Primary Domain
Infrastructure
Within the Primary Domain facet, Infrastructure intelligence groups reporting by primary domain so readers can follow a focused area of internet infrastructure, governance, connectivity markets, or digital capital. The page brings together related articles, public evidence, institutions, companies, people, regional exposure, operating dependencies, and market context that may otherwise sit across separate category pages. It explains the domain, the likely actor class, the market or governance context, and the source material readers should use when comparing signals. Operators, analysts, and governance readers can see how the same domain appears across events, profiles, market shifts, public-source evidence, regional dependencies, and longer-cycle infrastructure decisions over time.

Global Regional ISP Trends
IPv4-as-a-Service Makes Translation State an Operating Contract
An IPv6-only access line can look perfectly healthy while one old application, one literal IPv4 address or one changed resolver loses the IPv4 Internet. IPv4-as-a-Service saves scarce addresses by moving compatibility into a chain of synthesis and translation; it also moves the…
Europe and Middle East Regional ISP
Gigaclear’s Wi-Fi guarantee stops at the broadband contract
A room-level speed promise sounds like protection for the whole broadband purchase. Gigaclear’s current terms draw a narrower boundary: a failed Smart WiFi test can release the mesh add-on and produce one month’s broadband credit, while the underlying broadband service continues…

IETF
The Field That Meant More After the Handshake: TCP Window Scale
TCP kept a 16-bit receive-window field even after fast, long-distance paths needed far more than 65,535 bytes in flight. Window Scale did not enlarge that field. It made the handshake establish how each endpoint would interpret the field for the life of one connection.

Global Cloud Services
GitHub's Attestation Proves a Build Path, Not a Safe Binary
A valid signature can establish where a binary came from while leaving the deployment decision unresolved. GitHub’s artifact attestation becomes a security control only when the consumer tests the recorded build route against an explicit trust policy.

IETF
The Request Arrived Before the Handshake: TCP Fast Open's Replay Bargain
TCP Fast Open let a returning client put its first application bytes in the packet that asked to open a connection. The saved round trip was real, but so was the bargain: replay tolerance, cookie rotation, bounded pre-handshake work and reliable fallback became part of operating…

Global Regional ISP Trends
NQB Turns Low-Latency Broadband Into a Behavioural Contract
A gigabit access line can look idle while a short game update, voice packet or DNS reply waits behind a bursty upload at the home’s actual bottleneck. The new NQB standard offers a shallow queue, but only to traffic whose sending pattern can justify the privilege without turning…

IETF
The connection is larger than the path: Multipath TCP keeps one byte stream across several routes
A phone leaves an office with a live connection on Wi-Fi and reaches the street on cellular. Ordinary TCP ties that connection to one path. Multipath TCP can keep the application on one ordered byte stream while the endpoints add, retire and prioritise TCP subflows underneath it.…

IETF
When the Receiver Drew a Map: How TCP SACK Changed Loss Recovery
TCP once told a sender only where an uninterrupted stream ended. Selective acknowledgment added a second language: a compact map of the later bytes that had already arrived. That extra evidence changed loss recovery without changing who controlled the congestion window or when…
Global Regional ISP Trends
Hyperoptic coverage is not serviceable until the building says yes
A broadband map can colour an address as covered before anyone has secured the right to open the riser, use the shared duct or enter the corridor that leads to the flat. Hyperoptic’s own installation documents show why the useful unit of coverage is not the postcode but the…
IETF
How DNSSEC learned to prove a name does not exist
A signed answer can authenticate a record that is present. The harder design problem is authenticating the empty space where an attacker might otherwise hide a name, invent one or replace a truthful “no” with a forged response.

IETF
The quiet hour is only a forecast: ALTO makes traffic timing a published promise
A bulk transfer can wait for two in the morning. The harder question is why two in the morning should be cheaper at all. ALTO Cost Calendars let a network publish that expectation to an application. The calendar is useful precisely because it is not the network itself: it is an…

History
The Handshake That Had to Remember Its Previous Handshake: TLS Renegotiation
A TLS connection could be encrypted from end to end and still tell the server the wrong story about who had sent its first bytes. The renegotiation flaw of 2009 exposed a missing form of evidence: a new handshake needed to prove not only its own keys, but also which earlier…

Number Resource Society
The FAQ Answer Needs a Version Date
A frequently asked question looks like the lightest form of institutional writing. In practice, it can be the page a member reads before applying, changing details, relying on a benefit or choosing where to ask for help. When that answer has no visible date or predecessor…

North America Regional ISP Trends
BEAD awards do not become project cash until reimbursement clears
A fibre crew can finish a week's work while the contractor's payroll and the supplier's invoice fall due before the state has accepted the next BEAD payment trigger. The award may be valid, the construction eligible and the project economic, yet the subgrantee still has to…

IETF
The quarter-second bargain behind Happy Eyeballs
Happy Eyeballs turned dual-stack connection setup into a managed race. Its success lies in making path failure less visible to users; its cost is that the same success can make broken paths less urgent to repair.

Global Regional ISP Trends
RPKI’s Recovery Path Is Becoming a Routing Control Surface
A ROA is not useful merely because it exists. The operational result also depends on how repositories and validators move from delta to snapshot to fallback—and how long they trust a previously valid view when those paths fail.

History
The Address That Expired to Protect Its User: IPv6 Temporary Addresses
IPv6 privacy extensions did not make an address secret. They changed which address a host would prefer for its next conversation, how long that preference lasted, and when the identifier finally had to leave the interface.

IETF
Joining the group is no longer enough: SSM makes the receiver name the sender
Source-Specific Multicast turns a multicast join into a choice: the receiver must identify both the group it wants and the source it is willing to hear.

ICANN
The Public Query Became a Private Lead Machine: Register.com v. Verio
A daily list of newly registered domains looked like public infrastructure until Verio connected it to automated WHOIS queries and rapid sales calls. The resulting case is less a monument to web-contract doctrine than a practical warning about layered permission: public data, a…

Global Cloud Services Trends
Two Providers Receive 38.6% of Popular-Domain Mail. The Missing Metric Is Recoverability
Public DNS can show where a domain asks the Internet to deliver its mail. It cannot show how long that domain would take to leave.
