AFRINIC saga currently tracked end-to-end.
Governance / Case File
CASE FILE
Case File governance intelligence tracks institutions, policy processes, standards activity, registry operations, accountability disputes, and implementation signals that affect internet infrastructure. BTW.

Institution legitimacy and continuity risk mapping.
Primary-source based timeline and risk analysis.
Used for continuity and policy exposure planning.
Latest Coverage
Latest from CASE FILE
762 articles

CASE FILE
The Neighbor Suggested a Door; We Chose Whether to Enter: BGP MED and Advisory Authority
The Neighbor Suggested a Door; We Chose Whether to Enter: BGP MED and Advisory Authority intelligence summary explains the development, the public evidence available to readers, the organisations involved, the regional context, market exposure, and the infrastructure consequences…

CASE FILE
The Route Chose Three Times, the Neighbor Heard Once: BGP MRAI and Temporal Authority
A BGP router can change its mind several times while saying nothing new to one neighbor. The silence is not indecision. MRAI deliberately separates local route selection from external disclosure, trading the peer's freshest possible view for bounded UPDATE traffic and processing…

CASE FILE
The Server That Remembered Nothing: SYN Cookies and Stateless Admission
A listening server usually spends memory after the first knock and before it knows whether anyone can hear the answer. A SYN cookie changes that order. The server places a compact receipt for the unfinished connection inside its own sequence number, then waits for the requester…

CASE FILE
The Key Installed Twice: KRACK and the Authority of a Retransmission
Wireless loss made retransmission necessary. KRACK exposed the hidden assumption that arrived with it: an authentic copy of a handshake message could be treated as fresh authority to install an already-active key. The password held. The key stayed secret. The state around the key…

CASE FILE
The Failure That Chose the Cipher: POODLE and the Authority Hidden in Fallback
A failed TLS handshake should have been evidence of one thing: this connection attempt did not work. Compatibility code turned it into a much larger claim - that the server needed an older protocol. POODLE showed what happens when an attacker who can cause failure is also allowed…

CASE FILE
The Header That Became a Program: Shellshock and the Authority Hidden in an Environment
Shellshock did not require an exotic packet or a new network protocol. It needed two familiar interfaces to compose badly: one that placed remote request data in a process environment, and one that treated a specially shaped environment value as code. The incident remains a hard…

CASE FILE
The Patch Had Six Months. Slammer Needed Ten Minutes.
On 25 January 2003, the useful unit of incident response stopped being the working day. A 376-byte program could arrive in one UDP datagram, seize an unpatched database service and begin sending copies without waiting for a reply. The repair had already been published. The…

CASE FILE
The Cache That Answered 51,000 Times: Memcached and the Bandwidth Nobody Meant to Delegate
A reflector attack begins with a peculiar transfer of authority: one machine lies about who asked, another machine believes the return address, and a third party pays for the answer. In February 2018, public memcached servers made that transfer large enough to move GitHub's…

CASE FILE
The Answer That Won the Race: Kaminsky's DNS Poisoning and the Entropy Behind Trust
The dangerous answer did not need a signature or a privileged route; it only had to resemble one outstanding question closely enough and arrive first. The 2008 DNS crisis turned that narrow acceptance rule into a renewable race—and showed why a patch can buy safety without…

CASE FILE
The Rule That Reached Every Edge Before Anyone Priced It: Cloudflare's 2019 WAF Outage
Cloudflare's distributor needed seconds to place one approved security rule around the world; the incident lasted because approval had established what the rule should catch, not how much computation every request could make it consume.

CASE FILE
The Page That Borrowed Another Customer's Memory: Cloudbleed and the Boundary of a Shared Edge
A malformed page triggered Cloudflare's parser, but the escaped bytes could belong to somebody else entirely; Cloudbleed showed that stopping a leak and recovering what had already crossed the boundary are different acts of control.

CASE FILE
The Certificate That Was Valid for the Wrong Job: Flame and the Authority Hidden in Purpose
The Flame malware did not need Microsoft's root private key. It found a licensing certificate path whose mathematics, issuance habits and inherited trust could be rearranged into software-signing authority.

CASE FILE
The Request That Vanished but Kept Working: What Rapid Reset Revealed About Cancellation
HTTP/2 let a client withdraw one request without closing the connection; Rapid Reset exposed the moment when that valid cancellation stopped being a courtesy and became an unlimited claim on somebody else’s queues.

CASE FILE
The Patch That Could Not Retire a Key: Debian's OpenSSL Entropy Failure and the Afterlife of Weak Credentials
The repaired library stopped minting predictable keys. It did not find the old ones, remove them from remote authorization files, revoke their certificates or persuade a single relying party to refuse them.

CASE FILE
The Signature That Demanded Every Key: What KeyTrap Revealed About the Cost of Trust
KeyTrap turned a valid-looking DNSSEC workload into a claim on somebody else’s processor, exposing the point at which faithful verification must yield to a locally governed budget.

CASE FILE
The Root That Wasn't Sold: What Symantec's Exit Revealed About Transferable Trust
Symantec could sell its certificate-authority business, but it could not sell a command to keep trusting the old roots. That decision remained inside independently operated clients.

CASE FILE
The Route That Borrowed a Name: What the MyEtherWallet Hijack Revealed About Layered Authority
A route accepted elsewhere let false DNS answers arrive locally, but the 2018 MyEtherWallet attack still had to cross a chain of independent technical vetoes.

CASE FILE
A Verified RFC Erratum Corrects the Record Without Rewriting It
An RFC erratum can identify a real defect, supply corrected wording and be verified by the responsible parties. It still does not silently replace the published specification. That separation lets implementers learn from mistakes while preserving the text the community actually…

CASE FILE
DNSSEC Can Prove Absence Without Deciding Entitlement
A signed negative DNS answer can establish that a name or record type was absent from a particular signed zone during a bounded validity period. It cannot establish why the entry is absent, who deserves the label, whether a registrar should create it, or whether an Opt-Out…

CASE FILE
Mozilla’s Hidden Security Boundary: How the Public Suffix List Becomes Running Code
Mozilla began the Public Suffix List, and Firefox still turns a version of it into browser behaviour. The DNS can tell software that `whatwg.github.io` exists beneath `github.io`, but not whether those names belong to one organisation or mutually untrusting tenants. This article…
Member Unlock
Restricted Profile Intelligence
Login is required to unlock full profile briefings and deep-dive sections.
Strategic Circle Briefing
Join to unlock strategic briefings after signing in.
Join Strategic CircleLeadership Alliance Briefing
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership AllianceSession Map
Active Dossiers
AFRINIC Saga
Multi-year governance and legal crisis with implications for RIR accountability worldwide.
Open AFRINIC Saga