Skip to main content

Topic

Security Automation

Within the Topic facet, Security Automation topic intelligence connects articles that share a specific subject, signal focus, or monitoring theme. The page gives readers a richer path through related reporting, source evidence, market actors, and infrastructure implications, with enough context to understand why the topic matters across company movements, governance decisions, regional exposure, and operational risk. Readers can compare recurring signals, affected organisations, public evidence, market context, service continuity, procurement, competition, compliance, and strategic planning questions behind the subject instead of stopping at a thin list of matching articles. It explains what the topic covers, which infrastructure actors or policies are involved, what evidence supports the coverage, and why the subject may matter for operators, customers, investors, and policy readers.

Two mail servers exchange amber cleartext capability cards that dissolve at a central TLS boundary before a fresh blue capability exchange begins

History

The Greeting That Had to Be Repeated: How STARTTLS Reset SMTP Trust

The first greeting crossed the network in the clear. So did the client's name and the server's list of abilities. When SMTP added encryption without abandoning its old port, the protocol could not simply wrap that conversation and pretend it had always been protected. It had to…

Aug 24, 2026
A cyan credential token is verified at one submission gateway while a separate amber envelope and white content sheet continue through neutral mail relays beyond the trusted boundary

History

The Credential That Could Not Sign the Message: How SMTP AUTH Bounded Submission Identity

A password could open a mail submission gate. It could not sign the letter that passed through it. SMTP AUTH became useful precisely because the protocol kept those propositions apart: this client authenticated here; this account may act in certain ways; this message claims a…

Aug 24, 2026
AI-generated illustration of FreeRADIUS connecting Wi-Fi, network access, VPN, identity, certificate and accounting systems.

Global Institutional

FreeRADIUS and the trust decisions behind network access

A network login may be decided in a few packets, but the trust behind it can span certificates, directories, access devices, roaming partners and accounting systems. FreeRADIUS makes that policy inspectable and programmable, while leaving operators responsible for the legacy…

Aug 24, 2026

CASE FILE

The Tag Fit. The Authority Did Not: BGP Large Communities and the Namespace That Executes Policy

The route carried exactly the value the interconnection handbook prescribed. One provider acted on it, another erased it, and a third would have accepted the same instruction from a party that had never been authorized to give it. Twelve octets solved the numbering problem. They…

Aug 24, 2026

CASE FILE

The Route That Knew Nothing and Reached Everything: BGP Default Origination and the Authority of Last Resort

A customer still had an Established BGP session, a selected `0.0.0.0/0` and several successful probes. Most of the Internet had nevertheless become unreachable. The route with the widest scope had survived the loss of the service it was supposed to summarize.

Aug 24, 2026

CASE FILE

The Path Was Shorter Because the Evidence Was Gone: BGP ATOMIC_AGGREGATE and the Authority to Compress

The `/22` remained visible, its origin stayed valid and every external session was green. One of the four `/24`s beneath it had nevertheless disappeared. The public path looked cleaner at precisely the moment when the network knew less about the destinations it claimed to reach.

Aug 23, 2026

CASE FILE

The Internet Saw One AS. Operations Had Twelve: BGP Confederations and the Authority of a Hidden Topology

The public route never changed. External peers still saw AS 64500, the sessions remained Established and the prefix stayed visible in collectors. Inside the network, however, one router had crossed from Member-AS 65021 to 65031 while its neighbor still believed the old boundary.…

Aug 23, 2026

CASE FILE

The Router Could Not Read the Attribute, So It Forwarded It: BGP's Partial Bit and the Authority of Ignorance

This technical explainer opens with a constructed operating scenario, not a reported incident. The transit router does exactly what the protocol asks: it receives a route carrying an optional transitive attribute it does not understand, preserves the opaque bytes, sets Partial…

Aug 23, 2026

CASE FILE

The Prefix Was IPv4; the Way There Was IPv6: RFC 8950 and the Authority of a Cross-Family Next Hop

In an illustrative migration scenario, the maintenance report says the IPv6-underlay change succeeded. Every BGP session is Established, capability 5 appears in both OPEN messages, and the IPv4 prefixes remain visible. Yet one rack cannot reach an IPv4 customer. The route exists…

