Just a guy in Vermont trying to connect all the dots...
Author's posts
May 13
Know Someone Who Has Made the Internet Better? Postel Service Award Nominations Deadline May 15 (Featured Blog)
Apr 07
Celebrating 50 Years of the RFCs That Define How the Internet Works
50 years ago today, on 7 April 1969, the very first “Request for Comments” (RFC) document was published. Titled simply “Host Software”, RFC 1 was written by Steve Crocker to document how packets would be sent from computer to computer in what was then the very early ARPANET. [1]
Steve and the other early authors were just circulating ideas and trying to figure out how to connect the different devices and systems of the early networks that would evolve into the massive network of networks we now call the Internet. They were not trying to create formal standards – they were just writing specifications that would help them be able to connect their computers. Little did they know then that the system they developed would come to later define the standards used to build the Internet.
Today there are over 8,500 RFCs whose publication is managed through a formal process by the RFC Editor team. The Internet Engineering Task Force (IETF) is responsible for the vast majority (but not all) of the RFCs – and there is strong process through which documents move within the IETF from ideas (“Internet-Drafts” or “I-Ds”) into published standards or informational documents[2].
50 years ago, one of the fundamental differences of the RFC series from other standards at the time was that:
- anyone could write an RFC for free.
- anyone could read the RFCs for free. They were open to all to read, without any fee or membership
As Steve Crocker notes in his recollections, this enabled the RFC documents to be widely distributed around the world, and studied by students, developers, vendors and other professionals. This allowed people to learn how the ARPANET, and later the Internet, worked – and to build on that to create new and amazing services, systems and software
This openness remains true today. While the process of publishing a RFC is more rigorous, anyone can start the process. You are not required to be a member (or pay for a membership) to contribute to or approve standards. And anyone, anywhere, can read all of the RFCs for free. You do not have to pay to download the RFCs, nor do you have to be a member of any organization.
More than anything, this open model of how to work together to create voluntary open standards is perhaps the greatest accomplishment of the RFC process. The Internet model of networking has thrived because it is built upon these open standards.
Standards may come and go over time, but the open way of working persists.
While we may no longer use NCP or some of the other protocols defined in the early RFCs, we are defining new protocols in new RFCs. The next 1,000s RFCs will define many aspects of the Internet of tomorrow.[3]
We may not know exactly how that future Internet will work, but it’s a pretty good guess that it will be defined in part through RFCs.
- See also: Fifty Years of RFCs – reflections from current RFC Editor Heather Flanagan.
[1] See our History of the Internet page for more background.
[2] For more explanation of the different types of RFCs, see “How to Read a RFC“.
[3] As noted in our 2019 Global Internet Report section on “Takeaways and Observations”, we are concerned that an increasing number of new services and applications on the Internet are relying on application programming interfaces (APIs) controlled by the application or platform owner rather than on open standards defined by the larger Internet community.
The post Celebrating 50 Years of the RFCs That Define How the Internet Works appeared first on Internet Society.
Mar 30
TDYR 361 – Reflections on IETF 104 in Prague
Mar 18
TDYR 360 – What was the Internet like before the Web? Celebrating 30 years of the Web – #Web30
Mar 12
Celebrating the 30th Anniversary of the World Wide Web
Back around 1991, I was traveling throughout the eastern USA teaching an “Introduction to the Internet” course I had written. The students were mainly from telecom, financial, and software companies wanting to know what this Internet thing was all about. I taught about IP addresses and DNS, using email, sending files with FTP, using archie and veronica to find info, engaging in USENET discussions, and using Gopher to explore “gopherspace”.
At the end of the course, one of the final sections was on “emerging technologies”. And there, nestled in with HyTelnet and WAIS, was one single page about this new service called the “World-Wide Web”.
And all the page really said was: telnet to info.cern.ch, login as “www”, and start pressing numbers to follow links on the screen.
That was it! (and you can still experience that site today)
We had no idea in those very early days that what we were witnessing was the birth of a service that would come to create so much of the communication across the Internet.
In only a few short years, of course, I was teaching new courses on “Weaving the Web: Creating HTML Documents” and “Navigating the World-Wide Web using Netscape Navigator“. And all around us there was an explosion of content on the Internet as “everyone” wanted to create their own websites.
The Web enabled anyone to publish and to consume content (assuming they could get access to the Internet). Content finally broke free from the “walled gardens” of the proprietary commercial online services such as CompuServe, AOL, Prodigy, and others. The Web brought an open layer of publishing, communication, and commerce to the gigantic open network of networks that is the Internet. It was a perfect example of the “permissionless innovation” allowed by an open, globally-connected Internet, where no one has to ask permission before creating new services.
Whole new industries were born, while others faded away. New words entered our vocabulary. (ex. before the Web, who used the word “browser”?) New opportunities emerged for so many people around the world. Lives were changed. Education changed. Economies changed. The very fabric of our society changed.
