Skip to main content

Governance / Case File

CASE FILE

Case File governance intelligence tracks institutions, policy processes, standards activity, registry operations, accountability disputes, and implementation signals that affect internet infrastructure. BTW.

Institutional BreakdownLegal and Policy ConflictElection and Control Risk
CASE FILE signal visual
Governance / Case FileCASE FILE
Active Dossiers1 Live Case

AFRINIC saga currently tracked end-to-end.

Primary DomainGovernance

Institution legitimacy and continuity risk mapping.

MethodSignal + Timeline + Failure Paths

Primary-source based timeline and risk analysis.

Decision ValueHigh

Used for continuity and policy exposure planning.

Latest Coverage

Latest from CASE FILE

751 articles

CASE FILE

W3C Is Considering Web Speech for Audio. The Charter Draft Still Excludes It

W3C has publicly opened a route for Web Speech API to enter the Audio Working Group, but the document that would confer that authority has not caught up. The recharter issue calls adoption a substantive scope change; the draft charter still says speech recognition and synthesis…

Aug 31, 2026

CASE FILE

The Certificate Verified the Peer. The External PSK Still Needed a Custodian: RFC 9973 and TLS Authority

A security review can make an unusually comforting statement: the client validated the certificate, the server selected an external pre-shared key, the handshake finished, and the traffic was encrypted. Every clause may be true. None answers the question a security owner…

Aug 31, 2026

CASE FILE

The BFD Counter Rose. The Service Path Was Still Unproven: RFC 9978 and Stability Evidence

A BFD session can stay Up while control packets disappear inside its Detection Time. RFC 9978 makes that early deterioration observable. It does not turn a control-packet counter into proof of data-plane loss, a failed route, or a customer-facing outage.

Aug 31, 2026

CASE FILE

The Flag Said Several Routers Meant This Prefix. It Did Not Name a Working One: RFC 9983 and Anycast Evidence

An OSPF control plane can state that a prefix is meant to be advertised by several routers. That is useful coordination. It is not a statement that any particular replica is reachable, selected, healthy, authorised to serve, or able to complete the transaction a packet…

Aug 31, 2026

CASE FILE

A Cookie Matched the Request. It Did Not Prove the Decision: RFC 10025 and Ambient Authority

A browser can attach the right-looking cookie to the right-looking request at the exact moment a consequential button is pressed. That still leaves four questions open: who caused the request, whether the server still accepts the session, whether this action is allowed now, and…

Aug 31, 2026

CASE FILE

One Trustee Roster, Two Boards: Internet Society Decisions Need a Capacity Receipt

Internet Society and its Foundation use the same trustees, yet their governing documents create two Boards—and a third capacity when Internet Society acts as the Foundation's sole Member. Back-to-back 2026 agendas show why aligned oversight still needs a record of which legal hat…

Aug 31, 2026

CASE FILE

A Ciphertext Reached the Key. It Did Not Name Its Sender: RFC 9180 and the Authority Missing from HPKE Base Mode

A team can receive an HPKE ciphertext, open it with the intended private key and still be unable to say who sent it, what outer request it belonged to, whether it is fresh, or whether anyone was entitled to act on its plaintext. RFC 9180 makes the cryptographic transition…

Aug 31, 2026

CASE FILE

An MPLS Action Is Not an Admission Decision: RFC 9994

A packet can arrive with a perfectly formed MPLS Network Action Sub-Stack, an opcode that an engineer can name and ancillary data that a parser can read. That packet has not yet proved that the next node supports the action, that the action belongs on this path, that its data…

Aug 31, 2026

CASE FILE

The Packet Declared a Haptic Effect. The Device Still Had to Decide Whether to Render It: RFC 9993

A remote session marks one haptic unit as high priority. The packet is valid, the stream is negotiated and the receiver can decode it. None of that tells an actuator where on a body it may act, whether the requested amplitude is within the device’s envelope, whether a temperature…

Aug 31, 2026

CASE FILE

A Key Could Cross the Fabric. It Could Not Decide the Route: RFC 9992 and RIFT Authority

Two Top-of-Fabric nodes lose contact, each advertises the same RIFT key with a different value, and a leaf sees both. It must select one. A deterministic result is useful; it is not a declaration that the winning value is the current truth, that any receiver may act on it, or…

Aug 31, 2026

CASE FILE

The Private Key Never Left. Its Authority Did: RFC 9987 and the Transitive Trust of SSH Agent Forwarding

An engineer forwards a workstation’s SSH agent to a bastion. A process on that bastion cannot copy the private key, yet it may still ask the distant agent to sign a new authentication request. “No key exfiltration” is therefore an incomplete incident verdict: material custody and…

Aug 31, 2026

CASE FILE

The Domain Requested the Failure Report. The Receiver Still Had to Authorize Disclosure: RFC 9991 and DMARC Forensics

A mail receiver detects a genuine authentication failure in a forwarded calendar invitation. The author's domain has requested a forensic report at an external address. Sending the report could expose the invitation, its recipients and the forwarding path to a party that never…

Aug 31, 2026

CASE FILE

SC100’s Draft Draws DNSSEC’s Boundary at the Primary Perspective. The Receipt Must Name It

SC100 passed its vote by unanimity among the members who participated, but on 31 August 2026 it was still an accepted draft under intellectual-property review. Its most useful clarification is not that “DNSSEC is required.” That duty already exists. It is that the duty belongs to…

Aug 31, 2026

CASE FILE

SC101 Closes a Domain-Control Gap. The Transition Still Permits Two Rulebooks

A certificate authority can now point to one current set of TLS Baseline Requirements while legitimately running one of two different domain-control derivation rules. SC101 made the safer order explicit: choose the validation method, follow a permitted CNAME path, then prune…

Aug 31, 2026

CASE FILE

The Label Named the Encoding. It Did Not Name the Schema: RFC 9996 and Authority Behind a Protobuf Payload

A gateway accepts `application/protobuf`, the decoder returns a message value, and the request enters the business system. None of those successes establishes that the receiver used the producer's intended message definition. RFC 9996 gives Protocol Buffers a proper outer label.…

Aug 31, 2026

CASE FILE

WebDriver May Live at Candidate Recommendation. Cite the Snapshot

W3C's proposed Browser Testing and Tools charter makes an unusual choice explicit. WebDriver and WebDriver BiDi would be developed toward Candidate Recommendation, updated through Snapshots, and not deliberately advanced to Recommendation. That can fit technology implemented…

Aug 31, 2026

CASE FILE

W3C Proposes Dropping AT Driver Before ARIA Has Adopted It

W3C has published a clear departure document for AT Driver: the proposed next charter for Browser Testing and Tools removes the specification. The arrival document is not ready. ARIA's current charter does not list AT Driver, its receiving issue remains open, and its own public…

Aug 31, 2026

CASE FILE

The Envelope Signed the Digest. It Did Not Deliver the Preimage: RFC 9995 and the Authority Behind a COSE Hash Envelope

A release gate receives a valid signature over the digest of an SBOM. The envelope is small, the cryptography checks out, and the signed location points to a repository. Yet the SBOM itself is absent. Nothing has been downloaded, compared, parsed or judged. RFC 9995 makes the…

Aug 31, 2026

CASE FILE

The Proposed WebAuthn Charter Opens Raw Signing. Scope Is Not Approval

W3C is considering a larger mandate for Web Authentication. The proposed charter would let the group work on signatures over arbitrary data, including uses associated with agentic AI and verifiable digital credentials. That sentence opens a standards room; it does not certify the…

Aug 31, 2026

CASE FILE

W3C's WoT Registry Requires Two Reviews—Not Necessarily Two Reviewers

A proposed Web of Things charter would turn protocol bindings into a maintained W3C Registry. Its pilot rules make a revealing distinction: moving a binding to `Current` requires one review of the underlying protocol mapping and another of its fit with WoT, but the same qualified…

Aug 31, 2026

Member Unlock

Restricted Profile Intelligence

Login is required to unlock full profile briefings and deep-dive sections.

Only for Strategic Circle

Strategic Circle Briefing

Join to unlock strategic briefings after signing in.

Join Strategic Circle
Only for Leadership Alliance

Leadership Alliance Briefing

For qualified IP-asset owners and management; sign in to unlock alliance briefings.

Join Leadership Alliance

Session Map

Active Dossiers

AFRINIC Saga

Multi-year governance and legal crisis with implications for RIR accountability worldwide.

Open AFRINIC Saga