Intelligence
Latest Articles
Latest intelligence on infrastructure operators, policy decisions, market moves, and digital power shifts.

History
Both Networks Were Correct Until They Met: RFC 1918 and the Price of Local Uniqueness
At 09:00, two enterprise networks can each be orderly. Each has one machine at the same private address, one route toward it and one name that resolves correctly. At 09:01, an interconnection comes up. Nothing inside either machine has changed, yet the address can no longer…

Story
The RIR Draft Calls the System Bottom-Up. Status-Change Consultations Stay Optional
The recommended RIR Governance Document describes the Internet Numbers Registry System as open and bottom-up. A few pages later, its new Article 2.7 says neither the RIRs nor ICANN are obliged to consult their communities when assessing a proposal to recognise or derecognise a…

IETF
Justin Richer and the Active Token That Could Not Approve the Request
An OAuth resource server asks about a bearer token and receives the most reassuring two-word answer in the exchange: `active: true`. The token is current, the authorization server recognizes it and the request can move forward. Yet one decision is still missing. The introspection…

IETF
A CDN must carry a loop warning it cannot authenticate
A cooperative defence can depend on preserving information that remains untrusted. CDN-Loop exposes the division between a customer's configuration freedom, a provider's protective decision and the evidence needed to explain a failed request.

Creators
Roy Arends and the hard work of changing DNS safely
Roy Arends helped write the 2005 specifications that made modern DNSSEC interoperable across implementations. Two decades later, his work at ICANN focuses on a harder operational problem: changing keys, error signals and delegation in a global system that no organisation can…

IETF
DNSSEC Recovery Runs on Clocks No Signer Controls Alone
The private key is unusable. The zone is still answering, and yesterday’s signatures still validate. That is not recovery; it is borrowed time. A new DNSOP draft explains how to use that interval without destroying the trust that remains. Its harder lesson is institutional: the…

CASE FILE
A DNS Failure Drew 51 Queries. The Cause Was Still Unresolved
APNIC Labs sent several kinds of “no” from an experimental authoritative DNS service. Definitive negatives drew roughly four queries per test. `SERVFAIL` drew 51.73 and silence 83.46. Those are measurements of received traffic—not a verdict on which resolver layer multiplied it.

IETF
A captive portal needs an expiry date for its idea of a device
An address can legitimately pass from one terminal to another. The access system has to retire the old association, not merely recognize the address again. That small distinction connects network admission, accounting and privacy.

IETF
Rifaat Shekh-Yusef and the Nonce Count That Could Not Number the Transaction
The first authenticated request carries `nc=00000001`. It looks uncannily like the beginning of a transaction ledger: neat, monotonic and attached to a credential check. But in the HTTP Digest scheme edited by Rifaat Shekh-Yusef, that small hexadecimal field has a narrower…

History
Before Renumbering Had a Procedure, It Had a Field Diary: RFC 1916
Most RFCs are remembered for an answer. RFC 1916 deserves attention because it published a question. In February 1996, the IETF's PIER working group needed practical guidance for changing enterprise IP addresses, but it did not pretend that a standards room already possessed the…

Story
RIPEstat Is Rebuilding Routing History to Enable CSP. The New View Needs a Parity Record
A safer browser should not leave an operator wondering whether a changed graph reflects changed routes or changed presentation. RIPE NCC has a sound reason to replace legacy RIPEstat visualisations. Routing History is precisely where the migration needs a small public receipt…

IETF
A Self-Signed Delegation Update Proves a Key, Not Its Authority
A DNS message can prove that its sender holds a private key and still leave the decisive question unanswered: who entitled that key to alter a child’s delegation? A DNSOP proposal for rapid child-to-parent updates makes that distinction explicit. Its lasting value will depend on…

CASE FILE
The Purge Was Accepted. The Downstream CDN Still Said No
Revision 20 of an IETF working-group draft follows a cache-control request past the reassuring `201 Created` response. In a CDN cascade, a later rejection has to return as data inside another provider’s status resource—and the provider that refused may remain unnamed.

IETF
A firewall’s speed belongs to a particular configuration
Two reports can describe the same appliance without showing that its protection and performance were achieved together. The missing connection is often the configuration between the tests.

Creators
Roy Arends and the hard work of changing the DNS safely
Roy Arends helped write the 2005 specifications that made modern DNSSEC interoperable. Two decades later, his work at ICANN centres on a harder operational problem: changing keys, error signals and delegations across a global system that no institution can update by command.

History
The Assurance Was Public. The License Form Was Not: RFC 1915
A standard can be open to inspection while a decisive commercial term remains behind the next conversation. In 1996, the IETF published Motorola’s assurance that licences for claimed patents affecting two PPP control protocols would be available on reasonable and…

IETF
Tatu Ylonen and the SSH Window That Could Not Acknowledge the Command
An automation runner pushes a command through SSH, sees the channel window reopen and watches the encrypted connection close cleanly. The dashboard marks the job complete. Yet none of those events says that the remote application committed the intended change. Tatu Ylonen’s RFC…

CASE FILE
A Registry-Lock Quorum Counts Approvals, Not Independent Authority
Two approval messages can look like two-person control while both are recoverable through the same compromised mailbox. A proposed EPP registry-lock extension can count authorising contacts; the harder task is proving that the authorities behind those contacts were genuinely…

CASE FILE
The ICMP Error Named a Node. It Did Not Prove Which One
Revision 05 of an IETF draft makes node context harder to omit when an ICMP source address cannot do the diagnostic job alone. It also exposes a less comfortable truth: a more informative error can carry less of the packet that triggered it, and neither piece is authenticated.

IETF
Why a routing delay metric leaves the queue out
A network can need a stable signal for choosing paths and a sensitive signal for judging service. Trouble begins when a low-latency promise quietly treats them as the same measurement.
