Intelligence
Latest Articles
Latest intelligence on infrastructure operators, policy decisions, market moves, and digital power shifts.

IETF
Default Reject Turns Missing EBGP Policy from Silent Authority into an Explicit Failure
An external BGP session can be established while its authority to receive or advertise routes remains undefined. RFC 8212 changes the default at that boundary: without import policy, accept no routes; without export policy, announce none. The leadership question is not whether a…

CASE FILE
Sixty Names Were Defendants; the Statute Still Defined the Claim: Harrods v Sixty Internet Domain Names
The caption did something unusual: it named sixty domain names as defendants. That procedural choice made a dispute over the Harrods name look, for a moment, like a dispute over things rather than people. The Fourth Circuit’s answer was narrower. The names could be before the…

History
The Chain That Made a Public Key Believable: PEM Certificate Management
A public key does not identify its owner by itself. RFC 1422 addressed that gap for Privacy Enhanced Mail by specifying certificates, certification authorities, validation paths, and revocation information—the institutional machinery needed before a relying party could treat a…

IETF
Enhanced uRPF Lets an Operator Admit Feasible Source Paths Without Trusting Every Route
A valid packet from a multihomed customer can arrive on a link that the receiving router would not choose for the return journey. Strict reverse-path forwarding may discard it; loose checking may accept any routed source. RFC 8704 defines a narrower middle ground: build an…

IETF
The Prefix Arrived Before the Query: How RFC 9872 Changes NAT64 Discovery
An IPv6-only host that must reach IPv4 services needs to know which IPv6 prefix its network uses for address synthesis. RFC 9872 turns that knowledge into an access-network signal: learn PREF64 from Router Advertisements first, and use DNS discovery only when that signal is…

Global Regional ISP Trends
A Fast IPv4 Fallback Can Make Broken IPv6 Look Healthy
A dual-stack service can answer every ordinary check while its IPv6 path is unusable. The availability result is real, but the protocol-family conclusion is not: a client may have escaped through IPv4 before the dashboard noticed what failed.

History
The Pointer That Was Never Out of Band: TCP Urgent Data
TCP urgent data is a small control surface with a long history. The URG flag makes a 16-bit urgent pointer meaningful, but RFC 793 described the boundary it marks in two contradictory ways. That ambiguity crossed from the specification into implementations and application APIs.

IETF
ZONEMD Lets a Secondary Verify the Zone After the Transfer Ends
A completed zone transfer proves that a delivery procedure finished. It does not, by itself, prove that the receiver assembled the exact zone the publisher intended. ZONEMD adds a digest over the zone as a whole, creating a verification boundary after transport and before a…

IETF
The Bitmap Says a UDP Option Appeared—not What It Did: RFC 9870
RFC 9870 gives IPFIX exporters a compact way to report which UDP Option kinds appeared in a Flow. Its bitmaps are useful precisely because their claim is narrow: they preserve observed presence, not a packet history, a receiver’s processing decision or an application outcome.

Global Cloud Services Trends
Backblaze's customer-held keys change who operates the second copy
Keeping encryption keys can be a deliberate purchase of control. In Backblaze B2, it also changes which copying service a customer can use—and where the continuing operating work has to sit.

Story
A Failed RIPE Database Update Can Still Change Records
RIPE NCC's documentation describes an update message whose entities can finish differently. The useful response is therefore not just a verdict on the message: it is an account of the changes already made, those rejected and those the caller still cannot confirm.

Story
LACNIC’s IPv4 transfer market and the price of scarcity
IPv4 exhaustion does not end allocation politics. It changes the place where they happen: from the distribution of a free pool to the rules governing transfers of resources that are already held.

IETF
Maciek Konstantynowicz and the Benchmark Result That Was Not a Service Guarantee
A network benchmark earns its value by saying exactly what it measured. RFC 9971 makes that discipline explicit: its MLRsearch result is a bounded result from stated trials and goals, not a transferable promise about every customer path, application or production hour.

History
Six Bytes Became an Address Only After the Domain Was Known: RFC 1449
An archive can preserve every octet and still lose the fact. Imagine finding six bytes in an old SNMP configuration: four could be an IPv4 address and two could be a UDP port. That reading is valid only if another field says the value belongs to the UDP transport domain. Without…

History
The Database Said One Address. The Reply Followed the Packet Back: RFC 1445
The address book and the live packet disagreed. For a new request, the 1993 SNMPv2 administrative model used the address recorded for the destination. For the reply, it ordered something else: use the transport domain and address from which this request actually arrived, even if…

History
The Clock Went Back. The Key Had to Change: RFC 1446
After a power failure, an SNMP agent wakes with yesterday’s shared secret and a clock that thinks yesterday has not happened yet. A captured request, previously too old to accept, can become “recent” again. Its digest never changed. The receiver’s boundary of acceptable time did.…

History
The Key Changed Before the Reply Arrived. The Manager Had to Remember Both: RFC 1446
The agent had already installed the new secret. Its reply was built with that new value. The manager, still waiting for the reply before changing its own database, continued to trust the old one. RFC 1446 made this awkward interval explicit: a secure command could succeed at its…

Story
One Prefix, Two Countries in LACNIC’s Geofeed
A public location feed repeats 23 prefixes, four with conflicting country codes. The useful repair is narrower than deciding where the networks are: stop a loading rule from masquerading as geographic evidence.

Global Cloud Services Trends
Adyen's offline allowance grows with the terminal fleet
A retailer can give every till a sensible limit and still authorize more exposure than it intended. Adyen's store-and-forward controls make the number of disconnected terminals a commercial variable, not merely an equipment count.

IETF
A Negative Trust Anchor Lets the Resolver Suspend DNSSEC Without Changing the Zone
When a signed domain breaks, a validating recursive resolver can either preserve the failure or create a narrow local exception. A negative trust anchor restores reachability without repairing the zone, but it transfers temporary authority over DNS authentication to the resolver…
