Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 24, the week of July 16th. This is Robb Reck, and I'm here with Alex Wood.
Alex, what have you been doing so far this weekend? You know, my parents are in town. They are out here visiting from Ohio. We're getting ready to go on vacation next week. My cousin's getting married in Bend, Oregon.
So the whole family is going out there. That's going to be fun. And then going back through Las Vegas on the way back because beginning of the week for, for Black Hat and DEF CON. So Bend, Oregon is a little bit like the Grand Junction of Oregon where it's across the mountains from the main city. It's a little bit smaller town out on the plain.
Is that not right? So I think that in some respects, yes, but Bend is a little bit different than Grand Junction. Bend is the highest city per capita of microbreweries in the country. So it's ahead of Denver and other big cities in terms of having a lot of beer. So that's not what I think of for Grand Junction.
So were you derogatorily commenting on Grand Junction when you said you didn't want those to be compared to each other? No, no, I don't know. I don't know what you're talking about. So Colorado equals security, Robb. So trivia, I went to college in Oregon, a little school between Portland and Salem, and made my way out to Bend a couple of times.
My college girlfriend— hey, Liz— lived in eastern Oregon. I'm sure Liz is listening. I'm sure Liz is listening. Gosh, if she's still listening after all these years, then that's a problem. So this weekend, my sister is in town visiting from California.
We were Doing some random stuff. We hung out in Daniels Park yesterday. Today, this is Sunday. We hung out at Evergreen Lake, walked around the lake, hung out at Cactus Jack's, the nice, the bar there. They always have the nice live music on the river.
Yeah, fun times. Definitely a weekend for family. It sounds like. Sounds like it. Well, why don't we go ahead and dive into the news for this week?
Before we do that, though, if you aren't already, you should most definitely subscribe to the podcast. So Whatever podcast listener you use, whether that's the the Podcasts app in iOS or anything else, Google Play, Google Play, anything like that. Make sure that you're subscribing to the podcast. You know, we don't care if you listen; just subscribe, right? You should listen.
You should listen too. All right, first news story. There is a an article that came out saying why go into the office and. I completely agree. Denver Business Journal.
Thank you, Denver Business Journal. So Denver ranks 2nd in the nation for cities in terms of telecommuting behind Austin. I feel like we are, you know, behind Austin in a lot of stuff. So we got to work on that. We're right above Austin in a lot of things.
It's really neck and neck between Denver and Austin on a lot of lists. Yeah. And I think this just goes back to reinforce the point we've been making. It's a really high quality of life place to work, place to live, obviously, right? This is a place where we have a lot of flexibility and this is why we're here in Denver.
Yeah, and I, as someone that worked remotely and telecommuted for another number of years, I have to say it's a great option, although it is also nice being in an office and being around people. Yeah. So next news, Josh.ai is a home automation company headquartered here in Denver that just raised $8 million to help build the company. Yeah, so they do, uh, artificial intelligence around home automation, um, you know, so you could do like a, a Siri or other things like kind of, kind of thing, um, you know, tell it to turn off your lights, uh, you know, I'm leaving, turn down the water heater, whatever it is, change the temperature, play music, all that good stuff. It all gets plugged into the central system and it's only the low, low price of $10,000 to get your house wired up.
Not a problem. I'm sure a high roller like you, Robb, has no problem with 2 or 3 of those systems. So we've got some good news this year. The APEX Awards, which is put on by the Colorado Technology Association every year, in 2017, the APEX Awards are going to include an award for the best CISO of the year. That's awesome.
I'm very excited to win that award. So every year we have, there's a series of awards they give out. There's Project of the Year, CIO of the Year, all kinds of interesting stuff focused on technology where they try and get together the best at certain stuff. And then they have a, a ceremony, a, a gala event, if you will, where they get together and talk about the winners and present the awards. This year, and in no small part thanks to your Colorado Equal Security podcast, we've been talking to Michelle and Andrea over there— and excuse me, Monica and Andrea over there— and they are now adding a new category around CISO of the Year.
So the, the application process is up right now. You go to our web— go to our show notes and you can get to the website to to nominate someone. They're really looking for a CISO who has made— who has used security and the security program itself to help their company better achieve the goals. So it's not just about who has the best security, but who is using security to help their company succeed. I think it's really great to see that the security and the CISO role is moving to the level where it is being recognized in this way.
I think in the past people would have seen security as, uh, you know, sort of a second-class citizen, something maybe that you have to do compliance-related, but not an award like this where it's really recognizing someone moving a program forward. So I'm really excited about that. We're looking forward to it, and we'll, we'll get more news as we hear it. But this is your chance right now. Listen to me, go sign up, go nominate whoever you think really has done a great job helping their business succeed from the CISO seat, and let's use this platform to help drive that awareness.
All right, so next on the list, uh, the Colorado Division of Securities has adopted their final cybersecurity rule. So this actually happened a couple months ago, but just this past week it has gone into full effect. So this applies to, you know, financial services folks, broker-dealers, other things like that in the state of Colorado. It's really interesting that this has come about. The New York Department of Financial Services had a similar rule that that came about.
