Policy continuity, legitimacy, and accountability signals across internet governance institutions.
Governance
Governance
Internet governance intelligence tracks institutions, policy processes, standards activity, registry operations, accountability disputes, and implementation signals that affect internet infrastructure. BTW.

RIR Watchdog, Case File, NRS, ICANN, IETF, History of Internet, and NOG sessions.
Coverage prioritizes implementation evidence and institutional behavior over declarative positions.
Latest Coverage
Latest from Governance
4,334 articles
CASE FILE
The Cache That Answered 51,000 Times: Memcached and the Bandwidth Nobody Meant to Delegate
A reflector attack begins with a peculiar transfer of authority: one machine lies about who asked, another machine believes the return address, and a third party pays for the answer. In February 2018, public memcached servers made that transfer large enough to move GitHub's…
History
Who Opened TCP's Window Too Soon? The Cost of Immediate Permission
An early TCP receiver could publish every byte of newly freed capacity, and a sender could consume each offer at once. That openness looked exact and cooperative. Repeated quickly, it made the connection spend most of its effort on tiny packets. The historical repair assigned…
CASE FILE
The Answer That Won the Race: Kaminsky's DNS Poisoning and the Entropy Behind Trust
The dangerous answer did not need a signature or a privileged route; it only had to resemble one outstanding question closely enough and arrive first. The 2008 DNS crisis turned that narrow acceptance rule into a renewable race—and showed why a patch can buy safety without…
CASE FILE
The Rule That Reached Every Edge Before Anyone Priced It: Cloudflare's 2019 WAF Outage
Cloudflare's distributor needed seconds to place one approved security rule around the world; the incident lasted because approval had established what the rule should catch, not how much computation every request could make it consume.
History
The Window Update That Could Vanish: Why TCP Learned to Persist at Zero
A TCP receiver can say “send nothing” and remain healthy. The harder problem begins when it later says “continue” in an ACK that may disappear. TCP's persist mechanism turned that fragile permission into a recoverable conversation, while leaving the application—not a transport…
History
The Verdict UDP Withheld: Who Owned the Risk Behind Zero?
In UDP, zero was not a favourable checksum result. It was a notice that the sender had withheld the verdict. The history from IPv4 to IPv6 is therefore about more than arithmetic: it asks who may remove shared evidence, and when the party saving the work must also own the…
Story
RIPE's First-ASN Proposal Removes One Test but Leaves Three Records Open
RIPE's First-ASN Proposal Removes One Test but Leaves Three Records Open intelligence summary explains the development, the public evidence available to readers, the organisations involved, the regional context, market exposure, and the infrastructure consequences that may…
CASE FILE
The Page That Borrowed Another Customer's Memory: Cloudbleed and the Boundary of a Shared Edge
A malformed page triggered Cloudflare's parser, but the escaped bytes could belong to somebody else entirely; Cloudbleed showed that stopping a leak and recovering what had already crossed the boundary are different acts of control.
History
When Both Ends Called at Once: Why TCP Simultaneous Open Was Not a Collision
The familiar TCP handshake casts one endpoint as caller and the other as listener. TCP's original design was less hierarchical. If two processes called each other at once, their SYNs could cross, both stacks could change role without asking a coordinator, and one connection would…
History
The Price of Tolerance: How Receiver Leniency Turned Bugs into Protocol Law
The Internet's most famous rule for imperfect software began as a way to keep unlike implementations talking. Its receiver absorbed ambiguity so the network could start. Kept forever, the same bargain hid defects, made quirks contractual and charged every future implementation…
CASE FILE
The Certificate That Was Valid for the Wrong Job: Flame and the Authority Hidden in Purpose
The Flame malware did not need Microsoft's root private key. It found a licensing certificate path whose mathematics, issuance habits and inherited trust could be rearranged into software-signing authority.
History
The Pointer That Was Never Out of Band: How TCP Urgent Split from Its Own Stream
TCP offered applications a way to interrupt ordinary processing without creating another connection. The wire carried one ordered stream and a pointer into it; decades of software turned that boundary into a mythical side channel, then made the myth too widespread simply to…
CASE FILE
The Request That Vanished but Kept Working: What Rapid Reset Revealed About Cancellation
HTTP/2 let a client withdraw one request without closing the connection; Rapid Reset exposed the moment when that valid cancellation stopped being a courtesy and became an unlimited claim on somebody else’s queues.
CASE FILE
The Patch That Could Not Retire a Key: Debian's OpenSSL Entropy Failure and the Afterlife of Weak Credentials
The repaired library stopped minting predictable keys. It did not find the old ones, remove them from remote authorization files, revoke their certificates or persuade a single relying party to refuse them.
History
The Message the Internet Learned to Ignore: Why ICMP Source Quench Lost Its Authority
The early Internet allowed an overloaded gateway to send a separate command telling a distant source to slow down. Three decades of operational evidence reversed that bargain: congestion still required feedback, but a bare ICMP order no longer deserved the power to change a…
IETF
Susan Hares and the Route That Authorised the Filter
A reachability update tells a router where packets may go. A FlowSpec update can tell it which packets to slow, discard, remark or redirect. That change in consequence makes authority—not syntax—the hard part. Susan Hares's documented work on the revised FlowSpec standards helps…
Story
Three National Registers Expose the Gap Behind LACNIC's No-Consensus Result
Brazil calls an individual entrepreneur a natural person doing business in their own name. Argentina opens its simplified tax register to `personas humanas`. Uruguay describes a one-person monotributo business as a natural person registering before economic activity begins.…
CASE FILE
The Signature That Demanded Every Key: What KeyTrap Revealed About the Cost of Trust
KeyTrap turned a valid-looking DNSSEC workload into a claim on somebody else’s processor, exposing the point at which faithful verification must yield to a locally governed budget.
CASE FILE
The Root That Wasn't Sold: What Symantec's Exit Revealed About Transferable Trust
Symantec could sell its certificate-authority business, but it could not sell a command to keep trusting the old roots. That decision remained inside independently operated clients.
IETF
Bruno Decraene and the Discipline of Draining Before Shutdown
A planned BGP maintenance window is not a surprise failure. Yet an operator who closes the session first can make it behave like one: the old routes vanish, the network begins searching, and packets arrive while the replacement path is still becoming usable. The more disciplined…
Session Map
Governance Branch
RIR Watchdog
Five regional sessions tracking allocation policy, board legitimacy, and institutional continuity.
Open RIR WatchdogCase File
Long-cycle governance dossiers with legal, election, and institutional stress analysis.
Open Case FileNumber Resource Society
Membership, charter, and resource-governance intelligence from the NRS ecosystem.
Open NRS SessionICANN
DNS coordination, accountability frameworks, and global multi-stakeholder process dynamics.
Open ICANN SessionIETF
Protocol standardization trajectory and interoperability risk under fragmented policy conditions.
Open IETF SessionHistory of Internet
Long-cycle infrastructure history used for governance interpretation and structural forecasting.
Open History SessionNOGs
Operator-level implementation intelligence from APRICOT plus regional and national NOG ecosystems.
Open NOGs Session