Skip to main content

Intelligence

Latest Articles

Latest intelligence on infrastructure operators, policy decisions, market moves, and digital power shifts.

Editorial illustration of anonymous network operators and registry staff discussing records and identity verification at a conference table.

Story

AFRINIC Offered In-Person Registry Checks at AfPIF. The Frozen Page Does Not Report Outcomes

AFRINIC promoted face-to-face help with registry records, identity checks and open requests at AfPIF 2026; the frozen source set does not show what was completed.

Sep 5, 2026
A generic identity card crosses an upload gateway toward locked custody paths beside an incomplete policy sheet.

AFNOG

AIS 2026 Requires an ID Upload Without Publishing Its Handling Rule

AIS 2026 asks every registrant to upload a passport or other government-issued identity document. The public registration and terms pages explain several uses of attendee information, but the reviewed text does not explain the specific lifecycle of that required file.

Sep 5, 2026
A secure certificate-authenticated path is separated from a fading legacy TACACS+ path during migration.

IETF

The Insecure Middle of a Secure TACACS+ Migration: RFC 9887 and the Cost of Dual-Stack Authentication

A TACACS+ client using TLS must not fall back to non-TLS when TLS negotiation fails. Yet a migration can temporarily keep separate non-TLS TACACS+ servers for devices that cannot move at once. That coexistence is not a secure dual stack: RFC 9887 considers the mixed phase…

Sep 5, 2026
Translucent packet segments loop through a sequence-number wrap, with cyan and amber bands distinguishing two TCP-AO SNE epochs.

History

The Segment That Returned to the Same Number: TCP-AO's Sequence Number Extension

A TCP sequence number can come back during one long-lived connection. TCP-AO had to ensure that the repeated 32-bit value did not also repeat the evidence presented to its authenticator.

Sep 5, 2026
A luminous notification beacon leaves a repository while one server chamber contains complete data blocks and another remains empty, splitting the load-balanced delivery path.

CASE FILE

The Notification Arrived. One Backend Still Had Nothing to Serve

The IETF is asking for final comments on a proposed operating guide for RPKI publication services. Its sharpest rule is also the easiest to violate during a routine rollout: do not expose the new notification until every snapshot and delta it names is already available. An index…

Sep 5, 2026
Abstract route-candidate capsules cross a BGP carriage gate into an independent multi-source policy selection chamber; only the chamber-selected green path crosses a separate forwarding installation gate.

CASE FILE

The Candidate Path Reached BGP. The Forwarding Plane Had Not Voted: RFC 9830

A controller advertises two Segment Routing candidate paths to a headend. Both arrive over valid BGP sessions. One wins BGP's comparison for its advertisement; the other remains a distinct route because its Distinguisher differs. Neither fact says which candidate the SR Policy…

Sep 5, 2026
An empty conference archive desk where session recordings pass through a selection junction into a public collection.

AFNOG

AIS 2026 Promises Selected Recordings Without Naming the Selector

AIS 2026 is presented as a hybrid summit whose virtual entities will receive live-streamed sessions, interactive discussions and access to selected recordings. The word “selected” creates a governance question: who decides which sessions become part of the accessible record…

Sep 5, 2026
A drone broadcasts an identifier into a layered DNS delegation and cryptographic certificate chain.

IETF

When a Drone ID Becomes a DNS Delegation: RFC 9886 and the Registry Chain Behind Remote ID

A Broadcast Remote ID can carry a compact DRIP Entity Tag (DET), while the public evidence needed to authenticate registry inclusion is distributed across reverse-DNS delegations, HHIT and BRID records, and a certificate chain. The practical question is therefore not only whether…

Sep 5, 2026
An early-1990s mail workstation decodes one message into layered file, permission and dormant command forms, all stopped by a separate red local-approval barrier.

History

The Header Described an Archive. It Did Not Authorize the Decoder to Run It: RFC 1505

The line counts agree. The archive expands. The checksum closes. A shell command now waits in a directory created from an email message. In 1993, RFC 1505 drew the most important boundary at exactly this point: successful decoding was not permission to execute.

Sep 5, 2026
Editorial portrait of Karthick Thangavel against a fiber-network operations backdrop

Leaders

Karthick Thangavel and the Network Work Hidden Beneath India’s Broadband Growth

Every AI answer, streamed match and digital payment begins with a less glamorous event: somebody surveyed a route, joined a fibre, configured an access device and stayed available when the link failed. Karthick Thangavel’s public record is useful because it keeps that operating…

Sep 5, 2026
Editorial illustration of anonymous African Internet community participants discussing a survey around a table.