I think it was in effect in March-ish, and it really is trying to push the level of cybersecurity forward. So I found— I came across an article which we linked in the show notes, which is actually written by our friend Dave Navetta, who you've interviewed for this show. And what he says in here is that in addition to requiring written procedures that are reasonably designed to ensure cybersecurity, the rule also mandates an annual risk assessment of the firm's data security practices. So not real high level, not real detailed— excuse me, not real detailed requirements, but this is really going down the road of getting much more prescriptive and putting some teeth behind requirements around security for these financial services professionals. Yeah, and as, you know, someone that runs a security program for a financial services company, I look at that, I say, well, that seems like a pretty low bar, but knowing other companies in the financial services world, just requiring those things is a great step to make sure that at least everyone is doing those things.
It's those little companies, right? The little mom-and-pop shop that, you know, there's 3 people who do it and there's 1 front desk person. Somebody now has to really become the champion for security in that organization. Exactly. So the next one, it's not Colorado-focused.
You guys will have to forgive me, but I was so thrilled when I saw this story that I wanted to share it with all you guys. Palo Alto Networks and the Girl Scouts have teamed up to create security merit badges. And this is an opportunity for folks to, for girls, little girls early on to start getting their hands on technology and really learning what the basic principles of security are. I'm so excited that this is something that's coming down the road. I think it's great as well.
There have been numerous studies that show lower participation from girls as they go along in terms of STEM, you know, math, science, obviously computer science goes along with that. You know, there's a lot of it is, you know, them being intimidated or being told that, you know, you're a girl, you can't do these things. So it's great to see that the Girl Scouts are bringing in this type of, of education and merit badge for, for girls of that age. Yeah, I got to hear Rick Howard talk about this on a show. And his point was, It's true, we have way too few women in security, but you don't solve that problem by, you know, when you put up a job rec saying, I'm going to fill it with a woman.
The talent pool isn't there. We have one— what is it, you know, hundreds of thousands of open positions right now that we can't fill. The way we have to fill it is much earlier in the pipeline. You have to go back to not at the end of college, people are looking for new jobs, maybe not even, you know, looking at before college, between high school and college, looking for people to go into CIS majors. We have to go back even further and get you know, young elementary school, junior high-aged girls and minorities to understand technology and not see it as, you know, a man-dominated industry.
And this is one way to start addressing that. Amen. All right, good stuff. Uh, next on the list, uh, cybersecurity expert Dan Massey joins the Secure64 executive team as chief scientist. So we talked about Secure64 last week or 2 weeks ago when they had a press release.
This is fantastic. Dan Massey has been a DNS expert for a long time, and he's joining them to really help their executive team get a little bit more industry experience, hopefully help move them to the next level. Yeah, it also looks like Dan is at CU Boulder, so it's good to see someone local getting connected with a local company. So, so this company is headquartered in Greenwood Village, but I think that their, their offices are really in Fort Collins. So if you're looking to get involved with Secure64, I believe Fort Collins is your place.
Look on their website to confirm. So Swimlane was named a breakout vendor by Forrester. So Forrester being an analyst company, they're looking at the security automation orchestration area and named Swimlane as one of the up-and-comers in that area. Yeah. So we've been covering these guys for 4 months.
We interviewed Cody, who's the CEO over there, several months ago, pretty early on. I've been checking every week. I check their press release. Webpage to see, is there anything new coming out? And I sent Cody an email the other day, like, Cody, why have I not seen a press release for a while?
And come to, come to realize that I had the wrong URL. So they have been doing news, and we're going to start covering them much more diligently. They're doing a lot of good stuff, and I hear the rumor on the street is there's going to be some big news in the next week. So tune in next week, we'll find out what Swimlane's done here in the next week. There's the hook.
Automox, they're another local security company. We talked maybe we talked about a little bit, maybe we haven't. They specialize in patching. They're a very small startup. They have a blog out here this week that explains the CVE system.
CVE, Common Vulnerability— yeah, good question. Vulnerability, uh, exposures. Yeah, so something like that. CVE is, is the open source system that many, many products and, and companies use to, to you know, you'd be the unique identifier for vulnerabilities. Hey, you're going to patch a system.
Well, that corresponds to this vulnerability from the CVE database. This, this podcast— excuse me, this, uh, this blog explains what CVE is, gives you more details on how you can use it. Uh, kind of a neat resource if you're not familiar with it. I've been hearing a little bit more about Automox recently. They sound like a pretty neat company.
Automated patching, you know, focusing on the, the small and medium-sized business, which is You know, again, one area that gets neglected a lot, right? Um, not only because they don't have the resources for security, but because, you know, there's— they don't have the big bucks like the big enterprises do. So it's good to see a, a company focusing on SMB. All right, that's it for news this week. Let's dive into the calendar.
Before we do, just a reminder, we do have a calendar of events on the website where we go out all the way— I think we're into November right now on the calendar. We're going to talk about the next 2 weeks worth of events But there's a whole lot more stuff out there for you to look at, including some week-long events coming up. I recommend you guys take a look so you're not surprised when these things come upon you. So first on the list, OWASP is having their July monthly meeting on the 19th. The NCC has their Cyber Center Chariot at 2017.
So we, Alex and I, we talked about this last week and neither of us knew that word, so we kind of just skimmed over it. After the podcast, we looked it up. A chariot is a time where people can get together and hash through differences. And this event is actually meant to be a gathering together of different national cybersecurity centers like the NCC is, where they work through what's the right way to be that center of excellence for security in a region. Next, DenverSec is doing their monthly meetup on 7/20.
