Rafal (Wh1t3Rabbit) Los

Down the Security Rabbithole Podcast (DtSR)

News EN ↓ 750 episodes

This is Cybersecurity's premier podcast. Running strong since 2011 Rafal Los, James Jardine, and Jim Tiller bring a no-nonsense, non-commercial approach to our profession. DtSR brings interviews and discussion with people you want to meet, and stories you have to hear. So whether you're just starting out, or are decades deep into your career, you'll always learn something on this show. On Twitter/X: https://twitter.com/@DtSR_Podcast On YouTube: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHq On LinkedIn: https://www.linkedin.com/company/down-the-securit...

Author

Rafal (Wh1t3Rabbit) Los

Category

News

Podcast website

blogwh1t3rabbit.medium.com

Latest episode

Jul 7, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

DtR Episode 33 - NewsCast March 25th, 2013 25.03.2013

Welcome to the Down the Rabbithole NewsCast! Join me in welcoming James Jardine ( @JardineSoftwar e) of Secure Ideas to the show as a permanent co-host! The NewsCast is a bi-weekly (2nd and 4th Monday of the month) release where we'll discuss the news and events of the past 2 weeks, and attempt to analyze, break down, and generally make sense of the madness of the Security industry and real w...

DtR Episode 32 - Big Data in Little InfoSec 18.03.2013

In this episode... We discuss "big data", what the heck it really is, and whether it's something new, something old, or something marketing made up Marcus does interpretive dance, and makes up new words Alex (shockingly)  disagrees with Marcus, and actually describes 'data science' We hear Marcus talk about "NBS - never before seen" detection and why it's so...

DtR Episode 31 - Analyzing US vs. Cotterman (Cyber Law) 10.03.2013

Synopsis This timely podcast is right on the heels of the US vs. Cotterman decision from the 9th Circuit Court of Appeals. One of the watershed decisions on privacy and digital law, this is an extremely important case that touches on whether government agents can take and search your digital property while crossing the border with or without cause or suspicion. Michael and Shawn give their analysi...

DtR Episode 30 - It's Always a Business Decision [MISEC edition] 08.03.2013

Synopsis Security has an interesting view on " business decisions ", and in this podcast episode recorded at GrrCon 2012 in Grand Rapids, MI I sit down with some of the talent behind MISEC and we discuss #SecBiz topics of interest including the ugly phrase "it's a business decision" and why we say that. We also dive into how decisions are made, and why security and busines...

DtR Episode 29 - Shawn Tuma - The Law and the Hacker 05.02.2013

Synopsis Shawn and I have been trying to get together to record an episode for what seems like forever. We first started talking about the CFAA (Computer Fraud and Abuse Act) when it was ruled that a person could not be charged as a 'hacked' under the CFAA by their employer when they accessed information improperly if  the employed did not restrict that access appropriately. Shawn's...

DtR Episode 28 - Bill Burns - InfoSec in a Cloud of Constant Flux 29.01.2013

Synopsis I sat down with Bill at ISSA International in Anaheim, CA in the fall of 2012 to discuss what it's like, and what types of challenges he faces in the fast-paced, hybrid world of security at Netflix. We talked about some of the challenges his environment faces, and more generic issues that are endemic to the evolving security landscape. It's fascinating to hear Bill's take o...

DtR Episode 27 - Guest: Mikko Hypponen - Way beyond viruses 07.01.2013

Synopsis To kick off January on the Down the Rabbithole podcast I have Mikko Hypponen, the "malware adventurer" and Chief Resarch Officer from F-Secure Corp and we're talking about the state of malware and 'viruses' digging into the modern threat landscape and maybe digging up a bit of nostalgia from the late 90's. This is a fascinating conversation so I invite you to...

DtR MicroCast 06 - Guests: Steven & Martin - Hacking in Quebec (Hackfest.ca) 21.12.2012

Synopsis This microcast episode was recorded live  from hackfest.ca 2012, on location in Quebec. The conference is a phenomenal success for the challenges they face (primarily non-English speaking region, small market, etc) but they've managed to attract a ridiculous amount of people to this conference, awesome speakers, and have one of the best 'War games' scenarios I've ever...

DtR Episode 26 - Guest: Brad Arkin of Adobe - Software Security Under Pressure 18.12.2012

Synopsis This episode is special because it's been a long-time-in-the-making interview with Brad Arkin of Adobe. This is the organization that many of the hacker community like to hate, and pick on - without realizing the monumental task of securing the software that Brad's team is responsible for. Brad's official title at Adobe is Engineering Senior Director  but in real life one o...

DtR MicroCast 05 - Guest: Eric Cowperthwaite - The Rise and Fall of Enterprise IT 26.10.2012

Synopsis LIVE from day 2 of the ISSA International conference 2012 , in Anaheim, California I cornered Eric Cowperthwaite after a much-anticipated year-long wait... and we talked about his prediction that in the next 2 years many of the traditional IT employees will be employed as either business-IT resources in the enterprise, or IT-technical resources at an IT outsource or cloud provider... Eric...

DtR Episode 25 - Guests: Jim Manico, David Litchfield - From Black Hat 2012 with SQLi 22.10.2012

Syhopsis When I caught up with these two gentlemen in Amsterdam over the week of Black Hat 2012, I knew we wouldn't run out of things to talk about!  We ended up chatting for quite some time, and I think you'll find this conversation interesting from hearing of David's recent work with Oracle, and Jim's perspective on "the fix"... I kept the conversation going and am...

DtR Episode 24 - Guests: DarthNull & InfoJanitor - All the Things InfoSec 04.10.2012

Synopsis This week we went free-form with two of my favorite InfoSec insiders ...people you probably follow on Twitter but can't quite place.  Here are some of the topics covered this week: The Apple UDID theft - what really happened, why, and what more is there to this story? Information vs. DISinformation...the battle for online trust Speaking of distrust - where do you go post-breach? Info...

DtR Episode 23 - Guest: Patrick C. Miller - Energy Sector, SmartGrid and Resiliency 24.09.2012

Synopsis Today's podcast discussion is with someone who has one of the toughest jobs in the security world... Patrick helps organizations that generate and deliver the power that runs our gadgets and critical systems that maintain life as we know it.  The power grid is not only surprisingly vulnerable due to it's age-old infrastructure, but also surprisingly resilient due to the complex...

DtR Episode 22 - Guests: Marc Blackmer, Matt Morgan - Security + App Lifecycle viewpoints 20.09.2012

Synopsis This episode is a mini-episode recorded live  from the social media lounge at HP Discover Las Vegas 2012 .  It was an incredible show, where I caught up with Marc and Matt - two guys who are really from opposite side of today's deploy vs. secure coin.  Somehow we quickly dove into DevOps  and picked up right where my conversation with the incomprable Gene Kim left off in episode 20 ....

DtR Episode 21 - Guests: Wickett, Galbreath, Saudan - "Deploy faster, safer" 29.08.2012

Synopsis In this episode we ask the big question of "Can security be a part of the 'build/deploy faster!' culture?"  We discuss the need to separate out high/low risk code, understanding how to deploy dormant components of the applications, proper testing strategies and branching/merging in a world where faster  isn't just an ask, it's a need  to stay competitive. A h...

DtR Episode 20 - Guest: Gene Kim - DevOps live from HP Discover Las Vegas 06.08.2012

Synopsis This episode was recorded in June '12, live  from the show floor at HP Discover Las Vegas, 2012  and the talk of the town was once again DevOps .  Gene and I have had 2 prior conversations on the topic, but we're once again tackling the impact of DevOps on the IT and security relationship and overall business value.  We tip our hats to several people including Josh Corman (Rugge...

