1. This is true for did:web but less true for did:plc identities.
2. For did:plc identities to survive a full "bluesky PBC" death, you'd need to to transfer master authority for your PLC identity to a set of keys you control. If you don't then ultimately bluesky PBC would still have final authority over your identity. But if you transfer control to your own keys ahead of time then you can use those keys to make changes long after bluesky PBC's death.
This is a tool that allows you to create new recovery keys: https://github.com/renahlee/manual
Post about said tool: https://bsky.app/profile/renahlee.com/post/3lcbnab6rl22h
An article on how to do this manually: https://whtwnd.com/fei.chicory.blue/entries/How%20to%20get%2...
It's generally pretty sparse docs because everything is fairly "beta" still and because it is cryptography if you fuck it up you permanently lose control over your account forever. This is one of the reasons they don't advertise non-custodial recovery keys super aggressively.
And the protocol that is used for maintaining a ledger of key changes isn't exactly ideal or to my knowledge final but rather is in a "it's good enough until we douse the other fires" state.