Skip to main content

Intelligence

Latest Articles

Latest intelligence on infrastructure operators, policy decisions, market moves, and digital power shifts.

Two idle TCP endpoints exchange a keep-alive probe, while a fading return pulse shows that one missing acknowledgment cannot prove failure.

History

The Probe That Could Not Declare an Idle Peer Dead: TCP Keep-Alives

An idle TCP connection can be quiet without being broken. Keep-alive probing was designed to ask whether the peer's transport state could still answer, while denying any single unanswered probe the authority to declare that state dead.

Sep 4, 2026
Two distinct cryptographic streams converge through an SSH negotiation gateway into one session key, with server authentication remaining separate.

IETF

A Hybrid SSH Key Exchange Turns Algorithm Negotiation into a Migration Boundary

Installing post-quantum code does not mean an SSH session used it. RFC 10042 defines three hybrid methods that combine ML-KEM with an established elliptic-curve exchange. The protection becomes real only when both peers offer the same method, negotiation selects it, both…

Sep 4, 2026
AI editorial portrait of Prasad Vadke in an enterprise communications operations setting

Leaders

Prasad Vadke and the Escalation Clock Behind Enterprise Email

An enterprise email incident starts two clocks at once. One measures the technical work of diagnosis and recovery. The other measures missed decisions, interrupted meetings and the widening cost of uncertainty. Prasad Vadke's public writing on service-level agreements is most…

Sep 4, 2026
A certificate container is protected by two nested parameter rings for password-based key derivation and message authentication.

IETF

The Integrity Check Has Its Own Parameters: RFC 9879 and PBMAC1 in PKCS #12

A PKCS #12 exchange can fail at the integrity boundary when one implementation reads compatibility-shaped legacy fields while another follows PBMAC1’s nested parameters. The two sides can then disagree about the password-derived key, the MAC scheme, or the authenticated bytes.

Sep 4, 2026
Tiered sponsor plaques stand behind a translucent boundary from presentation cards under review.

IDNOG

IDNOG Publishes Sponsorship Tiers and Talk Review, Not the Boundary Between Them

IDNOG’s public record shows two systems around the same conference. One groups commercial supporters into named sponsorship tiers. The other assigns presentation review to a volunteer Programme Committee. What the reviewed material does not show is the rule separating those…

Sep 4, 2026
A luminous routing-identity token crosses between two control stations above a layered evidence ledger.

Number Resource Society

An ASN Transfer Needs a Routing-Identity Handover Ledger

An ASN Transfer Needs a Routing-Identity Handover Ledger intelligence summary explains the development, the public evidence available to readers, the organisations involved, the regional context, market exposure, and the infrastructure consequences that may follow. The Number…

Sep 4, 2026
Two TCP segments approach a timed receiver gate, which releases one cumulative acknowledgment after the second segment arrives.

History

The Acknowledgment That Waited for a Second Segment: TCP Delayed ACKs

TCP does not always answer one received data segment with one immediate acknowledgment. The receiver may wait briefly, but that silence is governed by a second-segment threshold, a timer, and exceptions that preserve loss evidence.

Sep 4, 2026
Conceptual illustration of QNAME minimisation as a bounded DNS query sequence across delegation and cache states.

IETF

QNAME Minimisation Is a Query-Sequence Contract, Not a Privacy Switch

A resolver may advertise QNAME minimisation while exposing very different names, costs and failure modes from one lookup to the next. The feature matters only when operators can reconstruct the bounded sequence produced by delegation knowledge, cache state and negative proofs.

Sep 4, 2026
A structured SRv6 locator passes through a lease clock into a routing graph, with one route withdrawing.

IETF

An SRv6 Locator Lease Makes DHCPv6 Part of the Routing Control Plane

An SRv6 locator is the address-space foundation from which a segment endpoint creates SIDs. RFC 10038 allows that foundation to arrive as a DHCPv6 lease. The convenience is real, but so is the transfer of authority: pool selection, lease renewal, route installation and withdrawal…

Sep 4, 2026
A SIP policy matrix allows or rejects protected P-Header tokens according to message context at a trust boundary.

IETF

A Header Allowed Here Is Not Trusted Everywhere: RFC 9878 and SIP P-Header Scope

A call can fail at the trust boundary when a sender puts a P-Header in a SIP message that its receiver believes must not contain it. One implementation strips the field, another rejects the message, and a third accepts it. The disagreement can affect charging context…

Sep 4, 2026
An abstract glass registry record in a federal-court setting, crossed by fine global network lines.

CASE FILE

The Registrant Was Abroad; the Dot-Com Registry Was in Virginia: CNN v CNNews.com

The Registrant Was Abroad; the Dot-Com Registry Was in Virginia: CNN v CNNews.com intelligence summary explains the development, the public evidence available to readers, the organisations involved, the regional context, market exposure, and the infrastructure consequences that…

Sep 4, 2026
A phone connection moves from Wi-Fi to a mobile network while opaque QUIC tokens continue toward one application endpoint.

Global Cloud Services Trends

A QUIC Connection ID Is Not a Subscriber Identity

A QUIC connection can survive a change from Wi-Fi to mobile access. The identifier that helps packets find that connection is transport state, not proof of who holds the handset, which account is active, or whether an application action remains authorised.

Sep 4, 2026
An RDAP registry gateway links a bounded IP prefix to a geofeed while rejecting an out-of-range record.

IETF

The Link Is Not the Location: RFC 9877 and RDAP Geofeed Control

A geofeed link tells a client where to look; it does not turn every location claim in that file into verified truth. RFC 9877 makes RDAP a scoped discovery and authority signal, with controls that keep lookup scope, freshness, authenticity and privacy separate.

Sep 4, 2026
A four-stage ledger tracks an IPv4 transfer pre-approval from timed eligibility through source matching and registry completion to expiry.

Number Resource Society

An IPv4 Transfer Pre-Approval Needs a Registration-and-Expiry Ledger

An IPv4 transfer pre-approval answers a narrow question: how much address space a recipient may qualify to receive during a defined period. It does not identify a source, complete a transfer or prove that the registry has changed.

Sep 4, 2026
Abstract TCP endpoints hold tiny buffer increments until they form one efficient data segment, avoiding a loop of small packets.

History

The Window That Refused to Open One Byte at a Time: TCP Silly Window Syndrome Avoidance

A TCP receiver can have room for more data without advertising that room immediately. That deliberate silence prevents a small permission from becoming a self-repeating stream of small packets.

Sep 4, 2026
A compact payload token passes through a registry checkpoint, with separate paths representing permanent, temporary, documentation and experimental allocations.

IETF

A Two-Byte Number Can Lie About the Payload: RFC 9876 and CoAP Registry Control

CoAP defines Content-Format as a small integer that identifies a payload's media type and any content coding. RFC 9876 makes the registration procedure behind that integer stricter, because the code point is meaningful only when its media type, parameters, coding and semantics…

Sep 4, 2026
A board and executive committee connected by an accountability chain with five auditable checkpoints.

BDNOG

bdNOG Publishes Who Oversees Its Executive Committee, Not How

bdNOG’s public governance pages draw a clean line: the Board is the highest authority, while the Executive Committee (EC) manages the community’s work. The Board page says it approves yearly activities and holds the EC accountable. The EC page names the operating committee and…

Sep 4, 2026
A recursive DNS resolver selects two enclosed encrypted paths to authoritative servers while an exposed fallback path remains available.

IETF

A Resolver Can Choose Encryption Before DNS Operators Coordinate

Encryption between a user and a recursive DNS resolver does not protect the next hop. The resolver may still send the resulting query in cleartext to an authoritative server, exposing another part of the path to passive observation. RFC 9539 proposes an experimental compromise…

Sep 4, 2026
Queued data waits while a TCP receiver closes its window, sparse probes cross the connection, and a later reply reveals that the window has reopened.

History

The Window That Closed Without Ending the Connection: TCP Persist

When a TCP receiver says it has no room left, the sender stops sending ordinary data. The harder question is how either side escapes that pause if the one message announcing new room never arrives.

Sep 4, 2026
One early-data request splits across two global edge paths before converging on a single authoritative application commit ledger.

Global Cloud Services Trends

A Fast 0-RTT Handshake Is Not a Once-Only Transaction

TLS 1.3 and QUIC can remove a round trip from a resumed connection. That is a latency result, not a receipt that a state-changing request reached the application once, was committed once, and will never be replayed elsewhere.

Sep 4, 2026