
Down the Security Rabbithole Podcast (DtSR)
Rafal (Wh1t3Rabbit) Los
The DtSR Podcast is dedicated to the cyber security profession - with timely topics, lively personalities, deep dives, and no fear of the third rail. Running since 2011 - founded by Rafal Los (aka "@Wh1t3Rabbit"), and co-hosted by James Jardine and now featuring Mr. Jim Tiller - the weekly show will entertain you while you're learning something.
On Twitter/X: https://twitter.com/@DtSR_Podcast
On YouTube: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHq
On LinkedIn: https://www.linkedin.com/company/down-the-security-rabbithole-podcast/
All episodes
Best episodes
Seasons
Top 10 Down the Security Rabbithole Podcast (DtSR) Episodes
Goodpods has curated a list of the 10 best Down the Security Rabbithole Podcast (DtSR) episodes, ranked by the number of listens and likes each episode have garnered from our listeners. If you are listening to Down the Security Rabbithole Podcast (DtSR) for the first time, there's no better place to start than with one of these standout episodes. If you are a fan of the show, vote for your favorite Down the Security Rabbithole Podcast (DtSR) episode by adding your comments to the episode page.

DtSR Episode 448 - YGHT Knock Knock Who's There
Down the Security Rabbithole Podcast (DtSR)
05/25/21 • 48 min
Send the hosts a message - try it now!
Prologue
You've GOT to hear this!
This week on the podcast, I invited Martin Zizi of Aerendir, to talk about how we can use technology to not only distinguish between humans and non-humans (bots?) but also how to identify humans with staggering levels of precision - using commonly available and inexpensive components. He's got humor, an eclectic background, and great knowledge of the topic. Join us!
Guest
- Martin Zizi
- Bio: Dr. Martin Zizi, MD-Ph.D, deep expertise in Molecular Biophysics and Neurosciences. He is one of the Founders & CEO of Aerendir Mobile Inc. He is the inventor of the NeuroPrint®, a cloudless AI-supported neural-tapping technology that can be used for authentication, identification, encryption, secure TLS, and bot segregation. Following his early years in the United States as a Scientist at the Walter Reed Army Institute of Research where he worked on very advanced projects, he had a 20-years dual-track career, leading both academic and strategic projects as a top scientist in 3 fields and was also a Chief Scientific Officer for Belgian DoD. Martin was a sought-after advisor for the Belgian, the EU governments, international organizations (UN) and the industry. Aerendir Mobile Inc. is his second start-up. He was #2 at another start-up in the Medical technology vertical.
- LinkedIn: https://www.linkedin.com/in/martinzizi/
- Twitter: https://twitter.com/MartinZ_uncut
- Aerendir Mobile, Inc.
>>> If you're reading this, consider clicking the link above to support the show!
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
YouTube home: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHq
LinkedIn Page: https://www.linkedin.com/company/down-the-security-rabbithole-podcast/
X/Twitter: https://twitter.com/dtsr_podcast

DtSR Episode 211 - NewsCast for Sept 13th 2016
Down the Security Rabbithole Podcast (DtSR)
09/15/16 • 48 min
Send the hosts a message - try it now!
Chrome to label more sites as insecure in 2017
- Link: https://security.googleblog.com/2016/09/moving-towards-more-secure-web.html
- Focus on sites that transmit passwords or credit card info over HTTP
A USB Device is all it takes to steal credentials from locked PCs
- Link: http://www.pcworld.com/article/3117793/security/a-usb-device-is-all-it-takes-to-steal-credentials-from-locked-pcs.html
- This is actually pretty interesting, but a little trickier than it sounds
- Still - it's quite fascinating that a USB attack works cross-platform, based on network activity and default USB behaviors
DHS chief: 'Very difficult' for hackers to skew vote
- Link: http://thehill.com/policy/national-security/294956-homeland-head-very-difficult-for-hackers-to-skew-vote
-
- Instead of dismissing the claim, let’s explore the merits
- Then let’s consider what, if anything, it means for enterprise security
- “It would be very difficult through any sort of cyber intrusion to alter the ballot count, simply because it is so decentralized and so vast,” he said, noting the series of state, local and county systems involved in running elections. “It would be very difficult to alter the count.”
-
- Decentralized and vast - the merits
- How many companies make the systems - so is it as decentralized as we’d like
- How much of what you do in the enterprise is decentralized?
- What are your points of failure - or the easy pathways to attack?
- If someone did alter the vote... would we know? How would we know?
- What’s the impact of appearing to alter the vote?
- Depending on your organiz
>>> If you're reading this, consider clicking the link above to support the show!
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
YouTube home: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHq
LinkedIn Page: https://www.linkedin.com/company/down-the-security-rabbithole-podcast/
X/Twitter: https://twitter.com/dtsr_podcast

DtSR Episode 564 - What Happens at Black Hat 23
Down the Security Rabbithole Podcast (DtSR)
08/15/23 • 41 min
Send the hosts a message - try it now!
TL;DR:
On this episode of post-Black Hat 2023, my buddy Will Gragido joins me to talk about what we saw, what we learned, and what shenanigans transpired. We're focused on marketing and booths - how do vendors differentiate, what do conferencegoers take away, and what makes your booth or offering unique? What about AI?
Yeah, we talk about all of that.
YouTube Video: https://youtube.com/live/cWwKA-2XsQU
Guest
- Will Gragido
- LinkedIn: https://www.linkedin.com/in/gragido/
>>> If you're reading this, consider clicking the link above to support the show!
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
YouTube home: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHq
LinkedIn Page: https://www.linkedin.com/company/down-the-security-rabbithole-podcast/
X/Twitter: https://twitter.com/dtsr_podcast

DtSR Episode 284 - MSS SOS
Down the Security Rabbithole Podcast (DtSR)
02/20/18 • 50 min
Send the hosts a message - try it now!
This week on the Down the Security Rabbithole Podcast, Raf and James welcome long-time friend of Rafal's - Scott Stanton - to the microphone. Scott's able to join Raf in person in Atlanta, while James is predictably on the other end of a Howdy Doodie (you'll get this if you listen).
This week, we tackle the MSS issue (Managed Security Services providers) again, but with a fresh angle where we aren't just spending the entire time bashing something we all rely on - but rather providing some constructive feedback into MSS providers from an enterprise perspective. And reminiscing a little. A lot.
Join us! And spread the word!
Guest:
- Scott Stanton ( @Scott_Stanton ) - Information Security leader with experience in the High Tech, Manufacturing, Engineering, Services, and Energy industries. My technical depth includes application development, IP networking, operating systems, virtualization, and storage systems. Scott is currently the Senior Manager of Infrastructure Security at a medical technology company.
If you've noticed the new logo, it's courtesy of a phenomenal artist, whose name is Peter Czaplarski. Yes, you too can hire him to draw amazing things for you, you can find him here: http://fb.com/CzaplarskiArt. Peter is also the artist behind Vengence Nevada (found here, for you comic lovers: https://www.comixology.eu/Vengeance-Nevada-1/digital-comic/593731 ) and has been an artist in many other venues. We highly encourage you to give his Facebook page a like!
>>> If you're reading this, consider clicking the link above to support the show!
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
YouTube home: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHq
LinkedIn Page: https://www.linkedin.com/company/down-the-security-rabbithole-podcast/
X/Twitter: https://twitter.com/dtsr_podcast

DtR Episode 34 - The Inside Scoop on Cyber Liability Insurance
Down the Security Rabbithole Podcast (DtSR)
04/01/13 • 32 min
Send the hosts a message - try it now!
First ...a milestone.
I want to take this time to formally welcome Mr. James Jardine, of SecureIdeas, as my permanent co-host to the podcast. James has experience podcasting as he already co-pilots the Professionally Evil Podcast, and he's witty, knowledgeable, and awesome to work with on the microphone. I ask that you all give James a warm welcome!
In this episode...
- Overview of what cyber liability insurance is and what it isn't
- We ask "Why would we need a security program, when you can just buy insurance?"
- How do [cyber] under-writers figure out how to insure you, and how much of a liability your organization and its practices is?
- The types of costs and coverages available in some of the different policies at the various carriers
- We pull on the 'reputation' thread ... again
- We try to divine the magic formula used to calculate how to calculate a 'liability' or coverage requirement
- We try and figure out how an enterprise can drive down their cyber liability insurance premiums
- Christine touches on mobility, encryption, and some interesting tidbits for the modern enterprise
Guest
- Christine Marciano ( @DataPrivacyRisk ) - Christine Marciano is President of Cyber Data Risk Managers, an Independent Insurance Agency specializing in Cyber Risk/Data Breach insurance, Directors & Officers insurance and (IP) Intellectual Property protection. Christine has over 17 years of experience working in various roles within the Insurance and Financial Services industry. Prior to establishing Cyber Data Risk Managers, Christine has held positions at CIBC Oppenheimer, Axa Advisors and Allstate Insurance Company.
Links
- Christine's Blog - http://databreachinsurancequote.com/blog/
- My 2013 Data Privacy, InfoSec & Cyber Insurance Trends report - http://databreachinsurancequote.com/wp-content/uploads/2013/02/2013-Data-Privacy-Information-Security-and-Cyber-Insurance-Trends-Report.pdf
- Christine's free weekly newsletter signup page - http://databreachinsurancequote.com/subscribe-data-breach-weekly-newsletter/
>>> If you're reading this, consider clicking the link above to support the show!
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
YouTube home: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHq
LinkedIn Page: https://www.linkedin.com/company/down-the-security-rabbithole-podcast/
X/Twitter: https://twitter.com/dtsr_podcast

Down the Rabbithole - Episode 07 - David Elfering's "As the Security Lightbulb Turns"
Down the Security Rabbithole Podcast (DtSR)
12/06/11 • 33 min
Send the hosts a message - try it now!
Synopsis
My guest David Elfering (@icxc on Twitter) and I go all over the map covering various SecBiz related topic, and come up with a fantastic set of quotes including: "No matter how long you hold the light bulb up, the world will not revolve around InfoSec" and other gems. We talk through how to present to a business group or executive, the communication and written skills required and various other topics related with bridging the business - security gap. This is a great episode to listen to - we cover a lot of ground.
Guest
- David Elfering (@icxc) - David is the Senior Director of Information Security over at Werner Enterprises out of Omaha, NB. David is a verteran of the IT industry providing leadership at corporate level, building and leading the security program and infrastructure for a two billion dollar, multi-national corporation. Experience at community, state and national levels with FBI Infragard, Nebraska Infrastructure Protection Council and the SANS Institute. Able to translate information security practices to business advantage. Experienced speaker, instructor and mentor. Member ISSA CISO Executive Forum. CRISC #1115272
>>> If you're reading this, consider clicking the link above to support the show!
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
YouTube home: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHq
LinkedIn Page: https://www.linkedin.com/company/down-the-security-rabbithole-podcast/
X/Twitter: https://twitter.com/dtsr_podcast

DtSR Episode 145 - NewsCast for June 1st, 2015
Down the Security Rabbithole Podcast (DtSR)
06/01/15 • 49 min
Send the hosts a message - try it now!
Apologies to anyone who is having issues downloading this episode!
In this episode...
- The ACLU encourages the government to get into bug bounties
- Read the original letter: https://www.aclu.org/sites/default/files/field_document/aclu_-_iptf_recommendations_submitted.pdf
- Points 1 & 2 are at sane
- Point 3 makes a hard left into into crazy-town
- http://thehill.com/policy/technology/243265-aclu-says-government-should-offer-rewards-for-finding-security-flaws-on-its
- The massive taxpayer data fraud (not really a breach) is believed to be the work of Russia, says the IRS
- Does it really matter?
- Was this a breach or an abuse of functionality?
- Would your company have caught this?
- http://www.cnn.com/2015/05/27/politics/irs-cyber-breach-russia/index.html
- CareFirst says their recent breach affects only about 1.1M people
- Healthcare is clearly in the "bad guys" target zone
- Quick to point out what the attackers did not get access to
- Of course it was a sophisticated cyberattack
- http://abcnews.go.com/Technology/wireStory/carefirst-data-breach-affects-11m-people-31187250
- CNA Financial business unit refusing to pay out claim to Cottage Health System
- Claims hospital "failed to continuously implement procedures and risk controls identified"
- CNA unit alleges many failures -- but is this fair?
- http://www.businessinsurance.com/article/20150515/NEWS06/150519893
>>> If you're reading this, consider clicking the link above to support the show!
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
YouTube home: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHq
LinkedIn Page: https://www.linkedin.com/company/down-the-security-rabbithole-podcast/
X/Twitter: https://twitter.com/dtsr_podcast

DtR Episode 83 - NewsCast for March 10th, 2014
Down the Security Rabbithole Podcast (DtSR)
03/10/14 • 34 min
Send the hosts a message - try it now!
Topics covered
- Target CIO resigns, new central CISO and CCO roles created; but what's really going on here? - http://www.darkreading.com/attacks-breaches/target-begins-security-and-compliance-ma/240166451 & http://pressroom.target.com/news/target-reports-third-quarter-2013-earnings
- City of Detroit employees' information (including SSNs, DoB, etc) are "at risk" because someone clicked something they shouldn't have - http://www.freep.com/article/20140303/NEWS01/303030085/Detroit-computer-security-breach
- ComiXology was [big time] hacked, but it's all good because the passwords were 'cryptographically secured' but where's the transparency? - http://www.theregister.co.uk/2014/03/07/comixologys_phantom_zone_breached_by_evil_haxxor/
- A North Dakota University System was hacked and now 290k students, employees and faculty (yes including SSNs) data is at risk ... or is it? - http://www.greenfieldreporter.com/view/story/8f909740809e48e9a5669de333418134/US--University-System-Hacked
- NC State researchers have a genius new way to detect Android malware (hint: you look for C code) - http://www.computerworld.com/s/article/9246825/N.C._State_researchers_devise_tool_that_detects_Android_malware
- The AARP (yes, that AARP) has decided that now is the time to post a bulletin to their system to teach retired persons how to make good passwords - http://www.aarp.org/home-family/personal-technology/info-2014/create-password-avoid-hacks-kirchheimer.viewall.html
>>> If you're reading this, consider clicking the link above to support the show!
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
YouTube home: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHq
LinkedIn Page: https://www.linkedin.com/company/down-the-security-rabbithole-podcast/
X/Twitter: https://twitter.com/dtsr_podcast

DtR Episode 43 - NewsCast for June 3rd, 2013
Down the Security Rabbithole Podcast (DtSR)
06/03/13 • 27 min
Send the hosts a message - try it now!
It's June already?! Where has the first half of 2013 gone? James and I break down the last 2 weeks of interesting InfoSec news in a short "Monday morning quarterback" style... enjoy!
Topics Covered
- Evernote adds 2-step veficication for their authentication, and follows suit with just about every other 'modern' app. Following on the hells of Twitter, LinkedIn, FaceBook, Apple and the one that started it all, Google - we're now getting multi-step authentication from Evernote. Free users not welcome ...yet? - http://blog.evernote.com/blog/2013/05/30/evernotes-three-new-security-features/
- Dropbox down for more than an hour, but it wasn't a security bug (we don't think), it's just that they had 'technical difficulty'. If you depend on Dropbox for your file synchronization services, you knew this happened - http://www.computerworld.com/s/article/9239648/Dropbox_goes_down_for_more_than_an_hour
- NIST 500-299 "Cloud COmputing Security Reference Architecture" document is released. There's a bit of irony here, as the document itself is a whopping 299 pages! - http://collaborate.nist.gov/twiki-cloud-computing/pub/CloudComputing/CloudSecurity/NIST_Security_Reference_Architecture_2013.05.15_v1.0.pdf
- Drupal.org has been hacked, and it appears 2013 just isn't a good year for the folks over at Drupal. Apparently about 1 million accounts have been compromised/affected, and all accounts had their passwords reset - I apparently had a Drupal account I don't remember anymore and my password was reset too - http://techcrunch.com/2013/05/29/drupal-org-hacked-user-details-exposed-and-reset/
- Google changed its disclosure policy for critical issues that are actively being exploited from the standard 60 days, to 7. A week. 7 days down from 60 ... this needs more reading and discussion - http://www.csoonline.com/article/734286/google-zero-day-disclosure-change-slammed-praised
- Hackers are exploiting Ruby on Rails vulnerability that was patched this past January, so zero-day no longer applies... the lesson here is to patch in a timely fashion! - http://www.computerworld.com/s/article/9239588/Hackers_exploit_Ruby_on_Rails_vulnerability_to_compromise_servers_create_botnet?taxonomyId=17
>>> If you're reading this, consider clicking the link above to support the show!
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
YouTube home: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHq
LinkedIn Page: https://www.linkedin.com/company/down-the-security-rabbithole-podcast/
X/Twitter: https://twitter.com/dtsr_podcast

DtSR Episode 237 - NewsCast for March 21st 2017
Down the Security Rabbithole Podcast (DtSR)
03/21/17 • 49 min
Send the hosts a message - try it now!
The Cost of Cybercrime - Let’s Take a Different Perspective
- Cybercrime is reported as a $450B drag on the economy; the absolute number sounds big
- The question to ask: “How big is the global economy?”
- Turns out that this is only 0.57% of the global economy, in 2014 (nominal)
- By way of contrast - how many minutes are in a day?
-
- What is 0.57% of your day?
- What it means - we’re doing a good job. Fraud is low. Cybercrime might be on the rise, but for now, it’s at low relative percentages
- Does it mean we don’t matter? No. Don’t be silly. Our efforts are why the numbers are low
- Keep up the good work
- http://www.en.netralnews.com/news/business/read/1249/cybercrime.costs.the.global.economy..450.billion
- https://en.wikipedia.org/wiki/Gross_world_product
Home Depot to Pay Banks $25 Million in Data Breach Settlement
- New settlement with banks
- http://fortune.com/2017/03/09/home-depot-data-breach-banks/http://www.cnbc.com/2017/02/21/home-depot-earnings-q4-2016.html → has autoplay with the same video
Survey: Experience Preferred Over Education When Hiring For Cybersecurity
- The survey of 350 IT security professionals gauged their attitudes toward the skills shortage in cybersecurity. Some 93 percent agreed that experience is more important than qualifications. A further 73 percent claimed that it didn't matter whether IT staff were college graduates when it came to getting the job done.
- Qualifications are considered degrees and certifications
-
- The rub -- and what they didn’t ask -- is how do you assess the experience and capability o
>>> If you're reading this, consider clicking the link above to support the show!
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
YouTube home: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHq
LinkedIn Page: https://www.linkedin.com/company/down-the-security-rabbithole-podcast/
X/Twitter: https://twitter.com/dtsr_podcast
Show more best episodes

Show more best episodes
FAQ
How many episodes does Down the Security Rabbithole Podcast (DtSR) have?
Down the Security Rabbithole Podcast (DtSR) currently has 686 episodes available.
What topics does Down the Security Rabbithole Podcast (DtSR) cover?
The podcast is about News, Security, Infosec, Risk, Tech News, Hacking, Podcasts, Technology, Cyber and Cybersecurity.
What is the most popular episode on Down the Security Rabbithole Podcast (DtSR)?
The episode title 'DtSR Episode 555 - Why Can't We Figure Out the Developer Security Relationship' is the most popular.
What is the average episode length on Down the Security Rabbithole Podcast (DtSR)?
The average episode length on Down the Security Rabbithole Podcast (DtSR) is 43 minutes.
How often are episodes of Down the Security Rabbithole Podcast (DtSR) released?
Episodes of Down the Security Rabbithole Podcast (DtSR) are typically released every 7 days.
When was the first episode of Down the Security Rabbithole Podcast (DtSR)?
The first episode of Down the Security Rabbithole Podcast (DtSR) was released on Sep 13, 2011.
Show more FAQ

Show more FAQ