Skip to main content

Intelligence

Latest Articles

Latest intelligence on infrastructure operators, policy decisions, market moves, and digital power shifts.

Current and successor RPKI trust-anchor keys connected by reciprocal verification, with validators adopting the successor in stages and a separate legacy TAL path.

Number Resource Society

A Trust Anchor Rollover Needs an Acceptance Ledger

An RPKI trust-anchor operator can publish a successor key without making every relying party ready to use it. The transition is a sequence of verified observations, not a launch date: a defensible record must show what was announced, what remained stable, which validators crossed…

Sep 4, 2026
One short TCP segment travels toward the receiver while later byte blocks wait behind a gate for an ACK or a full segment.

History

The Packet That Waited for Its Predecessor: Nagle's Small-Segment Rule

A one-byte write did not need a universal delay timer. It needed a rule about whether the connection already had data in flight. Nagle's answer made acknowledgment state—not the wall clock—the gate for another short TCP segment.

Sep 4, 2026
A crystalline certificate sends three distinct algorithm-identity paths toward lattice signatures, with an empty parameter field and tagged private-key branches.

IETF

The Algorithm Name Is Not the Certificate Profile: RFC 9881 and ML-DSA in PKIX

The Algorithm Name Is Not the Certificate Profile: RFC 9881 and ML-DSA in PKIX intelligence summary explains the development, the public evidence available to readers, the organisations involved, the regional context, market exposure, and the infrastructure consequences that may…

Sep 4, 2026
A public rules panel connects to a partially obscured moderation decision room.

AFNOG

AfNOG Publishes Mailing-List Rules, Not the Moderation Procedure Behind Them

AfNOG’s mailing-list page sets clear expectations for a technical community: keep discussion operational, avoid disrespect, and do not use the list for blatant product marketing. The published page establishes the rules. It does not explain the procedure used when a post is…

Sep 4, 2026
A signed RPKI object set moves from a commit chamber through manifest and RRDP layers to independent observation nodes.

Number Resource Society

An RPKI Publication Point Needs a Commit-to-Visibility Ledger

An RPKI publication server can accept an authenticated update atomically while relying parties still hold an earlier repository view. That is not necessarily a contradiction or a failure. It is a boundary between different authorities, protocols and observation times. A useful…

Sep 4, 2026
A registry ledger sends a configured DNS TTL into an operations view while separate cache clocks count down across authoritative servers.

IETF

A Registry TTL Is Policy State, Not a Live DNS Observation

RFC 10037 lets a registry publish configured DNS time-to-live values through RDAP. That sounds like a small JSON extension. Its more important effect is to expose a piece of registry policy without pretending that a registration-data service is watching the live DNS. The…

Sep 4, 2026
One semantic Thing model feeds two different protocol-binding implementations, illustrating that shared SDF meaning does not define wire behavior.

IETF

A Data Model Is Not a Wire Contract: RFC 9880 and SDF Protocol-Binding Boundaries

Two implementations can claim the same Thing model yet disagree on the wire: one chooses a URL and JSON payload convention, while the other expects a numeric identifier and different invocation rules. The gap appears when a protocol binding was implicit rather than versioned and…

Sep 4, 2026
Two idle TCP endpoints exchange a keep-alive probe, while a fading return pulse shows that one missing acknowledgment cannot prove failure.

History

The Probe That Could Not Declare an Idle Peer Dead: TCP Keep-Alives

An idle TCP connection can be quiet without being broken. Keep-alive probing was designed to ask whether the peer's transport state could still answer, while denying any single unanswered probe the authority to declare that state dead.

Sep 4, 2026
Two distinct cryptographic streams converge through an SSH negotiation gateway into one session key, with server authentication remaining separate.

IETF

A Hybrid SSH Key Exchange Turns Algorithm Negotiation into a Migration Boundary

Installing post-quantum code does not mean an SSH session used it. RFC 10042 defines three hybrid methods that combine ML-KEM with an established elliptic-curve exchange. The protection becomes real only when both peers offer the same method, negotiation selects it, both…

Sep 4, 2026
AI editorial portrait of Prasad Vadke in an enterprise communications operations setting

Leaders

Prasad Vadke and the Escalation Clock Behind Enterprise Email

An enterprise email incident starts two clocks at once. One measures the technical work of diagnosis and recovery. The other measures missed decisions, interrupted meetings and the widening cost of uncertainty. Prasad Vadke's public writing on service-level agreements is most…

Sep 4, 2026
A certificate container is protected by two nested parameter rings for password-based key derivation and message authentication.

