> DID is resolved to hosting
Yes, via DNS, of which you have lost control if you use did:web, unless you decide to have your did:web links resolve to a secondary domain under a separate TLD, registrar, and payment method, which only the most paranoid individuals will accept the overhead of doing.
Because you lost control of DNS, the new domain controller may decide to take those DIDs offline, or direct them to a different server for which the domain controller will receive a valid web PKI cert from the likes of Let's Encrypt since domain control is used to determine ownership. This will break pre-existing links.
Your claims are true only when using did:plc, under which your identity is ultimately controlled by a third party, with associated risks, see original post. Yes, domain control is also controlled by third parties (either the TLD owner or a registrar could steal your domain), and there's a good-faith debate to be had over which is safer, which is why the reigning advice is to use a neutral TLD and boring registrar with a good reputation.
Wait until the Chinese, etc. start to come in and threaten to start to block ATProto-based social sites en-masse (Bluesky in particular but other ones as well) until plc.directory takes down the DID links to dissident content, then we'll see how small the risks of did:plc really are.