Skip to main content

Intelligence

Latest Articles

Latest intelligence on infrastructure operators, policy decisions, market moves, and digital power shifts.

Teal routes cross an external BGP boundary through explicit policy gates while an amber route without policy stops.

IETF

Default Reject Turns Missing EBGP Policy from Silent Authority into an Explicit Failure

An external BGP session can be established while its authority to receive or advertise routes remains undefined. RFC 8212 changes the default at that boundary: without import policy, accept no routes; without export policy, announce none. The leadership question is not whether a…

Sep 3, 2026
Editorial illustration of sixty domain-name nodes converging on a court docket across a jurisdiction boundary.

CASE FILE

Sixty Names Were Defendants; the Statute Still Defined the Claim: Harrods v Sixty Internet Domain Names

The caption did something unusual: it named sixty domain names as defendants. That procedural choice made a dispute over the Harrods name look, for a moment, like a dispute over things rather than people. The Fourth Circuit’s answer was narrower. The names could be before the…

Sep 3, 2026
An early-1990s workstation beside a mail document, linked certificate cards, certification-path diagrams and a revocation ledger.

History

The Chain That Made a Public Key Believable: PEM Certificate Management

A public key does not identify its owner by itself. RFC 1422 addressed that gap for Privacy Enhanced Mail by specifying certificates, certification authorities, validation paths, and revocation information—the institutional machinery needed before a relying party could treat a…

Sep 3, 2026
Two approved multihomed source paths pass an interface boundary while an unrelated spoofed path is rejected.

IETF

Enhanced uRPF Lets an Operator Admit Feasible Source Paths Without Trusting Every Route

A valid packet from a multihomed customer can arrive on a link that the receiving router would not choose for the return journey. Strict reverse-path forwarding may discard it; loose checking may accept any routed source. RFC 8704 defines a narrower middle ground: build an…

Sep 3, 2026
An IPv6 host receives a prefix signal from its local router before traffic crosses a NAT64 translation boundary.

IETF

The Prefix Arrived Before the Query: How RFC 9872 Changes NAT64 Discovery

An IPv6-only host that must reach IPv4 services needs to know which IPv6 prefix its network uses for address synthesis. RFC 9872 turns that knowledge into an access-network signal: learn PREF64 from Router Advertisements first, and use DNS discovery only when that signal is…

Sep 3, 2026
A client starts two network paths; the cyan path breaks before the service while the amber fallback reaches it.

Global Regional ISP Trends

A Fast IPv4 Fallback Can Make Broken IPv6 Look Healthy

A dual-stack service can answer every ordinary check while its IPv6 path is unusable. The availability result is real, but the protocol-family conclusion is not: a client may have escaped through IPv4 before the dashboard noticed what failed.

Sep 3, 2026
A single TCP byte stream with a highlighted URG boundary and a 16-bit pointer marking a position ahead of the receive sequence.

History

The Pointer That Was Never Out of Band: TCP Urgent Data

TCP urgent data is a small control surface with a long history. The URG flag makes a 16-bit urgent pointer meaningful, but RFC 793 described the boundary it marks in two contradictory ways. That ambiguity crossed from the specification into implementations and application APIs.

Sep 3, 2026
A secondary DNS server recomputes a whole-zone digest after transfer and compares it with the publisher's authenticated value.

IETF

ZONEMD Lets a Secondary Verify the Zone After the Transfer Ends

A completed zone transfer proves that a delivery procedure finished. It does not, by itself, prove that the receiver assembled the exact zone the publisher intended. ZONEMD adds a digest over the zone as a whole, creating a verification boundary after transport and before a…

Sep 3, 2026
Datagram observations flow into an IPFIX collector and split into two option-kind bitmaps and a separate experimental identifier list.

IETF

The Bitmap Says a UDP Option Appeared—not What It Did: RFC 9870

RFC 9870 gives IPFIX exporters a compact way to report which UDP Option kinds appeared in a Flow. Its bitmaps are useful precisely because their claim is narrow: they preserve observed presence, not a packet history, a receiver’s processing decision or an application outcome.

Sep 3, 2026
Deux armoires d'archives encadrent un mécanisme de transfert séparé, avec une capsule bleue et une clé sur un plateau rouge.

Global Cloud Services Trends

Backblaze's customer-held keys change who operates the second copy

Keeping encryption keys can be a deliberate purchase of control. In Backblaze B2, it also changes which copying service a customer can use—and where the continuing operating work has to sit.

Sep 3, 2026
Five record cards lie beside an opened envelope; an amber card is held separately in a small clamp.

Story

A Failed RIPE Database Update Can Still Change Records

RIPE NCC's documentation describes an update message whose entities can finish differently. The useful response is therefore not just a verdict on the message: it is an account of the changes already made, those rejected and those the caller still cannot confirm.

Sep 3, 2026
Editorial illustration of finite IPv4 address blocks moving through published transfer rules.

Story

LACNIC’s IPv4 transfer market and the price of scarcity

IPv4 exhaustion does not end allocation politics. It changes the place where they happen: from the distribution of a free pool to the rules governing transfers of resources that are already held.

Sep 3, 2026
Maciek Konstantynowicz in an editorial portrait with two defocused benchmark traces in a fictional network-performance lab.

IETF

Maciek Konstantynowicz and the Benchmark Result That Was Not a Service Guarantee

A network benchmark earns its value by saying exactly what it measured. RFC 9971 makes that discipline explicit: its MLRsearch result is a bounded result from stated trials and goals, not a transferable promise about every customer path, application or production hour.

Sep 3, 2026
Four differently partitioned glass address trays sit behind violet, green, red and amber domain keys, while one unchanged cyan message passes through the transport housings behind them.

History

Six Bytes Became an Address Only After the Domain Was Known: RFC 1449

An archive can preserve every octet and still lose the fact. Imagine finding six bytes in an old SNMP configuration: four could be an IPv4 address and two could be a UDP port. That reading is valid only if another field says the value belongs to the UDP transport domain. Without…

Sep 3, 2026
An early-1990s management chassis receives a cobalt request and sends an amber response back through the same conduit, while a blank-card address cabinet points to a separate unused path and a sealed lever guards record changes.

History

The Database Said One Address. The Reply Followed the Packet Back: RFC 1445

The address book and the live packet disagreed. For a new request, the 1993 SNMPv2 administrative model used the address recorded for the destination. For the reply, it ordered something else: use the transport domain and address from which this request actually arrived, even if…

Sep 3, 2026
Голубая временная дорожка изгибается назад к янтарной капсуле записанного сообщения, фиолетовый цилиндр старого ключа связан с часами, а новый зеленый ключ ждет на дорожке, ведущей только вперед.

History

The Clock Went Back. The Key Had to Change: RFC 1446

After a power failure, an SNMP agent wakes with yesterday’s shared secret and a clock that thinks yesterday has not happened yet. A captured request, previously too old to accept, can become “recent” again. Its digest never changed. The receiver’s boundary of acceptable time did.…

Sep 3, 2026
An early-1990s management console keeps brass and cyan key states while a cyan reply from the updated agent stops at an offset verifier; a separate beacon and clock preserve evidence.

History

The Key Changed Before the Reply Arrived. The Manager Had to Remember Both: RFC 1446

The agent had already installed the new secret. Its reply was built with that new value. The manager, still waiting for the reply before changing its own database, continued to trust the old one. RFC 1446 made this awkward interval explicit: a secure command could succeed at its…

Sep 3, 2026
Two translucent location records rise from one gridded address tile above a faint South America silhouette.

Story

One Prefix, Two Countries in LACNIC’s Geofeed

A public location feed repeats 23 prefixes, four with conflicting country codes. The useful repair is narrower than deciding where the networks are: stop a loading rule from masquerading as geographic evidence.

Sep 3, 2026
Three retail payment terminals send blank receipt ribbons into one amber tray beside a closed ledger.

Global Cloud Services Trends

Adyen's offline allowance grows with the terminal fleet

A retailer can give every till a sensible limit and still authorize more exposure than it intended. Adyen's store-and-forward controls make the number of disconnected terminals a commercial variable, not merely an equipment count.

Sep 3, 2026
A DNS hierarchy remains validated in teal while one narrowly scoped amber branch passes through a resolver-side exception.

IETF

A Negative Trust Anchor Lets the Resolver Suspend DNSSEC Without Changing the Zone

When a signed domain breaks, a validating recursive resolver can either preserve the failure or create a narrow local exception. A negative trust anchor restores reachability without repairing the zone, but it transfers temporary authority over DNS authentication to the resolver…

Sep 3, 2026