Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 107 for the week of March 4th. You get to hear me introducing the podcast again, so that means Robb is still unavailable.
We are in a weird time between vacation and RSA, so this week you actually get to hear me do the newscast by myself. So this is the first time I get to do that. Robb did it once before, so let's see how it goes. Before I get into the news, some announcements. Of course, we do have a Slack channel.
So go ahead and check that out. We have just about 800 people in there now. Discussion, you should definitely check it out. Go to the website colorado-security.com for a link to that Slack channel. We also have a mailing list that you can find on colorado-security.com.
If you sign up, you will get a copy of the show notes emailed to you every week. Also, please rate us and subscribe to the podcast, whether that's through iTunes, Google Play, or whatever your favorite podcast subscription service is. The better ratings we have, the more likely we are to get found by other folks that would be interested in the podcast. And if you are willing to support us financially, we would love to have you sign up as a patron on Patreon. We have a couple of different subscription levels there, but all the money that we get goes right into the podcast and the website and all the other things that we do with Colorado Equal Security.
Putting all that right back into the community. And if you're not willing to support with financial means, we would love for you to just tell a friend about Colorado Equal Security and get them involved in the Colorado Equal Security movement. Before we get into the news, I would like to thank a new patron, Susan Bullwinkle of EvoTech. Thanks, Susan, for signing up to support us through Patreon. Susan signed up at that $10 a month level, so she gets this shout out on the show.
And also gets a free t-shirt. So we'll be getting that out to Susan. She does work for a company called EVOTEK, and I believe we're going to have some additional announcements from them in the coming weeks here. So, uh, take a look out for that. Uh, jumping into the news first, did you know that Colorado is home to the world's largest independent beer keg owner?
So MicroStar Logistics, they've tripled their output and become the largest independent owner of beer kegs in the world. They're basically a service provider that works with different breweries. Instead of the breweries having to own and maintain their supply of kegs, MicroStar does that. They supply them to the brewery. When they're done, they clean them, they transport them, they get them back to where they need to be.
So The— they have grown from 500,000 new keg fills in 2014 to 1.5 million fills per year presently. So these are also new, that is not total. So the amount that they are doing in new has tripled in that time. Pretty cool. They are based down in Lodo, and they have just had phenomenal growth.
One of those growth points is with Constellation, which is the brewer of brands like Corona and Modelo and Pacifico. Anyway, in case you didn't know it, we are the home of beer kegs. In other growth news, Guild Education, which is a startup here that focuses on working with companies to get their employees better educated, and not just, you know, training for their jobs, but just general education. So they work with fast food companies, retail, other entry-level type jobs to help folks get high school and college diplomas, which is pretty cool. So they are based here in Denver.
They're currently at about 240 employees, and they are planning this year to double that to about 500 total employees. As part of that, they have leased some new space in Republic Plaza downtown on the 16th Street Mall. So good luck to them, sounds like they are doing well. Another business expansion here, Amazon, you know, fresh off of their, their, I don't know if you want to call it disaster, their rejection of New York City for one of their HQ2 sites, has leased some space at 1515 WinCoop. This is essentially the spot that Chipotle has vacated as they move their headquarters to California.
So Amazon had previously been building their team here. They were using some coworking space, but they have gotten to the point now where they need some real space. So they have signed on for 3 floors of space at 1515 Wynkoop. Also just happens to be the same location that Red Canary is located. One more startup piece of news here, Strava.
Which is a physical fitness startup that they do tracking of your workouts and that sort of thing. Their headquarters is in San Francisco, but they have a very large presence here in Denver, and they just leased some new space at 1414 Wazee down in LoDo. They have about 150 employees here now, and they're only planning to grow that to be larger. Again, another good sign for the startup scene here in Denver. Strava definitely seems to be doing— growing and doing well.
Next, Denver is reported to be a top tech town for women, but it could still do better. So this year, Denver was ranked in Smart Assets' 5th annual survey for best cities for women in tech. And we were ranked at number 15, which is 2 spots up from where we were last year. This is down a little bit from the best ranking that we've had, which was several years ago at number 8. The survey shows that women in tech make about $54,500 after housing costs in Colorado, and there is about an 89% pay gap.
