diff --git a/docs/rotation-keys.md b/docs/rotation-keys.md index aed005c..6a920ca 100644 --- a/docs/rotation-keys.md +++ b/docs/rotation-keys.md @@ -4,15 +4,17 @@ Recap Time Squad maintains two distinct PLC rotation keys: one for the productio These keys are generated using `goat key generate` command on Andrei Jiroh's NixOS laptop -## Production PDS Rotation Key +## Available keys -**Public key**: `did:key:zQ3shqgB6GTB4UDsiNCDtZwDN3knzVAaYgna8WyvPF2qPWNg9` (K-256 / secp256k1) +### Production PDS Rotation Key + +**Public key**: `did:key:zQ3shqgB6GTB4UDsiNCDtZwDN3knzVAaYgna8WyvPF2qPWNg9` (K-256 / secp256k1, currently in-use), `did:key:zDnaex4piMNmwKHa9JFjVujw63AdHGyADS9A4GVqWG24W11th` (P-256 / secp256r1, backup/unused) **Link to the vault item (internal only to Recap Time Squad Crew):** This key is primarily used in production by default for fresh and newly-migrated accounts on our PDS service, as set in the `PLC_ROTATION_KEY` variable in our production `.env` file (encrypted via `dotenvx`). This key is used to sign routine PLC updates like updating account handles and switching the `AtprotoPersonalDataServer`/`#atproto_pds` service in case we change `PDS_HOSTNAME` in the future. -## Recap Time Squad HQ Account-Level Rotation Key +### Recap Time Squad HQ Account-Level Rotation Key **Public key**: `did:key:zDnaeR1hzR5NrD3iQx6W91NaT9S4cctcsHsP6EMHF8isGfvUh` (P-256 / secp256r1) @@ -40,3 +42,9 @@ goat account plc add-rotation-key --token=ABCDE-12345 did:key:zDnaeR1hzR5NrD3iQx If you use the PDS Moover webapp to set up repo backups for your account or similar GUI-based tool to manage repo backups and keys, you can add our key in addition with your own keys when prompted. Alternatively, you can migrate to our PDS instance instead since it will automatically use the PDS-wide rotation keys once you complete the migration flow. To initiate the account recovery flow, [contact Andrei Jiroh](https://andreijiroh.dev/contact) with the details about your situation (i.e. account handle, whether your account was banned (aka takendown) for any reason or not (hacked servers/account takeovers also count here), and whether you have backups of your account data). If you do have your own keys added to your account, we recommend doing the self-serve recovery flow first at unless you lost it. You will be asked to verify your identity by showing proof of account ownership (i.e. email address used to create that account OR the current one on your current/former PDS) to protect your account from unauthorized access and minimize social engineering attacks. + +### Account Recovery Cookbook + +See [Using your key for recovery in the AT Proto Docs about Account Recovery](https://atproto.com/guides/account-recovery#using-your-key-for-recovery) and [David Bunchanan's guide on adversarial PDS migration](https://www.da.vidbuchanan.co.uk/blog/adversarial-pds-migration.html) for details. We recommend having a backup of your/their account data such as repository CAR files, blobs, and private data (i.e. app preferences) handy for this process. + +For those who entrusted us with account recovery by adding our keys to their account, make sure you have access to the private keys [as documented above](#available-keys) before proceeding with the recovery process. If they sent us the details on where PDS to switch to rather than just using ours, make sure they have received a invite code to the PDS they want to switch to if required.