Rafal (Wh1t3Rabbit) Los

Down the Security Rabbithole Podcast (DtSR)

News EN ↓ 750 episodes

This is Cybersecurity's premier podcast. Running strong since 2011 Rafal Los, James Jardine, and Jim Tiller bring a no-nonsense, non-commercial approach to our profession. DtSR brings interviews and discussion with people you want to meet, and stories you have to hear. So whether you're just starting out, or are decades deep into your career, you'll always learn something on this show. On Twitter/X: https://twitter.com/@DtSR_Podcast On YouTube: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHq On LinkedIn: https://www.linkedin.com/company/down-the-securit...

Author

Rafal (Wh1t3Rabbit) Los

Category

News

Podcast website

blogwh1t3rabbit.medium.com

Latest episode

Jul 7, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

DtSR Episode 149 - NewsCast for June 29th 2015 29.06.2015

In this episode With me gone, James and Michael run feral! It's June, so here are the top 3 security priorities for CISOs for 2015 (yes in June) http://www.information-age.com/technology/security/123459699/top-3-security-priorities-cios-2015 Boils down to: patch faster, improve credentials, code better Is this the right list?  It mentioned side-stepping cloud and mobility. What if migrating t...

DtSR Episode 148 - Focus on the CISO 22.06.2015

In this episode... What is the Security Advisor Alliance? We discuss some of the issues facing CISOs today Clayton gives us his perspective on how to solve some of those issues Clayton tells us about the mission of the SAA If your'e a CISO, are you signed up for the SAA Summit?  Shoot Clayton an email   Guest Clayton Pummill ( @cp48isme )  - https://www.linkedin.com/pub/clayton-pummill/10/32a...

DtSR Episode 147 - NewsCast for June 15th, 2015 15.06.2015

In this episode... Facebook has released PGP-encryption-enabled email communications The anti-privacy platform will now encrypt emails to you if you give them your PGP public key Does no one see the insane irony here? http://www.theregister.co.uk/2015/06/01/facebook_pgp_support/ White House issues mandate for HTTPS (by default) for all federal websites "By the end of 2016" Is this a good...

DtSR Episode 146 - State of Enterprise Incident Response 08.06.2015

In this episode... Defenders are set up to fail? how and why How do we fill forensics and IR positions? What skills and qualifications do forensics/IR need to have? How can enterprises get better at IR from where they are today? How do we solve some of the problems plaguing the security industry?   Guest Andrew Case ( @attrc  ) -  Andrew Case is a senior incident response handler and malware analy...

DtSR Episode 145 - NewsCast for June 1st, 2015 01.06.2015

Apologies to anyone who is having issues downloading this episode! In this episode... The ACLU encourages the government to get into bug bounties Read the original letter:  https://www.aclu.org/sites/default/files/field_document/aclu_-_iptf_recommendations_submitted.pdf Points 1 & 2 are at sane Point 3 makes a hard left into into crazy-town http://thehill.com/policy/technology/243265-aclu-says...

DtSR Episode 144 - Insights from the ISC2 2015 Survey 25.05.2015

In this episode... David Shearer, Executive Director for ISC2 joins us to talk about the results of the  ISC2 2015 Information Security Workforce Study We ask David to highlight some of the results We discuss how malware and application security were identified as top threats 3 years in a row -- and what's to be done about this We discuss the major discrepancy between priorities from this sur...

DtSR Episode 143 - NewsCast for May 18th, 2015 18.05.2015

In this episode... Netflix launched FIDO (not that one, or that one, no the other one) Focused on automating incident response practices FIDO is an orchestration layer that automates the incident response process by evaluating, assessing and responding to malware and other detected threats. If you don't use it, at least they provide a structured framework for response and IR workflow http://t...

DtSR Episode 142 - Basics and Fundamentals, That Win 11.05.2015

In this episode... A quick walk-through of Rob’s talk (“Hacker ghost stories”), and why it’s completely relevant today Simple things that work blocking java (externally) effectively blocking “uncategorized” sites in your forwarding proxies (not) resolving DNS internally (not) default routing to the Internet from inside canaries in the coal mine, or evil canaries Guests James Robinson ( @0xJames  )...

DtSR Episode 141 - NewsCast for May 4th, 2015 04.05.2015

In this episode... A join Ponemon Institute & IBM Security study shows that, surprise surprise, developers are "neglecting security" The study only looked at mobile apps and app developers Less than half (of their study) test the mobile apps they build About 33%  never test their apps http://www.eweek.com/developer/ibm-study-shows-mobile-app-developers-neglecting-security.html Illino...

DtSR Episode 140 - Ethics of Hacking Live from AtlSecCon 2015 27.04.2015

In this episode... What about public safety, where do we draw the line on open research? Self-regulation? Disclosure? What are our options… What makes a researcher? We discuss “Chilling security research” A quick dive into bug bounty programs; do they help? Ethics vs. moral compass …we discuss Hacker movies, and what they’re doing for our profession Guests Keren Elezari ( @K3r3n3 ) -  brings years...

DtSR Episode 139 - NewsCast for April 20th, 2015 20.04.2015

In this episode... Friend and security researcher Chris Roberts steps into it...  A poorly-conceived tweet, followed by mass hysteria Most everyone talking about this is missing the point entirely Of course, the EFF jumps in to keep from "chilling research" (roll eyes) h ttp://www.usatoday.com/story/tech/2015/04/19/chris-roberts-one-world-labs-united-rsa-computer-security-tweets/26036397...

DtSR Episode 138 - Useful Knowledge on Intelligence 13.04.2015

In this episode... Where do you even start with “threat intelligence”? Ryan talks about context, and why it’s *the* most important thing when it comes to threat intel How does a SME make use of a “luxury item” like threat intelligence? Michael asks what are 1-2 things you can do *immediately* as an SME? What are the basics, beyond the basics of security? Where do you make your first investment? Ge...

DtSR Episode 137 - NewsCast for April 6th, 2015 06.04.2015

In this episode... TrueCrypt security audit results are good news, right?  Why are some of the most depended-upon  http://arstechnica.com/security/2015/04/truecrypt-security-audit-is-good-news-so-why-all-the-glum-faces/ At Aetna, CyberSecurity is a matter of business risk Jim Routh talks about how he runs a security program Security  is a matter of  business risk, if not you're doing it wrong...

DtSR Episode 136 - Crypto and Privacy with Jon Callas 30.03.2015

In this episode... Jon Callas gives a little of his background and his current role We talk through why cryptography is so hard, and so broken today Jon overviews compatibility, audit and making cryptography useful Jon brings up open source, security, and why "open is more secure" is bunk We talk through "barn builders" vs. "barn kickers" and why security isn't i...

DtSR Episode 135 - NewsCast for March 23rd, 2015 23.03.2015

Remember folks, as you listen reach out to us on Twitter and hit the hashtag #DtSR to continue the conversation, and speak your mind! Let's hear what your take is on the stories we discuss...maybe you have a unique angle we've not considered? In this episode-- Target settled class-action lawsuit over its data breach - for $10M USD Who wins? Lawyers, clearly the lawyers Burden of proof on...

DtSR Episode 134 - Fundamental Security 16.03.2015

In this episode... Michael C and the team talk bout "going back to basics" and the need for security fundamentals Michael C talks a little about why we (security professionals) fail at fixing problems at scale We dive into the need for automation, and Michael C talks about why creating more work for security professionals is a bad thing Michael C and the crew talk through why many of our...

DtSR Episode 133 - NewsCast for March 9th, 2015 09.03.2015

In this episode-- Law firm hit and crippled by ransomware, decides it's not paying the ransom. They aren't quite sure what got encrypted But they have backups... ..and data was likely not exfiltrated http://news.softpedia.com/news/Ransomware-Hits-Law-Firm-Encrypts-Workstation-and-Server-474788.shtml Major law firms for ISAC to fight off adversaries, share intelligence Catching up to the...

DtSR Episode 132 - Good Guys, Bad Guys, and Reality 02.03.2015

In this episode... We learn the origins of "RSnake" as told by Rob himself Rob gives us a peek into the dark side, from his contacts and experiences We discuss the black-hat economy as it's verticalized, specialized, and matured Rob discusses the balancing act of the good vs. bad and why the situation is as bad as it needs to be We discuss some of the things businesses and defenders...

DtSR Episode 131 - NewsCast for February 23rd, 2015 23.02.2015

In this episode-- Would you be OK with your credit card company tracking you, to decrease fraud rates? Visa wants to track your smartphone. http://triblive.com/business/headlines/7774328-74/visa-card-fraud Your stolen healthcare data is increasingly being sold on the black market http://www.ihealthbeat.org/articles/2015/2/19/security-experts-health-data-increasingly-being-sold-on-black-market Leno...

DtSR Episode 130 - Where Law and Cyber Collide 16.02.2015

In this episode Traveler's Insurance files suit against a web developmeent company for failing to provide adequate security, resulting in a breach of one of its customers http://www.law360.com/articles/614158/travelers-blames-web-designer-in-bank-website-data-breach We discuss whether security standards are now "implied"? Does Traveler's have any standing to sue? (Shawn thinks...

DtSR Episode 129 - NewsCast for February 9th, 2015 09.02.2015

Topics covered Massive breach at American Health Insurer Anthem - from the "haven't we done this once before?" department as Queen - Another One Bites the Dust plays in the background https://gigaom.com/2015/02/05/oops-another-big-data-breach-this-time-at-anthem/ http://money.cnn.com/2015/02/05/investing/anthem-hack-stocks/index.html?sr=twmoney020615anthemwallst0600story (Obligatory...

DtSR MicroCast 07 - Taking Security Seriously 08.02.2015

This is the 7th installment (call it a rebirth) of the MicroCast. Short and to the point, Michael and James talk about the phrase breached companies use - " We take your security seriously... "  .. join the conversation at #DtSR on Twitter! Have something to say? Let's hear it. Support the show >>> Please consider clicking the link above to support the show! -=-=-=-=-=-=-=-=...

DtSR Episode 128 - When Breach, Buy the Dip 02.02.2015

Fans - If you haven't booked your ticket for InfoSec World 2015 in sunny Orlando, FL check this out. Register using our code CLD15/RABBIT for 15% off. If you want a chance to go for FREE, listen to Episode 127 for your chance!   In this episode... John gives us a little lesson on markets, and why they move up/down, commentary for the information security professional John discusses what #BTFD...

DtSR Episode 127 - NewsCast for January 26th, 2015 26.01.2015

** There is a special gift for our listeners in this episode, from our friends at InfoSec World 2015! Listen to find out how you can  go for free .  We have a promo code! CLD15/RABBIT – 15% off for “Down the Rabbit Hole” listeners Topics Covered Google picks up really big rocks, but lives in a glass house. As Google drops zero-day on Apple and Microsoft they respond with a lame excuse as to why th...

DtSR Episode 126 - The Defense Always Loses 19.01.2015

In this episode... The blog post that started it all -  http://blog.norsecorp.com/2014/11/10/the-new-reality-in-security-offense-always-wins-and-defense-always-loses/ Vince, tells us what he means by "Offense always wins, defense always loses" We disagree over this snip from his blog post: "To “win” in cyber security, defense must be right 100% of the time, while offense only has to...

Listen to the Down the Security Rabbithole Podcast (DtSR) podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.