Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 64, the week of April 23rd. Alex, last week was the big security conference in San Francisco.
How was Detroit? You know, I was at another big security conference, not really a security conference, the Mortgage Bankers Association Technology Conference. Yeah. Where we spoke about security. You had some security speakers there, right?
We did. I actually was even quoted in a HousingWire article. Oh, how about that? Congratulations. HousingWire.
Yeah, I know. Big deal. Pretty good stuff. Well, welcome back. We're both back to Denver in time for the snow over the weekend.
Pretty good. Yeah, you know, beautiful weather. Um, of course, uh, snow on Saturday, 70 on Sunday. Yeah, sounds like Denver. Sounds like Denver.
All right, let's go ahead and jump into stuff. First of all, uh, we do want to remind you we have a Slack channel, over 400 participants in there, and a great place to have conversation. There's a link to join the Slack channel both in the show notes and on the front page of colorado-security.com. Also, if you subscribe on iTunes or Google Play, please rate us. We would love to have your rating as part of that.
And we do want to remind you we have a Patreon campaign. If you want to support the show, we would really appreciate it. Any, any contributions you give go directly toward paying for the, the, like the hosting and the hardware we use to actually do the show. We do appreciate those very— appreciate very much those who are already supporting the show. Exactly.
So let's jump into the news. We had a story this week. Denver rent is up 48% since 2010. The only place worse is the Bay Area. Yeah, up really basically 50% over the last 8 years.
That's pretty significant. Obviously, it's become a lot more expensive to rent in Denver. A lot of folks having to move further from the city. But it just goes to show how attractive, how nice a place this is to live. And while it has been up 48%, it still could be worse.
That's actually, you know, the percentage gain. Looking at the actual numbers in the 4th quarter of 2017, The effective rent, some index that they use, I guess, was about $1,400 in Denver. Well, it was about $3,250 in San Francisco. So, and I guarantee we're still doing okay. The folks in San Francisco are not making twice as much as the folks in Denver.
I guarantee you, as much as they— you might think they're getting paid well, they are not getting paid twice as much. So yeah, from a quality of life perspective, this is a whole lot more affordable out here. Moving along, there's a survey here from Denver Business Journal around which cities most wanted to have Amazon HQ2 come to town. And the punchline, it was not Denver. Yeah.
And in fact, Denver least wanted to have HQ2 come to town. We were not only lowest in saying we should reach out and we need it. Basically, there was only 16% of Denver folks said that we need to have HQ2 come. We also rated near the lowest for saying, well, you know, should we give tax breaks and would people be willing to have a longer commute in order to have HQ2 come to town? I think some of the cities that were high on the list were Pittsburgh, Indianapolis, and I think maybe Atlanta.
Yeah, there's— I remember Atlanta for sure being on the list. And of course, near the bottom of support for what they'd be willing to do was Austin right there with us saying, right, exactly, we don't need it, we don't want it. We're already doing okay, we don't need any more people. Yeah. So next, venture capitalist funding is still high in Colorado and we ranked 8th in US funding.
Yeah, so obviously yet another indication that Denver and Colorado in general are really high in the tech world, very well appreciated from both the workers' perspective and from the funding perspective. We're, you know, getting quite a bit of venture funding here in town. There were some companies listed that got funding recently. None of them were security companies. It looks like a lot of biotech.
But, you know, there was a great quote from someone at PwC in there that, you know, says that these companies are using blockchain and artificial intelligence and big data to change the world. So really excited for that. If there's one thing we know about venture capitalists is that they love their buzzwords and they love being covered in media. So they'll say what it takes to be covered. Speaking of venture capitalists, Techstars is the big accelerator up in Boulder that was started by— oh man, Brad Feld.
Brad Feld and a couple others. We had Brad on the show last year. They've actually hired a new president to run the Techstars Foundation. And she was— Lou Cordova is her name. And she previously was a chairman of the Federal Reserve Bank out of Kansas.
Yeah, so the Techstars Foundation is a little bit different than Techstars itself. You know, it's a nonprofit that is trying to work to help bring, you know, sort of the same kind of services, funding acceleration, to potential companies that are— that have not had it, you know, minority-owned, or, you know, people that have been left out of the process previously. Yeah, so really cool to see them investing there and trying to help trying to help move things in the right direction from a startup perspective. So congratulations to those guys. And we have an article from the Denver Post about the Facebook fiasco that has been going on.
And you might think, well, okay, that there's nothing new there and doesn't really have anything to do with Colorado. Well, other than the fact that there's a whole bunch of people in Colorado that Facebook probably gave their data away. But besides that, The article actually quotes someone that we know, Mr. Robb Reck. So Tamara Chuang, the reporter from Denver Post, was trying to figure out, trying to bring the story home.
What is the impact of the Facebook breach to Colorado companies? So they interviewed a few of the folks here in town, including myself, just to ask, how does this impact our customers? How does it impact our companies? And at Ping, as we talk about identity quite a bit, and Facebook is one of the larger identity providers on the at least on the consumer side, there's some impact. And it's an interesting conversation, I think worth taking a look if you're interested in knowing how does the Facebook breach impact companies, not just impacting individuals.
Yeah. So next, uh, Castle View High School— we've talked about this previously, but they started a program called Operation Cyber Blanket. And basically they're helping those in the community to make sure that their personal devices and networks are secured so that you don't have problems from, from security issues. Yeah, so there's a video on this on the link here. You can learn a little bit about what they do, also give some information on how you can reach out if you know someone who could use this kind of volunteer service.
So I think it's a really cool thing and really want to applaud not only the students who are doing this but the adult mentors they have that are making this happen. Yeah, and pretty cool that they, uh, they made a story on, you know, Fox, uh, KDVR, the Fox channel here in town. Uh, the video is from that, so pretty cool. Uh, next story is actually a blog post that I wrote for Ping Identity, uh, and it kind of is a follow-up to the news that we have received our ISO 27001 certification. This is an international standard that kind of sets guidelines for how you do your IT and security practices.