IETF

The Integrity Check Has Its Own Parameters: RFC 9879 and PBMAC1 in PKCS #12

A PKCS #12 exchange can fail at the integrity boundary when one implementation reads compatibility-shaped legacy fields while another follows PBMAC1’s nested parameters. The two sides can then disagree about the password-derived key, the MAC scheme, or the authenticated bytes.

Sep 4, 2026
Tiered sponsor plaques stand behind a translucent boundary from presentation cards under review.

IDNOG

IDNOG Publishes Sponsorship Tiers and Talk Review, Not the Boundary Between Them

IDNOG’s public record shows two systems around the same conference. One groups commercial supporters into named sponsorship tiers. The other assigns presentation review to a volunteer Programme Committee. What the reviewed material does not show is the rule separating those…

Sep 4, 2026
A luminous routing-identity token crosses between two control stations above a layered evidence ledger.

Number Resource Society

An ASN Transfer Needs a Routing-Identity Handover Ledger

An ASN Transfer Needs a Routing-Identity Handover Ledger intelligence summary explains the development, the public evidence available to readers, the organisations involved, the regional context, market exposure, and the infrastructure consequences that may follow. The Number…

Sep 4, 2026
Two TCP segments approach a timed receiver gate, which releases one cumulative acknowledgment after the second segment arrives.

History

The Acknowledgment That Waited for a Second Segment: TCP Delayed ACKs

TCP does not always answer one received data segment with one immediate acknowledgment. The receiver may wait briefly, but that silence is governed by a second-segment threshold, a timer, and exceptions that preserve loss evidence.

Sep 4, 2026
Conceptual illustration of QNAME minimisation as a bounded DNS query sequence across delegation and cache states.

IETF

QNAME Minimisation Is a Query-Sequence Contract, Not a Privacy Switch

A resolver may advertise QNAME minimisation while exposing very different names, costs and failure modes from one lookup to the next. The feature matters only when operators can reconstruct the bounded sequence produced by delegation knowledge, cache state and negative proofs.

Sep 4, 2026
A structured SRv6 locator passes through a lease clock into a routing graph, with one route withdrawing.

IETF

An SRv6 Locator Lease Makes DHCPv6 Part of the Routing Control Plane

An SRv6 locator is the address-space foundation from which a segment endpoint creates SIDs. RFC 10038 allows that foundation to arrive as a DHCPv6 lease. The convenience is real, but so is the transfer of authority: pool selection, lease renewal, route installation and withdrawal…

Sep 4, 2026
A SIP policy matrix allows or rejects protected P-Header tokens according to message context at a trust boundary.

IETF

A Header Allowed Here Is Not Trusted Everywhere: RFC 9878 and SIP P-Header Scope

A call can fail at the trust boundary when a sender puts a P-Header in a SIP message that its receiver believes must not contain it. One implementation strips the field, another rejects the message, and a third accepts it. The disagreement can affect charging context…

Sep 4, 2026
An abstract glass registry record in a federal-court setting, crossed by fine global network lines.

CASE FILE

The Registrant Was Abroad; the Dot-Com Registry Was in Virginia: CNN v CNNews.com

The Registrant Was Abroad; the Dot-Com Registry Was in Virginia: CNN v CNNews.com intelligence summary explains the development, the public evidence available to readers, the organisations involved, the regional context, market exposure, and the infrastructure consequences that…

Sep 4, 2026
A phone connection moves from Wi-Fi to a mobile network while opaque QUIC tokens continue toward one application endpoint.

Global Cloud Services Trends

A QUIC Connection ID Is Not a Subscriber Identity

A QUIC connection can survive a change from Wi-Fi to mobile access. The identifier that helps packets find that connection is transport state, not proof of who holds the handset, which account is active, or whether an application action remains authorised.

Sep 4, 2026
An RDAP registry gateway links a bounded IP prefix to a geofeed while rejecting an out-of-range record.

IETF

The Link Is Not the Location: RFC 9877 and RDAP Geofeed Control

A geofeed link tells a client where to look; it does not turn every location claim in that file into verified truth. RFC 9877 makes RDAP a scoped discovery and authority signal, with controls that keep lookup scope, freshness, authenticity and privacy separate.

Sep 4, 2026