Aug 23, 2026
A cyan request path crosses an amber access-network boundary that reveals a separate portal route while the trusted origin keeps its own sealed identity

History

The Network Answered in the Origin's Place: Why HTTP Needed 511

A client asked one server for a resource and received an answer from the network in between. HTTP 511 tried to name that substitution without granting the interceptor the origin's identity. Its limits explain why captive-portal design later moved toward provisioned, authenticated…

Aug 23, 2026

CASE FILE

The Next Key Was Announced but Not Delivered: TCP-AO and the Authority of a Key Epoch

In an illustrative rollover scenario at 02:07, the dashboard turns green. Both BGP routers show key 42 in their key chains, and one captured TCP segment carries `RNextKeyID=42`. The operator concludes that the rollover has completed and deletes key 17. Seconds later, TCP…

Aug 23, 2026
A client opens control and data paths through a firewall while an old server callback stops at the boundary

History

The Server That Stopped Calling Back: How Passive FTP Crossed the Firewall

FTP’s most consequential accommodation to the firewall was not encryption, tunnelling or a new transfer engine. It was a smaller decision: let the client make the second call. That reversal made old machinery fit a new network boundary while leaving security judgment where it…

Aug 23, 2026

CASE FILE

The Packet Arrived with No Distance to Spare: BGP GTSM and the Authority of Proximity

In an illustrative maintenance scenario at 02:13, one direction of a multihop BGP session moves onto a longer path. The peer still emits every TCP segment with TTL 255. The receiver, configured to admit two routed hops, now sees 252 instead of 253 and discards the traffic before…

Aug 23, 2026
A host chooses a narrow reachable route from a few first-hop advertisements while a higher-preference path is broken

History

The Host That Learned a Small Routing Table: How IPv6 Ranked First Hops

IPv6 did not make every host a routing speaker. It let a router disclose a few expiring choices, then left the host to combine longest-prefix logic, observed reachability and local policy. The useful invention was as much the boundary as the route.

Aug 23, 2026

CASE FILE

The Filter That Crossed the Session but Not the Boundary: BGP ORF and the Authority to Ask for Less

Consider an illustrative customer changing its inbound prefix-list from a full table to a narrow feed. Its router immediately looks cleaner: unwanted routes disappear from the local RIB. Yet the provider may still be generating and transmitting every one of them, only to have the…

Aug 23, 2026

CASE FILE

The Session Was Established and Carried No Routes: RFC 8212 and the Authority of Explicit Policy

The following replacement-edge maintenance scenario is illustrative, not a reported incident. The new edge shows `Established`; KEEPALIVEs advance and the peer has been stable for twenty minutes, yet the IPv4 table is empty and nothing has been advertised. The transport is…

Aug 23, 2026
A translucent candidate endpoint waits behind a gate while local-link probes return with matching and different nonce tokens

History

The Silence That Licensed an Address: What IPv6 DAD Could Prove

IPv6 DAD based an important decision on a negative observation: no rival appeared during a bounded local probe. The protocol had to say exactly how far that silence could reach.

Aug 23, 2026

CASE FILE

The Session Fell Silent but Left a Reason: BGP Shutdown Communication and the Authority to Explain a Closure

The peering drops at the scheduled minute. This time the receiver does not see only `Cease`. The terminal NOTIFICATION also carries a compact ticket reference, a reason and an expected maintenance interval. That text can remove hours of ambiguity. It can also be forged, exposed…

Aug 23, 2026

CASE FILE

Both Connections Reached OPEN; Only One Could Remain: BGP Collision Detection and the Authority of a Stable Identifier

Both routers dial at once. Two TCP connections complete between the same pair of addresses, and each carries a valid BGP OPEN. Neither transport is broken. Yet one configured peering cannot keep two competing finite-state machines and two versions of its session history. BGP…

Aug 23, 2026

CASE FILE

The Peer Kept Sending but Stopped Receiving: BGP SendHoldTimer and the Authority to End a One-Way Session

The neighbour is still sending KEEPALIVEs, so the BGP dashboard remains green. Yet its TCP receive window has collapsed to zero and none of the local withdrawals can leave the socket. The session is established, inbound liveness is real, and the route information held by the…

Aug 23, 2026