Skip to main content

Primary Domain

Infrastructure

Within the Primary Domain facet, Infrastructure intelligence groups reporting by primary domain so readers can follow a focused area of internet infrastructure, governance, connectivity markets, or digital capital. The page brings together related articles, public evidence, institutions, companies, people, regional exposure, operating dependencies, and market context that may otherwise sit across separate category pages. It explains the domain, the likely actor class, the market or governance context, and the source material readers should use when comparing signals. Operators, analysts, and governance readers can see how the same domain appears across events, profiles, market shifts, public-source evidence, regional dependencies, and longer-cycle infrastructure decisions over time.

A certificate chain crosses an amber timestamp boundary; certificates before the cutoff remain blue and trusted, while a later certificate is isolated behind a red browser-trust barrier.

CASE FILE

The Certificates Did Not Expire: Chrome's Entrust Cutoff Turned Trust Into an Operating Licence

The decisive field was not the expiry date printed inside a TLS certificate. It was the timestamp proving when that certificate entered the public record—and whether Chrome still accepted the authority behind it at that moment.

Aug 26, 2026
Editorial illustration of a European cloud region connected to operational, identity, support, software-supply and emergency-authority control paths.

Europe and Middle East Cloud Services Trends

Sovereignty is a dependency map before it is a location label

AWS's European Sovereign Cloud makes a serious case for regional separation. The harder procurement question is whether every consequential decision path—not only stored data—can be kept, tested and evidenced inside the promised boundary.

Aug 26, 2026
Editorial illustration showing DNS root priming: an aging root-hints card sends one query to the DNS root, whose current authoritative records replace the hint in a resolver cache.

History

The Hint That Had to Be Replaced by an Answer: DNS Root Priming

A recursive resolver begins with an awkward form of knowledge: enough addresses to reach the DNS root, but no current root data in its cache. Priming is the small exchange that turns that inherited hint into an authoritative, expiring answer.

Aug 26, 2026
A public outer network message carrying a luminous encrypted inner message through a shared gateway toward one of several backend servers.

IETF

The secret server name still needs a public front door: ECH’s new privacy boundary

Encrypted ClientHello gives a TLS connection two introductions: one the network may see, and one only the service can open. That is a real privacy gain, but it is not disappearance. The destination’s protection now depends on DNS configuration, a shared front door, key rotation…

Aug 26, 2026
A small illuminated registry tile and a much larger translucent slab jointly cover a framed address range while separate fibre lights remain outside the registry plane.

Story

ARIN’s RDAP Bottom Search Is a Coverage Answer, Not a Leaf List

One query for a `/21` returns a direct `/22` allocation and an administrative `/8`. The result looks upside down only if `rdap-bottom` is mistaken for a list of descendants; its real job is to account for registry coverage.

Aug 26, 2026
A central request hub routes access tokens to separate registry approval vaults, with only accepted requests producing bounded zone-data copies.

ICANN

One Portal, No Clock: Who Actually Grants Zone-File Access?

CZDS lets a researcher ask many generic top-level-domain registries for zone files from one place. The common doorway is easy to mistake for a common decision. It is neither automatic access nor a single permission desk.

Aug 26, 2026
A forged paper instruction enters a registry console as a domain-control token crosses from a verified blue lane to an amber lane beside a broken confirmation link and a visible restoration path.

ICANN

The Forged Letter That Moved Sex.com: Kremen v. Cohen and Network Solutions

A forged instruction did not move a physical entity. It changed the authoritative registration record for a domain name—and forced a federal appellate court to ask what, exactly, the registrant controlled.

Aug 26, 2026
Blank registration cards, a sealed authorization wafer and illuminated fibre paths remain visibly separate in a network operations room.

Story

ARIN’s NET Route List Stops at the Direct Allocation

An empty collection can look decisive until the query boundary is drawn. In ARIN’s routing-registry API, the ordinary NET route list ends at the direct registration; the downstream tree belongs to a different request.

Aug 26, 2026
A global edge network appears rolled back on central monitors while one remote POP remains amber.

North America Cloud Services Trends

Rollback has not happened until every edge population proves the old decision is gone

A control plane can accept the previous Fastly service version in seconds. The business is not restored until requests across the edge stop encountering the withdrawn rule, artefact or cache decision—and the evidence covers the populations that matter.

