All episodes

Don Bailey

Apple Podcasts Spotify SoundCloud

In this episode:

Don Bailey of Lab Mouse Security was our featured guest. News from Boom Supersonic, TapInfluence leaving Colorado, Microsoft, ProtectWise, SecureSet, LogRhythm, Ping Identity and root9B.

Happy birthday 'Murica

It's our nation's birthday! We hope you are grilling a hot dog, hanging at the pool in your flip flops as you listen to this episode. We kept it quick so you don't burn (on your shoulders or your grill) while you listen. Robb sat down with local security entrepreneur Don Bailey of Lab Mouse Security. Plus all kinds of great local news. 

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. We're continually working to improve the show, and appreciate the feedback we get from our listeners. If you discover any audio issues, or have suggestions for our format, let us know.

This week's episode is available on SoundcloudiTunes and the Google Play store. Reach out with any questions or comments to info@colorado-security.com

Feature interview:

Don Bailey, founder and president of Lab Mouse Security, sat with Robb to talk about how he made his way from studying and playing music, to hacking phones and cars, to securing the Internet of Things. Don sheds some light on the Colorado security scene and where he sees the industry going. Find Don on Twitter.

Local security news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events:

View our events page for a full list of upcoming events

If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript11536 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is episode 22 for the week of July 3rd, 2017. This is holiday week.

We're going to keep this episode pretty short. Alex, glad to have you here though. It's short, so we're done. See you later. Thanks, Robb.

Well, we are going to— we're going to go through it faster than usual, let people get on to their holiday, Fourth of July holiday, and we're going to be out of town watching fireworks or setting off fireworks or something. Exactly. Try not to burn things down. All right. So let's jump into the news first.

Axe throwing. We have Denver. Not only— we mentioned a couple of weeks ago that there was an axe throwing chain coming to Denver. Believe it or not, this is a fad and there are 2 axe throwing chains, not one, But 2. Yeah, so that the new one that is coming in, I think it's, well, I can't remember the name, but it's downtown Denver at Lawrence and 20th, really close to my office.

So I've actually scheduled my team meeting to be there on sometime in August. We'll have to hear how that is, Robb. And I will report. Absolutely. Next on the list, Boom Supersonic.

Again, not a security-related thing here, but, but just super cool. They are an aviation company that is building a supersonic jetliner. So I think everybody knows the Concorde from years past, and that fad kind of came and went. But they're trying to reinvent that. And they're based here in Colorado.

They're down by the Centennial Airport, down in the Tech Center. They just revealed their, their sort of pilot design at the Paris Air Show. So, you know, maybe if you're in the Tech Center, you'll be hearing some supersonic tests here pretty soon. And they do say that they've seen sales increase by sevenfold. So yeah, that's from 1 to 7 planes.

I don't know. Well, if you're at 0, how can you get 7 times 0? So it's still 0. Is that— I don't know. So Microsoft is giving $25.8 million to expand Colorado workforce training.

Yeah. So this was an interesting article.

The company that they're giving it to, I guess not exactly a company, it's a group. Um, called Skillful. And so they're here in Colorado and they're helping folks transition into other jobs. So if, you know, maybe you've been in, uh, you know, more of a blue-collar job trying to transfer into technology or things like that, so it's good to see Microsoft supporting, uh, Colorado and, and that effort to get people into the workforce. So maybe not applicable to those who listen to the show regularly, but maybe friends and family of yours who are interested in making a change into IT, this could be a good way in.

For sure. So next on the list, we have news that is extremely uber important. The next edition of the Cybersecurity 500 just came out, and I'm sure you'll all be shocked to know Route 9B is at the top of the Cybersecurity 500 again. Congratulations to Colorado local Route 9B for topping the list again. We, we talked about this maybe the first week of the show, really early on in the show.

We weren't familiar with the list. We've now looked into it. You know, it may or may not add a ton of value in terms of what's actually the best companies out there, but it's really cool to see a good sampling of Colorado companies on the list yet again. Yeah, there are a number of other companies farther down the list as well. So next, we're gonna talk about ProtectWise and SEP2 have entered into a channel partnership.

So SEP2 is a reseller out in the UK, and now ProtectWise is gonna work with them to distribute their products in Europe. Uh, going global. Yeah, it's, it's just neat, you know. This is just another indication of their growth and good news for them. Uh, next, uh, SecureSet.

Um, we talk about them a lot on this show. They, they do training as well as, um, they have a, an accelerator. Uh, they announced this week that they added some, some firepower, uh, to their board. So Mark Udall, who is a former U.S. senator, is now joining the board for SecureSet. I think that is a pretty cool move there.

Alex Kreilein, who is, you know, one of the SecureSet guys, came from the government, so I think he has some government ties. So good to see some heavyweight political folks getting in. Congratulations to SecureSet for landing that name. And I don't know what his creds are in terms of security, but certainly in terms of bringing some visibility to the company, he's going to go a long way. Now, I do have a trivial question.

You know, I know if you used to be president, you're not former President Obama, you are President Obama. For a senator, are you former Senator Udall? Or are you Senator Udall for the rest of your life? I'm pretty sure that you get a former. You get a former?

Yeah, it's not one of those positions for life kind of deals. Well, for any— anyone who knows for sure, tweet at us, email us. This is the kind of stuff that's really important. And we'll cover it next week on the show. info@colorado-security.com.

And you should check the website out at colorado-security.com. That's where we have the calendar of events, the show notes, and all the other fun news you week. Last news item we have for this week, uh, there was a LogRhythm blog post this week, uh, by Greg Foss. Uh, Greg's a great guy, been around the community for a long time, um, working over there at LogRhythm. And he talks about deploying NetMon freemium at home to monitor IoT.

So NetMon is a LogRhythm product to, strangely enough, do network monitoring. And they have a free version that you can use, you know, at your home or things like that. So it's a very detailed post about how to go through and set this up at your house. I love these kind of activities. It's You know, of course it's marketing for LogRhythm.

It's one of their products that there's a free version of and there's a paid version of, but it's adding value to all of us anyway, right? It's a great way to market, great way to get the name out. So certainly applause to, to Greg and James Carder and the whole LogRhythm team for, for doing it this way. Yeah. And I think that they still have their NetMon contest going, so you can probably find that at the LogRhythm website.

