All episodes

Steve Kosten, President of OWASP Denver

Apple Podcasts Spotify SoundCloud

In this episode:

Steve Kosten, President of OWASP Denver, is our feature guest this week. News from: Red Robin, Convercent, Optiv, Ping Identity, Cognizant, Gates, DISH Network, LogRhythm, Secure64, Red Canary and a lot more!

"First I'd like to thank the Academy"

On Wednesday night at the Denver Center for Performing Arts, we got to see the first Colorado CISO of the year awarded. Each of the finalists were former guests of Colorado = Security. It was so exciting that Robb videoed it and learned how to use Youtube. Check it out. In other news: Red Robin looks to slow down a bit, Convercent makes a list of fast growers, Optiv hires more big names, Andre Durand has fit a lifetime of achievements in to his first 49 years, LogRhythm serves up some PIE, Red Canary dives in deeper on their Atomic Red Team, and Robb really doesn't like Secure64's take on IoT devices.

Did you catch our trivia question? Be the first to reply to info@colorado-security.com with the right answer and get any $25 item from the Colorado = Security store.

Feature interview:

Steve Kosten, President of OWASP Denver is our feature guest this week. Alex sat down with Steve to discuss OWASP, how he got involved in volunteering, and his future plans with the OWASP organization. Steve started his career as a developer which helped drive his move to application security and his current role in application security consulting.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

Local security news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events:

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript9790 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood.

Welcome to Colorado Equals Security. This is the newscast for episode 41 for the week of November 13th. Alex, how's your weekend been? You know, it's been super exciting, Robb. Friday night, took one of my sons to a coffee shop to play Magic: The Gathering.

You know, super geeky stuff there. Went to a football game yesterday and then had a bunch of kids sleep over. Good times. Good times being a parent. That's right.

In the suburbs. How about you? I got to hang out with my wife, went to a concert Friday. We got to hang out. My kids came to the office.

We played 3-man chess. Have you ever seen 3-man chess? I have never seen 3-man chess. It's a circular board. Wow.

And you can, you can attack either way. It's really quite a complex game. I won. I beat my 8 and 10-year-old kids. So, so that was the highlight of my weekend.

Congratulations, I guess. You're the mental equivalent of an 8 and a 10-year-old. 18-year-old. I like it. Yeah.

Yeah. All right. Why don't we go ahead and jump into the news for this week? Number 1 is one of our local restaurants has announced it's going to stop expanding. Yeah.

Not a security or even a technology story, but just something that was kind of interesting. Red Robin noted that they're gonna stop developing new restaurants after 2018. I think mostly because of sort of changing trends in the way that people are, are going out to dinner and things like that, you know, more, more takeout, more fast casual, more, you know, less sit-down kind of food. I assume that this means that they're, you know, their new restaurants are losing them quite a bit of money and that they're trying to, trying to build up a little bit of cash before they start again. They said 18 to 20 4-month hiatus from building new restaurants.

Yeah, I mean, I think it's an interesting thing to think about too, because those sort of changing trends change the way that we work in general. And so it's definitely something we should think about. Yeah. Next, the 5 Colorado companies named to the Deloitte Technology Fast 500. So these are the 500 companies around the country that are growing the most quickly.

Yeah, and one of them was Conversant, who we've talked about several times. They do ethics and compliance training, and they were— I don't remember what number they were. They're on the list, one of the 5 Colorado companies on the list. Yeah, they made the list. Optiv has hired a couple of new hires to support their growth.

They hired Peter Evans as the new Chief Marketing Officer and Sean— is it Catlett— as a newly created role of Senior Vice President of Emerging Services. Sounds awesome. Emerging services. That's basically he's going to be creating new services for them. So it sounds like anything that is emerging.

There you go. All right. Like it. Next, big news this week. We talked about it the last couple of weeks leading up to this.

The Apex Awards from the Colorado Technology Association were this week, and both Robb and I were there. There was a lot of the folks from our community there. I don't know. I saw 20, maybe 20 different CISOs and security leaders there at the group. And there were probably 600 people there, maybe?

It was a big group of folks, yeah. But the first part of that that was really cool is that Andre Durand won the CTA's Lifetime Achievement Award. Yeah, so Andre is the CEO and founder of Ping Identity. Previous to Ping, he was the founder of Jabber, which was acquired by Cisco. And previous to Jabber, he had founded a company called Durand Technologies.

He's been in Colorado for 17 years, maybe a little bit more than that. And really, he's been involved with CTA, and it was really cool to get to hear the impact he's had on the organization and that they were recognizing him for, you know, all of his activities here in Colorado. I think he chafed a little bit about being a 49-year-old man saying he had a Lifetime Achievement Award. Yeah, there's a long way to go still for him. Well, I mean, from what he has done, he has had a lifetime in technology.

So I think it's pretty cool that he is only 50. And has done all these things. Yeah, it's very neat. So also at the awards, you know, there was there was quite a few different awards that were given, and you can see all of those things on the Denver Business Journal who all the winners were: CIO of the Year, Company of the Year, which was SendGrid, Educator of the Year. Yeah, a lot of cool stuff.

