Skip to main content

Intelligence

Latest Articles

Latest intelligence on infrastructure operators, policy decisions, market moves, and digital power shifts.

An intact amber signed-zone lattice remains linked to old trust material while a dormant signer, a new cobalt signer, a parent layer and three secondary nodes progress on separate timing arcs.

IETF

DNSSEC Recovery Runs on Clocks No Signer Controls Alone

The private key is unusable. The zone is still answering, and yesterday’s signatures still validate. That is not recovery; it is borrowed time. A new DNSOP draft explains how to use that interval without destroying the trust that remains. Its harder lesson is institutional: the…

Sep 8, 2026
A single red DNS signal branches into many cyan retry paths across layered resolvers before reaching an authoritative server.

CASE FILE

A DNS Failure Drew 51 Queries. The Cause Was Still Unresolved

APNIC Labs sent several kinds of “no” from an experimental authoritative DNS service. Definitive negatives drew roughly four queries per test. `SERVFAIL` drew 51.73 and silence 83.46. Those are measurements of received traffic—not a verdict on which resolver layer multiplied it.

Sep 8, 2026
Two blank terminal models linked by paper paths to a gateway and separate status tabs; the older path stops short.

IETF

A captive portal needs an expiry date for its idea of a device

An address can legitimately pass from one terminal to another. The access system has to retire the old association, not merely recognize the address again. That small distinction connects network admission, accounting and privacy.

Sep 8, 2026
AI editorial portrait of Rifaat Shekh-Yusef beside a nonce-scoped request sequence separated from a durable application ledger

IETF

Rifaat Shekh-Yusef and the Nonce Count That Could Not Number the Transaction

The first authenticated request carries `nc=00000001`. It looks uncannily like the beginning of a transaction ledger: neat, monotonic and attached to a credential check. But in the HTTP Digest scheme edited by Rifaat Shekh-Yusef, that small hexadecimal field has a narrower…

Sep 8, 2026
Blank field notebooks collect cable-linked observations from 1990s network equipment before an empty procedure binder is written.

History

Before Renumbering Had a Procedure, It Had a Field Diary: RFC 1916

Most RFCs are remembered for an answer. RFC 1916 deserves attention because it published a question. In February 1996, the IETF's PIER working group needed practical guidance for changing enterprise IP addresses, but it did not pretend that a standards room already possessed the…

Sep 8, 2026
Two transparent panels show the same luminous routing timeline, joined by a narrow amber verification bridge.

Story

RIPEstat Is Rebuilding Routing History to Enable CSP. The New View Needs a Parity Record

A safer browser should not leave an operator wondering whether a changed graph reflects changed routes or changed presentation. RIPE NCC has a sound reason to replace legacy RIPEstat visualisations. Routing History is precisely where the migration needs a small public receipt…

Sep 8, 2026
An amber candidate credential waits in a clear intake chamber while three independent verification paths separate it from a cobalt parent-delegation plane that retains its incumbent credential.

IETF

A Self-Signed Delegation Update Proves a Key, Not Its Authority

A DNS message can prove that its sender holds a private key and still leave the decisive question unanswered: who entitled that key to alter a child’s delegation? A DNSOP proposal for rapid child-to-parent updates makes that distinction explicit. Its lasting value will depend on…

Sep 8, 2026
An amber purge signal is accepted by a middle cache, rejected downstream and returned as a red status error above repeated counters and a reconciling node.

CASE FILE

The Purge Was Accepted. The Downstream CDN Still Said No

Revision 20 of an IETF working-group draft follows a cache-control request past the reassuring `201 Created` response. In a CDN cascade, a later rejection has to return as data inside another provider’s status resource—and the provider that refused may remain unnamed.

Sep 8, 2026
A dark cutaway network appliance beside two open cartridges with different colored layers, each clipped to a blank paper folio.

IETF

A firewall’s speed belongs to a particular configuration

Two reports can describe the same appliance without showing that its protection and performance were achieved together. The missing connection is often the configuration between the tests.

Sep 8, 2026
Editorial illustration representing DNS security, DNSSEC and the operation of global domain name infrastructure.

Creators

Roy Arends and the hard work of changing the DNS safely

Roy Arends helped write the 2005 specifications that made modern DNSSEC interoperable. Two decades later, his work at ICANN centres on a harder operational problem: changing keys, error signals and delegations across a global system that no institution can update by command.

