Time Horizon
Multi-year
Within the Time Horizon facet, Multi-year time-horizon intelligence organises articles by the period over which a signal is expected to matter. The page helps readers distinguish immediate operational changes from longer-cycle governance, investment, standards, and infrastructure shifts that may unfold across quarters or years. It connects timing assumptions with public evidence, related actors, market context, customer exposure, policy pressure, and infrastructure planning so readers can judge whether a development is urgent, strategic, or still waiting on confirming evidence. The page also explains how time horizon changes the meaning of a signal, which organisations may be exposed, and which infrastructure decisions require short-term action or long-cycle monitoring.

IETF
Alexey Melnikov and the Authentication Success That Could Not Grant a Service
The status light turned green. The credentials had been accepted, an identity had been associated with the session, and the exchange was over. Yet the next operation could still be refused without contradiction. The architecture Alexey Melnikov and Kurt Zeilenga set out in RFC…

IETF
Alissa Cooper and the Privacy Review That Could Not Issue a Safety Certificate
The review workbook had answers in every cell: identifiers listed, observers named, retention discussed, defaults justified. What it did not have was a truthful final cell marked “safe”. Alissa Cooper and her co-authors designed RFC 6973 to make privacy reasoning inspectable, not…

IETF
Barry Leiba and the Capital Letters That Could Not Create Authority
A requirements scanner finds `MUST` in a specification and reports certainty. It has found a word, not yet an obligation. Barry Leiba’s RFC 8174 drew a clean boundary around the special vocabulary of BCP 14, but the boundary works in both directions: capitals activate defined…

IETF
Michelle Cotton and the Code Point That Arrived Before Its RFC
The awkward moment comes before a standard is finished: two implementations need the same numeric language to meet, but the registry would normally wait for publication. Michelle Cotton’s RFC 7120 turned that timing gap into a visible, expiring state. Its most important word is…

IETF
Erik Kline and the DHCP Code That Was Assigned but Not Vacant
A standards registry said 160; a live network said the number already had another life. The resulting collision did not make the registry irrelevant, nor did it make undocumented use legitimate. It showed something more operationally useful: an authoritative assignment can define…

IETF
James Gould and the Redaction Signal That Is Not Policy Proof
An empty place in an RDAP response can mean that no value exists, that a value was withheld, or that the question exposed a shape the server chose not to acknowledge. RFC 9537 gives one of those absences a machine-readable explanation. James Gould’s work on the specification…

IETF
Hugo Krawczyk and the Public Salt That Is Not Password Hardening
A value may be public, repeated and still do important cryptographic work. That is the apparent paradox at the centre of HKDF. Hugo Krawczyk’s extract-then-expand design makes the answer operational: salt, source entropy and application context are separate inputs with separate…

IETF
Suzanne Woolf and the Server Label That Is Not a Machine Identity
A DNS reply can carry a label for the server that produced it. That sounds like identity until anycast, operator-defined bytes and hop-by-hop scope are allowed back into the picture. Suzanne Woolf’s work on the requirements behind NSID offers a more useful interpretation: the…

IETF
Sara Dickinson and the Resolver Promise Encryption Cannot Prove
The padlock beside a DNS resolver name is reassuring because it proves something useful: the client has protected its conversation on the way to a particular service. It is also dangerously easy to ask that icon to prove the rest. Sara Dickinson’s co-authored RFC 8932 follows the…

Leaders
Nurani Nimpuno and the Accountability Layer Behind Number Governance
Internet number governance is often described through institutions and acronyms. Nurani Nimpuno’s public record reveals a more useful operating question: how can a community preserve technical discretion while making delegated authority reviewable?

IETF
Ole Trøan and the Three Decisions NAT Used to Hide
A laptop has two globally usable IPv6 addresses, two routers and two DNS resolvers. Nothing is missing, yet the first packet can still fail: the chosen source may belong to one provider, the chosen door to another, and the chosen name answer to a third context. Ole Trøan’s…

Leaders
Kanchana Kanchanasut and the Infrastructure Hidden Inside a First Connection
The celebrated moment in Kanchana Kanchanasut’s career is an early connection: an email link from the Asian Institute of Technology to colleagues outside Thailand. The more durable story is what had to come after that experiment—addressing, operating institutions, training and a…

IETF
Tim Chown and the Host List Hidden Inside an IPv6 Address Plan
IPv6 made blind enumeration uneconomic, but it did not abolish reconnaissance. Tim Chown’s work shows how addressing conventions and operational exhaust can turn an immense namespace into a succession of small, testable target lists—and why defenders face the same discovery…

IETF
Brian Haberman and the 40-Bit Global ID That Was Not an Allocation Receipt
A locally generated IPv6 prefix can be extraordinarily unlikely to collide with another one and still carry no guarantee. Brian Haberman’s work on RFC 4193 makes that distinction operational: probability reduces coordination cost, but only an inventory, a route decision and a…

ICANN
Allison Mankin and the Name-Collision Sample That Could Not Prove Its Cause
A root server can record a query for a private-looking name with great precision. The record still cannot say which application produced it, who owns the broken dependency, how many users rely on it or what a future delegation would harm. Allison Mankin’s work on RFC 8023 helps…

IETF
Radia Perlman and the Appointed Forwarder That Had to Stop Forwarding
A TRILL switch may still hold the appointment for a VLAN while its safest legal action is to drop the native frames it would normally handle. That is not a contradiction in the standard. It is the moment when recorded authority and permission to act must be read as separate…

Leaders
Hisham Ibrahim and the Measurement Problem Inside Community Building
When RIPE NCC reorganised its community work in 2021, Hisham Ibrahim inherited more than a collection of events and services. He inherited a harder management question: how can an institution tell whether community activity creates lasting value rather than merely producing a…

Leaders
Daniel Fett and the Issuer Field That Named the Server, Not the Token
An OAuth callback can contain the right state and a real authorization code and still be on its way to the wrong server. RFC 9207 adds one small comparison before that mistake becomes a disclosure: did the server named in the response match the issuer the client recorded when the…

History
The Address Was Supposed to Declare the Charging Rule Before Contact: RFC 1681
In 1994, one IPng paper imagined a Gopher server redirecting a caller to a paid destination before any useful warning could appear. Its answer was to make the destination address speak first: some bits would identify who paid, or point to a charging algorithm. RFC 1681 exposed a…

History
The Test Measured the Reserve by Spending It: RFC 1628
A UPS exists to preserve power when ordinary supply disappears. RFC 1628 defined a diagnostic that learned more about that reserve by deliberately drawing it down. The result could improve confidence in battery replacement and run time, but the test left the protected load with…