That's a little bit misleading. I think that means that the, the pay for women in tech is about 89% what it is for men in tech. So that is a relatively good thing. Obviously, we want that to be even better. It is 5 percentage points better than the national average, which is 84%.
So I mentioned we are number 15. The number 1 on this list was actually Washington, D.C. So good for Washington, D.C. More on the women in tech here, and not just necessarily in tech, but Deloitte has launched a program to help increase women on corporate boards. So they have a program that they've had in several other cities, and they saw a need for it here in Colorado, so they have launched that. The first cohort of folks going through the program has 19 women that hopefully will end up on corporate boards in the not-too-distant future.
There are 27 of the 111 public companies in Colorado have boards with 20% women or more. Leading that is Red Robin, which has a 50% ratio of women to men on their corporate board. So good for Red Robin. Glad to see that this is happening. I think diversity is extremely important.
Always great to get more voices in the room. So getting more women onto corporate boards is definitely a good thing. Next article, there was an announcement from Central High School in— where is this? It's in Western Colorado. I believe it is in Grand Junction.
But the, the interesting piece about this is Central High School will be one of 7 high schools that students can earn a free associate's degree for participating in a STEM program there. There's a program called Pathways in Technology Early College High Schools, which is what it is run through. This is a state of Colorado program, and it pays for the, the students at these high schools, these 7 high schools, to get a free 2-year degree as part of completing high school. So when they are done, they will have an associate's degree in one of these science-related fields. So that is pretty cool.
On the Front Range, the STEM School in Highlands Ranch is one of these 7 schools. So if you have a kid at STEM School in Highlands Ranch, they would be eligible for this program. Pretty cool stuff.
Next, there was an announcement from CenturyLink. As we all know, CenturyLink and Level 3 merged within the last year. As part of that, Level 3 had a threat research group that is obviously now part of CenturyLink, and they have rebranded themselves and they are now called Black Lotus Labs. So this is Mike Benjamin and his folks up there doing a lot of botnet takedowns and other threat research. So now they have their own cool name as part of CenturyLink that we can refer to them to.
I'm sure they're going to be doing the same cool stuff that they've always been doing. One of the things they've been talking about lately is talking about the takedown of the Necurs botnet. So we have a link here that talks a little bit about that. And the, the new name of Black Lotus Labs.
Another announcement here, Route 9B announced that they have completed their expansion of their Colorado Springs-based Global Adversary Pursuit Center. So I would normally call it a SOC or Security Operations Center, but they have a fancier name for it. When I interviewed one of the Route 9B folks, I got a chance to go see their their previous site. I think it may be the same location but a new expanded area. But they have now expanded to 12,000 square feet, which can house more than 150 cybersecurity professionals down there at their headquarters in Colorado Springs.
This includes their 24/7 security operations center— excuse me, Global Adversary Pursuit Center. So that is good for Route 9B, Glad to see that they are still growing down there in the Springs. Next, we had a blog from Ping Identity this week talking about API governance. API governance, a vital building block for API security. So this is talking about just general governance of APIs, which I think, you know, is not a direct security responsibility, but it's something that I think we can all agree will lead to better security of APIs If you look at any of the security standards, one of the first things that they ask you to do is to make sure that you have a good asset inventory, understand what it is that you have, and that's some of the things that we're talking about here with API governance.
So tracking lifecycle of APIs, what are the consumers and subscriptions and relationships around those APIs, what's the schema, who should be talking to them, you know, all the sorts of things that you need to know about those different APIs. One, this helps, you know, all of your development teams understand what is out there and work better with these APIs. It's going to help security so that you can know what's out there and what behavior that you should be expecting from your APIs so that you can better secure them. All in all, a good article. Definitely check that out if you want to learn more about API governance.
Next, Webroot had a blog post this week talking about ransomware. I think we've talked a lot less recently about ransomware. My thought was maybe it is decreasing, but the subject of the blog is ransomware threat isn't over, it's evolving. So they're talking about what the current state of ransomware is, how it's getting delivered, what sort of trends they're seeing, how people are are trying to infect folks with ransomware, you know, what those mechanisms are. Good blog here talking about where we are today with ransomware, so check that one out too.
And then the final piece of news that we have this week, we have a blog from Virtual Armor. Virtual Armor is a managed security service provider here in town, and they have a blog talking about crafting a comprehensive cybersecurity incident response program. So if you're looking to start an incident response program, this is a good blog to check out, get a good overview of the steps that you need to take to start one of those. So that is it for the news. Let's jump over and talk about our Slack message of the week.
So as you know, we have a Slack message of the week every week to highlight our Slack channel. And thanks again to Andre Gaeta, who sponsors the Slack message of the week. He's been doing this for an awfully long time, and he does it out of the goodness of his heart and the bounty of his pocketbook. So thanks again, Andre. We appreciate you being a sponsor of this segment.
So this week's Slack Message of the Week comes from Benjamin Edelen, who is the, the CISO at the City of Boulder. And he had an announcement on the Slack channel this week about an internship that they have. And while I believe we actually talked about this, um, well, sorry, we will talk about this in the jobs, uh, this week also, but I wanted to sort of double highlight this because I think internships are extremely important. It really is helpful for the security community to get more people into the workforce, and I wanted to highlight the fact that the internship there in the city of Boulder can either be a summer internship or it can be up to a 6-month internship. So if you are someone that is looking to get some experience, or you have a, you know, a child that is a student, or, you know, someone that is looking to get into the field, I think this would be a great opportunity.
Anyway, I wanted to congratulate Benjamin Edelen in City of Boulder on getting their internship in place and highlight that a little bit. We will connect him with Andre and get him his prize, which is something free out of the Colorado Equals Security store. Of course, you can find that store on the website, colorado-security.com. There is a link in the hamburger menu for the store. Actually added a whole bunch of new items to the store this week.
So you should want— if you haven't been there in a while, you might want to go check that out as well. All right. Well, let's move over to events. First, we want to again highlight SnowFROC. Tickets are on sale now.
If you haven't gotten your tickets, get them soon so that you can get out there to the Front Range OWASP conference. It is coming up here on the 14th, so I would imagine they're gonna be selling out pretty soon. The first event for the week, NCCC is doing their Beyond Bitcoin Blockchain 101 for Beginners on the 6th of March. SecureSet is doing a Hacking 101 with PowerShell on the 7th. ACES, which is the, the physical security organization, is doing their PSA Tech, which is their March 2019 meeting, and this is on the 11th to the 14th of March, so check that out.
On the 12th, SecureSet is doing a beginner's intro to capture the flag. On the 12th and 13th, ISSA Denver is doing their March meetings, Of course, on the 12th, this is lunch in Boulder and then dinner downtown. And on the 13th, lunch in the Tech Center. We already mentioned it, but SnowFROC is on the 14th. Also on the evening of the 14th is CTA's Sea Level at Mile High.
So this is an executive networking event. Basically, they get a whole bunch of people together. Great way to network. You can talk to a bunch of what they call celebrities there. Those are CIOs, CISOs, other folks in the community that have volunteered to essentially give their time as a donation so people can bid to get time with these celebrities.
Anyway, great event. You should definitely check that out. And that is the last event that we have coming up in the next 2 weeks. So let's go ahead and jump over to jobs. First, Ping Identity is still trying to fill their manager of security operations and engineering job.
So if you are someone that can run a security operations team, go ahead and check that one out. Reach out to Robb and talk to him. Vail Resorts is looking for a director of information security governance, risk, and compliance.
Ryan Dunn, who had that position previously, has left and is taking a new opportunity. So reach out to Ian Buxton and learn more about that if you like governance, risk, and compliance, and maybe skiing. Survey Gizmo is looking for a senior governance, risk, and compliance analyst. I'm sensing a, sensing a trend here. Survey Gizmo also, I believe, had a couple other opportunities open as well.
So if GRC is not your bag, check them out anyway. Lark IT and Security is looking for a senior DevOps engineer. So this is not a direct security role, but I think with any DevOps kind of position, you're going to have some security impact. City of Boulder, as I mentioned, has their IT security internship. IHS Markit is looking for an associate general counsel for privacy and cybersecurity risk.
So this is the second week in a row we've had a legal position related to cybersecurity. In the job rundown. Pretty cool. Arrow Electronics is looking for a cybersecurity automation engineer. American Mortgage Consultants is looking for an information security analyst.
Nelnet is looking for an IT risk analyst. First Bank Holding Company is looking for an information security project analyst. And Janus Henderson is is looking for a security analyst as well. So that is it for the jobs this week. And that closes out our newscast.
So coming up is our feature interview. This week, I sat down with Jimmy Woodard. I had a nice conversation with him about who he is and what he does. He has recently started the CTF discussion on our Slack channel. So he is kind of the man leading that up.
I think he's got a passion for CTFs and wanted to get folks involved and out there doing some CTFs. So listen to the interview and then check out the CTF channel on the Slack workspace. So that's it for now, and we will talk to you next week. Hi, this is Vincent Grimard, CSO at Nelnet. Welcome to Colorado Equals Security, for Colorado security professionals by security professionals.
Welcome back to Colorado Equal Security. This is our feature interview segment, and today I have a very special guest, Jimmy Woodard. Welcome, Jimmy. Thanks, Alex. How you doing?
Good, good. Thanks, appreciate you coming down and talking to me a little bit today. I'm guessing that if people are on the Slack channel, they probably have seen your name before, but I think most people probably don't know who you are. So why don't we start out with that? Sure.
Who the heck are you? I'm Jimmy Woodard. I'm currently a security and compliance engineer at Contigix. Currently that's about 90% security, 10% compliance side.
I've been there for about 8 years now, and I moved over to the security team just 2 months ago. So the security role is sort of new to me. When I first started at the company, it was actually another company, Black Mesh, which ended up getting acquired by Contigix. When I started at Black Mesh, I was like the 5th employee there, and now we've grown to over 250, I believe. So early on when we were first starting out, you know, when your team's that small, you have to do a little bit of everything.
Throughout the years, I would always try and make my niche security. Even though I was on support or help desk or whatever, I would try and just go a little bit further with security. It was always an interest to me. When the opportunity came up on the security team, I jumped for it. Is this your first full-time security role?
Yeah. That's awesome. It sounds like you've had a bunch of different experiences though. Help desk support, that kind of stuff, kind of all leading up to this, right? Like I said, I started my very first job when I was like 16, was a help desk at a small web host.
So nice. I mean, I've never had a non-technical job. At Black Mesh, I worked my way up to NOC manager and then Just, that's the position I held just prior to coming to security. Okay, so what was your thinking? Why was it that you were interested in the security portion of it?
What drew you to that? I mean, I've always been, I think I've always been interested in security. I've been the type to just take things apart as a small kid, just really try to see how things work. You see a sign that says, do not enter, employees only, and you want to know what's in there.
Grew up reading 2600, the Hacker Quarterly, at a young age. My father was in the intelligence community as something like a sysadmin ever since I was a kid. So even in the early '80s, I was born in '85, even in the mid and late '80s, I was around BBSs and stuff like that. Nice, good stuff. Obviously, to move from a non-security role to a security role, you have to have some experience in doing the security pieces, right?
I'd imagine you've done stuff on your own to try and hone your skills, scratch the security itch, I guess. Yeah, absolutely. I mean, I keep a home lab at home, participate in CTFs, which is actually why you asked me to come in today to talk a little bit about the involvement in— my involvement in CTFs and how we can get more people interested in that on the Slack channel and stuff like that. Yeah, awesome. Yeah, so exactly.
So over the past, I don't know, couple weeks or so, it seems like there's been some more chatter in the Slack group about doing CTFs and about people interested in that kind of stuff. And so I think, was it just last week that you popped up and said, hey, can we start a CTF channel? And so you're kind of the founder of that piece of the world in there. So what was your thinking around doing that? Just the need for one, you know.
I was getting started on Texas A&M was hosting a CTF this past week. It was a 7-day-long competition. Usually most CTFs aren't that long. So I knew I was going to try and compete in it, and I just wanted to see if I could get a couple other people involved. And luckily, you know, it worked.
We actually did pretty well. The competition's not over yet, but last I checked, we were in like the top 10% of all public teams in the public bracket, rather. That's awesome. How many people did you get participating with you? I think at most that I know about was maybe 4 people, and there was one other one that actually scored a couple of the challenges for us.
So between me and that guy, we did pretty well considering it was just 2 of us. That's good. So what really drew your interest to doing CTFs?
I don't know. I think probably seeing it at DEF CON. At DEF CON, there's like 3 main formats for most CTFs. There's the attack and defend, which is the kind they have at DEF CON, which was, I believe, historically the first one at DEF CON. Where you're given like a network with some hosts on it, or maybe it's just one host, and it has some services on it, probably vulnerable, or well, definitely vulnerable services running on it.
And your team's job is to not only secure your services, but then go and attack the other team's vulnerable services. So once everybody, you get a set amount of time, Blue teams can up the defense and the red teams can start looking at attack vectors on those services that they have deployed on their machines.
Once the time runs out, it's go time. Everybody connects up to the network and then it's just basically a war game. Mass chaos. Right. That's one type.
I've never played in that type before. There's the second type, which is Jeopardy. That gives you like kind of different categories, and then in those, each category will have different challenges. And then some challenges will be worth more points because they're harder. The easier ones will be worth less points.
It's popular for a CTF to have the points, the point value drop as the competition goes on. The more people that solve a particular challenge, the less that you'll get for solving that particular challenge.
Sometimes questions or challenges will remain hidden until you solve like their prerequisites.
That's pretty common. And so that's basically the way Jeopardy works. And then there's a third type of CTFs which is mixed, which is kind of like a combination between the first one, but it'll also have, you know, a specific time frame where you're doing some of the Jeopardy style challenges. Nice. And which style was the Texas A&M competition?
This one was a Jeopardy challenge. And the reason— the other reason besides the length of this one that drew me to this one was it's one put on by a university, and those are typically a little bit easier. You know, nobody wants to go into a CTF their first time and and not get anywhere on it. You'll probably just be turned off to the idea.
This is the best I've ever done on a CTF too, so my interest in them has probably exploded more than it ever has in previous CTFs. Nice.
I know that there's probably not a super big strategy behind creating the CTF channel and what you're thinking about there, but what are your thoughts? What are you looking to gain out of getting people involved in the channel? Well, I think my real goal is I'm actually interested in bug bounty, right? And a lot of the CTF challenges kind of scratch that itch a little bit, but my technical skills I don't feel like are to where I can actually be out hunting for bugs.
I just don't feel like that's a proper use of my time right now, just with my current skill set. So it scratches that bug bounty itch, and who knows, maybe we can get the best people from that CTF group to actually start doing group bug bounty type stuff. Nice. So I think I saw a couple on the list that you have Do you have specific ones that you're aiming at the group participating in coming up? Yeah, so I'm basically just looking at, there's a website that basically keeps track of all the CTFs that happen and they also keep an aggregate score of how well each team does in every competition throughout the year.
So I'm sorry, what was the question? No, so what's the plan? What's coming up? What are you— Oh, right, right. So basically I just look at that list and if there's an English language CTF, you know, it's going to go on the events list on— or I'll send it to you and you can put it up on the events calendar on Colorado Eco Security.
Yeah, so I think that that's going to be pretty cool. It's always great for people to have a place to practice their skills, to get better at their skills. And now we've got, you know, sort of a semi-organized group of people that can get together and do this stuff on, on specific challenges. You know, we've got the Slack channel where people can come and talk about it. You guys can share what's going on, you know, what you're doing on the individual CTFs.
And yeah, as you mentioned, you know, as you guys work as a team in different ones, we'll we'll post on the events calendar when there's going to be a CTF coming up so people can go there and look, see that there's a CTF coming up, and if they've got the time and want to participate, then they can jump in with the Colorado Digital Security team that's in there. Yeah, the next one is actually, I believe it's this coming Monday, it's the BSides San Francisco CTF, so that one should be a pretty good one as well. That should be a good one. I won't be at BSides, but I will be in San Francisco for RSA. So if I run into any Colorado people that are out there, I'll tell them that they should be participating in that.
And that one actually, that's an online and in-person one, right? If I remember right. That is correct. A lot of the time, some of the CTFs will have prizes. So if you're usually, they're only, you're only eligible for the prizes if you're in person.
But I mean, there's all kinds of formats. There's online, there's in-person, there's online and in-person. Nice.
