Primary Domain
Infrastructure
Within the Primary Domain facet, Infrastructure intelligence groups reporting by primary domain so readers can follow a focused area of internet infrastructure, governance, connectivity markets, or digital capital. The page brings together related articles, public evidence, institutions, companies, people, regional exposure, operating dependencies, and market context that may otherwise sit across separate category pages. It explains the domain, the likely actor class, the market or governance context, and the source material readers should use when comparing signals. Operators, analysts, and governance readers can see how the same domain appears across events, profiles, market shifts, public-source evidence, regional dependencies, and longer-cycle infrastructure decisions over time.
CASE FILE
Who Owns the Renewal Clock? ACME ARI and the Last Mile of Certificate Replacement
A certification authority can spread renewal work across a day, yet a fleet can still compress that day into one frantic minute. ACME Renewal Information supplies a window; the client, deployment system and live service decide whether that window becomes a safe replacement.
CASE FILE
The Reply Said Success. No Client Had Changed: DHCPv6 Reconfigure and the Authority of a Trigger
A relay can report that configuration changed, a server can answer `Success`, and an authenticated packet can reach a client without any of those events proving that the client now runs different addresses, prefixes or service parameters. DHCPv6 Reconfigure is useful precisely…
CASE FILE
The route outlived the speaker
BGP Long-Lived Graceful Restart can keep a failed peer’s routes for hours or days after ordinary restart protection ends. That buys time, but it also turns stale state into a temporary operating promise whose timer, forwarding basis and exit must be proved.
CASE FILE
The User Matched Twice. The Packet Was Valid: RADIUS CoA and the Authority to Change a Live Session
A correctly protected control request reaches an access router and asks for a new traffic filter. The subscriber name matches two live sessions. Cryptography has answered who sent the packet on this hop. It has not answered which connection may be changed.
CASE FILE
The session stayed green. The routes disappeared
A malformed BGP UPDATE no longer has to take an entire peering session down. That is a major containment gain, but it changes what operators must prove: an Established session can now coexist with a precise set of destinations that the receiver has removed for safety.
CASE FILE
The Packet Was Authentic. The Clock Was Still Wrong: NTS and the Authority of a Time Measurement
Two time servers answer the same machine. Both replies pass Network Time Security checks. Their offsets are 800 milliseconds apart. The cryptography has done its job, yet the operator's hardest question remains unanswered: which measurement, if either, may steer the clock?
CASE FILE
The route that came home wearing its own ASN
The route that came home wearing its own ASN intelligence summary explains the development, the public evidence available to readers, the organisations involved, the regional context, market exposure, and the infrastructure consequences that may follow. The CASE FILE intelligence…
CASE FILE
The DNS ID Changed. The Old Rule Still Blocked Mail: MTA-STS and the Authority of a Cached Policy
At 09:00 a recipient added a backup MX to its HTTPS policy and changed the `_mta-sts` TXT `id`. One sender fetched the update. Another could not refresh and still held yesterday's unexpired `enforce` policy. Both resolved the same backup host; only one was permitted to use it.…
CASE FILE
Two paths, one hot link: governing BGP multipath
Two routes can be equally eligible, present in the forwarding table and still fail to share capacity in the way an operator expects. Multipath is permission to use a set of paths—not a promise about what the traffic inside that set will do.
CASE FILE
The Header Said DKIM Passed. It Did Not Say Who Ran the Test: Authentication-Results and the Authority of a Trust Boundary
Two messages arrive with the same line near the top: `Authentication-Results: mx.example; dkim=pass`. One line was written by the receiver after it checked the signature. The other was supplied by the sender before the SMTP connection began. A downstream rule sees identical…
CASE FILE
The Certificate Was the Same. The Service Name Was Not: DANE TLSA and the Authority of a Port-Bound Assertion
The certificate chain was identical on two listeners. One DANE-aware client accepted it; the other rejected it. Nothing cryptographic had changed inside the certificate. The selected service had changed, and the DNS assertion was never written for that second port.
CASE FILE
BGP’s quiet instruction: who gets to prefer an exit?
LOCAL_PREF can send traffic towards a longer path without telling an external neighbour why. Its power lies in the local policy behind the number—and in whether that policy survives the journey from a border router to actual packets.

Global Datacenter Trends
GE Vernova data-centre orders top $5bn
GE Vernova booked more than $5bn of data-centre orders in its Electrification business during the first half of 2026, already more than double its 2025 total.

Europe and Middle East National Telecom Trends
Proximus fibre lines reach 820,000 in Belgium
Proximus added 44,000 active fibre lines in the second quarter as its Belgian fibre footprint reached 2.75 million homes and businesses.

Leaders
Aidan Casey and the Operational Burden Hidden Inside Managed IT
ARIN lists one executive in five network roles, exposing hidden managed-IT work without proving sole control, resilience or customer outcomes.

Story
LACNIC’s RDAP Last Changed Event Dates the Registry Record, Not the Network Handover
A timestamp in a registration record can anchor an investigation, but it cannot substitute for the event the investigator actually needs to prove. LACNIC’s live RDAP data makes that boundary unusually visible: a network entity and the entities embedded inside it carry different…

Global Cloud Services
Datadog’s Observability Pipelines Move the Cost Cut Upstream
Datadog offers a way to reduce telemetry volume before it leaves a customer’s environment. That can lower a downstream bill, but it also moves the authority to discard operational evidence to a point where a later search cannot recover it.

Global Cloud Services
A DDoS Scrubbing Contract Must Say Who Delivers the Clean Gigabit
A mitigation cloud can absorb an attack measured in terabits and still leave one customer's legitimate traffic dependent on a much smaller circuit, tunnel and router. The purchase decision is therefore not only how much hostile traffic the provider can discard. It is what clean…

IETF
The Timer the Peer Could Hear: TCP User Timeout Without Negotiated Patience
One TCP endpoint could decide how long unanswered data was worth keeping, but the other endpoint could not hear that decision. RFC 5482 put the timeout on the wire as advice. The difficult part was preserving the distinction between a useful warning and a promise neither side had…

Africa National Telecom
A Tower Sale Does Not Sell the Power Bill
Selling passive mobile infrastructure can release capital and move steel, shelters and site operations to a tower company. It does not answer who pays when diesel rises, a generator burns too much fuel, a ground lease lapses or an uptime target is missed. Those outcomes live in…
