Skip to main content

Governance / Case File

CASE FILE

Case File governance intelligence tracks institutions, policy processes, standards activity, registry operations, accountability disputes, and implementation signals that affect internet infrastructure. BTW.

Institutional BreakdownLegal and Policy ConflictElection and Control Risk
CASE FILE signal visual
Governance / Case FileCASE FILE
Active Dossiers1 Live Case

AFRINIC saga currently tracked end-to-end.

Primary DomainGovernance

Institution legitimacy and continuity risk mapping.

MethodSignal + Timeline + Failure Paths

Primary-source based timeline and risk analysis.

Decision ValueHigh

Used for continuity and policy exposure planning.

Latest Coverage

Latest from CASE FILE

764 articles

Two identical luminous data streams reach a glass trust boundary; one dissolves at entry while an internal verification engine creates the stream that continues.

CASE FILE

The Header Said DKIM Passed. It Did Not Say Who Ran the Test: Authentication-Results and the Authority of a Trust Boundary

Two messages arrive with the same line near the top: `Authentication-Results: mx.example; dkim=pass`. One line was written by the receiver after it checked the signature. The other was supplied by the sender before the SMTP connection began. A downstream rule sees identical…

Aug 27, 2026
A glass certificate object faces two separate dark service corridors, while only one corridor forms a complete illuminated chain of DNS trust anchors.

CASE FILE

The Certificate Was the Same. The Service Name Was Not: DANE TLSA and the Authority of a Port-Bound Assertion

The certificate chain was identical on two listeners. One DANE-aware client accepted it; the other rejected it. Nothing cryptographic had changed inside the certificate. The selected service had changed, and the DNS assertion was never written for that second port.

Aug 27, 2026
Cutaway view of an internal policy mechanism steering one incoming fibre flow toward the longer of two available egress paths.

CASE FILE

BGP’s quiet instruction: who gets to prefer an exit?

LOCAL_PREF can send traffic towards a longer path without telling an external neighbour why. Its power lies in the local policy behind the number—and in whether that policy survives the journey from a border router to actual packets.

Aug 27, 2026
A certificate chain crosses an amber timestamp boundary; certificates before the cutoff remain blue and trusted, while a later certificate is isolated behind a red browser-trust barrier.

CASE FILE

The Certificates Did Not Expire: Chrome's Entrust Cutoff Turned Trust Into an Operating Licence

The decisive field was not the expiry date printed inside a TLS certificate. It was the timestamp proving when that certificate entered the public record—and whether Chrome still accepted the authority behind it at that moment.

Aug 26, 2026
Separate streams of glass records pass through differently ordered brass field frames, with an isolated old frame across a broken session boundary and uncollected blocks before a selection grate.

CASE FILE

The Template ID Was Familiar. The Flow Still Needed Its Exporter: IPFIX and the Authority of an Observation Domain

The collector saw Template ID 256 after an exporter reconnected. It reused the definition cached from the old transport session, and the incoming bytes still produced plausible counters. The dashboard was orderly, the parser was satisfied and every field name was wrong. Nothing…

Aug 25, 2026
A sealed domain complex connects through one narrow DNS delegation bridge to a small validation zone that can activate certificate issuance while deployment, observation and revocation remain separate.

CASE FILE

The TXT Record Was Correct. The Vendor Still Wasn't the Domain: ACME DNS-01 and the Authority of Delegated Validation

The vendor had been removed from the application, CI and staff accounts. One control survived: `_acme-challenge` still delegated to its validation zone. When the vendor's ACME account requested a wildcard certificate, the expected TXT digest appeared and every protocol check…

Aug 25, 2026
Two routing nodes are joined by many cyan route paths; one amber route crosses a circular count boundary and the central BGP session splits, forcing prior paths toward alternatives or dead ends.

CASE FILE

When a Route Counter Becomes a Kill Switch: Governing BGP Maximum-Prefix

A BGP maximum-prefix limit is often presented as a protective ceiling. Its real significance is more demanding: depending on the implementation and action, a count of routes can authorize the withdrawal of an entire session. The control is defensible only when the network can…

Aug 25, 2026
Two abstract name-resolution paths lead to different server-key pedestals while a separate intent compass, external port sockets and two cache clocks expose the limits of an SSHFP match.

CASE FILE

The DNS Answer Was Secure. The Host Was Still a Policy Choice: SSHFP and the Authority of a Fingerprint

An operator typed `ssh db`. A network-supplied search path expanded the short name to a different fully qualified host. Its DNSSEC chain was Secure, its SSHFP fingerprint matched and its server held the corresponding private key. Every proof was valid for the host the client…

Aug 25, 2026
A cyan signature instrument validates a bounded document region while an appended paper tail extends outside it and separate amber-red domain tokens remain unaligned above.

CASE FILE

The Signature Passed. The From Address Still Wasn't the Signer: DKIM and the Authority of a Domain Signature

The message displayed `bank.example` as its From identity, carried an urgent payment instruction and passed DKIM. The result was genuine—but for `receipt-alert.example`, a domain controlled by the attacker. A valid signature had been promoted into authority over a different name.

Aug 25, 2026
A luminous stream containing one red anomalous byte passes a checksum instrument, while an empty identity socket and closed authority gate remain separated beyond a glass boundary.

CASE FILE

The Digest Matched. The Sender Was Still Unknown: HTTP `Content-Digest` and the Authority of a Checksum

The policy upload carried a valid `Content-Digest`. The service recomputed the hash, displayed a green “verified” badge and applied the file. The file was malicious. Nothing had been corrupted in transit; the attacker had chosen both the bytes and the checksum.