Sep 8, 2026
A mid-1990s standards workspace where open protocol papers pass through an illuminated procedural gate while a sealed blank licence folder remains behind frosted glass

History

The Assurance Was Public. The License Form Was Not: RFC 1915

A standard can be open to inspection while a decisive commercial term remains behind the next conversation. In 1996, the IETF published Motorola’s assurance that licences for claimed patents affecting two PPP control protocols would be available on reasonable and…

Sep 8, 2026
AI editorial portrait of Tatu Ylonen beside an SSH flow-control aperture granting byte credit while the command result remains unlit

IETF

Tatu Ylonen and the SSH Window That Could Not Acknowledge the Command

An automation runner pushes a command through SSH, sees the channel window reopen and watches the encrypted connection close cleanly. The dashboard marks the job complete. Yet none of those events says that the remote application committed the intended change. Tatu Ylonen’s RFC…

Sep 8, 2026
Four amber approval nodes feed a registry gate while concealed conduits converge on one shared control hub beneath the surface.

CASE FILE

A Registry-Lock Quorum Counts Approvals, Not Independent Authority

Two approval messages can look like two-person control while both are recoverable through the same compromised mailbox. A proposed EPP registry-lock extension can count authorising contacts; the harder task is proving that the authorities behind those contacts were genuinely…

Sep 8, 2026
A blue node-context capsule and a shortened amber packet-evidence strip leave a translation gateway for separate inspection trays.

CASE FILE

The ICMP Error Named a Node. It Did Not Prove Which One

Revision 05 of an IETF draft makes node context harder to omit when an ICMP source address cannot do the diagnostic job alone. It also exposes a less comfortable truth: a more informative error can carry less of the packet that triggered it, and neither piece is authenticated.

Sep 8, 2026
A queue of ivory packet tiles on a copper track beneath a calm blue measurement rail between two sculptural routers.

IETF

Why a routing delay metric leaves the queue out

A network can need a stable signal for choosing paths and a sensitive signal for judging service. Trouble begins when a low-latency promise quietly treats them as the same measurement.

Sep 8, 2026
A closed case folder sits apart from four orderly tracks of abstract disposition tokens on a dark boardroom table.

Story

ARIN’s Ombuds Reports Reach the Board. The Public Record Does Not Track the Advice

ARIN’s minutes show that outside advice about the safety and conduct of its meetings does not disappear into a ceremonial file: recommendations have changed practice, some have met practical limits, and the Board is now considering the programme’s scope, continuation and…

Sep 8, 2026
AI editorial portrait of Tim Bray beside a parser prism splitting duplicate object names into incompatible outcomes

IETF

Tim Bray and the Duplicate JSON Name That Could Not Be One Value

A request crosses an API gateway, an authorization service and an audit store. Each component says it parsed the same JSON entity successfully. Yet one kept the last occurrence of a name, another rejected the entity, and a third retained both. The disagreement began before…

Sep 8, 2026
Three luminous financial-state slabs send network transactions through a threshold gate toward a separate layered audit archive.

CASE FILE

An EPP Balance Can Gate Transactions Without Exposing the Ledger

A registrar can be told exactly how much spending room it has and still be unable to explain why the next domain command was refused. The emerging EPP balance mapping makes funding state operational; it does not turn that state into an accounting record.

Sep 8, 2026
A cyan registry archive and amber holder data cabinet exchange query paths across a transparent authority seam while remaining visibly separate.

CASE FILE

A Holder-Designated RDAP Referral Extends Discovery, Not Registry Authority

A Holder-Designated RDAP Referral Extends Discovery, Not Registry Authority intelligence summary explains the development, the public evidence available to readers, the organisations involved, the regional context, market exposure, and the infrastructure consequences that may…

Sep 7, 2026
AI editorial portrait of Peter Saint-Andre between an anchored client identity and a separate certificate comparison plane

IETF

Peter Saint-Andre and the Certificate Match That Could Not Choose the Service

The certificate was valid for the name the client checked. That sentence sounds like the end of authentication, but it hides the first and more consequential choice: why did the client check that name? Peter Saint-Andre and Rich Salz make the order explicit in RFC 9525. The…

Sep 7, 2026