All episodes

Chris Nickerson

Apple Podcasts Spotify SoundCloud

In this episode:

Chris Nickerson, founder of Lares and BSides, is our feature guest. Plus news from Telsa, SparkFun, eFolder, Fortrust, Optiv, CyberGRX, Red Canary, and a lot more. 

Yes, we do know where you can buy a Colorado = Security thong

The founder of SparkFun has created a robot that's got your back. It's not a very cute robot unfortunately. Also this week, the Colorado = Security podcast is selling out (we hope), we learn that DIA booked an IR training, Telsa is charging up Littleton, eFolder is folding into a competitor, Fortrust is swallowed by a Mountain, Optiv sees its way to a Gartner top 10, Red Canary sings a dirge for perimeter security, and a lot more bad puns.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. We're continually working to improve the show, and appreciate the feedback we get from our listeners. If you discover any audio issues, or have suggestions for our format, let us know.

This week's episode is available on SoundcloudiTunes and the Google Play store. Reach out with any questions or comments to info@colorado-security.com

Feature interview:

Chris Nickerson, founder of Lares and BSides, is our feature guest this week. Alex sat with Chris to learn about Chris's background, hear some of the stories of the early security community in Colorado, and what it's like building a conference and a security consulting company. 

Local security news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events:

View our events page for a full list of upcoming events

If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript12302 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood.

Welcome to Colorado Equals Security. This is the newscast for episode 27, the week of August 7th, 2017. Alex, this is a very important question. Where are you buying your new clothes? Where?

There's this new online boutique that I found. It looks good. What you're wearing looks really good. Yes, indeed. But, you know, strangely enough, the only thing that they sell there is Colorado Equals Security merchandise.

Holy smokes. Colorado Equals Security. That's why it looks so good. Must be. So I guess the news for this week is that we are— have opened up a little store on CafePress.

If you guys want to help us, number one, if you want to look good, if you want to look as good as Alex does right now, you can buy some of the merchandise there and you can help us keep the show going. We haven't brought any sponsors on the show at this point and it wouldn't hurt for us to have a little bit of those costs defrayed. First, Robb, it's impossible for anyone to look as good as me. But that said, they can try by getting some of the merchandise there. We have a wide array of different things.

Alex actually has kind of a funny look right now. He's wearing the onesie and, and the thong and the baseball cap. It's a, it's a pretty good look, and I certainly appreciate that. I do have a sweatshirt for when it gets cold. Yeah.

All right, so, uh, let's get into the news here. DIA just had a, uh, an incident response test in the last couple weeks, right? They did. And this, you know, this is not an information security incident response test. It's an, a, you know, an emergency response test.

Uh, but we wanted to put this in here, I think, from, from my perspective, just to talk about the the different scale of these kind of tests and how important it is in information security to do the same thing as well. They had 600 people participating, you know, quote, injured people in makeup and things on fire. I've never done that as part of my incident response testing. I don't know about you, Robb. Yeah, no, I haven't done that.

But the makeup, I'm sure, really makes it more fun. And, and people love live-action roleplay, right? So there you go. There's a place to do it at work. So when you think of entrepreneurship in the Colorado area, what city comes to mind?

You know, the one that comes to mind first is definitely Castle Rock. Castle Rock, Colorado. Absolutely. So the Castle Rock, the EcoDevo people, the economic development group down there is looking for startups to pitch them. So we've got a link in the show notes about some of that.

Cool. Yeah, absolutely. It's neat to see the metro area trying to just drive more entrepreneurship. Tesla. I think we all know that Tesla, they make cars and they also make pretty cars.

Yeah. They also own a solar company that makes roof tiles and batteries and other things like that. They opened a showroom in Littleton. You know, they just announced the deliveries of their first Model 3, which is pretty cool. And now they have another showroom in Littleton.

It's— if anybody knows Littleton, it's on Broadway, kind of at Littleton Boulevard, where there used to be a whole bunch of old car dealerships there. So they took over one of those, but good to see them expanding. So if I could get a Model 3, I would absolutely drive over there right now. But my suspicion is it's only a 2 to 3 year wait once you, once you get on the waiting list. I think, I think if you're lucky.

Yeah. So next article this week is Spark Funds founder did something really cool at DEF CON last week. He created a robot. It's not a cute little robot BB-8 or R2-D2. It's a, it's a, it's a little basic, basically like a cross that fits over the front of a safe.

But this robot's able to hack a safe, be able to break into a safe, break the combination. And it was a really nice safe and able to do it in less than 30 minutes. Yeah, I thought that was pretty cool. It looked like sort of in true machine learning style. They had to, you know, feed it some data first and let it try things out.

And then once it did that, then it was sort of primed and ready to break the safe. But SparkFun is one of the local Colorado companies, and it was the founder doing that. They're not necessarily a security company. It's just cool that he's been working on that on the side. Kind of a skunk's work thing for him.

Robots and security are cool. eFolder, we've talked about on the show before, is merging with the California company Axient. Josh Foltz, who we know runs a security program over there, and I think, Robb, you reached out to him and he gave some good feedback, said it's good news and really a good thing for growth. The CEO of eFolder will be running the joint company, so it's good for us as a Colorado-headquartered company to be growing and having that additional additional personnel and reach. And, you know, what they basically do, business storage, you know, kind of think of them as a Box or Dropbox type of a competitor with, you know, their own niche that I don't know.

I don't know a ton about. Yeah, not a security company directly, but good to see the security team over there thriving. But speaking of local companies, Fortrust, which is one of the large data center companies here in Denver, is being acquired by Iron Mountain. Good for them. Maybe not good for consumers.

Who knows? I think we've seen a lot of consolidation. In the sort of small data center provider space. Time Warner Telecom got bought, Viawest got bought, now Fortrust is purchased. Yeah, it's kind of on the fence about it.

If you don't have these kind of exits, people are not incentivized to create businesses. However, it's a bummer to lose those local companies, and they were a nice local company here. Yeah, exactly. Optiv, they were ranked top 10 global security consulting provider in revenue by Gartner. Um, so I think what that means is Optiv is big.

Yeah, and you know, I, I think one of the points that they've had for the last several years is they want to go from just being a product reseller to being a services company. And this is a— I don't know, it's a milestone showing that they've moved, they've moved up the stack in terms of doing the services and consulting. And they, they've really been trying to get that mix to be less product and more services. So, you know, good for them. They've made some progress here, it looks like.