Also on 7/20, ISC² is getting back together. They, they, they took quite a break. Um, they met in June and we were kind of surprised by it because we thought they were on break, but they're back again here in July. They're meeting at the SecureSet building and they're talking about the CISSP-ISEP certification. So that is one of the more, um, that's the engineering one, right?
The more technical-focused CISSP emphasis. So you guys can learn about that and understand what that certification is all about. Uh, on the 22nd, ISSA Colorado Springs is having one of their mini seminars. So if you need some, uh, some CPE credits, go ahead, take a look at that. And they do those, I think it's once a month, Saturday mornings for about 4 hours.
They don't necessarily say what the topics are ahead of time, so we don't know what it's going to be, but we do know you'll have plenty of time to learn and network there. The following week, the 24th through the 28th, the NCC is doing the Air Force Association's Cyber Patriot Cyber Camp. We talked about this a few weeks ago. Such, such a neat thing. My kids are a little too young to do this quite yet, but it is a week-long summer camp where you get to learn about cybersecurity.
Yeah, mine are a little too young as well. I think it's only high school students, but definitely something cool to check out. It kind of goes hand in hand with the whole Girl Scout stuff we were talking about. That's right. Yeah, get them involved early.
SecureSet is doing a capture the flag event on the 28th. We've talked about their capture the flag events many times in previous podcasts. And then finally, the last news, last event we'll talk about this week. Once again, we're back to the Springs. The first week of the CISSP exam prep course happens on 7/29, and that's what, uh, the first of 5 Saturdays that they're going to get together.
So if you haven't signed up yet, please do as early as you can. I saw on the website there was maybe a dozen spots left, so sign up now so you get— you guys get an opportunity to go. Yeah, exactly. One of the folks that works for me did their Security+ prep and he really enjoyed it. So I'm sure that the CISSP prep is just as good or better.
All right, let's dive into jobs. We've got a handful of jobs. Number one, we've— I think we've talked about this position before, but it's still open. Gates is hiring their Director of Information Risk and Security. This is, you know, basically the CISO position at Gates, which is a multinational Fortune 500 type company.
This is a chance to run a very large security program for a company that really could use it. Connect for Health Colorado is looking for a security analyst. Connect for Health Colorado is the healthcare exchange here in Colorado. We were talking this week with Michael Steffen about that position. Michael is the security leader there at Connect for Health Colorado.
He actually not only asked us to post it, but he gave a short description about the position. So it's non-technical, mostly compliance, privacy, and working with multiple partners, really trying to focus on the, the programmatic aspect, not so much the technical aspect. He says the ideal candidate is someone who has excellent communication skills, some knowledge of security frameworks, either NIST or PCI, and some background in security. And of course, you need to be eager to learn, and he wants someone who's smart. So Alex, that does rule you out.
Oh, damn it. Yeah, that was brutal, wasn't it? Next, ProtectWise. They're looking for a malware analyst and threat researcher. There's actually 2 positions.
I know. I put them on one line, but I thought interesting that they're looking for both a malware analyst if you want to get real deep into the code of malware and a threat researcher. Coalfire. They are looking for a senior security consultant and a penetration tester. I'm assuming that since those are on the same line, that's one position.
Damn it, Robb. I just did it one time. I apologize. I messed up the show notes for Alex here. Red Canary is hiring a security operations center analyst.
Webroot is looking for an advanced malware threat research engineer. So what would the acronym be here? AMTRE. AMTRE. AMTRE.
If you want to be an AMTRE over at Webroot, this is your opportunity, guys. And finally, Ping Identity, the number one security company in Colorado, is looking to hire a GRC analyst. I know a little bit about that position. So if you are interested in getting involved, go to the website and apply, and then maybe send me a note, and I'll be happy to answer any questions you have. The drawback to that job is that you have to work for Robb.
Yeah, but good news is there is a level between, so you won't have to work with me all the time. Oh, perfect. Well, I think that's it for the news this week. We're going to talk to Bana Sidhe, Jen Southwick. Jen is one of the kind of the charter members of the security community here in Denver, a cornerstone of what we do on the kind of on the Black Hat side of things.
Things. Yeah, and, uh, she does a lot of security event organization, um, not, you know, besides here, uh, in Denver, besides in Las Vegas, as well as lots of other places too. Uh, just an interesting person. Yeah, so look forward to that. Uh, we want to hear from you guys if you have any feedback on the show, anything you want to see us do that we're not doing, anyone who you want us to talk to.
Send us a note, uh, info@colorado-security.com. And as always, check out the website, www.colorado-security.com.
Hit up iTunes, hit up Google Play, subscribe. All right guys, have a great week. We love you, Colorado.
Hi, this is Sam Masiello, Chief Information Security Officer at TeleTech. Welcome to Colorado Equals Security, for Colorado security professionals by Colorado security professionals.
Welcome to Colorado Equals Security. Today I have the, uh, the pleasure of getting to sit with my friend Genevieve, uh, Genevieve, also known as Bana Sidhe, who's been one of the big promoters of the security industry not only here in Colorado but really nationally and maybe internationally. We've— we got to meet, I think, maybe 4 years ago helping plan BSides Denver, something like that. And, you know, we've— I think it seems like every 6 months we run into each other at something else. And, um, normally on the airplane to RSA.
