Skip to main content

Governance / Case File

CASE FILE

Case File governance intelligence tracks institutions, policy processes, standards activity, registry operations, accountability disputes, and implementation signals that affect internet infrastructure. BTW.

Institutional BreakdownLegal and Policy ConflictElection and Control Risk
CASE FILE signal visual
Governance / Case FileCASE FILE
Active Dossiers1 Live Case

AFRINIC saga currently tracked end-to-end.

Primary DomainGovernance

Institution legitimacy and continuity risk mapping.

MethodSignal + Timeline + Failure Paths

Primary-source based timeline and risk analysis.

Decision ValueHigh

Used for continuity and policy exposure planning.

Latest Coverage

Latest from CASE FILE

734 articles

CASE FILE

A Celestial Name Is Not a Network Address: The Authority Split TIPTOP Has to Preserve

One entity can be discovered under a temporary tag, receive several provisional designations, gain a permanent number and acquire a name years later. A route cannot afford to mistake any one of those labels for proof of where a packet should go.

Sep 7, 2026

CASE FILE

A Deprecation Date Is Not a Client Migration Plan

The response is still `200 OK`, but it now carries a date after which the resource will be deprecated. That date can warn a client. It cannot identify who owns the client, whether a replacement preserves its assumptions, or what must be true before the old endpoint can be…

Sep 7, 2026

CASE FILE

The IAB Gave Post-Quantum Authentication Evidence Another Week. It Still Needs a Chain of Custody

The extended deadline invites one more week of operational evidence. The harder task begins after a paper arrives: keeping measurements, disclosure choices, workshop synthesis and eventual standards work from collapsing into one unsupported claim.

Sep 7, 2026

CASE FILE

A security.txt File Needs a Live Disclosure-Channel Receipt

The `Expires` line says the coordinates are still publishable. It cannot tell a researcher whether anybody is listening. That gap between a fresh file and a working response operation is where a small disclosure-channel receipt becomes useful.

Sep 7, 2026

CASE FILE

The Message Was Encrypted. Its Headers Still Needed Their Own Receipts: RFC 9788

An encrypted-mail badge compresses a complicated evidence chain into one reassuring symbol. RFC 9788 shows why the symbol cannot answer which header was hidden, which sender identity was authenticated, what an intermediary changed, or where a reply may safely go.

Sep 7, 2026

CASE FILE

An OSPS Baseline Claim Needs a Version, a Level and a Date

“OSPS compliant” looks tidy in a supplier register. It is also incomplete. The Baseline is versioned, divided by project maturity and explicitly assessed at a point in time; a useful claim must preserve those coordinates and the evidence behind them.

Sep 7, 2026

CASE FILE

The Key Was Known. It Was Not Yet Trusted

A self-signed DNS update arrives at a parent carrying a new key and an instruction to delete the old one. The signature proves that somebody holds the new private key. It does not prove that this somebody may change the child's delegation. As DNSOP's 7 September Last Call reaches…

Sep 7, 2026

CASE FILE

A CA Audit Is Not a Certificate-Issuance Verdict

An annual assurance report can show that a certificate authority’s controls were examined over a bounded period. It cannot, on its own, answer the smaller and more consequential question a relying party often needs to ask: why was this exact certificate for this exact name and…

Sep 7, 2026

CASE FILE

Four Bits Looked Like IP. They Were Not: RFC 9790 and the End of Payload Guessing

An MPLS router can see `0x4` after the label stack and reach for an IPv4 hash. RFC 9790 explains why those four bits cannot carry that conclusion on their own.

Sep 7, 2026

CASE FILE

A GitHub Actions workflow_run Trigger Is Not an Artifact-Trust Verdict

A GitHub Actions `workflow_run` trigger can create a useful separation between an upstream check and a downstream, more privileged workflow. It does not establish that the upstream result, the artifact consumed downstream, or a later target operation deserves trust.

Sep 7, 2026

CASE FILE

A GitHub Actions OIDC Token Is Not a Cloud-Authorization Verdict

A GitHub Actions OIDC token can identify a bounded workflow context to an external provider. It does not, by itself, establish that a cloud trust policy matched, that a cloud session was issued, that a resource permitted an action or that a target changed.

Sep 6, 2026

CASE FILE

The Final Dot Vanished. The Trust Boundary Moved with It

Two hostnames can lead DNS to the same node and still lead an application to different security decisions. As the DNSOP Working Group closes its 7 September Last Call on guidance for bringing domain names into applications, a recent curl flaw gives the abstract warning a concrete…

Sep 6, 2026

CASE FILE

One Circuit Failed. The Port Did Not: RFC 9784 and the Cost of the Wrong Failure Domain

A provider edge port can carry thousands of virtual services. RFC 9784 asks operators to prove which entity failed before allowing recovery to inherit the size of the container.

Sep 6, 2026

CASE FILE

A GitHub Actions Concurrency Group Is Not a Deployment-Serialization Verdict

A GitHub Actions concurrency group can reduce conflicts between named jobs or workflow runs. It does not, on its own, establish the order of every consequential action against a target or the effect of those actions.

Sep 6, 2026

CASE FILE

The Timestamp Was More Precise. The Association Still Had to Survive: RFC 9769

RFC 9769 can deliver a transmission time captured closer to the wire by placing it in a later packet. The improvement is real only while the state linking those exchanges remains intact.

Sep 6, 2026

CASE FILE

The Root Verified. The Proof Still Could Not Name the Leaf

A one-bit path can point to leaf 1, 2, 4 or 8, depending only on how large the tree was. The current SCITT profile can still prove that a candidate statement belongs under a signed CCF root. What it cannot always do, from the proof alone, is say where that statement sat.

Sep 6, 2026

CASE FILE

The Message Fit the Schema. That Still Did Not Make It True: RFC 8927

RFC 8927 builds a deliberately narrow gate for JSON messages. A message that passes has the declared shape; identity, authority, freshness and real-world effect still wait on the other side.

Sep 6, 2026

CASE FILE

A Dismissed Dependabot Alert Is Not a Remediation Verdict

A dismissed Dependabot alert records a triage decision about a repository-facing signal. It can be sensible and well documented. It still does not prove that vulnerable code is absent from a deployed system, that an upgrade was accepted, or that a remediation has happened.

Sep 6, 2026

CASE FILE

The Relay Appeared on the Local Network. Who Authorized the Advertisement?

A MOQT client can now be told how to find a nearby relay, which protocol label to offer and which name to check in its certificate. The new draft is precise when DNS moves the socket. It is not yet precise about who may put the local relay in front of the client.

Sep 6, 2026

CASE FILE

The Client Reported the File Attributes. The Metadata Server Could Still Verify Them: RFC 9766

RFC 9766 gives an NFS client a cheaper way to carry data-file observations back to the metadata server. The design is valuable because it refuses to make that report final: weak evidence can save work without becoming metadata sovereignty.

Sep 6, 2026

Member Unlock

Restricted Profile Intelligence

Login is required to unlock full profile briefings and deep-dive sections.

Only for Strategic Circle

Strategic Circle Briefing

Join to unlock strategic briefings after signing in.

Join Strategic Circle
Only for Leadership Alliance

Leadership Alliance Briefing

For qualified IP-asset owners and management; sign in to unlock alliance briefings.

Join Leadership Alliance

Session Map

Active Dossiers

AFRINIC Saga

Multi-year governance and legal crisis with implications for RIR accountability worldwide.

Open AFRINIC Saga