Primary Domain
Infrastructure
Within the Primary Domain facet, Infrastructure intelligence groups reporting by primary domain so readers can follow a focused area of internet infrastructure, governance, connectivity markets, or digital capital. The page brings together related articles, public evidence, institutions, companies, people, regional exposure, operating dependencies, and market context that may otherwise sit across separate category pages. It explains the domain, the likely actor class, the market or governance context, and the source material readers should use when comparing signals. Operators, analysts, and governance readers can see how the same domain appears across events, profiles, market shifts, public-source evidence, regional dependencies, and longer-cycle infrastructure decisions over time.

CASE FILE
The Certificates Did Not Expire: Chrome's Entrust Cutoff Turned Trust Into an Operating Licence
The decisive field was not the expiry date printed inside a TLS certificate. It was the timestamp proving when that certificate entered the public record—and whether Chrome still accepted the authority behind it at that moment.

Europe and Middle East Cloud Services Trends
Sovereignty is a dependency map before it is a location label
AWS's European Sovereign Cloud makes a serious case for regional separation. The harder procurement question is whether every consequential decision path—not only stored data—can be kept, tested and evidenced inside the promised boundary.

History
The Hint That Had to Be Replaced by an Answer: DNS Root Priming
A recursive resolver begins with an awkward form of knowledge: enough addresses to reach the DNS root, but no current root data in its cache. Priming is the small exchange that turns that inherited hint into an authoritative, expiring answer.

IETF
The secret server name still needs a public front door: ECH’s new privacy boundary
Encrypted ClientHello gives a TLS connection two introductions: one the network may see, and one only the service can open. That is a real privacy gain, but it is not disappearance. The destination’s protection now depends on DNS configuration, a shared front door, key rotation…

Story
ARIN’s RDAP Bottom Search Is a Coverage Answer, Not a Leaf List
One query for a `/21` returns a direct `/22` allocation and an administrative `/8`. The result looks upside down only if `rdap-bottom` is mistaken for a list of descendants; its real job is to account for registry coverage.

ICANN
One Portal, No Clock: Who Actually Grants Zone-File Access?
CZDS lets a researcher ask many generic top-level-domain registries for zone files from one place. The common doorway is easy to mistake for a common decision. It is neither automatic access nor a single permission desk.

ICANN
The Forged Letter That Moved Sex.com: Kremen v. Cohen and Network Solutions
A forged instruction did not move a physical entity. It changed the authoritative registration record for a domain name—and forced a federal appellate court to ask what, exactly, the registrant controlled.

Story
ARIN’s NET Route List Stops at the Direct Allocation
An empty collection can look decisive until the query boundary is drawn. In ARIN’s routing-registry API, the ordinary NET route list ends at the direct registration; the downstream tree belongs to a different request.

North America Cloud Services Trends
Rollback has not happened until every edge population proves the old decision is gone
A control plane can accept the previous Fastly service version in seconds. The business is not restored until requests across the edge stop encountering the withdrawn rule, artefact or cache decision—and the evidence covers the populations that matter.

ICANN
A Domain Name in a Receiver’s Hands: Office Depot v Zuccarini
The judgment was entered in Florida, the debtor lived elsewhere, the registrars were scattered across three countries, and the `.com` registry sat in Northern California. To collect the debt, the Ninth Circuit had to decide where an intangible domain name could be found.

ICANN
When ICANN Ends a Registrar, Who Receives the Domains?
ICANN’s public bulk-transfer table shows a terminated registrar, a gaining registrar and a date. The missing middle is the consequential part: who was eligible to receive the registrations, which operating promises mattered, and what the decision did—and did not—give the…
CASE FILE
The Template ID Was Familiar. The Flow Still Needed Its Exporter: IPFIX and the Authority of an Observation Domain
The collector saw Template ID 256 after an exporter reconnected. It reused the definition cached from the old transport session, and the incoming bytes still produced plausible counters. The dashboard was orderly, the parser was satisfied and every field name was wrong. Nothing…
CASE FILE
The TXT Record Was Correct. The Vendor Still Wasn't the Domain: ACME DNS-01 and the Authority of Delegated Validation
The vendor had been removed from the application, CI and staff accounts. One control survived: `_acme-challenge` still delegated to its validation zone. When the vendor's ACME account requested a wildcard certificate, the expected TXT digest appeared and every protocol check…
CASE FILE
When a Route Counter Becomes a Kill Switch: Governing BGP Maximum-Prefix
A BGP maximum-prefix limit is often presented as a protective ceiling. Its real significance is more demanding: depending on the implementation and action, a count of routes can authorize the withdrawal of an entire session. The control is defensible only when the network can…
CASE FILE
The DNS Answer Was Secure. The Host Was Still a Policy Choice: SSHFP and the Authority of a Fingerprint
An operator typed `ssh db`. A network-supplied search path expanded the short name to a different fully qualified host. Its DNSSEC chain was Secure, its SSHFP fingerprint matched and its server held the corresponding private key. Every proof was valid for the host the client…
CASE FILE
The Signature Passed. The From Address Still Wasn't the Signer: DKIM and the Authority of a Domain Signature
The message displayed `bank.example` as its From identity, carried an urgent payment instruction and passed DKIM. The result was genuine—but for `receipt-alert.example`, a domain controlled by the attacker. A valid signature had been promoted into authority over a different name.
CASE FILE
The Digest Matched. The Sender Was Still Unknown: HTTP `Content-Digest` and the Authority of a Checksum
The policy upload carried a valid `Content-Digest`. The service recomputed the hash, displayed a green “verified” badge and applied the file. The file was malicious. Nothing had been corrupted in transit; the attacker had chosen both the bytes and the checksum.
CASE FILE
The Header Named the Client. The Peer Address Did Not Agree: HTTP `Forwarded` and Proxy-Chain Authority
The origin normally sat behind two reverse proxies. One night a requester reached it directly, supplied an administrator's allowlisted address as the first `X-Forwarded-For` value, and crossed an IP rule. The header parser returned exactly what it had been asked to return. The…
CASE FILE
The Name Selected a TLS Context. It Did Not Authorize the Request: SNI and the Authority of a Routing Hint
The gateway received `tenant-a.example` in a ClientHello, selected Tenant A's certificate, and attached Tenant A's policy context. It then let the connection reach a privileged route without a tenant credential. Every TLS selection step had worked. The error was believing that a…
CASE FILE
The Certificate Signature Passed. The Handshake Was Not Finished: TLS 1.3 `Finished` and Transcript Authority
The dashboard declared a secure session when the server's CertificateVerify signature passed. One record later, the client rejected a corrupt `Finished` message and closed the connection. The certificate key had proved one thing accurately. Operations had promoted it into proof…
