Rafal (Wh1t3Rabbit) Los
Down the Security Rabbithole Podcast (DtSR)
This is Cybersecurity's premier podcast. Running strong since 2011 Rafal Los, James Jardine, and Jim Tiller bring a no-nonsense, non-commercial approach to our profession. DtSR brings interviews and discussion with people you want to meet, and stories you have to hear. So whether you're just starting out, or are decades deep into your career, you'll always learn something on this show. On Twitter/X: https://twitter.com/@DtSR_Podcast On YouTube: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHq On LinkedIn: https://www.linkedin.com/company/down-the-securit...
Author
Rafal (Wh1t3Rabbit) Los
Category
Podcast website
Latest episode
Jul 7, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
DtR Episode 104 - JW Goerlich - Security Leaders Series 04.08.2014 34:42
In this episode Who is J.W. Goerlich (redux from episode - How did he get to where he is now? How does the security executive deal with the "moving finish line"? JW discusses how 'security' people can break down barriers between "us" and "them" We discuss why we still fail at the basics, and what all this means... JWG tries to talk about his favorite contro...
DtR Episode 103 - NewsCast for July 28th, 2014 28.07.2014 39:52
Topics covered Certificate pinning back in the spotlight with the GMail iOS app having some difficulties, but there is a bigger issue here. We discuss. http://securityaffairs.co/wordpress/26577/hacking/gmail-app-flaw-mitm.html Nearly 3 years later, the NASDAQ hack attributed to FSB/Russian 'state sponsored' hackers, via 2 "zero day malware'. Highlighting need for attribution, c...
DtR Episode 102 - Security Leaders Series - Jim Tiller 21.07.2014 41:52
In this episode Jim Tiller - a few things you probably didn't know? In the last 15 years, what has changed, and what hasn't? Why isn't security moving forward? "Complexity is the camouflage for bad guys" -Jim Chasing the moving line of 'security' "Fixing the airplane as it flies" How do enterprise security organizations push away from playing 'prev...
DtR Episode 101 - NewsCast for July 14th, 2014 14.07.2014 45:49
Topics covered Florida Information Protection Acf of 2014 is in the books, and it brings "sweeping changes" to the data breach disclosure process in Florida. Good thing or bad? You decide http://www.scmagazine.com/fla-passes-sweeping-data-breach-notification-bill/article/357858/ http://www.flsenate.gov/Session/Bill/2014/1526/?Tab=RelatedBills http://www.flsenate.gov/Session/Bill/2014/152...
DtR Episode 100 - Security Wisdom from Dan Geer 07.07.2014 1:00:35
In this episode Who is Dan Geer (just in case you live in a cave and don't know) Dan's definition of security - "The absence of unmitigatable surprise" What exactly is the pinnacle goal of security engineering? Responsibility, liability and when software fails as a result of security issues In a liability lawsuit - "What did you know, when did you know it?" The fracti...
DtR Episode 99 - NewsCast for June 30th, 2014 30.06.2014 48:19
Topics covered Your server may have a hardware flaw that exposes your baseband management interface to the world - http://arstechnica.com/security/2014/06/at-least-32000-servers-broadcast-admin-passwords-in-the-clear-advisory-warns/ Airports are getting hacked, APT involved, state-sponsored attackers! - http://www.nextgov.com/cybersecurity/2014/06/nation-state-sponsored-attackers-hacked-two-airp...
DtR Episode 98 - Grr (Grr Rapid Response) 23.06.2014 46:21
In this episode What exactly is "GRR"? What sorts of things can GRR do? What is a hunt, and how does it scale across tens of thousands of machines? How does GRR "hide" from malware? How does GRR keep some of the great power it has from being abused? Automating and integrating GRR with external sources and tools Features, functions, capabilities and some magic from Greg The futu...
DtR Episode 97 - NewsCast for June 16th, 2014 16.06.2014 52:02
Note : I want to thank Will Gragido for stopping by this morning to talk over the news with us. Always great to have someone with a fresh perspective, I hope you enjoy the show. Topics Covered Don't like Google Glass (or similar devices) on your network? Kick them off - http://mashable.com/2014/06/04/glassholes-wifi-jamming/ The FAA has issued an order for Boeing to 'protect the plan...
DtR Episode 96 - A CIO Talks About CISOs 09.06.2014 37:07
My apologies for some of the skips in this episode - we had some difficulty with the recording and ultimately I hope it doesn't take away from Joe's wonderful message. Thanks for your patience. In this episode From CISO to CIO - making that leap Does the CISO need to be technical? (answering that question, again) What types of things does a CIO need to know? Who should the CISO report to...
DtR Episode 95 - NewsCast for June 2nd, 2014 02.06.2014 47:26
Note: Today, Kim Halavakoski joined us on the show to provide perspective all the way from Finland! We appreciate his international addition to the show, and hope the listeners enjoy the added brainpower. Topics covered Facebook's next major update will turn your mobile device into an always-on listening tool for FaceBook. This is a good time to remind you that you are the product, not th...
DtR Episode 94 - ICANN, Tor, and Internet Freedom 26.05.2014 41:37
In this episode Jeff explains the background of the relationship between the US government, ICANN and IANA What is the ITU and why is this $0 contract handoff to the ITU such a big deal? What impact did Edward Snowden's actions have on the issue? The potential issues with DNS, cross-border censorship and DNS The importance of Tor, Freenet and challenges of implementation Discussing the evolut...
DtR Episode 93 - NewsCast for May 19th, 2014 19.05.2014 41:51
Announcements: I want to thank Circle City Con as a sponsor for the show! I have one more ticket to give away ... so watch the #DtR hashtag on Twitter! Thanks to special guest Philip Beyer for sitting in James' seat this morning... Topics discussed "US charges China with cyber-spying on American firms" (Hello, pot? this is the kettle...) - http://www.nbcnews.com/news/us-news/u-...
DtR Episode 92 - Rapid Incident Response [Guests: Robin Jackson, Dan Moore] 12.05.2014 31:35
In this episode Dan gives us the reality of living in what is commonly termed "the post-breach" world Dan and Robin talk through the explosion in the numbers of malware samples We discuss the different approaches to malware, crimeware, and the cross-over between them Dan explains what "rapid incident response" really means and why it's essential Dan and Robin give us some...
DtR Episode 91 - NewsCast for May 5th, 2014 05.05.2014 40:49
Topics dicussed Microsoft has issued a patch for the massive MS IE flaw - for WindowsXP ! - http://arstechnica.com/security/2014/05/microsofts-decision-to-patch-windows-xp-is-a-mistake/ Is Open Source Software more or less secure than closed-source? (in a post-Heartbleed era ) - http://www.telegraph.co.uk/technology/internet-security/10769996/Heartbleed-the-beginning-of-the-end-for-open-source....
DtR Episode 90 - Things Your Auto Insurance Knows [Anonymous guest] 28.04.2014 26:25
In this episode We discuss some of the new techniques auto insurance companies are using to custom-tailor rates to drivers Our guest discusses some of the capabilities of the widgets available Our guest discusses the 'call home' functions, and potential mis-use We use 'big data' seriously We talk about 'big data' and security - for real Our guest gives us a realistic...
DtR Episode 89 - NewsCast for April 21st, 2014 21.04.2014 33:51
Topics discussed The big story - "Heartbleed" http://www.csoonline.com/article/2142626/security-leadership/how-you-need-to-respond-to-heartbleed-and-how-you-can-explain-it-to-others.html http://www.csoonline.com/article/2146141/disaster-recovery/healthcare-gov-urges-password-resets-due-to-heartbleed.html http://xkcd.com/1354/ http://rt.com/news/heartbleed-arrest-canada-security-016/ The...
DtR Episode 88 - Advanced Threat Actors [Panel Discussion] 14.04.2014 54:27
In this episode Advanced Threat Actors - more or less a threat right now than before? ( how much is hype? ) Advanced Persistent Threat - is it really THAT advanced? ( a "what" or a "who"?) The distinction of what "APT" is ...and isn't Touching on Mandiant APT-1 ...hype from reality A quick discourse on corporate espionage! How we respond to APTs ... is this jus...
DtR Episode 87 - NewsCast for April 7th, 2014 08.04.2014 33:02
Topics covered WindowsXP is officially, for real, definitely end of life - http://windows.microsoft.com/en-us/windows/end-support-help Google Nest pushes update - examining the bigger picture - http://www.theregister.co.uk/2014/04/04/nest_waves_goodbye_to_alarm_switchoff_feature/ South Carolina's agencies are still not any better after the massive breaches - http://www.wbtw.com/story/25149...
DtR Episode 86 - From DDoS to Quantum Computing [Guest: Prof Alan Woodward] 31.03.2014 47:03
In this episode Rise of DDoS Where did it come from What's next Why does it work Spoofer project 3-DOS attacks Quantum computing What is it How is it different than what we commonly use today What problems does it solve How practical is it The dark web Where did it come from Legitimate uses, turn into nefarious use-cases Alternatives, adoption and options Guest Prof. Alan Woodward ( @ProfWood...
DtR Episode 85 - NewsCast for March 24th, 2014 24.03.2014 46:12
Topics covered The FTC jumps into the breech (pun intended) and may try and levy fines against Target, and future breach victims - http://ww2.cfo.com/technology/2014/03/ftc-urges-data-breach-penalties / http://www.nextgov.com/cybersecurity/2014/03/target-could-face-federal-charges-failing-protect-customer-data-hackers/80824/?oref=ng-channelriver Could the Barclays Bank breach of Feb 2014 have bee...
DtR Episode 84 - Rise of the Security Machines [Guest: Alex Pinto] 17.03.2014 48:56
In this episode what is the promise of automation, and where did we go wrong (or right?) the problems with 'volume' (of logging) and the loss of expressiveness a dive into 'exploratory based monitoring' how does log-based data analysis scale? baselines, and why 'anomaly detection' has failed us does machine learning solve the 'hands on keyboard' (continuous...
DtR Episode 83 - NewsCast for March 10th, 2014 10.03.2014 34:39
Topics covered Target CIO resigns, new central CISO and CCO roles created; but what's really going on here? - http://www.darkreading.com/attacks-breaches/target-begins-security-and-compliance-ma/240166451 & http://pressroom.target.com/news/target-reports-third-quarter-2013-earnings City of Detroit employees' information (including SSNs, DoB, etc) are "at risk" because so...
DtR Episode 82 - Likely Threats [Guests: Lisa Leet, Russell Thomas, Bob Blakley] 03.03.2014 43:15
In this episode Does is make sense, in a mathematical and practical senes, to look for 'probability of exploit'? How does 'game theory' apply here? How do intelligent adversaries figure into these mathematical models? Is probabilistic risk analysis compatible with a game theory approach? Discussing how adaptive adversaries figure into our mathematical models of predictability.....
DtR Episode 81 - NewsCast for February 24th, 2014 24.02.2014 26:29
Topics covered Apple had a "Goto Fail" failure - yes people at Apple Computer still use Goto statements in 2014 - http://www.computerworld.com/s/article/9246533/Apple_encryption_mistake_puts_many_desktop_applications_at_risk and Adam Langley's awesome blog - https://www.imperialviolet.org/2014/02/22/applebug.html Look out Terps, Univ of Maryland has lost 309,000+ staff members,...
DtR Episode 80 - Lies, Damned Lies, and #InfoSec Statistics [Guests: Jay Jacobs, Bob Rudis] 17.02.2014 58:32
In this episode Jay and Bob talk about their new book A discussion on using data as 'supporting evidence' rather than gut feelings Do we have actuarial quality data to answer key security questions? A discussion on "asking the right question", and why it's THE single most important thing to do Bob attempts to ask security professionals to use data we already have, to be da...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.