Skip to main content

Governance / Case File

CASE FILE

Case File governance intelligence tracks institutions, policy processes, standards activity, registry operations, accountability disputes, and implementation signals that affect internet infrastructure. BTW.

Institutional BreakdownLegal and Policy ConflictElection and Control Risk
CASE FILE signal visual
Governance / Case FileCASE FILE
Active Dossiers1 Live Case

AFRINIC saga currently tracked end-to-end.

Primary DomainGovernance

Institution legitimacy and continuity risk mapping.

MethodSignal + Timeline + Failure Paths

Primary-source based timeline and risk analysis.

Decision ValueHigh

Used for continuity and policy exposure planning.

Latest Coverage

Latest from CASE FILE

807 articles

An abstract four-stage editorial still life with separate review, credential, revision and release surfaces linked by thin brass rails.

CASE FILE

At Mozilla, a Module Owner’s OK Is Neither Commit Access Nor a Firefox Release Promise

Mozilla’s public governance material makes a useful distinction that reporting often erases. A module owner or peer can approve a change for a module; a person can separately be granted repository access; a change can be checked in or landed; and Firefox can later move code…

Sep 6, 2026
A luminous browser address bar reaches a delayed satirical page across a court file and registrar lock.

CASE FILE

The Parody Began After the Address Bar: PETA v Doughney

A joke can be obvious on a page and absent from the address that brought the reader there. That timing problem sat at the centre of *PETA v Doughney*. Michael Doughney said his “People Eating Tasty Animals” site parodied People for the Ethical Treatment of Animals. The Fourth…

Sep 5, 2026
Five provisional document folios are paired one-to-one with five brass-framed final folios along a single archival comparison rail

CASE FILE

WTPF-26 Adopted Five Opinions. Each Final Text Matches Its Last Public Draft

Five documents left WTPF-26 with new numbers, new dates and the word `DRAFT` removed. Their authority state had changed: the Forum had adopted them. Their substantive English text had not. A pairwise comparison of the last public temporary documents with the five final Opinions…

Sep 5, 2026
A telephone receiver, a 24-hour clock and an enclosed transfer mechanism before a courthouse reflection.

CASE FILE

The Two Letters Were Not the Whole Case: Virtual Works v Volkswagen and the Call About `vw.net`

A two-letter domain can look like a conclusion. `vw.net` resembled Volkswagen's famous mark, and short addresses were scarce. But the Fourth Circuit refused to make resemblance do all the work. Its judgment followed a sequence: what Virtual Works' principals discussed when they…

Sep 5, 2026
A luminous notification beacon leaves a repository while one server chamber contains complete data blocks and another remains empty, splitting the load-balanced delivery path.

CASE FILE

The Notification Arrived. One Backend Still Had Nothing to Serve

The IETF is asking for final comments on a proposed operating guide for RPKI publication services. Its sharpest rule is also the easiest to violate during a routine rollout: do not expose the new notification until every snapshot and delta it names is already available. An index…

Sep 5, 2026
Abstract route-candidate capsules cross a BGP carriage gate into an independent multi-source policy selection chamber; only the chamber-selected green path crosses a separate forwarding installation gate.

CASE FILE

The Candidate Path Reached BGP. The Forwarding Plane Had Not Voted: RFC 9830

A controller advertises two Segment Routing candidate paths to a headend. Both arrive over valid BGP sessions. One wins BGP's comparison for its advertisement; the other remains a distinct route because its Distinguisher differs. Neither fact says which candidate the SR Policy…

Sep 5, 2026
A sealed message leaves a challenge vault but only the complete upper path crosses separate custody beacons, list distribution, identity transformation, signing, certificate rollover and outbound relays to a distant mailbox.

CASE FILE

The Challenge Released the Message. It Still Had Not Reached the List

The IETF plans to replace the machinery behind its email services on 11 September. The design usefully separates challenges, list handling, identity rewriting, signing and outbound transport. It also makes the central operating question unavoidable: when one component reports…

Sep 5, 2026
Two abstract revocation-list capsules approach a signed manifest plane; the larger amber counter stops while a cyan hash-matched object and independent certificate reference converge before separate validation and routing gates.

CASE FILE

The CRL Number Was Higher. RPKI Still Had to Ignore It: RFC 9829

A relying party retrieves two signed revocation lists from one publication point. The first carries the larger CRL Number. The second is the file named by the certificate and hashed on the issuer’s current manifest. A generic PKI instinct says to trust the larger counter. RFC…

Sep 5, 2026
Five independently marked record streams meet a neutral cyan correlation lattice while an empty gap and amber conflict remain visible beside separate effect and outcome witnesses.

CASE FILE

The Trace Linked the Action. It Did Not Prove the Authority

A new IETF discussion list asks how an agent’s intent, delegation, changing permissions and external actions can be followed across services. The hard part is not inventing a universal trace identifier. It is preventing that identifier—and the agent’s own account of events—from…

Sep 5, 2026
Four ordered geometric tag tokens split into full-capacity and two-token limited-capacity router chambers, while separate aggregation, ECMP and policy paths preserve the provenance boundaries.

CASE FILE

The Tag List Kept Its Order. It Still Lost Part of the Policy: RFC 9825

Four administrative tags left an OSPF area in the intended order. The next router supported only two. Its log said the list had been preserved; its policy engine therefore looked healthy. Yet the action-bearing tag had occupied the third position. No field was reordered, no…

Sep 5, 2026
A cyan candidate tool-call stream meets a narrow argument-comparison gate while a separate amber authorization path arrives from above and a receipt trail returns below.

