Skip to main content

Intelligence

Latest Articles

Latest intelligence on infrastructure operators, policy decisions, market moves, and digital power shifts.

Two orderly 1990s enterprise network rooms use identical amber address devices before their cables converge at a shared boundary junction.

History

Both Networks Were Correct Until They Met: RFC 1918 and the Price of Local Uniqueness

At 09:00, two enterprise networks can each be orderly. Each has one machine at the same private address, one route toward it and one name that resolves correctly. At 09:01, an interconnection comes up. Nothing inside either machine has changed, yet the address can no longer…

Sep 8, 2026
An open ring of community network nodes and five institutional registry nodes feed separate paths into a transparent decision receipt.

Story

The RIR Draft Calls the System Bottom-Up. Status-Change Consultations Stay Optional

The recommended RIR Governance Document describes the Internet Numbers Registry System as open and bottom-up. A few pages later, its new Article 2.7 says neither the RIRs nor ICANN are obliged to consult their communities when assessing a proposal to recognise or derecognise a…

Sep 8, 2026
AI editorial portrait of Justin Richer beside separate token-state, authorization-decision and application-result planes

IETF

Justin Richer and the Active Token That Could Not Approve the Request

An OAuth resource server asks about a bearer token and receives the most reassuring two-word answer in the exchange: `active: true`. The token is current, the authorization server recognizes it and the request can move forward. Yet one decision is still missing. The introspection…

Sep 8, 2026
A marked amber ribbon passes through three graphite gateways, bends back internally and meets a small stop.

IETF

A CDN must carry a loop warning it cannot authenticate

A cooperative defence can depend on preserving information that remains untrusted. CDN-Loop exposes the division between a customer's configuration freedom, a provider's protective decision and the evidence needed to explain a failed request.

Sep 8, 2026
Roy Arends and the hard work of changing DNS safely

Creators

Roy Arends and the hard work of changing DNS safely

Roy Arends helped write the 2005 specifications that made modern DNSSEC interoperable across implementations. Two decades later, his work at ICANN focuses on a harder operational problem: changing keys, error signals and delegation in a global system that no organisation can…

Sep 8, 2026
An intact amber signed-zone lattice remains linked to old trust material while a dormant signer, a new cobalt signer, a parent layer and three secondary nodes progress on separate timing arcs.

IETF

DNSSEC Recovery Runs on Clocks No Signer Controls Alone

The private key is unusable. The zone is still answering, and yesterday’s signatures still validate. That is not recovery; it is borrowed time. A new DNSOP draft explains how to use that interval without destroying the trust that remains. Its harder lesson is institutional: the…

Sep 8, 2026
A single red DNS signal branches into many cyan retry paths across layered resolvers before reaching an authoritative server.

CASE FILE

A DNS Failure Drew 51 Queries. The Cause Was Still Unresolved

APNIC Labs sent several kinds of “no” from an experimental authoritative DNS service. Definitive negatives drew roughly four queries per test. `SERVFAIL` drew 51.73 and silence 83.46. Those are measurements of received traffic—not a verdict on which resolver layer multiplied it.

Sep 8, 2026
Two blank terminal models linked by paper paths to a gateway and separate status tabs; the older path stops short.

IETF

A captive portal needs an expiry date for its idea of a device

An address can legitimately pass from one terminal to another. The access system has to retire the old association, not merely recognize the address again. That small distinction connects network admission, accounting and privacy.

Sep 8, 2026
AI editorial portrait of Rifaat Shekh-Yusef beside a nonce-scoped request sequence separated from a durable application ledger

IETF

Rifaat Shekh-Yusef and the Nonce Count That Could Not Number the Transaction

The first authenticated request carries `nc=00000001`. It looks uncannily like the beginning of a transaction ledger: neat, monotonic and attached to a credential check. But in the HTTP Digest scheme edited by Rifaat Shekh-Yusef, that small hexadecimal field has a narrower…

Sep 8, 2026
Blank field notebooks collect cable-linked observations from 1990s network equipment before an empty procedure binder is written.

History

Before Renumbering Had a Procedure, It Had a Field Diary: RFC 1916

Most RFCs are remembered for an answer. RFC 1916 deserves attention because it published a question. In February 1996, the IETF's PIER working group needed practical guidance for changing enterprise IP addresses, but it did not pretend that a standards room already possessed the…

Sep 8, 2026
Two transparent panels show the same luminous routing timeline, joined by a narrow amber verification bridge.

Story

RIPEstat Is Rebuilding Routing History to Enable CSP. The New View Needs a Parity Record

A safer browser should not leave an operator wondering whether a changed graph reflects changed routes or changed presentation. RIPE NCC has a sound reason to replace legacy RIPEstat visualisations. Routing History is precisely where the migration needs a small public receipt…

Sep 8, 2026
An amber candidate credential waits in a clear intake chamber while three independent verification paths separate it from a cobalt parent-delegation plane that retains its incumbent credential.

IETF

A Self-Signed Delegation Update Proves a Key, Not Its Authority

A DNS message can prove that its sender holds a private key and still leave the decisive question unanswered: who entitled that key to alter a child’s delegation? A DNSOP proposal for rapid child-to-parent updates makes that distinction explicit. Its lasting value will depend on…

Sep 8, 2026
An amber purge signal is accepted by a middle cache, rejected downstream and returned as a red status error above repeated counters and a reconciling node.

CASE FILE

The Purge Was Accepted. The Downstream CDN Still Said No

Revision 20 of an IETF working-group draft follows a cache-control request past the reassuring `201 Created` response. In a CDN cascade, a later rejection has to return as data inside another provider’s status resource—and the provider that refused may remain unnamed.

Sep 8, 2026
A dark cutaway network appliance beside two open cartridges with different colored layers, each clipped to a blank paper folio.

IETF

A firewall’s speed belongs to a particular configuration

Two reports can describe the same appliance without showing that its protection and performance were achieved together. The missing connection is often the configuration between the tests.

Sep 8, 2026
Editorial illustration representing DNS security, DNSSEC and the operation of global domain name infrastructure.

Creators

Roy Arends and the hard work of changing the DNS safely

Roy Arends helped write the 2005 specifications that made modern DNSSEC interoperable. Two decades later, his work at ICANN centres on a harder operational problem: changing keys, error signals and delegations across a global system that no institution can update by command.

Sep 8, 2026
A mid-1990s standards workspace where open protocol papers pass through an illuminated procedural gate while a sealed blank licence folder remains behind frosted glass

History

The Assurance Was Public. The License Form Was Not: RFC 1915

A standard can be open to inspection while a decisive commercial term remains behind the next conversation. In 1996, the IETF published Motorola’s assurance that licences for claimed patents affecting two PPP control protocols would be available on reasonable and…

Sep 8, 2026
AI editorial portrait of Tatu Ylonen beside an SSH flow-control aperture granting byte credit while the command result remains unlit

IETF

Tatu Ylonen and the SSH Window That Could Not Acknowledge the Command

An automation runner pushes a command through SSH, sees the channel window reopen and watches the encrypted connection close cleanly. The dashboard marks the job complete. Yet none of those events says that the remote application committed the intended change. Tatu Ylonen’s RFC…

Sep 8, 2026
Four amber approval nodes feed a registry gate while concealed conduits converge on one shared control hub beneath the surface.

CASE FILE

A Registry-Lock Quorum Counts Approvals, Not Independent Authority

Two approval messages can look like two-person control while both are recoverable through the same compromised mailbox. A proposed EPP registry-lock extension can count authorising contacts; the harder task is proving that the authorities behind those contacts were genuinely…

Sep 8, 2026
A blue node-context capsule and a shortened amber packet-evidence strip leave a translation gateway for separate inspection trays.

CASE FILE

The ICMP Error Named a Node. It Did Not Prove Which One

Revision 05 of an IETF draft makes node context harder to omit when an ICMP source address cannot do the diagnostic job alone. It also exposes a less comfortable truth: a more informative error can carry less of the packet that triggered it, and neither piece is authenticated.

Sep 8, 2026
A queue of ivory packet tiles on a copper track beneath a calm blue measurement rail between two sculptural routers.

IETF

Why a routing delay metric leaves the queue out

A network can need a stable signal for choosing paths and a sensitive signal for judging service. Trouble begins when a low-latency promise quietly treats them as the same measurement.

Sep 8, 2026