Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is Robb Reck welcoming you to the May 8th, 2017 newscast. Alex, how you doing?
I'm good. How are you, Robb? Doing great. So we've, uh, we've been talking about it since we started the podcast, right? But it's finally upon us.
It, it is that time. Uh, Rocky Mountain Information Security Conference is here. Yeah, it's a little bit like Christmas here for Colorado security people, right? I think it's even better than Christmas, um, because other than, uh, you know, learning about additional quirks of your family, you don't really learn anything at Christmas. So, you know, we're gonna get gifts, you know, from, from the vendors, all kinds of swag, but we're also going to learn things along in the process.
I do expect to have some drunken fights break out with your— again, kind of like Christmas. Your racist uncle is going to be there. So that was last year where we had the racist uncle there, right? Yeah. All right.
No racist uncles this year. Let's keep away from that. But, but it is, it is a big week here in Colorado, right? So, you know, you've been to RMISC for the last almost decade. Any advice you give for those who are, who are going for the first time this year?
I would say definitely take your time, plan things out, especially with it being 2 full days of conference tracks this year. There's a lot of stuff in there, so you're not going to be able to get to see anything. So make sure you know which sessions you really want to get to. I think also, as much as people like to malign vendors, I think this is a great opportunity to look to see what new wares people are peddling. Know, the new technology that's out there.
Um, you don't get that many vendors in one place in town very often. Yeah, it really should be a good opportunity. The expo floor is going to be packed. Um, the keynote schedule— well, let's go just kind of go through the high-level schedule again. Uh, so Tuesday the conference kicks off with, with full-day training sessions.
And, and these training sessions, um, they go from some highly technical sessions around penetration testing to risk assessments and leadership sessions. So really kind of depending on what you're looking for, there might be a great fit there on Tuesday for you for your full-day events. And then the kind of the general conference kicks off Tuesday evening where Jeremiah Grossman, our first keynote speaker, will start off the conference. And that's, I think, 4 o'clock on Tuesday. Immediately following Jeremiah, we have the Industry Ambassador Panel, which we started last year for the first time and was really successful.
And basically it's kind of some of the folks from Denver and from outside of the state who are really going to talk about what are the trends going on, what do they see in the big picture for security. And who are our ambassadors this year, Robb?
Yeah, so we have 7 ambassadors this year, a couple from last year and then some new ones here. So Anthony Fried, who's over at Silance and really a good industry guy, he's on the panel. Dave Lewis, also known as Gattaca. He's there. Brian Martin, or Attrition, he's going to be there with us.
Jericho, right? Eddie Mize, another local Denver guy, is going to be on the panel. Wendy Nather. Wendy is a former 451 analyst, now over at Duo Security, well known throughout the industry. Chris Roberts, another Denver guy.
Sid Dragon, if you like the call signs and all that. Chris is actually the guy who we have the feature interview this week on the podcast. And then Eric Vanderburg, and I actually don't know Eric, but— I don't know Eric either. But he's apparently pretty well known throughout the Twittersphere. Very good.
Yeah, so we have the ambassador panels there after Jeremiah on Wednesday. We start off with Cal Fussman. We did have that interview with Cal a few weeks ago on the podcast. Very excited about that and kind of his call to arms for those of us there. Yeah, I'm really excited to hear what he's going to have to say.
Wednesday evening, we close off with Andre Durand. Andre is the CEO and founder of Ping Identity. This is— he's a 3-time entrepreneur who's been pretty successful and hopefully going to give us a chance to get some insight into how he built a company and how he sees the industry going. Thursday morning, we start off with the governor. Governor Hickenlooper is going to be with us in the morning.
Recent news I got was that he actually might be, instead of the 8 o'clock slot, we might switch him and John Kindervog. So the governor would be like closer to 8:45 or 8:50. That's just due to his schedule and the legislation. Apparently the legislators are gonna have off after Thursday of this week. So he has to be around right at the very beginning of the day.
Anyway, we have him coming to give some remarks to kick off the conference. It's really neat to have a governor here in Colorado who is so supportive of security, who sees this as one the legacies he wants to leave behind. Yeah. And we, you know, we haven't aired it yet, but I spoke to the Highlands Ranch High School Cyber Patriot team a couple weeks back, and they got to meet the governor, and they also mentioned how excited he is about cybersecurity.
Yeah. So after the governor talks, we're going to have John Kindervogt. John was an analyst for Forrester for many years, and he created the zero trust networking, zero trust computing model for them. And now he's over at Palo Alto, but he's, he's really going to talk about what zero trust is and, you know, how that kind of takes the place of perimeter-based security. And then closing up the conference on Thursday, we have Josh Blue.
And Josh is a pretty well-known comedian who won Last Comic Standing, and he's a Boulder native as well. Great to have something a little out of the box, get some comedy to finish off the conference. And I'm actually— I got my wife coming to join us for the last session so she can watch a comedian. And I recommend other folks who are going to be there, you know, if you have some friends around who want to come join us, I think we should have plenty of room. Yeah.
Okay, so let's go ahead and dive into the news for the week. First on the news this week is that Colorado tech salaries provide the 4th best quality of life anywhere in the country. Yeah, and some of the cities that were in front of us were I don't want to say if they were surprising to me, but maybe not what I expected. So Seattle was number 1, followed by Atlanta, and then Austin, which not surprising to me. Austin and Denver seem to be in every list these days.
Austin and Denver, like you said, always near the top of the list. I was a little bit surprised by Seattle. I think the reason Seattle was quite so high is basically just the salary inflation that we've had from Microsoft and Amazon up there. Their salaries were quite high, and their cost of living was about the same as Denver, right? Yeah.
So I think for Seattle it was, uh, 41% of your salary went to essentially living expenses and then 59% for whatever you wanted to do with it. Whereas in Denver it was about 50/50. Um, it, it was, but the numbers themselves were quite a bit higher. I think like the salary in, in Denver was like an average of $131,000 or something like that. Really quite, quite a big number.
Um, and, and Atlanta surprised me just a little bit. It's not a place I think of as being an especially high quality of life type of place. Well, we may be biased. Next on the list, there's going to be a new national live news TV show that's going to be filmed out of Denver. Yeah, this has nothing to do with security.
But as we keep an eye on the local news, I try and pull out stories I think people will find interesting. This one was interesting to me. It's really a live show that's going to go everywhere. And the intention is, is some kind of interactivity with it where people can do, you know, polls in real time and interact with the hosts who are going to be there in downtown Denver at the 9News studio there. And it looked like it was gonna be several times a day that they were going to be doing this live show.
So it could be cool. And, you know, for all we know, maybe we can get some security content on there. Well, it's an experiment, right? And it's cool to see how this experiment goes. And hopefully we'll all get to watch it here.
Coming up in the next months and years. So next one was, there is a law to limit the government's knowledge of internet purchasing that was being considered by the Colorado legislature, and unfortunately it died. This is also called the Amazon Tax Bill, and basically the idea here was, as of July 1st, so just a couple months from now, the government is going to start forcing Amazon and other online retailers to send details about purchases to the government so they can collect Colorado sales tax on those purchases. This law was to prohibit the government from forcing retailers to share their, their purchase history. Yeah.
And, you know, privacy advocates were, you know, pushing for this, and rightly so. I think it's one thing for the government to require taxes. It's another thing for the government to start tracking information on the purchases that we get. So I— it would have been nice to see this get a little bit more, uh, traction than it did, but at least it did come up. People are talking about it.
So, you know, hopefully we'll see more on this front in the future and maybe get something like this passed. Yeah, very, uh, it is a little concerning for privacy advocates here. Uh, next piece of news this week, um, Conversant, which is a company that I hadn't heard of until recently, um, they, they got another $10,000— or excuse me, $10 million round. So Conversant, what it looks like they do is ethics and compliance training and monitoring for companies. There's a little bit of crossover into security where we obviously— the compliance can be, you know, Sarbanes-Oxley, it can be Foreign Corrupt Practices Acts, can be all kinds of stuff that has a security aspect to them.
And this company is a SaaS product which is trying to help companies make sure they're being compliant going forward. So, so interesting that this is a Denver-headquartered company. And, and what was really interesting here is, as I mentioned, they raised $10 million, and it was actually in February of this year, but that, that was the 4th time in the last 4 years that they raised a $10 million round. So starting in— what would that be— 2014, '15, '16, '17, they've raised $10 million every year. Uh, you know, I've never heard of something like that.
Is that something you've ever seen before? No, I haven't. It seems very different from, uh, most of the ways that people are going about getting equity. You know, it's usually something small and the next round is something bigger, and you're getting bigger and bigger until at some point Um, you know, your option is to go public or get bought by somebody. Yeah, a $10 million— you maybe a $1 million seed round, $10 million A round, and a $25 million B round.
But they just, they've just done 10 over and over for the last 4 years. Maybe they know something that, that other people don't, or, uh, or maybe it's just a new strategy. I don't know. Anyway, interesting to see that, and, um, might be something that's interesting for those of us— for some of the folks listening, if you're looking for compliance software and assistance they might be a good option for you. And next on the list, ProtectWise has hired Damon Harvey as VP for their EMEA sales organization.
So it looks like they're trying to get bigger in Europe. Yeah. He came from RSA. He was head of a group that was, was doing sales, I think, in, in the UK over there. So NetWitness, I think, right?
Yes. The NetWitness Group. Exactly. So, so ProtectWise, another Denver-based company. Obviously, it's fantastic to see them growing and looking to get their footprint out in Europe.
I don't know Damon, but this looks like a good opportunity for him and for ProtectWise to grow into new markets there. Coalfire this week released a new story basically about the FedRAMP marketplace and securing your cloud solutions. So the link in our show notes is to a summary of a report that they issued, which really just talks about what FedRAMP is, What is the effort to get FedRAMP certified? What's the timeline look like? What departments need to get involved?
It's a really nice summary if FedRAMP is something you're looking to do. And high-level, FedRAMP is the federal government's requirements for a cloud service provider in order for them to be able to host federal government information in the cloud. That's something that I've been working on at Ping, getting FedRAMP certified, and this is a really interesting article if you're looking to go down that road. Yeah, and we had a story a couple weeks back about Veris, who is now part of Coalfire, releasing notes on AWS compliance and FedRAMP. So definitely, Coalfire being a big auditor for FedRAMP, they have a lot of insight into the companies that are trying to be FedRAMP certified and how they're doing.
Speaking of Veris, Coalfire actually this week released a different press release that we didn't tag here, where they renamed Veris as Coalfire Government. So, so Verus is no longer as of, as of now. Um, I'll say one other thing about FedRAMP before we move on. Generally speaking, as you look at security standards, if you look at ISO or NIST 800-53, NIST Cybersecurity Framework, the SANS Top 20, these are frameworks that are, they're more general in what they require. There's not very much that's prescriptive in there.
You know, they'll tell you to go do a risk assessment and then deal with your highest risks and you know, do appropriate stuff. FedRAMP is the one standard, maybe a little bit with PCI DSS as well, but FedRAMP is the most strict prescriptive standard I'm aware of. They don't tell you, you know, do what's risk appropriate. They say do these things. You will, you know, if you go after FedRAMP High, you will automatically, using technology built into the systems, mitigate findings, vulnerabilities, as soon as they're identified.
There's really specific things you have to do. And it's interesting to look at if you're looking for some guidance for a program that's going to really take your security program to the next level, FedRAMP might be a good place to look. Yeah. And it seems, you know, one of the things I picked out of the article is that people are starting to figure out FedRAMP certification more. They had some stats in here where, you know, in 2014 it was taking between, you know, like 13 and 17 months to get FedRAMP certified, whereas in 2016 it was down to like 7.
So definitely maturing and people are figuring out how to do this better. Yeah, it is. It is beginning to be a more mature thing. Last news story for the day. LogRhythm announces a TAP program, a Technology Alliance Partnership program.
Have you taken a look at this story? Yeah, you know, so I think with all providers you want to have other complementary security technologies play well with your platform. LogRhythm being a SIEM, I think it makes sense that for them to be, you know, a possible central piece in your security environment. So this program is, is trying to get partners on board to be more integrated with their platform. It seems like a good thing for them.
You know, I did notice that this is a pay-to-play platform. So if you want to be in this program with LogRhythm and you're a vendor, you're gonna have to pay some money for it. So it wasn't anything outrageous, especially from a vendor perspective. But it's also not just something that's open to anybody. There's a bar.
Yeah, well, good to see that. And they had quite a few vendors who were in there right off the bat and good partnerships that, that we're looking forward to seeing how those develop. So let's go ahead and dive into the events for the next week. This is a very busy week here in Colorado, so we'll go, I think, a little bit faster through these. We mentioned RMISC already.
That's going to be happening Tuesday through Thursday this week. On the 10th, the Colorado Technology Association is doing a 101 event to learn about CTA. Also on the 10th, down in Colorado Springs, they're doing a CTU Presents presentation where they have Major General Nina Armagno, who's the Director of Strategic Plans, Programs, and Requirements at the Air Force Space Command down there. She's gonna be talking in Colorado Springs. On the 11th, SecureSet is having an event, part of their Expert Series.
Ben Yablon, I'm probably butchering that name, uh, talking about, uh, blockchain technology. Could, could be interesting if you're not gonna be able to make it to RMISC. Yeah, that does look pretty interesting. And then Friday and Saturday, we have the Denver BSides conference happening. Once again, we've talked about this one not quite as much as RMISC, but hopefully enough that you have a flavor for what we're talking about.
There's going to be a lockpick village, there's capture the flag, there's lots of great talks, so it's going to be beer the whole time. Try and make it if you can. I believe that there's, you know, there's no more, more, no more opportunities for you to buy a ticket ahead of time. But if you show up at the door, you have a good shot of getting in. Make sure you're there early though.
Yeah, for sure. We do have the jobs for the week. We'll go through these pretty quickly. TeleTech is hiring a network manager, excuse me, a manager of network security. So this would be reporting to Sam Masiello.
Sam was one of our guests recently on the show. Sam's a great guy, highly recommend taking a look at this position if you're interested in a new management position. Uh, the Colorado Housing and Finance Authority is looking for an information security officer. I assume that's probably down downtown, right across the street from the ballpark on 20th. That's where their main office is.