CASE FILE

The Token Authorized the Tool. It Did Not Authorize These Arguments

OAuth can establish that an agent may call a payment, messaging or infrastructure tool. The dangerous decision comes one layer later: whether the exact destination, amount, command and live form state produced by the model are the act a principal or governed policy approved. An…

Sep 5, 2026
A neutral DNS header ring floats above a cyan signed absence chamber; capability relays split into different downstream presentations while repeated queries return to a bounded signing chamber.

CASE FILE

The Header Said NOERROR. The Signed Body Said the Name Did Not Exist: RFC 9824

A security pipeline closed a nonexistent-domain alert because the DNS header said `NOERROR`. The validating resolver had reached the opposite conclusion from the signed NSEC evidence: the queried name did not exist. Neither observation was fabricated. One component had read the…

Sep 5, 2026
Two redundant service-record proxies carry an amber stale copy and a cyan current update into a neutral recency gate, followed by a separate service-verification chamber.

CASE FILE

The Older Service Record Won. The Service Had Already Moved

A name collision is supposed to stop a newcomer from impersonating an established local service. Put two registration proxies between the service and that local link, however, and the same safeguard can protect yesterday’s address from today’s legitimate update. DNSSD’s proposed…

Sep 5, 2026
A constrained peer and authenticator exchange two separate protected messages between matched derived-context chambers; disposable resource gates, a separate policy branch, overlapping old and new state, and a deletion acknowledgement show that method success is not authority.

CASE FILE

The EAP Method Succeeded. The Protected Session Still Needed a Second Witness: RFC 9820

The access controller displayed three green facts: the EAP method had succeeded, the Master Session Key had been exported, and the constrained device had been placed in the security domain. Only the first two facts could be reconstructed. No one could produce the protected…

Sep 5, 2026
Three crystalline ML-KEM modules pass through registry apertures toward a neutral recommendation plane, while a separate operator switchyard and canary remain downstream.

CASE FILE

The IESG Approved Three ML-KEM Groups. The Registry Recommended None

An approved IETF document can define exactly how three post-quantum groups travel through TLS while leaving the deployment verdict deliberately unresolved. That is not bureaucratic ambiguity. It is a precise boundary between an interoperable mechanism, a registry coordinate and…

Sep 5, 2026
A bounded program chamber inside a programmable network device links an authorization token and artifact fingerprint to finite resources, instance state, output, independent override, rollback and quarantined residue.

CASE FILE

The Switch Executed the Program. It Did Not Inherit the Right to Read, Rewrite or Decide: RFC 9817

A program that runs inside a switch or network interface card is no longer merely near the traffic. It can become part of the path by which traffic is classified, transformed, delayed, replicated or converted into a control action. RFC 9817 catalogs the opportunity and, more…

Sep 5, 2026
Three separate attestation evidence chambers and a freshness ring stop short of a closed certification decision aperture, leaving the CSR key-to-platform joins visibly incomplete.

CASE FILE

All Three Attestations Were True. They Still Did Not Belong to the CSR Key

A certification request can arrive with one valid statement about an HSM, another about corporate ownership and a third about platform health. The dangerous moment comes when a certificate authority treats three successful checks as one joined fact. Revision 29 of an IETF draft…

Sep 5, 2026
One luminous timing oscillator splits into three IPv6 Neighbor Discovery paths, while a separate bank of counters is cut off by broken causal joins and a discontinuity ring.

CASE FILE

One Timer Drove Three IPv6 Decisions. The Counters Could Not Explain Which One

A network team changes one millisecond value on an IPv6 interface. Address resolution, reachability probing and duplicate-address detection all inherit it. The edit receipt is precise; the operational meaning is not, until the team joins the change to an interface, an epoch and…

Sep 5, 2026
A central translucent route reflector redistributes paired topology tokens above a fabric while endpoint instruments observe a broken directional link the reflector cannot see.

CASE FILE

The Route Reflector Distributed the Link. It Never Witnessed It: RFC 9815's Sparse-Peering Evidence Boundary

A route reflector can hold the newest authenticated account of a data-centre link and still know nothing directly about whether that link carries a packet. RFC 9815 makes this separation operationally useful: BGP can distribute a link-state graph over far fewer sessions than the…

Sep 5, 2026
Two IPv6 payloads cross a dual enforcement boundary: one without a segmented header reaches a local function aperture, while one with a segmented ribbon only transits above finite hardware tables.

CASE FILE

The Packet Had No SRH. It Could Still Target an SRv6 SID

An edge filter inspects an IPv6 packet, finds no Segment Routing Header and lets it pass. The packet still carries a locally instantiated SRv6 SID as its destination. The visible header test succeeded; the admission decision examined the wrong fact.

Sep 5, 2026

Member Unlock

Restricted Profile Intelligence

Login is required to unlock full profile briefings and deep-dive sections.

Only for Strategic Circle

Strategic Circle Briefing

Join to unlock strategic briefings after signing in.

Join Strategic Circle
Only for Leadership Alliance

Leadership Alliance Briefing

For qualified IP-asset owners and management; sign in to unlock alliance briefings.

Join Leadership Alliance

Session Map

Active Dossiers

AFRINIC Saga

Multi-year governance and legal crisis with implications for RIR accountability worldwide.

Open AFRINIC Saga