Certification & Online Trace Collection · service active
WACZ · ISO 28500/ eIDAS timestamping/ Client area
C.E.R.T.O.
Sign in Register for free
IT EN
C.E.R.T.O. / Modules / Comparison of acquisitions
— · CONFRONTO

Comparing two acquisitions of the same page

You acquired the same page twice, some time apart. This feature tells you whether the site really changed — and how.

C.E.R.T.O. “Compare two acquisitions” screen: you choose the two BagIt packages (.zip) of the same URL and start the comparison, which runs on the computer without sending any content. Below, the history of comparisons with address, outcome (“changed” or “rendering only”), number of differences and the actions to open, export to PDF or show the folder.
Key features

What this module does.

  • It compares the resources actually downloaded from the site, not the rest of the bundle.
  • It separates a change to the site from the page rendering, which changes at every visit.
  • Perceptual image comparison: it distinguishes a re-saved photo from a replacement.
  • Text differences shown side by side, before and after.
  • Entirely local: no slots, no external service, nothing leaves the computer.
Exhibit · COMPARE-0042/26Sealed
Module
Comparison of acquisitions
SHA-256
9f2a1c7b·4e0d·a83f·11c6·5d7e9042bb1a
Double timestamp
RFC 3161 · BagIt · Ed25519
Chain of custody
What it is, exactly

It does not acquire: it reads two bundles you already have.

Every other module captures something and seals it. This one does not: it opens two already sealed bundles of the very same address and states what changed on the site between one acquisition and the other.

No slots

The comparison consumes no slots, because it queries nothing and produces no new bundle.

Entirely on your computer

No external service is called and the content of the two bundles never leaves the machine.

It answers one question

“Is the page from back then the same as today's?” — the question that arrives months later, when the other side claims never to have written that sentence.

Why it does not compare everything

44 files “modified” on an unchanged page

Two acquisitions of the very same page, two minutes apart, without touching anything.

The measured result: 62 files in common, 18 of them identical and 44 different, plus about thirty present in only one bundle. A naive inventory comparison would have declared “44 files modified” on a page that had not changed by one comma. In a forensic report that is worse than useless: it is misleading.

The reason is that almost everything inside a bundle is produced by the acquisition and not by the site: logs, network traffic, route tracing, registry queries, video, screenshots, timestamps, reports, system information. They necessarily change at every run. Even the names change, because some snapshots carry the time in the file name.

So only the resources actually downloaded from the site are compared — the bytes the server delivered — and the verdict rests on those. Widening the set “for completeness” would put the noise back in, and noise buries the change that matters.

The distinction that avoids false alarms

Did the site change, or is the page just redrawing itself?

The downloaded resources — this is the proof

The bytes the server sent. If they change, the site changed: the verdict rests on these. The comparison states how many resources have changed, how many have been added and how many are no longer there.

The page rendering — reported separately

The page after the scripts have run. It changes at every visit if there is a clock, a counter, a rotating banner or content generated on the fly. In the two identical acquisitions measured, the pages differed exactly there and nowhere else: on its own this difference does not prove the site changed, and the report says so.

What it shows

Not just “different”: what changed

The text, side by side

The page text differences in two columns, before and after, with the lines no longer there and those that appeared. Plus a measure of how similar the two texts are.

Images, with a perceptual fingerprint

A photo re-saved with different compression has entirely different bytes but is the same image. The perceptual comparison looks at structure and colour rather than bytes, and distinguishes a re-saved photo from one that has been replaced — something a hash-only comparison cannot do.

Moved images too

A picture that disappears from one address and reappears at another is not a removal: the comparison recognises it as a move, instead of counting it twice.

What the comparison does NOT do

It does not say when the change happened, nor who made it, nor whether in the meantime the page changed and reverted: it says what changed between the two moments the acquisitions were run. And it does not verify the integrity of the two bundles: for that there is the verifier included in each one, which checks fingerprints, signature and timestamps.

FAQ

Frequently asked questions

What gets compared, why not the whole bundle, images and cost: the most common questions about the Comparison.

Does it compare the entire content of the two bundles?
No, and it must not. Almost everything inside a bundle is produced by the acquisition, not by the site: logs, network traffic, video, screenshots, timestamps, reports. Measured on two acquisitions of the very same page, two minutes apart and without touching anything: 62 files in common, 44 of them different. A naive comparison would have declared “44 files modified” on a motionless page. So only the resources actually downloaded from the site are compared — the bytes that came from the server.
Why is the page rendering reported separately?
Because it changes at every visit on any page containing a clock, a counter, a rotating banner or content generated on the fly. In the two identical acquisitions measured, the pages differed exactly there and nowhere else. Confusing the two means crying foul on every living site, and in a forensic report that is worse than useless.
Does it tell a replaced image from one that was merely re-saved?
Yes: modified images are compared with a perceptual fingerprint, which looks at the structure of the image rather than the bytes. A photo re-saved with different compression has entirely different bytes but is still the same image, and is declared as such; a replaced photo is not. A hash-only comparison could not tell them apart.
How much does it cost and what is sent to the server?
It costs no slots and nothing is sent: the comparison happens entirely on your computer, without calling any external service. The content of the two bundles never leaves the machine.
Does it also verify that the two bundles are intact?
No, and the report says so: a bundle's integrity is established with the verifier included in each bundle, which checks the fingerprints, the Ed25519 signature and the timestamps. The comparison answers a different question — what changed between the two moments — and does not replace that verification.

Compare two acquisitions you already have.

Register for free and download C.E.R.T.O. Desktop for Windows and macOS from your client area.