Intelligence
Latest Articles
Latest intelligence on infrastructure operators, policy decisions, market moves, and digital power shifts.

Number Resource Society
A Trust Anchor Rollover Needs an Acceptance Ledger
An RPKI trust-anchor operator can publish a successor key without making every relying party ready to use it. The transition is a sequence of verified observations, not a launch date: a defensible record must show what was announced, what remained stable, which validators crossed…

History
The Packet That Waited for Its Predecessor: Nagle's Small-Segment Rule
A one-byte write did not need a universal delay timer. It needed a rule about whether the connection already had data in flight. Nagle's answer made acknowledgment state—not the wall clock—the gate for another short TCP segment.

IETF
The Algorithm Name Is Not the Certificate Profile: RFC 9881 and ML-DSA in PKIX
The Algorithm Name Is Not the Certificate Profile: RFC 9881 and ML-DSA in PKIX intelligence summary explains the development, the public evidence available to readers, the organisations involved, the regional context, market exposure, and the infrastructure consequences that may…

AFNOG
AfNOG Publishes Mailing-List Rules, Not the Moderation Procedure Behind Them
AfNOG’s mailing-list page sets clear expectations for a technical community: keep discussion operational, avoid disrespect, and do not use the list for blatant product marketing. The published page establishes the rules. It does not explain the procedure used when a post is…

Number Resource Society
An RPKI Publication Point Needs a Commit-to-Visibility Ledger
An RPKI publication server can accept an authenticated update atomically while relying parties still hold an earlier repository view. That is not necessarily a contradiction or a failure. It is a boundary between different authorities, protocols and observation times. A useful…

IETF
A Registry TTL Is Policy State, Not a Live DNS Observation
RFC 10037 lets a registry publish configured DNS time-to-live values through RDAP. That sounds like a small JSON extension. Its more important effect is to expose a piece of registry policy without pretending that a registration-data service is watching the live DNS. The…

IETF
A Data Model Is Not a Wire Contract: RFC 9880 and SDF Protocol-Binding Boundaries
Two implementations can claim the same Thing model yet disagree on the wire: one chooses a URL and JSON payload convention, while the other expects a numeric identifier and different invocation rules. The gap appears when a protocol binding was implicit rather than versioned and…

History
The Probe That Could Not Declare an Idle Peer Dead: TCP Keep-Alives
An idle TCP connection can be quiet without being broken. Keep-alive probing was designed to ask whether the peer's transport state could still answer, while denying any single unanswered probe the authority to declare that state dead.

IETF
A Hybrid SSH Key Exchange Turns Algorithm Negotiation into a Migration Boundary
Installing post-quantum code does not mean an SSH session used it. RFC 10042 defines three hybrid methods that combine ML-KEM with an established elliptic-curve exchange. The protection becomes real only when both peers offer the same method, negotiation selects it, both…

Leaders
Prasad Vadke and the Escalation Clock Behind Enterprise Email
An enterprise email incident starts two clocks at once. One measures the technical work of diagnosis and recovery. The other measures missed decisions, interrupted meetings and the widening cost of uncertainty. Prasad Vadke's public writing on service-level agreements is most…

IETF
The Integrity Check Has Its Own Parameters: RFC 9879 and PBMAC1 in PKCS #12
A PKCS #12 exchange can fail at the integrity boundary when one implementation reads compatibility-shaped legacy fields while another follows PBMAC1’s nested parameters. The two sides can then disagree about the password-derived key, the MAC scheme, or the authenticated bytes.

IDNOG
IDNOG Publishes Sponsorship Tiers and Talk Review, Not the Boundary Between Them
IDNOG’s public record shows two systems around the same conference. One groups commercial supporters into named sponsorship tiers. The other assigns presentation review to a volunteer Programme Committee. What the reviewed material does not show is the rule separating those…

Number Resource Society
An ASN Transfer Needs a Routing-Identity Handover Ledger
An ASN Transfer Needs a Routing-Identity Handover Ledger intelligence summary explains the development, the public evidence available to readers, the organisations involved, the regional context, market exposure, and the infrastructure consequences that may follow. The Number…

History
The Acknowledgment That Waited for a Second Segment: TCP Delayed ACKs
TCP does not always answer one received data segment with one immediate acknowledgment. The receiver may wait briefly, but that silence is governed by a second-segment threshold, a timer, and exceptions that preserve loss evidence.

IETF
QNAME Minimisation Is a Query-Sequence Contract, Not a Privacy Switch
A resolver may advertise QNAME minimisation while exposing very different names, costs and failure modes from one lookup to the next. The feature matters only when operators can reconstruct the bounded sequence produced by delegation knowledge, cache state and negative proofs.

IETF
An SRv6 Locator Lease Makes DHCPv6 Part of the Routing Control Plane
An SRv6 locator is the address-space foundation from which a segment endpoint creates SIDs. RFC 10038 allows that foundation to arrive as a DHCPv6 lease. The convenience is real, but so is the transfer of authority: pool selection, lease renewal, route installation and withdrawal…

IETF
A Header Allowed Here Is Not Trusted Everywhere: RFC 9878 and SIP P-Header Scope
A call can fail at the trust boundary when a sender puts a P-Header in a SIP message that its receiver believes must not contain it. One implementation strips the field, another rejects the message, and a third accepts it. The disagreement can affect charging context…

CASE FILE
The Registrant Was Abroad; the Dot-Com Registry Was in Virginia: CNN v CNNews.com
The Registrant Was Abroad; the Dot-Com Registry Was in Virginia: CNN v CNNews.com intelligence summary explains the development, the public evidence available to readers, the organisations involved, the regional context, market exposure, and the infrastructure consequences that…

Global Cloud Services Trends
A QUIC Connection ID Is Not a Subscriber Identity
A QUIC connection can survive a change from Wi-Fi to mobile access. The identifier that helps packets find that connection is transport state, not proof of who holds the handset, which account is active, or whether an application action remains authorised.

IETF
The Link Is Not the Location: RFC 9877 and RDAP Geofeed Control
A geofeed link tells a client where to look; it does not turn every location claim in that file into verified truth. RFC 9877 makes RDAP a scoped discovery and authority signal, with controls that keep lookup scope, freshness, authenticity and privacy separate.
