Open standards body with worldwide implementation impact.
Governance / IETF
IETF
IETF governance intelligence tracks institutions, policy processes, standards activity, registry operations, accountability disputes, and implementation signals that affect internet infrastructure. BTW.

Protocol process and standards legitimacy.
Spec-to-implementation gap across vendors and operators.
Major standards shifts usually affect systems over 120d+ cycles.
Latest Coverage
Latest from IETF
1,086 articles

IETF
Hooman Bidgoli and the Leaf Set That Was Not a Delivered Multicast Service
The control plane can produce an orderly list of intended receivers while the data plane is still divided across controller state, replication segments, service context and receivers that have not seen a packet. RFC 10018 makes the list useful. It does not make the list a…

IETF
Carlos Pignataro and the Watt Reading That Did Not Prove a Greener Network
A power meter can report a precise number while leaving the environmental claim undecided. Turning that number into energy, emissions or permission to switch off spare capacity requires separate evidence—and a record of who accepted the trade.

IETF
IETF Marks Two Capture Controls Incomplete. Their Q4 Proof Needs a Public Map
One line in the IETF Administration LLC’s 2026 Risk Register names the institutional failure that open technical organizations are often least comfortable naming: “The IETF, or a key part of it, is captured.” The same line says two controls are complete and two remain unfinished…

IETF
Sean Turner and the Private-Key Proof That Did Not Authorize a Certificate
A certification request can carry a valid signature and still have no right to become the certificate it asks for. The signature answers a narrow question about a key; identity, namespace entitlement, intermediary action and issuance remain separate decisions.

IETF
Lukasz Kondrad and the RTP Group That Was Not Yet a Reconstructed Scene
A session description can place an atlas, occupancy, geometry and colour stream inside one V3C group. That is a precise statement about membership—not evidence that a receiver rebuilt the same three-dimensional scene.

IETF
IETF Tools Kept Every-Line Review for AI Code. Its Next Boundary Is Still Unwritten
The IETF Tools Team has named a genuine capacity problem: AI can produce ambitious pull requests faster than maintainers can safely absorb them. Yet the contribution guide it actually adopted in August still puts every submitted line in front of a human maintainer. That is a…

IETF
Panos Kampanakis and the SSH Session with Three Different Security Receipts
An SSH client can negotiate a hybrid ML-KEM key exchange, verify the server through a conventional host key, and admit a user through a still separate credential. The session is one connection; the evidence is not one claim.

IETF
Cullen Jennings and the Capability Document That Was Not a Live SIP Trunk
An enterprise edge device can discover the right URL, pass TLS and OAuth, receive HTTP 200 and parse a valid provider capability document while no production call can cross the trunk. RFC 10006 makes configuration exchange easier; it does not collapse retrieval, activation…

IETF
IETF’s STIR Recharter Separates the Right to Use a Number From Entity Identity
A call can carry a valid cryptographic assertion for a telephone number and still leave a basic institutional question unanswered: which entity stands behind that authority, and in what capacity? The proposed STIR recharter names that gap directly. Its value will depend on…

IETF
Tobias Fiebig and the Four DNS Reachability Receipts
A zone can display two A records, two AAAA records and a reassuring “dual stack” label while still withholding names from an IPv6-only resolver. RFC 10001 replaces that label with four bounded claims: two authoritative services must answer over IPv4 and two must answer over IPv6…

IETF
Weiqiang Cheng and the SRv6 Locator Lease That Still Needed a Route
The DHCPv6 log can show a valid Reply, a locator, an IAID and two working clocks while the route table still has nothing to say. RFC 10038 makes that gap explicit: assignment is one controlled event; reachability must be created, distributed and observed through separate systems.

IETF
The IETF ‘Believed’ Its Last Cutover Delivered Every Message. This Time It Can Prove It
On 11 September, the IETF plans to replace much of the machinery that receives, checks, rewrites and sends mail for four of its institutional domains. A one-hour delay would be tolerable. An unexplained hole in a working-group record would not. The difference cannot be…

IETF
Bas Westerbaan and the Hybrid TLS Handshake That Did Not Make the Certificate Post-Quantum
A browser can report `X25519MLKEM768`, derive a session secret from classical and post-quantum components, and still authenticate the server with a classical certificate signature. Both observations can be true in the same TLS 1.3 connection. Calling the whole service…

IETF
Daniel Fett and the QR Context That MFA Never Authenticated
The password was right, the second factor was real and the authorization server behaved as designed. The attacker still received the session, because the ceremony proved who the user was without proving whose request the user had approved.

IETF
Mike McBride and the Multicast Registry That Prevented One Kind of Collision
Two IPv6 multicast allocation methods had been told to draw identifiers from the same box. RFC 10028 divided the box before a future host protocol and an old server protocol could make the same choice—and left operators with the harder job of proving that their networks had…

IETF
Gavin Brown and the Successful Create That Did Not Yet Register a Domain
The server said the command had completed successfully. In the same breath, it said the action was still pending. RFC 8334 makes that apparent contradiction useful: an accepted application is evidence, but it is not yet a registered domain.

IETF
RADEXT’s Recharter Is Still Under Review. Seven Milestones Are Dated May or August
The proposed RADEXT charter has two clocks. Its approval clock still reads External Review. Its delivery table carries two milestones dated May 2026 and five dated August. That does not prove seven failures: some work is active, some awaits adoption, and the proposal itself is…

IETF
Russ Housley and the MAC Address a Certificate Could Name but Not Make Unique
Six bytes can fit cleanly inside a certificate. The difficult part begins after they leave it: who assigned them, what interface is using them now, who observed that use, and why a local network should permit an action.

IETF
Benoît Claise and the Augment the Base Module Could Not Name
A YANG module can list the modules it imports. It cannot, by reading itself, identify every external module that later inserts nodes into its schema tree. RFC 10035 makes that hidden direction reportable—one direct edge at a time.

IETF
Kazuho Oku and the Header That Makes Refusal Legible but Cannot Promise Streaming
An HTTP field can require a proxy that understands it to reject instead of quietly buffering. It cannot command a proxy that has never learned the field. RFC 10036 improves the evidence around incremental delivery precisely by preserving that distinction.
Member Unlock
Restricted Profile Intelligence
Login is required to unlock full profile briefings and deep-dive sections.
Strategic Circle Briefing
Join to unlock strategic briefings after signing in.
Join Strategic CircleLeadership Alliance Briefing
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance