/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Global Cyber Alliance, IBM, and Packet Clearing House launch free Quad9 DNS service that blocks malicious domains using consolidated threat intelligence

Sean Gallagher / Ars Technica :

Ars Technica Sean Gallagher

Context & Ripple Effects

The launch of Quad9 by Global Cyber Alliance, IBM, and Packet Clearing House is the consumer-facing payoff of IBM's decision to open decades of X-Force cyber-threat data to the public in 2015 — that intelligence feed is what lets a free resolver block malicious domains at scale. Packet Clearing House brings the anycast DNS infrastructure side of the partnership.

The model fits a broader arc of nonprofit-backed, free internet-defense utilities: Alphabet's Jigsaw later widened Project Shield's DDoS protection across EU newsrooms ahead of elections, and major networks eventually banded together under MANRS on routing security. Within six months of launch, Quad9 reported growth from 1M to 27M users.

First-order effects

  • Internet users gain a no-cost DNS resolver that blocks known-malicious domains before connection, powered by threat intelligence pooled across the three founding organizations rather than a single vendor's feed.
  • IBM gets a public deployment for its X-Force intelligence — converting an internal research asset into visible, running proof of its detection quality.

Second-order effects

  • Commercial DNS-security vendors now compete against a free, privacy-oriented alternative backed by a nonprofit consortium, pressuring paid resolver products on price and on surveillance practices.
  • Other threat-intelligence holders face the same playbook choice: pool data into shared public infrastructure or watch consortia like this one define the default defensive layer.

Third-order effects

  • If the pattern holds, core internet plumbing — DNS resolution, DDoS shielding, routing validation — consolidates around free, collectively operated defenses funded by alliances rather than subscriptions, shifting baseline security from a product category to a public utility.
  • That shift raises governance questions the coverage leaves open: who curates the blocklists, and how much visibility such resolvers trade away when they are also designed to resist surveillance.

The trend: Internet infrastructure defense is moving toward free, consortium-operated utilities built on shared threat intelligence, with Quad9 as an early template alongside Project Shield and MANRS.