All episodes

Brian Martin

Apple Podcasts Spotify SoundCloud

In this episode:

Brian Martin (aka Jericho) is our feature guest this week. News from: NCC, Western Union, Galvanize, InteliSecure, root9B, Ping Identity, Convercent, DigitalGlobe, Vertafore, SecureSet and more!

Exposed sensitive info on every player in the league? That's 30 second in the box

Summer must really be over, because news came fast and furious this week. Ed Rios is out at NCC, Western Union's moving their HQ, Galvanize is laying off employees, Boulder schools gets scammed and beefs up security, a security company makes Denver's Fast 50 list, news in the root9B soap opera, Ping Identity is the king of Open Banking?, Convercent has a good quarter, and a whole lot more news. 

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. We're continually working to improve the show, and appreciate the feedback we get from our listeners. If you discover any audio issues, or have suggestions for our format, let us know.

This week's episode is available on SoundcloudiTunes and the Google Play store. Reach out with any questions or comments to info@colorado-security.com

Feature interview:

Brian Martin (nom de plume - Jericho) is one of the most famous and infamous security community members in Colorado. In this interview Brian tells us his background (hint: it involved some illegal stuff), his hobbies (hint: they have nothing to do with computers) and where he sees the industry going. You can check out my previous interview with Jericho here. Here is the Techdirt link he mentioned, for those who want to support them. And click here if you want to support the animal rescue he tells us about.

Local security news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events:

View our events page for a full list of upcoming events

If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript12912 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood.

Welcome to Colorado Equals Security. This is the newscast for episode 31 for the week of September 4th, 2007. Alex, we've reached the official unofficial end of summer and beginning of fall. Makes me sad. Labor Day is upon us.

I assume you got some great family plans for the weekend. Yes, my plans with the family are that I'm going to leave them behind and I'm traveling. Exactly. Traveling. Asking for this for years.

Believe me, my wife, she's really happy about this. No, I'm going to Minnesota for a Skewer World Conference, teaching a class there. So I'm heading out tomorrow, teaching on Tuesday. We went— my family went to, uh, Eilat Gardens yesterday. Nice.

We've been— we actually got season passes this year and enjoyed going to the park probably like 8 times or so. Quite a bit. Uh, this is— we, as we went the rides, the, the lines were really short. The shortest they've been all year. We, we thought, man, no one comes to Eilat Gardens on, on Labor Day weekend, which really surprised us.

And then in the afternoon we're like, let's go over to the water park area. And we found where all of the people were. They were all in the water park. It was pretty hot yesterday, that's for sure. Yeah, it was pretty good.

All right, why don't we go ahead and jump into the news? Top of the news is DigitalGlobe made the news. You want to talk about that? Yeah, so last week we interviewed Chris Martinez, who's the CISO over there, but this story is more about the business that they do. So I think we're all aware of the hurricane damage in Houston and sort of in the Gulf States, and DigitalGlobe is lending their satellite imagery to help people respond to that, so they're providing images of the damage to help emergency responders figure out where they need to go and do other things like that.

So I thought that was pretty cool. And if you look in the show notes, we do have a link to an article that gives some examples of the images they do. It's really neat. You can— you have a little slider, you can go left to right to see what the area looked like, the satellite image looked like before the flooding and then after the flooding. Really cool stuff.

Yep. Next, Major League Lacrosse. Well, they're not doing so hot. They exposed the personal information of every player in the league. Yeah, so, you know, obviously the Colorado Mammoth, which I'm sure, Alex, you're a huge fan of the Mammoth.

No, this is actually, um, the Outlaws, the outdoor lacrosse. The outdoor lacrosse, not the indoor. I, I apologize to any Mammoth representative who I, who I may have offended there. Um, so yeah, they, they put their basically all of their player and potential player data in a spreadsheet, which they put on the web and you could just click on a link on their website and see all of their Social Security numbers and addresses and what their, their real full-time job is when they're not playing lacrosse. Yeah, pretty good stuff.

Yeah, it's a pretty big oops. I'm sure somebody is not coming back to work the next day. But the good news is they did get prepaid credit monitoring. So this, this problem shouldn't hurt anyone, right?

So Panasonic Automotive Systems is working with the CDOT, Colorado Department of Transportation, to do a smart highway on I-70. Up in the mountains. Yeah. So there's like, I believe, a 70-mile stretch that they're going to be deploying these sensors and other things for a smart highway. I'm not sure exactly how smart it's going to be.

But, you know, it's supposed to get road conditions and other things like that. But, you know, when I saw this article, it just screamed to me, you know, security issue. Yeah. As you and I were talking before the show, I was trying to figure out exactly why they're doing this and what the what the real value is. You know, that the— this company, Panasonic, they're also making the infotainment systems for many new cars, and this should be integrated with that.

So as you're driving up the road, it can tell you, you know, hey, icy conditions up ahead. I see some value. I think that we're missing something. There's some kind— there's some kind of, you know, final ta-da that will make this more impressive. But certainly there's going to be security risks and You know, what are we gonna do about that?

Probably deal, you know, get the security risk exposed, you know, in the worst possible way is my guess. Yes, probably. Next, Western Union is moving their headquarters. So they're moving from Douglas County to one of the new developments on Bellevue, still in the Tech Center, but I think they're technically in Denver now as opposed to being in Douglas County. Yeah, that north side of Bellevue is officially in Denver right there.

And it's just on the west side of 25, brand new building. It's actually pretty close to my house. I've been watching it go up. Look, pretty good stuff. I'm not sure why they're moving.

The article said to be closer to the airport for visiting guests and shorter commutes in general. But interesting move. It's a pretty big move for Denver in general. Yeah. And it's a brand new building.

So I'm sure that that's a benefit. I would bet that since they're moving into Denver, Denver probably gave them some incentives or something too. Well, so Galvanize, this story kind of surprised me. Galvanize just laid off 37 people, which is about 11% of their workforce here this last week. Yeah.

And so Galvanize, you know, they do training and I don't know that they have an accelerator, but they have, you know, workspace for startups and other things like that. And we talked about them, I don't know, a couple, 2, 3 weeks back about them landing a deal to do— was it Amazon Web Services training? Alexa? It was Alexa training. Alexa.

Yeah, that's right. So, yeah, I mean, Considering that story a couple weeks ago, it's surprising they're laying folks off. But, you know, the story talks about how it's, uh, it's a very competitive field for these boot camp type education companies right now. So our next story is about, uh, Boulder schools were breached about a year ago. Um, they were doing— having some construction work done, and some scammers— really kind of an interesting thing that happened here— some scammers called saying that they were working with the, the working for the construction company that the school district was using and said they need to change the way that they get paid.

So, you know, it doesn't sound like it was too bad a deal. The, the older people said, okay, well, there's a form you need to fill out. Um, they, they got the form to 'em. The form was sent from a legitimate email address at the construction company with a forged signature by the CFO saying, here's the new bank, bank account information. Uh, they sent over $850,000 worth of payments before they figured out there was a problem.

