Topic
Security Automation
Within the Topic facet, Security Automation topic intelligence connects articles that share a specific subject, signal focus, or monitoring theme. The page gives readers a richer path through related reporting, source evidence, market actors, and infrastructure implications, with enough context to understand why the topic matters across company movements, governance decisions, regional exposure, and operational risk. Readers can compare recurring signals, affected organisations, public evidence, market context, service continuity, procurement, competition, compliance, and strategic planning questions behind the subject instead of stopping at a thin list of matching articles. It explains what the topic covers, which infrastructure actors or policies are involved, what evidence supports the coverage, and why the subject may matter for operators, customers, investors, and policy readers.

History
The Green Light That Was Not Yours: How NNTP Separated Group Policy from Posting Permission
A news server marks one group `y`, the old shorthand for posting permitted, and still refuses the person at the keyboard. Another group carries `n`, yet a specially privileged client may pass. NNTP did not contradict itself. It made the catalogue describe the group's ordinary…

History
The Address Seen from Outside: What STUN Could Discover but Not Guarantee
When a client behind a Network Address Translator (NAT) seeks to understand its reachable address from the perspective of an external server, it performs a specific exchange: sending a STUN Binding request. This request, originating from a known local address and port, traverses…
CASE FILE
The Certificate Named an Interface. It Did Not Prove the Device.
The commissioning test produced two honest identifiers. The certificate named the factory address of one Wi-Fi interface. The frame arriving at the access point used a private address chosen for that network. Rejecting the connection would punish a real device for using a privacy…

IETF
Brian Carpenter and the Boundary That Needed Proof
A network diagram can draw a clean perimeter around a campus, cloud overlay or industrial system. A packet cannot rely on the ink. Brian Carpenter and Bing Liu's RFC 8799 asks what must replace that intuition when a protocol has meaning only inside: verifiable membership…
CASE FILE
The Timestamp Got Sharper. The Clock Did Not Gain Authority.
Send one NTP request through ordinary UDP port 123 and its arrival may be timestamped after software and queueing have already left fingerprints on the measurement. Wrap the same logical request in a PTP event message, and a compatible network card can timestamp it at the wire.…

History
The Command Authentication Could Not Resume: How NNTP Made the Client Ask Again
An NNTP client asks for a restricted newsgroup and receives `480`. It authenticates successfully, yet the requested group does not open. The command must be sent a second time. That small repetition preserved a consequential boundary: proving an identity could change the…
CASE FILE
The Message Had Expired. The Mailbox Had Not.
At noon, an offer in the inbox reaches the date chosen by its sender. At 12:01, the mail reader dims it. Search still finds it, the archive still holds it, and no deletion has occurred. That small separation is the point of the IETF’s newly approved work on the email `Expires`…

History
The Birth Record That Could Outlive the Group: How ACTIVE.TIMES Separated Provenance from Availability
One list says a newsgroup can be selected now but remembers nothing about its beginning. Another preserves a group's local creation record after that group has disappeared from the selectable catalogue. NNTP made both answers valid on the same server. The apparent contradiction…

ICANN
ICANN Wrote a 24-Hour Disclosure Clock. Authentication Decides When It Starts
The most consequential sentence in ICANN's new urgent-disclosure rules is not the one containing “24 hours.” It sits lower on the same policy page, in an implementation note: the obligations become effective when ICANN fully implements a Consensus Policy that establishes…

History
The Prefix the Resolver Sent on Someone Else’s Behalf: EDNS Client Subnet
A recursive resolver usually speaks to an authoritative server from its own address. EDNS Client Subnet changed the message: the resolver could send part of a client's network instead, asking the authority to tailor an answer for someone who had not made that upstream query. The…

History
The Layer That Had to Come Last: How NNTP Compression Turned Order into Security
Two clients want the same three things: an encrypted channel, an authenticated account and fewer bytes on the wire. One asks for compression first. The server replies `206`, and two doors close: this connection can no longer begin TLS or accept `AUTHINFO`. The other client…

Global Cloud Services Trends
A Code-Signing Certificate Has Two End Dates
A replacement certificate changes tomorrow's build, but a valid timestamp can preserve yesterday's binary beyond the signer's expiry. The real cutover is therefore an inventory of artifacts, timestamp tokens, revocation time and verifier results—not a closed renewal ticket.

History
The Secure Channel That Had to Forget the Conversation: How NNTP STARTTLS Reset the Session
A news client has already inspected a server's capabilities, selected a newsgroup and positioned an article. Then it asks for TLS. The TCP connection stays open, but the protocol refuses to carry those earlier conclusions into the protected phase. The group selection disappears…

Global Cloud Services Trends
Fortinet's 52% Product Growth Shifted 6.5 Points Toward Lower-Margin Revenue
Fortinet's second quarter contains a useful contradiction. Product gross margin improved, yet the company's total gross margin fell. The missing fact is composition: product revenue grew 52% and moved 6.5 percentage points of the revenue mix away from the still-higher-margin…

History
The Article the Server Declined Before It Saw the Body: How IHAVE Separated an Offer from Acceptance
One news server offers three identifiers to a peer. The peer answers that it already has the first, cannot decide about the second just now, and wants the third. Only then does the third article cross the wire. Even that transfer does not settle the matter: after inspecting the…

History
The List That Described an Entire Hierarchy but Could Not Force It to Match: How checkgroups Separated Reconciliation from Ownership
Two news servers can receive the same newer, authenticated list of every group in a hierarchy and still end with different catalogues. One removes an old local entry that the list omits. The other keeps it as an explicit exception. The list is complete, scoped and ordered; the…

History
The Mapping the Host Could Request but the Gateway Still Owned: PCP
A PCP request looks like agency at the edge: a host names the service it wants exposed and proposes a public port. The reply reveals the harder truth. The gateway decides which mapping exists, for how long, and under whose policy—and the host must keep earning that state through…

History
The Group That Existed in a Message but Not on Every Server: How newgroup Separated Namespace Declaration from Local Adoption
A Netnews control article could carry a proposed group name across the network, yet the name became usable only where a serving agent chose to adopt it. The gap between declaration and local state was not a flaw around the protocol. It was the authority boundary that made a…

History
The Header That Opened the Gate but Could Not Authenticate Its Approver: How Approved Separated Moderation from Authorship
One Usenet article could carry its author's identity and somebody else's authority to publish it. The `Approved` header made that second role portable across the network, but it did not prove the person behind the mailbox name. Moderation worked only when an injecting agent…

History
The Message That Chose Failure Over Cleartext
Two messages could wait in the same relay queue for the same domain and deserve different outcomes. One might travel without TLS when security negotiation failed. The other carried `REQUIRETLS`, turning non-delivery from an accident into the only permitted result.
