Rafal (Wh1t3Rabbit) Los

Down the Security Rabbithole Podcast (DtSR)

News EN ↓ 750 episodes

This is Cybersecurity's premier podcast. Running strong since 2011 Rafal Los, James Jardine, and Jim Tiller bring a no-nonsense, non-commercial approach to our profession. DtSR brings interviews and discussion with people you want to meet, and stories you have to hear. So whether you're just starting out, or are decades deep into your career, you'll always learn something on this show. On Twitter/X: https://twitter.com/@DtSR_Podcast On YouTube: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHq On LinkedIn: https://www.linkedin.com/company/down-the-securit...

Author

Rafal (Wh1t3Rabbit) Los

Category

News

Podcast website

blogwh1t3rabbit.medium.com

Latest episode

Jul 7, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

DtR Episode 79 - NewsCast for February 10th, 2014 10.02.2014

Topics covered In the wake of the Target & Nieman Marcus breaches - is chip+pin really a priority right now, and does it solve the real problem? -  http://blogs.csoonline.com/security-leadership/2977/does-chip-and-pin-actually-solve-problem-find-out-asking-these-questions Speaking of Target ... it turns out that 3rd parties really are a problem and still  a blind spot in many organizations&apo...

DtR Episode 78 - Legal Professional Privilege [Guest: David Prince] 03.02.2014

In this episode David discusses what it's like working for a law firm (in the UK) A quick wade through the UK Data Protection Act (mostly Principle 7) "When lawyers get to interpret the laws" Law firms as targets for data breaches The new regulations in the UK, fines between 2%-5% of your REVENUE? Ouch. Defining "adequate measures" in regulations A brief chat on fines, reg...

DtR Episode 77 - NewsCast for January 27th, 2014 27.01.2014

Special thanks to Michael Santarcangelo ( @catalyst ) for stopping by the show and guest-hosting with James and I! We had fun, and I think you'll all enjoy Michael's perspective and humor. Topics Covered Nieman Marcus breach - all new, same as before, or is it? -  http://www.wired.com/threatlevel/2014/01/neiman-marcus-hack/ Coca-Cola loses laptops ... sort of ... but no worries, no evide...

DtR Episode 76 - Payment Industry Turmoil [Guests: Laura Claytor & Alfred Portengen] 20.01.2014

In this episode Did the Target/Neiman/? breach finally create a catalyst for change? The card system, payment processing infrastructure clearly wasn't designed with defensibility in mind ... who should be changing that? Are today's fraud rates finally getting high enough such that card processors, issuers, banks need to depart from the status quo? Are the days of "zero fraud liabili...

DtR Episode 75 - NewsCast for January 13th, 2014 13.01.2014

I can't believe it's 2014 already, and we're rolling through our 3rd calendar year! As we grow and you "regulars" mount, James and I want to thank you for listening, bookmarking, sharing and talking about the podcast. Your patronage has really made a us smile, and you're the reason we do this. Topics covered Reuters: Retail community may be ready for a change in the p...

DtR Episode 74 - Supply Chain [In]Security 06.01.2014

In this episode Chris Wysopal - who is that masked man? Putting some reality to the state-sponsored backdoors (Huawei) and supply-chain compromise The risks coming through the door with the products you buy The case for setting up an independent testing lab for mitigating 'backdoor' accusations Chris does an interesting assessment on software security practices in the enterprise Chris di...

DtR Episode 72 - Applied Threat Research and Defense 23.12.2013

In this episode Will gives us a lay of the land on the state of "state sponsored" and advanced threats We discuss collective advances in malware We discuss the persistence of 'old' malware, and code re-use We discuss enterprise defense and strategy Will gives us some wisdom from his experiencein helping clients defend themselves Guest Will Gragido ( @wgragido ) - Will is curren...

DtR Episode 71 - The 2013 Year in Review 16.12.2013

Hello! This is a special episode in that it's our year-end wrap-up. We bring together 3 of the industry's best to talk about the year that was, the things that made were on your mind, and maybe give us a hint at what is to come... Guests Will Gragido ( @wgragido ) - Will is the Sr. Manager of threat Research Intelligence for RSA NetWitness and a lightweight with the cold medicine. John P...

DtR Episode 70 - Embedded Systems Shenanigans 09.12.2013

Folks, if you work with, design, or implement embedded systems this is one episode you don't want to miss. Fair warning, it's a little bit long at just over 50 minutes total. I hope you find the extra time worth the effort of listening, I know we sure did! In this episode The quirky things that Josh's organization gets to work on and deconstruct The methodology of breaking foreign t...

DtR Episode 69 - NewsCast for December 2nd, 2013 02.12.2013

Special thanks to Steve Ragan ( @SteveD3 ) for sitting in this morning and providing his perspective as a journalist. Topics Covered "Leaked" FBI memo to government agencies says "there's a hacking spree on government websites, and it's Anonymous!" (we have to chuckle, a little) -  http://www.theregister.co.uk/2013/11/18/anon_us_gov_hack_warning/  ,  http://www.thewir...

DtR Episode 68 - Buffer's Big Hack 22.11.2013

I want to thank Carolyn Kopprasch and the @BufferApp team for getting back to me, and agreeing to not only join the podcast, but also field questions from "anyone" ...what a cool group of people! In this episode Carolyn gives us some of the insider's perspective on what really happened, when Buffer got hacked Carolyn and I discuss triage methodology, and how Buffer's small team...

DtR Episode 67 - NewsCast for November 18th, 2013 18.11.2013

I'm back! Maybe a little sleep-deprived and a tad grumpier than usual, but back to talk news! Topics Covered Microsoft unveils the new Digital Crime Unit, and it is quite the statement -  http://www.darkreading.com/attacks-breaches/microsoft-unveils-state-of-the-art-cyber/240163924   http://www.microsoft.com/en-us/news/presskits/dcu/ CME Group hacked, claims platform and trades unaffected ......

DtR Episode 66 - ISSA International 2013 - Cowperthwaite Weighs In 11.11.2013

In this episode... We revisit some of the topics Eric & I talked about nearly 2 years ago at ISSA International, Baltimore. Eric discusses the paradigm shift  that needs to happen in security We talk about shifting resources (in the defensive) from "everything" to something more reasonable Eric and I discuss how CISOs must re-allocate resources to survive in a post-breach reality Gue...

DtR Episode 65 - NewsCast for November 4th, 2013 06.11.2013

Hey all - Raf here and I wanted to thank James for flying solo as my wife and I celebrate the brith of Niccolai and Isabella our new twins! I'll be back in our next episode... Topics Covered The buzz over calling yourself a 'hacker' -  http://www.theguardian.com/technology/2013/oct/24/hacker-computer-seized-us-open-source  (Raf's note - I personally think the way this has been...

DtR Episode 64 - A US Attorney's Perspective on Cybercrime 26.10.2013

Special thank you to the US District Attorney's office for the Southern District of California for a fantastic interview and for letting us pick Sabrina's mind for the podcast...  In this episode... Hackers, carders, and the disturbing trend of them pairing up with the traditional mafia The challenge of VPSes in cyber-crime Evangelizing the truths about cyber-crime to businesses, average...

DtR FeatureCast - Rt Hon Baroness Neville-Jones on CyberSecurity 26.10.2013

In this episode We get a peek into the first member of English Royalty that we've ever had on the podcast Baroness Neville-Jones discusses the difficulties in cybersecurity at the government level We discuss the challenges of policy, compliance and implementing real-life security The Baroness discusses her efforts to raise both the awareness and collective security of business The Baroness di...

DtR Episode 63 - NewsCast for October 21st, 2013 21.10.2013

Thanks to Josh Corman for joining us this morning ... always nice to have Josh's experience and brain power on the show. Topics Covered Gargantuan Oracle CPU (Critical Patch Update) including -51- Java security fixes! -  http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html Huawei calling for "independent cybersecurity assurance lab" framework, an interesting but...

DtR Episode 62 - A Peek Behind the Blue Curtain 14.10.2013

In this episode... James and I host legitimate Polynesian royalty  (a princess....) really! Katie gives us the skinny on Microsoft's 10 year progression to get to a bug bounty program We discuss the merits of bug bounties and execution in a very large enterprise Katie gives us as many details as she can about the recent $100,000  payout Much... much ... more! Guest Katie Moussouris ( @k8em0 )...

DtR Episode 61 - NewsCast for October 7th, 2013 07.10.2013

Big thanks to the soon-to-be-regular peanut gallery ... @JoeKnape and @BeauWoods for jumping in this morning and breaking it down with James and I. As a personal message to those of you who listen and our community - please ...remember we all live in a giant glass house, and throwing rocks is a bad, bad idea. I've said it before and I'm looking right at the media for this one (ahem...) -...

DtR Episode 60 - Conversations from DerbyCon 3 30.09.2013

In this episode... Dave Kennedy wraps up DerbyCon 2013, and gives us the statistic you don't want to tell your management Dave announces the top secret guest for DerbyCon 4 Chris & Gabe discuss risk modeling using REAL automated tools Gabe introduces us to his concept of using a 'big data' approach to risk modeling We discuss risks, network segmentation, and other things you&apo...

DtR Episode 58 - NewsCast for September 23rd, 2013 23.09.2013

I want to thank Mr. Josh Corman ( @JoshCorman ) for guest-commentating today's episode, and lending his expertise and industry leadership point of view. Topics Covered UK's GCHQ has been using Prism (Courtesy of the NSA) to spy on you ... the revelation continues -  http://www.telegraph.co.uk/news/uknews/law-and-order/10106507/GCHQ-has-been-accessing-intelligence-through-internet-firms.h...

DtR FeatureCast - HP Protect 2013 - Episode 3 18.09.2013

For those of you unfamiliar with the event,  HP Protect  is the premier event of the year for the HP Enterprise Security products and services organization, held to bring customer practitioners, industry experts, products/services managers and their support specialists together to not only solve real-world problems but to also help set the course for the next year. If you've not had a chance...

DtR FeatureCast - HP Protect 2013 - Episode 2 18.09.2013

For those of you unfamiliar with the event,  HP Protect  is the premier event of the year for the HP Enterprise Security products and services organization, held to bring customer practitioners, industry experts, products/services managers and their support specialists together to not only solve real-world problems but to also help set the course for the next year. If you've not had a chance...

DtR FeatureCast - HP Protect 2013 - Episode 1 18.09.2013

For those of you unfamiliar with the event, HP Protect  is the premier event of the year for the HP Enterprise Security products and services organization, held to bring customer practitioners, industry experts, products/services managers and their support specialists together to not only solve real-world problems but to also help set the course for the next year. If you've not had a chance t...

DtR Episode 58 - Of BSides and Bettering Infosec 16.09.2013

In this episode... Mike explains once and for all how the BSides namesake came to be We talk about how the industry has evolved over the last 10+ years Mike dispenses a little of his philosophy on how to better the industry We talk burnout  and why it exists, and possibly how to get through it Guest Mike Dahn ( @MikD ) - Mike Dahn is one of the original co-founders of the Security BSides conferenc...

Listen to the Down the Security Rabbithole Podcast (DtSR) podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.