And, and they ended up getting back all but about $173,000 of it. So they got most of the money back, but big impacts. Yeah. Again, reading between the lines, it's interesting to me, you know, was the construction company hacked? Was their email insecure so that they could be spoofed?

You know, what was going on there? I think it was some pretty sharp attackers there to be able to figure out all that stuff. Yeah. So the article itself says they're putting new security countermeasures in place, but it doesn't say anything about what they are. So not a lot interesting going on there.

Uh, the Denver Business Journal released their, uh, 2017 Fast 50 finalist list. So this is the fastest growing Denver area companies, and InteliSecure was on that list. Yeah, one of the companies we talked to their CEO and one of their early employees a few weeks ago. Uh, good news for those guys. They're, they're having great growth and nice to see them get recognized.

Um, we've talked the last couple of weeks about Route 9B news. They, they had an auction of their assets scheduled for— I think it was the 31st— ended up getting postponed. It's now scheduled for September 28th, so we'll get to cover this story for a few more weeks. Yeah, so they'll have another month where they can hopefully secure some financing so they don't have to go through with the sale and can continue on with business. Um, next Ping Identity, they were chosen for the Open Banking UK Framework standard.

So there, Ping is now going to be used for that standard. Yeah, so this is really cool stuff at Ping. What we, uh, we have the opportunity to work for this brand new regulation in the UK. Quick summary, banks in the UK need to make it easy for consumers to get data in and out. Think about how Uh, in the US, you know, if you use Mint or you use, you know, QuickBooks or something where you want to get information out of your bank accounts, it's not always easy.

Sometimes they have to do screen scraping to pull data out, and the banks are not really incentivized to make it easy. Well, open banking is a standard in the UK that tries to standardize this, and there's a central organization that actually manages that system. Well, that— the central organization picked Ping to be the, the data Uh, you know, the, the, not the stewards, but the interaction between them and the banks. And then the banks get to pick their own technologies. So, you know, so Ping's working with many of those banks as well.

So pretty cool stuff. The story, uh, here kind of summarizes that. And, uh, pretty cool, been good stuff for us here. Uh, so next, uh, Conversant, who we've talked about a few times, uh, they post record results for the second quarter. Um, Robin, I had a, a, uh, a joke earlier that as opposed to record results, they're recording results.

But depending on how you read it, it's really exciting or it's really boring. But, but they actually had a really good quarter. They have a few bullet points showing they had 40 new customers join in the quarter. They hired another— what was it, 30 or 12 employees? I think it was— they're up to like 127 employees now.

And my favorite bullet point, they had greater than 100% customer retention for the second quarter. Yeah, absolutely. Some funny numbers there, but I'm sure that's standard salesy stuff. So Conversant is the, the company that does ethics and compliance training, uh, as a SaaS service. They, they've been growing well.

Sounds like a great place to work. Uh, really cool stuff for them. Uh, last piece of news here, Ed Rios, who we interviewed on the show a couple months ago, uh, he was the CEO for NCC and he has stepped down from that position. Yeah, um, I was interested to, to hear more details about this, um, you know, looking through the press release that came out Um, it sounds like he's going to be leaving to spend more time on his own business ventures. Um, I think that he, I don't know, I guess didn't have enough time for, for all the stuff that he was trying to do.

And the other piece in there that I thought was interesting is Vance Brown, who is the former CEO of Sharewall Software. They do help desk and, and ITIL kind of software, you know, competitor with ServiceNow and things like that. He's going to be stepping in in the interim to be the CEO of the NCC until they hire a full-time person. Well, this seems good. I know NCC has a lot of promise and there's certainly a vision there.

They haven't yet delivered on that vision. Hopefully Vance can come in and help move us there more quickly. A couple of housekeeping things. Number one, if you like the show, please subscribe to us on iTunes, Google Play. Rate us.

I don't think we talked about that. You could rate us. Yeah. Only if you like us. Don't rate us if you hate us.

But that'd be great if you wouldn't mind doing that. Also, we have a store if you guys want to buy your Colorado Equal Security t-shirts, hats, koozies, whatever else. It's all out there on the website. Keychains, phone covers, anything you could possibly think of. And speaking of the website, we do have a calendar of events on the website.

We'll go through the next couple of weeks worth of events now. So first, Denver Sec, they have their South meetup on the 4th. And that's the only thing happening this week. Uh, pretty, pretty mellow week. Um, the following week on the 9th— excuse me, the 12th and 13th, ISSA Denver has their, their September meetings, and Dionne Mahaffey is going to be talking.

Dionne is the security leader at Antero Resources, one of the big oil and gas companies in Denver. I think she's going to be talking about her endpoint replacement project. I believe so too. Cool to have a local person, uh, talking at one of those meetings. Next, CTA is having their Insight Series with Forrester Research on the 13th.

On the 14th is the 3rd Women in Security event. This is the Denver Women in Security group that's met a couple times already. Been a fantastic success so far. This is a chance for women to get together, talk about the unique challenges they have in the security industry, help promote one another's careers, and there's some good education going on as well. So number one, if you're a woman and you haven't been to one yet, highly recommend you check Check this out on the 14th.

Or if you're a man, you probably know some women either who are involved in security or may want to get involved. So just reach out, send some notes. Let's try and drive attendance for this event. And I believe if I remember right, this is the event where they're going to have some of the high school CyberPatriot kids come in and do some presentations as well. So that should be pretty cool.

They are. And they're also going to have a bunch of recruiters there. I know that they have recruiters from LogRhythm, Optiv, Ping Identity. Some other local security companies who may want to just talk to new candidates. So this is a chance to really get to meet folks.

It's a really good opportunity to get to not only meet the hirers at security companies, but also the security leaders from a lot of different companies in town. Also on the 14th, SecureSet, they're having a career conversations, Hillary Constable, on utilizing your network. Well, hopefully, it seems like the order might be wrong. We need her to talk before so people will go utilize their network at this event. Exactly.

Or maybe you make a network at Women in Security and then you learn how to utilize it. Either way, uh, the last event here in the next couple of weeks is on the 16th. There is a CCSK training. That's a Cloud Certified Security Knowledge training. It's the Cloud Security Alliance's kind of entry-level-ish certification.

I took this 5 years ago or something. Uh, highly recommend taking a look at this if you really want to learn how to get more knowledgeable about the cloud as an entry point. It's put on by Muhammad, who's a— who's our friend who works at OIT and security with Debbi Blyth, and he's also on the board for the Local Cloud Security Alliance. Uh, and one more event that we wanted to talk about is not in the next couple weeks, but, um, there is a SANS Security 511 Continuous Monitoring and Security Operations course that's coming up. This is actually happening at the LogRhythm headquarters on the 18th to the 23rd.

So LogRhythm wanted to have this class for their folks, but there's also some open slots there. So if that's something that would be of interest to you You can sign up through SANS just like a normal class, but it'll happen here in Colorado at the LogRhythm headquarters. So no travel. If you've been looking about doing SANS and it's hard to pay the price tag and have to do the travel, well, here's your chance to try and just pay the price tag for the training. Exactly.

