Topic
Software Lifecycle and Lock-in
Within the Topic facet, Software Lifecycle and Lock-in topic intelligence connects articles that share a specific subject, signal focus, or monitoring theme. The page gives readers a richer path through related reporting, source evidence, market actors, and infrastructure implications, with enough context to understand why the topic matters across company movements, governance decisions, regional exposure, and operational risk. Readers can compare recurring signals, affected organisations, public evidence, market context, service continuity, procurement, competition, compliance, and strategic planning questions behind the subject instead of stopping at a thin list of matching articles. It explains what the topic covers, which infrastructure actors or policies are involved, what evidence supports the coverage, and why the subject may matter for operators, customers, investors, and policy readers.

IETF
The Signature Algorithm Is Not the Signed Byte Sequence: RFC 9882 and ML-DSA in CMS
Two CMS systems choose ML-DSA-65 for identical content, yet verification fails when one signs a final implicit-tag representation and the other verifies the complete DER SignedAttrs value with its explicit SET OF tag. The algorithm is the same; the signed byte domain is not.

History
The Packet That Waited for Its Predecessor: Nagle's Small-Segment Rule
A one-byte write did not need a universal delay timer. It needed a rule about whether the connection already had data in flight. Nagle's answer made acknowledgment state—not the wall clock—the gate for another short TCP segment.

Global Cloud Services Trends
A TLS Delegated Credential Is Not a Delegation of Domain Control
A short-lived credential can let a CDN edge complete a TLS handshake without holding the certificate owner's long-term private key. That is a precise cryptographic delegation. It is not a transfer of the domain, certificate-issuance authority or the organisation behind either…

IETF
The Algorithm Name Is Not the Certificate Profile: RFC 9881 and ML-DSA in PKIX
The Algorithm Name Is Not the Certificate Profile: RFC 9881 and ML-DSA in PKIX intelligence summary explains the development, the public evidence available to readers, the organisations involved, the regional context, market exposure, and the infrastructure consequences that may…

IETF
A Data Model Is Not a Wire Contract: RFC 9880 and SDF Protocol-Binding Boundaries
Two implementations can claim the same Thing model yet disagree on the wire: one chooses a URL and JSON payload convention, while the other expects a numeric identifier and different invocation rules. The gap appears when a protocol binding was implicit rather than versioned and…

History
The Probe That Could Not Declare an Idle Peer Dead: TCP Keep-Alives
An idle TCP connection can be quiet without being broken. Keep-alive probing was designed to ask whether the peer's transport state could still answer, while denying any single unanswered probe the authority to declare that state dead.
IETF
A Hybrid SSH Key Exchange Turns Algorithm Negotiation into a Migration Boundary
Installing post-quantum code does not mean an SSH session used it. RFC 10042 defines three hybrid methods that combine ML-KEM with an established elliptic-curve exchange. The protection becomes real only when both peers offer the same method, negotiation selects it, both…

History
The Window That Refused to Open One Byte at a Time: TCP Silly Window Syndrome Avoidance
A TCP receiver can have room for more data without advertising that room immediately. That deliberate silence prevents a small permission from becoming a self-repeating stream of small packets.

History
The Window That Closed Without Ending the Connection: TCP Persist
When a TCP receiver says it has no room left, the sender stops sending ordinary data. The harder question is how either side escapes that pause if the one message announcing new room never arrives.

History
The Number Made Harder for an Off-Path Attacker to Predict: TCP Initial Sequence Numbers
A TCP connection begins by exchanging numbers. The security change was not to hide that exchange, but to stop one visible number from revealing the next connection's starting point.

Global Institutional Trends
A Valid Software Signature Is Not a Durable Authority Record
A green verification result can survive long after the authority that made a release legitimate has changed. The cryptography may still be sound. The missing evidence is organisational: who was permitted to sign, under which role, at what time, and what later revocation or…

History
The Chain That Made a Public Key Believable: PEM Certificate Management
A public key does not identify its owner by itself. RFC 1422 addressed that gap for Privacy Enhanced Mail by specifying certificates, certification authorities, validation paths, and revocation information—the institutional machinery needed before a relying party could treat a…

History
The Pointer That Was Never Out of Band: TCP Urgent Data
TCP urgent data is a small control surface with a long history. The URG flag makes a 16-bit urgent pointer meaningful, but RFC 793 described the boundary it marks in two contradictory ways. That ambiguity crossed from the specification into implementations and application APIs.

Global Cloud Services Trends
A Root Certificate Removal Is a Fleet Migration Before It Is a Browser Update
A root programme can withdraw trust in one release while many applications keep making decisions from older, private or embedded stores. The security change is complete only when the verifiers that matter can prove the intended rejection.

IETF
The Bitmap Says a UDP Option Appeared—not What It Did: RFC 9870
RFC 9870 gives IPFIX exporters a compact way to report which UDP Option kinds appeared in a Flow. Its bitmaps are useful precisely because their claim is narrow: they preserve observed presence, not a packet history, a receiver’s processing decision or an application outcome.

CASE FILE
At Python, an Accepted PEP Is Neither a Release Commitment Nor an Implementation Receipt
Python’s public process deliberately separates the decision on a proposal from the work of making it real. A PEP may be discussed by contributors, resolved by the Steering Council or an approved PEP-Delegate, implemented in CPython, merged to a particular branch and eventually…

History
Six Bytes Became an Address Only After the Domain Was Known: RFC 1449
An archive can preserve every octet and still lose the fact. Imagine finding six bytes in an old SNMP configuration: four could be an IPv4 address and two could be a UDP port. That reading is valid only if another field says the value belongs to the UDP transport domain. Without…

History
The Database Said One Address. The Reply Followed the Packet Back: RFC 1445
The address book and the live packet disagreed. For a new request, the 1993 SNMPv2 administrative model used the address recorded for the destination. For the reply, it ordered something else: use the transport domain and address from which this request actually arrived, even if…

CASE FILE
At Apache, a Release Vote Is Neither a Code Veto Nor a Board Technical Decision
At the Apache Software Foundation, a person can commit code, a qualified voter can stop a code change, a PMC can issue a formal release, and the Board can oversee the Foundation. Those acts sit in one institution, but they do not carry the same authority. Treating them as one…

Story
RIPE's Flip Chart Experiment and the Work After the Introduction
A paper board helped researchers and network operators find one another. RIPE NCC's new account points to a useful next test: whether a promising introduction becomes a question both sides can afford to pursue, without silently committing either to data access or production…