Yeah, for sure. CyberGRX has made some hires. I was looking through the folks that they hired, 3 new leaders, including some folks from some pretty big companies. Yeah, Brian Gale joined the company as Chief Product Officer. And Brian was over— it was at Palo Alto.

I'll look it up here in just a second. McAfee. So they got the guy from— there was another guy from Justin Bryant. Silence. So, so Brian Gale was from Silence.

Oh, I'm sorry. Which, that was the surprising one to me, is to get a guy from, you know, Silence, which has been growing very quickly and, right, it became a unicorn a couple years ago, uh, to get him to come over to CyberGRX. I think that's a good, a good sign for the, the folks here at CyberGRX. Uh, yeah, good for them. Glad to see that they're growing.

So anyway, they hired the new product officer, they hired a new development leader, and they hired a marketing strategist. So Uh, you know, 3 new big hires as they're expanding and growing. Um, and finally on the news list, uh, Red Canary had a blog post this week, um, about— I think they're doing a series of security mistakes, and this one was about focusing on the perimeter. Yeah, um, nothing earth-shattering in there, but it was just, you know, a good reminder and, and some good information in the blog post. You know, if you just, if you just take the trend, right, a sampling of what's written out there, you can see where the industry is going.

And this is one more thing kind of showing us the industry is going away from focusing on that perimeter. And I think that's a really good thing. Definitely. The Women in Security meeting is happening in September. We've talked about the last 2.

The 3rd one's coming up in September the 14th. We got a note from the leader of that group, Sarah Avery, asking us to let folks know. Number one, of course, if you're a woman interested in security or involved in security, please sign up. But she also encouraged any recruiters or hiring managers out there to come, as there's a lot of entry-level or recent graduate or career shifters who come to these meetings looking to get their career going, and it's a good place for you to look for candidates. Definitely.

Also, as we've mentioned in prior weeks, the CISO of the Year Award as part of the, the CTA's APEX Awards is available for nominations still. So go out there and nominate somebody. If you know a CISO who's done good things, go ahead and put a nomination in for them. Yeah, I know we got a few nominations last week. We only have one more week though.

This is— I think this is the last time it's— we'll be mentioning it to you. So take this chance. It's your last reminder. Go do it now. Get the nominations going.

We'd like to have a good showing on there. So let's move on to events. As always, you should take a look at the website and look at our event calendar. We've got events through nearly the end of the year out there. Obviously more in the short term, but definitely plan your schedules off the event calendar.

Yeah. Last week, or maybe it was 2 weeks ago, we had zero events. Over the course of a week. And now you're going to see it's going to pick up a lot this week. Yeah, starting on the 7th, uh, the DENSEC is having their, their meeting in the south in the evening.

I think it's 7 to 9 o'clock. ISSA Denver is having their August meetings on the 8th and 9th. On the 10th, SecureSet has their expert series with Colin Hobby talking about Miranda and open source. Uh, the NCC is doing their cybersecurity oversight training Colorado Springs on the 10th. This is the, the board-level training, so trying to educate people who are on boards about cybersecurity.

And the next day on the 11th, SecureSet has their open house for their Colorado Springs event— or their Colorado Springs location, excuse me. The ISSA Financial Services Special Interest Group is having their meeting on the 16th of August, and that's going to be downtown at IMA Financial. It looks like it's in the evening versus the half-day format this time. Yeah, and it's on cyber insurance, so that should be interesting. SecureSet on the 17th has a cybersecurity career trends with Sean Owen, the CEO of Salt Lending.

And then finally, also on the 17th, uh, Densec is doing their North meetup. Yep. Uh, and so let's go ahead and jump over to jobs. The first job, kind of interesting, I don't know where you found this one, but Google is hiring a security operations engineer, uh, here in town. Yeah, and that's for working on their, uh, the Google Cloud, uh, platform.

So that could be pretty cool. Uh, De Novo Ventures, they are looking for a director of information security. So if you're looking to run a security program, that'd be an opportunity. Yeah, you know what, I looked at that position. It looks like De Novo does security services.

So I don't know what the mix is, if this is internal building a program, if it's external working with customers. Probably it's a mix based on, you know, the kind of company you're talking about. Yeah, I don't, I don't know the mix either, but they definitely did mention some internal security. SecureWorks is hiring a managed security services consultant. I didn't know SecureWorks had folks here in Denver.

Yeah, you know, and there were actually a couple SecureWorks posts this week, so I don't know if they're just growing their staff in town or what the story is, but it looks like they're hiring a few people. Well, if you, if you're at SecureWorks, reach out to us. I'd like to know what you guys are doing here in town. IHS Markit, they are looking for an enterprise risk management senior manager. That's pretty cool.

IHS Markit was a recent merger, I think acquisition, IHS, which has been a traditional Denver company and market, who I think is Germany. It's definitely from Europe somewhere.

Trustech is hiring a senior network security engineer. So you must be really old to apply for that one. Cognizant, they are looking for an associate director of corporate security in GRC. So you and I talked about this one off the recording last week. So what I'll tell everyone else what I said, this is a position that I personally would be pretty interested in if I didn't have a great job.

I think working for Matt Shufeld, at that company that's growing and getting to do some interesting stuff. It's a good opportunity. Recommend anyone who's either already been doing GRC or, you know, looking to make that change into there might wanna look at this position. Ping Identity, we're hiring. We actually are hiring 2 positions here in Denver.

We have a security compliance analyst, and we're also hiring a junior product security engineer. So if you have experience either with controls or auditing Or if you have Java development experience and interested in getting into security, those would be good positions for you to apply to. Ball Aerospace has a couple of positions. They are looking for a cybersecurity specialist, entry level, and they are also looking for a cybersecurity operations lead. And we got a note from Dan Koller up there about these positions and sort of a primer on Ball and the complexities of the different groups in security up there.

Uh, the last position this week was actually sent to us by Travis Shack. If you know Travis a little bit— I do. Travis leads the security program at WellTalk, and he formerly was the CISO for the state of Colorado, I think, you know, going back 3 CISOs ago. So the position they're hiring there at WellTalk is as a business security liaison. Honestly, I did not know WellTalk, so he sent over a little description of the company.

It was recently named to Forbes Cloud 100 list. They do, you know, consumer health enterprise SaaS work, basically. Sounds pretty cool. Yeah. And so the position is going to be working in between security and the business.

So pretty good opportunity there to get involved. And that's all the jobs that we have for this week. So interview this week, you sat down with Chris Nickerson. And what do you guys talk about? What do we have to look forward to?