Aug 25, 2026
A sequence of proxy planes carries a floating client claim toward an origin, where a red trust boundary stops it before a closed access gate.

CASE FILE

The Header Named the Client. The Peer Address Did Not Agree: HTTP `Forwarded` and Proxy-Chain Authority

The origin normally sat behind two reverse proxies. One night a requester reached it directly, supplied an administrator's allowlisted address as the first `X-Forwarded-For` value, and crossed an IP rule. The header parser returned exactly what it had been asked to return. The…

Aug 25, 2026
An anonymous name token selects one illuminated certificate-bearing TLS context while a separate authorization vault remains closed beside an empty identity socket.

CASE FILE

The Name Selected a TLS Context. It Did Not Authorize the Request: SNI and the Authority of a Routing Hint

The gateway received `tenant-a.example` in a ClientHello, selected Tenant A's certificate, and attached Tenant A's policy context. It then let the connection reach a privileged route without a tenant credential. Every TLS selection step had worked. The error was believing that a…

Aug 25, 2026
A silver certificate-signature aperture succeeds before a separate amber secret-and-transcript chamber refuses a misaligned handshake artifact, leaving the application corridor dark.

CASE FILE

The Certificate Signature Passed. The Handshake Was Not Finished: TLS 1.3 `Finished` and Transcript Authority

The dashboard declared a secure session when the server's CertificateVerify signature passed. One record later, the client rejected a corrupt `Finished` message and closed the connection. The certificate key had proved one thing accurately. Operations had promoted it into proof…

Aug 25, 2026
Two cool cyan data lanes terminate at a central metal edge appliance, while one separate amber lane begins on the other side and runs toward an origin rack.

CASE FILE

The Edge Negotiated HTTP/2. The Origin Still Spoke HTTP/1.1: TLS ALPN and the Authority of One Connection

The browser offered `h2` and `http/1.1`. The edge selected `h2`, completed TLS and exchanged valid HTTP/2 frames. A fleet dashboard then labelled the origin “HTTP/2 native.” It was not. The edge terminated that connection and opened a different one upstream, where it sent…

Aug 25, 2026
Multiple certificate candidates enter a cyan selection rail, one chain passes a white verification aperture beside a separate trust-anchor core, and a later amber authorization boundary rejects the identity.

CASE FILE

The CA Was on the List. The Identity Was Not Approved: TLS `certificate_authorities` and the Authority of a Selection Hint

The client chose a certificate whose issuer appeared in the server's CA list. The server built and validated the chain. Then the application rejected the subject because that identity had never been admitted to the tenant. Every cryptographic step could be correct while access…

Aug 25, 2026
An intact amber signed OCSP capsule passes a later red revocation boundary, above separate certificate identity, responder delegation, three clocks, chain coverage and client decision mechanisms.

CASE FILE

The Staple Was Signed. The Status Could Still Be Stale: TLS OCSP and the Authority of a Cached Answer

The certificate was revoked at 10:07. At 10:11, the server still stapled a correctly signed `good` OCSP response whose `nextUpdate` was hours away. Nothing had been forged. The answer was authentic, within its declared interval and already behind reality. The incident began when…

Aug 25, 2026
Two glass data rails show an amber TLS sending direction sealed while the cyan reverse direction remains active above separate message, transport and green commit boundaries.

CASE FILE

The Socket Closed. The Transaction Did Not: TLS close_notify and the Authority of an Ending

The payment service wrote a success response, initiated an orderly TLS shutdown and recorded the request as complete. Its database commit failed milliseconds later. The client had received an authentic ending, but not the fact it needed. `close_notify` said the server would send…

Aug 25, 2026
An amber session ticket crosses from a shattered old connection through a validator into a new cyan key tree while stale red authorization is stopped at a separate gate.

CASE FILE

The Ticket Survived. The Session Did Not: TLS 1.3 Resumption and the Authority of Carried State

The failover node accepted a TLS 1.3 session ticket issued before the user’s access was revoked. Cryptographically, the shortcut worked: the client knew the resumption PSK and its binder covered the new handshake. Operationally, the old decision had crossed into a new connection…

Aug 25, 2026
Three transparent inner records contain different content and zero-padding proportions but emerge as equal-length opaque ciphertext capsules.

CASE FILE

The Record Was Longer. The Message Was Not: TLS 1.3 Padding and the Authority of Observable Length

The incident report treated a larger encrypted record as a larger application message. Its arithmetic was precise and its conclusion was false. The sender had rounded TLS 1.3 records to a block boundary and sometimes emitted padding-only Application Data. The capture established…

Aug 25, 2026
A continuous transcript rail carries a multi-option first offer through one narrow retry gate into a single-share second offer.

CASE FILE

The First Hello Was Rejected. It Was Not Erased: TLS HelloRetryRequest and the Authority of the Transcript

The capture began with a second ClientHello. It offered one key share, the server accepted it, and the handshake completed. Read in isolation, the trace appeared to prove that the client had chosen that group from the start. It proved nothing of the kind. The missing first flight…

Aug 25, 2026

Member Unlock

Restricted Profile Intelligence

Login is required to unlock full profile briefings and deep-dive sections.

Only for Strategic Circle

Strategic Circle Briefing

Join to unlock strategic briefings after signing in.

Join Strategic Circle
Only for Leadership Alliance

Leadership Alliance Briefing

For qualified IP-asset owners and management; sign in to unlock alliance briefings.

Join Leadership Alliance

Session Map

Active Dossiers

AFRINIC Saga

Multi-year governance and legal crisis with implications for RIR accountability worldwide.

Open AFRINIC Saga