Skip to main content

Topic

Software Lifecycle and Lock-in

Within the Topic facet, Software Lifecycle and Lock-in topic intelligence connects articles that share a specific subject, signal focus, or monitoring theme. The page gives readers a richer path through related reporting, source evidence, market actors, and infrastructure implications, with enough context to understand why the topic matters across company movements, governance decisions, regional exposure, and operational risk. Readers can compare recurring signals, affected organisations, public evidence, market context, service continuity, procurement, competition, compliance, and strategic planning questions behind the subject instead of stopping at a thin list of matching articles. It explains what the topic covers, which infrastructure actors or policies are involved, what evidence supports the coverage, and why the subject may matter for operators, customers, investors, and policy readers.

CASE FILE

The Group Key Reached the Devices. It Did Not Assign the Act: RFC 10020 and CoAP Group Authority

A protected message can leave one sender and be intelligible to a group. It cannot make five receivers one decision-maker. RFC 10020 matters because it gives constrained systems a disciplined way to speak to a group without erasing the separate evidence required for membership…

Sep 1, 2026

CASE FILE

The Model Named an Endpoint. It Did Not Start a Service: RFC 10009 and HTTP Configuration Authority

An HTTP endpoint can look settled long before it exists in practice. A URI is present in a management tree; permitted versions are listed; TLS parameters and a proxy are named; a server has a name and an apparent stack. Those are useful, reviewable decisions. RFC 10009 makes…

Sep 1, 2026
A warm local-name plaque, a pale host-zero record card, a nested amber mask lattice and a separate blue number tree are linked but remain distinct.

History

The Name Was Local. The Number Still Needed a Record: RFC 1101’s DNS Mapping Boundary

In 1989, DNS could already distribute host information, but it did not yet offer a standard way to ask what a network number was called. RFC 1101 proposed a small answer: use PTR records, host-zero names and masks in `IN-ADDR.ARPA`. Its lasting discipline is equally small. A…

Sep 1, 2026

CASE FILE

What the Aggregate Report Actually Knows: RFC 9990 and the Boundary Before Enforcement

A DMARC dashboard can make a narrow observation look like a verdict. One receiver reports a large count from a source range, records an evaluated policy and shows a disposition. That is valuable operational evidence. It is not a global traffic census, proof of a sender's intent…

Sep 1, 2026

CASE FILE

The Preference Was Published. It Was Not an AI Control: RFC 9969

RFC 9969 records an Internet governance problem without pretending to solve it by publication. A preference attached to content can tell another actor what an owner wants considered. It does not identify that actor, bind a downstream model, prove a use was compliant, create an…

Aug 31, 2026
Panos Kampanakis in an AI editorial portrait beside three abstract SSH security checkpoints.

IETF

Panos Kampanakis and the SSH Session with Three Different Security Receipts

An SSH client can negotiate a hybrid ML-KEM key exchange, verify the server through a conventional host key, and admit a user through a still separate credential. The session is one connection; the evidence is not one claim.

Aug 31, 2026

CASE FILE

The Provisioning Realm Was Requested. It Was Not Network Access: RFC 9965

RFC 9965 gives an uncredentialed EAP peer a disciplined way to ask for a provisioning path. The `eap.arpa` realm and its provisioning identifier make a request legible; they do not authenticate the peer, prove a route, issue a credential or grant general network access.

Aug 31, 2026
A luminous cyan fiber ring surrounds a nested amber packet panel; a small local mapping tile sits below while a muted distant endpoint remains visibly separate.

History

The FDDI Frame Carried IP. It Did Not Carry Identity: RFC 1188’s Encapsulation Boundary

An FDDI interface could put an IP datagram onto a fast local ring only after several small facts agreed: which link grammar carried the payload, how large a packet could be, and which local hardware address represented an IP neighbour. RFC 1188 made those facts interoperable in…

Aug 31, 2026

CASE FILE

The Hybrid Secret Was Derived. The Client Still Had to Trust the Host: RFC 10042

RFC 10042 gives SSH a precise way to combine ML-KEM and classical ECDH into a fresh session secret. It makes a key-establishment transcript stronger against a defined class of cryptographic risk; it does not make the client’s host-trust decision, authenticate a user, grant an…

Aug 31, 2026
A small envelope follows a route to an amber mailbox-shaped contact node, while three separate local operational zones retain distinct boundaries and tools.