So let's jump into the jobs. First, Cognizant is looking for an endpoint security architect. So we heard from Jacob Rubin over there. They're looking for somebody. So If you want to work with Jacob, go ahead and check that one out.

So this Cognizant area, it used to be Trizetto down in the tech center area. Um, if you guys are familiar with Trizetto, pretty good-sized company that was swallowed up by Cognizant 2 or 3 years ago. They've really been doing some cool stuff since then. We're supposed to get Matt Shufeldt, who's the CISO over there, on the show one of these days to talk about what they're doing. Digital Globe is looking for an information system security site reliability engineer.

Weldyne, who I hadn't heard of before, but they look like they manage prescription insurance, uh, for a lot of different pharmacies. They're hiring an information— a director of information security, which is their CISO title. They actually have the title CISO there as well. Uh, Vertafore is looking for application and product security manager. Yeah, and Vertafore is one of the companies that's owned by the same private equity that owns Ping, so I actually know the the guy who had security over there, Adrian, and I'm happy to share information if you guys are looking at this.

Uh, they are looking for someone who, who knows how to done— how to do product security, application security, and maybe he's done it before. Accenture, they are looking for a cloud security senior manager. InteliSecure is hiring a cybersecurity intelligence expert. So if you're an expert, go ahead and apply there at intelligence. Uh, the Bureau of Reclamation is looking for an information systems security officer.

SecureWorks is hiring a security sales engineer focusing on SLED, state and local government and education. Um, and that, that's, I guess, SecureWorks here in Denver. And then some company I've never heard of, Ping Identity, is looking for an IT systems administrator. Yeah, if you want to come do IT for an awesome company, that's a good opportunity. Reach out to me if you want to, I can help you.

Get plugged in there. Well, that's it for the news this week. Our feature interview starting in a couple minutes is going to be Brian Martin, also known as Jericho, talking about some pretty interesting stuff. He's been in Denver for 30 years or whatever and really has been doing some fun stuff in the community. We're going to get to hear about attrition.org.

If you haven't taken a look at that website, you might want to look at attrition.org before you listen to the interview because it's really cool. Yeah, Brian's a really interesting guy, so I'm looking forward to hearing it. Cool. So, all right, well, have a good weekend, or have a good week, and we'll talk to you next weekend. Thanks, Robb.

Hello, this is Ian Buxton, Senior Director of Information Risk and Security at Vail Resorts. This is Colorado Equals Security, for Colorado security professionals by Colorado security professionals.

Welcome to Colorado Equals Security. For this feature interview, I get to have the opportunity to sit with one of Colorado's foremost security good guy, gray hat, black, black hat, uh, historical guys. Um, we get Brian Martin, also known as Jericho, who runs attrition.org. Brian and I were just talking about, um, rehabilitating raccoons. So Brian, you want to tell how we got there?

Why are we talking about rehabilitating raccoons? Right, so, uh, in the industry a lot of people know me as the squirrel guy. I tend to post or tweet about animals and squirrels more than security these days. And yeah, we were talking about in the context of not only are they fun, clever, resilient creatures, but I actually volunteer up north just outside of Longmont at a place called Greenwood Wildlife Rehab. And we rehabilitate around 3,000 animals a year, Colorado wildlife.

That includes just about every species of bird here, waterfowl. So you have geese, ducks, We get some rare ones in, bitterns, cormorants. We also do raccoons, which I am now trained to work in. So that's fun. Raccoons are always, you know, everyone loves them when they see them on the internet, but when one's walking up to you or your trash can, it's a different story.

But yeah, that's basically my Sunday. Don't touch a computer day. Go and help animals. And yeah, I've found it's very relaxing and good for the mental health. So if there's somebody listening right now who wants to help with animals, what should they do?

Well, unfortunately Greenwood is about the last shop in most of Colorado. The other ones have mostly shut down for various reasons, almost always funding, because none of them receive any help from the state or local governments, but they have to comply with all the regulations and rules. The best way to help is if you actually have the time is sign up to become a volunteer. You'll take a 1-hour training session for birds, for example, or a 1-hour session to rehabilitate squirrels. And after that, you volunteer for 5-hour shifts.

They prefer at least once a week. And yeah, after that, you just get to help animals. And then failing that, if you have a few bucks, go to their webpage and Um, also check out Facebook and Twitter and you can see videos of a lot of the animals in the process. So, uh, one of them that's real fun right now is we have 5 minks, which until last year I had no idea that Colorado had minks. I didn't know that either, right?

So last year we got one in, uh, his name was Robbie, and he got released within 24 hours because he was perfectly healthy. He had fallen down a window well. Someone found him and thought it was a ferret, so they took it to Longmont Humane, right? Wild Non-Humane didn't actually identify it until they went back and they said, oh crap, that's not a ferret. And I heard the rumor on a Sunday and I was working the front desk at Greenwood and said, hey, if you can get them over here, we'll be glad to take them.

Yeah. And so yeah, now we have 5 little— well, they're getting big, but 5 baby minks. So these are the animals that are of the infamous mink coat, is that correct? Yes, technically. Um, I had no idea they were in Colorado.

Yeah, no, there's a, there's a lot of animals that pop up and you're just like, wow, we have these? Uh, because sometimes they're just isolated in certain pockets or, or whatnot. But, um, yeah, it's, it's extremely rewarding, uh, to watch the animals go through that process. And if you can go to a release, uh, where we, you know, say, hey, it's rehabilitated, it's ready to go, yeah, it's just one of the best feelings. Yeah.

So I guess we'll just take a little bit of a turn. You and I talked, was it 2 years ago, maybe even 3 years ago, All right, we did a write-up interview. Um, we don't want to go over all the same ground, but I think it would be useful to— and by the way, I'll put this— I'll put the link to that interview in the show notes— be useful to just kind of talk about how you got into security and what you've been doing. So, you know, back us up 20 years or whatever, and how'd you get here? Yeah, um, I, I actually kind of like telling this part of the story because I'm one of the only people in our industry that will openly admit it, that I started out as a what we now call a black hat hacker, that I was breaking into systems.

But the statute of limitations is— oh yeah, it's passed. And but part of it is that the mindset, the tone of it, the reasons were very different because back in '91 and '92, we didn't have Google. You couldn't download 15 different operating systems and run them in a VM. You couldn't look up their documentation online. So the only way to learn those systems was to somehow get access to them.

That for us meant dialing into a voicemail system, using it as a diverter to go to a second voicemail system, to go to a PBX. So we diverted 3 times. We would go into Colorado.edu's dial-up annex. We would pop through 2 or 3 Colorado.edu machines and then explore the internet at the time. And it was never malicious.

It wasn't defacing. Even back then, you know, you're talking the first days of the HTTP protocol, let alone websites. What years are we talking about? '91 to '94 was kind of the peak of it for me. Yeah.

And yeah, so it was, it was really about what's out there. The first time that you got to log into a system you had never seen, you know, it's like making the, the change from a Unix box to VAX VMS. All of a sudden it's a completely different world. None of the commands that you're used to work. Just trying to figure out how to learn the commands, then what they do.

