Skip to main content

Intelligence

Latest Articles

Latest intelligence on infrastructure operators, policy decisions, market moves, and digital power shifts.

A map of Latin America and the Caribbean with reverse-DNS anycast nodes, synchronized records and traffic shifting away from one withdrawn instance.

Story

LACNIC’s reverse-DNS anycast turns registry continuity into a distributed control

Reverse DNS is easy to overlook until it stops answering. LACNIC’s use of anycast for delegated reverse zones shows why registry continuity is not a single-server property, but an operating discipline built from placement, routing, synchronization and observation.

Sep 5, 2026
Two distinct cryptographic paths converge on one compact TCP authentication interface between network endpoints.

History

The Standard That Required Two Answers: TCP-AO's Cryptographic Baseline

Algorithm agility sounds like freedom of choice. For TCP-AO, RFC 5926 exposed the harder half of that promise: two endpoints could each support sound cryptography and still fail to authenticate a single segment unless they shared one precise MAC-and-key-derivation pair.

Sep 5, 2026
Selected conversation nodes flow into a six-column outcome ledger while informal exchanges remain outside it.

AFNOG

AIS 2026 Says Conversations Become Progress Without Publishing an Outcome Ledger

AfNOG presents AIS as a place where conversations translate into real progress. The current first-party page reviewed here does not publish the outcome ledger that would separate discussion from commitment and show follow-through.

Sep 5, 2026
An amber maintenance path remains available at lower preference while blue alternate BGP paths carry traffic between two networks.

IETF

A Graceful Shutdown Community Declares Maintenance Without Taking the Neighbor's Routing Authority

Planned maintenance is a local decision, but the traffic it moves belongs to an interconnection. RFC 8326 gives one network a standard way to say that an EBGP path is about to disappear while leaving the neighboring network in control of its own route preference. That…

Sep 5, 2026
An authenticated TCP path crosses an option-rewriting middlebox before a NAT boundary changes the connection’s endpoint identity.

History

The Translator That Changed the Authenticated Connection: TCP-AO and NAT

A middlebox can change a packet without changing its route. TCP-AO made the consequences depend on what changed: rewriting a TCP option could be accommodated by authenticating fewer fields, but rewriting an address or port changed the identity of the protected connection itself.

Sep 5, 2026
Three institutional stations connect to one conference table through decision paths with an incomplete hand-off route.

AFNOG

AIS 2026 Names Its Organisers and Host but Not Their Decision Boundaries

AIS 2026 publicly names AfNOG and AFRINIC as joint organisers and TESPOK as host. The current first-party page reviewed here does not say which institution decides what when their roles meet.

Sep 5, 2026
A map of Latin America and the Caribbean with distributed measurement probes and network paths converging on a shared evidence repository.

Story

LACNIC’s measurement commons turns regional latency into operating evidence

A latency chart is not a verdict on a country’s Internet. It becomes useful when operators can see the probes, time window and comparison behind it—and when the result leads to a question that can be tested again.

Sep 5, 2026
Abstract network map showing monitored route paths around a protected reserved address block.

Story

AFRINIC Reported Unauthorised Routes from Reserved IPv4 Space. Full Withdrawal Was Not Yet Confirmed

AFRINIC described route announcements involving parts of 102.224.0.0/12 and several response actions; its notice did not close the record on full withdrawal.

Sep 5, 2026
In-room and remote conference paths converge beside an incomplete service and remedy loop.

AFNOG

AIS 2026 Calls Distance No Barrier Without Publishing a Hybrid Participation Standard

AIS 2026 promises live streams and interactive discussions and says distance is not a barrier. The current first-party page reviewed here does not publish the service and remedy standard behind that commitment.

Sep 5, 2026
Two network peers separated by a reboot gap, where an unauthenticated TCP-AO reset is rejected while liveness checks clear stale state.

History

The Reset That Could Not Be Trusted: TCP-AO After a Peer Reboot

TCP normally has a blunt way to tell a peer that an old connection no longer exists: send a reset. TCP-AO makes that answer harder to trust on purpose. When a protected peer reboots and forgets its connection state, the reset it can still send may be precisely the reset the…

Sep 5, 2026
A clear decision gateway stands beside an incomplete review path in a conference setting.