You can develop some interesting use cases for NetMon and win some money. Solve, solve an interesting problem, win some money. Exactly. So let's dive into the events for the next 2 weeks. This week, the week of the 4th, there's only one event scheduled.

Which is the DENSEC meetup on the 3rd. It is a holiday week, so we're not sure if they're having that meeting, but it is still on their calendar. Next on the list, CSA has their July meeting on July 11th. Yeah, it's downtown. And also July 11th and July 12th, the ISSA Denver chapter are having their meetings for July.

There'll be the Boulder one at lunch on, on Tuesday. The downtown Denver will be dinner on Tuesday. And of course, the DTC, which is meeting I believe it's at Oracle again this month for the last time for a while, is going to be Wednesday for lunch. Also on the 12th, CTA is having their Colorado Growth Company Series. Yeah, it's really an interesting series where they feature up-and-coming companies in the area and give you a chance to learn about those local organizations.

Continuing on that trend, on the 12th and 13th, 12th and 13th, that is, ISSA Colorado Springs is having their monthly chapter meetings. And then finally, the Colorado Innovation and Technology Experience, that's a CTA event, is happening on the 13th and 14th. It's a 2-day event. Take a look. Really a good chance to get involved with the tech community here in town, not specific to security, but overall tech in the area.

So let's move on to jobs. The first job on the list, haven't heard about this one before. Why don't I go ahead and take this one, Alex? You want to do this, Robb? So Ping Identity is hiring a GRC analyst, and we will continue to announce this until we hire it.

I actually found out from my recruiters this week that we were a little backed up on parsing candidates. So if you have applied and you haven't heard back, send me a note and let me know so we can, uh, we can make sure you don't get lost in the system there. But we're looking for someone who has controls experience and wants to get help, help us with our compliance initiatives. Uh, next on the list, SecureWorks. They are hiring a senior security program manager.

So if you want to help some of their customers with security projects. So SecureWorks has an office in Denver? I don't know that they have an office here, but the job is posted here. Well, they got to have something, right? Interesting.

I didn't know that. Well, that's great. Swimlane is hiring a technical writer, technical content writer. So if you want to work for a security company that's up and coming and they have a really cool product, that'd be a good fit up in Louisville. Vail Valley Medical Center is looking for an IT security analyst.

Who doesn't want to live in Vail, right? Yeah. So this one, this next one's interesting. Amazon is hiring a senior security engineer up, I think it was Broomfield or somewhere up north there. Very cool.

I don't, I didn't know they even had a security presence in town, but maybe it's coming along with all the robots that they're trying to keep secure. Yeah, you get to secure all the robots. Hopefully they will leave you alone. Yeah, very cool. Next on the list, Oracle is looking for a senior security analyst.

Oracle has a big presence here in town. Absolutely. They're hiring up everybody. LogRhythm is hiring a professional services consultant, a senior professional services consultant, and a manager of professional services. So if you want to do pro services, that might be a gig for you over there.

And then the last ones that we have are for Salesforce. So they are hiring 3 positions. Manager of external certifications, senior analyst for external certifications, and a senior analyst for IT SOX. If you look at those positions, they do say that they're in California and some other locations. But Robb, I believe you talked to them and they said that they can be hired in Colorado as well.

Thanks to Jeff Ellis for reaching out with these. He confirmed that these are eligible to be hired in Colorado. So apply even though it looks like you're not eligible here locally. Awesome. With that, we're going to go ahead and throw it over to the feature interview, which is with Don Bailey.

Who's going to talk to us about his career. Really interesting career. He's an entrepreneur here in Denver focused on security. We're looking forward to it. And with that, have a great Fourth of July and we'll catch you guys next holiday.

Yeah, happy Fourth of July. All right, thanks. 'Murica.

Hi, this is Mary Haynes, VP of Network Security at Charter Communications. Welcome to Colorado Equals Security, for Colorado security professionals by Colorado security professionals.

Welcome to the Colorado Equal Security Podcast. This is Robb Reck, and I have the opportunity to sit with Don Bailey today. Don, you've had some pretty interesting experiences and started your own company at this point. I guess the first question I want to ask you is, why in the heck are you doing security? Yeah, that's a, that's a great and terrible question at the same time, right?

Probably everybody answers that way. I think for me, security was really just more a requirement. I got into, well, initially I was in music. So I went to University of Michigan to study music. I was supposed to be a concert violinist.

That was my goal. It was really my life's focus from the time that I was 4 years old. It was kind of set up to be this thing. But then I realized as I grew older that I really didn't have the passion to keep that as a career. You know, I didn't want to dig into things the way that most musicians do.

I didn't really care about, you know, the background of Bach or like why Shostakovich was choosing particular notes to like, you know, signify a time in Russian history. Like none of that was intriguing to me, you know what I mean? So first, I have friends that just like they obsess over every single detail. I never felt that way. I was blessed really to be a pretty talented musician, but I never just found that depth.

And somehow I had this girlfriend at Michigan State University, like brief fling kind of thing, but she was an engineer in the engineering school at MSU, and she was running like some obscure version of Unix on a desktop in her dorm room, and it just completely blew my mind that something could not be Windows. Right, like I thought that was amazing. I don't know why it struck me as so odd, but I was just like completely engrossed by this. Yeah, so I started researching it on my own, you know, just hitting up AOL and thinking I'm being slick, like what is Unix? What is a compiler?

Like what is programming languages? And for the first time I was actually engrossed by something, you know, it made me want to learn more and made me want to understand every single layer of the computing architecture and like what they meant. You know, and that's really why security became a focus for me. It wasn't really because it was the hip thing to do or because, you know, it looked like there'd be money in it. At the time I got interested, nobody even knew that was a career.

Sure. You know, it was just a thing that people talked about in sidelines on the internet. But for me, it was really understanding like when I'm developing an application, Since I have no background in computer science or physics or anything of that nature, how do I know that what I'm doing is actually valuable and is stable? You know, it's not enough to understand the complexities of the programming language that you're developing in, but the architecture that you're also building applications on and the operating system that makes decisions on your behalf, like all of those things working as a platform together define whether your application is going to function. So for me, it was at the time this big opaque box, and understanding the security of that box was really a critical component.