We talked about a number of things. You know, Chris is an interesting guy. Uh, I think that it was, it was fairly tame in Chris Nickerson standards, but, you know, talked about his past and, you know, things that he's seeing as a, as a security tester and evolutions, how that's going. I think it's a good interview. People will like it.

Uh, the audio was not great on this one as you were in an echoey conference room, so we will do our best to clean it up, but I think it's worth listening to and enjoy the interview. Are we going to have the explicit tag thrown on our podcast after this? I don't think so. I think that there, there may, maybe one or two adult words. So if your kids are in the car, you know, maybe pause this for later.

But I don't think we're gonna get explicit. So, all right, well, we'll talk to you guys next week. Awesome. Thanks, Robb.

Hi, this is Merlin Namath, Director of Security at Red Robin. Welcome to Colorado Equals Security, for Colorado security professionals by Colorado security people.

All right, this is Alex Wood. I am here with Chris Nickerson. Chris, how's it going? The famous, infamous Chris Nickerson. Infamous.

Infamous. Famous inside of my own bathroom. Yeah, so I'm sure for those of you who are listening, if you have been around Colorado for a while, you've heard Chris's name. Pen tester, raconteur, rabble-rouser, troublemaker. Um, I guess, Chris, let's start with, uh, why don't you tell folks about who you are, uh, for those that don't know you?

Sure. Uh, how you got into this industry and, and what it is you're doing today. Yeah. Um, well, I'm Chris. Um, I've been doing security type things pretty much all my life since I was a little kid trying to break out of my cradle all the way out into turning it into a profession.

I've been here at a company called Laris that I started 9 years ago. I have a partner that I started it with, and we've been all out of business and opened another office in Atlanta and now moving on to some, some resources offices up in Canada because my wife is Canadian and man, that'll help my passport. Just don't tell anybody right now. Maybe I'll tell everybody. But yeah, so that's kind of the personal me.

I've been in the security industry for ages now. I started really my first security job when I was young working at really annoying people on American Online, and through that started to meet some of the admins who wanted to see some of the ways that we were building tools and some of the ways that we were finding that we could kick people offline and stuff of that nature. So instead of having the kind of adversarial relationship where they're like, oh damn hackers who are annoying people and beating up the system, they were really cool and were like, hey, can you show us how you do these things and we'll give you free accounts. And since in order for me to get on a computer, I had to— well, first I used to be able to just walk into the room, but then after my stepdad realized that I was using his computer, which was, you know, some old IBM giant green screener that eventually turned into like the new hotness, which was some $10,000 thing that was at the house with he was like a manager of a big insurance company. He started realizing that I was like using this thing, so he came home and caught me one day.

And then from there, they started locking the door, so I had to learn how to pick locks. And that worked out pretty fun. So I've been practicing that for quite a long time. Once I learned how to pick locks, then I had to figure out how was I going to get a modem the thing because they didn't have a modem. They were like, you know, he was using it as like a word processor.

$10,000 word processor. Yeah, yeah, right. And that was like the— that was the jam. So I figured out through a local 2600 group how I could get, let's call it, access to a modem. Um, and then I had to figure out how I was going to get a phone line to the room that I could use that my parents weren't going to be able to pick up on.

So luckily at the time, my, you know, kind of absentee deadbeat, like, biological father— my real father's my stepfather— um, my, my, uh, my dad's genetic dad had a construction company. Uh, so I found a way to kind of weasel myself down to where he had the equipment yard and borrowed an auger so that I could use the auger while my parents were away and I was staying at a friend's house to trench all the way from the green box that was out in the woods up the hill and into where the house was, and then talked to a bunch of people on a bulletin board about how I could get it underneath the siding. So I learned how to replace siding and brought it up to the second floor of the house so that I could bring this phone line modem in and then hide it because they had those crappy old, like, uh, the wood panel— what's that wood paneling called? You know what I mean? Yeah, yeah.

Every room, like, looked like it was all wood, right? Um, so I found, I found a scrap piece of that and put it in there. So I made like a little false wall underneath that nobody could see, and I hid this modem in it. Uh, so then at night I could go break into the thing once everybody was asleep and go dial up to other BBSs. And then after the BBSs into AOL and messing with them and showing them some of the stuff I was learning and really developing my connection to the community because at that time, especially in the BBSs, it was, you know, there's a pretty high bar to entry.

You had to actually know some things or you had to be willing enough to take everybody's shit for long enough that they would just be like, okay, we're going to let you read this book. And, you know, there weren't all these hacker books and things that you could go touch and see. So you either had to go physically find one of them, which happened to be in, you know, unlocked S&T trucks and stuff like that, that, uh, you know, what are they, white shopping vans? Um, those places you could find books and manuals. You could find them on some of these, uh, you know, different sites that were out in BBSs.

So dial down wait all night, pull down this manual, and then, you know, hang out in a room and read for hours and hours and hours to try and figure out, you know, what is DZVIB, and try and learn the basics of how networking worked. And so I think that was really my start. And then I kind of moved on. I went to college for a second, and that we didn't really Didn't get along with that. Yeah, it was a bad relationship for both of us.

Um, so, so, uh, I, I left there, uh, decided I could go to the military. Uh, that wasn't necessarily the best fit for me either, just with the, the way that I wanted to operate in the world and what they wanted to do at the time. Now I'm, I'm super proud of them and would love to be back in, because they're doing the things that I really wanted to do back then. Like, cool, like China's messing with us, let's go break into China and get at all that shit. Let's go break in right now.

And they're like, no, you can't really, that's not like how the operations teams and things work. And I'm like, but it can be, like all you have to do is give me a computer and I guarantee you I can go get your shit with this 5-people cannon. And they're like, yeah, but we don't really do that. But now they have huge capabilities. So it's a changing landscape, you know.

Then worked in the legal field in the beginning because I was— I wanted to be back in the IT game somehow and learn more about stuff. So I was a trial site coordinator for a big giant law firm. So I was setting up, you know, T1s and like all computers for the office, doing all that stuff. Perfectly secure, I'm sure, too. Yeah.

You know, 4 months, right? But, uh, I actually found this dude that was breaking into the office to try and steal stuff because I was in the office so much. Because I, I was a kid who didn't have any money, so I didn't have like computers. So in order for me to touch stuff, I had a job where a place that had computers, and I would just go mess with them all the time because like I can't afford any of that stuff. So like I was in there banging away all night like seeing seeing what I could do and like optimizing things, like reading all this stuff.

