# BGP Vortex: Internet Kill Switch? Page: https://stenobird.com/podcast/threat-talks-your-gateway-to-cybersecurity-insights-6755159/bgp-vortex-internet-kill-switch Text version: https://stenobird.com/podcast/threat-talks-your-gateway-to-cybersecurity-insights-6755159/bgp-vortex-internet-kill-switch.md Podcast: [Threat Talks - Your Gateway to Cybersecurity Insights](https://stenobird.com/podcast/threat-talks-your-gateway-to-cybersecurity-insights-6755159) Published: 2025-12-23T08:07:34+00:00 Episode link: https://share.transistor.fm/s/46deaaec Audio file: https://2.gum.fm/op3.dev/e/pdcn.co/e/pscrb.fm/rss/p/pdst.fm/e/dts.podtrac.com/redirect.mp3/media.transistor.fm/46deaaec/53fca182.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/threat-talks-your-gateway-to-cybersecurity-insights-6755159/episodes/bgp-vortex-internet-kill-switch Duration seconds: 1322 ## Resource Could a single BGP trick really break the internet? A new “BGP Vortex” claim says yes - by abusing route oscillation and BGP communities to trigger endless update loops and exhaust router CPU. So we check what actually holds up in the real world. In this Threat Talks Deep Dive, Rob Maas, Field CTO at ON2IT, sits down with Eric Nghia Nguyen Duy, Network Engineer at AMS-IX, to understand what BGP (short for Border Gateway Protocol) actually does, how the proposed Vortex mechanism works (route oscillation + community behavior), and why real-world internet operators are far more resilient than the headline suggests. Yes, it’s an attention-grabbing claim. No, it’s not a “break the whole internet tomorrow” button. (00:00) - – 02:29 Introduction: The BGP Vortex Claim (02:29) - - 06:35 What is BGP? (06:35) - - 13:13 BGP Vortex: How it works (13:13) - - 15:02 What an Attacker Would Actually Need (15:02) - - 19:08 What can we do to prevent this (19:08) - - 19:56 What role AMS-IX plays (19:56) - – 22:01 Conclusion Key topics covered • What BGP is and why the internet depends on it • How route oscillation and update amplification can overload routers • Why the attack relies on upstream policy choices (communities aren’t “magic”) • Why the “break the internet” claim is mostly theoretical • Practical mitigations: filtering/inspecting communities, monitoring, session shutdown Resources • BGP Vortex research paper: https://www.usenix.org/system/files/usenixsecurity25-stoeger.pdf • BGP Vortex presentation video: https://www.youtube.com/watch?v=dd6L1mdQLmk • Threat Talks: https://threat-talks.com/ • ON2IT (Zero Trust as a Service): https://on2it.net/ • AMS-IX: https://www.ams-ix.net/ams Subscribe to Threat Talks and turn on notifications for deep dives into the world’s most active cyber… ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/threat-talks-your-gateway-to-cybersecurity-insights-6755159/episodes/bgp-vortex-internet-kill-switch/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/threat-talks-your-gateway-to-cybersecurity-insights-6755159/bgp-vortex-internet-kill-switch.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.