And not just like, you know, the relationships between what you write and the documentation that supports what you're supposed to be doing, but those subtle tweaks that allow you to bypass the controls that are supposed to be defined by that documentation. Implementation, like the differential between, you know, the implementation of a system call and what the man page says the system call is going to do. Well, those things are fine, right? The actual implementation is going to be the implementation. It's going to go as much to the spec as possible.

But when you get into the security context, where you can affect things that you're not supposed to be doing using security flaws, like how does that create volatility in an application and what are the side effects of that? And that's what really intrigued me. So let's back up. You're playing violin, you're in college at this point. Yeah.

And what's your major right then? Music. Music, okay. So you're a music major who's decided that computers look interesting. What do you do with that?

Did you finish out as a music major? Did you make a change? Oh, hell no. Music major, that whole ship had sailed. Yeah, I was just kind of like, you know, I have no interest in this, no passion in it, and it sucked.

It was really a very interesting existential time for me because I was realizing that, you know, my life was going to go in a completely different direction and I had no foundation for it, right? Like, I had no background, and as I mentioned earlier, I had no background in, um, or education in physics or computer science or anything. Uh, so it was really just, yep, I'm gonna take this big huge leap of faith and trust that my passion in this subject is going to be enough to sustain me. So did you, did you go to school for computers at that point, or did you drop out altogether? I just dropped out.

You dropped out? Okay. Yeah, I didn't really have the interest in sticking around. And also, like, when it came to not having this deep background, um, for science, I realized that most of my time was going to be spent catching up. Yeah, right, to other people who had already gone through all of those programs.

And so I actually just moved down to Florida, got myself a small apartment, was completely separated from my friends for like a year and a half, 2 years, and literally did nothing but like— I got a job at a grocery store that was super, super easy, worked that 9-to-5 job, um, and basically studied every single day until I passed out on the background of, you know, computer science and physics and mathematics, literally anything I could get my hands on. To feel like I had enough of a foothold in a potential career. So what did you do at the end of that, you know, basically like that time away, right, to learn and study and cram? What did that turn into for you? That was an interesting experience.

So that was a time when the government was recruiting hackers very quietly. And because I ended up, a lot of people don't know this 'cause I was kind of embarrassed about it at the time. I didn't really know what I was doing and I wrote one of the first fuzzers for Linux, really for Unix in general. I wrote it for BSD and Linux. But it basically just fuzzed command line applications, but it did it really well.

And I published it on Full Disclosure or some shit back in the day. And I ended up getting emails from organizations that were like, hey, this is interesting. What are you doing? Do you have any interest in working with us? And I was like, No, and not because I was against it or anything, but really more because I didn't think I could hang.

Because you were enjoying the grocery store too much? Well, hey, the grocery store was— I mean, there were some gorgeous girls that were working there, so I was perfectly fine. But, you know, at the time I really didn't think that I was going to be able to hang because these guys were coming to me thinking that I had a completely different level of skill. Sure. They're like, oh, you wrote one of the first fuzzers, like, this is really important.

I'm like, great, thanks. But to me I'm just learning how to do, you know, exploit development. I don't really know the reason why this is a big deal. I don't really understand the history of it. This automating it just made sense to me, right?

But they're thinking that I understood the history and knew why this was important, and that's why I did it. Yeah, so they thought I had all this background. They're like, yeah, we can get you kernel hacking. We're gonna have you like doing all this kernel auditing stuff and like PA risk. I didn't even know what PA risk was at the time.

So I'm just like, oh, these guys are way beyond me. I'm not I can't hang yet, you know, but I kept those relationships for quite a while. In fact, one of the leads of HP's security team reached out to me at the same time as well because of that, and he was one of those guys that was like, yeah, we'll get you started, and like, you know, you can do kernel auditing, you know, system call auditing, all this great stuff, and that was in like '99, you know, and I'm like, I'm not the guy. I would love to be the guy, but I'm not the guy. So it took a few years for me to actually, you know, start landing contracts, but I started getting a couple of things here and there privately.

You're just doing stuff on the side? Yeah, I was basically starting to do like small consulting gigs doing auditing like C and stuff like that. I was the first guy to start looking into ROP. Well, I shouldn't say I was the first guy. I was one of the first guys looking into ROP, and I published this paper.

What's ROP? Sorry? Return-oriented programming. Okay. Yeah, so at the time it was really return to text.

And return to libc, and people weren't really interested in the ROP perspective yet. And I wrote this stupid paper. I actually like the paper. I got a lot of shit for it, but back in like 2002, I wrote a paper on Sendmail on the prescan vulnerability, which was a huge, huge deal at the time. But for certain architectures, a lot of people had a lot of trouble exploiting it.

And I figured out that using the CISC architecture of Intel, you could actually jump into the middle of instructions and cause it to be interpreted as a different instruction, well, some of the only targets that you could exploit were targets where you wouldn't actually be jumping to a specific intended offset of a known instruction. You were going to jump into the middle of a long instruction and take advantage of what the processor was going to perceive as a completely different instruction that wasn't actually in the code flow. And that was my first look at at what is now called ROP. Did that back in 2002. And again, I had no idea why that was important.

You know what I mean? So people were just like, oh blah, like you released this great paper but you also didn't really release an exploit for it. I had completely over-engineered the proof of concept but didn't actually provide payloads that you could download for exploiting 'cause I was worried about the ethics of disclosure, right? But I released the paper and it was really cool, but I didn't understand for probably 5 more years why that was relevant. Hmm.

You know what I mean? So that was really weird. I actually got a death threat from that paper, funny enough. Why? Why would someone do that?

This cat who's really well known in information security had written a small paper and never released it to anybody but a couple of his buddies. Yeah. On the same thing. On the whole, like, you know, instruction offset sequencing for ROP. And he messaged me and was basically like, I'm gonna fucking kill you because, you know, you clearly stole this from me.

Yeah. And I was like, you know, this isn't Theodorat versus Spender here, you know what I mean? Like, I have no idea what this paper you're talking about is or anything. Yeah. And it turns out it was a paper that he wrote in French.

