Intelligence
Latest Articles
Latest intelligence on infrastructure operators, policy decisions, market moves, and digital power shifts.

History
The First Answer Was Not the Last Word: How RFC 887 Separated Discovery from Confirmation
A host in 1983 could ask an entire local network who provided a service. Yet RFC 887 refused to treat the first name it heard as final truth. Broadcast discovery, an explicit negative answer, a third-party hint and a provider’s own confirmation were four different kinds of…

CASE FILE
WebDriver May Live at Candidate Recommendation. Cite the Snapshot
W3C's proposed Browser Testing and Tools charter makes an unusual choice explicit. WebDriver and WebDriver BiDi would be developed toward Candidate Recommendation, updated through Snapshots, and not deliberately advanced to Recommendation. That can fit technology implemented…

IETF
Kazuho Oku and the Header That Makes Refusal Legible but Cannot Promise Streaming
An HTTP field can require a proxy that understands it to reject instead of quietly buffering. It cannot command a proxy that has never learned the field. RFC 10036 improves the evidence around incremental delivery precisely by preserving that distinction.

History
The List Called It Official. It Still Did Not Call It Implemented: How RFC 880 Separated Status from Running Code
One row in RFC 880 called the Gateway Gateway Protocol experimental. The same row said it was then used in the core gateways. The apparent contradiction was the point: classification, deployment and fitness were different facts, and the Internet's official catalogue kept them in…

CASE FILE
The Envelope Signed the Digest. It Did Not Deliver the Preimage: RFC 9995 and the Authority Behind a COSE Hash Envelope
A release gate receives a valid signature over the digest of an SBOM. The envelope is small, the cryptography checks out, and the signed location points to a repository. Yet the SBOM itself is absent. Nothing has been downloaded, compared, parsed or judged. RFC 9995 makes the…

CASE FILE
The Proposed WebAuthn Charter Opens Raw Signing. Scope Is Not Approval
W3C is considering a larger mandate for Web Authentication. The proposed charter would let the group work on signatures over arbitrary data, including uses associated with agentic AI and verifiable digital credentials. That sentence opens a standards room; it does not certify the…

Europe and Middle East National Telecom Trends
An NG eCall button is not a proven local safety service until the 4G/5G path is ready
A visible SOS control and an eligible registration date can establish that a vehicle may carry Next Generation eCall. They do not prove that the current UK vehicle-to-emergency-service path is ready to rely on.

AUSNOG
AusNOG Turns Conference Attendance Into Voting Power
AusNOG does more than reward people who keep showing up. Its published rules convert event attendance into membership classes, then convert those classes into different numbers of votes at general meetings.

Story
RIPE NCC Began Verifying Roughly 1,600 No-Contract Legacy Holders. Its Q3 Plan Still Describes Two-Place Updates
RIPE NCC has a sensible plan to give old resource records a clearer organisational anchor. Its own quarterly plan also reveals the awkward middle of that migration: one change may still have to be performed manually in two places. The test is not whether the campaign looks…

IETF
Aaron Parecki and the BFF That Stops Token Theft but Not Client Hijacking
Putting OAuth tokens behind a server is a material security improvement. It is not the end of the authorization story. RFC 10017 shows why: malicious browser code may be unable to steal a token and still be able to spend the user’s live session through the same Backend for…

ICANN
The Proposed Root-Server Governance Model Would Allow Suspension. It Does Not Define Reinstatement
The final proposal for governing the DNS root-server system reserves its sharpest verb for an extreme security case: the future Security Incident Reporting function could suspend a root server operator. The model is careful about how full authority would begin and how permanent…

History
The Back Door Was Not a Route: How RFC 831 Reached a Partitioned SATNET
The emergency machine was allowed to behave like a gateway, but it was forbidden to become one. That distinction carried the whole proposal in RFC 831. A multihomed host at UCL could rewrite a chosen maintenance exchange around a broken SATNET path, yet it would send no routing…

History
The Gateway Could Carry the Bytes. It Could Not Invent the Missing Meaning: How RFC 875 Challenged Protocol Translation
A rectangle labelled “gateway” made incompatible networks look one arrow apart. RFC 875 asked what the rectangle had to remember: two address models, two acknowledgements, two flow-control contracts and exceptional signals that did not command the same actor. Moving data was the…

IETF
Hannes Tschofenig and the Authority ID That Was Not the Token Signer
A measured component can name the key that signed its firmware and still say nothing about the key that signed the enclosing attestation token. RFC 10013 makes that boundary explicit. The identifier, the measurement, the EAT signature and the relying party’s decision are four…

Story
LACNIC Calls Postman Its Current API. The Website Still Says ROAs Change by Serial Number
LACNIC gives an API operator two public descriptions of the same control surface. Its Registration API page says Postman holds the most current v3 documentation, while the route table beside that instruction describes modifying or removing one ROA by `serialNumber`. Follow the…

ICANN
ICANN’s Redaction Archive Reaches 2026. The Register Workbook Stops at FY24
ICANN can show that its annual review of confidential Board material still releases information: a 2025 resolution now names Seville while leaving the contract amount protected. But the Redaction Register page still points to a workbook ending in FY24. The release mechanism…

History
The Master File Could Be Current. The Network Could Still Be Stale: How RFC 849 Split Push from Poll
In May 1983, Mark Crispin described a naming failure that could survive a perfectly updated master file: a host that never learned the file had changed. RFC 849 treated freshness not as a property of the registry alone, but as a chain of version evidence, delivery, integrity…

IETF
Corey Bonnell and the CRL Signature Whose Key Was Not Authorized
A certificate revocation list can carry a flawless digital signature and still be signed by the wrong certified key. RFC 10007 closes that uncomfortable gap by requiring a version 3 CRL issuer certificate to say, explicitly, that its key may sign CRLs. The change turns a skipped…

CASE FILE
The Number Named the Enterprise. It Did Not Authenticate the Model: RFC 9997 and Authority Inside a Private SID Block
A network controller receives the integer key it expected, from the numerical territory associated with the vendor it expected. That is enough to avoid a collision. It is not enough to know who made the mapping, which model the integer denotes, or whether the device in front of…

CASE FILE
Yesterday’s Path Lent the New Flow Its Window. It Did Not Lend Its Capacity: RFC 9959 and the Authority to Reuse Congestion State
A service remembers that yesterday’s connection filled a long, fast path, so today’s connection starts with more confidence than an ordinary new flow. The gain can be real. So can the queue it creates when the same address now reaches another server, route or bottleneck. RFC 9959…
