4 ms·
They'd need the private key to post as you. The DNS record just points to where the DID document is, but there's a verification check that the DID document poin
by thisismissem 1y ago
They'd need the private key to post as you. The DNS record just points to where the DID document is, but there's a verification check that the DID document points back, and this is automatically performed as a part of the resolution process.
DNSSEC would add additional security around DNS record changes, but not having it wouldn't allow someone to impersonate you, because your server would need to agree with that.
- captn3m0 1y agoIs there any reading material on the private-key recovery bits? I want to learn how AT manages failure scenarios, especially around key-loss.
- danabramov 1y agoThe private key is normally stored on your PDS (hosting). See https://www.da.vidbuchanan.co.uk/blog/adversarial-pds-migration.html https://www.da.vidbuchanan.co.uk/blog/adversarial-pds-migrat... for how to be prepared for adversarial migration.