Time Horizon
NEAR TERM
Within the Time Horizon facet, NEAR TERM time-horizon intelligence organises articles by the period over which a signal is expected to matter. The page helps readers distinguish immediate operational changes from longer-cycle governance, investment, standards, and infrastructure shifts that may unfold across quarters or years. It connects timing assumptions with public evidence, related actors, market context, customer exposure, policy pressure, and infrastructure planning so readers can judge whether a development is urgent, strategic, or still waiting on confirming evidence. The page also explains how time horizon changes the meaning of a signal, which organisations may be exposed, and which infrastructure decisions require short-term action or long-cycle monitoring.

IETF
A BMP Percentile Is Local Until Its Sampling Method Travels With It
A router can report a P95 that is correctly encoded, correctly attributed and still unsafe to compare with the P95 from the next router. The missing link is not another decimal place. It is the method that selected the observations from which the percentile was made.

IETF
IPv6-Only Is a Scoped Forwarding Claim, Not an IPv4 Decommission Certificate
The phrase “IPv6-only” sounds like a clean finish line. In an operating network it can describe something much narrower: one link natively forwards IPv6 while IPv4 still reaches users through translation, another plane remains dual-stack, and a management path still depends on…

IETF
A Valid CoSERV Result Is Not a Completeness Proof
A relying party asks for the reference material needed to judge attestation evidence. The query is deterministic, the response is signed, the contents are still valid and every cryptographic check succeeds. That is a strong result—but a bounded one. The exchange proves what was…

IETF
A Token Status Bit Is Not a Revocation Timeline
A relying party reads one compact value and declines a credential. The decision may be correct. Yet the bit alone cannot say when the underlying state changed, who authorised that change, when the list exposed it, which cached copy was consulted or why this application treated…

IETF
A Signed Transaction Token Does Not Attest Every Claim
A service accepts a correctly signed Transaction Token and treats every nested value as independently verified by the signer. The signature is real, the token is intact, and the conclusion is still too broad. What the Transaction Token Service chose to carry is not the same…

IETF
A TLS Flag Is Not a Feature-State Record
A monitor stores flag 8 as `true`. That compact fact does not say whether a client proposed a feature, a server announced it in a ticket, an acknowledgement was required, early data was involved, or the feature was ever exercised. The bit can be exact while the state inferred…

IETF
A QUIC Flow Record Is Not a Reconstructed Connection
Two values can sit in adjacent IPFIX columns and have completely different authority. A version number may have been read by a router from a visible long header. A stream ID may have been disclosed by an endpoint after removing packet protection. Standardising both field names…

IETF
RFC 9950 Can Configure TLS. It Cannot Authorize the AAA Cutover
RFC 9950 gives operators a precise language for telling network equipment how to reach TACACS+ servers over TLS 1.3. That language can name a server, select a security mode and point to credentials. It cannot say whether a fleet is ready to cross the bridge, who accepted the…

IETF
The Raised Eyebrow Has an RFC Number, Not Enforcement Power
RFC 9948 gives a raised eyebrow the furniture of officialdom: a permanent number, a DOI, capitalised requirement words and a place in the canonical RFC archive. The joke works because readers can see the furniture and the absurdity at once. A downstream system may preserve only…

IETF
RFC 9947 Keeps the Packets In. The Evidence Still Has to Leave
At the edge of an RFC 9947 experiment, a filter has a clear job: packets carrying the experimental SRH TLV must not cross the controlled-domain boundary. The harder crossing happens later. Results derived from real traffic are supposed to reach outside reviewers, and no packet…

IETF
RFC 9945’s Moderator Team Is Not Its Activation Receipt
The RFC is published. The team exists. A public repository contains procedures. None of those facts, taken alone, answers the question RFC 9945 itself makes decisive: which exact procedures did the IESG approve, and when did the new moderation regime take effect?

IETF
DetNet’s ‘Optimal Path’ Is a Governance Decision Before It Is a Calculation
A DetNet controller may be able to calculate several feasible routes and install one of them precisely. The difficult question arrives earlier: who was entitled to decide that latency mattered more than spare capacity, that protection justified duplicated resources, and that…

IETF
A Valid ECH Key File Does Not Prove the Right Privacy Boundary
RFC 9934 gives operators a portable way to place an Encrypted ClientHello private key beside the public configuration that uses it. The match is valuable, but it is smaller than the decision a privacy service must make: which names, DNS records, servers, retry paths and time…

IETF
The Route Policy Can Change While Its SR-Algorithm Number Stays the Same
RFC 9933 lets a path request name an SR-Algorithm. For a Flexible Algorithm, however, the number is only a handle: the policy that actually selects a route lives in a winning definition, a metric dictionary, a topology snapshot and an ordered evaluator that can all change…

IETF
A Valid Federation Signature Cannot Audit the Decision to Admit a Member
A machine can verify that a federation operator signed today’s member list. It still cannot see who admitted a member, which rule they applied, what evidence they accepted, or whether an exception has expired.

IETF
A Previous HTTP Upgrade Success Cannot Confirm the Next Protocol Transition
The proxy has seen this transition work a thousand times. It sends an HTTP/1.1 CONNECT request, expects the familiar success, and lets the application’s first bytes follow immediately. On attempt 1,001 the destination is unavailable and the proxy rejects the tunnel. The bytes…

IETF
A Valid YANG Schedule Is Not Evidence That Its Action Is Still Authorized
At 02:00, a controller executes the seventh occurrence of a maintenance schedule created six months earlier. The recurrence is enabled, its version is current, the clock is trusted and no scheduling conflict is reported. Yet the team that approved the action has been reorganized…

IETF
A YANG Service Model Can Match While Its Lifecycle Semantics Diverge
At 18:00, a time-bounded network service reaches the end written in its order. The BSS marks it complete. The orchestrator begins decommissioning. One controller still calls the connection active, another has already removed a segment, and the assurance system reports a healthy…

IETF
A Company-Certs Endpoint Cannot Prove Who Approved a Trust-Anchor Rollover
At 10:00, an application retrieves two valid private-CA chains from its company’s well-known HTTPS endpoint. The older chain still works; the newer chain has the later `valid_from`, so the client selects it exactly as the draft describes. TLS validation passed, the JSON parsed…

IETF
A Workload Credential Can Outlive the Attestation Decision Behind It
At 09:00 a workload proves that it is running in Germany and receives an eight-hour credential. At 09:05 the orchestrator moves it to France. The credential still verifies, the key is still under the workload’s control, and the unchanged service still accepts it. Yet one fact…