And I ended up finding this dude who was breaking in from the opposing team who was trying to get information on his lawsuits. So now my mentor at the time, Arch, was, uh, was talking to me and he's like, you know, you know, you got— you obviously have a knack and eye for this type of stuff, you know, why don't you try helping, helping us set up our first firewall? They, they didn't have one. Didn't even have an internet connection. So I set up a Sidewinder firewall and it was freaking amazing.

And, you know, I got my, my like trial by fire BSD and it was just, it was wild. And, uh, and then shortly after that I became the head of network engineering because both of the network engineers got into a fistfight in the office at the same day. And being the NP badass that my boss was, just drug both of them out and was like, all right, you guys are out. And then later on the next day, the core switch died. And so he calls me up and he's like, hey man, you're probably the only one I can go to.

Can I talk to you for a second? It's like midnight. I was like, yeah, what's up? And he's like, so we got this core switch down. I was like, okay.

He's like, do you think you could fix it? And I was like, do you have manuals? He's like, yeah. And I was like, hell yeah, I can fix it. So you go over there and bang this thing out all night, find out problems, I get promoted, do some things, and then, you know, start going through the certification path.

Moved over from there to start working at Sprint as their Chief Security Architect, and then did all this really cool stuff like, you know, saw deploying 3G and, you know, lighting up data for all the cell phones in the world, and, you know, being a carrier traffic provider where you could like, you know, see the entire internet, not just a piece of it, like a big pipe with everything going through it. And learned tons there working in security and compliance. And then came out here to Colorado. Now I was shaking my head because I've always told people, oh yeah, I've been here like 10 years, but I feel like I've been telling people that for like 10 years. Yeah.

So I looked yesterday, I finally got to the point where I was gonna look and And I've been here almost 16 years. So I think given that I leave— I left Connecticut when I was 17— that I am now almost a year away from saying I'm from here. So as soon as I can break that 17-year mark, I'm gonna just say I'm from here. It's the longest place I've ever lived. Yeah, this year, actually this month, is 20 years for me being here.

So really, I've been here longer than I've been anywhere else. Yeah, that's— man, now you're from here. Yeah. Um, I can't call myself a native because, you know, you say you're from here. Yeah, definitely.

But the, uh, you know how picky people— yeah, you know how picky people are about that. Um, one interjection. Yeah, man, try not to bang the table. The mic will pick it up. Sorry.

That's right. Um, so keep going. Yeah, sorry. Um, so moved out here to Colorado to work at KPMG, which was interesting being the fact that I'm a little bit more of a hacker type than I am a suitcase auditor. So that was an interesting experience, probably for more off the record than on the record, but let's just say it was oil and water when they wanted to do things Uh, and they wanted to check boxes, and my job my whole life has been a professional box unchecker.

Yeah. Um, moved from that to Breck for a little while to ski bum and try and resort what was going on in my life. That was amazing. And got to ski a whole bunch and enjoy the beautiful, beautiful scenery up there and all the cool people. And then came back down and started working for a big distributor called Alternative Technology that then got bought by Arrow, which is a big, super ultra big company.

And there I was doing security services, so ethical hacking, pen testing, showing people where holes were, vulnerabilities, stuff like that. And that was where we got picked up when it was 2008 or '09, somewhere in there, when some people in Hollywood had heard that there was a group of guys in Colorado that were doing this thing called red team testing, and they didn't know what that was, and it sounded weird, and they called us and talked to us and said, hey, we want to go out to DEF CON with you because we hear that it's just this crazy hacker party and you guys have been going there forever, and we want to come see what it's all about and like, you know, be in the hacker underworld. And you know, it's not, it's just a bunch of hackers hanging out. People drinking. Yeah, drinking against being smelly and trading exploits and stuff.

But we talked to them and we told them, yeah, we also do a little bit more hardcore exercises beyond the pen testing, beyond the phone stuff, beyond the risk assessment compliance, beyond all those different types of services that we give businesses to kind of get them to a point so they know how vulnerable they are and teach them how to fix it. We also do this red teaming thing where we take pretty much any discipline of any type in any scope, if that's physical, if it's electronic, if it's social, you know, manipulating people, dressing up in crazy costumes, forging badges, doing weird James Bond stuff, you know, rappelling in from ceilings, you know, hot-rodding alarm systems, hacking stuff, whatever. And they're like, well, this sounds really, really cool. We want to watch you guys do it. Do it.

So we brought them along on a job and they're all geeked out and they decided that they're gonna make a TV show about us. So they, uh, I said, well, none of my clients want to be on TV. Like, they're, like, they're doing it in-house so that we can figure out where our weaknesses are and train. I don't want somebody to see me, you know, naked in the shower when I haven't, like, made myself look good. I'll just look gross, you know?

Like, I don't want any of that. And, um, so they, they ended up getting some Hollywood-style clients. They got this big car dealership in Beverly Hills, uh, and they got this jewelry store in Beverly Hills that made like bling jewelry for rappers and stuff. Like big, you know, like 50-carat diamond, what's up, I'm Crump kind of plate, dollar sign. Yeah, crazy dollar sign Jesus face, you know, emerald eyes and all those other stuff.

Stuff. And, uh, and, and so they're like, okay, do you think you guys can break into these places? And now to us, being used to breaking into, you know, the Fortune 500, where we have to actually do some pretty complicated things because they do have money and they do secure things in like a really specific way, or at least some of them try to, uh, these guys were like, you know, it was like a car dealership. I'm like, yeah, sure. I mean, do you want to go now?

Right. We'll do it right now. And they're like, well, no, I mean, you gotta make it cool for TV or whatever. So they named this TV show Tiger Team, and, uh, and we went out, we broke into a car dealership, we showed them we could just steal everything, uh, broke into this, uh, this jewelry store, uh, showed that we could get into the safes and like, you know, did all the social engineering stuff to show them like how we could extract information and do all these other things. And, um, And then Hollywood people being Hollywood people, uh, completely screwed us.

So we had— it was super fun. It was fun-ish. Being in the public limelight is kind of shitty. Yeah. Um, but, but it was cool to like do it and to like show people some of the stuff we were doing.

So like my mom could finally see. She's like, oh, you sell cars? That's what you do. That's not what I do. I help business this is.

And she's like, I saw you, I saw you stole car money, you know. Um, but, but we get, we get to the point where the thing's gonna air, and in the second, in the second episode, we're driving this big, uh, Expedition. And as I'm going, going through the turnstile to get out of the hotel, this guy's giving me shit about like a parking card. And I'm like, I'm staying in the hotel. And he's like, but I need the card.