Yeah, we do take the same Southwest flight from Denver to SFO, uh, Saturday afternoon every year to RSA. That's, that's true. Uh, we shared an Uber last year, I think. Um, so, you know, I thought this would be a great chance just to get to talk about how you got to be, uh, such a big part of helping plan not only the Denver Security World, but I know the Vegas stuff going on and other conferences you've been a part of. As a starting point, I'd love to kind of just put you on the spot and ask you, what is the thing that you've done so far with security that you're most proud of?
What's, what's really something that you would like to share and you would be known as at this point? Well, it's not something I specifically want to be known as, but something that I want the conference to be known for. I developed the Proving Ground speaker mentorship program for BSides Las Vegas. Yeah. And basically what that does is it allows new speakers who've never spoken on a national stage— if they've spoken at their ISACA or their ISSA, that's one thing, but if they've never spoken on a national stage, we can help them with a scholarship, a small stipend to get them out to Vegas, and we pair them with a mentor who has a proven track record of speaking in the community, in the industry, and help them with their slide deck and their presentation and their their stage presence.
Yeah, what an awesome opportunity. How did, how did that come about? Uh, actually it was a conversation between Dave Shackelford and myself at RSA years ago. Um, I guess it was in 2012, right after I had taken over B-Sides Las Vegas. That actual— yes, Jack and I had just made the decision that he would bring me in as an executive producer, and we're sitting around brainstorming about new ideas to do for Vegas, and Shackelford said, what about a mentorship program for new speakers?
And that was all it took. I just, I ran it from there. That's awesome. Although, uh, Noyes did help name it. It was, uh, Shackelford, Noyes, and I brainstormed on the names.
Um, so what year was that that started that program? That was 2012. So it's 5 years now. Yep. Wow, that's great.
Yes. Um, have you— we're gonna get lots of time to come around to see, figure out how you got there, but how Let's just talk a little bit more about the Proving Ground program. Have you seen, you know, what percentage of the time do you think, wow, that was really successful versus, oh man, what I've experienced with kind of mentoring relationships is sometimes the mentee does not, doesn't have the drive to go after it and sometimes the mentor doesn't have the time to commit. You know, how's that gone for you? Well, we haven't had that problem so much partly because it's more of a check-in mentorship.
Yeah. When we first pair the speakers and the mentors, the presenters and the mentors together. They do a check-in with each other to make sure the outline is okay, and then the presenter is responsible for starting to come up with the outline for their slide deck and getting that together. And they have check-in points where they go over things together. So it's not necessarily like they need an hour of everybody's time every week.
We have had problems with mentees just not making calls You know, of course we've had problems with people submitting to the program who weren't actually— they weren't eligible because they'd already spoken someplace else before, or, you know, they had their talk already ready to go. They just wanted somebody else to look at it for them. That's really not what we're there for. So for people who might be listening who are, you know, they've never talked, or they've, you know, like you said, just done a local talk, What, you know, is this— who is this good for and how would they go about trying to sign up for this? I assume for 2018 at this point.
Yes, for 2018. So our call for mentors and our call for presenters for the Proving Ground program normally opens up around January 1st, and you can go to the website besides lv.org and find under Get Involved, you'll find Or actually, I'm sorry, under tracks, you'll find Proving Ground. And that'll give you more information on— but basically, you just need to submit your abstract through our conference paper system, which we use OpenConf. And then we also have the mentors sign up through the same system, so we have everything together. And then we just pair— we put out the list of the people who are looking for mentors, along with the synopsis of what it is they're looking for in a mentor, whether it's DFIR or you know, pen testing, whatever their specialty is, that might make a difference, especially if it's like a heavy math, you know, then you're gonna need somebody who understands maths in order to read the proofs.
But the mentors get to pick their mentees and runs from there, and there's several checkpoints. We have an amazing director team for Proving Ground of Megan Wu and Michael Ortega. Also known as Totenkopf and Security Moey on Twitter. And they've been running Proving Ground now for the last 4 years. I ran it the first year and realized that that was a little— that was something that needed to be really brought up and taken care of with a dedicated crew.
Yeah, dedicated crew. Absolutely. So I will— I'll go ahead and put a link in the show notes to the Proving Ground application page that you mentioned. And there's a lot more information there too, including, I believe there's still information on there about the scholarship. Cool.
So we're gonna kind of do this memento style. We're gonna start with the present, we'll go backwards in time. So right now we're sitting in the Ping headquarters in downtown. We're both drinking an alcoholic beverage, and your hair is more colors than I've ever seen it before. So would we say this is 4 colors?
I see, I clearly see Um, blue, purple, red, maybe platinum. Yeah, so there's 5 colors in my hair. It's supposed to be 4— well, 6, sorry. 4 colors of purple, a red, and a silver. Yeah, but the one of the purples came out more blue.
Yeah, so I love it. Very well done. Thank you. Thank you. Um, and, and so let's kind of— that's now go Memento style.
We'll go to the very beginning now. How did this whole thing happen for you? Did you, you know, come out of school and say, hey, this, you know, event organization is what I want to do? It doesn't seem like very likely. I'd love to know how you came to this.
Yeah, so not so much with the school thing, unfortunately. I'm, um, I'm not that fortunate. I, I started working at the Renaissance Fair in Southern California doing night security when I was I was 19 years old. Okay. And I just went from— I enjoyed it so much.
I enjoyed working in the entertainment industry. So I have to ask a question about, uh, night security at the Renaissance Faire. Do they make you use a sword slash mace slash halberd, or— No, but we do spell it with a K. We do spell it— we did spell it with a K. So it's night security. Yeah, it was night security. But no, we, we were just— we weren't allowed to carry weapons 'Cause that wasn't our job.
So I started off there and I just worked my way up from working night security into working operations. And I did just a little, about a little bit of everything under the sun as far as working for the Fairwind. Moved around all the departments and realized that I loved it. And I took a job in San Francisco working for another theater company that was basically the same also doing Renaissance Faires, but they also added a Dickens Faire at Christmas time. And I eventually worked my way into the role of producer for the— or not producer, I'm sorry, technical director, which is basically the production manager.
Okay. So during these years, you know, Renaissance Faire, while a lot of security people might be at the Renaissance Faire, you know, there's no technology necessarily, right? Or very low technology. And how Were you interested in technology, or is this really, you know, just coming from a different place altogether?
It was a mesh of my friends in the Ren Faire scene. Some of them were crossover into the hacker scene, and the hackers that I met, I would hang out with during the week and do the Renaissance Faire on the weekends, right? So we'd have Tuesday meetings in Fullerton, The Digital Decay bulletin board. We'd all get together and hang out. And I just made really good friends with a lot of the local hackers and information security.
Well, they weren't information security back then, right? It was hackers. It was hackers. Yeah, yeah. We're still looked down upon at that point.
But we just started hanging out and one thing led to another. I wound up at DEF CON 4. My best friend drug me out to DEF CON 4. And that was basically all she wrote. Just fell into the community, and because what I do for a living can benefit the community, it made sense for me to put my skills to work for them.
Yeah, it's kind of like being an accountant for the mob. Like, you're not really in the mob. Yeah, but I'm not keeping 2 sets of books for any of the B-sides I'm running, okay? All right, sorry, so I know I kind of cut you off. You're talking about being the technical director for the Dickens show, and Was it directly from, from doing that to, you know, how did you go from there?
Yeah, so I actually left the Dickens Fair in 2013. Um, that's when I moved to Denver from San Francisco Bay Area, and I, uh, I put in my notice because I was coming out here to work what I thought was going to be a full-time job for another company. Yeah, so, so how did you transition from— like, maybe I should say, what next? What happened after 2013, where'd you go? When I got here.
Okay, so I got here, I'm running BSides Las Vegas, and I decided to— you were already running BSides Las Vegas? Yeah, I started BSides— I started running BSides Las Vegas in February of 2012. Okay, um, seeing the community, you said you went to DEF CON 4, which that was what, like 2000, early 2000, right? Late '90s. Late '90s.
Yeah, this is DEF CON 25, so I've been going to DEF CON for 21 years ago. Okay. Yeah, okay. Yeah. So, so, you know, what happened there in the late '90s?
You started getting plugged into the community. What did that mean in terms of— did you start doing events at that, you know, some events at that point, or you're just hanging out with the folks, or what? I was more hanging out with the folks. The first year of BSides Las Vegas, I wasn't able to attend BSides Las Vegas because I was actually helping run DEF CON 101. That was the first year they'd ever done that, and I was helping stage manage DEF CON 101.
What's DEF CON 101? DEF CON 101 is a noob track or introductory to hacking and how to present yourself at a conference, how to behave, how not to, you know, the 3-2-1 rule, all that fun stuff. So it sounds like you, you know, you just got to know a lot of people and put your hand up and said, yeah, let me help putting some of this stuff together. Is that really what it came down to? Yeah, so I got to stop saying yes, so.
I know how that sounds on the radio.
2012, I— 2011, I just found out about the first BSides Vegas and realized that I'd missed it and I wanted to make sure I was involved in 2011. Oh wait, '09? '10 was the first one I did, sorry. And I was second in charge of security. And then '11 I ran security and then '12 I started running the conference.
So that was the way that worked. I stepped up and offered my physical security skills, and, you know, I wrote up the policy for BSides Vegas. I mean, it wasn't much because there was only like 10 of us on staff or on security crew, so we didn't need a full incident response plan, but we're getting there now. Yeah, so could you, could you talk about the interplay? You know, there's— I'm sure there's tons of folks who have heard of DEF CON, heard of Black Hat, heard of BSides Vegas, maybe heard of DC 303.
Can you talk about those different groups that are all kind of, you know, in the same area with the same cohort but have different nuances? Do you mind sharing your perspective on those? Well, that's an interesting question. You really put me on the spot. Well, Black Hat, right?
As the— Oh, the differences between Black Hat? Yeah, between the different events. Okay, yeah, that's easy. So Black Hat is more of a corporate conference, their badges are up in the, you know, 4 digits in order to get in. And basically it gives cost, right?
For cost, $1,500 or whatever. Yeah, you're gonna be paying over $1,000. It's a lot like RSA conference, very commercialized and very, very corporate. Lots of governments. A lot of the talks are tool pitches or, you know, solution pitches, maybe couched in a more educational stance.
But has that changed over the years from your perspective, or is it always been that way? I've never been to Black Hat. Okay, so from what you hear? From what I hear, it's not— yeah, it's been the same. The reason BSides started was because there were a couple of talks that got kicked— that were rejected from Black Hat because they were a little too technical.
