Hijacking Bluesky Identities with a Malleable Deputy

from blog David Buchanan's Blog, | ↗ original
By David Buchanan, 28th September 2023 If you don't live under a rock, you might've heard of Bluesky, a decentralised social microblogging app built on top of the AT Protocol. In early June 2023, I identified a vulnerability in Bluesky's core user identity mechanism, did:plc, which allowed me to modify the identity information...