Skip to main content

Intelligence

Latest Articles

Latest intelligence on infrastructure operators, policy decisions, market moves, and digital power shifts.

A luminous routing-identity token crosses between two control stations above a layered evidence ledger.

Number Resource Society

An ASN Transfer Needs a Routing-Identity Handover Ledger

An ASN Transfer Needs a Routing-Identity Handover Ledger intelligence summary explains the development, the public evidence available to readers, the organisations involved, the regional context, market exposure, and the infrastructure consequences that may follow. The Number…

Sep 4, 2026
Two TCP segments approach a timed receiver gate, which releases one cumulative acknowledgment after the second segment arrives.

History

The Acknowledgment That Waited for a Second Segment: TCP Delayed ACKs

TCP does not always answer one received data segment with one immediate acknowledgment. The receiver may wait briefly, but that silence is governed by a second-segment threshold, a timer, and exceptions that preserve loss evidence.

Sep 4, 2026
Conceptual illustration of QNAME minimisation as a bounded DNS query sequence across delegation and cache states.

IETF

QNAME Minimisation Is a Query-Sequence Contract, Not a Privacy Switch

A resolver may advertise QNAME minimisation while exposing very different names, costs and failure modes from one lookup to the next. The feature matters only when operators can reconstruct the bounded sequence produced by delegation knowledge, cache state and negative proofs.

Sep 4, 2026
A structured SRv6 locator passes through a lease clock into a routing graph, with one route withdrawing.

IETF

An SRv6 Locator Lease Makes DHCPv6 Part of the Routing Control Plane

An SRv6 locator is the address-space foundation from which a segment endpoint creates SIDs. RFC 10038 allows that foundation to arrive as a DHCPv6 lease. The convenience is real, but so is the transfer of authority: pool selection, lease renewal, route installation and withdrawal…

Sep 4, 2026
A SIP policy matrix allows or rejects protected P-Header tokens according to message context at a trust boundary.

IETF

A Header Allowed Here Is Not Trusted Everywhere: RFC 9878 and SIP P-Header Scope

A call can fail at the trust boundary when a sender puts a P-Header in a SIP message that its receiver believes must not contain it. One implementation strips the field, another rejects the message, and a third accepts it. The disagreement can affect charging context…

Sep 4, 2026
An abstract glass registry record in a federal-court setting, crossed by fine global network lines.

CASE FILE

The Registrant Was Abroad; the Dot-Com Registry Was in Virginia: CNN v CNNews.com

The Registrant Was Abroad; the Dot-Com Registry Was in Virginia: CNN v CNNews.com intelligence summary explains the development, the public evidence available to readers, the organisations involved, the regional context, market exposure, and the infrastructure consequences that…

Sep 4, 2026
A phone connection moves from Wi-Fi to a mobile network while opaque QUIC tokens continue toward one application endpoint.

Global Cloud Services Trends

A QUIC Connection ID Is Not a Subscriber Identity

A QUIC connection can survive a change from Wi-Fi to mobile access. The identifier that helps packets find that connection is transport state, not proof of who holds the handset, which account is active, or whether an application action remains authorised.

Sep 4, 2026
An RDAP registry gateway links a bounded IP prefix to a geofeed while rejecting an out-of-range record.

IETF

The Link Is Not the Location: RFC 9877 and RDAP Geofeed Control

A geofeed link tells a client where to look; it does not turn every location claim in that file into verified truth. RFC 9877 makes RDAP a scoped discovery and authority signal, with controls that keep lookup scope, freshness, authenticity and privacy separate.

Sep 4, 2026
A four-stage ledger tracks an IPv4 transfer pre-approval from timed eligibility through source matching and registry completion to expiry.

Number Resource Society

An IPv4 Transfer Pre-Approval Needs a Registration-and-Expiry Ledger

An IPv4 transfer pre-approval answers a narrow question: how much address space a recipient may qualify to receive during a defined period. It does not identify a source, complete a transfer or prove that the registry has changed.

Sep 4, 2026
Abstract TCP endpoints hold tiny buffer increments until they form one efficient data segment, avoiding a loop of small packets.