And then this blog post describes what does it mean for our customers. So if you're interested in knowing why, why you might care about a company receiving ISO certification, this is a nice summary about that. It adds some assurance to our customers, and it really makes it much easier for us internally to do communication around security and really maturing all of our processes. And I would like to give you guys kudos, Robb. ISO 27000, it, it's not an easy thing to get certified in.
You can't just decide one day that you're going to do it and Uh, you know, next week you're certified. Uh, lots of work that went into that, I'm sure. Yeah, for us it was about a 2-year process. It, you know, there's a maturation behind the scenes before you're really ready to, to go have the third party come in and, and do the review. Uh, Optiv, they opened their new Denver headquarters this week.
Um, they are part of a new building downtown, new skyscraper. Uh, they've got their name on it, Optiv Tower. Optiv Tower. And, uh, I've heard it's nice and swanky. Yeah, so it's Optiv Tower at the— I'm gonna get this wrong, but it's like the Gates Plaza and Chipotle, the Chipotle cafeteria, something like that, right?
Like, like all 3 of the big companies in there really wanted to have their name on the building. And there was a little bit of bidding war. So congrats to Optiv for getting the tower named after them. This is, I think it's the 2nd tallest skyscraper in Denver now. Don't quote me on that.
But I think it's the 2nd tallest. It's definitely a beautiful new building. I can see it from my office. I'm looking forward to going and seeing. I've heard it's very nice.
It is cool also that we have a building with a security company's name on it here in town. Yeah, that's pretty cool milestone. Speaking of Denver security companies, which is really all we do here, CyberGRX and Deloitte have partnered. So as you guys may know, CyberGRX does third-party risk management services where basically they're a platform that any enterprises can use to get access to the security posture of different vendors. And of course, in order to do that, CyberGRX has to do some kind of assessment of those security vendors.
Well, it looks like in this announcement they have reached agreement with Deloitte that they can use Deloitte to go out and do the assessments for them rather than CyberGRX having to do all— do them all themselves. They now have a partner who can help deliver, you know, at global scale since Deloitte is so big. It seems like a really smart partnership there. If you are a small startup and you need to assess people all around the world, having a company with global reach like that is really going to be helpful. Yeah, scalable.
And then finally in the news this week, a company called DeepCam out of Longmont unveiled their new product at a security show in Las Vegas. The big security show last week? No, no, no, this is a little bit different. International Security Conference and Expo in Las Vegas. Yes, that's the one.
They— so this is not a cybersecurity startup, this is a physical security startup. The company is looking to help stop shoplifting, and they're using artificial intelligence to help figure out when, when people in stores are stealing things. So this is both awesome and really scary at the same time, right? So there's gonna be cameras in the stores looking for what, you know, not humans, but what cameras pick up as suspicious activity that might lead to theft. And they say that they can cover, you know, catch way, way higher percentage of theft than stores usually catch without these cameras.
Yeah, I think they said that normal loss rates are about 10%. Normal catch rates. Sorry. Catch rates are about 10% for folks that are trying to steal things. So it does seem like that there's a little bit of an opportunity there if you're leaving 90% of it on the table.
Yeah, using, you know, creepy AI technology for monitoring people could help with that. Yeah. And this actually reminds me of a story that has nothing to do with Colorado, but where China has, you know, been— they've been using cameras to find people and they had cameras in a stadium with like 50,000 attendees at the stadium and they were able to, from the cameras, pick out the one individual fugitive that they were looking for, you know, Basically, I assume from from the gate, but it might have been facial facial recognition. I don't know. But either way, we are moving.
We are moving towards one of those dystopian movies that yes, we've been watching since for the last thirty years. Let's hope that that DeepCam does not push us towards the the things that are happening in China right now. So we'll see. All right. So moving over to the Slack message of the week.
Congratulations to Steve Carlton. Steve, we just wanted to call you out for your post recognizing the Operation Cyber Blanket story. We just. Talked about on KDV-R, and also for your help in organizing the group. So with our sponsor Andre Gaeta, we want to give you access to get something from the Colorado Equal Security store and once again say thank you to what you've been doing and, and really the good conversation you started in the Slack channel this week.
Yeah, good job, Steve. Thanks. Uh, with that, we will move on to our events. So we do have an event calendar on the website at colorado-security.com. Go check that out for the latest events.
And the first one that we have for this week, the Women in Security meeting is happening on the 24th. This is their 1-year anniversary, so make sure you bring candles or a card. What's the appropriate gift for a 1-year anniversary? I think paper. I think it's paper, right?
Yeah. Papier-mâché, maybe. You know, some $100 bills, whatever.
All right. The Colorado— excuse me, the Cloud Security Alliance Colorado chapter is having their April meeting also on the 24th. On the 25th, there's a GDPR meetup talking about Article 32 and the Elastic Stack. On the 25th, DENSEC is having their monthly meetup that is downtown. SecureSet is doing a— one of their capture the flag events on the 27th.
And if you have never done a capture the flag event and you're thinking this is gonna be too hard for me, they have just the solution for you. Show up an hour early at 5 o'clock, they'll give you a a little bit of a pre-event training and show you how you can participate in the capture the flag. So when the real event starts at 6 o'clock, you have some support and you actually know what to do. So pretty cool stuff. On the 28th, Colorado Springs ISSA has one of their many seminars.
That's the 8 AM to 12 o'clock Saturday event where you basically just get, you know, 4 CPEs for free. And on May 3rd, CTA is doing their Insight Series. Uh, entitled Turn Big Data into Big Business. Pretty good stuff. This is one of those that would be pretty relevant for a lot of companies here in town.
Uh, you know, we're looking just one week after that, right? So just, just really 3 weeks from now, man, at RMISC, our big conference here in town. It is really sneaking up on us, Robb. Yeah, I know we've done really well with, with sponsorship. I think there's still a couple sponsor slots open last I heard.
A few, not too many, but if you want to sponsor, you still can. I am pretty confident we'll sell that out this year. And registration is moving along really well. So if you haven't got signed up yet, please do. We're looking to blow the numbers off of what we've had in previous years, and hopefully we really fill out the convention center.