Interesting opportunity there. Amazon is hiring a senior software development engineer, network security focus. Yeah, so it's interesting to see, um, you know, both Amazon and Google and, and some other big players have been moving, uh, into the area. So it's, it's nice to see that they're hiring some people in Colorado for that stuff. It looks like that position's up in Broomfield.
National Jewish Health, they're looking for a security analyst. Newmont Mining is hiring an IT and compliance analyst. If you remember a couple months ago, we were talking about them hiring a leader over there, and he's in place now. CenturyLink is looking for a lead information security engineer for cybersecurity vulnerability assessment. Of course, CenturyLink and Level 3 are getting close to, I think, finishing their merger and they are going to be called CenturyLink going forward, I believe.
So would be interesting team to get involved with. Yep. And IHS is hiring an information security engineer that'd be headquartered in downtown Denver. And Lockheed is hiring a cyber intel analyst, senior. A senior one.
So I assume that means you have to have a son. Is that what that means? Or be very old. Well, I think that takes us to the end of the agenda here. Any, any final notes before we rush off to RMISC?
Yeah, Robb and I are going to be at RMISC this week. Come by and say hi. I think we're still debating, but we, you know, we may be trying to interview some people while we're there. So if you want to have a chat with us, let us know and we'll see about getting that set up. And we will have Colorado Equal Security stickers at the ISSA booth in the expo hall.
So come by there and pick up a sticker and share it with a friend. We'd love to have you share the podcast. And, you know, I know we've been talking about it for months, but if for some reason you are still not registered to come to RMISC, you can just show up and register on site. So don't feel like you're missing out because you haven't registered yet. Yeah, register online right now or register when you get there.
Either way, it should work just great. Well, I think that takes us to the end of the podcast. Thanks for your time. Stick around here for a few minutes and we're going to be going over to the feature interview with Chris Roberts. And you can hear me ask him about flying a plane sideways.
Ooh. All right, you guys have a good week. Thanks, Robb. Hello, this is Rock Lambros, Information Security Manager at MarkWest Energy Partners. This is Colorado Equal Security, for Colorado security professionals, by Colorado security professionals.
Well, this is Robb Reck with the Colorado Equal Security Podcast. I'm really fortunate today to be sitting with Chris Roberts. Chris is one of the best-known members of the Colorado security community. Sid Dragon is a kind of call sign online. Chris, I think I met you maybe 3 years ago at one of the BSides events when you were talking there and haven't had a chance to get to know you as much as I'd like, but we've met a few times over the years.
You know, as a starting point, I'd love it if you could just kind of talk about where you come from. You know, you don't have a Colorado accent to my ear. Maybe we could just start off, you know, with your distant past. Yeah, so nice to be on the show. Thank you kindly, sir.
I mean, I've been in the US since 1998. I came over here probably dragged kicking and screaming courtesy of a bit of an altercation between myself and some US assets. British intel and US and some other bits and pieces got dragged over here many, many years ago to help fix that mess I'd managed to cause.
Prior to that, obviously a lot of stuff in the UK, a lot of stuff in Europe in the security arena. I mean, I come out of IBM, 3Com, HP, DEC, and a few of the other places. Yeah. Where are you from originally? Where are you born?
Oh, born in Cyprus. Oh, wow. Okay. And part English and part Scottish on various different flavors from various bits of the family. So, did you move around or did you live in Cyprus?
Yeah. No, father was Royal Air Force. Okay. So, moved around. The every 2, 3 year cycle of— and fortunately enough, you know, lived in the UK, lived up north, lived in south, lived in— went over to Belize, lived in Sardinia, all over the place.
Yeah. So it's kind of nice. And then honestly, when I, I first got yelled at badly when I was 14, um, managed to get a bunch of computers confiscated. Were they, were they your computers? They were at the time.
Yeah, they weren't for much longer. Police managed to take those from me, bless them. And then just kind of went from there. Did military for a while, British military. Okay.
Um, came out of that and went back into the IT field. So did you— when did you join the military? Was that after high school? Uh, yeah, high school and I got on with each other until I was about 15 years old. Yeah.
And then we decided to part company fairly quickly. Mutually? Yeah, mutually assured destruction was about to occur, so yeah, get the hell out of there before anything too happens. Plus some stuff at home, but, um, Yeah, went from about 16 years old, 16 to 18, did a bunch of work in all— I mean, shit, I did everything from human resources to working in factories to working in early IT. Just one of those, okay, what do I want to do, how do I want to do it?
Yeah. Then did military for a while, uh, got thrown out of airplanes for a living. Oh wow. And, uh, came out of that and went back into the IT field again. Okay, so when, when did you go— obviously at 14 years old when you're uh, you're getting computers confiscated.
You're, you're kind of in the security realm at that point, I, I imagine. Uh, how did you go from IT guy, uh, later in your career to like formally back in, formally back into security? Um, I think almost fell back into it because it was, you know, on the IT side of things, I got involved in the networking pretty heavily. Um, I still have my non-disclosure from when a bunch of us signed it between IBM and Microsoft. So that dates me fairly well.
Yeah, in the days when this new thing called Windows NT was coming out. Yeah, so I still have the freaking install floppy disks for that bloody thing. Sure you do. Yeah, and so I go back and did a bunch of that, and then we went from there into security with OS/2, and then started getting more into the networking side of things, and then ended up working in the city for a while in London. Okay.
And got pretty heavily in the security space on that one. A lot of stuff on the backend financial transactions. And we got yelled at once or twice for some indiscretions. We're like, hey, you're not going to listen to us, sod it, we're going to move money. And then when you find out we've moved money, we're going to tell you how we moved the money and we're all pretty and clever.
And yeah, it didn't work that way. We got yelled at for moving money that we shouldn't have. It's life. But yeah, I mean, that was mid, mid-late '90s. Okay.
And then I came over here. What brought you over here and to where over here? I ended up landing basically North Carolina neck of the woods. Sure. And ended up working out of Virginia, North Carolina for quite a while.
And working with government agencies or contractors? Exactly. Government contractors and agencies. Yeah. Doing a bunch of work on crypto work, doing a bunch of security work, repairing some of the holes that we'd managed to break through.
Obviously out in the rest of the world, security, is it a vertical. I think, you know, we've matured enough that security means a million different things. What would you say your expertise was at that time in terms of security? Is it offensive security, breaking into stuff? Is it— yeah, you mentioned cryptography, you mentioned networking.
Where would you say your specialties lay? Probably at that time, definitely on the offensive security. Offensive and then a lot of networking stuff. And then the crypto stuff came as part of it because, I mean, the stuff we were going after was somewhat protected and somewhat controlled. Defeating crypto, defeating implementations.
Defeating implementations of crypto. Yeah, not necessarily defeating crypto itself, but defeating the implementations of crypto and looking at how would it be no different than we do today. Right. You know, it's like, okay, if I can't break something, how do I get around it? Yeah.
You know, more often than not, we don't walk in— well, actually, we do still walk in the front door. Let's be perfectly honest. But a lot of times we'll try to go in the side door, the vendors to partners or whatever, no different 15, 20 years ago. Now, when you talk about the crypto implementation issues, is it mostly key management or other issues? Bit of key management, still some of the human error side of things and storage of the keys, storage of the architecture, one-time use, a whole bunch of other stuff.
