Skip to main content

Intelligence

Latest Articles

Latest intelligence on infrastructure operators, policy decisions, market moves, and digital power shifts.

AI editorial portrait of Bob Hinden beside a hollow IPv6 length cell handing off to a large payload option and a high-capacity path

IETF

Bob Hinden and the Zero Payload Length That Did Not Mean an Empty Packet

An IPv6 capture can present an apparently decisive fact: the base header says the payload length is zero. Bob Hinden’s standards work helps show why that observation is not yet a conclusion. When a Hop-by-Hop Options header follows and bytes remain, zero is a dispatch value: the…

Sep 8, 2026
Seven luminous registry nodes feed four distinct channels into one ambiguous central result, while four separate receipt stacks preserve attribution below.

Story

APNIC’s NIR SIG Asked Four Charter Questions. Its Deck Shows One Unlabelled Result

An APNIC 62 charter-review deck asks seven National Internet Registries four different questions, then places one 86% support chart beside them without saying which question it answers. The proposed charter may still deserve support. But if the NIR SIG is to consolidate views for…

Sep 8, 2026
A teal carriage on a curved metal rail remains connected by an amber cable to a terracotta anchor.

IETF

An IPv4 lease has an IPv6 moving part

Dynamic softwire provisioning gives an IPv4 service more freedom over where it starts. The price of that freedom is a binding whose location, update rate and privacy properties cannot be read from the IPv4 allocation alone.

Sep 8, 2026
A copper stepped schedule on archival map sheets crosses a metal bridge into a longer teal schedule over a networked map of Latin America and the Caribbean.

Story

LACNIC Deferred Its $2,100 IPv6-Only Fee to 2029. The 2020 Notice Still Ends the Waiver in 2026

The lower 2026 price is not an accounting mistake. It is the result of a unanimous Board decision that shifted the final step of LACNIC’s IPv6-only discount from 2026 to 2029. The documentary problem is quieter: the original notice remains public with the old endpoint, while the…

Sep 8, 2026
An amber experimental DNS value passes through a modular gate, splitting from a cyan service path into a monitored branch with a countdown and emergency stop, while a rigid downstream component jams.

IETF

DNS GREASE Needs an Experiment Charter Before It Becomes a Default

A resolver deliberately puts a value with no useful meaning into a DNS query. A correct peer ignores it. A brittle peer may reject the query, stay silent or provoke a retry. The experiment protects tomorrow’s protocol by creating a small inconvenience today. That bargain is…

Sep 8, 2026
AI editorial portrait of Ralph Droms beside a finite DHCP lease arc linking an address pool, renewal, rebinding and return to the pool

IETF

Ralph Droms and the DHCP Acknowledgement That Was Not Address Ownership

A DHCPACK can feel like a title deed: the network has answered, the client has configured an address, and traffic begins. Ralph Droms's DHCP specification defines something more disciplined. In the ordinary allocation path, the acknowledgement commits a server-side binding and…

Sep 8, 2026
Two wooden clasps sit on a continuous purple ribbon; one is open and the other remains closed.

IETF

The repair window inside an EVPN address conflict

Removing a duplicate endpoint and releasing the network state it disturbed are different parts of recovery. Their separation exposes a decision that a closed incident ticket can easily conceal.

Sep 8, 2026
Parallel 1990s message lines pass through a warm character-set gate and return to neutral byte tiles before reaching a cropped CRT window.

History

Every Line Returned to ASCII So the Middle Could Be Read: RFC 1922

Open a long Chinese message at line twenty. If that visible line depends on an escape sequence hidden nineteen lines above, scrolling has become a decoding hazard. RFC 1922 answered with deliberate repetition: a Chinese line declared the character set it needed and returned to…

Sep 8, 2026
AI editorial portrait of Scott Rose beside a recursive resolver validation chamber, one protected AD result path and a separate unsealed path

IETF

Scott Rose and the Authenticated Data Bit That Was Not End-to-End Proof

The `AD` flag in a DNS response can carry a valuable result: a validating recursive resolver believes the relevant answer and authority data is authentic. It can also be dangerously overread. The flag does not authenticate its own trip to a client, describe every validation…

Sep 8, 2026
An amber rehearsal path and cobalt enforcement path converge on a cracked signed-zone crystal, surrounded by a small illuminated resolver cohort and a much larger dark unmeasured network.