But of course, the one we care most about and the one that we had a hand in was the the CISO of the Year. We've talked in the last couple episodes who the finalists were. We had Sam Masiello, John Everson, and Matt Shufeldt as finalists, and we're happy to announce that Matt Shufeldt was the winner of CISO. I don't think we could have been any luckier, Robb, with running Matt as the interview last week. Just how it worked out that way.

We've obviously had all three of those fine gentlemen on the show, and congratulations to Matt, of course. Well deserved. And congratulations to Sam and John as well. They've done a really good job in the community, and I'm really, really glad that all three of those guys got to get recognized. In the show notes, you're going to see links to the stories that profile these guys.

There's also a link to my first. Ever YouTube. I, I did a video of the presentation of the award if you want to see. It's about, I think it's about 5 minutes. See Matt getting his award and giving his acceptance speech.

It's very cool. That is really cool. Uh, next, LogRhythm had a blog this week about the, uh, Phishing Intelligence Engine, or PIE, and the, uh, their open source release of that project. This actually, it's a really cool project that, uh, the labs folks over there did Uh, Greg Foss, who we know, James Carder, the CISO over there. Um, Pi is really cool in that it helps automate the process of reviewing and responding to phishing emails.

So they, you know, obviously they are LogRhythm, so they're using LogRhythm and Office 365, and it makes that process, you know, super easy. So you can automatically review and respond to these things, pull the emails out of people's inboxes. Lots of stuff that saves time around phishing. Yeah, it's neat to see them creating open source, you know, value-add tools for their customers. If you're a LogRhythm customer and you use O365, you should, you should take a look at this.

Yeah, definitely. Um, it is something that we are reviewing. Uh, so next, Secure64 had a blog. Basically it says the Internet of Things, just because we can doesn't mean we should. And I'd say the tone of this article is Hey, just because you can connect your toothbrush or your washer dryer to the internet doesn't mean it's a good idea.

So I throw it to you, Alex. What do you think about this? So I can see sort of both sides of this argument. One, I don't know about from a security perspective if we should be poo-pooing what people are doing in the marketplace, but I definitely can see from a consumer perspective that we should definitely think about, well, does it make sense for from a consumer perspective to connect your toothbrush or your bicycle or your whatever it might be and make it smart. But, you know, really the market is gonna be the one that drives that kind of stuff.

If someone makes something smart and people buy it, well then there's obviously a market for it. So there's only been a couple times in the show where I really tell y'all how I feel and I really hate this article. I hate it with a passion as I think it makes security people and security companies come across as once again, the department of no, right? Hey, hey, don't do that new thing. Don't, don't go down that new road because it's not safe.

It's not secure. Our job in security is not to tell people that, you know, to, to not go after technology, to be Luddites. It's to say, here's how we can do it securely. Here's the right way for us to enable those stupid features that we don't care about. I think plugging your, your toothbrush into the internet may be a dumb idea, but if there's a market that people want to buy it, Our job isn't to say don't sell it.

It's to say here's how you can do it responsibly and securely. And I really just don't like this article, especially that it came from a security company. If this article came from a consumer advocate group or if it came from the manufacturers themselves saying, you know, here's some risks to these things, it will be different. But from a security company, it just reinforces the idea that we are, you know, a roadblock in the way of adopting new technologies. Yeah, it's We have a habit of calling everybody else stupid because they don't see the value in security.

And I think this is another one of those instances where someone was trying to do that. Yeah, I know, I know. Obviously, I have a strong opinion about this one, but we can move on. Next, Red Canary had a blog this week. It's actually more of an FAQ or Q&A about their Atomic Red Team framework.

So we had an article last week or the week before about their release of this Atomic Red Team Framework, basically a systematic way that you can go about testing the defenses that you have on your network. So I think it's something that it's a— well, one is a great idea. People do testing of their networks to check how their defenses are all the time, but to have that systematic way to do it and what it is that you're looking for, I think is really cool. And this blog just gives essentially some, some questions and answers and clarification around what they've seen since it's been released. It really puts a systematic approach in place for this, right, where generally Generally, if you test your network, you're gonna do something like a vulnerability scan, which looks through, you know, this huge repository of CVEs that's not customized to your environment, or a penetration test where you're really depending on the skills and the tips that the tactics and tips and protocols that that attacker knows, right?

So it's really much better for us to be able to, you know, create a framework that looks at what's the highest risk for us, what are the controls we have in place, and let's test those specific controls. And I really like that about this. And I think this article kind of explains in more detail how that works. I think any time we can make what we do more systematic is going to be a good thing. And we can more evidence-based, right?

More data to say it's working or it's not working. And yeah, I know people struggle from that all the time. Hey, I have all these defenses in place. Are they actually working? What can they actually detect?

I think this really is a good step forward in helping to test to answer some of those questions. Yeah. All right. Couple pieces of news, or that's the end of the news rather. And next couple pieces of thing I want to say, housekeeping.

Go ahead and sign up, get on our mailing list if you're not already. That'll get the show notes delivered into your inbox each week. We would love it if you would sign up for the podcast on iTunes or Google Play. And of course, if you can write us a review on there, all the better. That helps people find it, helps us move up the list on search results, which is not a bad thing.

So let's move into our trivia questions. So last week, the trivia question was, what's the 2nd most secure location in Colorado? We had a couple of hints. We said number 1 is Cheyenne Mountain and number 2 is not the Buckley Air Force Base. Yeah.

