Hacker News new | past | comments | ask | show | jobs | submit login

Is this a typo then?

This is to be used in adversarial situations in which a user's signingKey leaks or is being held by some custodian who turns out to be a bad actor.

In a situation such as this, the signingKey may be used to rotate both the signingKey and recoveryKey.

From: https://atproto.com/specs/did-plc#account-recovery

Seems to suggest the signing key is all that’s needed to change the keys for a user? I was expecting it to say the recovery key could be used for that (which only I have).




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: