Rafal (Wh1t3Rabbit) Los

Down the Security Rabbithole Podcast (DtSR)

News EN ↓ 750 episodes

This is Cybersecurity's premier podcast. Running strong since 2011 Rafal Los, James Jardine, and Jim Tiller bring a no-nonsense, non-commercial approach to our profession. DtSR brings interviews and discussion with people you want to meet, and stories you have to hear. So whether you're just starting out, or are decades deep into your career, you'll always learn something on this show. On Twitter/X: https://twitter.com/@DtSR_Podcast On YouTube: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHq On LinkedIn: https://www.linkedin.com/company/down-the-securit...

Author

Rafal (Wh1t3Rabbit) Los

Category

News

Podcast website

blogwh1t3rabbit.medium.com

Latest episode

Jul 7, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

DtSR Episode 197 - NewsCast for June 7th 2016 07.06.2016

In this episode...     Are people "going offline" as a result of increasing dangers of the Internet? This article makes the case for yes:  http://www.techspot.com/news/64839-increasing-number-internet-dangers-driving-millions-americans-offline.html But ... "millions"? We collectively call BS As the world moves more to mobile and digital, who thinks they have 'control'...

DtSR Episode 196 - Jason Witty 31.05.2016

On this episode of the Down the Security Rabbithole podcast, I get the pleasure of sitting down with one of my all-time favorite Chief Security Executives, Mr. Jason Witty . He's had a long career of successful security leadership, and in this podcast he sits down with us to talk about risk, threats and words we often confuse. You're not going to want to miss this episode. Have something...

DtSR Episode 195 - NewsCast for May 24th 2016 24.05.2016

This week the gang's all here to talk about some news happenings. Michael, James and I talk through some of the stories we've been tracking. Have something you've been reading and want to talk about? Hit us on Twitter with hashtag #DtSR and suggest a topic/story for the next NewsCast!   Tennessee Amends Breach Notification Statute http://www.natlawreview.com/article/tennessee-amends...

DtSR Episode 194 - Update on Cyberlaw w Shawn Tuma 17.05.2016

In this episode ...   Michael and I welcome back Shawn Tuma, our resident Cyber Law Expert from the great state of Texas. We discuss some of the recent cases (unlocking an iPhone!) and some of the tough issues facing the court systems today. Shawn provides insights into the use of the finger (not joking) and some amusing and frustrating aspects of cyber law as the courts continue to evolve. Join u...

DtSR Episode 193 - NewsCast for May 10th, 2016 10.05.2016

In this episode..   ImageTragick - major flaw in open source image processing toolkit ImageTragick is CVE-2016-3714 Logo & Website: https://imagetragick.com Has a logo, so it must be yuge Is this really that big of a deal? How many are impacted potentially? https://blog.sucuri.net/2016/05/imagemagick-remote-command-execution-vulnerability.html Remote code execution, with minor caveats - likely...

DtSR Episode 192 - Healthcare and Critical Infrastructure Security 04.05.2016

In this episode... Join our guest Larry Whiteside, Michael and I as werecord  live from InfoSec World 2016 in sunnyOrlando, Florida! We talk through the life of a CISO, and thechallenges of being in the Healthcare and Critical Infrastructurespaces and the similarities and differences. Larry has had a verydiverse and successful career leading some of the most challengingorganizations, so we dig int...

DtSR Episode 191 - NewsCast for April 26th 2016 26.04.2016

In this episode... Only about a third of companies know how many vendors accesstheir systems nearly every company is at risk for a third party breach it's almost impossible to vet every third party developing a strategy and being consistent, scaling is key http://www.csoonline.com/article/3055012/techology-business/only-a-third-of-companies-know-how-many-vendors-access-their-systems.html No f...

DtSR Episode 190 - Interview with Lance James 20.04.2016

In this episode, James, Michael and I are  live from InfoSec World 2016 and we get the pleasure of interviewing Lance James fresh off the keynote stage. In this intimate, fast-paced and bold interview we talk through some of the challenges InfoSec is facing today, and where Lance believes we should be going.   If you haven't been to InfoSec World, we highly recommend going next year. The cont...

DtSR Episode 189 - NewsCast for April 12th 2016 12.04.2016

In this episode...   Pros examine mossack-fonseca breach: Wordpress plugin, Drupal likely suspects Plug-ins seem to be a universal weakness Many companies have this type of 3rd party security issue The broader enterprise implications - how do you find these sites? http://www.scmagazine.com/pros-examine-mossack-fonseca-breach-wordpress-plugin-drupal-likely-suspects/article/488697/ WordPress pushes ...

DtSR Episode 188 - Security Talent Truths 05.04.2016

Intro song: "Josh Gabriel - Deep Down"; Intro/Outro v/o courtesy of @ToddHaverkos Have something to say? Let's hear it. Support the show >>> Please consider clicking the link above to support the show! -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-= YouTube home: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ...

DtSR Episode 187 - NewsCast for March 29th, 2016 29.03.2016

In this episode... BadLock bug (which now has a website, a graphic, and more hype than Bieber) is out there Is the bug really worth all this hype? Is this anything more than a PR stunt, and a big marketing opportunity? Everyone has an opinion, but one thing is for certain, this bug is making big waves http://www.wired.com/2016/03/hype-around-mysterious-badlock-bug-raises-criticism/ Your  wireless...

DtSR Episode 186 - Becoming a CISO 22.03.2016

In this episode   I posed some questions to Joey, an InfoSec professional who had recently moved into a CISO role in a midwest retail company: Let's talk a little bit about the background you had before walking into your first day as a CISO... How long have you been in your role, and what do you think "so far"? What do you think were the biggest lessons you've learned in your t...