So drum roll. Drum roll, please. The answer is it's the ADX Florence Prison, basically the supermax prison where many of our most famous national federal criminals are being held. And this was, this was got by Chris Linton. Chris is the— is a employee of Jeffco Schools.

Is that right? That is correct. I actually got to see Chris this week. I asked him when he receives his, his swag to take a picture of himself in it. And we can include that in the show notes to show that, hey, look, this actually does work.

People, people do get stuff. And then going on to this week's trivia question. It's actually a— it's not, it's not in the form of a question. It's a command. This week's trivia command is Colorado Security has had 2 lawyers as guests.

Name them now. Name them both. Name them now. All right. So send a note to info@colorado-security.com.

And if you're the first one there, you'll be the winner. You'll get to pick something from the Colorado Equal Security store worth up to $25. And once again, thanks to Andre Gaeta, who has been sponsoring this trivia competition. Awesome. So let's go ahead and go to events.

As you guys know, we do have an event calendar on the website. Make sure you check that out. To see what's coming up in the near future. First on the list, ISSA Denver is having their November chapter meetings on the 14th and the 15th. Also on the 15th, the CTA has this Are You Prepared for AI in the Workplace meeting.

I think it sounds really interesting and something that you can get non-security folks involved with. Also, Denver OWASP is having their November meeting on the 15th. So just a theme here as we go through this week, everyone's trying to get their stuff in before Thanksgiving. So there's a lot of stuff going on this week. Also on the 15th, Anomaly is doing a Denver Threat Day event.

ISSA Colorado Springs is doing their November chapter meetings on the 15th and the 16th. Moving into the 16th finally. Yeah, on the 16th, ISSA Denver is doing their Women in Security meeting. Also on the 16th, ISACA Denver is doing their November chapter meeting. We're not even close to done, guys.

DenSec is doing their North meetup on the 16th. They pushed this forward a week to avoid Thanksgiving. Also on the 16th, SecureSet is doing their Expert Series, Dr. John Black, Understanding the Equifax Hack. Should be kind of interesting. Yeah.

And then finally on the 16th, we have ISC² doing their monthly meeting with Stephen B. Armstrong talking about enterprise risk management. Again, sounds like a pretty interesting topic. They're just all on top of each other on the 16th and the 15th. Yeah. I dare someone to go to all of those events.

Seriously though, I think that it is something that we need to make sure that people keep looking at that calendar so that we don't end up with everything on the 15th and the 16th of the month. Although this— that's it for the next week. There's nothing the week of Thanksgiving. But then we do have an event on the 29th that we want to call out. Optiv does these focus groups where they get together a small group, say call a dozen people to talk about a big problem in security.

Then they take that, they go actually around the country and do this in different cities. So they're coming to Denver to talk about application security and building an AppSec program. This is a really good chance for you to meet not only with some experts at Optiv, but probably even better, meet with some local people who are working on AppSec, and you'll get, you'll get to talk with them about how to solve the problem. And then after the research and the new framework is created, you'll be on the list of folks to get it first and for free. So I highly recommend folks to go to this.

I've been to a couple of these different focus groups, and I've seen a lot of value out of it. Yeah. I mean, I would like to say also that this is not, uh, they're not trying to sell you anything here. This is actually a research opportunity. Um, so they're actually trying to gather information from you.

Um, and then as Robb said, you can get this information back as part of being a participant. No salespeople in the room. Yep. Um, so the, the info for that's in the show notes. Get signed up early.

If you don't sign up early, they, they might cancel it. Uh, if they don't get enough people in these different cities, they don't do them. So, you know, it'd be, it'd be great if, if 5 or 6 of you listening could go sign up and just make sure this happens. All right, let's move on to jobs. Uh, first, the National Renewable Energy Lab is looking for a security manager and CISO.

Very cool. You could, you could do security for an organization that, you know, I personally believe in. I think renewable energy is a noble effort and something that we need to get better at. So a cool chance. That's up in, up in Boulder, right?

Uh, no, it's actually, uh, sort of near Golden. Okay, a little farther south. All right, cool. Uh, Teletech is hiring a director of information security. We, uh, uh, you know, they had a CISO position posted.

That CISO position is, uh, apparently going to be filled soon, and this director position will be reporting to that new guy. So a new opportunity there. Polar Field Services is looking for an IT and communications manager. This one looked cool. There is some security responsibility in there, but this is one of those jobs where you'll get to go to, you know, really cold places like, uh, like Alaska and maybe the South Pole or who knows what.

Very cool. Hang out. SecureSet is hiring a cybersecurity technical instructor. If you want to go teach people how to do security, that's a good opportunity for you. Quantix Protec is looking for a cybersecurity forensic analyst.

GE is hiring a cybersecurity engineer in Longmont. Xcel Energy is hiring an IT intern. And this is a rotational job. So it sounds like you're going to go through a number of different functions at Excel, including security. That's, that's a really good opportunity.

Yeah, I, I would, I would highly recommend anyone who's looking to, you know, I assume it's targeting college kids. I would assume college. If, if you're a college kid who's applicable for this, highly recommend taking a look at it. You get really good experience across their IT department that way. Uh, the last one on the list is Red Canary is hiring a sales development rep.