Yeah, it was interesting. And back then it was The community was also generally more tight-knit because it was mostly a spirit of being helpful to each other or trading knowledge. And it wasn't one of those, you know, work out, hammer out an agreement. It was more like, oh, hey, you know VAX BMS, I know a 1A phone switch. You want to, you know, share some of our skills.

And sometimes you would actually sit down in person with them and look over their shoulder and you would learn it. Other times it would be on IRC or whatever. So yeah, it was very different back then. I think anyone that was hacking during that time frame really does miss it, and we, we talk, we joke, and we get harassed a little bit about the good old days.

But yeah, it's, it's a world that's long since gone, and I don't think that will ever return, or if it does, it's just much more isolated. Isolated because the way the internet's changed. So how, how did you develop a community in, I assume, in Colorado around that? Because you're, you're all hacking into individual things. How did you guys get together?

BBSs? Or— it was BBSs. Um, that's where you start to identify other people. And depending on the nature of the BBS at the time, whether it was a little more closed, or oftentimes you would log in and default access, you would have access to say 10 forums or whatever. And then once the, the sysop identified you as, oh, kind of a hacker type, you might get access to a general hacking forum.

And from there, the more they learned about you or what you were interested in, it might open up new avenues, or someone would send you a message and say, hey, I noticed that you mentioned this, you know, SunOS 4.1.3. I've been having a hard time with this exploit, or you know, you want to compare notes. Yeah. And, um, at the time, I think it was '92, give or take, uh, there was a— because back then there were hacking groups, you know, kind of akin to a gang that you had your fellow people you ran with, and everyone was proud of their, their name and their skills and what they could accomplish. And I joined a group called TNO the New Order.

And we, like a lot of groups, we published online zines with hacking articles and basically shared some of our knowledge. Is that a national group or a regional group? It was all Colorado, at least at the time. Um, I think one of the members may have moved, but it wasn't, you know, and there were national groups. It was people who knew each other that were all part, right?

We actually met several originally once a week, and then, uh, 2 of us became roommates. Then sometimes it would be Friday, Saturday, both nights would be 6, 7, 8-hour hacking sessions. Yeah, driving around town going trashing and looking for manuals and everything. So yeah, that also really lended to that tighter-knit community because we were friends as much as kind of work colleagues. And even back then, it, it was still almost like a company.

It's like, hey, I'm having a problem. Let's, let's go get— talk to so-and-so who is really our Unix guy. Or, man, we lost 2 diverters. Let's go talk to the guy who's doing all the scanning for phone systems. Yeah, you know, um, so we all had our little skill sets and then we started cross-training.

I was really into phones to start. Freak. Yeah. And one of the guys in our group, he was really good with Unix boxes. And we one night said, okay, let's cross-train.

He started teaching me everything he knew about Unix and hacking. And I showed him as much as I could about phones. And then even on a national level, there was a hacker that at the time, I think he lived in Texas, but he had grown up in Colorado. And he was a really solid phone guy. Yeah.

And he came in and we set up a meeting. He basically was like a guest lecturer, showed us how to do 1A switches. And then once I really latched onto that, and after that it was, okay, I want to learn more. Then it was trashing 1A switches, looking for command output and everything. And one of the funniest stories I can remember is the Denver Southeast 1A switch.

It's over off Colorado Boulevard and Evans, I think. Okay. I actually lived less than half a mile from it. So it was basically, oh, after work, let's run by, jump in the dumpster, pull it out, all the trash, and we would look for these logs of all the command output. And so we're doing this and months into it, I'm going through my night's haul and I notice, whoa, someone's running the same kind of commands I I am.

And it was another hacker. Yeah. Turns out it was the guy that we ended up talking to that did the guest lecture. Oh, really? He still called in from Texas to access that switch.

And yeah, I told him about it and he just thought it was hilarious because it ended up being just a great coincidence. And, you know, but it was also, oh, by the way, I've been shredding those, so the evidence is gone.

Huh. Yeah, those are the kind of stories that anytime a few of us get together now, we still reminisce over it. And, uh, any of the guys who I know part of this, other than you obviously? Yeah. Um, I— they don't want to throw their names out right now?

I will let them out themselves. You definitely know, I would say, at least one, or know one or two by reputation, even if you haven't really talk to them. Um, okay, well, it's cool that people are still in the community. All right, so, so very cool you guys built a community. Yeah.

Did you have a job at this time? What were you doing? So when I moved to Colorado the first time, uh, I think that was '92, maybe. I think so. Anyway, um, my first job was working at Computer City as a cashier.

Then eventually they realized I knew quite a bit about the computers themselves. So I started doing sales, went to Best Buy after that and worked on the sales floor. I also sold cell phones. And another irony of ironies, years later when I talked to Kevin Mitnick, yeah, that period was when he actually lived in Colorado under a different name. And he said that he frequented that Best Buy quite a bit, and he remembers a guy that really knew cell phones.

So we're pretty sure that I sold him one of his cell phones. It's just another freak coincidence. For those who don't know, Kevin Mitnick was, uh, was convicted of all kinds of computer abuse, one of the, one of the early hackers, and served some time in prison. And he's now kind of a speaker and consultant, right? Yeah.

And One of the reasons that his name is well known is that when he was busted, I think it was the second time, and he was in the LA County Jail, the judge said that he could not have phone access, that he could not touch any electronic device. And the reason that he couldn't have phone access is that the DA or whoever argued that he might be able to call up a military installation and whistle nuclear launch codes. And the judge bought it. Well, they didn't know much back then, I assume, right? Or they didn't care much, either way, right?

Um, so he was not only stripped of those kind of privileges, but he was denied a bail hearing for over a year. Wow. Which constitutionally, that's just unthinkable. So his case had all kinds of legal problems and hurdles. And wow, we've never heard of this before.

So it was very much an uphill battle for his lawyers. Um, it's a fascinating story. Uh, not only that, but all the, the hijinks that led up to it. And it's covered in a book or two. The Ghost in the Wires, that's the one I read by him.

I 5 years ago or something like that, right? And then, um, Samara or whoever, uh, one of the guys that helped track him down wrote a book as well. And then, um, a journalist with the New York Times, uh, wrote a book about it. So there were 3 books about that part of his life from 3 very different angles. And when you read all 3 of them, it's another fascinating glimpse because back then those were very radically different viewpoints and to see the contrast.

I think for anyone who hasn't, who doesn't know much about the early hacking community, that I think that'd be a good entry point. Absolutely. It's approachable. It's interesting. It's Colorado-based, at least a large part of it.

It'd be a fun thing to read, right? They're compelling because they're written as, let me tell you a long story that's really interesting, not here's all the technical minutiae or whatever else. And even back then, I enjoyed reading any kind of hacker or security sociology books much more than the technical ones. I mean, yeah, sure, I love learning, but those are the ones that really, like I say, they told you a story, right? And stories are how we, how we love to communicate.