AFNOG

AIS 2026 Names the Power to Exclude but Not a Meeting Appeal Route

AIS 2026 makes one end of its conduct system clear: AFRINIC may exclude a registrant from the meeting, including chat or other communication channels. The public pages reviewed for this article do not make the full meeting-specific decision and review chain equally visible.

Sep 5, 2026
A red DNS failure signal crosses a resolver unchanged while a separate amber diagnostic layer reaches an operator console.

IETF

An Extended DNS Error Explains Failure Without Authorizing a Different Answer

A DNS failure can be technically correct and operationally opaque. RFC 8914 lets a responder attach a more precise explanation to the result, but it deliberately leaves the result itself unchanged. That separation gives operators a useful observability channel—and creates a…

Sep 5, 2026
A stylized route-origin authorization passes through cryptographic validation gates into a resilient routing network.

Story

LACNIC’s RPKI controls make route origin authority operable

LACNIC’s RPKI controls make route origin authority operable intelligence summary explains the development, the public evidence available to readers, the organisations involved, the regional context, market exposure, and the infrastructure consequences that may follow. The Story…

Sep 5, 2026
A bounded cluster of authorized provider links joins a longer AS path that continues outside the attestation frame.

Number Resource Society

An ASPA Is Not a Complete AS-Path Attestation

An ASPA can help an operator test whether an AS path is consistent with published customer-to-provider authorizations. That is valuable route-leak evidence. It is not a signature over every hop, a proof of route origin, a commercial contract, or a guarantee that the published…

Sep 5, 2026
Two versions of meeting terms pass through a publication gate while the notification path stops short of attendee symbols.

AFNOG

AIS 2026 Can Change Its Attendance Terms Without Publishing a Notice Rule

AIS 2026 says its attendance terms may be amended and become valid upon publication. It also treats attendance after a change as confirmation that a registrant has accepted it. The reviewed terms do not say how a consequential change will be brought to each registrant's attention…

Sep 5, 2026
Editorial illustration of anonymous network operators and registry staff discussing records and identity verification at a conference table.

Story

AFRINIC Offered In-Person Registry Checks at AfPIF. The Frozen Page Does Not Report Outcomes

AFRINIC promoted face-to-face help with registry records, identity checks and open requests at AfPIF 2026; the frozen source set does not show what was completed.

Sep 5, 2026
A generic identity card crosses an upload gateway toward locked custody paths beside an incomplete policy sheet.

AFNOG

AIS 2026 Requires an ID Upload Without Publishing Its Handling Rule

AIS 2026 asks every registrant to upload a passport or other government-issued identity document. The public registration and terms pages explain several uses of attendee information, but the reviewed text does not explain the specific lifecycle of that required file.

Sep 5, 2026
A secure certificate-authenticated path is separated from a fading legacy TACACS+ path during migration.

IETF

The Insecure Middle of a Secure TACACS+ Migration: RFC 9887 and the Cost of Dual-Stack Authentication

A TACACS+ client using TLS must not fall back to non-TLS when TLS negotiation fails. Yet a migration can temporarily keep separate non-TLS TACACS+ servers for devices that cannot move at once. That coexistence is not a secure dual stack: RFC 9887 considers the mixed phase…

Sep 5, 2026
Translucent packet segments loop through a sequence-number wrap, with cyan and amber bands distinguishing two TCP-AO SNE epochs.

History

The Segment That Returned to the Same Number: TCP-AO's Sequence Number Extension

A TCP sequence number can come back during one long-lived connection. TCP-AO had to ensure that the repeated 32-bit value did not also repeat the evidence presented to its authenticator.

Sep 5, 2026
A luminous notification beacon leaves a repository while one server chamber contains complete data blocks and another remains empty, splitting the load-balanced delivery path.

CASE FILE

The Notification Arrived. One Backend Still Had Nothing to Serve

The IETF is asking for final comments on a proposed operating guide for RPKI publication services. Its sharpest rule is also the easiest to violate during a routine rollout: do not expose the new notification until every snapshot and delta it names is already available. An index…

Sep 5, 2026