These are, these are the positions that many of you guys get emails and phone calls from that drive you nuts. It is probably the hardest position in many companies, but it's a great way to get your foot in the door to know how the company works, learn how to do sales, learn how to communicate with customers. It's a really good opportunity to step into a neat company at Red Canary. I also think, you know, we all do dread getting those sort of cold calls or, you know, outreach from a lot of security companies. So maybe this is a time when someone can go and do this job and do it better.

So we don't mind getting those calls quite so much. All right, well, I think that's the end of our jobs for this week. Uh, so our feature interview this week, Alex, you sat down with Steve Kosten. Steve is the president of OWASP Denver, right? Yeah, and, uh, we talked about OWASP, we talked about, uh, just some general application security stuff.

It was a good conversation, so I think everyone's gonna enjoy it. All right, well, everyone have a great week. We'll talk to you next weekend. Sounds good. Thanks, Robb.

This is Robert Wood, VP of Security at Alps Fund Services. This is Colorado Equals Security, for Colorado security professionals by Colorado security professionals.

This is Alex Wood, and I am here with Steve Kosten. Steve, welcome. Thanks for being on the podcast with us. Hey, thanks for having me, Alex. So Steve wears several hats.

You know, one of them, you are the president of the local OWASP chapter here in Denver. That's correct. And you also, I'll say, are an application security expert, guru, whatever word you want to use. So why don't you start by telling us how you got your start in information security and how you got to sort of where you are today? Sure thing, Alex.

First, I started off, actually my undergrad was in aerospace engineering, and I actually moved out to Colorado to work with Lockheed Martin. And I was doing thermal engineering, and as part of that, I had to write a lot of my own code to perform analysis. I was working with the launch vehicles. So I worked on the Atlas and the Athena launch vehicles. And at that time, you either worked for Lockheed or you worked for Boeing, and then your career was pretty much those 2 companies.

And that didn't really entice me so much. So I started actually diving into the software world, just started working in, you know, C++, Java. And I, in the dot-com boom, I just switched over and got out of the aerospace world. And then later on, kind of did the whole dot-com scene, and then I went to work eventually back with Raytheon, and that kind of combined my aerospace and software backgrounds, but it's in the defense sector and security is very important in that area. And so I started getting very involved with security, especially application security for some of the applications we were developing for Raytheon.

And then I ended up getting my master's in information security from James Madison, and at that point I just went full in, dedicated straight to information security and application security, and been there since. And I think that was about since about 2002 or 2003 when I made the full conversion. So it's been a little bit. Nice. And so today you're doing sort of your own thing, right?

Doing consulting around application security testing and training, that kind of stuff? Yeah, so we have a company, Cypress Defense, and we do a lot of work in application security. And what our main goal is really just try to get people to— we'll do application assessments and things like that, but we try to really get them to— people to— and our customers to the point where they're getting full secure lifecycle and not just these little, little quick assessments. We want to see continual developed— developing secure software. Yeah, so I'm interested, you know, you came at security sort of, uh, from a different angle than many people.

A lot of people come sort of straight into security and then do a lot of stuff You came up on the development side. When you first started doing application security, it sounds like it was a few years back. What was sort of the environment around application security at that point? I think, you know, sort of today application security is sort of at the front of a lot of people's minds, you know, being really important. I mean, a lot of the security is moving towards the application, but, you know, back then application security was a, you know, a lot younger.

There wasn't as much stuff around there. What was it like back then? As you said, it's really evolved, but it was pretty much nonexistent. You know, when I mentioned when I was working back at Raytheon, we were working with some pretty important customers, and to be honest, I had to actually ask for security requirements to be invoked.

And that was a good thing for Raytheon at the time because it gave them more work, so they were very happy with that. I talked to the customer, but in reality, they did not— this one particular customer did not have security requirements levied on us. That's pretty crazy. Yeah, in that world especially. Yeah.

So were you, were you doing a lot of manual work back then, or were you, you know, developing tools? What— how did you actually do the work? Because I'm sure a lot of, you know, the commercial solutions that are out there today weren't in Yeah, a lot of the commercial things weren't there. We worked with the, you know, Bink on the development side. I worked with the formal security team and really trying to get their input on how they addressed network layer and kind of introduce them to things they have to be concerned with on the application side.

And so it was really a lot of education taking place and saying, hey, if you're concerned about this element here, you should also be concerned about this element in the application world. So there's really a lot of education, advocation, making the story that, hey, we need to be doing more from this front. Oh, that's cool. And there's, yeah, there's no tools in place. And so a lot of it, you know, you're looking at authorization issues and showing, hey, I can abuse the system this way.

And really at that point educating the developers on how to remediate. It sounds a lot like thinking about threat modeling before there was threat modeling. Yeah, really, that's what it— that's what we were doing. And, you know, and I was just, you know, cutting my teeth on it, but I was interested, interested at the time and, um, just went from there. Nice.

So, um, as I mentioned earlier, you know, one of the other things that, that you are big involved in is, is OWASP. So I wonder if you could take a moment to tell everybody what OWASP is, if they don't know already. I'm sure a lot of people do. Yeah, sure thing. So OWASP is really just a grass-level organization.

It's the Open Web Application Security Project. And one of the big things, we, we focus a lot on web applications, but we'll have meetings and discuss all aspects of security. But it was founded focusing more on web applications and I got involved many years ago and then about 5 years ago I became the chapter lead. But we do— there's a lot of projects and volunteer projects within OWASP that are trying to better educate the community on developing secure software. We're perhaps best known for the OWASP Top 10 and one of the problems we tend to face is it is a grassroots organization.

Developing essentially products for people to use everywhere. There's some good projects out there like the Java Encoder Project, which helps out with cross-site scripting remediation. You, of course, have the OWASP Top 10, which has done wonders from the awareness perspective. But when you look at these projects, they can be pretty immature actually when you dig underneath and see that. And that's something that OWASP is really trying to work at, is really developing the maturity of the products and making sure that as the projects are used, people understand the maturity that is associated with that project.

And why do you think that is, the lack of maturity? Is it just, you know, it's volunteer-based? Is it just not a good lifecycle? What do you— It's volunteer-based. It's a strict thing.

You know, I was at a conference in London, the Yoast Summit this summer, and I was talking with Simon, and he runs the Zap project, which is a great proxy and testing for web applications. But he's pretty much the only developer, and he works with Mozilla and is only able to dedicate a few hours a week on the project. It has wide use, but the, the number of people can actively contribute, it's always on the side. And so when you have people doing things on the side, you don't have the dedicated focus that you would like to really mature a product. Um, yeah, and I know that you're, you're involved more at the local level, but do you— is there anything going on sort of at the, the larger international level to try and, and make those mature or get support, you know, better support for these projects?

I know You know, like if you think about like the, uh, um, you know, Apache Software Foundation, stuff like that, that, you know, they've started to get sort of corporate donations from a lot of people because, um, you know, people are using their open source products and they need to make sure that they're, they're going to work and have, you know, vulnerabilities fixed and things like that. Is there anything about things like that at the OWASP level or anything around there? Yeah, and it's actually funny you mentioned that. Um, I am very involved at the local level, but I've been there for 5 years and I'm actually going to be bowing out. I'll be meeting with the rest of the board members shortly.

We've already discussed this, but we're going to be working on that. And I'm actually running for the national level for the election in November, or international level. But to answer your question, they— yes, we're working on that. One of the things we're really— that there's an effort right now at the board level, international board board level is we're looking to hire an executive director to really get someone who's full-time focused, not just these part-time board members where it's very difficult to have someone dedicated to managing the full-time OWASP staff and provide more strategic thinking at a full-time consideration. And so we're working on that right now.

There's an active hiring process going on. And then, yeah, we do have corporate sponsors helping out with this. ZAP, while it's a part-time effort, Mozilla is contributing people part-time to help with that. But the projects that receive that are kind of far and few between. And so what we're— there's been an active effort to really spell out what the maturation process is for OWASP projects and to say if you're going to be at this level and be advertised at this level of then you need to meet these requirements.

And that is an active effort, but again, it's difficult because it takes a lot of effort to corral all these projects and get people to spend time to assess the maturity of them. Yeah, so you mentioned a minute ago that you are gonna be stepping down as the Denver OWASP chapter lead and running for the international board. Congratulations first. I know, as being— I haven't won or done anything. Well, just being able to step down is a congratulations.

You know, being a former president of ISSA, I know how that goes. And, you know, sometimes, you know, you may want to do it for a short time and you end up doing it longer than you want to, and it's a whole lot of time commitment. So, I mean, I guess thank you and congratulations. If someone wanted to get involved in terms of the election or other things like that, because obviously, you know, you're a local person, we want you to win, what should folks do? Well, the election is restricted to OASP members.

When OASP has our meetings, we open it up to everybody. We don't charge anybody admission to our meetings. And so we have a lot of people coming to our meetings. You know, when we— I started, we were having— well, I started with Andy Lewis and we were having people coming in, you know, 15, 20, probably built to about 30, and now we're having about 150 people coming. But of those who are actually OWASP members who have paid the $50 annual fee, those are far and few between.

So if someone wants to vote in the election, they actually would have to become full-time members, and then they'll have an election ballot sent to them. That's the only thing we can do. So all I can do is just reach out to our local membership. So what we need is a local OWASP membership drive, is what you're saying? We partially did that when we had our SnowFROC conference.

We do our conference in March, and this last year we gave people an option of joining and becoming OWASP members at the time for a slightly discounted price, which ended up being the same price as they got full-time with the full fee to the conference. And so they got membership at basically no cost. And so we did that because There's some decisions at the global level that were being made that we thought were to the detriment of the Denver chapter, and we wanted to have a little bit more voice in that. Gotcha, that's great. So you mentioned SnowFROC, you mentioned the local chapter meetings.

Again, for the folks that aren't familiar with the local chapter, you know, so what sort of schedule do you guys do in terms of events, and, you know, where do you meet, how can people get involved other than obviously going to the Colorado Equals Security event page to see when all the OSINT chapter meetings are. Yeah, please go see that. But we, we have a meetup group and you go there, we'll announce our meetings. We meet typically on the 3rd Wednesday of every month and we're looking to continue with that. October is gonna be a little different because we're partnering with SANS for the SecureOps.