All right, let's move forward. You know, you're working at Best Buy. How did you get into security? Well, from Best Buy, then I started working at what became the Geek Squad. I was actually one of the first Best Buy techs that actually started doing in-home work.

Did they give you the little— was it a VW? No, this was use your own car and we'll pay you for mileage. It was basically the pilot program that turned into the Geek Squad. And after that, one of the guys in my hacker group, he had been working at a trade college here in Colorado And he said they needed another instructor to teach what they called business computer science, which is primarily Office, Excel, you know, desktop business applications. Then I helped him design an intro to Unix course.

So that was my first real job as far as something related to computers other than selling or fixing them. After that, another friend of ours, he worked at a security company down in Colorado Springs. And at the time, my resume showed that I knew nothing about computer security, yet I clearly did. So I had an interview with 2 guys from that company. And they said, look, you know, you seem like you, you really know your stuff.

But we do a lot of, you know, consulting with the military, we have to share the resumes with the them, and if they see this, they're not going to understand that you seem to know computers. And, you know, is there anything that you can tell us that's really compelling? Basically fight for this. How— why do you deserve the job? Yeah.

And so this is back in the days of the Motorola flip phones, and one of the guys had one. I said, can I borrow your phone? Took the battery off, jumpered it into test mode, hit a few buttons, and I handed the phone to him and said, listen, And so he puts the phone up, he's like, what am I listening to? I said, someone else's conversation within about 100 yards of here. You're hired.

It was almost that simple and that quick. Wow. Is that as soon as it became a hands-on demonstration and that it was just kind of like, oh no, this is easy enough.

So in '96, I got my first penetration testing job. Back then there were very few companies doing it. It was, I want to say, '97 to '99 was kind of the big explosion, as I recall, of pen test companies forming or whatever.

So yeah, that was a, it was a big transition. And then from there, that was pretty much cold turkey. No more hacking at that point. Anyway, you went from bad guy to good guy. On a dime, basically.

Close, yes. And it was basically, now I have something to lose. Yeah, I have a good job, I have a salary, I've got benefits, and at this point, if I got caught, that, yeah, it could ruin me in the industry forever, right? So, uh, yeah, it was quite the, the change. Yeah.

Okay, so, so you started doing penetration testing, basically, uh, computer testing, or Phone systems or everything? It was probably not much phone systems. They didn't care for that, did they? Most of them didn't, but we did one or two engagements that had a social engineering component. They would give us a list of 20 employees to call up and see if we could get information out of them.

Pretext calls, right? Some of them were very straightforward. Hey, this is Bob from admin. What's your password? Right.

It's amazing how many people give it away. And they did make up a name, Sam from IT, for that. Engagement, 19 out of 20 gave up their password, and the only reason the 20th didn't is it was one of their security guys. Wow. So of course he's— and I remember his line mostly word for word.

It was something like, you know, you sound really nice, but I'd rather have you put a bag over my head and kick me than give you my password. To which, of course, we're laughing, saying, no, I understand. Um, but there was still no indication that he thought I was someone from outside the company. Um, was it a pretty big company? I believe so, yeah.

Uh, but yeah, we ended up doing almost all computer intrusion, um, through that company in the Springs. Uh, the team, we had to move to San Antonio, and then once down there, we started doing some really big clients, um, insurance industry, uh, We were already doing national banks in a few cases. Yeah. Yeah. Like one national bank that was still running NT4 servers completely unpatched or, you know, it was quite the shock.

Yeah. But yeah, so that was the transition. Did pen testing for 13 years and eventually got tired of that. Yeah. When did attrition.org come to be?

I think the domain's registered in '98. So I'm going to pause you real quick. Anyone who's listening right now, pause the podcast, go to attrition.org, and just look through the site so that you have context as we go. This is, this is, uh, this is what Jericho is probably best known for, I think. This website— not famous, infamous.

Um, yeah, so it really ramped up in '99. Uh, there were 4 or 5 of us that we called staff, and it was basically Hey, everyone, do your thing, whatever you want, whatever you think is helpful. One of the guys was big on teaching people about the safe use of firearms as much as computer security, so his page centered largely around that. We were writing a lot of guides for intro to security, intro to hacking. Sometimes it was just intro to Linux.

This is how you use some of these commands more effectively. And at some point, I was getting really, really tired of news articles that were misleading about security, so I started calling those out. And I don't even remember all the details of who else was involved, but several of us— I definitely spearheaded it, but we created what became known as Errata, a list of mistakes, basically. And the Errata section of the website kind of branched out, so it was the media, then it was companies, like if a security company got hacked or whatever.

We were the first one to catalog data breaches as part of Errata.

And probably the one that we're most well known for, because it's controversial, is people that we thought were frauds or charlatans in our industry, we would actually document that by name, show all the evidence that we had, and basically to offer it as a warning to people doing business with them. It's like, you know, do your due diligence, make sure you understand who you're getting involved with. Um, and that took a toll emotionally and even physically. Uh, there's been a few years of my life where I walk out my front door and I'm looking around for people with guns, uh, because I have received several death threats. Um, people don't want to be on that list, do they?

No. Uh, and when you tell them you're not going to take it down, yeah, then yeah, they're like, okay, fine, I'm going to meet you at a conference and we're going to, quote, talk about this, you know. So it needed to be done. I don't regret that, but it's not easy at all. You have a whole section on the website.

I have it up right now around legal threats. Yep. I assume this is about the Charlieson stuff or what's this? No, that's actually companies that are threatening researchers for disclosing vulnerabilities. That's one that I'm probably most happy about.

That's that part of the site is because it does show a clear pattern of certain vendors trying to intimidate researchers to hide vulnerabilities. And most of the people in our industry, I think, are much more— know that information should be public so that your customers are aware of it, that they can install the patch. Because if a company releases a patch and they don't say what it's for, well, why do I need it? You know, they may not install it. But as soon as you say, hey, it's a security patch, and as soon as you even say, well, there's a remote code execution vulnerability, that becomes more compelling.

Then the admins are like, yes, we have to install this patch. So you don't necessarily need to disclose all the technical details, but vendors, they just can't go after researchers like that. It's not ethical to me. I do feel like, and I'd love to get your take on it, It feels like the industry has come a long way and that responsible disclosure is something that many companies are taking seriously now. Back up.

We do not use the term responsible disclosure anymore. What do we say? It is coordinated disclosure. Coordinated. Okay.

This is actually a little bit of a campaign of mine. There's a lot of people that are embracing that, and the reason being is that that term was invented by a vendor to essentially to use it to potentially demonize the researchers. Tell them what they know, what the ethical thing is to do versus— Right. And the problem is, is that some of these researchers were being responsible according to those terms and the terminology put forth. But the problem is that the vendors weren't.

They were taking years to patch these vulnerabilities and they were kind of, I don't know, they had their head in the sand to a degree. Because they thought that, oh, well, only one person in the world knows it and he's working with us. No, that's not how it works. There's been a long history of the mutual discovery that show, yes, 2 or more parties knew of that vulnerability at the same time. And if 2 did, we have to assume one or 2 bad guys knew it as well.

