Skip to main content

Intelligence

Latest Articles

Latest intelligence on infrastructure operators, policy decisions, market moves, and digital power shifts.

A wide cyan data stream enters layered transport and host gates, but only a few amber units reach the nearly empty transparent application buffer beside timing instruments.

History

The Network Had Bandwidth. The Application Was Still Starving: RFC 1453

A fast network can be perfectly real and completely irrelevant to the frozen face on a conference screen. In 1993, RFC 1453 located that contradiction inside the machine: capacity had reached the link, perhaps even the transport, while buffers, operating-system paths and…

Sep 4, 2026
An abstract power-conversion core faces an amber temporary bridge, two unfinished steel rails and a distant separation gate in a dark industrial landscape.

Global Datacenter Trends

Flex Has a $4.4bn Bridge for a $4.4bn Deal, Not SpinCo’s Final Balance Sheet

The acquisition price, the temporary funding ceiling and the planned separation sit on three different clocks. Investors still need the permanent financing and allocation record that connects them.

Sep 4, 2026
Rohan Mahy in an editorial portrait before abstract certificate-chain and message-routing lights.

IETF

Rohan Mahy and the Certificate Purpose That Did Not Deliver an Instant Message

An IM certificate can say that a key is meant for an instant-messaging identity. That narrower purpose is useful security design. It does not say that an application submitted a message, that a service accepted it, or that any person received and read it.

Sep 4, 2026
Neil Jenkins in an editorial portrait against a fictional, defocused interoperability-engineering setting.

IETF

Neil Jenkins and the StateChange That Did Not Audit a Mailbox

A JMAP client that sees a new state string has learned something important: its local view may no longer match the server. That is a signal to synchronize. It is not, by itself, a record of which message changed, which mailbox moved, which principal made a request, which policy…

Sep 4, 2026
A signature certificate sends an assurance statement toward a separate key-establishment request while the second private key remains isolated in secure hardware and derived certificates branch below.

IETF

A Signature Is Not Proof of the Other Key: RFC 9883 and Private-Key Possession Statements

A second certificate request can be validly signed by an already certified signature key, yet that signature is only an assertion—not technical proof—that the requester controls the different private key behind the requested key-establishment certificate. RFC 9883 defines how a…

Sep 4, 2026
A red reset packet lands inside a TCP receive window while an amber challenge acknowledgment travels back and the blue connection remains intact.

History

The Packet That Had to Answer Back: TCP's Challenge ACK Repair

TCP once treated a reset that landed anywhere inside the receive window as sufficiently believable to tear down a connection. RFC 5961 replaced that destructive shortcut with a narrower rule: exact sequence alignment could act immediately; merely plausible input had to survive a…

Sep 4, 2026
Two amber transmissions of the same TCP sequence range lead to an ambiguous ACK, while a separate cyan exchange provides a clean RTT measurement.

History

The ACK That Could Not Say Which Packet Arrived: Karn's Retransmission Ambiguity Rule

The same sequence range crossed the network twice. The acknowledgment that returned proved the bytes had arrived, but not which transmission had earned the reply. Karn's rule turned that uncertainty into a discipline: delivery evidence could advance while the round-trip estimator…

Sep 4, 2026
A signed contact object branches into separate checks for channel reachability, human acknowledgement, authority and escalation, with one failed path.

Number Resource Society

A Ghostbusters Record Is Not an Incident Command Roster

An RPKI relying party can validate every byte of a Ghostbusters Record and still not know whether anyone is watching the listed channel when action is needed. The signed entity solves discovery of minimal CA-maintainer contact data; operational accountability begins where that…

Sep 4, 2026
Two CMS byte paths, raw content and encoded signed attributes, converge on an ML-DSA lattice before entering an HSM.

IETF

The Signature Algorithm Is Not the Signed Byte Sequence: RFC 9882 and ML-DSA in CMS

Two CMS systems choose ML-DSA-65 for identical content, yet verification fails when one signs a final implicit-tag representation and the other verifies the complete DER SignedAttrs value with its explicit SET OF tag. The algorithm is the same; the signed byte domain is not.

Sep 4, 2026
Editorial illustration of two anonymous council candidates, a ballot box, term-length cards and a laptop showing a broken-link symbol against an African network map.