DtSR Episode 185 - NewsCast for March 15th 2016 21.03.2016

In this episode...   The FTC is getting into providing guidance on password changes Well OK, this isn't really guidance, it's just a blog But - does this mean that the FTC is getting into technical guidance? https://www.ftc.gov/news-events/blogs/techftc/2016/03/time-rethink-mandatory-password-changes   Dwolla hit by CFPB and fined $100,000 Who is the CFPB (Consumer Finance Protection Bur...

DtSR Episode 184 - A CISO Post-RSA WrapUp 16.03.2016

In this episode , we wind down from RSA Conference 2016 and talk with Jonathan and Michael, both security executives and leaders at their respective companies whom were both out at RSA Conf and share with us some of their insights, lessons learned, and discuss some of the more interesting topics.   Join James and I for an informative, insightful, and slightly unnerving conversation about the state...

DtSR Episode 183 - NewsCast for March 1st 2016 01.03.2016

This is RSA Conference week, so while Rafal is out in San Francisco trying to make it through another one, James and Michael break down the news events that you may have missed.   300,000 Homes affected by security alarm bug http://www.forbes.com/sites/thomasbrewster/2016/02/17/simplisafe-alarm-attacks/#3202d4e679a3 According to Spokesperson, Alarm still alerts users' smart device when the al...

DtSR Episode 182 - Apple Versus the FBI 23.02.2016

In this episode... Michael and I moderate what turns out to be an expert-filled panel discussion on the real issues of the Apple vs FBI debate Shawn Tuma, our favorite cyber attorney, provides expert insights into the statutes, laws and applicable legislation in this case Dave Kennedy, Von Welch and Gary bring their technical expertise and background to discuss the issues from a technology and pol...

DtSR Episode 181 - NewsCast for Feb 16 2016 16.02.2016

In this episode   Class action lawsuit against SuperValu dismissed No damage (use of stolen information) so there's no case? As time passes, risk of use of stolen data, according to judge, decreases The precedent appears to be that in order to sue, you have to prove damage (imagine that?) http://legalnewsline.com/stories/510661014-data-breach-class-action-against-grocery-chain-dismissed Niema...

DtSR Episode 180 - From the CISO Perspective 09.02.2016

In this episode... Andrew discusses a few of the key challenges making it difficult for the healthcare sector right now Robb, Andrew and Raf discuss the importance of identity in the corporate environment Robb and Andrew give some of their wisdom for the successes and failures of CISOs (and the broader security industry) We discuss the technical vs executive CISO approach (which is better?) Robb a...

DtSR Episode 179 - NewsCast for Feb 2nd 2016 02.02.2016

In this episode   Employees may face penalties if they  misinterpret security policies? Human behavior still seen as the biggest weakness Employers are growing less tolerant of misbehaving employees If you "invite a data breach" you could be held liable http://www.welivesecurity.com/2016/01/14/employees-face-penalties-misinterpreting-security-policies/ New lawsuit filed blaming Twitter f...

DtSR Episode 178 - What Will Get Us There 26.01.2016

In this episode What goes us here - so where are we? Where do we go, and how? (addressing stunt hacking) We discuss how we can influence outcomes, without hand waving and endangering lives What about truly understanding risk, versus ‘security stuff’? Michael breaks out the “risk catnip” Raf asks Haroon - “What are the 2-3 things security does right now, that we should just quit?” We discuss some o...

DtSR Episode 177 - NewsCast for January 19th, 2016 19.01.2016

In this episode FTC imposes a $250,000 fine for "false advertising" of encryption Interesting case, where there really was 'false advertising' Would this even have been a 'security issue'? https://www.ftc.gov/news-events/press-releases/2016/01/dental-practice-software-provider-settles-ftc-charges-it-misled NY wants to ban encrypted smart phone sales Another clear case...

DtSR Episode 176 - 2015 InfoSec Legal Review 13.01.2016

We open up our 2016 year interviewing Shawn Tuma on the show. Shawn is our legal eagle, and a regular contributor to the podcast. This episode ran a little bit long (OK a lot long) but I think you'll enjoy the show...    In this episode... Most important cybersecurity-related legal developments of 2015 Tectonic Shift that occurred with “standing” in consumer data breach claims Discussion of l...

DtSR Episode 175 - NewsCast for January 5th 2016 05.01.2016

In this episode...   Juniper has a backdoor problem 2 separate issues, auth bypass & VPN weakness backdoor discovered in Juniper devices lots of speculation on who put it there, but it was meant to be disguised as ‘debug code’ enterprise implications - same as before (what's the bigger picture?) https://isc.sans.edu/forums/diary/Infocon+Yellow+Juniper+Backdoor+CVE20157755+and+CVE20157756/...

DtSR Episode 174 - Health Check on Healthcare InfoSec 28.12.2015

In this episode... We discuss what in the world is going on in the healthcare space, and why they’re such a target for attackers Dustin discusses why the explosion in digitalization in health care is both amazing and terrifying We discuss future-proofing “smart” healthcare I stumble on “the fundamentals” Dustin discusses the security of “data analytics” in the healthcare space I ask how we can mak...

DtSR Episode 173 - NewsCast for December 14th 2015 14.12.2015

In this episode... Vizio is getting sued, over data their TVs collect? James provided security tips on the local news station and one of those tips was around the privacy details of your gadgets Companies need to be considering what they are doing with their data At what point does data go from an asset to a liability? Do companies understand the difference? http://www.consumerreports.org/lcd-led-...

Listen to the Down the Security Rabbithole Podcast (DtSR) podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.