The Fediverse Instance and the Public Key Directory server could negotiate a shared secret, that only instance administrators possess. Then, every successful BurnDown would require this OTP in addition to a valid signature.
Operationally, this is reasonable, as the intent for BurnDown was to always require a deliberate administrative action.
Related to #42.
This would have revocation issues, naturally. If someone's server gets hacked, the attacker would need a valid TOTP to reset the secret. But if the legitimate admin loses the secret, they can no longer issue BurnDowns for the instance.
The Fediverse Instance and the Public Key Directory server could negotiate a shared secret, that only instance administrators possess. Then, every successful BurnDown would require this OTP in addition to a valid signature.
Operationally, this is reasonable, as the intent for BurnDown was to always require a deliberate administrative action.
Related to #42.
This would have revocation issues, naturally. If someone's server gets hacked, the attacker would need a valid TOTP to reset the secret. But if the legitimate admin loses the secret, they can no longer issue BurnDowns for the instance.
(Suggestion from @raphaelahrens.)