You acquired the same page twice, some time apart. This feature tells you whether the site really changed — and how.
Every other module captures something and seals it. This one does not: it opens two already sealed bundles of the very same address and states what changed on the site between one acquisition and the other.
The comparison consumes no slots, because it queries nothing and produces no new bundle.
No external service is called and the content of the two bundles never leaves the machine.
“Is the page from back then the same as today's?” — the question that arrives months later, when the other side claims never to have written that sentence.
Further reading: the Web pages module, which produces the acquisitions to compare · a website's public history · how to acquire a web page as evidence.
Two acquisitions of the very same page, two minutes apart, without touching anything.
The measured result: 62 files in common, 18 of them identical and 44 different, plus about thirty present in only one bundle. A naive inventory comparison would have declared “44 files modified” on a page that had not changed by one comma. In a forensic report that is worse than useless: it is misleading.
The reason is that almost everything inside a bundle is produced by the acquisition and not by the site: logs, network traffic, route tracing, registry queries, video, screenshots, timestamps, reports, system information. They necessarily change at every run. Even the names change, because some snapshots carry the time in the file name.
So only the resources actually downloaded from the site are compared — the bytes the server delivered — and the verdict rests on those. Widening the set “for completeness” would put the noise back in, and noise buries the change that matters.
The bytes the server sent. If they change, the site changed: the verdict rests on these. The comparison states how many resources have changed, how many have been added and how many are no longer there.
The page after the scripts have run. It changes at every visit if there is a clock, a counter, a rotating banner or content generated on the fly. In the two identical acquisitions measured, the pages differed exactly there and nowhere else: on its own this difference does not prove the site changed, and the report says so.
The page text differences in two columns, before and after, with the lines no longer there and those that appeared. Plus a measure of how similar the two texts are.
A photo re-saved with different compression has entirely different bytes but is the same image. The perceptual comparison looks at structure and colour rather than bytes, and distinguishes a re-saved photo from one that has been replaced — something a hash-only comparison cannot do.
A picture that disappears from one address and reappears at another is not a removal: the comparison recognises it as a move, instead of counting it twice.
It does not say when the change happened, nor who made it, nor whether in the meantime the page changed and reverted: it says what changed between the two moments the acquisitions were run. And it does not verify the integrity of the two bundles: for that there is the verifier included in each one, which checks fingerprints, signature and timestamps.
What gets compared, why not the whole bundle, images and cost: the most common questions about the Comparison.
A real case where this module is needed: read the story.
Register for free and download C.E.R.T.O. Desktop for Windows and macOS from your client area.