Intelligence
Latest Articles
Latest intelligence on infrastructure operators, policy decisions, market moves, and digital power shifts.

Story
One Source IP Accounted for 38.76% of APNIC's WHOIS Queries in an Hour
One Source IP Accounted for 38.76% of APNIC's WHOIS Queries in an Hour intelligence summary explains the development, the public evidence available to readers, the organisations involved, the regional context, market exposure, and the infrastructure consequences that may follow.…

Number Resource Society
Who can change the Dunnes RIPE record—and what that power does not prove
The authority behind a public internet-resource record is neither unlimited nor merely clerical. In the Dunnes case, protected RIPE Database entities are governed through maintainer authentication, `mnt-by` references and controlled member procedures. Those mechanisms can…

History
The Route That Came Back as Unreachable: How RIP Used Poisoned Reverse
A router learned a path from its neighbour, then deliberately told that same neighbour the path was unreachable. RIP called this poisoned reverse. The apparent contradiction bought fast escape from one kind of loop, while exposing how little any router could know about the…

CASE FILE
The Record Bound the Options. The Client Still Chose the Connection: DNS SVCB, HTTPS and Service Authority
A domain owner can authenticate a list of preferred endpoints, protocols and connection parameters before the first application exchange. That does not make the first preference a command, turn a routing target into the origin, or prove which path a real client can securely…

History
The Row That Existed Before It Could Be Used: How SNMP Separated Creation from Service
A network manager could write every visible cell in a configuration table and still not know whether the device had accepted a usable configuration. SNMP's answer was not to pretend that creation and operation were one event. `RowStatus` gave a conceptual row a lifecycle in which…

CASE FILE
The Counter Hit Its Ceiling. The Filename Opened a New Epoch: RPKI Manifests and Recovery Authority
A correctly signed RPKI manifest can become unusable because a relying party remembers an impossible predecessor. RFC 9981 gives the issuer a narrow way out: change the manifest filename, start a new comparison epoch and preserve every other freshness, location and integrity…

CASE FILE
The Feed Was Valid. The Answer Was Local: DNS Response Policy Zones and the Authority to Rewrite Resolution
An authenticated threat feed can tell a resolver what a publisher recommends. It cannot decide which users lose a name, whether the answer should disappear or be replaced, or who owns the damage when a correct transfer produces the wrong operational result.

IETF
Enke Chen and the Best Path That Kept Its Seat
A BGP router can change its forwarding choice even when the challenger is no better by policy, path length, origin, MED, session type or interior cost. RFC 5004 asks a narrower question: if the only remaining reason to move is the remote speaker's lower BGP Identifier, why move…

Story
AFRINIC's Validator Counted One Fewer Duplicate. The Final Set Stayed at 30,847
Two consecutive validation records moved in an oddly disciplined way. AFRINIC's public Routinator first counted 39,059 valid input VRPs and 8,212 duplicates, then 39,058 inputs and 8,211 duplicates. The final set offered to routers remained 30,847. That unchanged number is not…

History
The Reply That Could Not Edit the Request: How PPP Negotiated a Link
Two machines could share a point-to-point wire and still disagree about the link they were using. PPP did not resolve that disagreement by choosing a master. Each endpoint proposed the changes it wanted, and the other endpoint could accept the proposal exactly, suggest different…

History
The Byte That Had to Repeat Itself to Remain Data: How Telnet Made Room for Commands
Telnet put a terminal's characters and the protocol's own instructions into one TCP stream. That economy created a question every parser had to answer: when the value 255 arrived, was it data or the beginning of control? Telnet's answer was that a literal 255 could cross only by…

CASE FILE
The Digest Matched. The Zone Was Still Wrong: ZONEMD and the Limits of Cryptographic Integrity
A whole-zone checksum can expose truncation, corruption and substitution. It can also authenticate a mistake with perfect precision. The decision for infrastructure leaders is not whether to trust cryptography, but how narrowly to interpret what it has proved.

History
The Lease Could Outlive One Server, but Not Its Deadline: How DHCP Moved from Renewal to Rebinding
A DHCP client does not lose its address merely because one server falls silent. It first asks the server that granted the lease, later widens the request to other authorised servers, and keeps using the address only while the existing deadline still permits it. DHCP made…

History
The Deletion That Wasn't Real Until Goodbye: Why POP3 Waited for QUIT
A mail client could ask a server to delete a message and receive a cheerful `+OK`, yet the message still existed. That was not evasive protocol design. POP3 treated deletion first as a reversible intention, then made the final goodbye the boundary at which the server tried to…

Story
RIPE Marked the Upgrade Complete. Retrieval Failed Twice Afterward
At 17:56 CEST on 22 August, RIPE NCC marked its Alfresco maintenance complete. On Monday afternoon, document creation still worked but some files could not be viewed or downloaded. On Wednesday, a second incident began; RIPE NCC later changed the document system’s configuration…

CASE FILE
The Signal Was Signed. The Delegation Was Not Yet Secure: CDS/CDNSKEY and the Authority to Publish DS
A child zone can publish a perfectly signed request for a new DNSSEC secure entry point and still lack the one chain that would validate it. CDS/CDNSKEY makes parent coordination machine-readable; it does not collapse operational control, registrant authority, parent admission…

CASE FILE
The Catalog Was Valid. The Deletion Was Not: DNS Catalog Zones and the Authority to Provision
An authenticated DNS transfer can deliver a perfectly formed catalog whose operational consequence is to remove every zone from a secondary fleet. The transport may be trustworthy and the syntax impeccable while the decision encoded inside it is still wrong. DNS Catalog Zones…

Leaders
What Mohamed Awang-Lah controlled at MY.NeuTrans—and what he did not
Dr Mohamed Awang-Lah made a consequential structural choice after JARING: he founded a company designed to supply passive network infrastructure to operators without also competing for their retail customers. The public record supports that decision, its implementation and the…

Story
One LACNIC Office Has Three Public Calendar States
LACNIC’s contact record describes one Montevideo office, one set of weekday opening hours and one institutional doorway. Change the language, however, and its public holiday calendar changes year. Spanish presents thirteen dates in 2026; English leaves three in 2025; Portuguese…

CASE FILE
The F-Root outage that showed why redundancy is not the same as readiness
A January 2020 DNS incident exposed a narrow but consequential weakness in distributed infrastructure: many nodes can exist, yet recovery can still depend on whether separate organisations can detect a semantic fault, agree on its cause and exercise emergency routing authority…
