Topic
Digital Identity and Credentials
Within the Topic facet, Digital Identity and Credentials topic intelligence connects articles that share a specific subject, signal focus, or monitoring theme. The page gives readers a richer path through related reporting, source evidence, market actors, and infrastructure implications, with enough context to understand why the topic matters across company movements, governance decisions, regional exposure, and operational risk. Readers can compare recurring signals, affected organisations, public evidence, market context, service continuity, procurement, competition, compliance, and strategic planning questions behind the subject instead of stopping at a thin list of matching articles. It explains what the topic covers, which infrastructure actors or policies are involved, what evidence supports the coverage, and why the subject may matter for operators, customers, investors, and policy readers.

CASE FILE
WebAuthn’s Remote Client Can Validate the RP ID. The Local Permission Cannot Prove It Did
The first public draft of WebAuthn Level 4 proposes a careful handoff for remote-desktop sign-ins: a local browser may use client data supplied by a remote machine, but only after a per-origin grant. That grant opens the local capability. It does not preserve evidence of the…

IETF
One Bearer Token, One Audience: WIMSE Revision 07 Draws the Receiver Boundary
An external identity provider that accepts the same bearer token as a Kubernetes API server does not merely validate the workload. It acquires a credential it can present back to the API server as that workload. Revision 07 of the WIMSE practices draft turns the separation of…

Story
One Revoked Certificate, Three Browser Outcomes at APNIC 62
The certificate was on the revocation list. That was not the end of the story. Geoff Huston's APNIC 62 demonstration put the same adverse record in front of three browser policies and obtained different results—a useful warning about the distance between publishing a security…

IETF
WebAuthn’s 2026 Rejoin Handoff: The Governance Receipt Behind a New Participation Cycle
The Web Authentication Working Group’s 11 September 2026 recharter begins a new institutional phase for WebAuthn. The central challenge is not simply continuing technical discussion; it is preserving a reliable record of how an approved charter becomes active participation and…

IETF
RFC 9787 and the Moment a Draft Becomes a Message: Encryption, Commitment and Cross-Device Custody
A protected email draft is not merely an early copy of a sent message. RFC 9787 treats it as a different authority state: unfinished text may need confidentiality from the mailbox service while remaining unreadable to intended recipients and unendorsed by the user's ordinary…

IETF
When “Lease” Stops Meaning “Address Assigned”
An operator upgrades a DHCPv6 inventory schema and discovers that one familiar dashboard label—“lease”—now conceals two different origins of authority. In one record, the server selected or delegated the resource. In another, the device selected a SLAAC or static address and…

Story
APNIC Wants Login to Read the Current IRT Email State
An account should not inherit yesterday’s lock answer when today’s IRT contact state says something else. APNIC’s 2026 roadmap proposes replacing reliance on a static account lock flag with a login-time check of continuously tracked IRT email validity. That is a small sentence…

History
Anita Borg and the Systers List: Admission to a Governed Room, Not Proof of Equality
A message could enter Systers because a member, an address and the list's routing rules admitted it to a private professional room. That delivery made scattered women in computing less isolated; it did not verify every identity claim, guarantee a career opportunity, erase…

History
Andrew S. Tanenbaum and the Amoeba Capability That Authorized an Object, Not a Person
Amoeba compressed a service address, an entity name, an operations mask and an anti-forgery check into 128 bits. The resulting capability could travel with user code and carry authority without a central list of holders—but a valid token still said nothing by itself about the…

History
Rob Pike and the 9P Walk That Opened Nothing
A client walks a name in 9P and receives every qid it expected. The path has resolved, yet no file has been opened and no byte has moved. The distinction at the heart of Rob Pike’s naming work is useful far beyond Plan 9: a protocol receipt is strongest when it is allowed to…

CASE FILE
The Algorithm Label Changed. The Key Refused to Follow: RFC 9709
An attacker can rewrite a cryptographic label without breaking the advertised cipher. RFC 9709 answers that awkward fact by making the complete encoded algorithm identity part of the key itself—and by forcing operators to separate successful processing from evidence they can…

IETF
Marshall T. Rose and the SNMP SetRequest That Changed Every Variable or None
A maintenance console sends one SNMP SetRequest containing several variable bindings. The agent answers `noError`. That is a useful receipt—but only for a deliberately narrow claim. The early SNMP design associated with Marshall T. Rose’s working-group leadership helps show why a…

Global Cloud Services Trends
SailPoint’s AI ARR needs a renewal-status column
SailPoint has put a number on its new AI business: more than US$70 million of annual recurring revenue. The number is useful precisely because it is not yet a revenue line. Its definition can keep a contract in the count after expiry while a renewal or replacement deal is still…

History
Jerry Saltzer and the Link That Carried a Name but No Permission
A path can tell a computer where a file is without answering whether the person following it may read the file. Jerry Saltzer’s account of protection in Multics turned that separation into an operating rule—and exposed how much revocation, audit and institutional power can be…

History
Eve Schooler and the Invitation That Did Not Carry the Conversation
The most consequential line in an Internet call is not the one carrying a voice. It is the one that finds the other person, proposes a session and then gets out of the way. Eve Schooler’s path from experimental conference control to the early Session Initiation Protocol helps…

History
Lixia Zhang and the Data Packet That Did Not Need Its Original Server
The revealing moment in Named Data Networking is not when a packet reaches a machine. It is when an Interest is answered by a copy found somewhere else—and the receiver can still ask who signed the data, whether that key was entitled to sign this name, and whether a fresher…

CASE FILE
The Resource Disappeared. So Did the Diagnosis: RFC 9729’s Concealed Authentication Boundary
Concealed authentication removes a useful signal from an intruder: the server no longer has to advertise a challenge before an authorized client can prove itself. The same silence can also erase the evidence an operator needs when a key is revoked late, a gateway exports the…

History
Kenneth J. Klingenstein and the Registry Between Two Login Domains
A login crossing from a university to an outside service looks like a short trip through a browser. Kenneth J. Klingenstein’s work helped expose the institution hidden in the middle: a trust fabric that must make one domain’s assertion usable in another without pretending that…

History
Klaas Wierenga and the Credential That Stayed Home
A student from Delft opens a laptop in Cape Town. The local university can offer a network, but it cannot vouch for the visitor’s account. Delft can vouch for the account, but it does not control the Cape Town network. Klaas Wierenga’s decisive contribution to eduroam was to make…

Story
ARIN Can Attach a Ticket to an Org ID. That Does Not Make It the Organization’s Decision.
ARIN fixed a mundane but costly support problem: staff no longer need to begin every ambiguous question by asking which organization it concerns. The resulting Org ID selector gives a ticket context and a durable home. That is good service design. It also makes one distinction…
