Rafal (Wh1t3Rabbit) Los

Down the Security Rabbithole Podcast (DtSR)

News EN ↓ 750 episodes

This is Cybersecurity's premier podcast. Running strong since 2011 Rafal Los, James Jardine, and Jim Tiller bring a no-nonsense, non-commercial approach to our profession. DtSR brings interviews and discussion with people you want to meet, and stories you have to hear. So whether you're just starting out, or are decades deep into your career, you'll always learn something on this show. On Twitter/X: https://twitter.com/@DtSR_Podcast On YouTube: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHq On LinkedIn: https://www.linkedin.com/company/down-the-securit...

Author

Rafal (Wh1t3Rabbit) Los

Category

News

Podcast website

blogwh1t3rabbit.medium.com

Latest episode

Jul 7, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

DtSR Episode 125 - NewsCast for January 12th, 2015 13.01.2015

Welcome to a new year of the Down the Security Rabbithole Podcast! We are kicking off this year with a guest on this morning's program, Phil Beyer  joined us to talk about the last few weeks that have been a wild, wild ride in the security indsutry! Thanks for your support so far, and we promise a fantastic 2015 to come.   Topics Covered Sony. Sony. Sony. It's all anyone can talk about!...

DtSR Episode 124 - PCI DSS and Security (Yes, Really) 05.01.2015

Hi everyone! Welcome to the very first episode of the Down the Security Rabbithole Podcast for 2015! On this opening episode, Jeff Man joins us to talk truth to power on PCI-DSS and shatters myths for us.   In this episode Jeff tackles some common misunderstandings about PCI The crew discusses PCI – what’s right about it and what’s wrong about it Jeff tells us why he believes if you’re secure you’...

DtSR FeatureCast - 2014 Year in Review 29.12.2014

Hey everyone! We're almost done with 2014 and another new year is right around the corner. We thought this was the perfect time to sit back, relax a little and reflect on the year that was...and boy was it ever! Jack Daniel  & Allison Miller  join Michael, James and I on the podcast to talk it all out, share a few chuckles and try to make sense of it all!   Thanks for listening everyone,...

DtSR FeatureCast - US vs. Salinas ft. Shawn Tuma 22.12.2014

In this episode Attorney and CFAA expert Shawn Tuma joins us to talk about the US vs. Salinas case where Mr. Salinas was threatened with 440 years in jail, and now plead down to a misdemeanor. Prosecutorial discretion, or attorneys-gone-wild? Link:  http://www.wired.com/2014/11/from-440-years-to-misdemeanor/ Have something to say? Let's hear it. Support the show >>> Please consider cl...

DtSR Episode 123 - NewsCast for December 15th, 2014 15.12.2014

Topics covered The unfolding case of the Sony Pictures Entertainment breach http://blog.wh1t3rabbit.net/2014/12/when-press-aids-enemy.html http://www.thedailybeast.com/articles/2014/12/12/shocking-new-reveals-from-sony-hack-j-law-pitt-clooney-and-comparing-fincher-to-hitler.html http://www.csoonline.com/article/2857455/business-continuity/fbi-says-theres-nothing-linking-north-korea-to-sony-hack.ht...

DtSR Episode 122 - Enterprise Architecture's Role in Security 08.12.2014

In this episode Michelle explains to us what Enterprise Architecture is, and what it isn't Michelle gives her take on how both security and enterprise architecture both support each other We discuss the roll of standards, standards, standards - and why you can't have security without it We talk about GRC We talk through roles & responsibilities definition between security, architectu...

DtSR Episode 121 - NewsCast for December 1st, 2014 01.12.2014

Topics covered Sony Pictures is having a very, very bad couple of days - and it could keep getting worse. http://www.theverge.com/2014/11/24/7277451/sony-pictures-paralyzed-by-massive-security-compromise http://www.csoonline.com/article/2852982/data-breach/sales-contracts-and-other-data-published-by-sonys-attackers.html A newly discovered (but old) comment bug in Wordpress affects ~86% of sites. T...

DtSR Episode 120 - Hacking the Human (again) 24.11.2014

In this episode We revisit the 'human' side of hacking Chris tells us all about the Defcon CTF his team has hosted We discuss the role human nature plays in social engineering, or "Why the bad guys always win" Chris gives us his tips for making it harder for social engineers Michael and Chris talk metrics and measuring "getting better"   Guest Chris Hadnagy (  @HumanH...

DtR Episode 119 - NewsCast for November 17th, 2014 17.11.2014

Note:  The hashtag for the show on Twitter has changed, please connect with us using  #DtSR  going forward. Thanks!   Topics covered Update: Home Depot breach (Hint: apparently it was a 3rd party entry point) Story:  http://www.computerworld.com/article/2844491/home-depot-attackers-broke-in-using-a-vendors-stolen-credentials.html Apparently as a reaction, all execs are being switched to iDevices (...

DtR Episode 118 - Demystifying Threat Intelligence 10.11.2014

In this episode Adam and Dmitri discuss what is (and what isn't) threat intelligence We discuss strategic, tactical and operational security intelligence Who is using threat intelligence, and how? Adam talks about the success factors, key points, and trends Michael asks how an organization can know whether they're READY for a threat intelligence program Adam explains the term "finis...

DtR FeatureCast - Norse Corp DDoS - Nov 7 2014 07.11.2014

In this episode Jeff explains a little bit about who Norse is, and why they were potentially targeted with a DDoS We discuss what a DDoS is, how it becomes effective, and what methods/tools attackers use (in this case SNMP v2 reflection) We talk about threat intelligence (reputational intelligence) and how companies and intelligence platforms can leverage this data to decrease risks actively Guest...

DtR Episode 117 - NewsCast for November 3, 2014 03.11.2014

Topics covered Banks urging shoppers not to avoid breached retailers - Companies that get breached impact card holders minimally, at least as far as we can tell, right? http://www.kcentv.com/story/26887771/local-bank-leaders-no-need-to-avoid-hacked-retailers-during-holidays Federal officials (FBI, US SS) are making a big push to be your source for cyber-security help - Interesting that this comes...

DtR Episode 116 - Lines in the Sand on Security Research 27.10.2014

In this episode Chris attempts to explain the consternation with 'security research' right now Kevin gives his perspective and why he doesn't quite understand why people don't see they're "breakin' the law" Shawn discusses what parts of the CFAA he would like to see reformed James drops the question - "What is a security researcher?" ..and rants a...

DtR Episode 115 - NewsCast for October 20th, 2014 20.10.2014

Topics covered The FBI paid a visit to the " researcher " who revealed (and tinkered with) the hacked Yahoo! servers - we discuss the various aspects of this case, which we've been going round and round on lately http://www.wired.com/2014/10/shellshockresearcher/ US Cyber Security Czar Michael Daniel wants us passwords gone, replaced by .... "selfies"; We wish we were maki...

DtR Episode 114 - Threat and Vulnerability Management 13.10.2014

In this episode Ron gives us a brief history of Tenable and TVM for the enterprise Ron answers "How do you make network security obtainable and defendable?" We discuss TVM as a fundamental principle to many other security program items Ron tells us what the modern definition of "policy" is We discuss some hurdles and challenges of TVM programs in an enterprise We note that secu...

DtR Episode 113 - NewsCast for October 6th, 2014 06.10.2014

Topics covered The petition on WhiteHouse.gov titled "Unlock public access to research on software safety through DMCA and CFAA reform" and ...well we talk about it with an attorney and some necessary skepticism https://petitions.whitehouse.gov/petition/unlock-public-access-research-software-safety-through-dmca-and-cfaa-reform/DHzwhzLD My take:  http://blog.wh1t3rabbit.net/2014/10/to-ref...

DtR FeatureCast - CFAA, Shellshock and Security Research - October 2nd 2014 02.10.2014

Thank you to Shawn Tuma - an attorney specializing in CFAA and a good friend of our show - for stopping by and lending his expertise on this episode. If you enjoy Shawn's insights, consider following him on Twitter ( @ShawnETuma ) or just saying hello!   In this episode We discuss the CFAA in regards to Robert Graham's brilliantly written blog post on the topic - http://blog.erratasec.co...

DtR Episode 112 - DREAMR Framework 29.09.2014

In this episode DREAMR: What is it, and why is it so important to Enterprise Security today? Examples of aligning business and security requirements and winning hearts & minds How does a security organization get around "see I told you so!" security An example of how to make the framework work for you We discuss the importance of listening, then listening, then listening some more Je...

DtR Episode 111 - NewsCast for September 22nd, 2014 22.09.2014

Topics covered Hacker flees US for non-extradition country - why? http://blog.erratasec.com/2014/09/hacker-weev-has-left-united-states.html http://www.newrepublic.com/article/117477/andrew-weev-auernheimers-tro-llc-could-send-him-back-prison Class-action lawsuit againt Onity lock company ("easily hackable hotel lock") rejectd by judge https://www.techdirt.com/articles/20140903/1413452840...

DtR Episode 110 - Red Dragon Rising 15.09.2014

In this episode Separating the hype from reality of the Chinese hacking threat The escalation of economic tensions between US & China, over hacking What is the advice for the enterprise regarding state-sponsored attacks? The challenge with the uni-directional intelligence flow for government/enterprise The challenge with nation-state hacking of critical infrastructure The worst-case scenario (...

DtR Episode 109 - NewsCast for September 8th, 2014 08.09.2014

Topics covered Apple has been making news, issuing guidance, and refuting a hack - all around iCloud http://www.padgadget.com/2014/09/03/apple-warns-developers-not-to-store-health-data-in-icloud/ http://www.padgadget.com/2014/09/03/apple-says-celebrity-photo-leak-was-not-due-to-icloud-breach/ http://www.cio-today.com/article/index.php?story_id=94027 HealthCare.gov was hacked, but no worries it was...

DtR Episode 108 - Security in State Government 01.09.2014

In this episode We discuss the largest challenges in the state government sector Brian discusses balancing the need for openness versus security/secrecy Phil talks about the challenge of balancing policy with agency needs in state government Michael asks how state-level security justifies and prioritizes security requirements Raf asks how policy is created that can be both effective, and broad The...

DtR Episode 107 - NewsCast for August 25, 2014 25.08.2014

Topics covered Community health systems and UPS Stores breached - an analysis and contrast of the two breaches, the data, and the common message http://regmedia.co.uk/2014/08/18/community_health_systems_8k.pdf http://blogs.wsj.com/cio/2014/08/20/the-morning-download-community-health-systems-breach-stirs-up-heartbleed-fears/ http://time.com/3151681/ups-hack/ The case of the pre-mature declaration o...

DtR Episode 106 - My Compliance is Better Than Your Security 18.08.2014

In this episode Jason tells us why he isn't hating on compliance Jason talks about how security people are often the source of the issues Jason gives us his perspective on compliance-driven security Jason correlates compliance to quality assurance in security We talk about security's unbroken streak of failing at the basics We lament poor metrics, why we suck at them, and what comes next...

DtR Episode 105 - NewsCast for August 11, 2014 11.08.2014

Topics covered Survey shows CISOs still struggle for respect (from business peers) http://www.cio.com/article/2460165/security/cisos-still-struggle-for-respect-from-peers.html Hold Security uncovers 1.2  billion password heist on Russian hacker sites (but something smells funny) - draw your own conclusions folks... I'd love to hear 'em http://www.theverge.com/2014/8/6/5973729/the-problem...

Listen to the Down the Security Rabbithole Podcast (DtSR) podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.