Skip to main content

Governance

Governance

Internet governance intelligence tracks institutions, policy processes, standards activity, registry operations, accountability disputes, and implementation signals that affect internet infrastructure. BTW.

RIR WatchdogCase FileNumber Resource SocietyICANNIETFHistory of InternetNOGs
Governance signal visual
GovernanceGovernance
FocusInstitutional Governance

Policy continuity, legitimacy, and accountability signals across internet governance institutions.

CurrentSeven Governance Tracks

RIR Watchdog, Case File, NRS, ICANN, IETF, History of Internet, and NOG sessions.

SignalExecution over Statement

Coverage prioritizes implementation evidence and institutional behavior over declarative positions.

Latest Coverage

Latest from Governance

4,134 articles

History

Four Bytes Put a Message in TCP. They Did Not Rebuild the OSI Network: RFC 1006’s TPKT Boundary

TCP can deliver every byte in order and still decline to say where one application-shaped entity ends. In 1987, RFC 1006 addressed that awkward fact for ISO Transport over TCP with a remarkably small intervention: put four octets before a TPDU, then make the receiver count. The…

Aug 31, 2026

MYNOG

MYNOG Can Rewrite Attendance Terms After Registration

MYNOG’s published registration terms do more than set an entry price. They let the organisers amend the terms through publication on the conference website, treat later attendance as acceptance, and retain discretion to exclude a entity without refunding the registration fee.

Aug 31, 2026

CASE FILE

The Legacy Code Point Reached the Client. It Did Not Reauthorise the Server: RFC 9963

An IANA code point can look like a broad permission slip when it appears in a migration review. RFC 9963 is deliberately narrower. It gives TLS 1.3 three legacy RSASSA-PKCS1-v1_5 signature values, but only for a client proving possession of a client-certificate key after a server…

Aug 31, 2026

CASE FILE

The Reverse Socket Arrived. The Device Had Not Yet Identified Itself: RFC 10011 and RESTCONF Call Home

A controller can receive a connection from the direction it expected, on a listener it deliberately opened, after a device has been configured to call home. That is useful evidence. It is not yet the same thing as knowing which device has arrived, establishing a RESTCONF session…

Aug 31, 2026

History

The Token Found the Connection. It Did Not Admit the Subflow: MPTCP's MP_JOIN Boundary

One new TCP SYN can propose to become part of a connection that began somewhere else, on another address pair, minutes earlier. That is the useful oddity in Multipath TCP. It is also where a casual description—“the session moved”—loses the decisions that keep continuity from…

Aug 31, 2026

CASE FILE

W3C’s WebAppSec Charter Draft Gives 16 of 17 Deliverables No Completion Date

W3C’s proposed Web Application Security charter is unusually candid about time: almost every normative deliverable says its expected completion is undetermined. That is not evidence that sixteen specifications are late. It is evidence that the charter maps authority better than…

Aug 31, 2026

CASE FILE

The Quantum-Safe Key Was Added. The Classical Recipient Still Opened the Mail: RFC 9980

RFC 9980 gives OpenPGP a post-quantum vocabulary, including composite encryption keys that combine ML-KEM with X25519 or X448. That is an important interoperability step. It is also easy to overstate. A message can carry a genuinely PQ/T-capable recipient key and still be…

Aug 31, 2026

IETF

Weiqiang Cheng and the SRv6 Locator Lease That Still Needed a Route

The DHCPv6 log can show a valid Reply, a locator, an IAID and two working clocks while the route table still has nothing to say. RFC 10038 makes that gap explicit: assignment is one controlled event; reachability must be created, distributed and observed through separate systems.

Aug 31, 2026

ICANN

ICANN Names a Safeguard Assessment Provider. When Does String Review Become a Registry Agreement Obligation?

ICANN has appointed Mirror Group LLC for 2026 Round Safeguard Assessments. The important boundary is between a string-risk assessment and a safeguard that becomes part of a Registry Agreement.

Aug 31, 2026

Story

LACNIC and the economics of transition architecture beyond RIRs

A transition test built around functions, records and authority—not around the fantasy that scarce network resources can govern themselves.