So let's talk about what is BSides, and you know, you and I, we're old enough to know what a B-side is, and I know from experience recently talking about BSides at that some folks are not. So back when, uh, you know, when there was such a thing as a, as a single, when you would release a tape or a record with, you know, your hit one, you know, one-hit song, a music group would release what— your radio play song, your radio, your radio play song that was going to be, you know, the driver for your album sales. They would release this one little single, they called it, with that song on it, but there would always be a song on the other side, and that was called the B-side, where there would be you know, the song that, um, you know, wasn't gonna get the radio play and might be quite good but, um, is— it doesn't have the name recognition. And I think that's where the name for, for the B-Sides Conference came from. Exactly, that's exactly where it came from, yes, because the good stuff is on the B-sides.
Because it always used to be that the pop hit would be on side A and you'd listen to side B and go, wow, why isn't this on the radio? And, and that was, uh, and that was— that conference was started— I know Jack Daniels was part of it. Do you know who the organizers for that originally were? The original organizers for the very first B-Sides were Jack Daniels, Jeff Espinoza, and Travis Goodspeed. Got this thing started and then Chris Nickerson kicked in a place to do it, so he became one of the founders, and Mike Don helped out with the sponsor drive and getting a bunch of the logistical stuff done.
For the conference. So it was— BSides is ostensibly founded by Jack and Chris and Mike. They're considered the 3 founders of BSides, but really it started off from a community conversation on Twitter. So it's a community conference from the very first time somebody said, hey, let's do this, and somebody said, hey, I've got a place, and somebody said, hey, I can get some money, and it was a group effort. It went very quickly.
Yes, it went from 0 to 60 in no time. Yes. Yeah, so following Black Hat has been DEF CON for, I don't know, as many years as Black Hat or not quite as long? More. DEF CON started first.
DEF CON started as a party in the desert for DT's BBS friends to get together and hang out and hack and talk and drink. And then after a while, he realized that there was actually a market for this and he founded Black Hat, but DEF CON started first. Awesome. Yeah. And so how would you say, you know, you compare that to Black Hat?
We talked about Black Hat as being the commercial one with the highest price tag. Where does DEF CON fit in? DEF CON, I look at Black Hat like the trade show of the week, you know, the sales pitch. DEF CON, summer camp. DEF CON is 20+ villages and 100+ events.
Depends on what you're talking about. We have hardware hacking villages, we have software hacking, Capture the Packet, there's the Wall of Sheep, there's crypto, there's regular puzzles, there's villages for just about everything. And a village is just basically you're gonna go opt in for this thing that's running, you know, on a schedule most of the time. I can go pop in and just experiment hands-on with something. Exactly.
Yeah, you know, like when you're at summer camp, you You could sign up to go rowing at 3 o'clock in the afternoon and then sign up to go horseback riding at 4. And what, you know, one of the examples that we've had at the Denver BSides has been the lockpicking village where, you know, it's an opportunity for guys like me who spend most of their time at a computer writing policies to actually learn how to pick a lock. Pretty cool stuff. And similarly, they do electronic, the computer security stuff in there as well, sounds like. So, okay, the DEF CON, I know it's kind of I have been one time.
The difference being you have to pay cash, right? The price is quite low. There's no credit cards, no online purchases. The membership, the attendees, it's a different feel than we get at Black Hat, generally speaking. Yeah, it's shorts and tank tops and t-shirts.
It's not suit and tie or even polos and khakis. But they are right back to back every year, so you could come for one and stay for for the other or not. And so, you know, I did mention the DC 303 thing, and I'd just like to get, you know, some perspective on that. Leading in, generally in the hacker world, communities were identified by the area code where they were located. That was frequently the case.
And the 303 crew, being the people in the Denver area, was a relatively, I don't even know what the right word is. I don't want to say successful. A relatively lively community, how about that? Notorious? So what happened?
Why is there such a thing as a DC303 party and event that goes on out there? Okay, so we need to separate these. There's the 303 and then there's DC303. What's the difference? So DC303 is a DEF CON group.
That's what the DC designator is for. And they started way after the 303. Okay. Been around since the '90s, and they used to do, used to, they basically, they got, they met most of each other through 2600 or work. And actually, what's 2600?
2600 is a monthly magazine, or is it quarterly? I think it was monthly. Monthly magazine that came out of New York, Manuel Goldstein founded, that was all about phone phreaking and computer hacking, and it was a really very, very popular underground magazine, and they started the 2600 groups where every First Friday of every month at some local payphone bank, everybody would get together and meet up for— mingle for half an hour, and then they'd go off to some bar or restaurant and, and hang out and have a meetup. Well, the 303 group couldn't do it on Fridays because they were all older and already had jobs, so they started doing it on Saturday morning and called it 2601. So that way everybody who didn't live in Denver or work in Denver could get to Denver so we could have our little hangout.
And then years later, DC303 started after there was, I don't know if there was a schism or they just decided, I don't even think that that was the case. I think it was just that there was a group of people that wanted to start a DC303, and that's DEF CON related. But the crew that runs the 303 party at DEF CON is not DC303. Those are different things, got it. And there's a, in town here, there's a DC303 uh, 303, uh, mailing list, right?
And that's basically how communication goes on with that group. And correct, there's also a DC 303 mailing list, and there's a lot of crossover. But yeah, um, so the party— so who puts on the party in Vegas every year? That's the 303, and that's, uh, well, it's a mixture of— there's a bunch of us from the 303 crew that all pitch in to make sure that happens. For years it was, uh, our friend Carl Nimbus He's not involved this year.