I feel like we're about halfway to where we need to be on registration. That's a little bit ahead, I think, of where we want to be, but pretty typical. People tend to wait a little bit before they actually register. Even though we offer substantial early bird discounts, which have now passed. Oh well.
Well, sign up now. Sign up and come see us there. Both Alex and I will be there. I think we both are speaking a couple different times. Yep, exactly.
I'm so looking forward to it. All right, should we jump over to events? Or to jobs, I mean. Let's do it. So first job, the best job, is there's a senior security analyst position at Ping Identity that will be working on my infrastructure security team.
We're looking for someone who's got a good amount of experience and really wants to help us lead and form an infrastructure security function going into the future. The next best job, if you are not a senior security analyst, is Pulte Financial Services is looking for 2 security interns for this summer. So if you are a student, if you are someone that is looking for a summer internship, apply for that. We would love to have you. Awesome.
Carbon Black is hiring a product security engineer, so someone focused on application security here in town. Nice. I know they're building out a lot of folks up in Boulder. Peak Travel Group is looking for a director of information security and compliance, but this is a home-based position. Very cool.
So you get to work from home and run a security team, huh? Exactly. RLH Corporation is hiring a director of information security and infrastructure. Who is RLH? Do you know?
I don't. All right, while you talk, I'll look it up. Okay. Next, T-Tech, formerly known as TeleTech, is looking for a senior information security engineer. So RHL is an investment organization.
They do investments, capital stuff. Yeah, there you go. Sounds like fun. Comcast is looking for a senior auditor of technology. So if you want to be an auditor for Comcast, got a position for you.
Very cool. The Director of the Interior, the USGS, is hiring a security specialist here. I assume that's over at the federal center over at 6th and Sims. I believe so. First Bank is hiring a cybersecurity analyst, and CenturyLink is hiring an intern focused on tech planning and security for this summer.
Exactly. I think that takes us to the end of the news this week. Alex, anything else you wanna add before we kick it over to our feature interview? Get out there and register for RMISC. We do have our feature interview this week with Mike Glenn.
Mike is the CISO for CableLabs. We've talked a little bit about them in the past. Not only is he now at CableLabs, but he's been in the telecommunications company in Denver for a very long time. Worked with Quest and CenturyLink and has has done a lot of cool stuff. So interesting stories about him.
And, you know, we start off the interview and talk about a world record that he has. A world record. He, he, he was a world record holder. He actually had it taken. Wait, wait, wait.
Don't give it away. Oh, I'm not giving it away. Don't give it away. You got to listen to the interview if you want to hear it. All right.
Everyone have a great week. Thanks, Robb. This is Tim Coogan, Chief Information Security Officer of Denver International Airport. Welcome to Colorado Equals Security. Colorado Security Professionals by Colorado Security Professionals.
All right, this is Robb Reck, and today I am sitting with Mike Glenn. Mike, you're the, the CISO for CableLabs, uh, here's— here in Denver. We've talked about you guys on the show a few times, um, and I'm looking forward to getting to hear a little bit more about CableLabs and your background. But first, you know, I want to use this opportunity to, to ask for an autograph, as I understand that you are a former world record holder. Mike, what world record did you hold for a short amount of time?
It's a pretty amazing record. When I was 12 years old, I set the world record on pogo stick jumping. Now, is that consecutive number of jumps or is it duration? And we counted, yes, the number of jumps. And I made the local papers and we had validation.
And before the book was published, as you can imagine at 12 years old, it wasn't too hard to break. And so someone read the newspaper article and then broke it, and, you know, after, after me, and they were put in the Guinness Book of World Records. So dashed my hopes to go on to be a professional pogo stick jumper. It killed your whole professional pogo stick career. It did, it really did.
So how many jumps was it? I don't even remember, you know. 38,000 or something like that, that, you know, you're, you're clicking. When I got off the pogo stick, I was so sore I had to be carried in, right? I couldn't walk.
That's pretty impressive too. At my current age, that wouldn't be impressive at all for me to be that sore, but at 12, we're a little more resilient. Yeah. So do you remember how long that took? Yeah, I assume we're talking hours.
Hours, hours, yeah, but not days. And then, and then my brother later on decided to try to set the, the continuous record for trampoline jumping. Oh boy. And, and you got like a 10-minute break every hour or whatever, but he went 3 days.
3 days, and basically without sleeping then. Yeah, I'm hearing that's, that's the hardest part of that. But he didn't get in the, in the world record book either because again, someone, someone broke this before he got his record too. That's awesome. Well, I'm glad we got to talk about that.
Another interesting thing We were talking about before the interview is you're a sailor, and you sail here in Colorado along some of the lakes. Is that right? I do, yeah.
My version of sailing is when you're on the water and there's another boat, you're racing, because that's the only way you would want to sail. As fast as possible? Yeah, as fast as possible. There's no reason to sail around the lake 3 or 4 or 5 times. After that, it's pretty boring, right?
So racing is the only thing you really need to do when sailing in Colorado. Yeah, so we sail up at— sailed for a number of years at Carter Reservoir, sail up at Dillon. We sailed at the Santana 20 Nationals this last summer up in Dillon, have sailed in the U-20 Nationals at Dillon again. So it's fun. So is that something that you learned on your own, or is that a family thing?
Where did you come into sailing? Sailing? Um, well, early on in my career, I was out in Kansas and, and started to do windsurfing out there. And then when I lived in the Marshall Islands, uh, started to sail in the Marshall Islands and then stopped it for a while. And when I came back to Denver, uh, picked it up again because there's an active sailing community here.
I had no idea. There's a lot of communities here. There are. Well, uh, and then I had one other kind kind of interesting thing you were talking about. What's the most interesting place you've ever been?
I've been to a number of interesting places, but one of the funnest ones was when I was out in the Marshall Islands at Kwajalein. My wife bought me a trip to go dive the Bikini Atoll in the Marshall Islands, which is where they set off the nuclear bombs and the very famous pictures of are there with the ships all around that they captured after World War II, and they're trying to see the impact of that. When you see the atomic blasts in the water, and the ships are standing on end— I was able to dive the Bikini Atoll for a week, and dove the Saratoga aircraft carrier, which is the only— I think it's still the only diveable aircraft carrier in the world. You can't eat the food that's grown on Bikini even today, because the cesium in the soil accumulates in the, in the fruit, uh, in the, in the seeds of the fruit, and, and it looks a lot like nitrogen. So they fly all the food in.
