What happens if someone takes over an expired domain linked to a self-hosted PDS? #3482
Replies: 2 comments 1 reply
-
The worst thing the attacker could do is announce that alice's account has been deleted (via an This ought to be temporary however, since alice can update her DID document to point to a new PDS, which can broadcast a new |
Beta Was this translation helpful? Give feedback.
-
David's reply hits the main question for most accounts. Public repos are signed, and somebody getting the PDS domain should not be able to forge posts or other records without the account's cryptographic keys. Hosted blobs (eg, images) are content-addressed and can't be manipulated without detection. A related case where this can be a problem is |
Beta Was this translation helpful? Give feedback.
-
Let’s imagine Alice runs a self-hosted personal data server (PDS) at
pds.whatever.com
, and her account (using adid:plc
identifier) is tied to this domain. If Alice stops using her account for a long time and forgets to renew her domain, someone else could buywhatever.com
after it expires.If Alice’s DID keys are safe, can the attacker still do harmful things (like post fake data) ever for a short time?
Beta Was this translation helpful? Give feedback.
All reactions