Rafal (Wh1t3Rabbit) Los
Down the Security Rabbithole Podcast (DtSR)
This is Cybersecurity's premier podcast. Running strong since 2011 Rafal Los, James Jardine, and Jim Tiller bring a no-nonsense, non-commercial approach to our profession. DtSR brings interviews and discussion with people you want to meet, and stories you have to hear. So whether you're just starting out, or are decades deep into your career, you'll always learn something on this show. On Twitter/X: https://twitter.com/@DtSR_Podcast On YouTube: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHq On LinkedIn: https://www.linkedin.com/company/down-the-securit...
Author
Rafal (Wh1t3Rabbit) Los
Category
Podcast website
Latest episode
Jul 7, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
DtR Episode 79 - NewsCast for February 10th, 2014 10.02.2014 38:19
Topics covered In the wake of the Target & Nieman Marcus breaches - is chip+pin really a priority right now, and does it solve the real problem? - http://blogs.csoonline.com/security-leadership/2977/does-chip-and-pin-actually-solve-problem-find-out-asking-these-questions Speaking of Target ... it turns out that 3rd parties really are a problem and still a blind spot in many organizations&apo...
DtR Episode 78 - Legal Professional Privilege [Guest: David Prince] 03.02.2014 41:35
In this episode David discusses what it's like working for a law firm (in the UK) A quick wade through the UK Data Protection Act (mostly Principle 7) "When lawyers get to interpret the laws" Law firms as targets for data breaches The new regulations in the UK, fines between 2%-5% of your REVENUE? Ouch. Defining "adequate measures" in regulations A brief chat on fines, reg...
DtR Episode 77 - NewsCast for January 27th, 2014 27.01.2014 35:51
Special thanks to Michael Santarcangelo ( @catalyst ) for stopping by the show and guest-hosting with James and I! We had fun, and I think you'll all enjoy Michael's perspective and humor. Topics Covered Nieman Marcus breach - all new, same as before, or is it? - http://www.wired.com/threatlevel/2014/01/neiman-marcus-hack/ Coca-Cola loses laptops ... sort of ... but no worries, no evide...
DtR Episode 76 - Payment Industry Turmoil [Guests: Laura Claytor & Alfred Portengen] 20.01.2014 39:42
In this episode Did the Target/Neiman/? breach finally create a catalyst for change? The card system, payment processing infrastructure clearly wasn't designed with defensibility in mind ... who should be changing that? Are today's fraud rates finally getting high enough such that card processors, issuers, banks need to depart from the status quo? Are the days of "zero fraud liabili...
DtR Episode 75 - NewsCast for January 13th, 2014 13.01.2014 41:59
I can't believe it's 2014 already, and we're rolling through our 3rd calendar year! As we grow and you "regulars" mount, James and I want to thank you for listening, bookmarking, sharing and talking about the podcast. Your patronage has really made a us smile, and you're the reason we do this. Topics covered Reuters: Retail community may be ready for a change in the p...
DtR Episode 74 - Supply Chain [In]Security 06.01.2014 48:21
In this episode Chris Wysopal - who is that masked man? Putting some reality to the state-sponsored backdoors (Huawei) and supply-chain compromise The risks coming through the door with the products you buy The case for setting up an independent testing lab for mitigating 'backdoor' accusations Chris does an interesting assessment on software security practices in the enterprise Chris di...
DtR Episode 72 - Applied Threat Research and Defense 23.12.2013 47:19
In this episode Will gives us a lay of the land on the state of "state sponsored" and advanced threats We discuss collective advances in malware We discuss the persistence of 'old' malware, and code re-use We discuss enterprise defense and strategy Will gives us some wisdom from his experiencein helping clients defend themselves Guest Will Gragido ( @wgragido ) - Will is curren...
DtR Episode 71 - The 2013 Year in Review 16.12.2013 1:28:09
Hello! This is a special episode in that it's our year-end wrap-up. We bring together 3 of the industry's best to talk about the year that was, the things that made were on your mind, and maybe give us a hint at what is to come... Guests Will Gragido ( @wgragido ) - Will is the Sr. Manager of threat Research Intelligence for RSA NetWitness and a lightweight with the cold medicine. John P...
DtR Episode 70 - Embedded Systems Shenanigans 09.12.2013 51:04
Folks, if you work with, design, or implement embedded systems this is one episode you don't want to miss. Fair warning, it's a little bit long at just over 50 minutes total. I hope you find the extra time worth the effort of listening, I know we sure did! In this episode The quirky things that Josh's organization gets to work on and deconstruct The methodology of breaking foreign t...
DtR Episode 69 - NewsCast for December 2nd, 2013 02.12.2013 34:59
Special thanks to Steve Ragan ( @SteveD3 ) for sitting in this morning and providing his perspective as a journalist. Topics Covered "Leaked" FBI memo to government agencies says "there's a hacking spree on government websites, and it's Anonymous!" (we have to chuckle, a little) - http://www.theregister.co.uk/2013/11/18/anon_us_gov_hack_warning/ , http://www.thewir...
DtR Episode 68 - Buffer's Big Hack 22.11.2013 38:19
I want to thank Carolyn Kopprasch and the @BufferApp team for getting back to me, and agreeing to not only join the podcast, but also field questions from "anyone" ...what a cool group of people! In this episode Carolyn gives us some of the insider's perspective on what really happened, when Buffer got hacked Carolyn and I discuss triage methodology, and how Buffer's small team...
DtR Episode 67 - NewsCast for November 18th, 2013 18.11.2013 29:14
I'm back! Maybe a little sleep-deprived and a tad grumpier than usual, but back to talk news! Topics Covered Microsoft unveils the new Digital Crime Unit, and it is quite the statement - http://www.darkreading.com/attacks-breaches/microsoft-unveils-state-of-the-art-cyber/240163924 http://www.microsoft.com/en-us/news/presskits/dcu/ CME Group hacked, claims platform and trades unaffected ......
DtR Episode 66 - ISSA International 2013 - Cowperthwaite Weighs In 11.11.2013 36:32
In this episode... We revisit some of the topics Eric & I talked about nearly 2 years ago at ISSA International, Baltimore. Eric discusses the paradigm shift that needs to happen in security We talk about shifting resources (in the defensive) from "everything" to something more reasonable Eric and I discuss how CISOs must re-allocate resources to survive in a post-breach reality Gue...
DtR Episode 65 - NewsCast for November 4th, 2013 06.11.2013 21:44
Hey all - Raf here and I wanted to thank James for flying solo as my wife and I celebrate the brith of Niccolai and Isabella our new twins! I'll be back in our next episode... Topics Covered The buzz over calling yourself a 'hacker' - http://www.theguardian.com/technology/2013/oct/24/hacker-computer-seized-us-open-source (Raf's note - I personally think the way this has been...
DtR Episode 64 - A US Attorney's Perspective on Cybercrime 26.10.2013 49:21
Special thank you to the US District Attorney's office for the Southern District of California for a fantastic interview and for letting us pick Sabrina's mind for the podcast... In this episode... Hackers, carders, and the disturbing trend of them pairing up with the traditional mafia The challenge of VPSes in cyber-crime Evangelizing the truths about cyber-crime to businesses, average...
DtR FeatureCast - Rt Hon Baroness Neville-Jones on CyberSecurity 26.10.2013 28:49
In this episode We get a peek into the first member of English Royalty that we've ever had on the podcast Baroness Neville-Jones discusses the difficulties in cybersecurity at the government level We discuss the challenges of policy, compliance and implementing real-life security The Baroness discusses her efforts to raise both the awareness and collective security of business The Baroness di...
DtR Episode 63 - NewsCast for October 21st, 2013 21.10.2013 44:20
Thanks to Josh Corman for joining us this morning ... always nice to have Josh's experience and brain power on the show. Topics Covered Gargantuan Oracle CPU (Critical Patch Update) including -51- Java security fixes! - http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html Huawei calling for "independent cybersecurity assurance lab" framework, an interesting but...
DtR Episode 62 - A Peek Behind the Blue Curtain 14.10.2013 44:09
In this episode... James and I host legitimate Polynesian royalty (a princess....) really! Katie gives us the skinny on Microsoft's 10 year progression to get to a bug bounty program We discuss the merits of bug bounties and execution in a very large enterprise Katie gives us as many details as she can about the recent $100,000 payout Much... much ... more! Guest Katie Moussouris ( @k8em0 )...
DtR Episode 61 - NewsCast for October 7th, 2013 07.10.2013 46:01
Big thanks to the soon-to-be-regular peanut gallery ... @JoeKnape and @BeauWoods for jumping in this morning and breaking it down with James and I. As a personal message to those of you who listen and our community - please ...remember we all live in a giant glass house, and throwing rocks is a bad, bad idea. I've said it before and I'm looking right at the media for this one (ahem...) -...
DtR Episode 60 - Conversations from DerbyCon 3 30.09.2013 43:27
In this episode... Dave Kennedy wraps up DerbyCon 2013, and gives us the statistic you don't want to tell your management Dave announces the top secret guest for DerbyCon 4 Chris & Gabe discuss risk modeling using REAL automated tools Gabe introduces us to his concept of using a 'big data' approach to risk modeling We discuss risks, network segmentation, and other things you&apo...
DtR Episode 58 - NewsCast for September 23rd, 2013 23.09.2013 41:26
I want to thank Mr. Josh Corman ( @JoshCorman ) for guest-commentating today's episode, and lending his expertise and industry leadership point of view. Topics Covered UK's GCHQ has been using Prism (Courtesy of the NSA) to spy on you ... the revelation continues - http://www.telegraph.co.uk/news/uknews/law-and-order/10106507/GCHQ-has-been-accessing-intelligence-through-internet-firms.h...
DtR FeatureCast - HP Protect 2013 - Episode 3 18.09.2013 29:51
For those of you unfamiliar with the event, HP Protect is the premier event of the year for the HP Enterprise Security products and services organization, held to bring customer practitioners, industry experts, products/services managers and their support specialists together to not only solve real-world problems but to also help set the course for the next year. If you've not had a chance...
DtR FeatureCast - HP Protect 2013 - Episode 2 18.09.2013 23:31
For those of you unfamiliar with the event, HP Protect is the premier event of the year for the HP Enterprise Security products and services organization, held to bring customer practitioners, industry experts, products/services managers and their support specialists together to not only solve real-world problems but to also help set the course for the next year. If you've not had a chance...
DtR FeatureCast - HP Protect 2013 - Episode 1 18.09.2013 20:05
For those of you unfamiliar with the event, HP Protect is the premier event of the year for the HP Enterprise Security products and services organization, held to bring customer practitioners, industry experts, products/services managers and their support specialists together to not only solve real-world problems but to also help set the course for the next year. If you've not had a chance t...
DtR Episode 58 - Of BSides and Bettering Infosec 16.09.2013 35:46
In this episode... Mike explains once and for all how the BSides namesake came to be We talk about how the industry has evolved over the last 10+ years Mike dispenses a little of his philosophy on how to better the industry We talk burnout and why it exists, and possibly how to get through it Guest Mike Dahn ( @MikD ) - Mike Dahn is one of the original co-founders of the Security BSides conferenc...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.