Category
Far more power and cooling infrastructure than computing — by floor area, by cost and by engineering attention. The servers are the visible part and rarely the difficult part. What is physically
They differ in how they establish encryption, how much code they contain, how fast they are, and how well they cope with changing networks — and the differences are large enough that protocol choice
A leased line is a dedicated circuit reserved entirely for you, with guaranteed capacity in both directions and a contractual repair commitment. Business broadband is a shared service with a better
The mechanism by which senders discover how fast the network can carry their data without overwhelming it — and it matters because the internet has no central traffic controller. Capacity is
QUIC is a transport protocol built on UDP rather than TCP, designed to fix problems that could not be fixed in TCP itself. HTTP/3 is HTTP running over QUIC. The problem it solves: head-of-line
The client and server agree on how to encrypt, prove who the server is, and establish a shared key — all before any application data is sent. It happens in milliseconds and is the reason a padlock
A network that lets you associate and get an address, but intercepts your traffic until you complete some action — accepting terms, entering a room number, watching an advert. The awkwardness
Reliable at country level, decent at city level in dense areas, and frequently wrong at any finer resolution — because an IP address contains no location information at all. Everything is inference
The Network Time Protocol — the mechanism by which almost every connected device keeps its clock correct — and the reason it matters is that a surprising amount of infrastructure fails outright when
Because the address space was fixed at 32 bits — about 4.3 billion addresses — in 1981, when the internet was a research network and nobody expected every household to hold dozens of connected
Because in most countries the physical access network is a natural monopoly — nobody is going to dig up every street several times over — so regulation separates the company that owns the wires from
A globally unique identifier for a network under a single routing policy — an ISP, a large hosting company, a university, a bank. It is the unit in which the internet's routing table is expressed,
Nobody, and several bodies with narrow remits — which is the accurate answer rather than an evasive one. There is no central authority; there are institutions that coordinate specific scarce
Three DNS-published records that together let a receiving mail server answer one question: was this message really sent by the domain it claims to come from? Email was designed with no sender
A set of protocols that lets a device on your network ask the router to open a port to itself, automatically and without authentication — which is exactly why it is convenient and why it is
The mechanism for saying "this certificate is no longer valid before its expiry date" — and it is the weakest part of the web's trust system, because the obvious designs all conflict with either
"Down" covers several quite different failures, and the error you see narrows it down considerably — which is worth knowing before assuming the site is at fault. DNS failure. The name cannot be
WHOIS is the long-standing public directory of domain registration details — and the information it once exposed has largely been withdrawn, primarily because of data protection law. What it
Three separate services that are frequently bought from one company and are entirely independent — and understanding the separation is what makes moving any of them possible without breaking the
Whether your public address stays the same or changes periodically — and for most people it matters far less than it sounds, until it suddenly matters a great deal. Dynamic. Your ISP assigns an
Anycast announces the same IP address from multiple locations, and the routing system naturally delivers each user's traffic to whichever location is closest in network terms. It is one of the more
Considerable overlap, and a real distinction: a reverse proxy sits in front of servers and handles requests on their behalf; a load balancer distributes requests across several servers. Most modern
DNSSEC adds cryptographic signatures to DNS records so a resolver can verify that an answer genuinely came from the domain's owner and was not altered in transit. It addresses a real weakness, and
A WAF inspects the content of web requests and blocks those it judges malicious — operating at the application layer, which is what distinguishes it from an ordinary network firewall. The distinction