So when you're diving there, what's— obviously it's really cool to get to dive an aircraft carrier. That's, that's cool. What else is there to see? There's destroyers. I remember going down on this destroyer.
The wrecks are pretty deep, so you're diving in regular air. For those of you who are divers, we're diving anywhere— the checkout dive is 90 feet, and then the bottom, the deepest I got was 190 feet, and overran my dive computers and other things there. There's no decompression chamber on Bikini, so you have to be pretty careful. But it was a great experience. Experience.
Going down on this destroyer that had been vertical— they think was vertical in one of the atomic blasts— and you go down there, it's laying on its side, 700 feet long, and you can see the waves in the metal from the force of the atomic blast. Out of Kwajalein, there was also the Prinz Eugen, which was a sister ship to the Bismarck. It's out there, and diving on it was a lot of fun. There's just a lot of World War II wrecks out of Kwajalein and out there that were really fun to dive on. That's great.
Neat opportunities you've had. Well, let's go ahead and just, you know, start talking a little bit about the security space and how you got to do what you do. Let's start by asking where you're from. Where did you grow up? Sure.
So Colorado native, grew up in Arvada, went to Colorado School of Mines because I thought it was the best school out there. Really didn't know what I wanted to do and They forced me to pick a major, and so I picked the major that had the highest salary. I went into petroleum engineering. You're at the School of Mines, it makes a lot of sense, right? Yeah.
During school, things were going great, and when I graduated, the bottom fell out of the oil and gas business. I was thrilled to get a job out in Kansas. When I moved out to Kansas, graduated, got married, and moved Kansas in 3 weeks. Started doing hydraulic fracturing on gas wells out there.
Then after that, moved back— after 4 years, moved back to Denver, worked and completed a whole bunch of heavy oil wells in California within that space. Then on the 4th round of voluntary layoffs, where they were giving pretty good severance, right, a year's severance. Trying to get people to exit the business, I decided to leave. They were closing their office here in Denver, and I really didn't want to move to other places. I had my choice of moving to Houston, Texas; Dallas, Texas; Midland, Texas; Bakersfield, California; or New Orleans.
I decided I really didn't want to live in those cities for the rest of my life. So what'd you do next? After that, started my own company for a period of time, trying to do reservoir simulation. Really never got it to the market, but learned a lot by doing that. Then we were also doing some IT consulting.
My business partner got approached by Johnson Controls at the time, and they needed someone to go out to the Marshall Islands to to, to do a 4-week stint to work on their telephone system. And he turned it down, and he came to me and said, you know, had this opportunity. And I said, well, you know what, you ought to do it. You can always say yes, you can't always say no. You ought to learn about it.
And so we went back to them, and they said, well, you know, we want a pair of people, we want 2 people who work well together. Oh well, might be kind of fun to go to the Central Pacific, you know, for a, for a month and see what it's like. So we flew out there. 4 weeks turned to 8 weeks. And then, um, you know, we— they wanted us to work full-time on their stuff, on their projects from Denver.
We said, well, we can only work half-time. Did that for about 6 months. And then a job opening came up and said, you know, living on a small tropical island might not be such a bad change. And, uh, you know try something new, right? So, so then moved out to Kwajalein and worked on initially on their— they have 2 main contracts out there, technical contract and a logistics contract.
So started on the logistics contract, which is providing all of the services for a small 3,000-person city in the middle of nowhere. Kwajalein is, is located centrally located in Pacific, 2,000 miles from Hawaii, Japan, and the northern tip of Australia. It's on most maps because there's nothing else out there, right? Because you got to put something out there, right? So it's a military range.
It's the last long-range military testing range that the U.S. has. And so when I was out there, they were doing the Star Wars testing. They would launch the interceptors from Mecca Island at Kwajalein and, and The missiles would come from Vandenberg, and then they'd also launch Peacekeepers from Vandenberg into the lagoon to test the accuracy and make sure they were still working. Then they also monitor for what they call new foreign launches, NFLs, out of Asia. All that data is fed in— used to be NORAD, but now Peterson Military Base.
A bunch of big radars. The technical contracts supported the radars and the launches, and the logistics contracts supported everything else. They had a K-12 school system. They had a hospital. We had to deal with pharmacy systems.
Were you doing technology for these guys, or were you doing logistics? What was your role? I started out in their communications area, and they had an LC-48 Sonnet system around the Atoll, around there. So for those who don't know, OC-48, oh, it's, it's, uh, uh, you know, a measurement of bandwidth, right? So, so, uh, 2.4 giga— uh, gigabits per second, which was a connectivity, which was a big deal at that time, period of time, you know, in the early, early, uh, '90s.
And so learned that, right? Taught myself programming, took classes had some programming in college, but took remote classes from CU on telecom, learning what a DS1 was and the signaling and the framing and DS3s and OC specs and all of that.
Worked and ran the unclassified networks out there for a period of time and then moved over from the technical contract back to the logistics.
Basically, I was the IT software manager. I think I was a class away from being a certified Oracle DBA, those type of things. So did all the Oracle applications, HR, accounts payable, accounts receivable, payroll, all of the stuff to run a small city. How do you go from this to security? It seems like there's a ways out.
Sure. We started to get into security a little bit at Quad, dealing with some of the first firewalls, some of the home-written ones from MIT Lincoln Laboratories, and some of the early ones, application firewalls with Sidewinder firewalls, if anyone remembers those, and that type of stuff, right? And, and then basically, um, uh, 5 years in, my, my old boss, uh, he had left and he was at a startup in the Springs. And he called and called the home number, 8 hours difference, right, on time zones. And my wife answers.
He said, do you think Mike would be interested in this job? She said, he sure would.
So I didn't end up going to work for that company, and it took me a year to leave, right? But I ended up going to work in the backbone architecture team for Quest Communications. Okay. Yeah. Is that back when Quest was with a U or a W?
With a W. All right. It always had a W. Did it? Yeah. Oh, okay. But, uh, I joined 2 weeks after the, the Quest and US West merger.
One side note Out of Kwajalein. It was kind of fun. I hadn't realized it, but my father was out there in World War II intercepting Japanese radio traffic. He originally started in Hawaii, and then he moved to Kwajalein. Before he passed away, he was able to come out, and we were able to actually go on the island and see the Japanese buildings and stuff that they occupied after the Marines had stormed the atoll.
Basically leveled everything out there.
That was kind of neat. He was out there in World War II, and then I was there following him, which was kind of cool.
I went in the backbone team at Quest Communications. A lot of friction at that point. Interesting time. Joe Nascio was the CEO, who later went to jail. Why a lot of friction?
Joe had a somewhat abrasive personality and was pretty brutal on the US West folks after the merger. Fortunately, I was on the Quest side of things, but a lot of animosity there. Then at that same time, there were some interesting things going on with family and friends deals with vendors. Getting calls around, we have 800 Redback routers in this warehouse in we need you to certify them and deploy them on DSL. These were DSL B-RAS routers.
We took them into the lab, we evaluated them, and they were not very good. Let me just put it that way. Getting calls from senior executives, when are you going to deploy it? Sorry, we're not going to deploy it. On VPN, CoSign products, and other things, right?
When are you going to deploy it? Well, there's a lot of issues with this. Turns out later some of those folks had stock options in those vendors and other things, right? That went on for a while. Took over— started as an individual contributor working on carrier DNS, combining different DNS systems.
Then decided I really preferred being in management and kind of driving a vision. Then took over the backbone team as far as backbone applications and services, and we did all kinds of stuff. We managed the carrier DNS, customer email for all of the ISP customers and business customers, RADIUS infrastructure for authentication. We also did hosting certifications, uh, within that. And, and during that time, I, I took over the single backbone security engineer for the company, right?
Don Smith. Shout out to Don. And, and he's still at CenturyLink. He's pretty well known in the security carrier space. But, uh, grew the team up and had some, you know, it was really fun and interesting times during that time, right?
Because I kind of got my feet wet during that. I, I decided I'd better learn some stuff about security, right? So got my, my, uh, SANS GSAC, and, you know, at that time there was the goal and you had to write a paper, and, and, you know, wrote the paper on, on carrier-based DDoS techniques, right, which is still out there. And, and then, you know, in 2003 had a couple interesting events happen. The first one was around an issue that Cisco had, so John Chambers called the CEOs of the top 6 carriers and said, we have this problem and we need you to help us with it.
They had a vulnerability in their backbone routers and they were concerned that if the carriers went down, none of the enterprises would be able to download the patches. All of a sudden, I'm in charge of this because I have the backbone team, which was 1 or 2 engineers at that time. We spent the next couple days and these tense sessions with Cisco and a team of 70 people on these phone calls around— Cisco wanted us to block all IP protocols on our backbone except TCP, UDP, and ICMP. So we went and looked at what we were running on our backbone at that time. We had 53 different protocols running.
It's like, we can't do that, right? So we ended up negotiating a special NDA with the Cisco general counsel after 3 days. There were 4 vulnerable protocols, but the real big one was one called PIM, which is a multicast protocol. The problem was, if you ran 75 PIM packets through a router that did not have PIM turned on, it would lock up the interface and you had to reboot the router.
We blocked those 4 protocols and And then within one of the carriers, which I'll leave nameless, leaked this, the information to their marketing department, and they made it public. Within 6 hours, we had started to see PIM traffic on our backbone that we never saw before, which was really interesting. At the time, it worked out okay? It worked out fine. And then we created, you know, the special group.
So that was at the time of information sharing with Barry Green, Chris Morrow, who's been over at Google for a long time now. But they were really advocates and really good at helping to educate carriers on backbone carrier security, as far as BGP security and locking down routers and recolorization of packets on your backbone when you're running QoS and all kinds of techniques, implementing black hole filtering, both destination source, implementing unicast RPF for anti-spoofing, all kinds of good carrier techniques. Involved with that, 2003 also is when the Slammer worm hit.
It caused havoc on the enterprise, but on the backbone, we only had one link go down, and we were really lucky because we were just well over-provisioned. But it became very clear, we saw traffic levels rise with than 10 minutes to huge volumes, right? And so as a result of that, we worked with the backbone architecture team to put a pretty innovative backbone architecture in where we took BGP out of the core, we privatized the core, and then we broke up our internet traffic, our long-distance VoIP traffic, and our enterprise VPN traffic into different domains and then segmented those with within the backbone. So if you had another slammer event on the internet side, it wouldn't affect your long-distance phone traffic. It wouldn't affect your enterprise VPN traffic for the traffic you were carrying for your enterprise customers.
I think that's still in place today. Let me just pause a second from the story, if you don't mind, and ask you. You've been involved in 2 of the biggest industries in Denver. Obviously natural gas. We've been in the natural gas city for forever, right?
And then telecom, I think it's kind of clear why we're a natural gas hub, but why are we a telecom hub? It's really decades of experience now, right? What— why are we here? Because of geography. So Denver is a good place within the country, you know, when you're laying fiber optic lines, and, and, you know, it's a— it has a good geographic region where you can access different areas.
We had a lot of telcos and cable operators, satellite providers migrate here. Can you give me an idea why Denver, not Salt Lake City or Salida or Wichita or Cheyenne? Any ideas why? I think just Denver was the major hub here. Then you had folks like Philip Anschutz who realized the potential of telecom.
He bought up all the railroads. He made his money in oil and gas right now in Utah, and then bought up the railroads and realized, I have this right-of-way running across the country. Then what they did is laid fiber optic cables along the right-of-ways on the railroads for Qwest. They didn't have to negotiate all those right-of-ways. He was located in this for example.
So Anschutz, and then Daniels is another big— Daniels, yeah. You know, how does he factor into this? I don't. I don't know the story on Daniels. He's obviously the DU guy, and there's the cable center down there at DU from his— right, from his investments.
But I don't know, I'm just curious. Obviously that's been a huge part of Denver, and probably part of why we're such a good tech and security hub now is because we were a big telecom, right? And we can— we continue to to, to, uh, drive that, right? When you, when you look at Facebook, you know, Facebook has some of the backbone engineers here, right? And in other areas.
So, uh, Charter, for example, you know, they've got their big engineering center, the SeaTech, down south. Of course, Dish and EchoStar, right? Level 3, uh, Quest, US West. DirecTV has a big presence here too. They do.
Yeah, yeah. And Interesting. It seemed to be a hub and a magnet, although with different consolidations, we aren't nearly as dependent on telecom as we used to be, just like oil and gas, which is probably a good thing for the city overall. Anyway, sorry, that was a little bit of a tangent. It just occurred to me that you might have a little bit of perspective on this.
Always interesting to learn a little bit about the technical history here in Colorado.
Communications industry is a pretty small industry, really, both nationally and even internationally. But it was a fun time in the early 2000s around this. This is when we started to see the first real attacks against PoPs, so we had to harden all of our backbone routers and point of presence. We had TeraPoPs where we had 3 main core routers in it, and we started to see attacks against the CPUs of the routers and other things. So you had to harden the services on the routers and really make it where they could survive that.
Learning some of the techniques about ensuring that rate limiting the number of packets that could go to the CPUs of the routers. Routers are really good at forwarding packets, but they don't have really big CPUs and memory. So if you can get the routers to start punting packets to the CPU, you can DOS them pretty easily. Did you have any background with the phreaking, the phone hacking that we saw? It was more '90s, but I assume some of it extended into the 2000s as well.
No, I was out at Kwajalein during that time, so I wasn't really involved with that. Some of the folks at Quest who was there before I got there, they dealt with Mitnick and other folks, and were dealing with the the FBI at that time, and they helped track him down. He did a lot of fun antics to Quest before he got there. By the time you got there, they'd pretty well figured out how to protect against those activities? Yeah, in general, yeah.
But it kept going, it kept evolving, and the attacks kept evolving. We started to see the botnets. We deployed the first DDoS monitoring system at Quest in '01. That was one of the first things I did there, Arbor system. Then I spent many years trying to get scrubbers in place, and only until we supported the Democratic and Republican National Conventions in '08 would they put scrubbers in place.
It was always too big of a budget hit for This was a time of downsizing. We had talked about that. The company was under continual downsizing over time. It was interesting. I followed our CEO one time, Dick Notebaert at the time, in a speech to state government customers.
What I didn't realize is kind of during the bad time at Quest, they came within 10 weeks of not making payroll. This is a Fortune 200 company. There were some dark days there, and then Nashua went to jail and other things. But they had a very strict ethics and compliance program that resulted from that, which was a good thing. They were really a leader, I think, in their organizational structure around their compliance programs.
They had a Chief Risk Officer. Back in '04 that had all risk functions— insurance, ethics, information security. They had information cybersecurity back in 2002. Pretty early, yeah. It is pretty early, right?
They were pretty forward-leaning, but very driven by legal, as you might imagine after having to restate— $2 billion in revenue. Fast-forward me a little bit in your career there at Quest. Obviously, you're leading the backbone team. What came next? Then I decided I wanted to learn more governance and compliance instead of just technology, so moved over into the enterprise security team that had governance over the whole company.
Worked for the CISO there with kind of the assumption that I would become the CISO once she left. It was Mel Gates, and she ended up leaving and became the CISO then in 2009. Ran the CISO program as the CISO until the merger with CenturyLink, and then at that point couldn't be the CISO because my boss got got the CSO job because they were alternating management between the companies at the merger. So I became a peer of the CISO. We worked pretty closely together.
Then at that same time, in 2010, Quest had gotten a letter from General Alexander about trying to do a 90-day pilot on protection of U.S. critical infrastructure in a partnership with the intelligence community. So got on a plane, flew out there, and that 90-day pilot ended up being a 3-year program around putting together a system to take sensitive indicators and apply it to unclassified traffic and protect certain key infrastructure. Sounds like something that Snowden might have leaked. It might have been. It was all above board, You can look, for example, at the privacy assessment that DHS did on the project.
That's all public. It was on the up and up? Oh, yeah. Everything was on the up and up, and with very good intentions from Alexander and other folks around it. The initial project was called the Enhanced Cybersecurity Services within that space.
That was so-so successful. Successful, because they wanted private industry to fund it, and it never really got the funding that it needed. But then part of the way in, they had developed Einstein I, Einstein II, and then they had developed Einstein III for the federal government and deployed Einstein III in the DOD. But it really wasn't scalable in a manner. They wanted to do Einstein 3 Accelerated around it.
And so we pivoted the program and worked pretty hard to work on productions for the .gov, the civilian federal government, and got that in place. But DHS didn't have the authority to deploy it across all .gov agencies, and a lot of agencies wouldn't deploy it. Then OPM happened, Office of Personnel Management. The big breach of all the classified data, right, for everyone with clearances. That really woke some people up.
Congress then acted and provided additional funding for E-3A and provided DHS congressional authorization to force those agencies to use E-3A. Then it was deployed across the entire .gov space. The good news is we started on just the initial program with some core services, but the good news is you haven't heard a lot about breaches in the .gov space. To me, that's a really good sign. In talking with a few folks, I know they've had some good successes that they can't talk about.
That is That was pretty fun, right? Fun where you're working on projects that you think make a difference. That's very cool. That's the reason why at the merger with CenturyLink and Level 3, I stayed on, because I was heavily involved with that and working on it. What year did you do this work?
It started in 2010 and went on to probably— I was directly— actively hands-on engaged to probably 2013, and was really a fun project, right? Because at that period of time, it wasn't about compliance, it was about how to get the mission done. And so we would develop architectures and we'd have people review them, and as long as you could protect the data, that's all that mattered. So we were the first company to have our, our architecture certified. Right?
What that involved was we had 12 people from 2 different government agencies come out, and they split up into 3 pen testing teams. We had given them all the source code 3 months ahead, so they had done all the source code analysis, and they actually developed a zero-day exploit on the code. Then they came in, and one team started outside, and was trying to break in, and the next team assumed the first layer of defense was compromised and started the first layer in. Then the third team started in assuming the second layer of defense was compromised and started in there. They never got the sensitive data, right, which was really— they learned a lot.
No. So they were out there pen testing for 2 and a half weeks, um, you know, so So it was kind of fun, and learned a lot from that. Learned about— one of my adages is, when you make security too complex, it can actually be worse than a simplified security program. Now, you don't want to make it too simple, don't get me wrong, but the conditions around the program were such that there were you had to use people with existing clearances, and you had to use existing facilities, which means that there were only 2 of us who had adequate-level clearances at the time, and a 3rd person was getting his clearance. He had a clearance, but it was getting upgraded.
Then I remember taking this conference room, ripping out— that was appropriate— ripping out the tiles, putting in racks, putting in air conditioning, and making it into a little small data room, data center to do this and supporting it. Now it's much bigger than that.
I left when they said, okay, the program's well established now. You've got to go through FISMA compliance. I went, okay, this is not what I want to do. I'm going to move on. That brings us into, yeah, 2013 and then 2014.
Again, working in that and also working as a peer to the CISO, so we were actively engaged. I was running about half the program at that point again, and John Kneese had the other half of the program. We had it split.
Then the CEO of Quest at that time was touting world-class security, but they kept cutting the people in the program. Then we brought in Lockheed Martin to evaluate our program, because we had worked with them in the DIB, because we were a defense contractor. I'm sorry, the Defense Industrial Base. It's U.S. defense contractors, and it's the information sharing. There's extensive information sharing and tactical sharing that goes among the defense contractors.
We had worked with them, and I had a lot of respect for Lockheed and Lockheed's program. So we brought them in to do an evaluation of ours, and then we gave them 8 critical objectives to see if they could breach those that would have significant impact on the business, and they were pretty successful. That got senior management's attention, and then we were in crisis mode. And so then we were trying to hire 50 people and raise the program from 30, 32 people, I think, on up to 80, which would— and dealing with, with all of the kind of knee-jerk reaction that happened, right? We had 11 critical projects that we had to do within 30 days and then 22 within 90 days.
And it's like, you know, we've been trying to tell you this for the last 3 years and you haven't been listening, and now it's a crisis. Yeah, now it's a crisis. Right. Well, obviously there's, you know, some negatives and some positives about pointing out the, the bad stuff, right? Maybe they might make you move too fast, faster than you want to, right?
Yeah, absolutely. So at that point, I, I decided to, to leave. I was ready for a break, and an opportunity came up at CableLabs and, and decided to take it. So what is CableLabs? I know we've talked about it a little bit, and, you know, you and I have talked But for those listening who don't know anything about it, what is CableLabs?
CableLabs, you can think of CableLabs as the Bell Labs of the cable industry. We develop technology for the global cable industry. We're best known for DOCSIS that provides broadband into the home. We also developed the technology to provide voice in the home over cable. We actually have a technical ME in our office.
A technical what? Emmy for our work in broadcast television. Like an Emmy Award? Yes. Oh, all right.
Didn't know there was such a thing. Yeah, so, so work there. So, um, and about 4 or 5 years ago now, the— we are, we're a member-funded organization, so we have 60 members in 34 countries. These are cable operators, so they're the people you would think right? Comcast, Charter, Cox, Liberty Global in Europe, right?
National Broadband Network out of Australia. You know, those folks. And so we get a percentage of their cable revenues, and that's how we're funded. So we're a relatively small organization. We have about 180 employees, and we have some contractors.
Pardon me. And You know, we work on different projects around cable technology and we're focused really in 4 main areas. We're focused in wired, which includes both coax and fiber, both fiber to the home and access fiber. We're focused in wireless, so Wi-Fi technologies, which are really important for our members, and 5G wireless. We're focused in machine learning and artificial intelligence.
And the fourth— and we're just starting in that area. And then the fourth area is security. And those are the 4 main areas that we're focused on. So I run the security team there and we're working in a number of different areas. So we've secured the cable industry globally with PKI.
We're a big believer in PKI. And so we run the global PKI for the cable industry. We own the root, right? We've deployed somewhere between 500 million and 1 billion certs globally in cable products.
And, you know, what I like to say about CableLabs, right, if you have cable in your home, you're using our technology no matter what you have, whether it's broadband, voice, or video.
And so what we're trying to do is our budget is broken up into 2 main areas. 50% of our budget goes to R&D, which is what we classify as projects that are 0 to 3 years out from commercialization, and then the other 50% is innovation, and those are projects that are 3 to 8 years out. Our CEO, Phil McKinney, is, you know, well known for innovation work. He spent 9 years at HP as the Chief Innovation Officer, has the longest-running podcast in the world now, active podcast. The longest-running podcast in the world, huh?
13 years now. So you can shoot for that record, Robb. You and Alex— I have no idea what's happening 13 months from now, much less 13 years.
And what we're trying to do is we're trying to develop— what Phil is trying to do with CableLabs is develop a sustainable innovation engine for substantial innovations for the cable industry is what he's trying to do. An example of that right now is we're working on coherent optics. So coherent optics in the access networks, we're trying to take ultra-long-haul technologies, which is really expensive, simplify that for access networks and shorter reach. And over the technology that's deployed today, we're trying to increase the capacity on a single fiber by 200 times and decrease the price by 80%. So let's dumb that down.
What I think I just heard you say is, you know, you're trying to decrease the cost of longer runs or you're using the longer run technology for shorter runs. We're using the longer run technology that you would run a fiber optics backbone across the country. Yeah. That's ultra long-haul technology and what we're trying to do is leverage that to cheapen it, if you will, or reduce the costs for access networks in metro areas. What's an access network?
That's the last mile? The last mile problem? Okay, not the last mile. The last mile is, is the coax, but this is, this is the, the network from kind of where the cable modem connects into, for example, the CMTS, which is the aggregation point for, for, uh, an area, right? For where your cable— my neighborhood might have a CMTS for 500 houses or something like that?
Yeah, or more. 500 or 1,000 or 10,000 houses, right? And then upstream of that, you have to carry all that traffic. So DOCSIS today, the current DOCSIS spec that we've developed, theoretical rates over coax are 10 gig down, 1 gig up, right? We're working on symmetric DOCSIS, which is symmetric 10 gig rates into the home.
So when you carry that much traffic, the access network and then the core backbone network have to have significant capacity. If you have 1,000 houses getting 10 gig each, it's a lot of traffic. It's a lot of traffic, yeah. Understood.
What we're trying to do with coherent optics, for example, is dramatically reduce the cost and dramatically increase the capacity within that network. Until you get to the core network for our operators and our members. How does your security team play a part in that? We're focused on a number of things. We manage and help architect the PKI around it.
Cable uses certificates to authenticate the cable modem to the headend equipment. Then we also have certificates to do secure software downloads. You can't upgrade your cable modem firmware. If you've ever looked at that, you can't do it. The operators do it on your behalf.
That has really helped secure that ecosystem. That's the way it's been for about the past 15 years. We deal with PKI and we deal with new architectures around that. We're putting in new security features in the next version of DOCSIS. We also do a lot of work in kind of a number of different areas.
That's one area. We're working with our wireless teams around 5G wireless authentication around that. We're also working on some improvements to Wi-Fi within that space. We're really big into IoT, and we're focusing in 2 main areas of IoT, consumer and medical. And we have, if anyone's interested, we put out some vision films called The Near Future, and we've done it 2 years in a row now.
First one is called Game On, which is kind of a fun video of why you would need gig speed in the house. And then the second video this year is called A Better Place, around what IoT could be like for people aging in the home and what it would look like if we had really good security there.
We're trying to drive strong security controls into IoT products at a global scale. If you give me the links for those, I can put those in the show notes. We'll do that. Would that be worth doing? Okay.
I'll give a note to do that. We are running short on time here, and I want to ask you a couple of community-type questions. Obviously, you've been a part of Colorado generally your whole life, basically, for a little bit. The security community here for the last 15 years or so, is that About right? Yeah.
Well, talk to me about how you've seen it changing over the last, you know, decade plus and how it's been maturing. What have you seen? Yeah, it's interesting. You know, at the beginning, we were just kind of pockets of people within the Denver community, I believe. Yeah.
You know, there was a period of time where Brendan Babek with Oracle, right, he was organizing dinners and activities with different folks to bring them together here, and then that kind of dropped off. He got pretty busy. I'm really glad to see folks like yourself and Alex stepping in. I know Ram Ramos over at CHI, he was heavily engaged in ISACA when he worked for me for a number of years and helped with the Rocky Mountain Information Security Conference and other things. Grown.
What really amazed me, as you have done your podcast, right, is just the number of startups, security startups, there are in the area, because I didn't realize it. I didn't realize— amazing, isn't it? You know, I think we all knew that there was like the 5 or 6 big companies, you know, the LogRhythm, Ping, Optiv, Webroot, but then there's like this 2 dozen other companies that I was totally surprised to learn about as well. Yeah, which is really neat and really fun, and it's, it's great to see, you know, the medical community and the people involved with that. Of course, telecom.
It seems like the telecom folks are a little bit more shy, if you will. I think it's a more reserved industry generally, right? Well, it is, and I think they— my experience is the communication folks tend to associate with themselves around it. I'm glad to see you pulling us out of the woodwork, right? Which is great.
It really is. Yeah, it's been a lot of fun. So I know we're getting short on time. I'd ask you any final thoughts for the community, anything you want to throw out there? Yeah, so I'll get on my soapbox for 30 seconds, right?
And the one thing that I've been trying to advocate for now for a while is a mind shift on security of how do we use security to provide better customer experiences, whether that's residential customers, whether that's business customers, whether that's your employees around it. Way too often, people view security as a cost center and a cost burden on the business. It's like insurance. I only want to pay to the level I need. I think what we need to start thinking about as security professionals is instead, how do we make security really benefit the business?
If we think about it and we're in at the very beginning of product design or architecture design, how do we build security in so it's really simple to use, really easy to use, and just works seamlessly and transparently for our customer, whoever that customer is? I remember our back at CenturyLink, the CEO going, can't I— you want me to change my password, can't I just use my thumb scan, you know, to do it? At that point in time, we didn't have the technology and the tools to do that, right? But now we can start to do that, you know, and associate it with WebAuthn and the different biometric— secure biometric protocols, right? But, you know, we're working on next-generation home networking architectures architectures, right?
And in the past with infected devices with IoT in the home, you try to do these customer notifications, right? Put in the first customer notification system back in '06, which is still in use, right? At scale, automated customer notification system for infections. But that's not going to scale in an IoT world, right? When you have 300 connected devices in the home, if I send you a notice that I'm seeing this anomalous traffic from this embedded Linux system, and can you figure out where that is in your home and then patch it, please?
Some people want us to cut off the Internet service of that person until they do. It's like, what a horrible customer experience. Instead, we need dynamic networks that recognize those infections and then limit the impact on customers using SD-WAN. Technologies and other monitoring technologies. It's a little Big Brother-ish, and we definitely have to design privacy into that along with security.
But there are easy ways— that's not a good— they're not easy ways. There are ways to do that, but it actually takes a lot of thought behind it. I think that's a great point, and certainly the better we can do to not be an inhibitor but be an enabler for customer having a good experience, the better off we're going to be. Right, because when you think about it, people don't buy security. They don't want to buy security.
But they will pay a premium for a good customer experience. When you have poor security, you have a really bad customer experience. If you can demonstrate to the business that you're helping them through that customer experience, through good, strong, well-thought-out security measures, That's where I think we need to go in this security industry. Awesome. Mike, thanks so much for your time.
We'll leave it with that, and hopefully we'll hear more soon what you guys are doing at CableLabs, and we'll catch up with you soon. Sounds great. Thanks, Robb. This has been Colorado Equals Security, and we'll talk to you guys next week.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.