Is he here in town? Yeah, he lives local. He actually helps me. He's my co-host for the B-Sides Las Vegas podcast. He does video too.
And Blue Knight runs SkyTalks. Pyro founded it and then handed it off to Blue Knight several years ago. I was helping with it for many years, and I have taken a backseat for that, partly because besides Las Vegas, has become more of a full-time job. Plus now I'm gooning at DEF CON, so I don't have the time to dedicate to the 303 room. But between SkyTalks during the day and the parties at night, that room's normally relatively lively.
Yeah, so it's great from everything I've heard, and I've never been to a 303 party out there. Everything I've heard, it's one of the main attractions of the of the whole hacker summer camp week, right? That's what I hear. Is that kind of your experience?
That depends on which crowd you run with. I mean, there are so many people that attend DEF CON now. We're talking 25,000 plus, right? So there's a core group of, you know, I'd say 500 to 1,500 people that we've all known each other for 25 years since we started going to DEF CON, and we use Vegas as our reason to come together and see each other once a year because we're now spread out all over the world. So knowing that we have a place at DEF CON that hasn't changed over the years, that we still know we're going to run into the same faces, makes it an easy pivot point.
All right, so let's transition a little bit and talk about your stuff. And you've been, you've kind of, I think, really gone professional with your conference organization over the last couple years, right? You want to talk about what you're doing and, you know, what that transition's been like for you? Well, I started Squirrel Herder Productions in 2014. Does that have anything to do with Jericho?
Yeah, well, yes and no. Yes, it does actually. Well, herding hackers is a lot like herding squirrels because they all have attention deficit disorder of some sort, or, you know, they're— every time you try to get them to go in one direction, they're seeing something shining and running off the other. So it was a mixture of that, because hacker— hurting hackers is like hurting squirrels, and also because of Jericho. Yeah, because he's a very, very good friend of mine.
And, and he's, uh, he— what, what is it? You know, he's got a squirrel thing going on. Attrition. Attrition.org. What's the squirrel connection?
Is it just he likes squirrels? He loves squirrels. He loves that. That's— I know he's a He's a big Humane Society rescue guy, and squirrels is part of that. Okay.
Yes. Got it. So you started Squirrel Herder Productions, and what's that— how's that transition been for you? It's been difficult. I have— I can't necessarily say that I have a lot of the— oh, this is gonna sound weird— the high-end business skills to run a company by myself.
Yeah, there's a lot, but it's just me, so it's not like there's a lot, a lot. Um, but the skill set running an event and running a company, they're different, right? It's, it's a different, it's a different skill set. Yeah. So I've, I've had some excellent clients over the past few years.
I've had a couple of conferences. I had a nonprofit that I threw their 25th anniversary for. Um, I just actually got back from Indianapolis for Circle City Con where I was running their security, their safety operations department for them. Yeah. So I either— I can piecemeal a department, or you can give me, you know, a clump of your conference to run if you need assistance with it.
One thing I'm not really good at is sales, but I'm working on that. So what are some of the events you've done? Um, uh, IT Hot Topics in North Carolina for Carolina Advanced Digital. Cool. I ran speaker operations for them.
I ran Source Boston a couple of years ago. I thought that was going to turn into— but that didn't work out. Yeah, so Source Boston one year. I ran— I helped run security for DerbyCon for a couple of years, but that wasn't actually under the company banner. That was more of a volunteer thing to help out a friend.
And I've— besides all Vegas, obviously, Besides Denver. And, um, and this year was your first time running Besides Denver, right? Officially, as like— yes, the sole executive producer. Exactly. Yes.
And it worked great this year. That the venue— the venue we had this year, City Hall— City Hall was great. I'd never been there before. That was it. It was excellent.
Yeah. I'm really kind of was hoping that Alex would be here because I wanted to prod him for the dates for Armisk. Yeah, we need to to give Alex a hard time about it. Yeah, we need to get— because I need to reserve the venue for next year and I can't do that. Let's put him on the, on the hook about that.
Um, oh, I know they were just having elections too though, so— yeah, well, elections are done, and, uh, and so— but Alex is, is going to be the guy who's organizing RMIC next year, so we can definitely, we could definitely put him on the hook. Um, so you're, uh, you know, let's, let's talk a little bit more about the community here in town. There's a If someone wants to get involved in ISSA, they go to denver.issa.org and see when the next event is and they go show up. Similarly for other groups. It's not quite so simple if they want to get involved with the 303 group and get to know you guys.
How would you recommend someone who sees that, the hacker lifestyle and kind of what you guys have done and wants to get to know you and wants to be a part of that group, how should they go about doing that? Well, the best way to do that would probably be to introduce yourself to us at a conference, right? I mean, you don't necessarily know who we are. It's not like we all run around with 303 tattoos. Some of us do.
Some of you guys cover them up, right? Yeah, some of us cover them up. And some of us just refuse to get inked, so that's okay too. But reach out to somebody that you know that's in the 303 and say that you're interested interested in maybe coming out, we do have irregularly occurring events where we all get together and hang out, just have dinner and a couple of drinks. We're all getting old.
