Topic
Software Lifecycle and Lock-in
Within the Topic facet, Software Lifecycle and Lock-in topic intelligence connects articles that share a specific subject, signal focus, or monitoring theme. The page gives readers a richer path through related reporting, source evidence, market actors, and infrastructure implications, with enough context to understand why the topic matters across company movements, governance decisions, regional exposure, and operational risk. Readers can compare recurring signals, affected organisations, public evidence, market context, service continuity, procurement, competition, compliance, and strategic planning questions behind the subject instead of stopping at a thin list of matching articles. It explains what the topic covers, which infrastructure actors or policies are involved, what evidence supports the coverage, and why the subject may matter for operators, customers, investors, and policy readers.

History
The Line That Looked Like the End in SMTP
SMTP ended unknown-length mail with a one-period line. Dot stuffing made that sentinel reversible; CHUNKING later moved the boundary to exact octet counts.

History
Permission Was Not Acceptance: Why HTTP Added 100 Continue
HTTP 100 Continue let a server reject from headers before a large body crossed the network, while keeping interim permission separate from final acceptance.

IETF
Tony Li and the Four-Byte Envelope That Refused to Rule the Payload
A GRE tunnel gives a packet a second address without taking away the first. The outer header decides how the envelope crosses an underlay; the inner header still decides what happens after the envelope is opened. Between them, the smallest GRE header can occupy only four octets.…
CASE FILE
The Key Installed Twice: KRACK and the Authority of a Retransmission
Wireless loss made retransmission necessary. KRACK exposed the hidden assumption that arrived with it: an authentic copy of a handshake message could be treated as fresh authority to install an already-active key. The password held. The key stayed secret. The state around the key…
CASE FILE
The Failure That Chose the Cipher: POODLE and the Authority Hidden in Fallback
A failed TLS handshake should have been evidence of one thing: this connection attempt did not work. Compatibility code turned it into a much larger claim - that the server needed an older protocol. POODLE showed what happens when an attacker who can cause failure is also allowed…
CASE FILE
The Header That Became a Program: Shellshock and the Authority Hidden in an Environment
Shellshock did not require an exotic packet or a new network protocol. It needed two familiar interfaces to compose badly: one that placed remote request data in a process environment, and one that treated a specially shaped environment value as code. The incident remains a hard…

IETF
Acee Lindem and the Router That Had to Remember Rebooting
A valid signature can authenticate an old packet perfectly. That is the danger. If an OSPF router restarts and forgets which authenticated packets it has already accepted, a recording from yesterday can arrive wearing a correct digest and present itself as new. RFC 7474 makes…
CASE FILE
The Patch Had Six Months. Slammer Needed Ten Minutes.
On 25 January 2003, the useful unit of incident response stopped being the working day. A 376-byte program could arrive in one UDP datagram, seize an unpatched database service and begin sending copies without waiting for a reply. The repair had already been published. The…

Story
Khipu's Local Archive Preference Creates an Evidence Expiry Boundary
A historical Khipu view can reach farther back than the archive shelf available on the workstation opening it. Once the number of local `ip2asn`, `ixp`, `ip2country` and `asn2country` snapshots is a preference, reproducibility has an expiry boundary that the measurement date…

History
Who Opened TCP's Window Too Soon? The Cost of Immediate Permission
An early TCP receiver could publish every byte of newly freed capacity, and a sender could consume each offer at once. That openness looked exact and cooperative. Repeated quickly, it made the connection spend most of its effort on tiny packets. The historical repair assigned…

Creators
Jakub Kicinski: How Linux makes network features supportable
A new network card can arrive with an impressive capability and a commercial deadline. Linux has to ask a slower question: can the feature be expressed in a way that other hardware can understand, operators can observe, tests can reproduce and maintainers can still support years…

History
The Verdict UDP Withheld: Who Owned the Risk Behind Zero?
In UDP, zero was not a favourable checksum result. It was a notice that the sender had withheld the verdict. The history from IPv4 to IPv6 is therefore about more than arithmetic: it asks who may remove shared evidence, and when the party saving the work must also own the…

History
The Price of Tolerance: How Receiver Leniency Turned Bugs into Protocol Law
The Internet's most famous rule for imperfect software began as a way to keep unlike implementations talking. Its receiver absorbed ambiguity so the network could start. Kept forever, the same bargain hid defects, made quirks contractual and charged every future implementation…
CASE FILE
The Certificate That Was Valid for the Wrong Job: Flame and the Authority Hidden in Purpose
The Flame malware did not need Microsoft's root private key. It found a licensing certificate path whose mathematics, issuance habits and inherited trust could be rearranged into software-signing authority.

History
The Pointer That Was Never Out of Band: How TCP Urgent Split from Its Own Stream
TCP offered applications a way to interrupt ordinary processing without creating another connection. The wire carried one ordered stream and a pointer into it; decades of software turned that boundary into a mythical side channel, then made the myth too widespread simply to…
CASE FILE
The Patch That Could Not Retire a Key: Debian's OpenSSL Entropy Failure and the Afterlife of Weak Credentials
The repaired library stopped minting predictable keys. It did not find the old ones, remove them from remote authorization files, revoke their certificates or persuade a single relying party to refuse them.

Global Institutional
DMTF: The Standards That Control Servers Below the Operating System
A server can be powered off, inspected, updated or reconfigured even when its operating system is unavailable. DMTF defines much of the language used for that privileged management plane, from Redfish APIs and MCTP transport to PLDM commands, SPDM identity and SMBIOS inventory.…

Global Institutional
DMTF and the Language of Server Management
A server can be powered off, inspected, updated or reconfigured even when its operating system is down. DMTF defines much of the language of that privileged management plane: from the Redfish API and MCTP transport to PLDM commands, SPDM identity and SMBIOS inventory. Common…

Story
One Document Store Put Five RIPE NCC Workflows on Hold
A resource transfer can wait because a policy question is unresolved, because evidence is incomplete, or because the filing cabinet is being upgraded. On 22 August, RIPE NCC members encountered the third case. The distinction matters: a planned administrative pause is not a…

Story
The Evidence ARIN Should Require Before Retiring Legacy Whois
ARIN's new directory-services consultation looks like a consolidation project. Its migration inventory tells the more important story: an API can announce its own retirement, a local reassignment server needs a conversion tool, and Port 43 can hide inside scripts that the…
