There is an open questions for what is the longest chain algorithm. The service could have generated a chain of 10 rotation events and withhold them, then the user publishes his rotation, and later the service publishes its entire chain. Which one is valid?

Replies (2)

Perhaps these "service" / custodial accounts should be declared as "genesis" type, and thus be deemed ineligible for backdated key rotation?