While it is true that the Web could not exist without the Internet, the Internet would not be as amazing as it is without the Web.
And so on this momentous day, we join with the people at CERN, the World Wide Web Consortium (W3C), the World Wide Web Foundation, Tim Berners-Lee, and so many others in celebrating the 30th anniversary of the Web.
The path forward for the next 30 years of the Web, which relies on the Internet to flourish, is not so clear. It is a challenging time for the Internet. And the intensity of the consolidation and centralization within the Internet economy has caused Tim Berners-Lee himself to issue a call to re-decentralize the Web.
But for today, let us focus on all the good the Web has brought to the Internet, all the people it has helped, all the lives it has transformed.
Happy 30th birthday to the Web!
Image credit: CERN’s re-created info.cern.ch.
The post Celebrating the 30th Anniversary of the World Wide Web appeared first on Internet Society.
Jan 30
Call for Proposals: ICANN 64 DNSSEC Workshop in Kobe, Japan (March 2019) (Featured Blog)
Jan 30
Call for Proposals: ICANN 64 DNSSEC Workshop in Kobe, Japan (March 2019) (Featured Blog)
Jan 29
Call for Participation – ICANN 64 DNSSEC Workshop in Kobe, Japan – March 2019
The DNSSEC Deployment Initiative and the Internet Society Deploy360 Programme, in cooperation with the ICANN Security and Stability Advisory Committee (SSAC), are planning a DNSSEC Workshop during the ICANN64 meeting held from 09-14 March 2019 in Kobe, Japan. The DNSSEC Workshop has been a part of ICANN meetings for several years and has provided a forum for both experienced and new people to meet, present and discuss current and future DNSSEC deployments.
For reference, the most recent session was held at the ICANN Annual General Meeting in Barcelona, Spain, on 24 October 2018. The presentations and transcripts are available at: https://63.schedule.icann.org/meetings/901549, https://63.schedule.icann.org/meetings/901554, and https://63.schedule.icann.org/meetings/901555.
At ICANN64 we are particularly interested in live demonstrations of uses of DNSSEC, DS automation or DANE. Examples might include:
- DNSSEC automation and deployment using CDS, CDNSKEY, and CSYNC
- DNSSEC/DANE validation in browsers and in applications
- Secure email / email encryption using DNSSEC, OPENPGPKEY, or S/MIME
- DNSSEC signing solutions and innovation (monitoring, managing, validation)
- Tools for automating the generation of DNSSEC/DANE records
- Extending DNSSEC/DANE with authentication, SSH, XMPP, SMTP, S/MIME or PGP/GPG and other protocols
Our interest is to provide current examples of the state of development and to show real-world examples of how DNSSEC and DANE related innovation can be used to increase the overall security of the Internet.
We are open to presentations and demonstrations related to any topic associated with DNSSEC and DANE. Examples of the types of topics we are seeking include:
1. DNSSEC Panel (Regional and Global)
For this panel, we are seeking participation from those who have been involved in DNSSEC deployment in the region and also from those who have not deployed DNSSEC but who have a keen interest in the challenges and benefits of deployment. In particular, we will consider the following questions: Are you interested in reporting on DNSSEC validation of your ISPs? What can DNSSEC do for you? What doesn’t it do? What are the internal tradeoffs to implementing DNSSEC? What did you learn in your deployment of DNSSEC? We are interested in presentations from both people involved with the signing of domains and people involved with the deployment of DNSSEC-validating DNS resolvers.
2. DS Automation
We are looking at innovative ways to automate the parent child synchronization CDS / CDNSKEY and methods to bootstrap new or existing domains. We are also interested in development or plans related to CSYNC, which are aimed at keeping the glue up to date.
We would like to hear from DNS Operators what their current thoughts on CDS/CDNSKEY automation are.
3. DNSSEC/DANE Support in the browsers
We would be interested in hearing from browser developers what their plans are in terms of supporting DNSSEC/DANE validation.
4. DANE Automation
For DNSSEC to reach massive deployment levels it is clear that a higher level of automation is required than is currently available. There also is strong interest for DANE usage within web transactions as well as for securing email and Voice-over-IP (VoIP). We are seeking presentations on topics such as:
- How can the industry use DANE and other DNSSEC applications as a mechanism for creating a more secure Internet?
- What tools, systems and services are available to help automate DNSSEC key management?
- Can you provide an analysis of current tools/services and identify gaps?
- What are some of the new and innovative uses of DANE and other DNSSEC applications in new areas or industries?
- What tools and services are now available that can support DANE usage?
We would be particularly interested in any live demonstrations of DNSSEC / DANE application automation and services. Demonstrations of new tools that make the setup of DNSSEC or DANE more automated would also be welcome.
If you are interested in participating, please send a brief (1-2 sentence) description of your proposed presentation to
dnssec-kobe@isoc.org before ** 07 February 2019 **
We hope that you can join us.
Thank you,
Kathy Schnitt
On behalf of the DNSSEC Workshop Program Committee:
Jean Robert Hountomey, AfricaCERT
Jacques Latour, .CA
Russ Mundy, Parsons
Ondřej Filip, CZ.NIC
Yoshiro Yoneya, JPRS
Dan York, Internet Society
Mark Elkins, DNS/ZACR
Jan 29
Call for Participation – ICANN DNSSEC Workshop at ICANN64 in Kobe, Japan

Will you be at the ICANN 64 meeting in March 2019 in Kobe, Japan? If so (or if you can get to Kobe), would you be interested in speaking about any work you have done (or are doing) with DNSSEC, DANE or other DNS security and privacy technologies? If you are interested, please send a brief (1-2 sentence) description of your proposed presentation to dnssec-kobe@isoc.org before 07 February 2019.
Call for Participation
The DNSSEC Deployment Initiative and the Internet Society Deploy360 Programme, in cooperation with the ICANN Security and Stability Advisory Committee (SSAC), are planning a DNSSEC Workshop during the ICANN64 meeting held from 09-14 March 2019 in Kobe, Japan. The DNSSEC Workshop has been a part of ICANN meetings for several years and has provided a forum for both experienced and new people to meet, present and discuss current and future DNSSEC deployments.
For reference, the most recent session was held at the ICANN Annual General Meeting in Barcelona, Spain, on 24 October 2018. The presentations and transcripts are available at: https://63.schedule.icann.org/meetings/901549, https://63.schedule.icann.org/meetings/901554, and https://63.schedule.icann.org/meetings/901555.
At ICANN64 we are particularly interested in live demonstrations of uses of DNSSEC, DS automation or DANE. Examples might include:
- DNSSEC automation and deployment using CDS, CDNSKEY, and CSYNC
- DNSSEC/DANE validation in browsers and in applications
- Secure email / email encryption using DNSSEC, OPENPGPKEY, or S/MIME
- DNSSEC signing solutions and innovation (monitoring, managing, validation)
- Tools for automating the generation of DNSSEC/DANE records
- Extending DNSSEC/DANE with authentication, SSH, XMPP, SMTP, S/MIME or PGP/GPG and other protocols
Our interest is to provide current examples of the state of development and to show real-world examples of how DNSSEC and DANE related innovation can be used to increase the overall security of the Internet.
We are open to presentations and demonstrations related to any topic associated with DNSSEC and DANE. Examples of the types of topics we are seeking include:
1. DNSSEC Panel (Regional and Global)
For this panel, we are seeking participation from those who have been involved in DNSSEC deployment in the region and also from those who have not deployed DNSSEC but who have a keen interest in the challenges and benefits of deployment. In particular, we will consider the following questions: Are you interested in reporting on DNSSEC validation of your ISPs? What can DNSSEC do for you? What doesn’t it do? What are the internal tradeoffs to implementing DNSSEC? What did you learn in your deployment of DNSSEC? We are interested in presentations from both people involved with the signing of domains and people involved with the deployment of DNSSEC-validating DNS resolvers.
2. DS Automation
We are looking at innovative ways to automate the parent child synchronization CDS / CDNSKEY and methods to bootstrap new or existing domains. We are also interested in development or plans related to CSYNC, which are aimed at keeping the glue up to date.
We would like to hear from DNS Operators what their current thoughts on CDS/CDNSKEY automation are.
3. DNSSEC/DANE Support in the browsers
We would be interested in hearing from browser developers what their plans are in terms of supporting DNSSEC/DANE validation.
4. DANE Automation
For DNSSEC to reach massive deployment levels it is clear that a higher level of automation is required than is currently available. There also is strong interest for DANE usage within web transactions as well as for securing email and Voice-over-IP (VoIP). We are seeking presentations on topics such as:
- How can the industry use DANE and other DNSSEC applications as a mechanism for creating a more secure Internet?
- What tools, systems and services are available to help automate DNSSEC key management?
- Can you provide an analysis of current tools/services and identify gaps?
- What are some of the new and innovative uses of DANE and other DNSSEC applications in new areas or industries?
- What tools and services are now available that can support DANE usage?
We would be particularly interested in any live demonstrations of DNSSEC / DANE application automation and services. Demonstrations of new tools that make the setup of DNSSEC or DANE more automated would also be welcome.
If you are interested in participating, please send a brief (1-2 sentence) description of your proposed presentation to
dnssec-kobe@isoc.org before ** 07 February 2019 **
We hope that you can join us.
Thank you,
Kathy Schnitt
On behalf of the DNSSEC Workshop Program Committee:
Jean Robert Hountomey, AfricaCERT
Jacques Latour, .CA
Russ Mundy, Parsons
Ondřej Filip, CZ.NIC
Yoshiro Yoneya, JPRS
Dan York, Internet Society
Mark Elkins, DNS/ZACR
The post Call for Participation – ICANN DNSSEC Workshop at ICANN64 in Kobe, Japan appeared first on Internet Society.
