Primary Domain
Infrastructure
Within the Primary Domain facet, Infrastructure intelligence groups reporting by primary domain so readers can follow a focused area of internet infrastructure, governance, connectivity markets, or digital capital. The page brings together related articles, public evidence, institutions, companies, people, regional exposure, operating dependencies, and market context that may otherwise sit across separate category pages. It explains the domain, the likely actor class, the market or governance context, and the source material readers should use when comparing signals. Operators, analysts, and governance readers can see how the same domain appears across events, profiles, market shifts, public-source evidence, regional dependencies, and longer-cycle infrastructure decisions over time.
CASE FILE
The Signal Was Signed. The Delegation Was Not Yet Secure: CDS/CDNSKEY and the Authority to Publish DS
A child zone can publish a perfectly signed request for a new DNSSEC secure entry point and still lack the one chain that would validate it. CDS/CDNSKEY makes parent coordination machine-readable; it does not collapse operational control, registrant authority, parent admission…
CASE FILE
The Catalog Was Valid. The Deletion Was Not: DNS Catalog Zones and the Authority to Provision
An authenticated DNS transfer can deliver a perfectly formed catalog whose operational consequence is to remove every zone from a secondary fleet. The transport may be trustworthy and the syntax impeccable while the decision encoded inside it is still wrong. DNS Catalog Zones…

IETF
David Meyer and the Address That Had to Ask Where It Lived
LISP lets an endpoint keep one identifier while its network attachment is described separately. That does not make location disappear. It moves forwarding into a chain of registered, resolved, cached, selected and reachable EID-to-RLOC state—and turns each link in that chain into…
CASE FILE
The Answer Had Expired. The Failure Had Not: DNS Serve-Stale and the Authority Beyond TTL
A DNS answer can outlive its ordinary freshness without becoming current again. Serve-stale is the resolver's narrow authority to prefer a known old answer over a fresh failure, but only after the source has been consulted, the failure has been bounded and the age of the…

IETF
Alan DeKok and the RADIUS Variant That Moved Trust into TLS
RFC 9765 is unusual not because it promises a clean break, but because it records a protocol author revisiting a choice he helped make: Alan DeKok's RADIUS/1.1 removes old packet-security machinery only where two peers explicitly negotiate a protected transport profile. The…

History
Mark Andrews and the DNS Server That Outlived Its Replacement
A replacement can be announced years before it becomes a migration. Mark Andrews's stewardship of BIND 9 during the BIND 10 programme shows why running infrastructure keeps imposing duties—security fixes, releases, tests and operator support—even while an institution invests in…

IETF
Joe Abley and the Trust Anchor That Had to Declare Where Trust Began
DNSSEC can prove a chain only after a resolver has decided where the chain starts. Joe Abley's work on the root trust-anchor publication format makes that first decision unusually legible: a signed file can prove where data came from, but it cannot order an operator to believe…

APRICOT
Anurag Bhatia and the Routing Difference That Could Not Explain Itself
A missing route is an observation before it is a diagnosis. At APRICOT 2020, Anurag Bhatia compared selected BGP views and found tens of thousands of prefixes that were not equally visible. The valuable result was not a blacklist. It was a test of whether an operator can keep the…

IETF
Vint Cerf and the Nine Exceptions Hidden Inside “Everyone”
Vint Cerf’s 2002 declaration that the Internet is for everyone is often remembered as a promise. Its more useful architecture lies in the next words: “but it won’t be.” Repeated nine times, that qualification turns universality from applause into unfinished work.

IETF
Geoff Huston and the IPv6 Default That Withdrew Itself
For a decade, `/48` looked like the neat answer to a difficult IPv6 question: how much address space should an ordinary site receive? Geoff Huston helped write the document that withdrew that single answer without surrendering the protections it was meant to provide.

IETF
Ray Bellis and the DNS Connection That Became a Session
A TCP socket can remain open without anyone agreeing what state it carries. RFC 8490 made that distinction explicit for DNS: the connection is transport; the session is a mutually recognized set of rights, timers and obligations. Ray Bellis and his co-authors turned persistence…

Europe and Middle East Regional ISP Trends
VOLZ’s 120-hour node-power claim needs a failure-domain ledger
VOLZ has put an unusually concrete number beside network continuity: batteries at 14 large Kyiv communications nodes that the operator says can sustain power for 120 hours, backed by generators for emergencies. The number is valuable because it identifies a real control. It is…

Europe and Middle East Regional ISP
Monitoring’s FTTH menu exposes where passive access ends and power responsibility begins
Scientific-Production Center “Monitoring” does something unusually useful for a regional internet provider: its public website distinguishes GPON, point-to-point fibre and fibre-to-the-building instead of compressing them into one “fibre” label. That distinction creates a better…

ICANN
ICANN Completes String Similarity Before Priority Batches. What Does the All-Strings Rule Protect?
A late Priority Number does not place a proposed string outside the comparison universe. ICANN's 2026 Round rules require the similarity review to cover every applied-for string before evaluation batches are formed.
CASE FILE
The Zone Went Dark. The Resolver Made the Outage Louder
When authoritative DNS stops answering, the first failure belongs to the zone. The next thousand queries may belong to the resolver. RFC 9520 draws a narrow but consequential line between the two: silence is not proof that a name does not exist, yet a resolver that has exhausted…
CASE FILE
The Block Was Explained. The Policy Was Still a Claim.
The night shift sees an authenticated DNS response that says a name was blocked, identifies a policy category and offers a support route. The explanation is orderly, machine-readable and intact. It still does not reveal whether the upstream classification was right, who had…
CASE FILE
The Proof Verified. The Fork Was Still Private.
Every response on Alice’s device verifies. Every later tree head extends the one before it. Across town, Bob sees the same tidy sequence—except his latest head commits to a different key for Alice. The log has not broken either local proof chain. It has separated the witnesses.
CASE FILE
The Handshake Succeeded. The DNS Question Was Already Exposed
RFC 9539 lets a recursive resolver encrypt its next hop to an authoritative server without waiting for the server to advertise a new policy or present a verifiable identity. That modest bargain can hide many DNS questions from passive observers. It also creates an unusually…

Europe and Middle East Regional ISP Trends
BSH's single-operator model makes dependency evidence part of the SLA
BSH offers distributed organisations a commercially simple proposition: aggregate communications services into one contract and give the customer one point of responsibility. That can reduce the cost of coordinating a fault. It does not, by itself, show whether the underlying…
CASE FILE
The Certificate Was Fresh. The Number Authority Had Its Own Clock.
A verifier receives a PASSporT with an intact signature, a valid certificate path and a certificate that will expire in hours. Between issuance and the call, however, control of the calling number has changed. The credential can be fresh in the precise X.509 sense while the fact…
