I think key rotation (recovery, history) is a higher level service that requires a social component, not just cryptography. My current thinking is baking key rotation into the did:method is a mistake. I think it can be addressed with a trusted nip05 service.
Discussion
did:method definitely a mistake
All the stuff I’ve seen on key rotation using cryptography means protecting even harder the root key. If that key gets leaked, you’re really screwed over.
Very good point. But there must be a better way. I dont think we'll find it until we try things, though. Like an evolution rather than a one shot answer.