Story

AFRINIC Invited Members and Stakeholders to a Survey. Results-Publication Status Is Unknown in the Frozen Source Set

AFRINIC published a survey invitation to members and stakeholders, but the frozen source set does not establish whether results were published or what decisions followed.

Sep 5, 2026
A sealed message leaves a challenge vault but only the complete upper path crosses separate custody beacons, list distribution, identity transformation, signing, certificate rollover and outbound relays to a distant mailbox.

CASE FILE

The Challenge Released the Message. It Still Had Not Reached the List

The IETF plans to replace the machinery behind its email services on 11 September. The design usefully separates challenges, list handling, identity rewriting, signing and outbound transport. It also makes the central operating question unavoidable: when one component reports…

Sep 5, 2026
A broad ROA authorization tree is separated from a smaller set of selected operational network routes by layered evidence checks.

Number Resource Society

A ROA maxLength Is Not a Traffic-Engineering Policy

A route can be RPKI Valid because a ROA’s maxLength admits its prefix length. That result proves a bounded origin authorization. It does not prove that the more-specific route was planned, approved, currently announced or preferred by the operator. Those are separate facts, and…

Sep 5, 2026
Luminous IPv6 prefix blocks pass through transparent policy gates from a Latin America and Caribbean map into an orderly network grid.

Story

LACNIC’s IPv6 allocation rules make scale plannable

**BTW analysis:** IPv6 offers a vast address space, but abundance alone does not tell a network operator what it may request, how need will be assessed, or what obligations follow an allocation. In Latin America and the Caribbean, those practical questions meet LACNIC’s published…

Sep 5, 2026
Matching IS-IS TLV modules are reassembled into a complete topology by one router while a legacy path retains only one part and produces an incomplete view.

IETF

When 255 Octets Stop Being Enough: RFC 9885 and Multi-Part IS-IS TLVs

A syntactically valid IS-IS LSP can leave a receiver with an incomplete entity when information crosses the 255-octet limit and the receiver processes only one TLV occurrence. RFC 9885 defines how to recognize and process those related occurrences without changing the underlying…

Sep 5, 2026
Two abstract revocation-list capsules approach a signed manifest plane; the larger amber counter stops while a cyan hash-matched object and independent certificate reference converge before separate validation and routing gates.

CASE FILE

The CRL Number Was Higher. RPKI Still Had to Ignore It: RFC 9829

A relying party retrieves two signed revocation lists from one publication point. The first carries the larger CRL Number. The second is the file named by the certificate and hashed on the issuer’s current manifest. A generic PKI instinct says to trust the larger counter. RFC…

Sep 5, 2026
AI editorial portrait of Artem Izbaenkov against an abstract Internet routing network

Leaders

Artem Izbaenkov and the Cost of Representation at RIPE NCC

Artem Izbaenkov’s 2024 campaign for a seat on the RIPE NCC Executive Board turned an operator’s career in DDoS defence and cloud security into a wider argument about who can participate effectively in registry governance—and what language, fees and institutional attention have to…

Sep 5, 2026
A visible criteria checklist leads toward a committee table behind translucent procedural layers.

AFNOG

AfNOG Publishes Fellowship Criteria, Not the Procedure That Applies Them

AfNOG’s published Abha Ahuja Bursary application page tells candidates what the fellowship is looking for. It identifies a selecting committee, lists eligibility criteria and says incomplete applications will not be considered. The reviewed page does not set out how those…

Sep 5, 2026
Five independently marked record streams meet a neutral cyan correlation lattice while an empty gap and amber conflict remain visible beside separate effect and outcome witnesses.

CASE FILE

The Trace Linked the Action. It Did Not Prove the Authority

A new IETF discussion list asks how an agent’s intent, delegation, changing permissions and external actions can be followed across services. The hard part is not inventing a universal trace identifier. It is preventing that identifier—and the agent’s own account of events—from…

Sep 5, 2026
Layered routing-security illustration separating a BGPsec router certificate and signing key from prefix-origin authorization and observed route paths.

Number Resource Society

A BGPsec Router Certificate Is Not Route-Origin Authority

A BGPsec Router Certificate Is Not Route-Origin Authority intelligence summary explains the development, the public evidence available to readers, the organisations involved, the regional context, market exposure, and the infrastructure consequences that may follow. The Number…

Sep 5, 2026