Oh, I did see that. So we're partnering with them for that conference, so it's about one week earlier than we would normally do it. But to get involved with OWASP, just show up to the meetings. We have great meetings. Solutions2 has been a great sponsor for the local chapter, and we've been meeting at Dave Buster's on the 3rd Wednesday of the month in a great room with 2 great projectors.

We have free food, a couple of drinks for everybody, so it works out really well. And then to get really involved, When I first got involved with the chapter, there was a limited board aspect to there, to the chapter, and as I became the chapter leader, I realized I wanted more people involved, have a little bit more of an executive board for the local Denver chapter. And so I started just recruiting people, and we have about 5 board members right now. And so that's been really helpful, and that's something I really want to see continue. And so to get involved in the OWASP chapter, volunteer.

We'll have more people come on as board members, and then we're gonna give you more responsibilities, and that's gonna of course help us grow and make the chapter better. Yeah, and I have to say, and I, you know, I've told this story before, you know, I started becoming an ISSA member and I volunteered and eventually was, you know, got a board spot and then became president, and it's one of the best things that I've ever done. You know, it's opened so many doors for me. So yeah, I would definitely encourage people to volunteer, whether it's OWASP, ISSA, you know, somewhere. There's always gonna be somebody that needs your help.

Yeah. And, and, you know, if you're willing to give some time, it will probably be returned to you 2, 3, you know, 4 times just because we have such a great community. Yeah. And the one thing I have to say, I'd like to give kudos. The Denver chapter, probably about 6 or 7 years ago, it was on the verge of being closed off because we were not having enough meetings.

And Andy Lewis, he kind of stepped up and kind of rescued the chapter, and he pulled together the board and he asked for volunteers, and that's when I stepped up. And he ran the chapter for a year, and then he basically handed the keys to me. But that's where I want to have a little bit more formality in the transitions. And, you know, we've grown the chapter, we have great sponsorship, and continue to mature the Denver chapter and then hopefully on the executive and the international board, we can grow the overall organization. Yeah, it's been great what you guys have done, the amount of people that you have now.

I remember I used to go to some of the meetings that were, I think it was at Lockheed over here. Yes. And then hosting after that, or maybe there's some places in between too, but it'd be a handful of people in a room with a couple pizzas and maybe a couple beers. Yes. And it's like, well, this is some interesting stuff, but it's sort of odd that we're kind of stealing a room at Lockheed Martin, what seems like in the middle of the night.

Anyway, so congratulations on how far you guys have come. It's really a great testament to how much work you guys have put in. Yeah, it's been a good amount of work from our side, but then again, having key sponsorship is very helpful as well. So we talked a little bit about ZAP, and you mentioned the OWASP Top 10. Why don't you talk a little bit more about the OWASP projects that are out there and maybe one or two that you think are really cool that if someone is into application security that it might be a benefit to them?

Yeah, there's a lot of great projects out there. ZAP is a really good one and more from a tool perspective, ZAP is very good as far as being freely available. A lot of tools that are out there commercially can can be extremely expensive for people to incorporate into the lifecycle, a lot of the commercial tools. But for SMBs, these small, mid-sized businesses, there are some very good tools out there within the OWASP community that are free. ZAP is a good one.

When you're dealing with encoding issues trying to address cross-site scripting, there's the Java Encoder Project. Which is a very good project. We also have a lot from the educational side. If you want to learn more, we have the cheat sheets available. So this is really good to give to the development team and say, hey, look at these issues, know how you're addressing them in the code.

So the cheat sheets are very good from a developer education perspective, as well as the testing guide. You can go through the testing guide and really have a developer become a security champion for the team and kind of follow that and provide the cheat sheets for the development team and really start really maturing the security of that program.

Let's see, Top 10 is very well known again just from an awareness perspective.

Let's see, and then we have the mobile projects as well, the Mobile Top 10. We have, let's see, some more education ones.

And I know I'm forgetting some really good projects out there, so excuse me. I know, I like the fact that these aren't all technology projects. So, you know, so some of them obviously are tools that people have to spend time coding, but other ones are, you know, policy-based, you know, OWASP Top 10. You know, being, um, you know, just sort of a survey-based, you know, it's, you know, this is the stuff that's out there, you should be aware of this stuff. Um, and, uh, I know that there's a few out there too that are, um, you know, educational, that it's sort of environments that you can play around with, right, right, so that you can learn more about, you know, either testing or, you know, potentially how, um, exploits work or other things like that.

And I, I love the fact that it just, it It runs the gamut of all different kinds of stuff. Yeah. I forgot OpenSAM, great project there. Juicebox, WebGoat, other good projects like that. iGoat.

Nice. So moving away from OWASP a little bit, you spend a lot of time in application security. You do application security testing. You do education. If someone was trying to get started with an application security program in their organization, where would you say that they should start?

If they're starting with a program, what I would probably want to do is start with educating the development team. The one thing that I found, if you provide developers They understand that developers want to develop good projects, products, and good services. And if they're not aware of the security vulnerabilities in their applications, they're not going to do anything about it. Well, I've had very good luck going and speaking to developers and showing them, hey, I can exploit your code this way, and they are very eager to clean it up because they don't want their applications being exploited. Amount of pride in the work that they do.

So I would initially focus on education of the team. And so I would, again, just because it's free and easy, I would just leverage OWASP for that. There's a lot of great resources there. And once you have a few people getting educated on that, there's going to be a few that are really going to jump in and really latch on to that. At that point, these are the people on my team that I'm going to want to become security champions, and I'm gonna want them to learn about testing a little bit more.