I mean, it's what's frustrating. It's almost the same problems we face these days that we faced, you know, whatever we're now like 18 years 19 years ago now. Key management is very difficult, and humans following procedures is not getting any easier, is it? Not at all. Not at all.
I mean, and it's not gotten any easier. And the problem is that the problems have gotten more complex. The architecture is more complicated. The systems we're using are more convoluted and more spread out than they ever were. Yeah.
You know, we always joke when we're standing on stage that, you know, 20, 25 years ago, security was easy. Easy. There was the mainframe, and then there was the man on the door that would shoot you if you went to the mainframe. You know, nowadays, a little bit more diverse. Sure.
So you were in North Carolina, Virginia, DC area from '98 to when? Till probably early 2000s. And then it was kind of— I bounced around a bunch. I was up in, let's see, Toledo. Then I was down in Atlanta for a while, then up in Toledo, Ohio.
Ended up getting to know somebody who I ended up getting married to for a while, not a very long time. And she moved to a university in Toledo, Ohio. And I remember going there and realizing how freaking flat it was there. Scared the hell out of me. Then ended up in Chicago for a while, working in Chicago.
And then from Chicago went down to Atlanta. And I got down to Atlanta at around about the same time the entire market decided to take an absolute nosedive. So it was fun watching that. Was that, was that the 2007 or was that the 2001? It was like 2001-2003 time frame.
Okay. Um, ended up going back to DC and New York for a little bit when some dumbass decided to drive shit into buildings and stuff like that. Got dragged back into that, came out of that, back down to Atlanta. Um, quite honestly, at that point I'm like, screw it, I'm done with technology for a while and went climbing down in South America for 6 months. Oh wow.
Yeah, I just went down to Bolivia. I'm just like, I was literally, I was getting divorced, whole bunch of crap going on with the ex, and it was one of those eff it moments. Was it just by yourself? Yep. And just met a lot of people and a lot of people hung out with a lot of people, got some amazing pictures.
Pretty awesome flipping time. 6 months, huh? Pretty much about 6 months. Went down there, came back, still sucked. So what did you, did you get I had to dig into this because I have these visions of going somewhere for 6 months.
Did you get tired of it after 6 months or were you just like, hey, I can't keep doing this because I need to have money? Why'd you end it? Why'd you stop?
To some degree, it's that dream of just being able to escape technology. You know how it is. Sometimes you're like, screw it, I want to put the technology aside. Well, that's what I did. And then every now and again, and it got more and more regular, it was like, I want to get back into it.
I want to get back into it. I miss it. How do I— that whole disconnect lasted for about 3 or 4 months. Yeah. And I was like, okay, I've got to get back into this.
And it was— it took me a while. Plus then when I was in the middle of nowhere and I was like, okay, I got to figure this shit out, it took a couple of weeks to get back from middle of nowhere to actually civilization and then head back up again. So you— so you were— you were there long enough to miss— miss your— your real life your normal life. Yeah, I mean, and it's rough because, I mean, I'd gone through a divorce. I have a, you know, I had a daughter from that and I hadn't seen her.
I hadn't talked to her and heard from her and she was, you know, still a wee bairn. So it was a case of like, okay, I cannot escape this forever. I've got to go back and sort this shit out. So, so you came back to civilization? Came back to civilization.
What'd you do? Realized it still sucked. Went up to Alaska and went climbing for about another month. Yeah, that's pretty funny. Yeah, I was just like, God, it's still awful.
Went up there, came back. I got a phone call from a friend of mine in Milwaukee who was like, hey, we need some help. Yeah. And, uh, ended up going up to Milwaukee and helped those guys out for about a year or so, I think it was. I was up there for about a year or so.
Um, ended up meeting somebody else, and I ended up— I got a phone call from Limited Brands saying— and they're in Ohio— and they're like, hey, we need some help, we've got problems. So I'm like, who the heck are you? I had no freaking clue who they were. They're like, we're a clothing company. I'm like, so what the hell do you need security for?
Completely not thinking, working in the financial sector and just brain wasn't switched on. They're like, uh, well, we own Victoria's Secret. And I'm like, oh yeah, that's a big website. And they're like, yeah, it's about a billion dollars. I'm like, oh yeah, Yeah, you probably need some security.
So, I ended up going out there and worked for an amazing guy. Dave was brilliant, totally great from a mentor, manager mentor standpoint. Ended up working with Clyde and a bunch of other guys out there, really, really nice. Were you in the security team over there then? Yeah, exactly.
Yeah, did a bunch of work on the security team for a variety of different people, things, and bits and pieces over there, basically pet projects and stuff. What years are we in right now? Oh God, we're— let's see, because Squeaks is now 13, so that would have been— what are we in, 2017? 2017, yeah. So 4 or 5, 4 or 5, 2004, 2005-ish.
That's when you're in— you went from Milwaukee to Ohio in that timeframe. Stayed there for about a year and a half-ish. Yeah. And then a good friend of mine who was the— I think he was the CISO at Limited ended up coming out to Colorado and, uh, took over the Sports Authority. Oh, and basically was the C— I think Robb was CIO over there.
Okay, something like that. Yeah, senior chap, definitely senior. I'm pretty sure he was CIO over there. Um, got a phone call from him and he's like, hey, we got problems. And I just started giggling cuz it's Robb and he knew me and I knew him, and, and it was one of those where he was like, yeah, we got some problems, we need some help.
And he was gracious enough, flew me out here, and I'm like, wow, this place is pretty amazing. Got in there, got talking to everybody, and they had some challenges, so they flew me out and they flew the family out, and we all traipsed out here in 2006-ish, give or take a little bit. Yeah, uh, Matt Shufeldt at the Sports Authority at the time, was he the director of security there? He wasn't the director of security at the time. Yes, Matt, I'm assuming that— no, yeah, because it's all folded, the whole place is gone.
Yeah, yes, Matt at the time was like operations manager or something. Yeah, he was not security focused at all. Yeah, he's, uh, you know, he's now the CISO for Trizetto, which is a healthcare company. Yeah, yeah, okay. No, yeah, Matt was an interesting one.
Um, yeah, unfortunately I managed to annoy— I got in there, did what I needed to to get done, got them all secured, got them all sorted out, and then did what I normally do, which is manage to crater myself at the same time. Um, I, I do not apparently work well in large corporate environments for anything longer than maybe about 12 months. Yeah, I think that's the maximum I managed to deal with before I piss enough people off that they're like, get rid of him somehow. So you— so I assume then you were there 2 2006 to 2007 or so helping with Sports Authority, helping TSA out, getting a bunch of their stuff out, and then went out on my own. And what did you— what do you say, went on your own?
Do you start your own company? Yeah, God, I think we went through like 4 or 5 companies. I had Unearthly Mess for a while, which is still sitting behind the scenes. I had CCI5, which was— the acronym was Commercial Counterintelligence, and it was like the first. So this is 2007-ish.
