Skip to main content

Governance / Case File

CASE FILE

Case File governance intelligence tracks institutions, policy processes, standards activity, registry operations, accountability disputes, and implementation signals that affect internet infrastructure. BTW.

Institutional BreakdownLegal and Policy ConflictElection and Control Risk
CASE FILE signal visual
Governance / Case FileCASE FILE
Active Dossiers1 Live Case

AFRINIC saga currently tracked end-to-end.

Primary DomainGovernance

Institution legitimacy and continuity risk mapping.

MethodSignal + Timeline + Failure Paths

Primary-source based timeline and risk analysis.

Decision ValueHigh

Used for continuity and policy exposure planning.

Latest Coverage

Latest from CASE FILE

762 articles

Two gateway arches in one network send amber and cyan recommendation tokens toward a separate circular decision hub, which selects one cyan forwarding path locally.

CASE FILE

The Neighbor Suggested a Door; We Chose Whether to Enter: BGP MED and Advisory Authority

The Neighbor Suggested a Door; We Chose Whether to Enter: BGP MED and Advisory Authority intelligence summary explains the development, the public evidence available to readers, the organisations involved, the regional context, market exposure, and the infrastructure consequences…

Aug 23, 2026
Two independent network clusters are joined by a narrow corridor; three colored route states move through a timing chamber on the left, while one cyan state reaches the decision hub on the right.

CASE FILE

The Route Chose Three Times, the Neighbor Heard Once: BGP MRAI and Temporal Authority

A BGP router can change its mind several times while saying nothing new to one neighbor. The silence is not indecision. MRAI deliberately separates local route selection from external disclosure, trading the peer's freshest possible view for bounded UPDATE traffic and processing…

Aug 23, 2026
Amber first-contact paths approach a server gate while cyan receipt tokens remain outside an empty state chamber; one returned receipt alone illuminates a single connection slot.

CASE FILE

The Server That Remembered Nothing: SYN Cookies and Stateless Admission

A listening server usually spends memory after the first knock and before it knows whether anyone can hear the answer. A SYN cookie changes that order. The server places a compact receipt for the unfinished connection inside its own sequence number, then waits for the requester…

Aug 23, 2026
A sequence of translucent handshake tiles passes above a cobalt key-state chamber, while a metal one-way ratchet diverts the repeated message onto an acknowledgement loop instead of reinstalling the key.

CASE FILE

The Key Installed Twice: KRACK and the Authority of a Retransmission

Wireless loss made retransmission necessary. KRACK exposed the hidden assumption that arrived with it: an authentic copy of a handshake message could be treated as fresh authority to install an already-active key. The password held. The key stayed secret. The state around the key…

Aug 22, 2026
Three translucent connection lanes descend toward a server gate: a dark fracture breaks the secure attempt, a small cyan retry token reaches the gate, and the cracked amber legacy lane is rejected.

CASE FILE

The Failure That Chose the Cipher: POODLE and the Authority Hidden in Fallback

A failed TLS handshake should have been evidence of one thing: this connection attempt did not work. Compatibility code turned it into a much larger claim - that the server needed an older protocol. POODLE showed what happens when an attacker who can cause failure is also allowed…

Aug 22, 2026
One amber request card crosses a gateway into a transparent environment capsule, turns into a red command waveform only inside a shell-shaped chamber, while a separate cyan path narrows the boundary and rejects a payload.

CASE FILE

The Header That Became a Program: Shellshock and the Authority Hidden in an Environment

Shellshock did not require an exotic packet or a new network protocol. It needed two familiar interfaces to compose badly: one that placed remote request data in a process environment, and one that treated a specially shaped environment value as code. The incident remains a hard…

Aug 22, 2026
One tiny amber datagram enters an exposed database server, which immediately emits a dense fan of equally small packets across a network while a separate cyan patch remains uninstalled and a local containment boundary begins to close.

CASE FILE

The Patch Had Six Months. Slammer Needed Ten Minutes.

On 25 January 2003, the useful unit of incident response stopped being the working day. A 376-byte program could arrive in one UDP datagram, seize an unpatched database service and begin sending copies without waiting for a reply. The repair had already been published. The…

Aug 22, 2026
A tiny amber UDP request crosses an edge into one explicitly open cache, expands into a vast reflected response fan, and is diverted by a separate cyan route-filtering path while other source lanes and cache sockets remain closed.

CASE FILE

The Cache That Answered 51,000 Times: Memcached and the Bandwidth Nobody Meant to Delegate

A reflector attack begins with a peculiar transfer of authority: one machine lies about who asked, another machine believes the return address, and a third party pays for the answer. In February 2018, public memcached servers made that transfer large enough to move GitHub's…

Aug 22, 2026
Amber forged DNS responses and a pale-cyan legitimate response race through separate transaction-ID and source-port mechanisms while a middlebox narrows port lanes and a signed-proof chain remains distinct.

CASE FILE

The Answer That Won the Race: Kaminsky's DNS Poisoning and the Entropy Behind Trust

The dangerous answer did not need a signature or a privileged route; it only had to resemble one outstanding question closely enough and arrive first. The 2008 DNS crisis turned that narrow acceptance rule into a renewable race—and showed why a patch can buy safety without…

Aug 22, 2026
An unmarked amber rule crystal enters a fast global rail and expands into tangled execution loops across edge-compute rings, while a separate blue path stages one node, a small cluster and a wider cluster before an independent emergency cut-off.

CASE FILE

The Rule That Reached Every Edge Before Anyone Priced It: Cloudflare's 2019 WAF Outage

Cloudflare's distributor needed seconds to place one approved security rule around the world; the incident lasted because approval had established what the rule should catch, not how much computation every request could make it consume.

Aug 22, 2026
A folded page crosses one luminous tenant boundary and carries colored memory fragments into the wrong lane while three edge gates close and residual fragments remain in downstream cache nodes.

CASE FILE

The Page That Borrowed Another Customer's Memory: Cloudbleed and the Boundary of a Shared Edge

A malformed page triggered Cloudflare's parser, but the escaped bytes could belong to somebody else entirely; Cloudbleed showed that stopping a leak and recovering what had already crossed the boundary are different acts of control.

Aug 22, 2026
Two distinct certificate plates converge on one amber digest seal; the constrained plate remains in a licensing path while the unconstrained plate approaches a separate blue software gate before a distrust shutter closes the old hierarchy.

CASE FILE

The Certificate That Was Valid for the Wrong Job: Flame and the Authority Hidden in Purpose

The Flame malware did not need Microsoft's root private key. It found a licensing certificate path whose mathematics, issuance habits and inherited trust could be rearranged into software-signing authority.

Aug 22, 2026
Blue request streams snap shut inside a glass multiplexed channel while amber work continues into downstream machinery until a connection-level gate closes.

CASE FILE

The Request That Vanished but Kept Working: What Rapid Reset Revealed About Cancellation

HTTP/2 let a client withdraw one request without closing the connection; Rapid Reset exposed the moment when that valid cancellation stopped being a courtesy and became an unlimited claim on somebody else’s queues.

Aug 22, 2026
A repaired blue key generator creates varied crystalline keys while repetitive amber keys remain distributed through a bounded screening comb toward independent relying mechanisms.

CASE FILE

The Patch That Could Not Retire a Key: Debian's OpenSSL Entropy Failure and the Afterlife of Weak Credentials

The repaired library stopped minting predictable keys. It did not find the old ones, remove them from remote authorization files, revoke their certificates or persuade a single relying party to refuse them.

Aug 22, 2026
A compact signed packet expands into many brass keys and glass signatures before a local limiter stops the overloaded validation branch while blue request paths continue.

CASE FILE

The Signature That Demanded Every Key: What KeyTrap Revealed About the Cost of Trust

KeyTrap turned a valid-looking DNSSEC workload into a claim on somebody else’s processor, exposing the point at which faithful verification must yield to a locally governed budget.

Aug 22, 2026
Legacy amber certificate infrastructure remains behind while business assets cross to a blue issuance chamber and three client gates independently reject, delay or accept trust.

CASE FILE

The Root That Wasn't Sold: What Symantec's Exit Revealed About Transferable Trust

Symantec could sell its certificate-authority business, but it could not sell a command to keep trusting the old roots. That decision remained inside independently operated clients.

Aug 22, 2026
A narrow amber route diverts from a blue DNS cluster through a recursive lens and a cracked certificate barrier toward a violet wallet chamber.

CASE FILE

The Route That Borrowed a Name: What the MyEtherWallet Hijack Revealed About Layered Authority

A route accepted elsewhere let false DNS answers arrive locally, but the 2018 MyEtherWallet attack still had to cross a chain of independent technical vetoes.

Aug 22, 2026
A preserved technical document sits beneath glass while a separate transparent correction layer and three independently archived review outcomes remain visibly linked beside it.

CASE FILE

A Verified RFC Erratum Corrects the Record Without Rewriting It

An RFC erratum can identify a real defect, supply corrected wording and be verified by the responsible parties. It still does not silently replace the published specification. That separation lets implementers learn from mistakes while preserving the text the community actually…

Aug 21, 2026
A signed chain proves one bounded empty interval, while a lower Opt-Out opening retains a possible child delegation and entitlement remains beyond a red boundary.

CASE FILE

DNSSEC Can Prove Absence Without Deciding Entitlement

A signed negative DNS answer can establish that a name or record type was absent from a particular signed zone during a bounded validity period. It cannot establish why the entry is absent, who deserves the label, whether a registrar should create it, or whether an Opt-Out…

Aug 21, 2026
An editorial network map in which a shared DNS tree crosses a thin boundary into four isolated tenant spaces, with staggered downstream copies below.

CASE FILE

Mozilla’s Hidden Security Boundary: How the Public Suffix List Becomes Running Code

Mozilla began the Public Suffix List, and Firefox still turns a version of it into browser behaviour. The DNS can tell software that `whatwg.github.io` exists beneath `github.io`, but not whether those names belong to one organisation or mutually untrusting tenants. This article…

Aug 21, 2026

Member Unlock

Restricted Profile Intelligence

Login is required to unlock full profile briefings and deep-dive sections.

Only for Strategic Circle

Strategic Circle Briefing

Join to unlock strategic briefings after signing in.

Join Strategic Circle
Only for Leadership Alliance

Leadership Alliance Briefing

For qualified IP-asset owners and management; sign in to unlock alliance briefings.

Join Leadership Alliance

Session Map

Active Dossiers

AFRINIC Saga

Multi-year governance and legal crisis with implications for RIR accountability worldwide.

Open AFRINIC Saga