Oh, that I couldn't read. That also really wasn't a paper, it was like 2 paragraphs. And, you know, I ended up getting, getting a hold of it, um, from him because he's like, well, I'm gonna send it to you and this is proof that you knew about it. I'm like, yeah, I totally never read this. I don't know how to read French and I just— makes no sense to me.

But yeah, it was, it was fascinating because like back then, you know, the hacker scene was pretty vicious. Yeah, a lot smaller too. Everyone knew everyone, right? Oh yeah. So, so you, you got the kind of side gigs for a while there, and did that just kind of build on itself?

And did you— at what point did you stop working at the grocery store? Well, um, I moved back to Michigan in like 2001. Okay. Um, and just started doing gigs on the side. I mean, that was pretty much it, you know.

I started doing my little like quiet consulting thing. That was my full-time thing. I didn't do it consistently. I wasn't making a lot of money. I wasn't making enough to get like an apartment.

Yeah. You know, and be able to eat, which was fine by me. I mean, all I really wanted to do is have the opportunity to like learn more and grow and try to like prove myself through contracts. Yeah. So yeah, I mean, it just kind of went from there.

And then, um, I had a lot more trouble once like our entire ecosystem changed somewhere around like 2005. You know, between like 2004, 2005, um, the world that I knew kind of got flipped on its head. And, um, for financial reasons, not personal final financial reasons, but like ecosystem reasons. So like the, the way that people got paid in this industry kind of changed significantly, and I think that kind of coincided with a lot of stuff that was happening, um, in the United States, uh, politically. And, uh, yeah, that was a really bizarre time, and it kind of like I ended up having a little bit of a crash because the world that I knew was kind of like, nope, this is gone, this is over.

And, uh, we're not gonna pay guys to do side consulting hacking for us. Is that the— yeah, pretty much. Okay. Yeah, or like they would do it, but for like, you know, 10% of what they used to pay. Oh wow.

Yeah, so it was a substantial change to my life. So I actually moved out here. Um, a friend of mine and I were gonna start What I mean, you know, this is a little bit revealing, but we were gonna start basically a zero-day business. We were selling zero-day to government.

At least that was the intent, but we were gonna focus mostly on military systems, not civilian systems, like not writing zero-day for Windows, but looking at like actual like military vehicles. How do you affect a UAV? How do you do that kind of stuff? Like that was literally our business plan. Yeah.

And, um, what year was that that you were setting that up? 2004. So we were talking about it like late 2003, and then, uh, 2004-ish we actually decided to, um, you know, pull the trigger on the plan. So I came out here a couple of times to visit, and we talked about that a little bit, and then I started thinking about actually moving. Well, um, I started solidifying my plans to move, and we had this all set up.

This guy was a well-known defense contractor, or worked for a well-known defense contractor, doing some of this very stuff. Um, and, uh, like right before I pulled the trigger to move, he got killed in a car accident. Oh my God. Yeah. Yeah.

And so that again was just kind of like, damn, I was super, super bummed. Like, I didn't even believe that he had died at first. Like, I had all these friends on IRC that were telling me like, dude, seriously, like, this is a real thing. Because, you know, people don't— probably don't know this about the hacker culture, but Hackers are dicks. Like, if you haven't noticed in modern society, like, back then it was even worse.

Like, people were just like really cruel for no reason. So you would get like random people would be dead, quote-unquote, for no other reason than somebody thought it was funny to do on a Tuesday, right? Yeah, just because somebody was like on vacation, they didn't tell anybody, and then everybody'd be like, oh dude, so-and-so, they fucking committed suicide or something like that. Like really horrible jokes, right? So when I first heard it, I was like, no, come on, that's not funny.

We shouldn't go there with that. But then it ended up being real. And I ended up, instead of coming out and doing a big huge proposal and talk, so to speak, on what we were gonna move forward on, we ended up, well, I ended up going to his funeral, which is very, you know, Very tragic. I was very sorry or sad to see him go. But yeah, so, um, I ended up moving out to Colorado anyway just because at that point I was like, well, that's what I was gonna do and I can't really do it on my own because I don't have clearance and I don't know anybody else that I trust to go into this kind of a partnership right now.

So I was like, yeah, I'll just move out there anyway and just whatever happens happens. Okay. And when was that that you moved out to Colorado? Um, end of 2004, beginning of 2005. Okay.

Yeah, yeah. So I've been here ever since except for a couple years in San Francisco.

So it didn't, didn't, uh, work out to start the zero-day for military stuff. So what, what did you do? More consulting work, or— um, actually I just kind of hung out for a couple years. Like, I had enough money to kind of like sustain myself and like, you know, um, pay for pizza now and then, you know. So I was just kind of like, yeah, I'll just like write code and see what happens.

Yeah, um, so the first thing that I ever wrote that was actually substantial to me was a proof-of-concept rootkit that I wrote in about 2002, 2003 called Faith. And there have actually been versions of this that other people have released that I found really interesting. That was the first time that I actually realized that the world that I knew was waking up again. I ended up giving a demonstration or a talk on that rootkit in Indonesia in 2005 at a conference called Belawa. And that's when I started to meet people that were like kind of reviving the space of like offensive hacking and what it meant and the value of it, because it wasn't really about breaking into systems.

It was more about understanding why systems can be subverted and then creating proof of concepts that really dig into, you know, these underlying architectural faults that we have in not just one type of computing systems but all computing systems and why that's important and what you can do to guard against it. Yeah, right. So what did that turn into for you as the industry started up again or your area of the industry started up again? What did you do with that? Funny enough, so I was thinking about going the zero-day route again and then I was kind of like, hmm, maybe I need to set that aside because I need a little bit more of a public profile, and that entire world is not.

So I was kind of like, you know what, I'm gonna go a different direction and kind of not do that anymore. So I ended up getting a job at Dish Network in the EchoStar's engineering branch and worked in the security area, or product engineering. Well, they didn't really have a security group. What year was this? 2007, like late 2006, somewhere around there.

Yeah. Um, and I, I was basically like, I was, I was brought in to be a security architect for their new IoT program. Okay. And I knew what IoT was and I played with embedded systems, but I hadn't really like taken a big focus on it until that point. Yeah.

And I was really, really into this and I, I really, really liked the idea of architecting secure IoT systems, distributed systems, whatever that meant. It ended up being a really poor working environment for a lot of reasons. There were a lot of good people there, but it was just poor structurally. And they also asked me to do a bunch of unethical shit, so I basically had to get out of there. So I spent like a year— they thought they were hiring a hacker, and I thought I was being hired as a security guy.

Gotcha. Yeah, so they would pull me into conversations. They would be like, hey Don, would you want to hack Ukraine. And I'd be like, the fuck I do. No.

Because at first, you know, it was even kind of one of those things where I was like, you know, I, I thought they were screwing with me to see if I was going to be like an unethical guy or something. Yeah. Since they didn't really know me. And I'm like, you know, I don't, I don't want to do those things and I'm not going to do those things. Like really making a point out of it.

And they just kept pushing and pushing and pushing. And so after the third time of being asked to do something that I was not approving of, It's kind of like, you know what, I'm done. Moved on. Yeah, and that was actually pretty early, but I had like, you know, this was my first like public gig, so this was like month 3. Wow.

Right? And I'm kind of like, okay, you know what, I've got— I've clearly got to go, but I also have to stick around long enough that this doesn't make me look super unprofessional. Yeah. So I basically just like dragged it out. For a year, which was a terrible experience, but I'm glad I did it.

It was kind of a requirement. It got me interested in a lot more of what was going on in IoT. Yeah, and it also gave me a lot of exposure to how, like, the side of engineering that I was missing, right? Which is understanding the internal process of building not secure systems but resilient systems, like especially in IPTV. How do you build a stable system that's really never supposed to be touched by an administrator and whose only connection to the world is really like a modem that dials up to some administrative system and uploads logs?

Right, like at what point can you release a box like that and actually say like, I'm confident that this thing is gonna be usable in the field for X amount of months before I'm okay with it crashing? Like they can crash once in a while, But there's a threshold, right? So understanding that whole set of processes was entirely, you know, a new type of engineering to me. That was really exciting to be able to like learn about that side of it. But in, in the meantime, I was kind of just trying to keep my head down and stop getting asked to do things that I hated, you know.

So yeah, it was, it was pretty crazy. You made it about a year there at EchoStar? I made it exactly a year. Yeah. And then I basically said, buh-bye.

So what'd you go do after that? I worked with— so you know Chris Nickerson? Sure. Yeah, and Luke McCombie and Ryan Jones. I worked with those clowns at Alternative Technology.

Fucking great guys. It was definitely a challenging place to work because I'm not really a red teamer. I'm more, you know, I'm what I consider like a classical hacker. But those guys are exceptional at red teaming, obviously. That's why they have great careers.

But I ended up hanging out with them for about a year, but it wasn't really my scene just because they wanted to do more red teamy stuff, and I wasn't really interested in the red team thing. I wanted to get back into zero-day analysis and that kind of thing. So I did it just so that I could cut my teeth and say, yeah, I did it, I understand what it means, I understand how to do it. I got my CISSP, and all that shit. And I had a lot of respect for the team there.

Ryan and Chris and Luke were very good at what they did. And they showed me a lot of really important tricks that I would not have understood otherwise.

So getting that side of red teaming under my belt, I think, was really critical for my overall career. But for my direction, I wanted to go more into research, and that was obviously not a place that I was gonna be able to go. With a tiger team like that. Yeah. Um, so I joined iSec Partners, and that's where I really, I really found myself, I think.

Yeah. So what'd you do at iSec Partners? Well, um, that's when I really got into, you know, the area of research that was primary for me, you know, I mean, which is cellular mobility and IoT. And that's really been my core ever since. It's what I wanted to do at DISH.

Yeah. But without the ability to really do what what I wanted to do. They just, you know, wanted me to do other things. Sure. So this was kind of my opportunity to focus on things that I really cared about, and especially a growing ecosystem.

That to me was obvious. Like when I found out that, you know, Dish was building the first IPTV systems and they were doing one of the first rollouts in the world, I was really excited. So to be able to learn more about how that area of engineering was growing and what that really meant to as a whole. That was my primary focus at Isaac Partners. So as a junior consultant, that's pretty much all I did.

And we had a really big breakout talk, Nick Di Petrillo and I, called the Carmen Sandiego Project. It was basically like the first step in understanding all of those systems and how they worked and how they secured our society today, or rather don't secure it.

That talk which I'm sure you know, for the listeners out there that don't know about it, that was really the big talk that broke open SS7, that allowed people to understand the effects of subverting SS7 and why it was so critical. So the Carmen Sandiego Project was basically a proof of concept that I could find and track and break into any single mobile device that you own only by knowing your name. That's it. So if I know Robb Reck, right, I can use the SS7 system and its components, which aren't necessarily SS7 itself but other databases that are, you know, akin to that, to be able to identify every single phone that you own or that your family owns and then find out where you are at any time within, you know, a pretty good range. So not like GPS, I can't find you on a street corner.

But I can— cell towers? Yeah, cell towers. So I can tell like basically within a, you know, 10-mile radius of where you're at, and usually that's good enough. Yeah. So Nick and I released that research, and that was pretty much like when my career really, really took off.

What did that research do for you? Well, it showed everybody that we could do something completely novel, that we could look into an area of interest that nobody else had thought of, and it also gave us the opportunity to build technology on top of it, to be kind of an engineer, right? So Nick and I actually built these interfaces that would create maps based on movement. So we could see a vehicle moving across different MSCs. So as they switch from cell tower to cell tower to cell tower, we could tell where somebody was going, and then we could create an overlay to Google Maps or, um, what is it, Google World?

I haven't used it in forever, so I forgot. Google Earth. Yeah. We could create these like opaque overlays or translucent overlays that showed where somebody had been. So they basically look like, you know, opaque squares on a map that show you like, oh, somebody's been in the northern part of Colorado.

Yeah. And here's the times they travel out of that area and back to this area. And we were able to use the White Pages database to cross-reference people's cellular information with their physical information. So if I knew like Robb Reck was in the White Pages, but I could also find his cell phones. I can find all the Rob Recs in White Pages that are around where your cell phone lives.

Yeah. And so I can basically say, like, out of these 3 Rob Recs, I can pin you down to this, like, you know, 10-square-mile area, you know. So I know that you're the Robb Reck that lives in northeastern Colorado versus the other 5 that live in central or something of that nature. So we were able to do some really cool stuff with not much information, just based on being able to make a lot of inferences based on the databases that we were able to gain access to. It was really fascinating work.

So how did this research— you said this really took your career to the next level. What was the opportunities that it opened for you? Well, it gave me an opportunity to really show ISAC partners the value of what we were doing and also the area of interest, because people were kind of like, yeah, I don't know if this is gonna be an interesting thing. Like, you say it's interesting, but all this data is showing, you know, web architectures are really important, iOS applications are going to be really important, so why don't you focus there? And I was like, there's this whole world that's really important, not just to telephony and IoT, but to society as a whole.

Yeah. You know, and that was kind of the first big proof that, okay, this is a big deal and we need to focus on it, you know. And also I got the opportunity to talk with So amazing people like Patrick McKenna, who's still on my board of advisory team. He's on the CISO team at AT&T. I got to meet him.

We got to talk about how to solve the problem at AT&T, how to solve the problem at T-Mobile, at Verizon, all these organizations that were affected by these vulnerabilities. Nick and I basically gave their CISO teams a reason to go get a budget to pin up new technologies that closed off these attacks, these United States. So in a way, we actually helped solve these vulnerabilities within the US. Anywhere outside of the US, you can still implement this stuff all day. Within the US, it's extremely hard to get this information out, which is, I think, a huge victory.

Congratulations, that's great. Thank you. So what do you do next? Well, I just grew at iSec Partners. They gave me a lot of really awesome opportunities.

I was able to do the first car hack in 2011. So before any, you know, before my good friends Chris and Charlie, you know, started hacking Jeeps and all that other stuff, they were partly inspired by, you know, seeing the research that I did at Black Hat in 2011, which, you know, I ended up hacking this small little car security device from Viper of all people. And so Viper basically, you know, had this remote start technology, but it was basically a bridge straight into the CAN bus that they had like a little 8-bit microcontroller on. It was like a Renaissance 8-bit microcontroller, like an ST7. Nobody had ST7 docs at the time, or like reverse engineering tools.

So I actually had like on my flight to Indonesia, I wrote a Python script that reverse engineered ST7 opcodes just so I could see what the hell the application was doing. Then it didn't matter what it did because we could replay every single message that was captured over the cellular network. So I basically sat there with a little, what do you call it, a bus logic adapter, captured all the traffic over the cellular chip, watched it traverse over the UART to the actual 8-bit microcontroller, and then watched everything come out on the CAN bus. And so it was really fascinating to identify how the messages traversed the network and that basically this was an opaque bridge that allowed you to do whatever the hell you wanted. So, you know, for the demo, we have a video, it's still online, of myself and the intern that we used for the reverse engineering engagement that basically showed us unlocking the vehicle's doors and starting the engine.

Yeah. You know, that was really exciting. It was a great thing to see this technology actually working as an attack surface because I had been theorizing this for a long time and basically talking about how this was an important area of research for a year or two at that point to the press. So this was a big step forward saying like, no, this research isn't just about hacking one device or the other device. 'Cause I had done a GPS or an AGPS hack before that which was very similar called, I attacked the ZoomBack.

And the ZoomBack was this really cool tracking device. It was used for like tracking kids, tracking your car, tracking your dog. But it was a similar attack surface, right? And it was like this whole new thing of IoT where all these really strange devices that were connecting our world in new ways but had zero security surface whatsoever. So this to me was the most you know, visual example of insecurity or growing insecurity in the IoT space.

This is 2011, you said? 2011. And the link somewhere they can put in the show notes for folks to take a look at what you did? Yeah, it's on YouTube. I can send you.

I'll get the link. I'll send you a link. Yeah. Yeah. So, okay, 2011, you get to hack a car.

That's awesome. What's next? Well, I decided that I really wanted to focus on that as my primary area of research. ISEC Partners were amazing, and I can't express to you how important they were as an organization, not just for my career, but for a lot of advances in security in many facets of technology. ISEC Partners is probably, in my opinion, one of the, if not the most important security consultancy in the world.

Weren't they— they got acquired, right? Yeah, by NCC Group. NCC. Yeah. Now, you know, as happy as I was at ISAC Partners and as much as I wanted to stay, I always had this plan, which was basically I wanted to go off and do my own consulting thing again.

Yeah. You know, except I wanted to do it on my own terms. So I basically like, you know, I did what I set out to do. And even though I didn't want to leave iSec Partners, and I was frankly quite scared to, you know, because it was a very comfortable place to work and I was doing well there. Before I left, they made me the director of research and I was very proud of that.

But, you know, I had to stick to my personal goal and I left and I started what is now LabMouse Security based on a Cyber Fast Track grant. Thank you, Mudge. Um, you know, that I got in 2012. Yeah. So the DARPA grant really, really, uh, gave me the ability to go out and, and learn the rest of, of the stuff that I needed to learn to get a really concrete, um, architectural view of the threat models in IoT.

Yeah. Right. So we spent $50,000, somewhere between $50,000 and $75,000 just on buying hardware, um, you know, to poke at everything from femtocells to new telematics systems to, um, different types of IP routers. We were looking at medical devices. We bought everything and anything that we could.

I even almost bought— it ended up being too expensive, but I almost bought a, um, a satellite communication system that was used by field reporters in war zones. Yeah, Began systems, like We were very, very serious about it. So reverse engineered the hell out of everything, and then kind of created these models of what IoT meant as a result of that. And I was so, so proud to be able to build that. But I didn't release it just plain under LabMouse after the DARPA engagement closed, because I wanted it to be more than just some company out there that's got an opinion, right?

Because Don Bailey's opinion in the grand view of things doesn't mean a lot, right? But if I team up with another organization that matters in the engineering space, mobility space, that kind of thing, and they agree with what I've come up with, with my assessment, then things start to build, and then, and then it matters. Sure, right? Um, so I actually started reaching out to companies that I thought would be a good fit to take on that kind of a relationship. And I, you know, pounded the pavement for a good year and a half, couldn't find anybody because they all wanted to take the research and basically put their stamp on it and then sell their own products.