Yeah, this was the first we really started to build what is now called threat intelligence, which is let's scour the darknet, let's basically see what's out there about an organization, help them understand what their external threat footprint is, and then they can cross-reference it with whatever the hell's going on on the inside. Again, a standard thing is like, it's all very well basically building new firewalls and building all the architecture, but if your developers are hardcoding passwords and putting it on GitHub, why the hell bother? Sure. And, you know, if the bad guys in China, Latvia, wherever are stealing that data and using it against you, then your focus is completely incorrect. Yeah.
So we tried dealing with that, but that was early, early days. And, you know, it's that new product with 3 or 4 people at the helm trying to talk about it, just didn't go down too well. So did a bunch of different stuff from there, ended up forming PsyOpsys We put CCI5 on hold, ended up forming PsyOpsis, which is actually still going in a different entity. Then it was myself, a gentleman by the name of Mr. Taylor, who is a lawyer here in town. It was a former federal agent, which is ironic given my fun with the FBI these days.
And Craig, I can't remember Craig's last name. It was basically 4 of us formed PsyOpsis. Formed it. And the whole concept was to bring forensics to more of the lawyers in town. So the computer forensic stuff was early days.
A lot of people were like, hey, really struggling with it. How do they deal with it? How do they gather electronic evidence? Can they use it? Is it useful?
What the heck is this e-discovery hold and all the other stuff? And it was a bit like the Wild Wild West. So that's where Charles Tendril and I ran into each other. And Charles and I mean, heck, I talk with him pretty well almost weekly these days. But that's where he and I ran into each other because we'd occasionally be on opposing sides of the table with lawyers.
So they'd engage us, we'd go do the forensics, we'd get everything sorted out, we'd obviously make sure we had all the handling and everything else was done properly. And then he and I would appear in court on the opposite side of the table lamenting the fact that we were dealing with bloody lawyers on a regular basis. And yet still doing it. But CCF, uh, Syopsys didn't really want to get into the business of the pen testing and assessment stuff. Their bread and butter was very much— they really wanted to focus more on dealing with, you know, the forensics and dealing with the lawyers, get brought into breaches, do e-discovery, do legal hold, all that stuff.
And that, that's great, but I got bored. And so it's one of those like, hey, we want to get back into doing pen testing and assessments and consulting and maturity modeling and all that stuff. And We ended up parting ways. They ended up— it was when we formed the company, it was all equal shareholders. And when I parted ways, it was a 3-to-1 vote.
So I managed to get myself voted out of my own company. Ouch. Yeah. Unfortunately, a trend that manages to continue. That's not a fun day.
No, it was not a fun day.
So what do we do from there? From there, well, Al came into existence. Is that OWL after Sapsys? Yeah, pretty much, because that was 2009, the end of 2009. OWL, One World Labs, right?
Yeah, acronym helps. Yeah, One World Labs. What was the vision there? The vision was twofold. One, to basically start up another security pen testing company, but not to do— and I'll use Justin's words here— what they call, what is it, the puppy mill pen testing.
And JW's got full credit for that word, for those who words. Not to do the generic, hey, we're gonna come in and do a pen test, not to do the box-standard crap, but actually to get in there and do it properly and to help an organization to basically, to be honest, cherry-pick organizations that would actually want to fix shit as opposed to going in and just doing it for the sake of a tick in the box. So it's a lot more to go in there, do the pen testing, do the assessment, help companies understand what the heck was going on, and at the same time, the vision was also to get this intelligence platform up and running again. I'd like— I want to dive just a little bit into your ideal customer candidate. In that case, what's a company that you, from the outside looking in, what's a company that you want to work with?
What does that look like? So, I mean, that's easy. Honestly, we've got probably 3 or 4 or 5 in town now that we're dealing with. Funnily enough, we're doing a lot of work with the growing industry. And for me, they're great because they actually realize they have a problem.
They don't always necessarily know what those issues are. They can't necessarily always quantify it, but they know there's a security problem. They know what it is. They're willing to listen. They're willing to engage.
They're willing to lay everything bare. It's not a game of cat and mouse, and they're willing to change. So, I would assume when you say growing, I assume you mean marijuana industry. Yep. I would assume that those companies don't have much of a security department.
There's no security department, probably, right? No. Now, when you engage with those folks, you probably don't need to do a pen test to know what they need to do to start, right? No. It's a consulting, here's how we build a program type of an engagement, I'm assuming.
Yeah, no, that's 99% correct. If anything, anything, we'll go in there really quickly and say, okay, instead of doing an actual pen test, let's actually do a maturity model. Yeah, no, I'm good. Okay, let's just— we'll do a maturity model. So we'll go in there, we'll ask them a bunch of questions, we'll sit there and have a couple of hour interview with them, literally, because it's easier, cheaper, less hassle.
And you know damn well that you can take everything from them. That's not the goal. The goal is like, okay, where are you? Where's your baseline? Right.
And how do we improve you? Yeah. And maybe in or 2's time, I'll get hold of somebody else and go, hey, we've got these guys where we think we're happy with them. You come in and see if you can break in, and then let's learn from there. Yeah, that's a great way to look at it.
And when you're not driven by compliance, if you're driven by the need for security, that works, right? When you're trying to get your PCI checkmark, it's a whole different environment. Well, some of these guys are driven— so one of the growing organizations we're dealing with does a lot of tracking from basically seedling all the way through to, you know, a final product. So, there's definitely elements of compliance in there. But again, their approach is, hey, this is what we built, this is how we built it, this is what we're doing, help us improve it.
And it's awesome because we've got a couple of good guys we're using to basically delve into the APIs for them, delve into the code for them. We're looking at the physical aspects of it. I did an amazing— we did a user training, user awareness session last week, week before for last. We just went up there for a couple of hours and just hung out with the entire team. Yeah.
And I took a presentation I'd done probably 2 years ago called Gunning for Grandma, and I did it over at DU for a bunch of, you know, 65, 75-year-olds. It was freaking awesome. We had a riot doing it. And I kind of changed that around and gave it to these guys, and it was the same kind of lessons learned. It's like, hey, here's what we can help you with as humans And if you take some of this on board, this is how it's going to help the organization that's giving you a paycheck every 2 weeks.
Yeah. And so it kind of works out really nicely. So you mentioned the 2-prong approach, the services, and then you also were working on the intelligence product, right? Yeah. Yeah.
And again, what's ironic is we started off by bootstrapping it. So it was like any money that we got in from consulting and any money we got in from pen testing, the money obviously paid people. The rest of the money went into into the product. And that's good, as you and I have talked about, that's good for a certain amount of time. But eventually, you know, you realize that the gorillas in the room are starting to catch up with this newfangled thing called threat intelligence.
And it's like, okay, do we kill it or do we try to grow faster? And at that point in time, when you look to grow faster, you've obviously got to go for outside money. Yeah. So we started to engage with the angel investment community. And, you know, first, one of the first times I'd end up doing that, we had a couple of people on board that thought they knew how to do it better, and we had a couple of people on board that had ideas and had friends.
And so we went out to the community, we went out and we talked to a bunch of people, we got a couple of people to sign up, which was pretty awesome. But in doing so, we handed over control to the company. You know, I had, you know, there were a number of us that had stock in the company and Yeah. And unfortunately, when we got the investment money, they split the stock and said, okay, this is common stock and this is preferred stock. And because we've put money in, we will get preferred stock.
And unfortunately, that was one of the first tipping points. And it was one of those things where I didn't know enough to argue. Right. And I didn't have good enough counsel on my side. I didn't have— I didn't have a good enough mentor on my side to say, hey, that shit shouldn't fly.
Well, you're a security expert, right? And that's too broad, but you're an expert at the things you're great at. And, you know, talking about offensive security and cryptography, what we were talking about earlier, you're probably not an expert at understanding venture capital and understanding corporate structure. And it's really a challenge. We talked about this offline earlier, to be a— to be really good at what's going to make a great product and also really good at growing a company?
Oh yeah, I mean, it's a huge difference in skill sets, and it's unfortunately one that I've had to learn through some pretty nasty bumps and bruises. Yeah. And some pretty negative stuff that's still hitting me these days. But it was definitely one of those where I didn't know enough to ask the right questions. Yeah.
Relyed on others both inside the company and externally who either didn't know enough or didn't realize enough or didn't care enough or didn't understand understand enough, or they had other motives or issues. So we raised some money, and that money went towards basically building a team out to build the product. Yeah. So pretty quickly, you know— What year are you talking about, by the way, when you raised that money?
2011, 2012-ish. Yeah. Yeah. And we'd raised some initial money, and that money got used to basically build the product. I mean, it was— that's what Owl's intelligence platform was based on.
Yeah. And it was, you know, it was good. It was a cool product. It took a lot of development and it took a lot of people putting a lot of time and effort in. Absolutely.
One of the other big challenges we had was obviously selling it. You know, it's like anything, good security product, good company is one thing, selling service is one thing, selling product is an entirely different ballgame. Different skill set, isn't it? Oh yeah, totally different skill set. And we didn't have that right skill set.
So, we struggled with that. And again, you know, the problem is when you're competing against the likes of Optiv and other companies like that who, you know, they have a budget and they have such a huge client base to pull from that to them just putting a press release out and something else saying, hey, we do intelligence or we're building this, it kills us. Because now, you know, you go talk to a company, you go, hey, we're doing this, and they're like, well, Optiv's doing it and they're bigger and they're nicer and they've got more bells and whistles. Yeah, it screws up a lot unless you can actually do a lot to prove it. So I think that that is kind of the fundamental, right, coming in with, you know, David and Goliath.
Uh, what were your lessons learned there? What, what would you have done differently or better in terms of just on the product side? How would you compete in a market that you know you're not going to be the only one in? I think so, a couple of things. One, we probably, we would have polished the product a little bit more.
But again, that means getting into the development life cycles. It means getting into tying that down a lot more effectively. Slower to market. Yep, slow. But the problem is slower to market, that means everybody else beats you.
You know, it's the one thing at Calvio we're dealing with now is we're getting chewed on a little bit because from the deception stuff, we haven't released a product and there's a bunch of other guys that have. Now, when we do hit the market, this thing's going to kick ass. Yeah. So, their theory hopefully is a better way of doing it. So maybe we should have taken a bit more time to get to market.
I don't know. Or honestly, one of the biggest things I had is if we had taken investment money, sure as hell structured it a lot differently. Yeah. So you took money in 2011, you developed the product for what year? 2012, 2013?
2012, '13. And we started releasing it. I mean, we had some good clients, we had some good people that beta'd it, beta'd it, whichever you want to look at it. And we got people on it, but again, it was a tough sell. And it was one of those, it was like, okay, do we do subscriptions, and how do we do this, and what's the pricing model?
I mean, the 101 things. The business things, yeah. Yeah, unless you've got somebody who knows product. I mean, we were freaking winging it, for crying out loud. But we winged it pretty well, and all the meanwhile, you know, the professional services side was kicking ass.
So, I think that was the frustration because eventually we ended up going back to the well, to the investors and saying, hey, we want to raise another round. We should maybe go after actual venture capital money as opposed to going after the A round guys. Yeah, well, the A round guys were like, oh no, we'll take care of it, we'll deal with it. And so they re-upped all nice, all credit. But again, in doing so, that dilutes the stock, it dilutes the shares, it gives more control to them.
And then you end up with a board that has to to get formed, at which point you've only got 2 friendlies and 3 investors on the board, and it started to get ugly, to be honest. So, so I, I don't want to skip ahead, but, you know, it seems like we're getting close to 2015 where, yeah, there was the, you know, the, the big story that you were well known for that year was the, uh, some tweets I believe that you had sent out about, um, a flight that you saw vulnerability on an airplane. You want to talk about that at all? Yeah, so let's see, if we go back in time to 2011, 2012, 2013, yeah, we'd obviously, as well as obviously all the pen testing and everything else, we've done a bunch of research, um, and we'd done stuff on cars. I mean, Jesse, myself, uh, at Chris's at B-Sides when B-Sides were still Chris's.
So we're like number 1, number 2 B-Sides at this point when it was still in the freaking house with a pool. Yeah, we'd released a whole bunch of stuff on hacking cars and vulnerabilities in cars. So that's, you know, 9/10/11 timeframe. We then focused a lot more on airplanes. So we started to take a look at the airplanes.
We took a look at the control surfaces. We took a look at how we can get to them on the grounds or the ground control computers. We then started to take a look at, you know, basically what makes an airplane, you know, how many different components, how many different vendors, how's it all connected, how's it all talking? We started to build up a fairly clear picture as to various attack vectors at that time. So we're 2011 to 2013 timeframe.
We started to try to reach out to all the major players, all of the major organizations, the partners, the vendors, and everybody else. And for the most part, got pretty well stonewalled. So started to talk about it at conferences, talked about it at BSides, talked about it at at Derby, talked about it at GURCON, a lot of the other conferences. It started to get enough traction that a couple of those vendors approached us and said, hey, we want to talk more, let's go under NDA. Brilliant, things will get fixed.
So, we went under NDA with a couple of them, and for 2 years they did absolutely nothing despite repeated conversations, repeated calls, repeated discussions. So, when the NDAs expired, which was, you know, 24 2015 timeframe, it was like, guys, you've done nothing. I still know there are vulnerabilities both directly in the cockpit systems, directly in the flight control systems, and in the infotainment systems. You haven't fixed it. You haven't done anything about it.
You haven't engaged us because it's a two-pronged— you know, again, this is one of those things. Research is great, but eventually it would be nice if it actually pays for itself. So can we engage with any of these customers and quite honestly get consulting engagements with them? Right. You know, there is, you know, taking all of the— taking the— what's the word— the altruistic side out of it.
At the end of the day, you've got a team. You know, Al had at the peak like 30-plus people. Those people are going to get paid every couple of weeks and they've got families relying on the fact that we're doing business. So the altruistic stuff and the research is good, but it gets the name out there to basically start bringing more business in. So it got to the stage where nothing was really getting fixed and it was one of those sod it moments.
Now, before everything blew up on the actual plane, we'd had conversations, got approached by CIA and FBI to have conversations, had conversations with those very well-documented conversations. And Al's lawyer and Al's CEO at the time both said, yes, you should have this conversation. So I did. And unbeknownst to me, the feds obviously took notes, and arguably their notes ended up in an affidavit and not necessarily how they should have been or could have been articulated. Some differences between, you know, what was remembered and what was written.
