Rafal (Wh1t3Rabbit) Los

Down the Security Rabbithole Podcast (DtSR)

News EN ↓ 750 episodes

This is Cybersecurity's premier podcast. Running strong since 2011 Rafal Los, James Jardine, and Jim Tiller bring a no-nonsense, non-commercial approach to our profession. DtSR brings interviews and discussion with people you want to meet, and stories you have to hear. So whether you're just starting out, or are decades deep into your career, you'll always learn something on this show. On Twitter/X: https://twitter.com/@DtSR_Podcast On YouTube: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHq On LinkedIn: https://www.linkedin.com/company/down-the-securit...

Author

Rafal (Wh1t3Rabbit) Los

Category

News

Podcast website

blogwh1t3rabbit.medium.com

Latest episode

Jul 7, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

DtSR Episode 172 - The Truth on Cyber Insurance 07.12.2015

Thanks for joining us! This is a very important episode with true experts on the topic of cyber insurance. I was lucky enough to get an attorney and a VP of an insurance firm who specialize in the topic and their depth of knowledge and candor may shock you. The net is that cyber insurance is a positive for our industry.   In this episode..   Eran says that if you don’t do good security, the courts...

DtSR Episode 171 - When the FTC Attacks 30.11.2015

In this episode I interview Mike Daugherty - author of The Devil Inside the Beltway [ Amazon.com link ] live from the Security Advisor Alliance first-ever Summit in Dallas, TX. Mike was kind enough to sit down with me (twice, thanks to a tech failure) and tell his absolutely surreal story of what happened to him, his company at the hands of what can only be described as an insane situation. If you...

DtSR Episode 170 - Minneapolis CISO Summit Roundtable 1 23.11.2015

In this episode We start a constructive discussion addressing the problem of the ‘talent shortage’ The panel discusses the general lack of understanding of the big picture challenge from both sides: business and security The panel discusses basic security issues in an expanding ecosystem of Internet connected things The panel discusses some real potential solutions to our talent issue   Guests Bry...

DtSR Episode 169 - NewsCast for November 16th 2015 16.11.2015

In this episode... Is this seriously the FBI suggestion to companies hit with ransomware? http://thehackernews.com/2015/10/fbi-ransomware-malware.html Sets an awful precedent ... or does it? What other options are there? Would you take this advice? Microsoft is opening a data center in the UK ...why? http://thehill.com/policy/cybersecurity/259656-microsoft-opens-uk-only-data-center-following-eu-ru...

DtSR Episode 168 - Practical Enterprise Threat Intelligence 09.11.2015

In this episode Rob & Liam discuss the practical applications of threat intelligence for today's enterprise We discuss what enterprise threat intelligence really is (and also what it isn't) We discuss the place of feeds, tools, processes and people in the mechanics of the program We discuss the need to conduct a program-based intelligence approach for the enterprise Guests Liam Randa...

DtSR Episode 167 - NewsCast for Nov 2nd 2015 02.11.2015

In this episode... Turn any old car into a "smart car" for $200 with this new miracle device " BACKED BY FROGVENTURES, VOYOMOTIVE IS TACKLING THE BURGEONING CONNECTED-CAR SPACE " Could be a fantastic idea Could be an awful idea Has anyone considered the security ramifications? What about privacy? http://www.fastcodesign.com/3052012/this-device-will-turn-your-clunker-into-a-smar...

DtSR Episode 166 - Cyber Security From Board Room to White House 26.10.2015

In this episode... Raf sits down with Howard Shmidt to talk about Cyber Security from the public to private sectors and everything in between. Howard & Raf talk through challenges of cyber security in the board room Howard gives us some of the challenges that government faces, from his experience Don't miss this episode!   Guest Howard A. Schmidt ( @HowardAS ) -  Former Supervisory Specia...

DtSR Episode 165 - NewsCast for October 19th, 2015 19.10.2015

In this episode... Standard & Poor's Adding Cybersecurity to Ratings The headline In a report issued this week, the rating agency says it could issue a downgrade before a cyberattack if a bank looked ill-prepared, or following a breach that causes significant damage to a bank's reputation or which leads to substantial monetary losses or legal damages. Behind the curve? Stop. Michael...

DtSR Episode 164 - 3rd Party and Supply Chain Risks 12.10.2015

In this episode... Raf asks why we talking about global supply chain, 3rd party risk again Josh discusses what little things we are not thinking about today, that we should Josh discusses what happens as companies move critical data to the cloud We discuss regional IT in a global data world Raf opens up the “tiny company 3rd party” can of worms We discuss the cyber crime survey and CISO board repo...

DtSR Episode 163 - NewsCast for October 5th, 2015 05.10.2015

In this episode... Patreon got hacked, but it's OK This is a lesson in how to do security in a reasonable manner Great response, good security https://www.patreon.com/posts/important-notice-3457485 The double-edged blade of the DMCA could have helped VW cheat emissions Reverse-engineering illegal Definitions of 'researcher' and further 'independent researcher' are interest...

DtSR Episode 162 - OSINT and Privacy in a Digital World 28.09.2015

In this episode... Kirby tells us what OSINT is We discuss how much we are giving away on digital channels? We discuss if there is such a thing as anonymity anymore Location sharing in apps — the bad, the ugly, the scary Kirby and Michael discuss “checking up on your executives” Raf talks about “logo pages” — why do these still exist?! Kirby gives us some thoughts on OPSEC Kirby leaves us with a d...

DtSR Episode 161 - NewsCast for Sept 21st, 2015 21.09.2015

On this episode of the NewsCast Intel forms new Automotive Security Research Board (ASRB) to focus on security of their automotive platform http://newsroom.intel.com/community/intel_newsroom/blog/2015/09/13/intel-commits-to-mitigating-automotive-cybersecurity-risks Good security as a competitive advantage? Interesting development in the effort to secure cars as a technology platform Appeals court...

DtSR Episode 160 - Leadership from a Navy SEAL 14.09.2015

In this episode... Brandon, Michael and I discuss the challenges of leadership and how leadership is more than just telling people what to do. Brandon gives us some of his back-stories and anecdotes to illustrate his points on leadership along the way. I promise you'll love this episode, and I highly encourage you to go donate what you're able to, to Red Circle Foundation ( http://redcir...

DtSR Episode 159 - NewsCast for Sept 7th 2015 07.09.2015

In this episode Court strikes down Wyndham's challenge to FTC power We have covered this before Wyndham argued due proces and lack of case law - asked for dismissal Court said no dismissal, FTC has standing FTC is arguing that Wyndham made promises it did not keep Should be interesting to watch this go to court (or likely not) http://www.csoonline.com/article/2975915/data-breach/wyndham-vs-ft...

DtSR MicroCast 08 - Conference Engagement 01.09.2015

In this MicroCast, live from HTCIA Conference 2015 in Orlando, FL, Michael and I quickly set the stage for a conversation on conference speaker/attendee engagement.  [Raf] One of my biggest pet peeves as a speaker is getting a room-full of people who watch (and listen) me speak, wait for me to finish, and leave when I'm done. [Michael] As an attendee, you need to know what you "do"...

DtSR Episode 158 - Managing Security with Outsourced IT 31.08.2015

In this episode... We discuss what life is like as the CISO when you have all the responsibility for, but no administrative access (or hands on keyboard) Brandon tells his story about how his IT organization went from in-house, to out-house, and how they got where they are Brandon tells us the process and strategy he uses to get a handle on his security We discuss why visibility is one of the most...

DtSR Episode 157 - NewsCast for Aug 24th, 2015 24.08.2015

In this episode... Just when you thought America's neutered "chip & sign" was a safe http://krebsonsecurity.com/2015/08/chip-card-atm-shimmer-found-in-mexico/ Admittedly we put these stories in here just to get Michael all fired up Ashley Madison's data and source code and  CEO's email spool now released and public http://www.theregister.co.uk/2015/08/20/ashley_madison...

DtSR Episode 156 - Leadership Defined Measured and Discussed 17.08.2015

In this episode... We discuss the ever-growing need for strong leadership in security I ask whether experience and longevity in a position naturally brings leadership qualities We talk through how leadership interplays with other competencies Michael asks whether the security leader has a place at the executive table (the "big kids table") Michael asks if the MBA has value in security le...

DtSR Episode 155 - NewsCast for Aug 10th, 2015 10.08.2015

In this episode... The Belgian government's internal phishing test has "gone off the rails" a bit Used a legitimate entity to test against Panic and hilarity ensued, but mostly panic http://www.networkworld.com/article/2951514/security/belgian-government-phishing-test-goes-offtrack.html British ICO makes a 180,000 pound fine Disconnect between policy and reality Was anything lost? 2...

DtSR Episode 154 - Enterprise Software Security Reloaded 03.08.2015

In this episode Raf asks - Why haven’t we solved the same old software security bugs? James asks how a security team gets out of the way and still get better security? We discuss threat modeling, and channel a bit of John Steven Jeff talks about the OWASP ESAPI and standard security libraries and controls Jeff talks about “libraries with known vulnerabilities” and the role of open source component...

DtSR Episode 153 - NewsCast for July 27th, 2015 27.07.2015

In this episode... "Hackers remotely kill a Jeep!" Lots to talk about Basics of segmentation weren't followed, aren't followed Discussion on software 'fitness' and liability http://www.cato.org/blog/hackers-remotely-kill-jeep Firefox blocks Flash and FaceBook calls for its death Should it concern you that FireFox can change your config without your permission or an up...

DtSR Episode 152 - The Great InfoSec Talent Shortage 20.07.2015

In this episode Talent shortage - is it real, and how bad is it? We discuss: what does negative unemployment actually mean? Michael asks- ecurity is still relatively new, how do we determined what “qualified” means? What skills are necessary to be a good security professional? Hiring - we discuss how we get better at screening potentially qualified employees We discuss how we can vet out real expe...

DtSR FeatureCast - HTCIA International Conference 2015 Preview 15.07.2015

In this episode...   Peter Morin joins us to talk through the upcoming HTCIA International 2015 Conference in sunny Orlando, Florida. We talk through a preview of talks, events, and some interesting reasons you should be going to HTCIA Int'l Check out the incredible lineup of keynotes, speakers and talks - http://www.htciaconference.org/ Come see the #DtSR crew live and in person as we record...

DtSR Episode 151 - NewsCast for July 13th, 2015 13.07.2015

In this episode... Appears as though Windows 10 WiFi Sense could have some issues with WiFi -- more on this as it develops Why is the default opt-in, and why in the world do I have to change my SSID to opt out?! Is it really a good idea to use an SSID to describe security constraints on your network? (Hint: NO) http://www.computing.co.uk/ctg/news/2415787/windows-10-wi-fi-sense-security-warning-ove...

DtSR Episode 150 - A CEOs Perspective 06.07.2015

In this episode We take a little peek inside the mind of a CEO, from the security perspective We discuss the state of information security in the last decade Dan shares his wisdom on how the role of a security professional and security leadership has changed over the course of his career We discuss about the talent shortage - and get an in-depth look at solving some of this problem Dan shares with...

Listen to the Down the Security Rabbithole Podcast (DtSR) podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.