We've all got— well, my daughter's married, but most of us have kids that are school age, so we're not going to be staying up till all hours of the night any night of the week anymore. Yeah. Um, or a good way to introduce yourself to the community is come out to DenSec. DenSec. That's, yes, that's the Denver Security Sec.
City Sec. Yeah, Denver City Sec. Yeah. And that's the Twitter feed. It's @DenverSec.
@DenverSec. @DenverSec on Twitter. It's DenSec for short. That's the hashtag that we use. It's Denver City Sec, which is short for security.
Every 2 weeks we have a meetup. The first Monday of the month is here in Southern Denver area, and the 3rd Thursday of the month is up in northern Denver. Actually, tonight, as soon as I'm done with this broadcast, I'm gonna be heading up to the Exchange Tavern. Where is that? In Westminster, on the Westminster-Bloomington border.
Bloomington? Broomington? Broomfield. Broomfield, thank you. Oh, yes, Broomfield.
So that group, you have to basically follow the Twitter account to figure out where it's going to be specifically. But no, actually, now you can go to besidesten.org, and DenSec has its own page off of our site. besidesten.org, and it's got its own page. That's great. So Jacob Torrey had been doing this, and you're taking the reins.
Yeah, since he's moved out of town to the East Coast, we needed somebody to pick up the torch for Denver City CitySec. And so I put this— I put the webpage together for, for Besides Denver. I just decided to throw the link up there. I love it. There's a calendar.
There's a calendar too? Yeah. Oh my goodness. Yeah, there's a calendar that'll show you where we're next. Uh, right now it doesn't have any information for the 1st of July on there, but it does have the information for today.
Well, this is great. Uh, you know, we'll— so we'll get the— your guys' events added to our event calendar that we put together. So as a part of this podcast, we have a website with an event calendar where we grab all of the different groups in town, put all their events in one place. So we'll get those on there as well so folks can, can start to, to get emails about it and let you know that these events are coming from our perspective too. And, and I love it because I, I've always kind of wondered when's it going to come, where is it coming, and now we got a schedule and we have locations.
That's, that's great. So we did move it. It had been the 3rd Wednesday of every month. We moved it over to Thursday so we're no longer conflicting with OWASP. As soon as I realized that that was an issue.
Why are we doing this? Stop it. Yeah, we're excluding half of our participants. That's great. Well, thanks for organizing those.
What's your— you've had the chance to observe the community for 20-plus years, it sounds like. And what do you think you see in terms of trends about what are we doing wrong? What should we be doing better?
I know I give you tough questions. This is going to get a lot of negative remarks in the, in your, in your, um, we can leave the negative remarks. Uh, there is a very large sense of community in InfoSec, and that is one of its best points. It also, unfortunately, the flip side of that is We also have a lot of egos and rock stars. And we need to figure out how to get those egos and rock stars to want to talk to the little guys and help spread what they have.
Because so much of, well, I do this little bit of InfoSec and I'm not going to share what I do with you because you do a different bit of InfoSec. Whereas if the 2 parts were talking, we could make a much stronger security field, right?
There's a lot of compartmentalization that I think we could— we need to tear down some walls and barriers and make the conversations last longer than 140 characters on Twitter. That's a fair point. I don't think that's going to get any negative comments. That's pretty fair.
It is an investment on everyone's side, but it's It's the only way we're gonna build up the community, right? We need to start sharing information. I mean, we can't patch what we don't know. Instead of tweeting about how we have a staffing problem, maybe we could spend some time teaching people, right? Right, that, or maybe we could spend some time teaching HR that 10 years of Splunk experience isn't really possible.
We actually need 15 years of Splunk experience. You started what, 9 years ago? How many years of Docker experience do you have? That's not gonna be enough. You need more.
That's fair. Right? Yeah. Well, you know, I hear, you know, we appreciate having you in the community here and what you've done to help get BSides some momentum and some consistency. I think that's valuable.
It's always been volunteer-run, which is great from a, you know, From many perspectives, but from the perspective of like getting in front of things and having things organized in time, it's really challenging. It is. It's asking a lot for the community to pick up a conference, even if you have a really good core group of 5 or 6 people to break up the responsibilities. It's still— each person would be taking on a lot, especially on top of a full-time job. And usually the people who tend to step up for things like running a BSides are people who have some managerial experience.
Experience or already in a managerial position, so their calendars are as, you know, any— very flexible, very, um, they, they can't exactly schedule a call every Tuesday night for something that's not work and expect to make it. Yeah, right. Yeah, that's fair. So anyway, we definitely appreciate what you're doing there. Um, you know, I, I think that's about the questions I have.
Do you have anything else you want to share with the community or anything else you wanted to chat about? As soon as we have dates, we will have the venue announcement for BSides Denver for next year. And if you go to bsidesden.org, we're working on a site redesign. It turns out that one of our CTF organizers, directors for BSides Denver, is actually a front-end dev, and he took one look at the website that I threw together and said, please let me fix this. I said, please do.
So We should be getting a site redesign soon and then more information about BSides Denver for 2018. Come out to DenSec, DenverSec on Twitter, or just check the DenSec hashtag.
Get involved with the community, mentor, teach, learn, expand the conversation, and most of all, save the world. Hack the planet. Hack the planet. Hack the planet. Well, well, thanks so much for your time, Jen.
We'll look forward to catching up soon. We appreciate you coming out. Absolutely. Thank you very much for having me, Robb.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado equals security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.