Aug 31, 2026

History

The Banner Marked the Screen. It Did Not Make the Policy: RFC 933 and Telnet's Display Boundary

A security banner could be sent once and kept visible by the workstation instead of being mixed into every screenful of application output. RFC 933 made that presentation bargain explicit—and left the security level, access decision and truth of the label outside the banner…

Aug 31, 2026

CASE FILE

The Model Could Explain the Network. It Could Not Authorize the Change: NEMOPS and the Boundary Between Visibility and Control

The NEMOPS workshop report asks for better models, observability, tooling and verification in network management. Those are valuable improvements in what an operator can see and test. They do not decide whose service may be changed, which risk is acceptable, or who bears the cost…

Aug 31, 2026

LKNOG

The Institution Born After APNIC 42: Why Sri Lanka Built LKNOG

APNIC 42 brought the regional internet operations community to Colombo in 2016. LKNOG's own early record suggests that the more consequential question began after the conference ended: who would maintain a place for Sri Lankan operators to exchange practice when the next…

Aug 31, 2026

IETF

The IETF ‘Believed’ Its Last Cutover Delivered Every Message. This Time It Can Prove It

On 11 September, the IETF plans to replace much of the machinery that receives, checks, rewrites and sends mail for four of its institutional domains. A one-hour delay would be tolerable. An unexplained hole in a working-group record would not. The difference cannot be…

Aug 31, 2026

CASE FILE

The Fast Packet Kept the Session Up. It Did Not Authorise the Change: RFC 9985

RFC 9985 offers a disciplined answer to an awkward operational fact: a protocol can need frequent authenticated liveness packets at a rate that makes identical expensive authentication hard to sustain. Its answer is a split, not a blank cheque. Stronger-in-cost authentication…

Aug 31, 2026

Story

APNIC’s Five-Year Audit Rule Needs a Public Exception Record

The interesting sentence on APNIC’s transparency page is not the comforting one about a financial audit. It is the operational one: the audit firm is rotated at least every five years. That is a rule a reader can hold in mind. The December 2025 Executive Council minutes then…

Aug 31, 2026

History

The NAK Rejected the Port, Not the Packet: RFC 938 and the Boundary Between Delivery and Dispatch

In an experimental 1985 Internet protocol, a receiver could say two things at once: the next packet number had been received in sequence, and the local port named in that packet was not known. RFC 938 called that reply `PORT NAK`. Its precision is a useful warning against…

Aug 31, 2026

CASE FILE

APT’s PP-26 Common Proposals Can Advance Without Regional Unanimity

The Asia-Pacific Telecommunity has finished its last scheduled preparatory meeting before ITU’s 2026 Plenipotentiary Conference. What happens next is easy to compress into a misleading phrase: “the region’s proposals.” APT’s own rules are more precise. They create a preliminary…

Aug 31, 2026

IETF

Bas Westerbaan and the Hybrid TLS Handshake That Did Not Make the Certificate Post-Quantum

A browser can report `X25519MLKEM768`, derive a session secret from classical and post-quantum components, and still authenticate the server with a classical certificate signature. Both observations can be true in the same TLS 1.3 connection. Calling the whole service…

Aug 31, 2026

CASE FILE

An OAM Requirement Was Written Down. It Did Not Prove a Working Diagnostic: RFC 9974 and BIER Evidence

A requirements catalogue can sharpen an engineering question. It cannot, on its own, answer whether a particular network can run the test, what the test observed, or who may act on it.

Aug 31, 2026

Session Map

Governance Branch

RIR Watchdog

Five regional sessions tracking allocation policy, board legitimacy, and institutional continuity.

Open RIR Watchdog

Case File

Long-cycle governance dossiers with legal, election, and institutional stress analysis.

Open Case File

Number Resource Society

Membership, charter, and resource-governance intelligence from the NRS ecosystem.

Open NRS Session

ICANN

DNS coordination, accountability frameworks, and global multi-stakeholder process dynamics.

Open ICANN Session

IETF

Protocol standardization trajectory and interoperability risk under fragmented policy conditions.

Open IETF Session

History of Internet

Long-cycle infrastructure history used for governance interpretation and structural forecasting.

Open History Session

NOGs

Operator-level implementation intelligence from APRICOT plus regional and national NOG ecosystems.

Open NOGs Session