And so that obviously caused some concern. And then obviously, I think what ended up happening was I was on an airplane. Plane heading out to the East Coast to give a presentation on avionics security. Yeah. And I got a, I got a text message from a friend of mine.
I was literally sitting on the plane heading to Chicago, got a text message from a friend of mine who basically said, hey, see this press release? And what had happened is I think one of the government agencies had put out a release going, hey, your avionics suck. And one of the major players based in Europe had said, oh no, we're perfectly safe. Now, Knowing full well that I had sat in the leadership's office of that particular European manufacturer and explained to them how their stuff sucked and how they haven't fixed it, I sent the message out on Twitter going, bullshit, I'm sitting here and this is what I know would be possible. And so that tweet obviously blew up.
It obviously united— sorry, United had handed it over to the FBI And then when I ended up in Syracuse, the FBI met me on the plane and said, let's have a good conversation. Yeah. So what— how did that tweet get translated into— so to, to Al getting blown up? No, well, to the, to the someone saying you— the plane flew sideways. This is— I didn't— I'm not the first one to say this, right?
This is, yeah, this is, this is a thing that was a meme for a little bit. What happened there? So what had happened was the research that we'd in about 2011, '12, '13 timeframe. The research had been done both on the ground and in the air. We'd had discussions with the feds and they were kimono wide-ass open discussions, you know, kimono open and a bottle of lube in hand, basically, to be fairly blunt about the whole thing.
And we told them everything because the FBI had come in with the CIA and said, we want to know because we want to be the champions of this. And we want to be the ones that go beat up on the vendors because you're not getting anywhere. You know that, we know that. We want to be the ones that want to go beat up on them. And I'm like, brilliant, I'm gonna hand you absolutely everything that I've done, all the conversations, all the discussions.
Didn't physically hand them any cables, didn't physically hand them everything, but basically just basically went, here's all my data, here's all my data. Yeah, and that data included a whole bunch of ground stuff, a whole bunch of like in the stuff that was done in research, nothing that went into attack or any of that kind of stuff. All of the, hey, we had a maintenance computer and this is what we did. We had this and this is what we did. So that unfortunately got taken a little out of context.
And I have to be careful what I say because there's a bit of an ongoing war of words, shall we say, between all parties concerned. But that unfortunately didn't get taken as it should have been taken. And yeah, the whole flew the plane sideways thing came out. So you— the FBI, you said in Syracuse, they pulled you aside to have a conversation. Can you share about that?
I don't want to dig in too much, but if you would, I'd love to hear it. Yeah, I mean, there was obviously the, you know, there was the initial, what the hell did you do? Like, uh, nothing. There was the, well, this is what you said. Okay, this is what the context of it was.
And so, I mean, I was very forthcoming, very forthright, had discussions with them. They wanted to look at my laptop to see what tools I had on there, and I said no, because I obviously had client data on there and a bunch of other stuff. What's ironic about it is the threat platform that we had was on a regular basis pulling top-secret level data off of the darknet and off of the internet. You know, it's unfortunately standard. You know, guy goes into a SCIF, comes out of the SCIF with more than he went into the skiff with because he wants to research it and do work on it, puts it on a computer that's either broken, pwned, or connected to the flipping internet, and hey presto, it's all released.
Well, a lot of that data was sitting on my laptop, and I'm like, you're not getting to that data. It's not yours. You don't have a clearance to see it, and you don't need to get to it. And by the way, I've got client data on it. I called up Al's CEO at the time and said, hey, guess what?
And he's like, don't let let him have access to it, so I didn't. Yeah, so they confiscated the computer and the USB drives and the iPad and a bunch of other stuff. And, you know, it was a very professional, very civilized conversation. And needless to say, obviously FBI in Syracuse contacted FBI in Denver, and the relationship between the two has been a little fractious at best, shall we say. So I, I, if I remember correctly, at least for a while, you weren't allowed to fly on a particular Oh, I'm still not.
Apparently there's an entirely new database for me. Bless them. You made your own database, huh? Apparently, yeah. So no, I'm thankfully— I will give a huge amount of kudos to Southwest and British Airways because those guys have both gone, hey, tried doing the right thing, got it, bit of a dumbass for tweeting, but you're in good shape.
Plus I think Southwest doesn't have infotainment in the seatbacks either. Know. But, uh, yeah, you know, they have their Wi-Fi. They do, they do. And I play nicely.
I have to. Good choice, Griff. Yeah, no shit. So it, um, it went from, you know, I— at one point it seemed like maybe even good PR for your, for your company and your career when, hey, this guy is an expert on this thing. Yeah.
To, uh, to kind of things falling apart. Yeah. Well, so I, I think what a lot of people haven't heard, and hopefully those that are still pissed and those that are still like blaming me for all of it, unfortunately. So this happened in whatever it was, February, March timeframe. So prior to that, so if we go back to— this is what, 2015?
So if we go back to the end of 2014, the very beginning of 2015, Owl's board of directors and I were getting sideways with each other, and I'll use that tongue-in-cheek. Our board of directors didn't want to go out and get a certain amount of money. They wanted to sell the company. They wanted to sell to both Fishnet and what was AccuVont at the time, and they had a couple of other suitors. So, they were trying to basically get the company all pony wrapped up and everything else.
At the same time, the development side was running out of money because we were burning through cash pretty extensively. You know, when you're out pen testing and assessing, that can support a certain amount of work and effort. But when you've got a team of, you know, 10, 15 developers or whatever, they burn money pretty quickly. So we had a certain pool of money that had been brought in from the angel guys. We had money that we were trying to put in from the rest of the company.
We were burning through it. Yeah. And so the end of 2014, there was a whole bunch of discussions of, do we get rid of people? I'm like, no, we can't. We've got to find out a way of doing this.
The board wanted to do one thing, investor board wanted to do one thing. I was pretty adamant I wanted to do something different. You know, we had a couple of what was Excelis at the time, who got bought by Harris, was interested in us. We needed to sign basically more contracts to keep everything afloat, but they were spending more money doing bullshit stuff than they were putting into sales and marketing and everything else. So I was frustrated that the direction certain things were going in wasn't the right direction.
This was like December, January, February timeframe. Yeah. So we had some really fractious, engaged discussions, and they weren't pretty and they weren't fun. Most people in Owl had absolutely no freaking clue this was going on. Everybody thought everything was great and happy.
So fast forward to the airplane thing, and now the board of directors and the investors have now got an excuse to go, huh, he is a risk. He's a threat. He's a loose cannon. And we need to do something about it. I'm sitting there holding whatever it was, like 50% of the company's common stock, not preferred stock.
And so they're like, okay, how do we get rid of him? At the same time as basically the money that they were going to put in and they had a bunch of promises. In other words, we needed a new CEO. I wasn't happy with the person they chose. They were like, well, if we bring him in, we will recapitalize.
And fund the company. Great. Well, that didn't happen. They brought the person in, they didn't put the money into the company. So now I'm sitting there with somebody that I didn't want in the company and no extra money.
And by the way, we're paying them money as well. So now more money is going out of the freaking company. So we fast forward and the board's like, okay, he's not agreeing with us, he doesn't like us, he's now on the front page of the news. We feel embarrassed, we feel hurt, as opposed to going, holy shit, we can use this as a positive spin, it got into the, great, this is a way to get rid of him. And as part of that, because they didn't put the money in, they basically had to say we had to let pretty much 50% of our staff go at the same time, which sucked.
Yeah, 30 people, 15 people let go. Yeah, basically 10, 15 people gone one Friday. It was a bad day. Horrible. Yeah.
Um, and obviously I got blamed for that and everything else. And then basically what ended up happening is like, well, we can't get rid of them. I end up saying I'm done, I need to quit, I need to resign. Um, and they ended up taking the company through bankruptcy to get rid of my funds. And the 2 people who were the CEO and the CFO bought the company's assets for $50,000 and started up Owl Cybersecurity or whatever the hell it's called now, and then started to rehire people back.
So needless to say, I don't have very good feelings towards many of those people. I mean, obviously a lot— I'm sure there's a lot of lessons here. I— oh yeah, I honestly, I feel like we could go another half hour, but you have a, you have a hard stop here in 7 minutes. So I'm gonna— I, I do want to give you a chance to talk about, uh, what you're doing now. Yeah, what's, what's got you excited, uh, these days?
And then I want to ask you about the community here in town as well. So yeah, tell me, tell me what's going on now. So it's kind of cool. Um, Accalvio— so after the whole Al debacle, um, a good friend of mine had a company I joined. I basically went under the umbrella doing pen testing and assessment and consulting.
Accalvio came along and said, hey, we're interested. After me being kind of stubborn for a while, we ended up agreeing. And so now working with Accalvio, I'm their whatever, my chief security architect or something like that. They're awesome. It's Deception Space.
I love what they're doing. I love how they're building it. And I love the whole idea that they're building something that actually might slow me down. So, you know, you break into a company, you've pretty much got carte blanche wherever you go because you can identify everything on the network. The whole concept about how they're building deception is it morphs.
So it sees activity, it's able to basically drop both thin and thick deceptions out there. So I never know if the handle I'm rattling of the next computer is a real one or a fake one. Yeah, a whole bunch of freaking cool technology and some really, really— what I love about it, there's people in the room smarter than me, and I'm like, yes! I really, really love the fact that I'm working with these guys. Totally awesome company, totally awesome way of doing things.
They've obviously got their challenges just the same as anybody else have, but what I love about it is they're just basically like, Chris, get out there, go talk on stage, go have fun, go discuss, go do professional services because we're still doing a bunch of that. And by the way, help train the deception technology to think the same way I do. So, pretty awesome. So, where's headquarters? They're based out in California.
Silicon Valley? Yeah, they're in literally just Santa Clara. So, just south of San Fran. Totally awesome bunch of guys. And how big are you guys now?
Yikes, 50, 60 of us between here and a bunch of guys over in Bangalore, over in India, and a couple of us out here and a few other places. Yeah. And, and you do have a product that's, that's for sale now, or is it? It's near as damn it. Yeah, it's, um, it was demoed at RSA.
It was demoed, early demo of Black Hat. It was demoed at RSA. We've got a bunch of clients on like TR1, TR2 stuff. Yeah. And they're working through a whole bunch of TR1, TR2.
I mean, there's some TR2, some amazing stuff out there. So it's kind of cool. There's a bunch of clients and a bunch of excitement that's getting built up. And now it's like, okay, now we just want the final sign-off and then get it. And the nice thing about it is, is they've gone, okay, go break it.
So the whole idea about a security deception company bringing in the hacker not only to help train the tool but make sure the bloody thing is secured when it's released, that's what I love about it. Yeah, it's an interesting developing field, deception technology. I, you know, we've had honey pots. But, yes, smart deception technology is something that's really been a new topic over the last couple of years from my perspective. Yeah.
And it is because you're right, honey pots were the great things and they started it all. But now— oh, yeah, I love them. Honeydew. I love it. But it's definitely— it's stepped up the game.
I mean, it really has. And now the fact that these things are at the stage where they can learn from behavioral analytics, they've taken a pretty decent leaf out of Mother Nature as well, and they translated that to the tech world. It's actually pretty cool. Yeah, well, I definitely want to hear more about it. Yeah, but I want to ask you one final topic before we go in just a couple minutes here.
I know one of the things we try and do on the podcast and with the movement is highlight all the different groups in town that people could be involved with. Yeah, and you know, you go to our website, we have the organizations tab, and there's all the formal groups there. Yeah, what you don't see is a link and a website for for the 303 type guys. That doesn't exist. And I'd hope maybe you could just spend a minute or two talking about, you know, really what makes a formal or informal group, you know, the collection of you guys who have all this experience, you know, on the offensive side.
What is the 303 group? And if someone is interested in getting to know you guys, what's the right way to try and do it? I think so. It's interesting. It's like a well-knit team.
Dysfunctional family. I mean, it really, really is. I mean, I, I've been in and out and I bashed my head against a bunch of things, but I would do almost anything for most of the people that I know around there. I mean, it really is a family and it's about as dysfunctional as it's possible to be. Yet somehow or other, every year we managed to actually put on the stuff at DEF CON.
Yeah, there are some amazing people in there who just go above and beyond it. I mean, they're freaking amazing people. Yeah, and it's a lot of, a lot of people would step out of line to do a lot of things for a lot of their friends. I think the best way of doing it is honestly come to like the Rocky Mountain InfoSec Conference, which is going on soon, middle of May. Yeah, yikes.
And then BSides is the 2 days after that. BSides is after that. So I mean, get along to those. It really is get into both of those and just come along, get in, get involved. Yeah, I think it's a lot unlike the makerspaces and stuff like that, is it's kind of getting involved in that stuff.
And that's a lot of it. It's just coming in, being involved, you know, taking some shit at the same time, um, giving some shit as well. I mean, that's, that's a big part of it. It's, it's a lot of that. And it's just, it's good.
There's a lot of good people. Uh, and I— is there— we're basically out of time, and I want to be respectful of your time. Yeah. Any final things? You know, you talk to the community here, hopefully you're talking to a few hundred people here in Denver.
Yeah. Well, anything you want to say? Uh, I think it's interesting. So, Wynn and I were talking earlier on today about the community, and one of my biggest frustrations is we spent 20 years beating up on people, and yet we still can't get them to remember passwords. I think some of what frustrates me is, as a community, we've got to somehow or other do a better job of reaching out to more people.
Is it into industry? Is it out to my grandmothers and grandfathers, to the young kids? How do we get better at communicating what we know and not just getting the word out there, but also bringing up the younger generation? I mean, one of the things I love doing is going out. I was talking at a bunch like Arapahoe and a few others.
My job is nothing more than making sure that those that are following on from me do better than I do. Sure. Preferably make less or make different mistakes. But I think that's the big part of it. It's just get out there and talk more.
Well, that's great. And I'd add on to that, maybe talk less to people and talk more to other people, right? Yes, yes, hugely so. Yeah. Well, Chris, thanks so much for your time.
We'll call it a day. I want to say I want to talk to you again in a few months because I don't feel like we got nearly as far as we needed to, but we can't keep going. Totally. So thanks for your time. Have a great day.
Appreciate it. Thank you, sir.
Learn more about the Colorado security scene at colorado-security.com, where you can information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado Equals Security.