History

The Window That Refused to Open One Byte at a Time: TCP Silly Window Syndrome Avoidance

A TCP receiver can have room for more data without advertising that room immediately. That deliberate silence prevents a small permission from becoming a self-repeating stream of small packets.

Sep 4, 2026
A compact payload token passes through a registry checkpoint, with separate paths representing permanent, temporary, documentation and experimental allocations.

IETF

A Two-Byte Number Can Lie About the Payload: RFC 9876 and CoAP Registry Control

CoAP defines Content-Format as a small integer that identifies a payload's media type and any content coding. RFC 9876 makes the registration procedure behind that integer stricter, because the code point is meaningful only when its media type, parameters, coding and semantics…

Sep 4, 2026
A board and executive committee connected by an accountability chain with five auditable checkpoints.

BDNOG

bdNOG Publishes Who Oversees Its Executive Committee, Not How

bdNOG’s public governance pages draw a clean line: the Board is the highest authority, while the Executive Committee (EC) manages the community’s work. The Board page says it approves yearly activities and holds the EC accountable. The EC page names the operating committee and…

Sep 4, 2026
A recursive DNS resolver selects two enclosed encrypted paths to authoritative servers while an exposed fallback path remains available.

IETF

A Resolver Can Choose Encryption Before DNS Operators Coordinate

Encryption between a user and a recursive DNS resolver does not protect the next hop. The resolver may still send the resulting query in cleartext to an authoritative server, exposing another part of the path to passive observation. RFC 9539 proposes an experimental compromise…

Sep 4, 2026
Queued data waits while a TCP receiver closes its window, sparse probes cross the connection, and a later reply reveals that the window has reopened.

History

The Window That Closed Without Ending the Connection: TCP Persist

When a TCP receiver says it has no room left, the sender stops sending ordinary data. The harder question is how either side escapes that pause if the one message announcing new room never arrives.

Sep 4, 2026
One early-data request splits across two global edge paths before converging on a single authoritative application commit ledger.

Global Cloud Services Trends

A Fast 0-RTT Handshake Is Not a Once-Only Transaction

TLS 1.3 and QUIC can remove a round trip from a resumed connection. That is a latency result, not a receipt that a state-changing request reached the application once, was committed once, and will never be replayed elsewhere.

Sep 4, 2026
An origin sends an invalidation pulse to one response group inside a bounded HTTP cache while a separate cache remains untouched.

IETF

One Header Can Invalidate a Whole Site Section: RFC 9875 and HTTP Cache Groups

A response can label related stored responses inside one cache and one URI origin, while a later unsafe request can name those labels for possible invalidation. The useful boundary is local coordination, not a promise of synchronization across caches, CDNs, or origins.

Sep 3, 2026
Editorial illustration of many anonymous applications passing through transparent gates toward five selected tokens, beside a closed process ledger.

Story

AFRINIC Named Five Fellowship Recipients from a Pool Above 1,700. The Selection Record Is Not Public

AFRINIC’s announcement identifies five people and describes a highly competitive programme. It does not publish the exact applicant total, the scoring method, the assessors or the decision record, so the notice proves an outcome without making the selection reproducible.

Sep 3, 2026
A central DNS catalog distributes zone-membership instructions across authoritative server racks, with one branch disconnected.

IETF

Catalog Zones Turn a DNS Member List into Fleet-Wide Provisioning Authority

An empty file is usually absence. An empty DNS catalog can be an instruction. If a generator accidentally publishes a catalog without its members, every consumer that originally provisioned those zones from that catalog may begin removing them and their associated state. RFC 9432…

Sep 3, 2026
Two period workstations exchange TCP sequence values while an isolated off-path observer cannot derive the next secret-dependent starting number.

History

The Number Made Harder for an Off-Path Attacker to Predict: TCP Initial Sequence Numbers

A TCP connection begins by exchanging numbers. The security change was not to hide that exchange, but to stop one visible number from revealing the next connection's starting point.

Sep 3, 2026
A signed software package is linked to identity, authority, trusted time, transparency and revocation evidence.

Global Institutional Trends

A Valid Software Signature Is Not a Durable Authority Record

A green verification result can survive long after the authority that made a release legitimate has changed. The cryptography may still be sound. The missing evidence is organisational: who was permitted to sign, under which role, at what time, and what later revocation or…

Sep 3, 2026