And I understood, you know, I mean, obviously a lot of companies, you know, that's what their goal is, right? Like, yeah, they're trying to make money, but I saw it as an opportunity to do something better, something bigger for engineering as a whole, for everybody, you know? Like, this is an opportunity for everybody to actually sit down and understand how to develop something securely. And nobody was interested in doing that. And that was a time, you know, it was only a few years ago, but at that time you couldn't raise money on an IoT platform.

And the goal of this was basically, we're putting out this research on how to build a secure IoT platform based on tons and tons of research, government-funded research. And we're gonna use that to go build this awesome new IoT platform, you know? So I couldn't raise money, and I couldn't find anybody that didn't want to usurp the research for their own capital purposes, which I understand. But I just kind of said, you know what, I'm gonna set this aside. Clearly this isn't the right time for it.

I'm way too early. So I'm just gonna go do my own thing, screw around, and figure out I'm gonna figure out my life and then I'll come back to this when it's more relevant. So for like a year and a half, I literally just did me. I tried writing a book. I thought about moving back to Michigan.

I built a $50,000 cryptocurrency attack lab in northern Wisconsin. So shout out to my, you know, one of my best friends in life, Max Rockefeller. Very good old friend of mine. He and I basically built that lab up in northern Wisconsin at his dad's place. So hi, Max Senior, if you're listening.

But we ended up getting in Forbes because that attack lab that we built basically allowed us to prove that we could completely control some of the smaller cryptocurrencies just by using massive amounts of processing power. Like, we were never gonna take over Bitcoin. Right? There was too much processing power allocated to Bitcoin already. But if you wanted to screw over the people that were trying to create pump-and-dump scams in like Dogecoin and some of the smaller coins, yeah, you could absolutely do it with $50,000 worth of hardware.

So we would basically create like— you could identify when somebody was doing a pump-and-dump by reading like, you know, Reddit messages and, you know, just looking at the payment and, and, um, volume transactions for certain coins, and then we would just flood the network with processing power and basically hold the network hostage so that nobody could actually do anything with it. And then when we wanted to, we'd release all the processing power at once, which drove up the price, and then we'd lock it up again. So we'd basically create these, you know, intentional ebbs and flows in prices of the coin when people were trying to make a monetary play. Yeah, and basically like drained their bank account. It was hilarious.

It was a good time. Yeah, also we found a vulnerability in, shoot, in Bitcoin miner that ended up being the vulnerability that was exploited by those guys that were hacking BGP in order to move everybody's miner to their miner so that they could be like a middleman. Yeah, and then take over all the shares. So they were basically like hijacking everybody's line. That was pretty cool.

I found that on accident and I didn't quite realize what it was. And then once I started seeing the BGP hijacking, this was even before HP put out a paper on it, I was like, okay, I see what they're doing. But HP then released the research and I did a talk at 44Con in London that basically demonstrated why this is vulnerable and what I saw and then what HP saw. Then I also at 44Con showed another vulnerability in the same miner that allowed you to do the same thing. And to this day, I don't think anybody's exploited it.

'Cause I don't think anybody's noticed that it was there. I literally just said, here it is, I'm not gonna provide a patch for this 'cause I don't care anymore, I'm done with Bitcoin. And nobody picked it up. Yeah, nobody looked at it. So yeah, anyway, point being, I just kind of fucked around for like a year and a half.

So then you came back, obviously you've come back to— Yeah, actually, so I got hooked up with GSMA, which was absolutely 100% the right team to work with. So Jimmy Johansson from Telenor, great friend, wonderful guy, he kind of brokered or negotiated this deal with the GSMA where we were going to take my research, my background in DARPA, and used that as a building block to create the GSMA IoT Security Guidelines. And David Rogers from Dark Horse in the UK, another amazing guy, love him, he was involved as well in kind of teaming me up for this. So Ian Smith of the GSMA, you know, kind of got all of these recommendations from all these guys and thought like, hey, you know, Don's been trying to publish this research for Excuse me, for a really long time. Jimmy actually had been following the work for a really long time.

I had talked to him several times about trying to release it, and he was like, you know what, let's help out with that, let's figure it out. And so I ended up getting a deal with them to publish the research, and now I'm like, golden opportunity, right? Yeah, GSMA research is ready. Like, we're going to be putting together basically a book, a how-to on, on building secure IoT technology. Now's the time to also drop the IoT platform that I've been designing for, you know, 3 years, right?

So, um, I thought the most important thing that we could do is not just release it as an IoT platform, but release it as a product. So I reached out to a small wearable company local to Colorado, and I was like, we should work together and put my IoT security architecture with your wearable solution and what we should do is basically like build a technology that proves the security architecture. Now, I wasn't telling them about the GSMA yet because I didn't want them to get involved in the GSMA stuff. I wanted that to be my thing, not the wearable company's thing. So I was keeping that separate and I was basically saying like, if we can work this out, we'll basically be the first and only platform that will be GSMA spec backed by DARPA research, and it'll be the first instance of a secure IoT platform ever.

And it'll be a huge win for wearable technology, you know. But, you know, I ended up picking a wearable company that was amazing from an energy point of view and had really strong leadership, very very ambitious leadership, but I had no tech background. So I was trying to sell them on a technical solution that did not exist in their minds, and they didn't really know what to do with it. Solving a problem that they didn't really care about? Well, I think they cared about it because they were building a security-based wearable, you know, for personal security.

But I don't think they understood the value in the security technology or why it was important. Yeah, you know, from a personal or ecosystem perspective. Um, so it was kind of hard to get them to focus on like, yeah, I mean, building a website or getting somebody to build us like, you know, an iOS application as a demo to raise money, like those things are kind of important because you can really raise money without that stuff. But actually like having all this security related infrastructure that we already have is way more valuable and we should focus on that. Like, if they don't have— if they don't have an experience in that world, they don't know why it's important, right?

So they're going to focus on, well, what are the steps that I know for building a, um, a, uh, new startup, right? Which is basically like website, go out and pitch, pitch, pitch, pitch, build application for for demo, and, you know, that's it, right? So they were sticking to what they knew, which I understand, and I respect that because you have to stick to your guns and your instincts, um, to succeed. But not being able to convince them to, you know, move forward with this model, I basically filibustered for like a month to get a little bit more experience and learn more about manufacturing because I'd never done that before. Yeah.

