imagine instance A posts something, it federates to instance B, but the post hasn't reached instance C. let's say B is a malicious actor, so B will send a post to C with the same ID as the previous post. B does that with every incoming post. C wouldn't be able to tell what posts are legit, and multiple posts can't have the same id.
what would happen? what am I missing? AP can't be THAT broken, right?