Story

AFRINIC Deemed Two NRO NC/ASO AC Candidates Elected Unopposed. Its Linked 2026 Rulebook Now Returns 404

AFRINIC’s final 2026 candidate slate said Stephen Musa Honlue and Nitin Kelawon Sookun would be deemed elected unopposed to the NRO NC/ASO AC, while voting would still decide the duration of their terms. The Election Guidelines page linked as the basis for that procedure returned…

Sep 4, 2026
Current and successor RPKI trust-anchor keys connected by reciprocal verification, with validators adopting the successor in stages and a separate legacy TAL path.

Number Resource Society

A Trust Anchor Rollover Needs an Acceptance Ledger

An RPKI trust-anchor operator can publish a successor key without making every relying party ready to use it. The transition is a sequence of verified observations, not a launch date: a defensible record must show what was announced, what remained stable, which validators crossed…

Sep 4, 2026
One short TCP segment travels toward the receiver while later byte blocks wait behind a gate for an ACK or a full segment.

History

The Packet That Waited for Its Predecessor: Nagle's Small-Segment Rule

A one-byte write did not need a universal delay timer. It needed a rule about whether the connection already had data in flight. Nagle's answer made acknowledgment state—not the wall clock—the gate for another short TCP segment.

Sep 4, 2026
A crystalline certificate sends three distinct algorithm-identity paths toward lattice signatures, with an empty parameter field and tagged private-key branches.

IETF

The Algorithm Name Is Not the Certificate Profile: RFC 9881 and ML-DSA in PKIX

The Algorithm Name Is Not the Certificate Profile: RFC 9881 and ML-DSA in PKIX intelligence summary explains the development, the public evidence available to readers, the organisations involved, the regional context, market exposure, and the infrastructure consequences that may…

Sep 4, 2026
A public rules panel connects to a partially obscured moderation decision room.

AFNOG

AfNOG Publishes Mailing-List Rules, Not the Moderation Procedure Behind Them

AfNOG’s mailing-list page sets clear expectations for a technical community: keep discussion operational, avoid disrespect, and do not use the list for blatant product marketing. The published page establishes the rules. It does not explain the procedure used when a post is…

Sep 4, 2026
A signed RPKI object set moves from a commit chamber through manifest and RRDP layers to independent observation nodes.

Number Resource Society

An RPKI Publication Point Needs a Commit-to-Visibility Ledger

An RPKI publication server can accept an authenticated update atomically while relying parties still hold an earlier repository view. That is not necessarily a contradiction or a failure. It is a boundary between different authorities, protocols and observation times. A useful…

Sep 4, 2026
A registry ledger sends a configured DNS TTL into an operations view while separate cache clocks count down across authoritative servers.

IETF

A Registry TTL Is Policy State, Not a Live DNS Observation

RFC 10037 lets a registry publish configured DNS time-to-live values through RDAP. That sounds like a small JSON extension. Its more important effect is to expose a piece of registry policy without pretending that a registration-data service is watching the live DNS. The…

Sep 4, 2026
One semantic Thing model feeds two different protocol-binding implementations, illustrating that shared SDF meaning does not define wire behavior.

IETF

A Data Model Is Not a Wire Contract: RFC 9880 and SDF Protocol-Binding Boundaries

Two implementations can claim the same Thing model yet disagree on the wire: one chooses a URL and JSON payload convention, while the other expects a numeric identifier and different invocation rules. The gap appears when a protocol binding was implicit rather than versioned and…

Sep 4, 2026
Two idle TCP endpoints exchange a keep-alive probe, while a fading return pulse shows that one missing acknowledgment cannot prove failure.

History

The Probe That Could Not Declare an Idle Peer Dead: TCP Keep-Alives

An idle TCP connection can be quiet without being broken. Keep-alive probing was designed to ask whether the peer's transport state could still answer, while denying any single unanswered probe the authority to declare that state dead.

Sep 4, 2026
Two distinct cryptographic streams converge through an SSH negotiation gateway into one session key, with server authentication remaining separate.

IETF

A Hybrid SSH Key Exchange Turns Algorithm Negotiation into a Migration Boundary

Installing post-quantum code does not mean an SSH session used it. RFC 10042 defines three hybrid methods that combine ML-KEM with an established elliptic-curve exchange. The protection becomes real only when both peers offer the same method, negotiation selects it, both…

Sep 4, 2026
AI editorial portrait of Prasad Vadke in an enterprise communications operations setting

Leaders

Prasad Vadke and the Escalation Clock Behind Enterprise Email

An enterprise email incident starts two clocks at once. One measures the technical work of diagnosis and recovery. The other measures missed decisions, interrupted meetings and the widening cost of uncertainty. Prasad Vadke's public writing on service-level agreements is most…

Sep 4, 2026