — Drain fra1-lab (Virtua FRA)ed25519:48586555edeac5bbMANIFEST.txt
2026-09-18-ewr1Experiment Nr. 1, Lauf 2 — Drain ewr1 (Vultr NJ)ed25519:55a24b2cf3462636MANIFEST.txt
2026-09-19-fra1Experiment Nr. 1, Lauf 3 — Rückkehr nach Wartung, Drain fra1-lab (Virtua FRA)ed25519:70ca7594ff7ebc9eMANIFEST.txt
2026-09-23-fra1-t3t7T3/T7 Drain fra1 (Vultr Frankfurt (AS20473)), Rückkehr nach Wartung mit echtem Verkehr und Nutzersichted25519:0f3d3f9fc96e487fMANIFEST.txt
2026-09-23-fra1-lab-t3t7T3/T7 Drain fra1-lab (Virtua Frankfurt (Kunde von AS35661)), Rückkehr nach Wartung mit echtem Verkehr und Nutzersichted25519:58334e673695e7a8MANIFEST.txt

What is not here

Raw measurement payloads, private keys and operational data are not part of a trail and are not published. A trail holds the entries themselves, their hashes, the signed checkpoints and the timestamp tokens.

Measurement entries come from two sources: RIPE Atlas (RIPE NCC, atlas.ripe.net), marked atlas-feed or atlas-feed-t7, and our own hosts.

What this proves and what it does not

It proves that these entries are unchanged, in this order, and that the trail existed in this form before the timestamps — not that it is complete, and not that our own clock is right. Section 6 of the guide says so in detail, and the times that matter come from RIPE, where you can pull them yourself.