Skip to main content

Intelligence

Latest Articles

Latest intelligence on infrastructure operators, policy decisions, market moves, and digital power shifts.

A closed case folder sits apart from four orderly tracks of abstract disposition tokens on a dark boardroom table.

Story

ARIN’s Ombuds Reports Reach the Board. The Public Record Does Not Track the Advice

ARIN’s minutes show that outside advice about the safety and conduct of its meetings does not disappear into a ceremonial file: recommendations have changed practice, some have met practical limits, and the Board is now considering the programme’s scope, continuation and…

Sep 8, 2026
AI editorial portrait of Tim Bray beside a parser prism splitting duplicate object names into incompatible outcomes

IETF

Tim Bray and the Duplicate JSON Name That Could Not Be One Value

A request crosses an API gateway, an authorization service and an audit store. Each component says it parsed the same JSON entity successfully. Yet one kept the last occurrence of a name, another rejected the entity, and a third retained both. The disagreement began before…

Sep 8, 2026
Three luminous financial-state slabs send network transactions through a threshold gate toward a separate layered audit archive.

CASE FILE

An EPP Balance Can Gate Transactions Without Exposing the Ledger

A registrar can be told exactly how much spending room it has and still be unable to explain why the next domain command was refused. The emerging EPP balance mapping makes funding state operational; it does not turn that state into an accounting record.

Sep 8, 2026
A cyan registry archive and amber holder data cabinet exchange query paths across a transparent authority seam while remaining visibly separate.

CASE FILE

A Holder-Designated RDAP Referral Extends Discovery, Not Registry Authority

A Holder-Designated RDAP Referral Extends Discovery, Not Registry Authority intelligence summary explains the development, the public evidence available to readers, the organisations involved, the regional context, market exposure, and the infrastructure consequences that may…

Sep 7, 2026
AI editorial portrait of Peter Saint-Andre between an anchored client identity and a separate certificate comparison plane

IETF

Peter Saint-Andre and the Certificate Match That Could Not Choose the Service

The certificate was valid for the name the client checked. That sentence sounds like the end of authentication, but it hides the first and more consequential choice: why did the client check that name? Peter Saint-Andre and Rich Salz make the order explicit in RFC 9525. The…

Sep 7, 2026
Editorial portrait illustration of Dr. Mohamed Awang Lah in a Malaysian internet-infrastructure setting with network diagrams, maps and server systems.

Leaders

Mohamed Awang Lah and the Problem of Making Internet Capability Survive Institutional Change

The most revealing question about Mohamed Awang Lah is not whether he was important to Malaysia’s early internet development. The public record makes his importance difficult to dispute. The harder question is what, precisely, survived his successive roles: a person’s authority…

Sep 7, 2026
A warm archival document lies beneath a translucent blue draft, with an interrupted registration notch between the two public states.

Story

APNIC’s Definition Page Shows a Draft. Its Official Text Is Still Active

APNIC built one definition document so the same words would not acquire different meanings as they crossed policy files. The document now has a different problem. Its main web page presents version 004 as a draft; its stable official-text address still presents version 003 as…

Sep 7, 2026
A server stack is observed through a policy lens at a dated validation instrument while sealed poll messages move in order toward a receiving gate.

CASE FILE

A Successful EPP Server Validation Is a Dated Policy Verdict, Not a Health Certificate

The word “success” can survive on a dashboard long after the observation that produced it has expired. A new EPP proposal would make the result portable; governance begins by refusing to make it timeless.

Sep 7, 2026
AI editorial portrait of Alexey Melnikov beside a completed identity exchange branching through separate application authorization gates

IETF

Alexey Melnikov and the Authentication Success That Could Not Grant a Service

The status light turned green. The credentials had been accepted, an identity had been associated with the session, and the exchange was over. Yet the next operation could still be refused without contradiction. The architecture Alexey Melnikov and Kurt Zeilenga set out in RFC…

Sep 7, 2026
A luminous primary token anchors an implicit constellation inside one atomic ring, connected through a central repository to three registry gateways while an external rule plate sets the boundary.

CASE FILE

The EPP Same-Entity Set Turns an External Policy Into an Atomic Boundary

A registrar can submit a command naming one domain while the repository must decide whether that command reaches a set too large to list. The protocol message is visible; the rule that draws its boundary may sit somewhere else.