I'm like, I don't have the card, charge me with the whatever it is, I'm late. And he's like, I need the card. And I'm like, so, so am I gonna have to like blow through the gate, right? And he's like, sir, can you just find the card? So I'm, I'm, you know, pissed, right?

And so I throw the car in this big Expedition, you know, it's a floor shift type thing, right? I throw it in park and I swing the door open and the door goes open between like the concrete turnstile and like the badge reader, right? Well, when I threw it in park because I was pissed, it hit park and then bumped back one into reverse. So I get out of the car and the car is now idled in reverse moving backwards and the door's going just bending the wrong way. And all the jerks in the car are just laughing at you, right?

You're not helping, you're just laughing. And so now I'm like, oh my God, go to the back, find the key, throw, throw the stupid ticket at him. Like pull the door shut and I'm like driving down the road like with my arm over the door to keep the door closed because it's now bent all hell. Um, moral of the story of all of this telling you is that once the first season aired, I got this note from Hertz and it was like sequestering to go to court. And I was like, let me go to court.

And they're like, well, you damaged one of our cars and failed to pay for it, and then you, you left the scene of a crime. I was like, no, it's a scene of a crime. They're like, well, when you, when you handed the keys over, which I did, they're like, you just left. I was like, yeah, I left because I had a flight to catch. And they're like, but you had to fill out forms.

I was like, I didn't rent the car, right? And so this goes on and on. I kind of like ignored it for a little bit. Then I get another— a sheriff shows up at my house with a warrant, and I'm like, all right, this is now getting out of control. So I shoot the warrant thing and everybody else to the TV guys.

TV guys go, oh, I don't know anything about this. And I'm like, hmm, okay. So then I shoot it to the network, which at the time was, uh, TruTV. So I shoot it to TruTV and they're like, well, we don't know anything about this, we'll check into Don't worry, we've got you. They're like super cool, right?

They're like, right, you're the talent, we've got you totally covered, it's all good, it's Hollywood, baby, you know, blah blah blah. I get a call 4 days later from the guys at TruTV and they say, hey, I wanted you to hear it from us, we have to cancel the show. And I was like, what do we do? And he goes, I'm gonna tell you the straight story, but you can't say anything to anyone, which is now I can say it on a podcast. Ha!

Um, he goes, so we saw all the insurance claim stuff and we saw that you got hit with all that. And when we went back to the production company and asked them how come they haven't dealt with it, they made up some story about their insurance provider and whatever else. So it kind of got us worried about the insurance. So we said, hey, provide us copies of your set insurance policies because they went back to the network after we did the first episode and said, hey, the stuff these guys is doing is so risky and could cost us so much money that we have to get more insurance. And we're going to have to insure it for like $100 million because these guys are breaking into a safe.

And if we break the safe or if one of the diamonds falls out or something like that, we're screwed. So we have to get this big thing of insurance. Network approved it, write the checks, right? Check was for like $100-something thousand for like $100 million in insurance and like set and all sorts of shit. Come to find out that because of this car episode and they're now insurance off it on the whatever it was, Stage 5 or whatever idiot Russell Youth asshole productions.

That fucking dirtbag. Um, he just pocketed the money from the insurance, never got any of it. And then when the network came back to be like, yo, put it on the insurance, he sent them fake documents saying that he had the insurance and then was gonna try and pay it out of pocket. So then he tried to hustle with Hertz to pay it out of pocket, and they're like, no. Oh, we want an insurance company.

He's like, well, no, I'm gonna pay for it, just let me know exactly what the bill is. They're like, no insurance company. And now that the network had gotten involved, all this thing fucking fell apart. And they were like, look, we want to continue this thing, it's cool, like what you guys are doing is really neat, but we can't use that production company. And since you're locked in with that production company, we gotta shift.

Oh man, that sucks. So, so that was my My, my, uh, I guess my second welcome to Colorado— my first welcome to Colorado was the day that I moved here. Um, I had a moving truck and I parked it over off of, uh, what's the big diagonal road that hits— so 25, you know where Micro Center is? Yeah. Um, and then there's that road that's a peak right over there by the Cherokee Reservoir or whatever.

Oh, like, um, anyway, yeah, whatever that giant road is that goes from down where Piper Center is diagonal all the way up towards the city, right? Um, so Parker. Parker, yes. So it was on— it was at a storage place on Parker Road, um, that, that had UPS trucks, and I had the biggest UPS truck you could get, a big, like, ultra big one. And, uh, I had gotten a divorce and had all my stuff in and stopped here because I didn't know where I was going to live, and I was thinking about just being a ski bum for a little bit.

Um, this is like pre-KPG job. Uh, I parked the thing, and then that night I went out and met some super cool people out at a bar, and they were like, hey, if you don't have— it was like a guy and his, his wife— they're like, hey, if you don't have a hotel room, like, you're welcome to stay in our guest room. And I was like, thanks, man. But like, it wasn't sketchy, they were super cool. And so I wake up the next morning 9 o'clock with a phone call from the UPS company that says, hey, your truck's been stolen.

So my first bump in the Colorado was taking all my shit. I, I could consider that my cleansing. Yes, and then starting fresh. My, my, my second welcome to the industry was, was, uh, was this, you know, TV kerfuffle. But it was hilarious.

And then, um, you know, from working there and doing that and then started this business about 9 years ago. So I guess that's the 30-minute version of it. It's where it came from. Only like 20, no big deal. Um, so you guys do a lot of pen testing, a lot of red team, a lot of, uh, you know, application, all that kind of stuff.

Uh, how have you seen that change over the time where you've been doing this? Um, you know, I Back, you know, as long as I've been around, I would see pen tests happen and be, I'd say, simple. You know, people would, uh, would scan something, they'd maybe show that you could exploit something, maybe not. They, they'd say, oh, you know, here's some stuff we found, right? Thanks, see you later.

Um, how have you seen that change? Um, or have you seen it change? Yeah, it's changed a ton. I, I can only I think, you know, if I was to explain it to my mom, it's kind of like the people who go to spas and get massages. I mean, like a real spa, not one of those.

I see your face.

So you go the first time, somebody kind of does the light touch thing, and they still find areas that hurt, but they're really not even getting in there and working on anything. They're just kind of like getting you used to the fact that you're getting a massage. And then the more and more experienced spa-goers want people who are like, I want you to reach through my skin and grab my bones and pull them into place so that I can get a distinct benefit versus like, oh, I had a nice relaxing day. I think our industry has now started to evolve to allow people to go deeper because they see that there's the ability to get some value there. Before, it was like, I just want you to scratch the surface because I'm afraid you're going to break everything and I have to keep making money today.