Aug 26, 2026
A sealed court order and a receiver’s custody case sit before domain-record files linked to registrar and registry systems.

ICANN

A Domain Name in a Receiver’s Hands: Office Depot v Zuccarini

The judgment was entered in Florida, the debtor lived elsewhere, the registrars were scattered across three countries, and the `.com` registry sat in Northern California. To collect the debt, the Ninth Circuit had to decide where an intangible domain name could be found.

Aug 26, 2026
Registration dossiers move through a registry checkpoint from an inactive registrar to an operational receiving registrar while registrant markers remain attached.

ICANN

When ICANN Ends a Registrar, Who Receives the Domains?

ICANN’s public bulk-transfer table shows a terminated registrar, a gaining registrar and a date. The missing middle is the consequential part: who was eligible to receive the registrations, which operating promises mattered, and what the decision did—and did not—give the…

Aug 26, 2026

CASE FILE

The Template ID Was Familiar. The Flow Still Needed Its Exporter: IPFIX and the Authority of an Observation Domain

The collector saw Template ID 256 after an exporter reconnected. It reused the definition cached from the old transport session, and the incoming bytes still produced plausible counters. The dashboard was orderly, the parser was satisfied and every field name was wrong. Nothing…

Aug 25, 2026

CASE FILE

The TXT Record Was Correct. The Vendor Still Wasn't the Domain: ACME DNS-01 and the Authority of Delegated Validation

The vendor had been removed from the application, CI and staff accounts. One control survived: `_acme-challenge` still delegated to its validation zone. When the vendor's ACME account requested a wildcard certificate, the expected TXT digest appeared and every protocol check…

Aug 25, 2026

CASE FILE

When a Route Counter Becomes a Kill Switch: Governing BGP Maximum-Prefix

A BGP maximum-prefix limit is often presented as a protective ceiling. Its real significance is more demanding: depending on the implementation and action, a count of routes can authorize the withdrawal of an entire session. The control is defensible only when the network can…

Aug 25, 2026

CASE FILE

The DNS Answer Was Secure. The Host Was Still a Policy Choice: SSHFP and the Authority of a Fingerprint

An operator typed `ssh db`. A network-supplied search path expanded the short name to a different fully qualified host. Its DNSSEC chain was Secure, its SSHFP fingerprint matched and its server held the corresponding private key. Every proof was valid for the host the client…

Aug 25, 2026

CASE FILE

The Signature Passed. The From Address Still Wasn't the Signer: DKIM and the Authority of a Domain Signature

The message displayed `bank.example` as its From identity, carried an urgent payment instruction and passed DKIM. The result was genuine—but for `receipt-alert.example`, a domain controlled by the attacker. A valid signature had been promoted into authority over a different name.

Aug 25, 2026

CASE FILE

The Digest Matched. The Sender Was Still Unknown: HTTP `Content-Digest` and the Authority of a Checksum

The policy upload carried a valid `Content-Digest`. The service recomputed the hash, displayed a green “verified” badge and applied the file. The file was malicious. Nothing had been corrupted in transit; the attacker had chosen both the bytes and the checksum.

Aug 25, 2026

CASE FILE

The Header Named the Client. The Peer Address Did Not Agree: HTTP `Forwarded` and Proxy-Chain Authority

The origin normally sat behind two reverse proxies. One night a requester reached it directly, supplied an administrator's allowlisted address as the first `X-Forwarded-For` value, and crossed an IP rule. The header parser returned exactly what it had been asked to return. The…

Aug 25, 2026

CASE FILE

The Name Selected a TLS Context. It Did Not Authorize the Request: SNI and the Authority of a Routing Hint

The gateway received `tenant-a.example` in a ClientHello, selected Tenant A's certificate, and attached Tenant A's policy context. It then let the connection reach a privileged route without a tenant credential. Every TLS selection step had worked. The error was believing that a…

Aug 25, 2026

CASE FILE

The Certificate Signature Passed. The Handshake Was Not Finished: TLS 1.3 `Finished` and Transcript Authority

The dashboard declared a secure session when the server's CertificateVerify signature passed. One record later, the client rejected a corrupt `Finished` message and closed the connection. The certificate key had proved one thing accurately. Operations had promoted it into proof…

Aug 25, 2026