Yeah. So yeah, that's— I find that's why I find it important is not to use the term responsible disclosure anymore. That it's a coordinated thing. It's the researcher and the vendor working together to produce a patch and release enough information to make it compelling for a company to install them. So you're telling me I need to go to Ping Identity's webpage and change my responsible disclosure title to coordinated disclosure?

Is that what I'm hearing? That would be ideal. I will look into it. I'll say that. Well, just consider is that if a researcher has a bad experience in the past with a company that went after them legally or threatened them, is that they may read that and say, well, this is another company that may try to demonize me.

And you want to make it— the goal is to make the happy path telling me about the vulnerability, right? You want to make that path as available as possible to as many researchers as possible. And yeah, you want to be open, inviting. And this is not just you and Ping. This is any company, is that it's only going to help you.

You're going to learn more about the vulnerabilities in your software or your services. You're going to be given more of a chance to patch them before a bad guy takes advantage of it. I'll tell you, you have made a difference for me at Ping. I've been here a year and a half. One of the times we talked in the last couple years, I remember you saying, number one, talking about disclosure quite a bit, but also talking about Hey, any security— I think you tweeted it— any security company that doesn't have security@ set up, you know, as is basically suggested by one of the RFCs.

RFCs, yeah. I don't think it was— I read the RFC after you tweeted it. It didn't say you have to, but it was a recommended thing. And but if you're a security company, you need to do it. And I'm like, yeah, yeah, we didn't have it externally available.

Now we do. And not a lot of folks talk through it, but trying to be that the other side of the coin, right? You're on the side finding it, being— trying to be on the side where we want to be as receptive as possible and make it convenient for you to let us know versus posting it on Twitter and we find about it that way. It's actually what is basically— it's that mindset that has given rise to the bug bounty programs is, yes, we want to be receptive, and now, hey, if we can reward you, you're even going to be more likely to report those vulnerabilities. And a lot of companies are finding great success with bug bounties.

They're not a magic bullet. They're not going to solve all of your problems, but it's definitely one thing to consider in the arsenal of your security capability and response teams. So just go back to finish off the attrition.org conversation. If you haven't read the charlatan page yet, I highly recommend everyone take a look at that. There's some fun email exchanges you've got in there as well.

Anything else you want to call out that's worth reading?

I would say probably there's one or two. My battle with Greg Evans is probably one of the longer and more compelling to read. Is that in the Charlatan section? Yeah, he's, I think, pretty much at the top of the page. Yeah, I see him there.

He is a character.

He loves to brag about certain things in the past that aren't quite accurate. He maintained for the longest time that he was the number one hacker in the world or the number one penetration tester in the world or whatever, when there was no evidence that he was even a half-skilled one.

He threatened to sue me, and he was one of the only ones to actually, uh, carry through with it. But even then, he was well known in the Atlanta court system, and there was— there were problems with his lawsuit. And he tried to file it versus John Does, uh, in an attempt where he could use it for discovery. Yeah. When in reality, he knew all but one of their names.

And so I was one of those John Does. Yeah. Um, and I— it's the only time I've had to retain a lawyer. Otherwise, after my bout with him, I now joke that I'm the number one armchair lawyer in the world. Uh, but that was the one time I actually had to retain a lawyer, uh, primarily because I didn't want to go down there and defend myself.

Yeah. If I had time and money, hell yes, I would have done that. That would have been a blast. Um, and yes, I know the adage about never represent yourself. Yeah.

Um, so anyway, uh, hired the lawyer. They went— he went to court and basically worked out a deal with Evans' lawyer. And, uh, it was for some reason, despite having 20 articles up about Evans, he wanted one piece of one article removed. Okay. And so I said Wait, let's get this in writing.

I read it and I said, yes, we'll agree to that, because first I'm done with court, the case is solved. So I removed one image from one article and replaced it with the image that was here had to be removed because Greg Evans threatened to sue. And so it became very much a Pyrrhic victory because it was also on archive.org, of course. So Yeah, it was just— did you have a link to the archive.org? I think I did.

It's probably still there, or I imply it. That was one of those that I was following the letter of the agreement. Uh, I was a little wavering, wavery on the, uh, the spirit of the agreement. Um, but, uh, yeah, like I said, he's a character. Um, after that, it's just such a weird mix and Here's one that's even relevant today.

On the list, there's— I forgot his name— some guy, he claims to have invented email. And he is currently trying to sue Tech Dirt now, because Tech Dirt wrote an article exposing him saying, look, you didn't invent email like you claim. But yeah, I had covered him. I think it was 2012. Okay, several years ago.

Uh, but yeah, this guy's still going around claiming it to anyone that will listen. And in my article, it was basically, here's why the claims are false, here's the RFCs that show the foundation of emails, his name's nowhere on them, this and that. So I, I approached it more, you know, just let's lay out the evidence, you make up your mind. Um, but yeah, this guy has resurfaced now, and I was like, oh, it's a blast from the past. Yeah.

I'm glad he's trying to sue someone else, not me. But yeah, TechDirt is a great organization. They write some incredible articles.

And I think right now they're encouraging people that if you like their content is to buy a shirt or help them out because they are going to have to mount a legal defense and it will be costly. Well, why don't we get a link in the show notes for that as well then? Right. I think it's just techdirt.com or @TechDirt on Twitter. Okay.

I do want to— we're going to run out of time here, so I do want to keep moving. Why don't you talk about— I don't know if OSVD is the next thing in your chronology or— Actually, so despite all my interest in the industry, the one thing that I have done pretty much most of my professional and hobby life with computers is maintain a vulnerability database of some kind or another. For the hacker group, it was more exploit databases. These are all the exploits, and we actually had a classification system so that we could quickly say, okay, this one's remote, requires authentication or not, whether it was denial of service versus execution.

And in 2004, I believe it was, just maybe a year into the project, I got involved with OSVDB, which at the time was the open source vulnerability database.

I became one of the officers of the Open Security Foundation, which was created to run that, and then another project, Data Loss DB, which was seeded off of the Attrition Errata breach archive. So yeah, I'm very much a collector one way or another. But is the Data Loss Database still up? No, both OSVDB and Data Loss DB were shut down. The overall reason is that, well, OSVDB was designed to be a community effort.

The philosophy early on was, well, if every security professional logs in for 15 minutes a week to help with one vulnerability entry, we will crowdsource and have the most amazing database that's free for everyone. Problem is, we had very, very few volunteers, they wouldn't stick around. So then we said, okay, well, start kicking in $5, you know. William Knowles, who took over the ISN mailing list from me, that was one of his big things. Skip one cup of coffee a month, give me $5 so that I can keep providing this service for you, because unfortunately there are costs associated with those services.

So with OSVDB, we had people using the data in ways that violated our license. And some of these companies started profiting very heavily off of it. Early on, I think 2008, '09 or so, we found one company using our data and basically approached them and said, hey, you're not supposed to use the data in a commercial atmosphere. You need a license for that. And he says, oh, well, you know, how about I donate?