Sep 7, 2026
A packet carrying a row of recipient compartments enters a final router, which fans delivery across a subnet only to selected terminals.

History

The Broadcast Packet That Carried Its Own Guest List

One UDP datagram approached a remote subnet as a broadcast, yet it carried a private instruction inside its IPv4 header: these hosts may listen; the others must stop. Selective Directed Broadcast Mode tried to make the packet itself serve as a temporary membership list.

Sep 7, 2026
AI editorial portrait of Alissa Cooper beside an unfinished privacy-review matrix linking observers, identifiers, correlation, retention and deployment evidence

IETF

Alissa Cooper and the Privacy Review That Could Not Issue a Safety Certificate

The review workbook had answers in every cell: identifiers listed, observers named, retention discussed, defaults justified. What it did not have was a truthful final cell marked “safe”. Alissa Cooper and her co-authors designed RFC 6973 to make privacy reasoning inspectable, not…

Sep 7, 2026
One pale canopy spans three different certificate workstations fitted with matching navy stencils, while an incompatible brass stencil rests unused beside them.

IETF

One CA Name, Several Ways to Issue

A buyer reviewing certificate operations asks a simple question: if DNS authorizes one certification-authority name with an account and a validation method, does that restriction govern every issuing system behind the name? RFC 8657 makes the answer consequential. A shared CA…

Sep 7, 2026
Equal cyan and amber protocol paths connect separate client-server pairs to parallel slots in a dark archival registry through distinct translucent namespace frames.

CASE FILE

The EPP Extension Registry Records Coexistence, Not a Winner

Two extensions can solve much the same provisioning problem, use different XML namespaces and both deserve a place in the same public registry. That is not a defect in the catalogue. It is the governance fact the catalogue must preserve.

Sep 7, 2026
Two illuminated starting markers feed one clockwork mechanism beside a networked map of Africa, while a separate ring hangs without an anchor.

Story

AFRINIC's Six-Month Implementation Rule Has Two Start Dates

A policy clock is useful only when the institution and its community can identify the event that started it. AFRINIC's current Consolidated Policy Manual starts its six-month implementation expectation at the end of Last Call. AFRINIC's current public explanation starts it at…

Sep 7, 2026
AI editorial portrait of Barry Leiba beside an abstract keyword embedded in a full requirement chain from document authority to implementation evidence

IETF

Barry Leiba and the Capital Letters That Could Not Create Authority

A requirements scanner finds `MUST` in a specification and reports certainty. It has found a word, not yet an obligation. Barry Leiba’s RFC 8174 drew a clean boundary around the special vocabulary of BCP 14, but the boundary works in both directions: capitals activate defined…

Sep 7, 2026
A blue card replaces an amber card at a waiting slot; another amber card is already beside a dark phone.

IETF

The Price of Keeping Only the Latest Notification

Web Push can spare a returning device a backlog of obsolete updates. The difficult decision is not how to replace a waiting message, but which information the business can afford to leave behind.

Sep 7, 2026
Four outer bundle capsules each trigger a delivery light, while their amber payload fragments remain split between two reassembly chambers and a separate BPA reception gate stays closed.

CASE FILE

Every Outer Bundle Was Delivered. The Inner Bundle Still Had Not Been Received

Bundle-in-Bundle Encapsulation gives a delay-tolerant network two journeys to observe. The outer bundles can reach their configured endpoint one by one, each with a valid delivery report, while the bundle carried inside them never reaches the Bundle Protocol Agent. The new DTN…

Sep 7, 2026
Paired glass evidence capsules pass from a resolver through layered registry and application gates, then stop at a consent threshold before exposed and protected retrieval paths.

CASE FILE

A DNS Filtering Notice Is a Chain of Three Decisions, Not One Explanation

A link that explains why a name was filtered looks like a simple act of transparency. By the time it reaches a user, however, a resolver, an application and the user have each made a different decision. The record must preserve all three.

Sep 7, 2026
AI editorial portrait of Michelle Cotton beside two implementation paths converging on a luminous time-bounded provisional protocol-registry slot

IETF

Michelle Cotton and the Code Point That Arrived Before Its RFC

The awkward moment comes before a standard is finished: two implementations need the same numeric language to meet, but the registry would normally wait for publication. Michelle Cotton’s RFC 7120 turned that timing gap into a visible, expiring state. Its most important word is…

Sep 7, 2026