DtR - Episode 19 - Bob Arno: The world's foremost legal pickpocket 10.07.2012

Synopsis This episode is special, not because it's more Info Security stuff, but because we take a far departure from the world of bits and bugs to the world of the pick-pocket and thief.  Sitting down with Bob Arno is a real pleasure, as he has the storytelling ability and knowledge to educate and open your eyes to a world where nothing is as it seems and anyone can be separated from their v...

Down the Rabbithole - Episode 18 - Kellman Meghu: Chaos, Resiliency, and more 02.07.2012

Synopsis I caught up with my friend Kellman Meghu at BSides Detroit as the conference was coming to a close and we finally got to sit down and have a fun conversation about chaos, and what sorts of things enterprises can realistically do to increase security today.  We both work for vendors so we talked about "shiny blinky boxes", when things fail, and the notion of resiliency.  Fun conv...

Down the Rabbithole - Episode 17 - Adam Shostack on New School Security 18.06.2012

Synopsis Greetings fans, this episode promises to be a great one with the likes of Adam Shostack starting off talking about what the whole concept of " New School Security" is all about, and how it differs from the way we've all done it for the past 15+ years.  Adam and I talked through some new interesting ideas for moving the information security community and discipline forward,...

MicroCast 04 - Kevin Riggins & Kenneth Johnson - QA + Security Software Testing 14.06.2012

Synopsis Last winter, on a frigid afternoon I got a chance to sit down with 2 of my favorite Iowa locals, Kevin and Kenneth to talk about the tenuous relationship between QA and Information Security.  Earlier in the day I had given a workshop on software security testing (of the web variety) to a ViViT user group, and with that topic and their questions/concerns fresh in my mind I settled down for...

Feature - Welcome to HP Discover Las Vegas 2012 04.06.2012

Greetings friends!  I am taking some time to do something a little out of the ordinary right now... I'm coming to you from beautiful  Las Vegas , Nevada and  HP Discover 2012  where the theme is  Make it matter . Rather than doing yet another blog post on how beautiful the show floor is, and how amazing the content is going to be, I've recorded a little bit of audio, about 6:30 miut...

Down the Rabbithole - MicroCast 3 - Paul Elwell + Albert School - Measuring Security 29.05.2012

Synopsis This episode of Down the Rabbithole microcast (~15 minutes length) was recorded live at the Ohio Information Security Summit. Albert and Paul were kind enough to sit down with me and discuss metrics and process - and essentially what demonstrating "good security" means to an enterprise.  "Can we ever get there ?"  Where is there?   Understanding the basics of security,...

Down the Rabbithole - Episode 16 - Spacerog and Shpantzer talk CyberPocalypse 25.05.2012

Synopsis In this episode, streamed live and recorded for your listening pleasure, I'm joined by @SpaceRog and @Shpantzer from Security BSides Delaware.  What started out as an off-the-cuff discussion on the 'Cyber Apocalypse' quickly materialized into a much longer discussionw which dove into various aspects of infrastructure security, critical protection and even the inability to s...

Down the Rabbithole - Episode 15 - Backstage at THOTCON 0x3 08.05.2012

Synopsis It's rare that I get to be a spectator at a podcast, but in this case I was listening to some of the conversations and talks being given at Chicago's very own THOTCON 0x3, and decided it would be valueable to you to get some of the conversation movers on the microphone.  We started talking about the applicability of information security conferences to your "day job", g...

Down the Rabbithole - Microcast - THOTCON 0x3_1 27.04.2012

Synopsis In this short microcast we rap about the THOTCON 0x3 experience, why we think the Chicago community has taken off so much, and what sorts of interesting things make THOTCON, and the local hacker con here in Chicago, so attractive to people from around the world.  Yes, there is comedy involved... Guests Todd  - Audio genius, InfoSec luminary, pen tester ...better known to his Twitter fans...

Listen to the Down the Security Rabbithole Podcast (DtSR) podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.