Now they're starting to go, I spent all this money on all these security controls and all these blinky lights. I want to see if this damn thing works. So like, put down some effort and let me see if, you know, if I have a shield, prove to me that the shield works, don't just hang it on the wall. And so people are getting to a point where they're allowing a larger scope, they're allowing a larger depth of testing, and they're able to be comfortable with more than just scratching the surface because they truly want to get value from it. They don't just want to be scared.

They don't want to just— I mean, some of them do, but they don't just want to use it as like a battering ram for budget. Some people truly want to see do my defenses work? And if they do work, how well do they work? And you can't do that without really going deep. So how does that work?

What are the things that you guys are doing or other people are doing to instantiate that? What sort of testing are you doing? Or, you know, so there's various different types of testing. I think you start off on the edge of general vulnerability assessment penetration testing. It's commonly misused because there's such a shortage of skill set in the industry that you get these amateurs who want to say they're doing expert work so they can get the expert price, right?

Um, and, and pen testing not only requires you to find vulnerabilities and to be able to exploit them, but it requires you to understand logic, to understand how the environment works, to use the environment against itself, right? Like, if I have chat in my internal company and I have a link server, you know, why am I not— and I can authenticate to that from the outside— why am I not trying to authenticate with that with the crappy passwords that everybody uses of Rockies1, Password1, Welcome1, Passwordbang, those types, you know, Summer, Winter, Fall. With just combinations of those passwords alone, you'll get into any environment in the Fortune 100, and I would I would bet a paycheck on it that— because in the 20 years almost that I've been doing this, I haven't ever had a point where I wasn't able to get in that way. So why not go after some of those things? Show them how you can use the environment against them.

Understand how the web apps work. Understand how the network devices work. Attack the network devices all the way up through the application stack and show multiple different paths to get in. Entry and then pivot those pieces of entry to internal resources that are goal-oriented. So we don't want to just say, oh hey, I got domain admin, oh hey, I got, I got this level of access or that level of access.

We want to communicate it to a point where the executives or the other people in other business units that are reading the report say, that's my stuff and you're not supposed to be able to see that. Whether that means finances HR, whether that means the new design of the cool new product that you're putting out there. Those are the things that actually communicate impact more than, you know, here's a shell and you're like, I don't know what the hell to do with it. Like, okay, great, it's a shell, what do you do next? So you have that kind of depth of really looking for impact-based testing to truly connect in a personal sense to the people that are reading it, not just the technical sense.

Because my longstanding belief is that the English word security is a feeling by definition. And if you work with that, then we have to connect to that feeling. And so to me, showing you a bunch of technical gobbledygook doesn't connect to the feeling. Then we look at other types of testing now where we're expanding people who have gotten an understanding that you get to that feeling, get to that goal-oriented point. And with them, we're working on adaptive training.

So we're now treating the defender like a fighter pilot, right? Instead of just going in and shooting all the planes down and going, haha, you can't, you can't stop me, I'm gonna take everything down. Now we're switching it up to say, if the defenders are the fighter pilots and if they're supposed to be the number one defense for what's going to happen to stop people from invading this country on the ground, on the sea, wherever else, right? Those are our eyes, our ears. Those are truly our rapid responders.

What are we going to do to make them more capable and more qualified? So we're trying to now work with that set to say, if I was to release malware rampant in your environment, that would give them a pretty good test, right? Because they would have to deal with that, and then the next time that malware attacked them, they'd be like, oh, I know how to deal with this. You know, I searched Bleeping Computer or whatever. But it would give them that experience.

So what we're trying to do now is we're trying to pivot a lot of those different attack techniques. So we call them, you know, TTPs, tool tactics, you know, programs or tool tactics procedures. And we try and emulate those TTPs across the lifecycle of an attack chain. So if we started at reconnaissance and we ended at exfil, and all the way through that, from delivering payloads to executing them to having exploitation to privilege escalation to lateral movement to, you know, finding, finding data, bunkering, getting external C2, and then moving to a point where we get exfil data. Each one of those pieces of the chain have a ton of different attacks, right?

A ton of different ways that you could exploit, a ton of different ways that you can see to over different ports, over different protocols, technologies, mediums. And what we're doing is we're mapping all of that out, and then we're starting down the path internally in these companies to test everything that we can think of in that piece of the chain. So if it's assessment of recon, right? So can you detect my port scan? Can you detect that I was, you know, doing DNS record pulls?

Can you detect these things? Then I get to the next stage of the chain. Okay, I'm trying to deliver you an exploit. Can I get to you over these protocols? Are these things even open?

Are there abilities for me to just insert it or do I have to authenticate or what like that? Once I get to that stage, then maybe it's exploitation. Here's a myriad of different types of exploitation. And what we find is that as we test all of these different TTPs and we make this sheet that goes from end to finish, we now have a fairly comprehensive set of things that people are used to doing. So the defenders now are being treated like the fighter pilot who goes in and you're like, okay, you know how to fly the airplane and you're proficient.

Every time you come into a new airplane, you have to regain your proficiency hours. So if we get a new tool in, you gotta regain your proficiency hours. Efficiency hours on that tool. Just like if I— if, uh, which I thought was interesting when I studied some of those guys, uh, if you put one thing in the cockpit, one thing, if one button gets added to the cockpit, despite whatever it does, it disqualifies every single pilot that can fly that plane. And that pilot now has to re-simulate all of those different hours all of those different exercises that they were already qualified for just because there's a new button in the plane.

Yeah, right, because, because that button will be effective at some point in their training. So, so we're trying to cheat defenses like that. Anytime you get something new in, you got to resim these things. You have to understand how defenders work and how they operate. And we're using our skills as attackers to be the flight simulator, right?

You want to get in a bad situation, send the guy in the airplane up and cut both of the engines to see if they can land it. That's something they have to really know how to do, not only to save the asset but to save how much training we put into that pilot. But do you want to train the pilot by actually sending them in the air and killing that, or you want to put them in a flight sim and let them do it a million times until they're like, I don't care if you kill the engines and start shooting at me, I'll still land this thing perfectly. And, and so what, what we're pivoting to in some of those teams is really being that simulation resource so that by the time the attacker uses one of these common techniques, they're like, done this a million times, gone. And I think that, that's one of those big things now that as we're starting to see the shift, we're starting to see the people that were afraid of going deep going deeper, and the people that went deep now wanting to prove that they can actually improve their program versus finding things that are Do you find that in all cases that that's being effective, or are there some teams that you're doing this and, and you're coming to the point where it's like, hey, you know, you guys have a personnel problem, or you have, you know, other things like this where you just don't have the resources that you need to be able to do what you want to do?

