Summary

  • RFC 1273 published the design of a planned one-year service-reachability study before the longitudinal result existed: six runs would test 13 TCP services across about 12,700 Internet domains.
  • A successful connection would be closed without application data transfer. Refusals and timeouts triggered separate stop rules, so none of those observations alone proved service usefulness, security policy, institutional intent or disconnection.
  • The study recorded a governance problem inside its method: broad notification imposed more load than measurement and could change behaviour, while individual permission could select sites less likely to disconnect. The compromise joined public advance disclosure, traceable probes, opt-out and aggregate-only publication.

The first public record was a plan

RFC 1273 appeared in November 1991 as an Informational memo. Its tense matters. It described a study that was to run in January, March, May, July, September and November 1992. Each run was expected to last one or two days. The longitudinal result lay in the future.

Publishing the design first made a different object available for inspection. Readers could examine the question, target population, service list, retry limits, load controls, privacy treatment and contact route before any final trend line could absorb them into a polished conclusion.

The proposed object of measurement was service-level reachability, not basic IP connectivity. The program would attempt 13 TCP services at approximately 12,700 domains: daytime, netstat, FTP, Telnet, SMTP, DNS, Finger, Sun portmap, rlogin, rsh, UUCP, klogin and krcmd or kshell. The authors hoped changes in that surface would say something about organisations’ willingness to support inter-organisational computing.

That last step was an interpretation. A socket outcome occurred at one selected machine and time. Organisational willingness was a larger claim about a real institution. RFC 1273 placed the two in one research design, but did not turn them into the same record.

A connection was deliberately a small claim

When a TCP connection succeeded, the program would close it immediately and count it. It would transfer no application data in either direction. RFC 1273 stressed that the security mechanism behind an individual service would not be tested and that this was not a network-security study.

The restraint defined what “success” meant. It showed that a TCP server accepted connection establishment at that target and moment. It did not show that a login would be authorised, a file transferred, mail delivered, a name answered correctly or an application transaction completed. Nor did it prove why the service was exposed.

Failure also needed more than one bucket. After three connection refusals for a service within a domain, the program stopped trying that service during the run. After three timeouts on machines in a domain, it gave up on the domain, with the possibility of retrying a day later to account for transient network problems. A refusal and a timeout consumed different branches of the instrument. Neither was automatically a policy decision or a permanent disconnection.

DNS records presented another reality boundary. The authors considered using Well Known Service records as a less invasive source, but rejected them as incomplete and inconsistent because network operation did not require them. A directory assertion could identify a claimed service. A live connection attempt could observe a response. Each could fail differently; neither carried the whole truth of an organisation’s service surface.

The limits were part of the instrument

The study did not treat traffic control as housekeeping outside the method. Once a service succeeded in a domain, it was not tried again during that run. Refusal and timeout ceilings bounded unsuccessful work. The authors calculated a worst case of 37 connection requests per domain and expected the average to be much lower.

An August 1991 test run gave the plan an operating receipt: 50,549 DNS lookups, 73,760 attempted connections, about ten hours, and no more than 20 network operations in progress at once. The program was controlled from one location; its logs and network load were observed during collection; it could be stopped centrally.

Those figures establish the behaviour the authors reported for that test. They do not establish the later six runs, today’s cost of scanning or the absence of burden at every remote site. A global percentage and a remote administrator’s interruption are different denominators.

Notice became part of what it could disturb

Initial notification used an alt.security post and individual mail to site administrators. About half the messages were returned as undeliverable. RFC 1273 says the messages created far more network and administrative load than the measurement, and that some sites regarded the announcement itself as an unnecessary demand on their time.

There was also reactivity. A broad notice might lead sites to change service reachability. Asking every site for permission could produce a self-selected population of organisations already less likely to disconnect. The governance control could alter the phenomenon whose distribution the study meant to estimate.

That tension does not make representativeness a portable authorisation. RFC 1262, produced around the consultation on this study, separately said measurements imposing undue remote burden should not proceed without prior explicit permission. RFC 1273 instead records how this particular team tried to keep disclosure, load and sample bias visible at once.

The resulting arrangement used public advance notice through the RFC and electronic postings. Probes would originate from a testnet account on a lightly used machine; a Finger query to the host and account would return study information. The principal investigator offered a direct contact for questions, result requests and site removal.

Traceability was therefore not identical to individual delivery. The plan tried to let an administrator who saw the traffic discover its source and stop participation even when universal notification had failed.

Raw visibility stopped before public identity

The authors recognised that a site-level list of accessible services could become a road map. Raw data would remain private. Published measurements would be global statistics separated from the identities of the sites underneath them.

Aggregation is not magic. It is a custody decision: who may retain the underlying observations, which link to a site is removed, and what later publication can reveal. RFC 1273 records the intended boundary, not proof that no individual could ever be reidentified or that every privacy consequence was resolved.

What the two RFCs establish

This article uses RFC 1273 for the named study plan, service set, collection logic, August test run, notification experience, traceability, opt-out and data-publication policy. It uses RFC 1262 only for the adjacent general guidance on impact, provider contact, public method, privacy and explicit permission before undue burden.

The sources do not contain the completed longitudinal result. They do not prove that the planned 1992 runs occurred as described, that service reachability moved in one direction, that a measured host represented a whole institution, or that one TCP outcome explained policy, security, collaboration or causation.

The historical achievement of RFC 1273 is narrower and more durable. It made the study inspectable while the answer was still absent. The plan, probe, notification and result were not allowed to arrive as one indivisible fact.