Intelligence
Latest Articles
Latest intelligence on infrastructure operators, policy decisions, market moves, and digital power shifts.

History
The Token Found the Connection. It Did Not Admit the Subflow: MPTCP's MP_JOIN Boundary
One new TCP SYN can propose to become part of a connection that began somewhere else, on another address pair, minutes earlier. That is the useful oddity in Multipath TCP. It is also where a casual description—“the session moved”—loses the decisions that keep continuity from…

IETF
Weiqiang Cheng and the SRv6 Locator Lease That Still Needed a Route
The DHCPv6 log can show a valid Reply, a locator, an IAID and two working clocks while the route table still has nothing to say. RFC 10038 makes that gap explicit: assignment is one controlled event; reachability must be created, distributed and observed through separate systems.

ICANN
ICANN Names a Safeguard Assessment Provider. When Does String Review Become a Registry Agreement Obligation?
ICANN has appointed Mirror Group LLC for 2026 Round Safeguard Assessments. The important boundary is between a string-risk assessment and a safeguard that becomes part of a Registry Agreement.

Story
LACNIC and the economics of transition architecture beyond RIRs
A transition test built around functions, records and authority—not around the fantasy that scarce network resources can govern themselves.

Europe and Middle East National Telecom Trends
A final digital-landline notice is not a safe cessation until the critical call path is confirmed
A dated notice can prove that a provider started a final process. It cannot by itself prove that the person, telecare service or critical call path at the address has been safely carried through that process.

History
The Banner Marked the Screen. It Did Not Make the Policy: RFC 933 and Telnet's Display Boundary
A security banner could be sent once and kept visible by the workstation instead of being mixed into every screenful of application output. RFC 933 made that presentation bargain explicit—and left the security level, access decision and truth of the label outside the banner…

CASE FILE
The Model Could Explain the Network. It Could Not Authorize the Change: NEMOPS and the Boundary Between Visibility and Control
The NEMOPS workshop report asks for better models, observability, tooling and verification in network management. Those are valuable improvements in what an operator can see and test. They do not decide whose service may be changed, which risk is acceptable, or who bears the cost…

IETF
The IETF ‘Believed’ Its Last Cutover Delivered Every Message. This Time It Can Prove It
On 11 September, the IETF plans to replace much of the machinery that receives, checks, rewrites and sends mail for four of its institutional domains. A one-hour delay would be tolerable. An unexplained hole in a working-group record would not. The difference cannot be…

CASE FILE
The Fast Packet Kept the Session Up. It Did Not Authorise the Change: RFC 9985
RFC 9985 offers a disciplined answer to an awkward operational fact: a protocol can need frequent authenticated liveness packets at a rate that makes identical expensive authentication hard to sustain. Its answer is a split, not a blank cheque. Stronger-in-cost authentication…

Story
APNIC’s Five-Year Audit Rule Needs a Public Exception Record
The interesting sentence on APNIC’s transparency page is not the comforting one about a financial audit. It is the operational one: the audit firm is rotated at least every five years. That is a rule a reader can hold in mind. The December 2025 Executive Council minutes then…

History
The NAK Rejected the Port, Not the Packet: RFC 938 and the Boundary Between Delivery and Dispatch
In an experimental 1985 Internet protocol, a receiver could say two things at once: the next packet number had been received in sequence, and the local port named in that packet was not known. RFC 938 called that reply `PORT NAK`. Its precision is a useful warning against…

IETF
Bas Westerbaan and the Hybrid TLS Handshake That Did Not Make the Certificate Post-Quantum
A browser can report `X25519MLKEM768`, derive a session secret from classical and post-quantum components, and still authenticate the server with a classical certificate signature. Both observations can be true in the same TLS 1.3 connection. Calling the whole service…

CASE FILE
An OAM Requirement Was Written Down. It Did Not Prove a Working Diagnostic: RFC 9974 and BIER Evidence
A requirements catalogue can sharpen an engineering question. It cannot, on its own, answer whether a particular network can run the test, what the test observed, or who may act on it.

CASE FILE
The Signed Time Saved a Transfer. It Did Not Prove a Moment: RPKI, RFC 9589 and the Switchover Boundary
A RPKI relying party can keep validating useful repository material after its preferred delivery path fails without pretending that a signed timestamp is a trustworthy clock. RFC 9589 makes that distinction operational: one CMS attribute can align filesystem comparison across…

History
The UUID Crossed the Connection. Authority Stayed Put: RFC 927 and the Double-Login Bargain
A TAC could check a name and password once, then send a four-octet user number to the next host. RFC 927's useful restraint lay in what did not travel with that number: the target still decided whether the first host's authentication was good enough for its own service.

Story
AFRINIC’s DBWG Shows 46 Open Items. A Count Is Not a State Path
Forty-six is a number that asks to be over-read. Put it next to the word Open and it can be made to sound like a verdict on an institution, a team or a service. AFRINIC’s public Database Working Group overview does not warrant that verdict. On the frozen 31 August 2026 capture…

CASE FILE
Four Thousand Was a Prefix Claim, Not a Rate-Limit Mandate: RFC 9977 and the Evidence Boundary
A prefix file can make an address range easier to group. It cannot convert a count of end sites into a command to relax a local risk control.

IETF
Daniel Fett and the QR Context That MFA Never Authenticated
The password was right, the second factor was real and the authorization server behaved as designed. The attacker still received the session, because the ceremony proved who the user was without proving whose request the user had approved.

Asia-Pacific Cloud Services
Velo Technologies expands its infrastructure business from Cyberjaya
The Malaysian private company spans data-centre capacity, cloud, managed security, networks and IT outsourcing. Its partnerships are increasingly visible, but its ownership names, absolute financial scale and the economics behind some of its infrastructure commitments remain…

History
The Branch Said “Nobody Below”: RFC 1075 and DVMRP’s Expiring Non-Membership Report
In 1988, experimental multicast routing had to decide when not to send a group’s traffic down a branch. RFC 1075 offered a deliberately limited answer: a downstream router could say that it had no descendant members for one multicast group, and its upstream neighbor could stop…