Yeah, I think part of that is a culture change, right? But with anything, you know, the old trust but verify organisms or whatever. But, but it's also a byproduct of understanding the service now, of like not being afraid of vuln scanning versus wanting somebody to try and go after the crown jewels versus wanting to do simulation. There's different cultures that are associated, associated with that underneath it. And I think to your point, since there's, you know, the negative unemployment rate, right?

There's a million open jobs in security with no one to fill them, right? I think that what they're finding is people really want to get to that point, but they don't have the people to get to that point, and they feel like there's a way to get there through the marketing of all of these vendors that exist that provide security tools. So the vendors look at this this million headcount thing, and they go, imagine how much shit we could sell people if I could take somebody's job description and just put it into a blinky box. And so they do it, they do it over and over and over again. And unfortunately, since there's no one there to simulate the new buttons in the cockpit, we have buttons all over the cockpit, we have no idea what anything does, and we can barely fly the damn plane anymore, right?

Right. But we spent all this money on all these flashy cool buttons. So yeah, I mean, I think it's a byproduct of the skill shortage, but also some of the philosophies, right? Because people are— people try and protect all of the bad and then have a problem because they protect some of the good with that. But if we trained our environments on bad things that we knew were bad, like I'm saying, if I can go in there and simulate bad things, only bad things, then whenever you saw that, all you would be doing is catching bad things.

You would never be catching good things because even if a good thing was doing that, it's a bad process. Right. Right? And so you're changing that paradigm from moving to, you know, it's kind of like the inverse, right? I have a little white speck in a giant black ocean.

But if I want to really do this and figure out how do I find the right black, all I have to do is inverse the color set and find the one little speck.

So speaking of blinky boxes, sort of, um, one thing that I've started to see is people pushing, uh, what they're calling security orchestration and automation. Do you think, do you think that that can help solve those problems? Where, hey, I'm coming in as a tester, I'm doing simulation, um, I— you can see what we did. Hey, now you have this tool or process, or, you know, maybe you have people writing scripts yourself or whatever. Hey, just let's do this and let's automate it so next time I come back you don't even have to do anything, it's already going to find this bad thing, right?

Um, I think there's, there's a couple things in stage right now of automation in orchestration. I think much like a lot of the other programs, they're trying to figure out what their job is in the market, and none of them have a real clear picture yet. They're also trying to find out what their job is in the market at a cost that is relative to replacing a tester.

And so if you say, well, you have— you would need to have 7 hardcore pentesters to be able to orchestrate testing this environment, so I'm gonna charge you $26 per machine to do this, right? They're out of their fucking minds. Like, they're just completely out of their minds, right? Because that's, that's not, it's not how orchestration works at scale anywhere. So I think they're gonna, they're gonna still need to find their way.

I think once they find their Either way, it's going to truly be about what are you doing. Are you testing a methodology or are you testing a card trick? And most of them right now don't have a story where they understand the totality of attack. They just go, oh, well, you just do this and then this and then this and then this, and now I've left artifacts for this thing.

Why? Right, right. Why would I, why would I even want to do that until I say I've tested everything? And then if I tested everything using Bayesian and using Monte Carlo iterations against all of my tests of everything to give you probabilistically what the defenses would respond to, and then be able to automate not only resolution paths but selected defensive capabilities, and then be able to virtually the selected defensive capability to be able to then rerun the orchestration and automation against to see if you've actually improved or not before it even gets to a point where it tells you, yeah, you should do this. It should be wargaming and simulating against itself.

So the work that I'm doing right now with MITRE on the ATT&CK framework and the work that we're now doing with the Unfettered Project on the defensive framework is starting to line out the ability to automate the automation in a way that actually makes sense. So we're using the giant brains that all of those guys have and research scientists to try and figure out, you know, kind of like how you saw the Cyber Grand Challenge maybe, where you had the computers fighting the computers, right? So now we're trying to figure out total attack sets and ways that those total attack sets can be transitioned. And what you really want to be able to get to a point of, of these attack sets have one side of the pane of glass and your defense is the other side of the pane of glass. And then you show me a correlation of what did I actually succeed on and how do I improve at my resolution.

My biggest qualm right now with the defense side, because I've truly fallen way more in love with defense over the years. It's beautiful and elegant, and I truly like it. But the thing that is the hip term is hunting. Yeah. Okay, what are you hunting for?

Something. Right. So bad stuff. Bad stuff. Right.

So So let's say I find bad stuff. How much bad stuff did you find? I found 20 bad stuff. Okay, how well did you hunt? Well, I found 20, right?

So that's good. All right, but what if there was a billion and you only found 20? Should you get fired? Right. But since there's no alternate number and no backstop, there's no way to really qualify these things.

So where orchestration needs to to go, and it's in its infancy, it's trying to get developed, it's very far away from it. And the problem is that most of the orchestration companies don't— they don't have the tie to understand really where they fit. Is they're really building unit testing for a dev process that eventually would be done by a QA analyst. And if you started treating a QA analyst for the whole of your network security, just like you do the QA analyst that makes sure that when I type in Chris and hit send, in my profile it says Chris and not curse. That's what they're building.

But they're still really impressed with like how high-tech it is, make it really, really expensive. And what they need to get down to the point of is all they're doing is unit testing that needs to be orchestration for an operator that's a very low cost because that's going to start to solve the way that we bring people into the industry at a $20,000 or $30,000 salary and then move them up as they start to get the skill, because orchestration will help them get the tools that they need to be effective. And then you can start having defensive tools, which Intel started to do a good job on, of building things like the DXL bus, where you have a universal bus that's on the processor that has its own threading that that's built solely for the purpose of consuming security events and deriving and exploring security events and then taking the security events of my machine and your machine and another machine and being able to shove all of those events into something. Now if we can get to that point where all of those boxes are working together, now I can say my orchestration did this thing, how well did my defenses do, and start to auto-suggest I need to make tweaks tweaks in this level of defense in this particular product— firewall, IDS, host-based rules, all those things— and now start to automate some of the suggesting paths and say, how well is it going to work and how can I optimize myself? And then you have those students running constantly to constantly optimize the environment as the environment shifts and changes.