So I'll probably want to use something like the OWASP testing tools to show them, hey, this is how you can improve and study and learn more. You can use JuiceBox and some of these other testing things that they get their hands on. I would give them, you know, the Burp proxy. Go play with this, play with some vulnerable virtual machines, and really start developing this. Now you've got some of the groundwork in place.

So at that point, you still need to be selling this upstream as well to— you need funding to really mature the program inside. So I would start wanting to work with the executive team and say, listen, we really need to be doing more, you know, show things like the Equifax breach, which could— has the potential to bring down the whole organization. And really start getting some funds to get dedicated time to dedicate security into the lifecycle. That's where I would start. How would you— so say someone tries to do that and then they have a development manager that is just totally dead set against it and they come back, hey, why are you taking this time away from my developers?

You're hurting our productivity. These guys are off doing all this security stuff. You know, how do you combat something like that? Someone that's sort of negative and not interested in you pushing that forward? Yeah, and you're always going to run into that, and I've seen organizations have that mentality.

And actually, we did an assessment just recently for this organization, and we did an assessment and it put the fear of God into them because they saw how vulnerable their application was. And I'm not a very big fan of throwing out a lot of FUD, fear, uncertainty, and doubt, but I mean, look, the Equifax CEO had to resign, the CISO, the CIO resigned. They didn't resign, they all retired. Yes, yes. So at a certain point, the boards are becoming more aware of this.

They're looking at this, that company has the potential to be decimated. And as board members, they have to be looking at that. So when I'm talking to a mid-level development manager that's potentially stymieing, stopping the right efforts, I would almost— I would make the argument that, listen, you're kind of hampering what could potentially be in the best interest of the organization at all. You do not want to be the person that says after a breach, hey, we tried to do this and so-and-so stopped us. Yeah.

You know, everyone's trying to, you know, look good and be productive and look for the best interests of the company, and sometimes people can be a little short-sighted, you know, looking at short-term goals and not the big picture overall. All right, so now we've got, we've got our people convinced, we've got some champions, Everybody, or at least some people, are excited about doing application security. How do you grow the program from there? What are, what are some of your next steps? Are you looking at implementing, implementing some, you know, dynamic testing, static analysis?

You know, sort of where do you go from there? Yeah, so I would like to start off, you know, once I have this going on, I'm trying to get security involved as early as possible in the lifecycle. So I'm a big fan of static analysis. And getting some tools in there to help out with that because as development's getting in place, before there's even a deployable product, you can perform some testing. But once I have that team in place, I don't want to be just focusing on, you know, these static assessments initially.

You know, we have to get the security requirements in place, and so it's not just educating the development team, but it's educating everybody associated with the SDLC. See. And so what one of the things we've done is go and talk to project managers and such. It's like, listen, you need to consider security as you're managing the product project as well. Get them bought in on that.

Get QA bought in on this. So really developing a robust team that all has security buy-in with that. Once that is in place, we do want to have a true security experts. Right now we have security champions. I also want to get the buy-in and actually have security experts in place to help out with developing security requirements.

Champions are great to help with the development day-to-day management, you know, hey, I need some advice on security, security aspect of the code, but I do want the experts to come in who are full-time concerned about security, giving advice on the requirements and the architecture, and these are the things you have to consider. Doing the threat modeling and helping educating the team on doing threat modeling so that they are continually addressing security at each stage of the lifecycle. Then you're going to be getting static analysis in place.

And to me, one of the problems with static analysis is a lot of the automated tools, you get a ton of potential false positives. And that's something the security program must manage because nothing is going to kill a development team faster than plopping down a 5,000-page report saying these are all security vulnerabilities and about 15% of them are. And so what we like to advocate is getting these automated tools in place but only putting in, running the rules and tuning them so that they're spitting out 90 to 95% true positives coming out. And that kind of lends— allows the team, the developers, to respect the security team, that they're not getting a lot of noise and causing extra work for them. But it's also really important from the education side.

It's showing them, hey, this is a security vulnerability in your code, and move Boom, this is how you fix it. And when it's integrated into the lifecycle like that, they're seeing it continuously. And that's just— if you just do training once a year in security, it's gonna diminish quickly. But if it's continuously a part of your everyday work that, hey, this security vulnerability popped up, this is how you fix it, you're gonna go through 2 or 3 cycles of that and it's just gonna be locked in. You're gonna remember that forever.

So we want to see that continual training, continual testing as part of the lifecycle on the static side. And the same thing on the dynamic side as we get into the deployments thing where you have a product that's deployable, running the dynamic tests. Because static tests, static assessments are good at finding certain vulnerabilities, dynamic's good at finding others. You really need them both hand in hand. You get that threat modeling in place, and really I do like the continuous integration, continuous deployment model too, to get rid of the security vulnerabilities that are out there quickly.

So that's kind of my vision, you know, where I like to see programs mature to from the AppSec side. Nice. So what are, what are some of the hallmarks of a, a really mature security program? So, you know, we've, we've started to build this up now, um, you know, what are the really good programs doing Is it automation? Is it more education?

