Topic
Network-resource Evidence
Within the Topic facet, Network-resource Evidence topic intelligence connects articles that share a specific subject, signal focus, or monitoring theme. The page gives readers a richer path through related reporting, source evidence, market actors, and infrastructure implications, with enough context to understand why the topic matters across company movements, governance decisions, regional exposure, and operational risk. Readers can compare recurring signals, affected organisations, public evidence, market context, service continuity, procurement, competition, compliance, and strategic planning questions behind the subject instead of stopping at a thin list of matching articles. It explains what the topic covers, which infrastructure actors or policies are involved, what evidence supports the coverage, and why the subject may matter for operators, customers, investors, and policy readers.

Story
RIPE Marked the Upgrade Complete. Retrieval Failed Twice Afterward
At 17:56 CEST on 22 August, RIPE NCC marked its Alfresco maintenance complete. On Monday afternoon, document creation still worked but some files could not be viewed or downloaded. On Wednesday, a second incident began; RIPE NCC later changed the document system’s configuration…
CASE FILE
The Signal Was Signed. The Delegation Was Not Yet Secure: CDS/CDNSKEY and the Authority to Publish DS
A child zone can publish a perfectly signed request for a new DNSSEC secure entry point and still lack the one chain that would validate it. CDS/CDNSKEY makes parent coordination machine-readable; it does not collapse operational control, registrant authority, parent admission…
CASE FILE
The Catalog Was Valid. The Deletion Was Not: DNS Catalog Zones and the Authority to Provision
An authenticated DNS transfer can deliver a perfectly formed catalog whose operational consequence is to remove every zone from a secondary fleet. The transport may be trustworthy and the syntax impeccable while the decision encoded inside it is still wrong. DNS Catalog Zones…

History
The Identifier That Could Survive a Session but Not a Rebirth: Why IMAP Needed UIDVALIDITY
An email client can remember a message for months, reconnect, and find it again by number. The difficult part is not making that number stable. It is admitting when the number has stopped meaning what the client remembers. IMAP solved that problem by pairing a persistent UID with…

IETF
David Meyer and the Address That Had to Ask Where It Lived
LISP lets an endpoint keep one identifier while its network attachment is described separately. That does not make location disappear. It moves forwarding into a chain of registered, resolved, cached, selected and reachable EID-to-RLOC state—and turns each link in that chain into…
CASE FILE
The Answer Had Expired. The Failure Had Not: DNS Serve-Stale and the Authority Beyond TTL
A DNS answer can outlive its ordinary freshness without becoming current again. Serve-stale is the resolver's narrow authority to prefer a known old answer over a fresh failure, but only after the source has been consulted, the failure has been bounded and the age of the…

History
The Bit That Refused to Make Half an Answer True: How DNS Changed Transport
A DNS server in 1987 had a small envelope for an ordinary reply: 512 bytes over UDP. The consequential invention was not merely a larger route. It was one bit that admitted when the envelope had failed, so a resolver would not mistake the records that happened to fit for the…

History
The Six Bits That Could Ask but Not Command: How DiffServ Bounded Quality of Service
A packet can arrive wearing the mark for expedited treatment and still enter an ordinary queue. DiffServ made that outcome legitimate by design: six header bits could select a behavior, but only the network that owned the queue could decide whether the request was trusted…
Story
ACSK-RIPE and AS210263: A Contact Handle Is Not a Control Title
ACSK-RIPE and AS210263: A Contact Handle Is Not a Control Title intelligence summary explains the development, the public evidence available to readers, the organisations involved, the regional context, market exposure, and the infrastructure consequences that may follow. The…

Story
AFRINIC’s Trust Anchor Still Runs to 2030. The NRO Roadmap Said “Short-Lived” by the End of 2025
A roadmap can name a destination and a date. It cannot prove that a live trust anchor has crossed the line. AFRINIC’s retrievable certificate shows why RPKI commitments need an implementation receipt rather than a silently ageing table.

Story
RIPE's Appointed NRO Seat Needs a Decision Receipt
RIPE NCC has opened a public door into one of its three NRO Number Council seats: nominations, eligibility checks and support statements are visible. The final passage is different. The Executive Board will appoint the member without a community vote, while the published election…

Story
RIPE NCC's 708 Extra Accounts Need a Migration Ledger
RIPE NCC has identified a rare simplification window. Only 410 members now operate more than one Local Internet Registry account, yet their 708 additional accounts keep complexity embedded across registry, billing, compliance and portal systems. Closing an exception is not the…

IETF
Joe Abley and the Trust Anchor That Had to Declare Where Trust Began
DNSSEC can prove a chain only after a resolver has decided where the chain starts. Joe Abley's work on the root trust-anchor publication format makes that first decision unusually legible: a signed file can prove where data came from, but it cannot order an operator to believe…

Story
K-root Says It Meets Every Expectation. The Evidence Is Uneven
RIPE NCC has answered the root-server community's operating expectations one by one. That makes K-root easier to question than a service hidden behind a general assurance of competence. Yet RIPE-859 also reveals a governance gap: a public metric, a control description and the…

Story
RIPE's NRTMv3 Stream Can Skip an Invalid Object. A Moving Serial Is Not a Completeness Receipt
RIPE Database release 1.124 made a small change with a large evidentiary consequence: the NRTMv3 server should skip invalid objects. Keeping a replication stream alive may be the right operational choice, but continuity alone can no longer answer the mirror operator's most…

APRICOT
Anurag Bhatia and the Routing Difference That Could Not Explain Itself
A missing route is an observation before it is a diagnosis. At APRICOT 2020, Anurag Bhatia compared selected BGP views and found tens of thousands of prefixes that were not equally visible. The valuable result was not a blacklist. It was a test of whether an operator can keep the…

Story
APNIC Prop-173 Would Put Copyright in Every Query. It Still Needs a Rights Ledger
An RDAP answer can carry a copyright notice in the same envelope as an address range, a registration date and a holder-supplied contact. That does not make every element the same kind of legal entity. APNIC’s prop-173 correctly identifies that ordinary directory queries lack the…

Story
LACNIC’s 70% Pass Mark Is Not a Candidacy Receipt
LACNIC’s Board-election rules contain a consequential distinction: a person can pass the mandatory competency assessment and still not become a validated candidate. The Electoral Commission receives the score and remote-proctoring incident evidence, but the public process does…

IETF
Geoff Huston and the IPv6 Default That Withdrew Itself
For a decade, `/48` looked like the neat answer to a difficult IPv6 question: how much address space should an ordinary site receive? Geoff Huston helped write the document that withdrew that single answer without surrendering the protections it was meant to provide.

Story
ARIN Put the Reg-RWS Key in a Header. That Does Not Make It Uncapturable
ARIN now accepts a Reg-RWS API key in the `Authorization` header while continuing to accept the same credential in a URL query string. The new channel removes a dangerous source of routine propagation, but the public record still needs to distinguish a safer request shape, client…