And we said, that probably works. He PayPal'd us $20, and his company was already making hundreds of thousands of dollars a year.

Eventually, Jake and I formed a company with 3 other people called Risk-Based Security, who I'm with now. And for the first 2 years, we were offering a vulnerability database based on OSVDB as a service where we had more metadata, more fields, but we still kept that one free. And it was our biggest competitor. It was business-wise, it was not very sound, but we were still that compelled to try to make that data free. We still wanted that to be available to everyone.

We believed in the open source idea. And eventually, no, we just— we get— we would receive more and more warnings that companies were using it. In some cases, they would talk to us as RBS, and say, hey, your service sounds great, but we don't want to pay that much money for it. And then a month later, we saw them scraping the OSVDB data. So we had to close it down.

It was— and I think Jake will agree with me, it was probably one of the hardest decisions either of us ever had to make, because we put a lot of time into it. And it was basically the same thing on the data loss side. Is it about a year ago, by the way, you shut that down? OSVDB was now think 2 years, give or take. I remember, I remember when you did it.

Right. So if you go to— big news. If you just go to osvdb.org, it'll redirect to the blog. And I think it might be a pinned blog about the closing down.

So now I'm focused on still running that, that type of database.

But the— it was more than 2, I think it was 3, or maybe 3 years that RBS completely funded OSVDB, provided the manpower and the money to keep the servers running, to do all the data input. And during that time, we were much more timely than we had been before when it was just a free hobby project. Right. But yeah, that's the foundation of what we call VulnDB on the RBS side. And it's basically vulnerability intelligence as a subscription model.

And We're finding it increasingly easy to sell that service because more and more people realize now that the other well-known public source of vuln intel, which is CVE, is woefully behind to the tune where they're missing about 50,000 vulnerabilities that we cover, for example. They're also desperately trying to change their model. They're going to what they call a federated system. Where they're making more and more companies able to assign the CBEs. And now they have a web form where any researcher can request it.

And that's fine, that's great on the turnaround time. But now they're also letting the people write those CBE descriptions themselves. And so the quality of CBE has gone way down. And consistency too, right? Right.

And some of them, they're, they're so vague that you don't understand what the real risk is. And now it's turning into more work for the companies. It's like, well, we can consume this data for free, except for it's what I call the high cost of being free, is now you have to have people go through, reread the disclosures, try to figure out what the vulnerability is. Oh, there's the version information we need. No, we're not even running that version.

You know, it's just, it's not sustainable in today's atmosphere where organizations have 100,000 computers and a security staff that is amazingly talented, but way too small, where they're still trying to make decisions about, well, we can't patch all the vulnerabilities, we have to triage. And yeah, you just can't afford to sink that kind of time into it.

So yeah, CVE, they're improving their number of vulnerabilities covered, but that's not helping anyone, you know, quality is going down at the same time, right? So anyway, that's, That's one of the 2 big things we do, and the other one is we offer data breach intelligence. What's that mean? So every week you'll hear about a company lost 5 million records, uh, patient data, whatever. Sure.

Those incidents have become so commonplace that it's only the big ones that are covered. Yeah. Uh, we catalog the other 250 that happened that week, you know, that kind of thing. And so we have an incredible database of what companies were breached, what information was lost, whether it was a malicious act, whether it was accidental, was it internal, was it external, was there a lawsuit involved. So once again, we're wrapping a lot of metadata around this.

And our number one consumer of that is the insurance industry, because right now cybersecurity insurance is the big thing. You know, companies are saying, Wow, we can actually pay pennies on the dollar to get insured, and if we get breached, we get a lot of our money back, you know, that kind of thing, or they get compensated for it. The problem is that the insurance companies, they have 200 years of data on like household fires, and they have 100 years of car accident information, but they really had no glimpse into data breaches and what's causing them and what's the fallout. So, they're big fans of that kind of data, which is interesting because it essentially starts to act as the actuaries for cybersecurity insurance.

But, yeah, so when people ask and I talk about this, I say I don't like the term threat intelligence. It's too broad. It's an umbrella term, and I understand it in certain conversations. And context, but I'm very quick to tell them we offer 2 very specific types. We don't do malware, we don't do threat actors, we don't do IP-based.

We specialize in 2 kinds, and by doing that, I think that, you know, you're able to offer a lot more superior offering versus some companies that offer threat intelligence, and it's a little bit of all of it, and oftentimes it's just so much data and you don't necessarily even know how to integrate it into your organization. It's like, well, great, I can read this report, but now what do I do? Yeah. So, but yeah, long story short, vulnerability aggregation, it's basically something I've specialized in for a long time.

For fun, I have debated with people that there are less than 10 people in the world that can call themselves an expert on vulnerability data databases because there are so many more nuances around them than people realize. I'm actually, the next time I do a presentation, it's probably going to be on that topic, that they're not simple and show a lot of examples of what we have to figure out, what we have to do. And now the game is every day I send dozens of mails to researchers and vendors and say, hey, you have an error in your advisory. You didn't clarify this. What about that version?

So I've got a good relationship with a lot of them, but it's exhausting trying to chase down this information that you can argue should have been there in the first place. I'll say on the vendor side, it's not always easy to, in the middle of, you know, finding a vulnerability, to be number one, totally candid. You know, you want to protect your customers, you want to, you know, do it the right way, and maybe, you know, we don't all have the nuance. Constantly the right way to do it. So I appreciate the guidance whenever I hear it.

Uh, let's take it— take a little bit of a left turn. You know, the 303 group you've been a part of for a long time— it's not even a— real quick, it's not a formal group. It actually, um, it started out as a joke because back in the early '90s, a notable charlatan named Carolyn Minnell, uh, she was big on using her words to try to demonize certain people and everything. And, um, she— and I don't think it was necessarily even referencing me, even though we went head-to-head on a lot of issues, um, but she, she called it the 303 Gang or something like that. And so after that, then it became just this ongoing joke in the '90s.

Yeah, I'm part of 303. Yo, represent, you know. Um, and then eventually it just kind of stuck that 303 is this loose group of mostly security people. Earlier on, yeah, it was the loose group of hacker groups because we had a few back then. And then it was, oh, well, you're kind of into security or you're into this, which is kind of a fringe topic we love to talk about.

And yeah, now it's just a big mix of people. There's no membership. You know, if you're into security and you want to join the mailing list, cool. Sometimes we talk about serious stuff, usually we don't. We are well known for inappropriate remarks across the board.

But it is also one of those that it's a great resource in that, oh hey, I just left, you know, my company, I'm looking for a job. Boom, you might have 3 or 4 links to open jobs where someone already knows you, can vouch for you, get you in the process. Other times it's Hey, I'm having a hell of a time trying to figure out this software, and someone will say, yep, I know all about that, let's talk off list. So it's a valuable and great resource. And you guys put together a party every year for, for Hacker Summer Camp?

Who? Well, yeah, for— and it's not me, I, I haven't been to DEF CON in a few years, but when I went, I would just volunteer. Uh, at DEF CON, it was centered around SkyTalk, Talks, which is kind of an alternate track. It's not recorded. Um, it's a little more kind of old school and freestyle that we want your weird fringe topics.

We want the ones that DEF CON said that's kind of cool but not main stage material. Okay. Um, and after Sky Talks, yeah, on I think it was Saturday night would be the 303 party, and we would usually have some ridiculous posting about what it took to get in the party, and you had to know this and have this handshake or this challenge coin or whatever. And usually it was more or less, hey, he's your friend, come on in. Yeah, hey, Robb's at the door, let him in, I know him, you know.

Um, and yeah, it was just a way for us to kind of, uh, like many of the, the parties there, time to unwind, you know. Uh, it is a summer con, it is supposed to be fun and everything, but if you actually go and you stand in lines and you go to the talks, and then in between it you're talking business with all the people you haven't seen for a year. It's a stressful, intense, now week-long thing. And yeah, more and more of us, we kind of dread the idea of DEF CON. It's like, shit, now it's 8 days of stuff.

I don't want to be there for 8 days. A long time in Vegas. Yeah, because oftentimes you're up real early, you end up staying up until 3, and it's like, crap, now I gotta go catch talk at 9 because my company wants me to. Um, so yeah, it's, uh, yeah, that was basically the idea of the party, is yet another one where people can unwind. Yeah.

Another thing that I think you do, aren't you on one of the CFP review boards out there? Um, I've been on several. Uh, the one that I spend the most time is DEF CON. Uh, I'm one of, I think there was 25 reviewers this year. Yeah, we had 534 submissions, uh, which was just over half of what Black Hat got.

They topped 1,000. Yeah, um, 534 for how many slots? I don't even remember how many tracks or slots. Part of it is that when they submit, we have the option of saying we don't think it's main stage material, but maybe it's good for the 101 track, which is actually getting a huge room this year, which is great. The guy that runs that, he has put together a great program And there's a lot of people that show up that are kind of new to security or that atmosphere, and they have found the 101 track to be incredibly helpful.

One of the criteria that I put forward in my reviewing is that, hey, that might be a fascinating talk, but will someone walk out of the room and be able to use anything that you told them? The 101 track almost across the board is like that. It's all very helpful. It's immediately impactful. Not to say that we don't accept some of those, you know, weird fun talks.

We love those as much as anyone. But on the CFP team, there was only, I think, 4, maybe 5 of us that actually reviewed close to 100% of the talks. And it is an intensive, time-intensive process because the talks start trickling in in February and And we tell everyone, submit early, submit early. And I'll get to that in a second, but the very last day of CFP, I think we got 105, 110. It's always that way.

Right, and then we're up against our deadline. And I, as soon as I can find time, I plan to write a blog about this year, because this is the first year that we actually maintained statistics. You know, I can tell you how many talks, how many were accepted, rejected. I can tell you how many women submitted versus men. I can tell you based on our kind of loose terminology, how many were around phones versus computers versus IoT versus SCADA.

Overall count of how many are red talks versus blue talks. What's your take, red versus blue, offensive versus defensive? I got out of the red game for my own reasons. It's absolutely helpful. It's great, but it is really overshadowed and taken away, I think, from the industry is that, hey, it's great that you can break in, and we keep seeing this with data breaches, a lot of people can break in.

How about you use that big hacker brain of yours to help with securing stuff? Yes, we do need people showing that stuff can be broken. We need to push the vendors to fix it, absolutely. But in the, the big picture, that only goes so far. We know that vulnerabilities aren't going to stop tomorrow or the next day.

And I don't think machine learning or AI or anything else is going to magically solve it either. You know, humans will be involved to some degree. So if we know that vulnerabilities are going to keep happening, and we know that the numbers are going up, and the data breaches are going up, and the instances of malware are going up, and everything is increasing, Something I tell everyone in our industry, we need to step back a second and say, wait a minute, we're failing our customers to some degree.

It's a harsh reality. There are companies that do amazing work. They put forward great people, great services. But once again, it's— they're humans. There's going to be mistakes along the way.

A company won't integrate your solution, properly, or maybe the CEO is going to disable it because it's inconvenient and he gets popped. You know, it's going to happen. But largely, we need stronger authentication, more identity management, we need better patching systems.

Back in the day, it was, oh, we can install the patch and the box crashes, no biggie. It's not a critical one. These days, no, it's crap. We have to install today with Microsoft, I think it was about 50 new vulnerabilities. Well, now every company in the world is trying to figure out, can we safely install these patches?

Or do we have to do it in our, you know, test network? How long can you let it sit in the test network before you install it on live? Because we also know that those same vulnerabilities take less than 24 hours to be reversed. And there's a a lot of effort, you know, developing technology to do precisely that. So the, the whole race on patching has become very weird over the years, and we just need better solutions.

Well, I— we're over time here. Uh, give you a chance to— any last comments, anything you want to share with the community? Um, I think one thing is, uh, check your mental health. And this is for everyone, is just make sure that you're not burning out, that you're still just as passionate today as you were 10 years ago, 20 years ago, or whatever. Take a day off.

I say this as someone who has worked 80 to 100 hours a week pretty much my entire life, but I've learned now, nope, Sundays are go hang out with the squirrels and the birds and the raccoons. And, you know, but just make sure that we're living a healthy lifestyle, especially mentally. It's really hard, right, seeing the same problem for 20 years, 25 years, that, right, we haven't solved the main problems yet. We still don't have great inventory of our assets. We're not good at just all of these basics.

We're bad. It is hard not to get discouraged. And so there's, there's actually a term around that, and it's well known in medical circles, but even as rehabilitation educators of wildlife, it's called compassion fatigue. Um, that after doing so much good work, you still see the animals come in that have to be euthanized. And when you see that one too many times, it takes an incredible toll on you.

And with security, it's not compassion fatigue, but at some point there is some kind of fatigue that sets in that we're not— what are we fixing? You know, we're still having all the same problems we did 20 years ago. And I guess the other big thing I would say is that a lot of the solutions that are being offered today, they're not doing a lot. We still haven't learned or mastered or implemented the basics. You know, I think that we need to really go back to our roots and say, let's go to the old model.

Because another fun thing is like, with vulnerabilities, I love historical ones. I love digging into the past, multics and all that. So a couple years back, I ended up buying every security book I could find that was published in the '70s. And there are a few of them that if I put it in front of you and I cover that date, you will read it saying, wow, this is all relevant. This is exactly what we need to read.

Yeah. And it's just as relevant now as it was 40-some years ago. And yet a lot of companies still aren't following those basics. So I would say for organizations and individuals, hey, that new blinky box, those shiny lights, that's nice and everything, but are you really solving a fundamental security problem or are you kind of creating a solution to what you put forth— forward as a new problem that really isn't that new? You know, it's just different terminology wrapped around it.

So, well, cool. I appreciate your time. Thanks a lot for this. Absolutely. We can catch up with you in a year or so.

There's a lot more to say that we didn't get through. Oh yeah. So we'll do it again. Happy to do it anytime. Thanks, Brian.

Thanks.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado Equals Security.

Back to all episodes