IETF

Dry-Run DNSSEC Tests a Resolver Cohort, Not the Internet

A zone is signed, a validator finds the signature wrong, and the user still gets an answer. That apparent contradiction is the point of dry-run DNSSEC. Failure is exposed to an operator without yet becoming failure for the ordinary client. The rehearsal can reveal a broken…

Sep 8, 2026
Two unbranded network test boxes joined by a copper-colored cable, with three paper strips lying straight, folded and curved.

IETF

The network passed the speed test. Who accepted the waiting?

A managed connection can deliver the expected volume of data while leaving an unresolved choice between delay, retransmission and individual transfer performance. That choice belongs in the service handover, not in an unexplained headline rate.

Sep 8, 2026
AI editorial portrait of Nat Sakimura beside an intact JWS signature lattice, a mismatched critical-extension aperture and a separate unlit application plane

IETF

Nat Sakimura and the Critical Header a Valid Signature Could Not Ignore

A JSON Web Signature can pass its mathematical check and still be unusable. RFC 7515 made room for that outcome through `crit`: an integrity-protected list that tells a verifier which extensions it must understand before it may accept the message. The distinction is easy to miss…

Sep 8, 2026
A complete blue route joins two ceramic terminals beside pale, disconnected network extensions.

History

Who pays while a network upgrade waits for everyone else?

A protocol can coexist with old equipment long before it delivers a return to its first users. The history of Quick-Start exposes the cost of that interval—and why a smaller deployment can sometimes be the more ambitious business.

Sep 8, 2026
One Telnet conduit divides into three 1990s terminal-device lanes while a premature second printer request breaks apart before admission.

History

The Second Request Was Deleted. Its Error Had to Wait: RFC 1921

A second printer request arrived before the first had finished. TNVIP did not queue it, number it or let it overtake. The receiver deleted it—and postponed the protocol-violation response until the first request had received its own answer. RFC 1921 used three small, separate…

Sep 8, 2026
An amber registry tile moves onto an archival rail while three cobalt server prisms transition at different stages and one distant client node retains an unlit path toward the old response stream.

IETF

A Deprecation Date Retires an RDAP Label, Not Its Clients

An IANA registry can mark an RDAP extension obsolete. An operator can publish an end date. Yet somewhere beyond both records, a client may still ask for yesterday’s interface. That is not a contradiction. It is a map of divided authority—and a warning against treating one date as…

Sep 8, 2026
A four-tier glass reservoir crowded in its amber lower tiers sends invoice tiles along separate luminous paths while an unlit gauge stands apart.

Story

AFRINIC’s 2025 Receivables Were Almost All Past 60 Days. June’s Zero Bad-Debt Line Does Not Close Them

A dash can look like an ending. AFRINIC’s first-half 2026 report shows no actual bad-debt expense, yet its last audited balance sheet carried USD 561,761 of gross trade receivables more than 60 days old. Those are different accounting states. A privacy-safe cohort rollforward…

Sep 8, 2026
Two orderly 1990s enterprise network rooms use identical amber address devices before their cables converge at a shared boundary junction.

History

Both Networks Were Correct Until They Met: RFC 1918 and the Price of Local Uniqueness

At 09:00, two enterprise networks can each be orderly. Each has one machine at the same private address, one route toward it and one name that resolves correctly. At 09:01, an interconnection comes up. Nothing inside either machine has changed, yet the address can no longer…

Sep 8, 2026
An open ring of community network nodes and five institutional registry nodes feed separate paths into a transparent decision receipt.

Story

The RIR Draft Calls the System Bottom-Up. Status-Change Consultations Stay Optional

The recommended RIR Governance Document describes the Internet Numbers Registry System as open and bottom-up. A few pages later, its new Article 2.7 says neither the RIRs nor ICANN are obliged to consult their communities when assessing a proposal to recognise or derecognise a…

Sep 8, 2026
AI editorial portrait of Justin Richer beside separate token-state, authorization-decision and application-result planes

IETF

Justin Richer and the Active Token That Could Not Approve the Request

An OAuth resource server asks about a bearer token and receives the most reassuring two-word answer in the exchange: `active: true`. The token is current, the authorization server recognizes it and the request can move forward. Yet one decision is still missing. The introspection…

Sep 8, 2026
A marked amber ribbon passes through three graphite gateways, bends back internally and meets a small stop.

IETF

A CDN must carry a loop warning it cannot authenticate

A cooperative defence can depend on preserving information that remains untrusted. CDN-Loop exposes the division between a customer's configuration freedom, a provider's protective decision and the evidence needed to explain a failed request.

Sep 8, 2026