| |
ATProto's Personal Data Server (PDS) architecture gives operators control over users' signing and rotation keys, allowing them to impersonate accounts across all ATProto-based apps and lock users out of their entire identity, not just a single platform. While the protocol allows users to enroll self-controlled rotation keys for protection, this feature is not the default, leaving most users vulnerable to a single compromised or malicious PDS operator who could impersonate them across multiple applications or permanently revoke their identity ecosystem-wide.
Read Full Article →
← More Tech news