Skip to main content

Intelligence

Latest Articles

Latest intelligence on infrastructure operators, policy decisions, market moves, and digital power shifts.

A visible criteria checklist leads toward a committee table behind translucent procedural layers.

AFNOG

AfNOG Publishes Fellowship Criteria, Not the Procedure That Applies Them

AfNOG’s published Abha Ahuja Bursary application page tells candidates what the fellowship is looking for. It identifies a selecting committee, lists eligibility criteria and says incomplete applications will not be considered. The reviewed page does not set out how those…

Sep 5, 2026
Five independently marked record streams meet a neutral cyan correlation lattice while an empty gap and amber conflict remain visible beside separate effect and outcome witnesses.

CASE FILE

The Trace Linked the Action. It Did Not Prove the Authority

A new IETF discussion list asks how an agent’s intent, delegation, changing permissions and external actions can be followed across services. The hard part is not inventing a universal trace identifier. It is preventing that identifier—and the agent’s own account of events—from…

Sep 5, 2026
Layered routing-security illustration separating a BGPsec router certificate and signing key from prefix-origin authorization and observed route paths.

Number Resource Society

A BGPsec Router Certificate Is Not Route-Origin Authority

A BGPsec Router Certificate Is Not Route-Origin Authority intelligence summary explains the development, the public evidence available to readers, the organisations involved, the regional context, market exposure, and the infrastructure consequences that may follow. The Number…

Sep 5, 2026
A single early-1990s computer network enters a remapping gateway, loops back by a redundant cable and appears as several translucent route-table shadows.

History

The Router Saw a New Network. It Was a Shadow of Its Own Mapping: RFC 1504

The route looked newly learned and the number was locally valid. The awkward fact was that no second network had appeared. A number invented at one translation boundary had travelled around a redundant path, lost its lineage and returned as if it belonged to a stranger.

Sep 5, 2026
Two routers exchange blue and amber authenticated TCP segments while old and new key states remain visible at both ends during rollover.

History

The Key That Could Change Mid-Connection: TCP-AO's Rollover Signal

Long-lived routing sessions made a simple operational question unusually dangerous: how can two endpoints replace an authentication key without dropping the TCP connection or guessing the same switching instant? TCP-AO answered with visible key identifiers and directional…

Sep 5, 2026
A local DNS resolver mirrors the signed root zone and switches to global roots as its freshness clock expires.

IETF

A Local Root Makes DNS Resilience an Operator-Controlled Failover Decision

RFC 8806 lets a recursive resolver answer root-zone questions from a complete local copy. The design can reduce dependence on a reachable remote root server and keep root queries off intervening networks. It also moves a consequential decision inside the operator’s own system…

Sep 5, 2026
Four ordered geometric tag tokens split into full-capacity and two-token limited-capacity router chambers, while separate aggregation, ECMP and policy paths preserve the provenance boundaries.

CASE FILE

The Tag List Kept Its Order. It Still Lost Part of the Policy: RFC 9825

Four administrative tags left an OSPF area in the intended order. The next router supported only two. Its log said the list had been preserved; its policy engine therefore looked healthy. Yet the action-bearing tag had occupied the third position. No field was reordered, no…

Sep 5, 2026
An MPLS label reaches the egress while LSP Ping separately compares SR Policy, candidate-path and segment-list identity, showing one aligned result and one reachable but mismatched result.

IETF

The Label Arrived, but Did It Reach the Right Path? RFC 9884 and PSID Validation

A label can arrive at the intended egress and be popped there, yet still be associated with the wrong SR Policy, candidate path, or segment list. RFC 9884 makes that control-plane correlation testable with LSP Ping instead of treating reachability as proof of path identity.

Sep 5, 2026
A blank bound report sits apart from translucent observation markers and layered network paths, with a small gap in the connecting line.

Story

LACNIC’s 2025 Path Study Does Not Date Its Measurements

A year in a report title tells readers when an edition belongs on the shelf. It does not tell a network operator when the packets behind its charts crossed the wire. LACNIC’s regional path study offers a useful view of routes and latency, but leaves that second clock unstated.

Sep 5, 2026
A cyan candidate tool-call stream meets a narrow argument-comparison gate while a separate amber authorization path arrives from above and a receipt trail returns below.

CASE FILE

The Token Authorized the Tool. It Did Not Authorize These Arguments

OAuth can establish that an agent may call a payment, messaging or infrastructure tool. The dangerous decision comes one layer later: whether the exact destination, amount, command and live form state produced by the model are the act a principal or governed policy approved. An…

Sep 5, 2026
Two distinct vintage electronic channels deliver blank response cards into a partly filled transparent ledger, followed by an incomplete circle of empty seats and a separate closed decision console across a gap.

History

The RFC Published a Straw Poll. It Did Not Create a Constituency: RFC 1501

Two electronic addresses at the end of a two-page RFC offered individual OS/2 users a way to be counted. They were doors into a proposed organisation, not proof that the people behind those doors had already become members, chosen representatives or moved IBM.

Sep 5, 2026
A neutral DNS header ring floats above a cyan signed absence chamber; capability relays split into different downstream presentations while repeated queries return to a bounded signing chamber.

CASE FILE

The Header Said NOERROR. The Signed Body Said the Name Did Not Exist: RFC 9824

A security pipeline closed a nonexistent-domain alert because the DNS header said `NOERROR`. The validating resolver had reached the opposite conclusion from the signed NSEC evidence: the queried name did not exist. Neither observation was fabricated. One component had read the…

Sep 5, 2026
Two redundant service-record proxies carry an amber stale copy and a cyan current update into a neutral recency gate, followed by a separate service-verification chamber.

CASE FILE

The Older Service Record Won. The Service Had Already Moved

A name collision is supposed to stop a newcomer from impersonating an established local service. Put two registration proxies between the service and that local link, however, and the same safeguard can protect yesterday’s address from today’s legitimate update. DNSSD’s proposed…

Sep 5, 2026
An abstract sealed message capsule passes through an early gateway while some geometric meaning tokens continue, one branch ends in an empty tray, and the wrapped object reaches a separate local handling station.

History

The Gateway Kept the Message. It Could Not Preserve Every Meaning: RFC 1496

RFC 1496 gave an X.400(84)–MIME gateway an admirably stubborn rule: convert what it can, encapsulate what it cannot, and never discard an entire message merely because one body part is unfamiliar. That discipline protected the carrier. It did not make every heading survive, every…

Sep 5, 2026
An amber archival corridor and a blue structured corridor face each other across a narrow luminous bridge in a dark registry chamber.

Story

ARIN’s IRR Objects Keep the Channel That Created Them

An IRR object migrated from ARIN’s email service can be deleted in ARIN Online but not edited there. The asymmetry is defensible as a record of provenance. The trouble begins when the web remedy—delete and recreate—changes that provenance without a visible continuity receipt.

Sep 5, 2026
A constrained peer and authenticator exchange two separate protected messages between matched derived-context chambers; disposable resource gates, a separate policy branch, overlapping old and new state, and a deletion acknowledgement show that method success is not authority.

CASE FILE

The EAP Method Succeeded. The Protected Session Still Needed a Second Witness: RFC 9820

The access controller displayed three green facts: the EAP method had succeeded, the Master Session Key had been exported, and the constrained device had been placed in the security domain. Only the first two facts could be reconstructed. No one could produce the protected…

Sep 5, 2026
Three crystalline ML-KEM modules pass through registry apertures toward a neutral recommendation plane, while a separate operator switchyard and canary remain downstream.

CASE FILE

The IESG Approved Three ML-KEM Groups. The Registry Recommended None

An approved IETF document can define exactly how three post-quantum groups travel through TLS while leaving the deployment verdict deliberately unresolved. That is not bureaucratic ambiguity. It is a precise boundary between an interoperable mechanism, a registry coordinate and…

Sep 5, 2026
A fixed brass service token sits beside two computing cabinets while a movable module selects one cabinet; separate sockets feed a routing board with one amber path and several cyan alternatives.

History

The Table Moved the Service. It Did Not Rename It: RFC 1498

A 1993 RFC recovered an older lesson: a table can change where a service runs while its name survives. Reaching it still requires separate evidence for the node, attachment point and path—and none of those bindings alone proves identity, authority or delivery.

Sep 5, 2026
A sealed archival chamber stands apart from a running early network mechanism, an incomplete translucent reconstruction, a correlation loop, a local decision machine, a terminal gate and a distant endpoint.

History

The Code Was Available. The Original Specification Was Not: RFC 1492

The original TACACS specification existed, and the author of RFC 1492 could not obtain it because of copyright issues. What reached the public record in July 1993 was therefore an Informational reconstruction, constrained by running code and candid about the possibility that the…

Sep 5, 2026
A bounded program chamber inside a programmable network device links an authorization token and artifact fingerprint to finite resources, instance state, output, independent override, rollback and quarantined residue.

CASE FILE

The Switch Executed the Program. It Did Not Inherit the Right to Read, Rewrite or Decide: RFC 9817

A program that runs inside a switch or network interface card is no longer merely near the traffic. It can become part of the path by which traffic is classified, transformed, delayed, replicated or converted into a control action. RFC 9817 catalogs the opportunity and, more…

Sep 5, 2026