Well, I'm really excited to get this going. I think that there's going to be a desire from people to have more time to hone their technical skills and have a— it is always sort of intimidating, right? There might be a CTF that's out there, you don't know where to start, you don't know how hard it's gonna be, you don't know if you're gonna be any good at it. I think this will really help and kind of get people, you know, pushed and going in that direction. They'll have a group of people they can talk to, figure out what's going on, you know, probably some coaching too, right?
If somebody figures out some of the challenges and other people can't figure them out, then, you know, talk through it, figure out, you know, what it is that you had to do to get that flag and get everybody learning? Absolutely. Like I said, it's one of the worst feelings in the world entering a CTF, you know, that's not a beginner one and just not getting anywhere with it and not having anybody to talk to on top of that about that, you know. And I've been there before, you know. My first CTF probably turned me off of the idea for, I would say, 3 or 4 years, I would say.
I really want to prevent that from happening to as many people as possible. I think this would be a great opportunity too. We have a lot of people that are in the community that are either new to security or are students.
Again, another avenue for people to get involved and get that experience and get those skills. I'm looking forward to see what happens. So anything else you want to talk about related to CTFs or what you got going on? Yeah, I've got a couple of just common questions that some people have for CTFs here. If you want to know more about the different challenges, the different scenarios within the Jeopardy-type CTF, those are Commonly you'll see things like web where you're given like a URL to scan and, you know, you start scanning it.
Maybe you uncover a directory that wasn't supposed to be, you know, have public access. Who knows, maybe it has a file in it. You know, what's in the file? You know, that information could lead to another avenue or directory which, you know, you go check out and then eventually you get the flag. And the flag in a CTF is meant to represent the data that we want to protect, right?
Or that the bad guys are usually after. It's going to be your personally identifiable information, health information, financial information, stuff like that. So the flag is a representation of that type of data, right? Sometimes you'll log on to a server and you won't have the correct rights to read the file that has the flag info in it. And you'll need to figure out a way to escalate your privileges and then gain access to that data.
So CTFs do have a lot of real-world scenarios that you might find actually in the real world. So it's not just a game, it's actually real practice for real-world scenarios.
Some of the other different types of challenges you'll see are like forensic or steganography, where you'll have data hidden inside of pictures or Maybe there's a file that's been encoded in another file and you have to file scrape it out is what they call it.
Sometimes the flag will be hidden in a PDF, but it'll be hidden as like a JPEG.
There are binary challenges where you're actually using a disassembler to look at the assembly code and try and do things like buffer overruns and stuff like that to obtain the flag.
Another topic that I'm not very good at is crypto, and that's all aspects of cryptography. One of the solutions to the recent TAMU CTF was one where they gave you ciphertext and it was just Morse code. And, you know, you transform that into text and then that text was— I recognized it as being hex ASCII, so I just decoded that and then, you know, got the flag within the plaintext there. Some of the other common ones will be like analysis. So you'll be analyzing things like packet captures, and they'll give you a scenario like, hey, we know the web server was attacked.
They exfiltrated this data. Can you tell us what ports were they using to exfiltrate, what protocols, things like that? And then the answers will then unlock the flag for that question. So I mean, it's all around. No matter what your specialty is in security, there's probably a category within most Jeopardies where you'll at least have some idea of what you're doing.
Nice. Cool, what else? If you're more interested in doing CTFs or just seeing how they run, checking out some of the answers to past CTFs, we've participated in, just stop in the CTF channel at colorado-security.slack.com and say hi. Nice. Yeah, so if you go to the colorado-security.com website, there's a link there that'll take you to Slack, or you can go to colorado-security.slack.com and get to the workspace, join the, the CTF channel there, find more information.
Hit Jimmy up. We'll have— as these come out, we'll get these events on the event calendar so you guys will be able to see them in advance. And then we'll start showing everybody how great the Colorado security community is at CTFs. So it should be fun. Yeah, hopefully we won't— we'll have more than 4 in the next one.
Hey, got to start somewhere, right? I agree. Nice. Well, thanks, Jimmy. Appreciate your time.
Good talking to you. Good. Thanks a lot, Alex. Thanks for having me. I'm looking forward to see how the, the CTF channel grows.
And this has been Colorado Equals Security. We will talk to you next time. Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.