Intelligence
Latest Articles
Latest intelligence on infrastructure operators, policy decisions, market moves, and digital power shifts.

IETF
DNSSEC Recovery Runs on Clocks No Signer Controls Alone
The private key is unusable. The zone is still answering, and yesterday’s signatures still validate. That is not recovery; it is borrowed time. A new DNSOP draft explains how to use that interval without destroying the trust that remains. Its harder lesson is institutional: the…

CASE FILE
A DNS Failure Drew 51 Queries. The Cause Was Still Unresolved
APNIC Labs sent several kinds of “no” from an experimental authoritative DNS service. Definitive negatives drew roughly four queries per test. `SERVFAIL` drew 51.73 and silence 83.46. Those are measurements of received traffic—not a verdict on which resolver layer multiplied it.

IETF
A captive portal needs an expiry date for its idea of a device
An address can legitimately pass from one terminal to another. The access system has to retire the old association, not merely recognize the address again. That small distinction connects network admission, accounting and privacy.

IETF
Rifaat Shekh-Yusef and the Nonce Count That Could Not Number the Transaction
The first authenticated request carries `nc=00000001`. It looks uncannily like the beginning of a transaction ledger: neat, monotonic and attached to a credential check. But in the HTTP Digest scheme edited by Rifaat Shekh-Yusef, that small hexadecimal field has a narrower…

History
Before Renumbering Had a Procedure, It Had a Field Diary: RFC 1916
Most RFCs are remembered for an answer. RFC 1916 deserves attention because it published a question. In February 1996, the IETF's PIER working group needed practical guidance for changing enterprise IP addresses, but it did not pretend that a standards room already possessed the…

Story
RIPEstat Is Rebuilding Routing History to Enable CSP. The New View Needs a Parity Record
A safer browser should not leave an operator wondering whether a changed graph reflects changed routes or changed presentation. RIPE NCC has a sound reason to replace legacy RIPEstat visualisations. Routing History is precisely where the migration needs a small public receipt…

IETF
A Self-Signed Delegation Update Proves a Key, Not Its Authority
A DNS message can prove that its sender holds a private key and still leave the decisive question unanswered: who entitled that key to alter a child’s delegation? A DNSOP proposal for rapid child-to-parent updates makes that distinction explicit. Its lasting value will depend on…

CASE FILE
The Purge Was Accepted. The Downstream CDN Still Said No
Revision 20 of an IETF working-group draft follows a cache-control request past the reassuring `201 Created` response. In a CDN cascade, a later rejection has to return as data inside another provider’s status resource—and the provider that refused may remain unnamed.

IETF
A firewall’s speed belongs to a particular configuration
Two reports can describe the same appliance without showing that its protection and performance were achieved together. The missing connection is often the configuration between the tests.

Creators
Roy Arends and the hard work of changing the DNS safely
Roy Arends helped write the 2005 specifications that made modern DNSSEC interoperable. Two decades later, his work at ICANN centres on a harder operational problem: changing keys, error signals and delegations across a global system that no institution can update by command.

History
The Assurance Was Public. The License Form Was Not: RFC 1915
A standard can be open to inspection while a decisive commercial term remains behind the next conversation. In 1996, the IETF published Motorola’s assurance that licences for claimed patents affecting two PPP control protocols would be available on reasonable and…

IETF
Tatu Ylonen and the SSH Window That Could Not Acknowledge the Command
An automation runner pushes a command through SSH, sees the channel window reopen and watches the encrypted connection close cleanly. The dashboard marks the job complete. Yet none of those events says that the remote application committed the intended change. Tatu Ylonen’s RFC…

CASE FILE
A Registry-Lock Quorum Counts Approvals, Not Independent Authority
Two approval messages can look like two-person control while both are recoverable through the same compromised mailbox. A proposed EPP registry-lock extension can count authorising contacts; the harder task is proving that the authorities behind those contacts were genuinely…

CASE FILE
The ICMP Error Named a Node. It Did Not Prove Which One
Revision 05 of an IETF draft makes node context harder to omit when an ICMP source address cannot do the diagnostic job alone. It also exposes a less comfortable truth: a more informative error can carry less of the packet that triggered it, and neither piece is authenticated.

IETF
Why a routing delay metric leaves the queue out
A network can need a stable signal for choosing paths and a sensitive signal for judging service. Trouble begins when a low-latency promise quietly treats them as the same measurement.

Story
ARIN’s Ombuds Reports Reach the Board. The Public Record Does Not Track the Advice
ARIN’s minutes show that outside advice about the safety and conduct of its meetings does not disappear into a ceremonial file: recommendations have changed practice, some have met practical limits, and the Board is now considering the programme’s scope, continuation and…

IETF
Tim Bray and the Duplicate JSON Name That Could Not Be One Value
A request crosses an API gateway, an authorization service and an audit store. Each component says it parsed the same JSON entity successfully. Yet one kept the last occurrence of a name, another rejected the entity, and a third retained both. The disagreement began before…

CASE FILE
An EPP Balance Can Gate Transactions Without Exposing the Ledger
A registrar can be told exactly how much spending room it has and still be unable to explain why the next domain command was refused. The emerging EPP balance mapping makes funding state operational; it does not turn that state into an accounting record.

CASE FILE
A Holder-Designated RDAP Referral Extends Discovery, Not Registry Authority
A Holder-Designated RDAP Referral Extends Discovery, Not Registry Authority intelligence summary explains the development, the public evidence available to readers, the organisations involved, the regional context, market exposure, and the infrastructure consequences that may…

IETF
Peter Saint-Andre and the Certificate Match That Could Not Choose the Service
The certificate was valid for the name the client checked. That sentence sounds like the end of authentication, but it hides the first and more consequential choice: why did the client check that name? Peter Saint-Andre and Rich Salz make the order explicit in RFC 9525. The…
