Intelligence
Latest Articles
Latest intelligence on infrastructure operators, policy decisions, market moves, and digital power shifts.

IETF
David Harrington and the SNMP Context That Did Not Identify the Operator
The command named an engine, a context and an entity with precision. None of those fields said which human had chosen the change. David Harrington’s SNMP architecture makes that absence visible rather than filling it with an assumption.

Story
A Backup DNS Plan Is Not a Second Resolver
A 9 September APNIC Blog account turns a household outage into a precise infrastructure lesson: resilience begins only when an alternative service is running, reaches the clients that depend on it, survives a controlled failure and can be rolled back.

IETF
RFC 9979’s `$istrusted` Badge Needs a Correction Record
A green check can outlive the judgment that painted it. A mail server marks a message `$istrusted`; several clients synchronize the shared keyword; a reader acts because the interface presents the sender as verified. Later, the server discovers that its evidence or policy was…

Story
RIPE NCC’s K-root Refresh Needs Three Acceptance Records, Not One Batch Status
Amsterdam can be refreshed while the three-site programme remains in progress. That is not a contradiction; it is a warning about the unit of evidence. RIPE NCC has named three K-root core sites whose seven-year-old routers and servers were due for replacement. The useful public…

IETF
Bernard Aboba and the EAP Method That Did Not Grant Network Access
The credential was valid and the authentication method finished cleanly. Yet the controlled port stayed closed. Bernard Aboba’s work on EAP explains why those two observations can coexist without contradiction.

IETF
An SSH Agent Signature Is Not a Consent Receipt
A private key never left its protected agent, the requested bytes were signed correctly, and the remote service still received an act that nobody had meaningfully approved. Those facts can coexist. Keeping a key non-exportable answers where the secret stayed. It does not answer…

IETF
The manifest followed the telemetry. The verdict did not
Revision 14 gives collected network data a companion record of its platform, schema and collection conditions. That makes a datapoint easier to read later; it does not make the datapoint complete, the clock trustworthy or the resulting decision correct.

IETF
Chris Newman and the Secure Mail Port That Did Not Authorize a User
Port 465 can require the conversation to begin with TLS, but it cannot decide who may send a message. Chris Newman’s work on secure mail access shows why transport, service identity, user authentication and authorization need separate receipts.

IETF
The log line parsed. The authority to read the connection did not: RFC 9850
RFC 9850 gives diagnostic tools a common way to read TLS connection secrets. The grammar is small; the authority it can transfer is not. A usable key-log record proves neither permission nor safe closure.

History
The Packet Stayed Native, but the Dictionary Moved: RFC 1977's Hidden PPP State
A packet capture can show an ordinary PPP datagram while both endpoints quietly rewrite the codebook that will determine the meaning of the next compressed packet. RFC 1977 made that invisible transition a condition of interoperability.

Story
AFRINIC Says It Belongs to All of Us. Its SGMM Notice Draws a Smaller Corporate Boundary
AFRINIC’s anniversary message speaks to members, stakeholders and the wider Internet community in one generous voice. Six days later, the meeting named in that message operated through a narrower set of corporate roles. Both can be legitimate. The governance test is whether a…

Story
LACNIC’s Autonomous-Network Ladder Needs a Scenario Ledger, Not a Company Badge
Two operators can both call themselves level three while describing entirely different machines. One may automate fault diagnosis in a radio network; the other may automate service fulfilment but leave every consequential configuration change to a person. The number sounds…

IETF
Set-Cookie Is Not a Storage Receipt
A response crossed the network with a valid `Set-Cookie` field, and the release dashboard marked the session step complete. The next request arrived without the cookie. Nothing in those two observations is contradictory. RFC 10025 gives the server authority to issue an…

IETF
Keith Moore and the Encoded Word That Changed the Display, Not the Sender
Two ASCII header lines can open into the same accented name on screen. That visual agreement is useful, but it is the end of a decoding process—not a receipt for who sent the message.

History
The Header Came Last: How RFC 1963 Reassembled Serial Frames over PPP
RFC 1963 made an unusual bargain with time: send the serial data first, postpone the adaptation header until the packet's end, and let the transmitter decide on segmentation only after compression had revealed the size. What reached the receiver was a grammar for reconstruction…

IETF
A CoAP Group Address Is Not a Security Membership Roster
RFC 10020 separates three groups that operational dashboards often collapse: endpoints listening on a multicast address, servers exposing a common application function, and devices holding shared security material. A packet can cross the first boundary and authenticate at the…

IETF
The verifier subscribed. The evidence chain still had seven tests
An IETF draft turns device attestation from a polling exercise into a stream. That is a useful change in tempo, but a signed notification is still only one link between a measurement and a decision.

Story
RIPE NCC Says Its 2027 Invoicing Changes Are Complete. The Bill Still Waits for 31 December
RIPE NCC has finished the applications work for its 2027 charging scheme before the data that will determine the first bills exists. That is sensible project management. It is also why “complete” needs a second, more operational meaning in January: can each charge be reproduced…

Story
ARIN’s RPKI Constraint Is Only as Current as the Package That Ships It
A trust boundary can be carefully designed, correctly signed and still arrive too late. ARIN’s planned RPKI constraint work makes that mundane distribution problem part of routing-security policy.

CASE FILE
AlmazCloud’s ASN Is Registered. What Can Be Shown as Operating?
AlmazCloud’s ASN Is Registered. What Can Be Shown as Operating? intelligence summary explains the development, the public evidence available to readers, the organisations involved, the regional context, market exposure, and the infrastructure consequences that may follow. The…