Is it metrics? What is it that you see for the teams that are doing application security the best? I think you have, yes, you have the automation in place. You have the education routine. It's not the checkbox once-a-year thing.

It's really a part of the culture, the education. And so it's being a part of the culture and continually striving, you just the maturity level, you're continually striving for improvement there.

But really, one of the things I like to see is a— what I consider a true security policy. Policies can kind of get a black mark and frequently do because I've seen hundreds of policies and they're hundreds of pages long and developers know where they are, but nobody follows them in the least, right? And one of my prouder aspects— and I'm gonna go back in years to when I again was at Raytheon— we had to develop our secure development policy, or software development policy, and I would have literally look at other programs for references and see 100-page, 150-page documents that nobody read. Yeah. And I was able to trim it down and really just try to cut it down to about 15 to 20 pages.

At that point, I thought I had something that developers would look at, read, get their buy-in, and they bought into it and they could use that. And so I want to see good policies that are saying, hey, we are following these policies, we are living to them, we're getting security requirements bought in, we're doing threat modeling, we're doing all these things. And so you're not dependent upon any single person at that time. It's actually a culture. You're following policies.

Everybody buys in. They know what they're doing. You're getting the metrics in place. To me, at that point, you have a much more mature model. How do you see DevOps?

You mentioned that the OWASP chapter is meeting at the SANS DevOps Summit that's coming up here. How do you see DevOps and application security working together or not working together, or is it making it easier or harder? Oh, it's— the model is definitely much more difficult. And the big reason, we're trying to get the testing in place, but with things, with builds and going out so quickly, having the time to actually run through some of the testing tools is just very onerous. Especially as you get some of the large applications, some of these testing tools can run, you know, 6, 8, 12 hours to run through and assess an application in full.

And that's too much when you're doing CI/CD. It's just way too much. And so a lot of organizations are trying to find the balance there and trying to struggle. It's like you weigh in the effects of, okay, I'm pushing out code that may not have been fully assessed, But I may be pushing out a remediation fix for a vulnerability that's already out there in production. And so that's part of the effort is really getting the policies in place and having a good secure application security program that understands what's being developed, what's going to have a critical security fix so that we can flag this one for, hey, we're going to do an analysis, static analysis of this this and dynamic assessment of this critical piece before it goes through.

This other stuff, which we don't see any immediate, uh, security impacts, we're going to let flow through and go and go through quickly. But periodically we're going to be doing full assessments. So if something kind of skipped through, we have a mechanism to catch it before it's been out there for too long. But it's definitely a problem, and, uh, the tooling— everyone's trying to get the tooling to try to figure out how to address that. Have you seen any good solutions in terms of tooling that people have come up with to make that easier?

I have not seen anything that's really worked. I think we're all working on that right now. Gotcha. So we're getting close to the end of time. I didn't know if there was any other topics that you wanted to bring up or anything that you wanted to mention.

No, I mean, just the one pain point for me and And I'm gonna go to Equifax, and I imagine you guys are talking about that separately.

But the one thing that's— when you're talking about getting buy-in too, I wanna see lawsuits, big-time lawsuits. I would love to see Equifax just decimated, that company disappear. I think that would do wonders for the whole application security community knowing that the board will see that if we don't respect people's information, if we don't put proper controls in place, our company could disappear. And I think it rightfully should. So, um, all right, I'm gonna have one follow-up to that.

So the, the report is that it was an Apache Struts vulnerability, um, that the attackers were able to get in through. But let's leave out the fact that, you know, even if it's there, They should have had some kind of detective control to see what was going on and so on and so forth. Do you feel like for that particular vulnerability, was it reasonable for them not to have patched it? Was it too hard? Was it, you know, my understanding is that for this particular one, it's, hey, we have to recompile, we have to, you know, make some application changes to fix this.

Is this Equifax being bad on that particular part of it? No, no. I think every program's gonna have flaws. Things are gonna be potentially missed. That's gonna happen anywhere.

What I— from what I have seen in the reports that I've seen out there, I would say there's a culture of lack of security within Equifax, and that's the reason I would like to see that, hey, someone makes a mistake, mistake, that's fine. You know, you have a good program in place and someone screwed up, that happens. But when I'm looking at Equifax and I'm seeing, okay, there is an admin username password on the database. When I look and see that, hey, I just got a credit freeze put in place and my PIN is a timestamp. When I go and see, oh, if I need to, if I forgot my PIN and it needs to be reset, the same information that was stolen is going to be used to reset my PIN.

I'm sorry, that's just a culture of lack of security. For that, I blame you.

Yeah, so, and that's good perspective, and thanks for that. I definitely think that there is— it's more than just this one thing at Equifax. There seems like a culture of lots of bad things at a place where they should have had some of the, the most security-focused culture of any organization based on the data that they had. So completely agree. Thanks.

Bad stuff, bad stuff. Uh, anyway, uh, anything else, Steve, before we wrap up? No, thank you for having me. Awesome. Uh, well, thanks again.

Appreciate your time. Um, everybody that's, uh, not an OWASP member should go and join OWASP, or at the very least, um, go out and hit the meetings. You know, if you join, definitely vote for Steve in the upcoming election. And this has been Colorado Equals Security, and we'll talk to you next week. Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security.

Reach out to Alex and Robb by emailing info@colorado-security.com. At colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes