Skip to main content

Primary Domain

Infrastructure

Within the Primary Domain facet, Infrastructure intelligence groups reporting by primary domain so readers can follow a focused area of internet infrastructure, governance, connectivity markets, or digital capital. The page brings together related articles, public evidence, institutions, companies, people, regional exposure, operating dependencies, and market context that may otherwise sit across separate category pages. It explains the domain, the likely actor class, the market or governance context, and the source material readers should use when comparing signals. Operators, analysts, and governance readers can see how the same domain appears across events, profiles, market shifts, public-source evidence, regional dependencies, and longer-cycle infrastructure decisions over time.

A bounded amber-lit connection plane stands before protected cyan-lit server resources, illustrating delayed TCP state allocation.

IETF

The Server Delayed the Cost of Belief: TCP's SYN-Flood Defenses

A TCP listener used to spend memory as soon as a stranger knocked. RFC 4987 explains how defenders moved that cost until the supposed client offered better evidence that it could hear the reply.

Aug 28, 2026
Three sealed consultation intake vessels link blank comments to versioned records, with confidential advice kept separate and later institutional decisions still unreached.

Story

AFRINIC Opened a Third Constitution Round. Every Comment Needs a Versioned Intake Record

AFRINIC’s Bylaws Review Committee continued constitutional consultation after the second-round deadline and narrowed attention to dispute resolution and safeguards around Resource Member termination. More time can improve the draft. It also creates a new recordkeeping duty: every…

Aug 28, 2026

Story

LACNIC and the economics of NRO coordination incentives

A regional Internet registry is not a shop that customers can abandon when service disappoints them. Internet number resources must remain unique, and each registry serves a defined region. That makes coordination indispensable. It also removes the most familiar market…

Aug 28, 2026

CASE FILE

The Message Had Expired. The Mailbox Had Not.

At noon, an offer in the inbox reaches the date chosen by its sender. At 12:01, the mail reader dims it. Search still finds it, the archive still holds it, and no deletion has occurred. That small separation is the point of the IETF’s newly approved work on the email `Expires`…

Aug 28, 2026

CASE FILE

The Catalog Went Empty. The Servers Obeyed

A DNS catalog zone can turn one compact, authenticated change into a new operating perimeter for an entire authoritative fleet. That efficiency is precisely why the catalog must be governed as executable authority rather than treated as a harmless list.

Aug 28, 2026
Illustration of five appeal committee seats around a versioned case record, with three nominee paths and a transparent recusal and replacement route.

Story

AFRINIC Sought Three Appeal Committee Nominees. The Appointment Record Must Be Case-Ready

AFRINIC’s Board opened nominations for three Policy Development Appeal Committee profiles and set a short, explicit deadline. The call establishes an intake step, not a functioning adjudicative body. Readiness will depend on what comes next: a versioned record of appointment…

Aug 28, 2026

Story

LACNIC and the economics of ICP-2 reform

The rule for recognising an Internet registry is also a rule about who must bear the cost of proving that institutional change is safe. LACNIC makes that trade-off unusually visible: regional legitimacy is built through members and an open policy process, while recognition…

Aug 28, 2026
Editorial illustration separating an APNIC RDAP registration record and legacy WHOIS service from independent BGP routing paths.

Story

APNIC's RDAP port43 Points to a Legacy WHOIS Service, Not Network Authority

In a live APNIC RDAP record, `port43` names `whois.apnic.net`. That is useful evidence about where to query the legacy registration service—but it is not a statement about who operates, routes or controls the addressed network.

Aug 28, 2026
An advancing amber clock enters a keyed offset prism and emerges as separate cyan per-conversation sequence lanes while crimson blind guesses fail to align.

IETF

The First Sequence Number Could Not Be Only a Clock: TCP's ISN Defense

Every TCP connection begins by publishing a number. When that number followed one global clock too plainly, an attacker who could not see the connection could still predict enough of its state to impersonate a peer.

Aug 28, 2026

CASE FILE

The Route Said Valid. The Evidence Was Local.

One RPKI service fails. A customer network changes its view a second before its provider; the provider changes next, about five minutes later. If both networks export validation results as route attributes, one dependency failure becomes two waves of BGP UPDATEs. Nothing about…

Aug 28, 2026
EDNS Client Subnet diagram showing a recursive resolver sending a truncated client-network prefix to an authoritative DNS server, whose returned scope partitions cached answers for later clients.

History

The Prefix the Resolver Sent on Someone Else’s Behalf: EDNS Client Subnet

A recursive resolver usually speaks to an authoritative server from its own address. EDNS Client Subnet changed the message: the resolver could send part of a client's network instead, asking the authority to tailor an answer for someone who had not made that upstream query. The…

Aug 28, 2026

CASE FILE

The signed chain skipped a delegation that still existed

NSEC3 Opt-Out allows a large parent zone to leave eligible insecure delegations out of its signed hash chain. That omission can be fully valid. It is also why the chain cannot serve as a complete delegation register: the proof authenticates a limited statement about a hash…

Aug 28, 2026

Europe and Middle East Datacenter Trends

A data-centre connection has no date at Gate 1

A site can have land, drawings and an impressive megawatt number while still lacking the one fact that makes its power plan schedulable: a confirmed grid-connection date.

Aug 28, 2026

Story

A Private Registry Still Needs Public Limits

LACNIC is private infrastructure governance with public consequences: legitimacy depends on a bounded mandate, published rules, evidence, review and an operational record that affected networks can understand.

Aug 28, 2026
A crimson control packet stops inside a broad TCP receive window while one amber challenge acknowledgement returns through a metering ring.

IETF

The Reset Had to Prove Itself: TCP's Challenge ACK Defense

A forged reset once needed only to land somewhere inside a moving receive window. RFC 5961 made destructive TCP control flags prove that they reflect the peer’s current state before one guessed sequence number can erase a long-lived connection.

Aug 28, 2026

Europe and Middle East Regional ISP Trends

Local broadband support has two clocks when Openreach owns the repair

A customer experiences one continuous outage. The organisations restoring it may be working to two different clocks, and the gap between them is where a promise of “local support” is either proved or exposed.

Aug 28, 2026
A sealed question record passes a delivery checkpoint toward a protected reply and layered public-state records.

Number Resource Society

An Unanswered Profile Needs a Reply-State Ledger

A public label saying that no answer has been recorded looks like a snapshot. In fact, it starts a clock: every bounce, partial reply, late response and correction can change what the label means.

Aug 28, 2026
A BGP edge router splits amber traffic onto alternate paths before shutdown while blue forwarding paths remain active during control-plane restart.

IETF

BGP Maintenance Needs Two Different Meanings of Graceful

Two change tickets can both say “graceful” while asking the network to do opposite things. One must move traffic away before a link or router stops forwarding. The other must keep forwarding on existing entries while the BGP control plane restarts. Treating those operations as…

Aug 28, 2026

IETF

QNAME Minimisation Makes Each DNS Delegation See Only What It Needs

A root server does not need an entire host name to point a resolver toward the next delegation. QNAME minimisation turns that observation into a disclosure rule: reveal the name one boundary at a time, measure fallback, and never confuse less upstream exposure with privacy from…

Aug 28, 2026

Europe and Middle East Regional ISP Trends

A digital landline is resilient only for as long as its backup path

The power fails at eight in the evening. The Digital Voice account is active, the number has migrated and a battery unit sits beside the router. An hour later the battery is empty. Or the router remains lit while the fibre modem does not. Or the cordless base and the telecare…

Aug 28, 2026