History

The Mailbox Was a Contact. It Was Not a Control Room: RFC 1173’s “Oral Tradition”

Before the Internet had a single operational mythology, it had a more modest arrangement: if a problem crossed a boundary, someone needed to be reachable on the other side. RFC 1173, published in 1990, made that arrangement visible. Its lasting lesson is not that a role mailbox…

Aug 31, 2026

CASE FILE

The TACACS+ Server Was Configured. Its Authority Was Not: RFC 9950

RFC 9950 gives a device a precise YANG surface for configuring TACACS+ servers, credentials and safeguards. That configuration can change a powerful future control path; it is not an authentication event, an authorization result or a proof that a server may decide for anyone.

Aug 31, 2026

CASE FILE

The Test Was Authenticated. The Capacity Claim Was Not: RFC 9946

UDPSTP can authenticate its control exchange, limit a short diagnostic test and feed status back to a sender. RFC 9946 does not convert any resulting number into a capacity entitlement, a service guarantee or an operator verdict.

Aug 31, 2026
A non-readable policy sheet hovers over a shared research-network field while five abstract markers and three separate local control zones remain visibly distinct.

History

A Policy Sentence Was Not a Network Control: RFC 1087 and the Limits of “Acceptable Use”

In 1989, the Internet Activities Board could identify conduct that threatened a shared research facility. It could say that intentional intrusion, disruption, waste, destruction and privacy compromise were unacceptable. What it could not do with a sentence was observe an act…

Aug 31, 2026
An editorial diagram shows a cyan message crossing several dark adapter gates while an amber line returns to its exact source; a separate coral integrity rail and destination sockets remain independent.

History

The Bit Preserved a Return Path. It Did Not Authenticate the Request: RFC 1044's HYPERchannel SRC

In a physical network, an address can do something concrete without saying who is entitled to act. RFC 1044 gave HYPERchannel messages a Source Address Correct bit that could survive only while the declared return address remained usable in reverse. That was valuable path…

Aug 31, 2026

CASE FILE

The CMC Message Arrived. It Did Not Arrive With Certificate Authority: RFC 10003

One CMC entity can travel by file, mail, HTTP or TCP. RFC 10003 makes that portability useful without turning any carrier, delivery receipt or listener into proof that a certificate authority made a decision.

Aug 31, 2026
Two vintage terminals exchange a consent gesture, a query pulse and a reply pulse; unnumbered local display dials and paced light bands remain separate from a neutral connecting line.

History

The Speed Was a Display Hint. It Was Not the Link: RFC 1079’s Telnet Boundary

In 1988, a remote terminal program could know something useful about the terminal at the other end without pretending to know the network between them. RFC 1079 made that distinction unusually crisp. It let one Telnet peer request a pair of terminal speeds and let the other peer…

Aug 31, 2026

CASE FILE

The Key Became Portable. Custody Did Not: RFC 9964, ML-DSA and the AKP Boundary

Post-quantum migration often arrives in a deceptively tidy form: choose a new algorithm, register an identifier, put a key in the familiar container, and continue signing. RFC 9964 does something more useful and more limited. It defines how ML-DSA keys and signatures can travel…

Aug 31, 2026

CASE FILE

A Completed SCIM Request Is Not a Completed Cross-Domain Decision: RFC 9967

An asynchronous identity request is easy to over-read. A provider accepts a SCIM change, returns 202, and later emits a Security Event Token that carries the same transaction value. The trail is valuable: it gives two parties something specific to correlate. But it does not…

Aug 31, 2026
An editorial illustration of four cyan format-selector blocks opening a bounded BOOTP option rail, with an unknown amber block bypassed before a red end marker and a separate unverified source.

History

Before DHCP, Four Bytes Chose the Grammar: RFC 1048 and BOOTP's 64-Octet Limit

Before a diskless machine could fetch its operating system, it needed enough network knowledge to ask for one. BOOTP carried that knowledge in a field only 64 octets long. RFC 1048 made the field intelligible across vendors with four opening bytes and a compact option…

Aug 31, 2026

CASE FILE

The Legacy Code Point Reached the Client. It Did Not Reauthorise the Server: RFC 9963

An IANA code point can look like a broad permission slip when it appears in a migration review. RFC 9963 is deliberately narrower. It gives TLS 1.3 three legacy RSASSA-PKCS1-v1_5 signature values, but only for a client proving possession of a client-certificate key after a server…

Aug 31, 2026