That's deep. Word. All right, so, uh, pivoting a little bit Uh, early on you mentioned, uh, BBSs and being part of the community. So obviously this is a, a podcast about Colorado and the community here and everything that's going on. Um, I know that you are part of the 303 community.

Uh, I think probably a lot of the people that are listening probably don't know what that is or what it's about. So I wonder if you want to comment on that. A little bit, uh, who it is, what it is, uh, sure, what you do there. Um, I can say it a whole bunch of different ways. They're being, being in security since we started off kind of having to, uh, hide in a corner somewhere because we were talking about like, how do we break this thing?

And people didn't understand that we wanted to not, not just break it, but we wanted to just see what it did. Like, it wasn't about what it does currently, it's about what I can make it do. And having that conversation in the public was really hard, you know? Like, like, how do you pick this lock? And you do that in a bar and people are like, hey, look at it, look at the criminals at the end of the bar, arrest that guy, right?

So, so we kind of had to do it on the DL and, and And so the way most of the scene started was bulletin boards, was making ezines like 2600 and FRAC and those things, or doing electronic versions or paper versions. That started into like 2600 meetings. So there's 2600 meetings of people getting together because you had to kind of find a safe space to talk before people just judged who you were or what your intent was without even knowing. Out of that bred a lot of micro-communities. So there was, you know, the communities of people that maybe came from 2600, the bulletin boards and stuff like that, and wanted to meet in real life.

Because as much as you can get on a screen back then, because we didn't have high internet pipe connections, if I wanted to get a document, there wasn't a Kinko's that I could go to. Or if there was, it was like $40 a page just to Scan stuff, right? Like hack the Kenko's thing, like do that. But, but in order to transfer information, it was sneakerware, you know. If I wanted to get a manual, I had to pick it up from somebody.

So, so you have, you know, each group have cliques, cliques have fallouts. So you have like, you know, 2600, they're like, oh, I'm not gonna go to 2600 meets, those guys are jerks. But there's some other people that aren't jerks, we'll have our own meets. So, you know, like there's 2601, and, you know, just control the other guys. And there's, you know, different groups and factions that split out.

And as those things were splitting out, and as during the bulletin board days, and as that became to like mailing lists, many different mailing lists got started. So there was, you know, gangs, if you will, right? Like LOD, MOD. There's research-ish groups who were pretty much just a bunch of people who did cool shit together, like Loft and those guys who ended up going to Congress, you know, back in the '90s, right? And fundamentally reshaping all of security because of these little micro-communities.

And here in Colorado, there's, you know, a very, very old micro-community called 303, you know, obviously because of our area code, that was, you know, found it for people to really have a way to get together in real life and chat about these things. There's tons of other ones. There's a DC303, which is kind of an offshoot of the people who go to DEF CON who are in this area. So it's like, hey, we're in the same club, we both go to the same conference together, like we should talk year-round because we live in the same city. You have the different certification-based communities, right?

The ISACA, the ISSA, You know, you have physical security communities, you have all of the different hackerspaces that exist. In Denver, there's— I haven't looked up recently, but there's 3 or 4 different hackerspaces, which are literally like a go there, knock on the door, and be like, hey, I want to learn how to do the thing. And they're like, what kind of thing do you want to learn how to do? People donate all sorts of cool crazy stuff to us. Do you want to like break something?

You want to fix something? You want to learn how a 3D printer works? Do you want to do molecular biology? There's one of the lab— one of the guys got a DNA sequencing machine. Like crazy stuff, right?

Because they were just giving it away and they knew enough people in those technology communities that they'd bring some of these cool things over. And so, you know, you have those spaces that are built more on the the kind of security conversations, then they expand into different makerspaces where it's, you know, I don't know how to do woodworking, I don't have a laser, you know, I don't have a CNC machine, and I don't have a Hadron Collider sitting around, you know, so like hook me up. And so, so all of these, these groups, you have kind of social groups like DC303 and, and those types of groups. You have some of the meetup groups. There's like a, you know, in many cities.

So Colorado Springs has one, Denver has a couple of them. And then you also have the spaces where you can go and learn how to do some of this stuff and just become a member. So $50, you become a member, you can go over there anytime you want, use all the cool tools that are there, help contribute, you know, teach some classes, take some classes, and it's really a way to kind of keep alive that community. Community learning that most of us that when we got started really had to participate in because there was no other venue for us to learn in. There was no college for us to immerse us in.

And we really want to keep that alive because I think that's really the heartbeat of that kind of hacker mentality. And hacker doesn't mean, you know, computer. Hacker means that you're there to not just see what it is, but to see what it can do. And whether that's a train, whether it's a plane, whether it's a power strip, whether it's a blender, doesn't matter what it is. It's all about exploring what something may be built to do and then seeing if you can make it do something else.

Maybe it's something better. Maybe, you know, I watched this wine sommelier troll a bunch of other sommeliers, and so they said, we're gonna test decanters. So they have this blind testing with this wicked expensive wine, and all these guys were, you know, giving their opinion with bottle shock and like, oh, you can't move the bottle too much, it has to flow like this because the peptide— and they start using their like fake knowledge of biology and all this other shit, right? So he sets up these decanters. He has like a $50 decanter, $100 decanter, $1,000 decanter, $5,000 decanter.

$50,000 decanter, and did another one. And he said, I'm going to pour from all these different decanters, same wine, and you're going to test the same wine, and you're going to tell me tasting notes against all of these blind, and then at the end we're going to determine which one's the best. Every single sommelier that was in the test of 4 picked the same exact wine. How is that wine decanted? In a blender.

In a blender. That, that's hacker right there. I was hoping it was one of those, uh, orange Home Depot buckets or something. Seriously, in a blender. Cool, it's aerated.

Put it in glass. Right. Yeah, cool. Well, we are running short on time. I think we could probably talk for another hour plus, so we'll have to do this again.

But Chris, yeah, thanks, appreciate your time. Thank you. And you know, if there's any way I can be of help to anyone in the community who's learning this stuff or wants to get into it, uh, or even, you know, is trying, you know, from, from the where do I get started to I already do this but I really want to focus on this, um, my email address is indigosax@indigosax.com. Gmail.com, and you can email me, and I'm more than happy to help when I can. Nice.

Uh, we'll include it in the show notes as well as Twitter and websites and all that kind of stuff to make sure people can get a hold of you. So cool. Thanks, man. Appreciate it.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes