Many of the internet’s quirks only make sense once you know the history. Why doesn’t IP care whether packets arrive? Why do websites need both a name and an address? And why is it so hard to introduce new protocols? Here we follow the development from the first packet-switched networks to the protocols being introduced now. If you want to get the basic concepts in place first, start with the guide to network protocols.
Before the internet
The telephone network was built on circuit switching: when you dialed, a fixed connection was reserved all the way to the recipient for as long as the call lasted. That works for voice, but is wasteful for data, which comes in short bursts. In the early 1960s, Paul Baran in the US and Donald Davies in the UK independently proposed something else: split data into small packets, and let each packet find its own way through the network. Many conversations can then share the same wires, and if one connection is cut, the packets find another route. That’s the idea the whole internet rests on.
ARPANET and TCP/IP
The idea became reality with ARPANET, funded by the US Department of Defense’s research agency. On October 29, 1969, the first message was sent between the University of California, Los Angeles and the Stanford Research Institute. The plan was to type “LOGIN”, but the system crashed after two letters, so the first message on what became the internet was “LO”.
At first, ARPANET used a protocol called NCP, which assumed the network itself was reliable. That held as long as there was only one network, but soon others appeared, over radio and satellite, with completely different properties. In 1974, Vint Cerf and Bob Kahn described a protocol that could connect different networks into one: a network of networks, an internet. The crucial decision was to put the responsibility for reliability on the computers at each end, not in the network. The network just had to try to deliver packets as best it could.
In the late 1970s, the original protocol was split in two: IP, which only finds the way, and TCP, which takes care of reliable delivery. That split is why IP still doesn’t care today whether packets arrive, and why other protocols, like UDP, can be built directly on top of IP. On January 1, 1983, the whole of ARPANET switched from NCP to TCP/IP in one go, a date often cited as the internet’s birthday.
DNS came the same year. Until then, every computer had a shared file with the names and addresses of every other machine, which had to be updated and copied around. That didn’t hold as the network grew, and DNS replaced it with a distributed system where each organization manages its own names. That’s why websites today have both a name and an address.
Timeline
The most important milestones in one place:
| Year | Milestone |
|---|---|
| 1969 | ARPANET sends its first message, and the first RFC is published |
| 1974 | Cerf and Kahn describe the protocol that becomes TCP/IP |
| 1983 | ARPANET switches to TCP/IP, and DNS is described |
| 1983 | Ethernet is standardized by the IEEE |
| 1986 | The IETF holds its first meeting |
| 1991 | The World Wide Web and HTTP become publicly available |
| 1995 | SSL from Netscape and the first IPv6 specification |
| 1997 | HTTP/1.1 and the first Wi-Fi standard |
| 1999 | TLS replaces SSL |
| 2011 | The central pool of free IPv4 addresses runs out |
| 2015 | HTTP/2 |
| 2018 | TLS 1.3 |
| 2021–22 | QUIC and HTTP/3 |
Standardization
From the start, the internet’s protocols have been described in open documents called RFCs, Requests for Comments. The first was written in 1969 by Steve Crocker, and the name reflects the tone: proposals others could comment on and improve, not decrees. Since 1986, the work has taken place in the IETF, which has no members in the traditional sense. Anyone can take part in the working groups, which today mostly meet on mailing lists and online.
A new protocol starts as an Internet-Draft, is discussed and changed in a working group, and is finally published as an RFC. There’s no vote. The IETF’s motto is “rough consensus and running code”: there has to be broad agreement, and there have to be implementations that work in practice. That pragmatism was crucial in the 1980s and 90s, when international standards bodies were working on a competing set of protocols built on the OSI model. OSI was carefully thought through, but TCP/IP already existed and worked, and as the internet grew, it won. The OSI model’s seven layers live on, though, as the way we talk about networks.
The IETF isn’t responsible for everything. The IEEE standardizes physical networks like Ethernet and Wi-Fi, the W3C and WHATWG handle web standards like HTML, and IANA administers the shared registries of addresses, port numbers and domain extensions.
The web and encryption
In 1991, Tim Berners-Lee made the World Wide Web available to everyone, and with HTTP as a new protocol at the top of the stack, the internet changed from a network for researchers into a network for everyone. Online commerce required encryption, and in 1995 Netscape launched SSL, which was replaced in 1999 by the open standard TLS. HTTP has since evolved through several versions, which we cover in the guide to how HTTP has evolved.
The future
The internet’s protocols are still on the move. Three developments will shape the coming years.
New protocols have to go in disguise
A paradox of the internet is that it has become hard to introduce new protocols. Firewalls, routers and other equipment along the way look inside packets and drop them if they look unfamiliar. This is called ossification. The answer has been to encrypt as much as possible, so the equipment along the way can’t see, and so can’t interfere with, what’s going on. QUIC is the clearest example: it runs on top of UDP, which all equipment knows, and encrypts almost all of its own header. That has made it possible to replace TCP in HTTP/3, something that would otherwise have been almost impossible.
More privacy
Even with HTTPS, information still leaks: DNS lookups are traditionally sent unencrypted, and the name of the site you’re visiting can be seen at the start of the TLS handshake. Encrypted DNS (DNS over HTTPS and DNS over TLS) is widespread in browsers and operating systems, and Encrypted Client Hello, which also hides the site’s name, is being rolled out.
Quantum-safe encryption and IPv6
Powerful quantum computers will be able to break the encryption used today to exchange keys. Since data intercepted now can be stored and decrypted later, browsers and large networks have already started using quantum-safe methods in TLS, combined with the classical ones. Meanwhile, the long transition from IPv4 to IPv6 continues, and an ever larger share of the internet’s traffic runs over IPv6.