And then I was like, okay, This is getting to the point where I, you know, I no longer have any value in this company, so I'm gonna bail and do my own thing. So I ended up going out and manufacturing my own boards like a half a year later, you know. So I just designed my own Bluetooth boards from scratch, like did the radio design my own. Nordic Semiconductor is freaking awesome, and basically they'll do a design review of your board for free because it's incentive for them to have people building custom radios that work. Yeah, you know, so I built everything from scratch.

I put my own CPU on it, I put my own radio on it, did the radio on my own, like didn't use any reference material whatsoever. Just like I learned how to build, you know, um, boards, learn how to do schematics, learn how to do the engineering or electrical engineering theory, like put that all together, build my own radios. Nordic made like 2 recommendations Put more ground, you know, sinks here and there, and then that's pretty much it. Um, went to manufacturing, got those built, and they worked way better than I could have imagined. I had 0% failure on the radio boards.

There was a daughterboard that I built that had like LEDs and a bunch of like proof of concept blinky stuff just for like demos. That had about 8% failure, which sucked. But I messed up some of the LED lines on that, which is, you know, that was my fault. But the radios themselves were beautiful. So what are you doing with them?

What's the— you have a product, and where are they going, and how are you using that? Yeah, great, great question. Thank you for bringing that up. So today, you know, we released the Mobile World Congress details about the GSMA IoT security guidelines. So that's out.

As of when was that released? 2016. So March of 2016, those are public. So you can today go to the GSMA's website and download that huge report that I wrote from scratch and was reviewed and edited by every major cell phone carrier and security technology manufacturer in the world. We all worked together.

We worked together in Atlanta. We worked together in Belgium to edit and build that piece of work. And I'll get that link in in the show notes as well. Oh yeah, oh yeah. And, uh, you know, we published that at Mobile World Congress and it ended up being amazing.

I, you know, Ericsson was a huge deal there, Telenor was a huge deal, Talit was a huge deal, um, you know, Mihai and everybody else that was a part of it, uh, Gemalto, Orange, especially Orange for being super patient with me. But all of those guys, you know, were, were instrumental in getting that, that, uh, that work out, and they could do so much with that body of effort. I'm very proud of being a part of that. So, you know, having released that material, now we can say that there's actually a guide that defines by major organizations worldwide how to implement security properly for IoT. And so these boards that I've built as a demo is a proof of that, a physical proof of this is the model for building that type of technology.

Yeah. So LabMouse's goal today is I'm actually starting to go out and raise money now to get this IoT platform off the ground. And we're also adding in a really critical component that I can talk about because I'm actually going to be releasing details about that in the next couple of weeks online. But I'll say here and right now, I am a current member of I just joined the RISC-V Foundation as an individual member. And as an individual member, I will be building my own RISC-V chips.

And the benefit of that is one of the issues behind IoT security is that we have all this technology built on processors that are inherently insecure. You know, ARMs are awesome. MIPS are awesome. PIC versions of MIPS are awesome. There are even solutions out there built on, you know, PowerPC.

That's all fine and good, but they don't include the one core— excuse me— one core construct that's really critical to IoT security. And that's, you know, essentially something akin to a TPM that's built into the processor. Now I know everybody out there is thinking, wait, but there's TrustZone, there's TrustZone, there's TrustZone, and there are similarities, you know, they're analogs to TrustZone in the Intel market as well. Fine, that's great. But guess what?

I can build— I can buy a Cortex-M3 for less than a dollar. Cortex-M3 doesn't have a TrustZone core in it, but I'm gonna be able to buy a Cortex-M3 alike, an M23 or an M33 pretty soon. Those do have TrustZone in it. But am I gonna be able to pay $0.99 for that processor? Absolutely not.

Absolutely not. So what's the solution to that? I'll tell you what the solution is. RISC-V's architecture is the solution for that because by design they have a 4-layer security architecture: machine mode, supervisor mode, hypervisor mode, and userland. And actually 2 of those are flipped, so if you're looking at it as a stack, it's MHSU.

But most implementations are not going to use all 4. And if you're looking at building a processing architecture, you know, for IoT, most people are just gonna do either machine mode or machine mode and user mode. But the secret sauce is if you release a security layer in M-mode, the highest privileged layer, and then everybody runs their standard operating system in the supervisor layer, and then you have your regular userland in the regular userland layer, you can essentially provide a ROM that has all the security functionality of TrustZone but at a fraction of the cost. So basically you're going to be able to, to give the level of security and granularity needed for the cost of the commoditized boards, right? Yeah, for basically pennies more instead of dollars more, I can give you the same value and same functionality as a Cortex-M3 or M4F.

But with the addition of a security layer that you would get with a TPM or with TrustZone or something of that nature. Well, that makes sense. We're getting— we're out of time here. I know you're going to be talking at the ISSA meeting in August. I believe so, yeah.

Yeah, we have you confirmed for that. And do you know, do you want to give like just a highlight what you're going to be talking about there? I think it's Asymptomatic Myopia is the name of your talk. Yeah. What are you going to talk about?

So the idea behind Asymptomatic Myopia is really thinking about, you know, the patterns that we see in information security from an architecture perspective and an ecosystem perspective in IoT, why they exist, how they're changing, how they're basically all collapsing into one universal model, and then how we're going to shatter that with more cost-effective security technology over the future. Awesome. Well, looking forward to it, and those will be, you know, the dates for that will be released in the future, but Um, high level, it's going to be August 8th and 9th in Boulder downtown in the DTC. Uh, anything else final? You know, certainly appreciate you coming on the show and talking about, you know, what your path has looked like.

I don't think anyone else is going to be able to take exactly your path. No, but it's— but it's instructive. Please don't try. It's a horrible experience. But it's instructive and we appreciate it.

Um, where do you hang out if people want to come, come see you? You know, Twitter or in person? What do you like? What do you think? Oh yeah, hit me up on Twitter.

I'm @donandrewbailey on Twitter. I'm always on there talking bullshit, so feel free to shitpost away with me on random security topics. And I'll get that on the show notes as well. Yeah, so there you go. I will say one last shout out to #plan9efnet.

Sup guys? Alright, well thanks Don, I appreciate your time and we'll look forward to talking to you soon. Yeah, thanks Robb. Alright.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes