Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is a newscast for episode 108 for the week of March 11th, 2019, and this is Robb Reck. And this is Alex Wood, and we're back together.
It's been a few weeks back together and it feels so good. Oh, I'll be totally honest. It doesn't feel as good as being in Mexico laying on a beach. Okay, I'll grant you that. Or not together in the rainy weather in San Francisco, right?
Yeah, we so I had a weekend in just south of Cancun with just my wife. The the kids were with grandparents. Was unbelievable, and a little bit of context for everyone. If you were in Denver on the the Saturday before that, I can't remember what time I. What the date was, but like the 20th or whatever that was, I had to— we had a really early flight.
And so to get to the Uber, the Lyft actually, to take me to the airport, I had to shovel about 8 inches of snow. That is perfect. At 3 a.m., 3 a.m., I go, I go to go out to the car and I'm like, oh my gosh, there's this much snow. So my wife and I both shoveled snow to get out to the car. And of course, to make sure that your shorts and your flip-flops because you're going to Mexico.
With the shorts and flip-flops underneath all of the butt layers, right? So we go to Mexico for a full week. Fantastic. Come back that Saturday, the 2nd of March. And, and if you guys remember last Saturday, it snowed that night overnight.
It was another like 6 inches at my house. I got up on Sunday and I shoveled snow to get in, to get to the lift to take me to the airport to go to RSA. So that was my Colorado experience for that week. That sounds like fun. Of course, we enjoyed a lot of rain in San Francisco and we made it back safe.
We did. Did you have any highlights of the trip? You know, RSA gets bigger every year. I wouldn't say bigger and better. You know, I had a good time, learned a few things, but it's always nice just seeing people and sort of getting the experience.
Yeah, there are— it is fun to have sightings of friends who I only see once a year and who I'd like to see more often. I think also it's funny because the basically the entire cybersecurity world is there. You know, you'll be walking around all of a sudden, it's like, oh, hey, there's Marcus Ranum. Yeah. Oh, there's Mikko Hypponen.
There's, you know, all these people that are, you know, sort of celebrities in our world. You just— they're just walking around with people doing whatever they're doing. It's pretty great. Yep. All right.
Well, we have a little bit of housekeeping to talk through. Alex, we have a Slack channel. We do. This is news to you or what? We just surpassed 800 people finally.
We've been talking about that coming and And we're well on our way to our next milestone. I think we were at 802 last I saw. We're almost to 900. Yeah, uh, we also have a mailing list, so go to the website colorado-security.com, sign up for that. You'll get the show notes in the mail, uh, every Sunday when we release a podcast.
On that same website, you can also find the link to join the Slack channel if you want to make it easy on yourself. We would love it if you would rate us and subscribe to get the podcast from your favorite listener. You don't have to go Scourging, scavenging, scourging, scouring, or scavenging. I'm not sure what I'm trying to say. Scourging.
It's fine. You don't have to keep looking for the podcast every week. It can be delivered directly into your, your player every week. And if you do that, you should rate us also and tell everyone how great of a podcast it is. Yeah.
While you're telling people about the podcast, why don't you tell one of your coworkers or friends or a lover?
Tell one of these people about the podcast. We'd love to have them listening. And, you know, it's one way— it's one way you can support the show.
If you want to support us financially, you can also go to our Patreon page. Again, you can find the link to Patreon on colorado-security.com and you can support us financially. Give a little contribution that we can use to pay for the costs of running the podcast. All that bandwidth. That's right.
It all comes out of our pockets. You know, we pay for this out of the goodness of our hearts and our Patreon supporters. So we'd love to have more on there. We do appreciate it. And, you know, Alex's pockets are relatively empty.
So, so really, this is helping out. Alex and Tammo would appreciate it very much. Next, speaking of Patreon, we have, we have a new patron to thank this week. We do. Big thanks to Josh Stewart.
Josh has signed up at the $10 a month level, which is Awesome. Josh, thanks so much for your support. Yeah, uh, Josh is actually interning for us at Pulte Financial Services, and by no coercion of mine, he signed up to support the podcast. So thank you, Josh. Appreciate it.
Appreciate that. As a benefit— as a couple of benefits he gets for sponsoring us at that level, uh, he gets a Colorado Equal Security shirt, and he also gets the shout out on the show. So here's your shout out, and Alex is going to bring you your shirt. All right, let's jump right into the news. First article, does Hyperloop transportation have a future in Colorado?
You know, don't leave me hanging, Alex. Does it? Well, I am going to leave you hanging, Robb, because a couple of weeks ago we had a similar story to this. This one goes into a little bit more detail. CDOT is actually just finishing up a transportation study that should be released soon, talking about the possibilities of using this type of transportation in Colorado.
And they talk about 4 potential companies and their solutions. Um, that they could, they could be used in Colorado to help us alleviate congestion and get places really fast. So I don't know if we, we haven't talked about Hyperloop in a while, like in terms of what the technology is. Um, I think, correct me if I'm wrong, there are different ways that one can do it. Um, some of the Hyperloop technologies are kind of like a vacuum-ish tube that trains go shooting through.
No, no friction. It can go super fast. Is that what we're talking about here? Yeah, the, the 4 companies all seem to have slightly different variations on that, but I think more or less it is some sort of pod in a tube. Right.
Yeah. Awesome. Looking forward to that. I would love it if we could, you know, get rid of all of our traffic woes and just, just beam me over where I'm going. Exactly.
It was like 400 miles an hour or something like that. Yeah, I think one of them they were talking about goes 150 and some of them go several hundred miles an hour. So awesome. Well, our next story is is around— excuse me, from Denver Business Journal— that Colorado is in the top 10 for venture capital deals by female co-founded companies in 2019. Yeah.
So Colorado tied for 8th with Pennsylvania in states ranked by the amount of U.S. venture capital involving female co-founded companies in the first quarter of 2019. Right. So not a lot of data yet, but 7 deals already this year. That's pretty great. And especially considering I recently have heard that we don't necessarily have lot of females in boards in Colorado.
It's great to see we do have a good representation of co-founders in the state. Uh, also nationally, startups with all female founders received $2.9 billion in venture capital in 2018. That's a pretty good amount of funding. I've never received anywhere near that much. Have you asked?
To be honest, I have not asked. All right, uh, so congratulations to all those ladies getting some money. Next, Fort Collins is partnering with a tech firm on a smarter street sweeper program. Say that 10 times fast. Smart street sweeper.
So is this some kind of like a training, on-the-job training that they're giving for their street sweeper staff? No, it is smarter than that. No, not that at all. It doesn't sound like they're, they're completely automating this, but it does sound like they're putting some some software along with their street sweepers to help make the paths better and optimize the routes that they use. Are they using blockchain technology along with their AI and ML?
If they're not, then they are silly. Well, you know, one thing that we could— we don't have the story in here, but we did just see some news this week about Denver going to blockchain-based voting for— what is it— for deployed military? Yeah, I believe it is. I think we, we saved that story for next week. Well, now we didn't.
So what? Okay, well, let's talk about it. I'll throw that into the show notes. Did, have you read the story? Are you ready to talk about it?
Uh, I'm not, but we will anyway. Um, let, let me find the story here, Robb. Can you tell we've taken a couple weeks off, people? So this is about people in Denver being able to vote on their smartphone, and this is similar to a, a pilot project that was run in West Virginia. Uh, for the last election, it's gonna be limited to overseas voters and military.
Uh, I think that's about 4,000 voters in Denver. So does, what kind of problems does this actually solve, Alex? Well, I'm glad you asked, Robb. There are actually 2 problems that this can potentially solve. Uh, first, it replaces older technology that's already in use, which is something that they have to do per, um, uh, per regulation.
And, and, The older technology uses email, which is, which is awesome. You always want your votes to be going over email. Email is, is like 99.9% secure, Robb. So I would trust that. Yeah.
That's more secure than most things, more secure than the blockchain. And then the second problem is that especially with these types of local elections, there's often runoffs. So there, there's not a whole lot of time to have the first vote count those votes. And if they're using paper ballots, remail those paper ballots to someone overseas, and then get them back in a timely manner. So having the electronic method, it can also help them go faster.
So as you described this, this fantastic voting system to me, it's clear that this is the only way you could do this is via blockchain. So I'm glad that that technology's finally enabled us to make that step. Yes. They do note in the article that they keep their blockchain private. It is not on public servers like Bitcoin, for example.
I would love to have a t-shirt that said, I keep my blockchain private. I bet we could get John Dixon to make us a t-shirt like that. I am right now wearing John Dixon's most recent shirt. You want to read this for our listeners? It's Robb is now part of the Huawei US network management team spying on all of us.
All right. Next story. There's a new ISP coming to town called Starry, and they're offering— it sounds like— was it— oh, shoot. It's high density. Yeah.
Millimeter wave. Millimeter wave for high density like condos and apartments. Yeah, it sounds sort of 5G-ish, but they're not actually calling it 5G. I think it's pre-5G kind of technology. But yeah, you put a large broadcast device on, you say, on the top of an apartment building, and then everyone in the apartment building would have the ability to subscribe to the service.
Kind of an interesting factoid here: this company spun out of Aero. I don't know if you if you used Aero. I actually did. I did. I loved Aero.
Aereo. Yes, Aereo. Yes. So they were the one. They were the service that would allow you to stream broadcast television to your TV so you didn't have to have an antenna in your house.
And I don't think they also gave free DVR or DVR included in the service, at least. Yeah, they tried to kind of skirt the rules and make a giant array of micro antennas so that you had your own little micro antenna to technically be in compliance with the law. But then they still got the Supreme Court Yeah, killed them. And of course, but Starry has spun out of that. So it's nice to see something good come from that.
Very true. In other startup news, there was big news over the last week. Drumroll. ProtectWise was acquired by Verizon. So ProtectWise is one of the, you know, midsize, biggish security companies here in Denver, Colorado.
They did the network, network kind of intrusion intelligence stuff. They called it a DVR for your network. Right. Um, started by Scott Chasin, who's been a serial entrepreneur, quite successful. I think that the category that was, uh, coined for that was like NDR.
I think there's some other people in that space now too, but ProtectWise was definitely early in that space. And I don't know if they were a leader or not, but they were definitely unique in that space. Yeah. So they've been acquired by Verizon. You know, we don't have any details about the finances of it.
I will say that, uh, you know, the last couple of years, ProtectWise seems like they, they weren't moving forward quite as quickly. So hopefully going to Verizon will help, you know, propel this product into new areas and help them be more successful. Yeah. So hopefully congratulations to that team. Hopefully this is a good thing for them and they will be able to make things better, even better at Verizon.
We had Scott Chasin, the CEO and founder, on the show 2 years ago-ish. So maybe we can twist his arm to come on the show again and talk about the exit and what's next for the Verizon— or excuse me, the ProtectWise. I guess it is Verizon, the Verizon team, now that they've teamed up. That'd be cool. Next, speaking of Colorado companies with some news, this one's maybe not quite so good.
Swimlane, who is our friends over there, they were removed from the RSA conference for not adhering to— this is a quote— to monopoly rules. An RSA conference was unavailable to comment. Yeah. So this is a quote from Protect or from Swimlane, not from the RSA conference. This is a press release that they, they released basically as soon as they got kicked out of the conference.
Right, exactly. So They sort of as a PR stunt, they pro— they staged a protest out in front of the Moscone Center. They had a number of what they were calling security analysts who were protesting the large amount of security alerts and too many alerts and the lack of automation, many alerts, which, hey, surprisingly, Swimlane's product helps solve those problems. So they were standing right outside. What is that?
That carousel right next to our Moscone conference with their signs protesting and I guess RSA conference didn't like this. Yeah, strangely enough, I actually walked through that protest. Did you? And I didn't even realize what it was at the time. I was like, what is all this stuff going on?
And that was a Marriott picketers. Something. Yes, you see those all over the place. So I didn't realize what was going on. And then later I heard actually from you that they got kicked out of the conference.
So there's some interesting quotes in this press release. Very, very clearly, Swimlane is not real happy with what happened. Their CFO has a quote here that says, I think that RSA conference has wronged us in perhaps an irreparable way. So very strong language here. It'll be interesting to see, you know, if anything comes out of this.
And, you know, certainly sorry to hear this happened. There is kind of sad to see their booth all kind of curtained off after they got kicked out. It was interesting. They— the conference did not take the booth down. They just put up black pipe and drape around the booth so that you couldn't get to it, but you could still see the top of the booth, you know, over the pipe and drape.
So anyway, I guess Swimlane is still getting a little bit of PR out of it, even though it was maybe not the PR that they wanted. Well, people are talking about it, right? Yep. Go ahead. Next, one more Colorado product announcement.
LogRhythm announced a new solution, LogRhythm NDR, an automated network security solution for detecting, qualifying, investigating, and responding to advanced network-borne threats. So does this— is this a replacement for NetMon? Is this in addition to NetMon? What do you think? Yeah, my take on it is this is a slightly souped-up NetMon with a new name.
So, because I mean, NetMon's been a pretty cool tool for watching your network traffic. Yeah. And they've had even those, those, uh, pretty neat contests they did. Remember about a year ago? They had the Home Edition that you could do and, you know, come up with a detection and win a prize.
So, so it looked like, uh, this new one has some kind of IoT focus on it. They're trying to, to have some rules specific to IoT. I'm not sure what other specifics there are with the new version, but it's obviously great to see them innovating and coming up with new solutions for us. Yeah, I look forward to testing it out. So there is a blog post this week from Andre Durand, the CEO and founder of Ping Identity.
Is willful ignorance influencing your enterprise security decisions? So Alex, this is a question for you. Are you willfully ignorant? I might be ignorant, but I don't think it's willful, Robb.
You're unknowingly ignorant. I like it. Yeah. Uh, so, so really, I think that the summary about this is, you know, are, are people choosing just to ignore the facts that they know around security? Is that about right?
Yeah. And there was, at the beginning of the article, they, they talked about, uh, some sort of psychology research talking about how this is, is sort of a human trait. You know, anything that is kind of, uh, going against your, your own ego, you kind of push back against it, right? So that's sort of a natural tendency of humans. And Andre's supposition here is that, you know, that sort of pushing back may be holding us back in certain areas in security.
Yeah. And I think it's people's unwillingness to challenge, you know, the way we've always done things, right? Anytime you look at, hey, well, so far what I've done has gotten me here, it's kind of the natural assumption is what I've been doing is going to get me where I want to go as well. Yeah, no one likes to have their baby called ugly. Um, you know, if you, again, to your point, if you've done things well, you like to think that you can still do them well.
And maybe you don't have to challenge all the assumptions that, that you have. And I do think it's a, it's a fair point. And something I try and take into my own program is what, you know, the risk appetite that all of our organizations should have when we're very young should be significantly higher than our risk appetite later. When, when your biggest question is, will my company survive? Does my company have a product that's worth, you know, the market even caring about, you should probably be pretty risky in how you go about doing things.
But later, once you've already established you have a great product-market fit and you actually are growing as a company, all of a sudden the security risk starts to be something that's worth managing. Yeah. And to that point, you know, if you make a lot of assumptions at that— the beginning of that life cycle and you don't go back and revisit those, then you are probably missing out on things. And, you know, whether that's willful ignorance or not, I think it's definitely good to challenge those assumptions from time to time. So our next couple stories, I think, kind of go hand in hand.
We are in the, you know, in a state with a lot of winners. The Colorado security companies are cleaning up this week. Winning. We are all winning. Hashtag winning.
That's right. So this is the time of year at RSA when there are a number of award shows that happen. So CyberGRX, they took home gold in the 2019 Cyber Defense Magazine InfoSec Awards. And Infosecurity PG's 2019 Global Excellence Awards. So one trophy in each hand?
I think so. Double fisting it? Well, hopefully the award shows weren't at the same time. They would have had to send 2 people, and then they would have to fight over it. I know they have at least 2 people.
I think they probably have more than one, so they can probably manage. Uh, well, and then next, Managed Methods won an award for the best SaaS cloud security product. Yeah, and this was for the Cyber Defense Magazine InfoSec Awards. So congratulations to both CyberGRX and Managed Methods. Obviously they are doing something right.
All right, big news, lots of news this week out of the Colorado security scene. But that's it for news. Let's go ahead and move over to the Slack message of the week. Big thanks to Andre Gaeta, who is our sponsor on this. Andre, we appreciate you very much.
The winner this week is Michael Stephen. Michael had posted the kind of breaking news around Chronicle, which is one of the Alphabet, which is formerly Google, right? Um, it's a lot of things. Uh, anyway, Chronicle has a new product called Backstory, which is really kind of their network-ish Splunk. Yeah, the internet Splunk, I guess.
It sounds like, um, hosted, sort of hosted Splunk, right? Yeah. And reading some of and hearing about some of the things that they talked about, it sounds really cool. So big thanks to Michael for posting that and sharing it with the community. Um, he'll get to pick something from the Colorado Equal Security store.
I know that there are some new things in the store and I'm excited to see what Michael picks from the brand new selection. Yeah, I added a bunch of stuff, so go check it out. And thanks for Andre Gaeta for sponsoring the Slack message of the week. We have a calendar of events on the website as well. If you want to go take a look at what's coming up in the community over the next several months, you can go out there and see it.
This week is the big conference, the, the big OWASP Denver conference that's going to be on the 14th at the Cable Center at So you guys can take that, take a look there. I will be there at least for part of the day, probably not the whole time, but looking forward to that. I'm really unhappy I'm gonna miss seeing Troy Hunt kick the event off, but that should be pretty interesting as well. Yeah, and I will be there as well, so I look forward to seeing people there. So let's, I guess let's talk about all of our events.
We just talked about SnowFrock. On the 11th through the 14th, ASUS is having their PSA Tech event, which is their March 2019 meeting. On, uh, on the 12th, SecureSet is doing a beginner's intro to capture the flag. On the 12th and 13th, ISSA Denver is doing their March meeting. On the 14th, after you go to SnowFROC, you could see— you can go over to Mile High Stadium and watch the Sea Level at Mile High event.
You can go bid on hanging out with your favorite technology celebrities. I know that there will be a number of CISOs there. I'm going to be there at the event, and come say hi if you make it. And, uh, I believe it was last week we talked about, um, we talked with Jimmy Woodward, um, about CTFs, and I mentioned that we were going to be putting CTFs into the event calendar. So this is our first one.
On the 15th, the UCSB ICTF for 2019 is happening. So if you go to the Slack channel and check out the CTF channel there, you can find out more details. And participate with the Colorado Equal Security team. Awesome. On the 19th, the Cloud Security Alliance is doing their March meeting.
You guys can join them there. Uh, and then on the 21st, ISACA Denver is doing their March chapter meeting. Fantastic. Let's go ahead and move over to jobs. Actually, before we jump to jobs, I do want to look a little into the future, Robb.
Let's do it. Rocky Mountain Information Security Conference is June 4th through 6th. And we have all of our keynotes 100% locked in. So let's not give them all away at once, Alec. That's, that's a lot of giving away all in one week.
What should we start at the beginning? Why don't we start with the first one? So we are again going back to an opening keynote this year. So that will be the evening of Tuesday, June 4th. Michelle Dennedy, who is the chief privacy officer for Cisco, is going to be kicking off the conference for us.
That's going to be fantastic. So we're going to have the community day on that Tuesday. There'll be some training events. Then there'll be the job fair. Yep.
And so even some meetings from local chapters, right? So we are not doing the local chapter meetings this year, but there will be the job fair. Yep. A reception. And we will have Michelle Dennedy speaking.
Awesome. Looking forward to that. And will there be alcohol? I believe that there will be alcohol as it is a reception. Food even.
Fantastic. And maybe next week we could talk about the keynote that's going to kick off on Wednesday. Yes, I think we can do that. It's a nice teaser. All right.
So now we can jump over to jobs. And you can kick that off, Robb. All right, I, I am hiring a few different positions at Ping right now. Uh, top of the list, I'm hiring a manager of security operations and engineering. Um, if that's— if you want to come help us run our security infrastructure program, I'd love to hear from you.
We're— a new one that just got posted, I didn't, I didn't even know that it was posted, and Alex found it for the show notes. Thank you for doing that. We're hiring a new product security engineer. This is really an application security engineer if you are a former developer or a current developer even who wants to get more into security and helping us build security into the software development lifecycle, I want to talk to you. This, this is a position that's, uh, it's going to be really fun.
We are also, uh, look, it's not posted quite yet, but reach out to me if you want to talk about it. We are also looking to hire a, a leader for that team, a product security team lead who's going to help us. Basically, we want to divide the team up because we've got too many engineers for one person to, to lead by themselves. Someone to help lead a team of about 5 different engineers. So is this a management role, Robb?
It is. It will be a team lead that we will— we're thinking we'll turn into a manager here in the next year or so, basically depending on who we hire. If we hire the right person who wants to be a manager right away, we could probably make that happen immediately. We got to figure that out. Gotcha.
Moving beyond the Ping Identity jobs, CenturyLink is looking for an information security lead penetration tester. They also had a senior information security lead job posted as well. So if you're more senior, you can apply to that one instead. And, you know, just as a little bit of a teaser, it's not this week, but we did just sit down with the new CSO over at CenturyLink, Chris Betts. And if you, you know, if you want to know more about that program, give it another week or so and he'll be on the show.
I'm looking forward to it. I did meet Chris at RSA, but I'd like to hear more. Next job, NBCUniversal is hiring a cybersecurity senior Active Directory architect. That's interesting. Yeah, that does sound interesting.
Most Active Directory architects are not specifically focused on security. Agreed. And not cybersecurity even more so. Yes. Um, Altvia is looking for a security and IT manager slash DevOps engineer.
That's a lot of hats. So this was an interesting looking job too. Um, it looked about half security and half DevOps engineer. If you are someone that maybe is looking to get more towards management and security, but also, you know, keep your hand in the technical world, this might be a job for you. Bank of America is looking to hire a senior information security officer, parenthetically, Bison.
I'm not sure what Bison is. Is that not what that says? No, no, that says, that says BISO. Oh, sorry. Almost, almost the same.
Connect for Health Colorado is looking for a security analyst too. Uh, the Gaming Labs International organization is looking to hire a security specialist slash entry level. You hear this, everyone? Entry level. Yes, it did look so.
5 years experience required, CISSP, uh, PhD. I'm just kidding, guys, just kidding. Uh, Ball Aerospace is looking for a technical intern in cybersecurity. And finally, CrowdStrike is hiring a channel solutions architect focused on the, uh, this region, the central slash Midwest region. Cool.
Well, that is it for the news this week. I think we're gonna kick it over to the feature interview, which is with James Condon. Oh yeah, James. Yeah, I wanted to get this one released pretty quickly because James actually was at ProtectWise for— I think he was like employee number 9 or something like that. So we get a little bit of ProtectWise conversation, and especially relevant since they just got purchased for sure.
But he's not there anymore now. He actually moved to Lacework just a few months ago, and we get to hear about his path and Uh, and what he— where he sees security going. Awesome, sounds like fun. All right, Alex, that's, that's good. Good to be back doing this, and we'll look forward to talking to you again next week.
Sounds good, Robb. Hello, this is Stanton Meyer, CSO of CoBank. Welcome to Colorado Equals Security, for Colorado security professionals by Colorado security professionals. Welcome to Colorado Equals Security. This is Robb Reck, and I am sitting with James Condon today.
James, you are currently— is it the director of research or threat research? Director of research at Laceworks, which we'll get to learn about Laceworks. To be honest, I didn't know them until, you know, several months ago. I think, you know, probably about the same time you went over there is when I first heard about Laceworks, and I'm looking forward to having you tell us about that. But as you know, I like to start these interviews by getting a little bit more of the personal touch, and what I just found out is you're a native Coloradan, but you didn't grow up here in the middle of Denver, right?
Yep. So talk to me about where you're from. Yeah. So, um, native to Colorado, uh, grew up in Conifer and then specifically in Conifer, grew up on top of Conifer Mountain, which was pretty cool because our house was at 9,600 feet. So we kind of had like this different, like, uh, elevation that you don't normally see, uh, in the lower parts of the foothills.
So had a pretty unique experience growing up there. Lots of— so what's the elevation of Conifer, like, proper? So Conifer proper, like Conifer High School area, it's about 8,200 feet. Okay, so another 1,000+ feet lower. I know, is it— was it Leadville is the highest town or city in Colorado?
Yeah, and it's like just over 10,000, so you guys are really not too far from that. Yeah, so we were pretty close. I mean, it's almost, almost the 10,000 mark. Uh, the very top of Conifer Mountain was 10,000 feet. What's the tree line?
How high is the tree line? The tree line I think is between 12 and— okay, quite a bit. About 12, around there. Okay. Yeah.
So what is it like to grow up on the top of a mountain, you know, not too far away from— so for me growing up, it was a blast because, you know, I didn't have to, you know, deal with commuting down to work or anything like that, but kind of more of the interesting things is, you know, we'd get so much snow. So during the school years, we were part of the Jeffco School District. And to get a snow day, you know, the schools down in Denver that were in Jeffco would kind of need to make the call. So growing up on Conifer Mountain, you know, we'd get a snow and then we'd have, you know, 5-foot snowdrifts, you know, blocking the door and things like that. And then, you know, we'd get and watch the news and look for the scrolling, like which schools were closed, and then Jeffco would be open.
And it would just be kind of crazy because we're like, we don't even know if we can get to school. So the buses would come. It would take them an hour later than usual. And then we would go down the hill. Sometimes we'd get stuck.
We'd get to school sometime around noon. And then by the time we'd get there, they'd be like, OK, you know what? We need to send everyone home because the snow's too bad. And so then we'd get home about the regular time because we'd get stuck again and stuff like that. So school was an interesting experience.
But we had a good time because had a couple acres on a pitch. So during the winter it was, you know, doing lots of sledding, you know, snowboarding in the backyard, fun stuff like that. Things that people travel to the mountains to do. And then in the summer we actually leveled out an area and we built a sand volleyball pit. So— Oh, really?
We were able to, you know, have summer nights doing some fun stuff there. So are you a good sand volleyball player? It depends on how you how you define good. So if it's someone who doesn't competitively play, then I'm alright. But from a competitive standpoint, like an actual team, no, I wouldn't be.
We play more for fun. Yeah, absolutely. That's awesome. So you grew up in Conifer on the top of the mountain. Did you graduate from Conifer High School?
Yep. So went to Conifer High School. It actually opened I think it was 2 years before I went to high school, so it was pretty new. Then after Conifer High School, went to Colorado School of Mines. Oh really?
I don't think I knew that. That's great.
You went to Mines and what did you— it looks like you majored in computer science there? Yeah, so majored in computer science, was on an Air Force ROTC scholarship, also did cross-country and track. My junior and senior year. So it was a fun time. I loved it.
Golden was like a great place. The atmosphere of the school, you know, it's really small, so you kind of recognize everyone on campus. Everyone has a similar focus, so it was great. I loved it there. And when you went there, were you like thinking, hey, I want to be a computer guy, I want to be a security guy, or was it just, I like— you have an affinity for computers, so you went after it?
What was the intention? So it was actually kind of interesting. I enjoyed math and science, particularly math. I would say that was kind of my strong suit in high school, so I figured I'd probably major in something engineering-ish. In high school, I liked writing programs for my calculator, whether it was for math stuff or games.
So I was like, maybe computers and programming might be a good fit. And then initially when I got the scholarship, it was for a technical degree. At first I was like, physics sounds really cool. And then after doing your first year of physics at Mines, I was like, okay, this is not something I'm super excited about. So I switched to computer science my sophomore year, and that's kind of how I ended up there.
Did you have an end in mind? Like, hey, I'm in computer science so I can do X? No, so I actually didn't have an end in mind because I was more focused on, you know, careers in the Air Force and things I might be doing there. So I kind of had looked into a different— a few different career options, and I was at the point where I was like, you know, I might be doing something computer-related and it might be something that I'm not. I was kind of seeing where things would go, but it was more to do something I enjoyed.
During college that I know, you know, might come in handy later. Okay. So you graduated from School of Mines and then obviously ROTC. I assume that means you were basically signed up to go join the Air Force immediately, right? Yep.
So the way it works is you do ROTC. There's kind of 2 different ways you can do it. You know, voluntarily where you can do the first couple years with no commitment, or you go in on a scholarship and then after your sophomore year is when you have a commitment that once you graduate, you're going into the Air Force. So I knew early on since I was doing a scholarship that that was the route I was going to go. And then we had a small group of folks at Mines who did ROTC, but our main detachment was actually at CU Boulder.
So, you know, once or twice, sometimes 3 times a week, we'd be up at Boulder doing those activities. And then as soon as I graduated, then commissioned in the Air Force, And started my gig there. So what'd you do in the Air Force? So in the Air Force, I was in the Office of Special Investigations, and it's kind of like the, the FBI of the Air Force, so to speak. There's a number of different things that OSI does, but one of the big things is investigating, you know, felony-level crimes.
Is that crimes committed by Air Force members? Yes. Okay. Yeah, or it could be— it could also have some sort of nexus to Air Force personnel. But in general, it's— it could be crimes committed by Air Force members or crimes that are affecting them.
It really kind of depends. We would do joint stuff with FBI and other branches as well. Okay. Can you give any examples of the kinds of cases you worked on? Yeah, so as far as cases, you know, when you first start out, I actually went into a specialty as a computer crime investigator.
And we do a couple different things on the base. We would investigate things like potential drugs, crimes like that, fraud, things like that. And then on the computer side, we would get our hands in pretty much any type of criminal case that would involve any electronic media where we'd basically do forensics on it, prepare it for trial, you know, testify that, you know, the hard drive that we pulled off the computer hadn't been tampered with, and, you know, show the chain of custody of how we maintain the evidence, things like that. So how did you go about learning how to do this stuff? I'm guessing that your computer science degree in college did not prepare you for forensics and military-level investigations.
Yeah, so it was actually, you know, quite a bit different.
So in doing computer science in school, especially at Mines, it was math computer science at the time, very heavy emphasis on math and kind of more of theory and stuff like that. And then in the Air Force, it was digital forensics mostly on Windows boxes. So it was completely different, completely different systems. So they basically have a pipeline of training courses that you go to and you get certifications along the way. So like one of them is, you know, a couple-week course on how to use EnCase for forensic investigations.
And then on top of that, when you become a special agent in OSI, you go to the Federal Law Enforcement Training Academy where you learn just kind of the basics of— call it 1811, which is, you know, investigating crimes as a federal agent. And there you kind of get all the different pieces and start putting them together, and through a series of of training, you know, after like a year and a half or so, you're at the level where, where you can do the job. So you— it looks like you did that job for about 4 years. Yep. And so you'd say the first 18 months was, was really like figuring out how to do the job well?
Yeah, first 18 months is really going to a lot of different training, uh, you know, shadowing. Uh, your first year you're called, uh, you know, you're on probation, it's called. And so you go through like a year of mentoring and, you know, like updates on proficiency and things like that before, you know, you become like a fully fledged, you know, special agent. So can you share anything, you know, during the, the 4 years you were there that you're especially proud of? Yeah, so we actually, we got to work quite a bit You know, on, on the intel side.
Got to see a lot of cool stuff. Can't really go into the details of some of those, but it's pretty neat because got the opportunity to work with, you know, high-ranking people in the government, high-ranking people from different agencies. And from that, kind of got some pretty cool accolades like, you know, Special Agent of the Quarter for, you know, the, the region and things like that. So That was always a lot of fun because it was really doing kind of some cutting-edge, you know, government-only stuff, and I really enjoyed that part. Where were you stationed during all this?
I was stationed at Travis Air Force Base. And so that's, you know, halfway between San Francisco and Sacramento. Yeah, I know, I know that area pretty well. Did you, did you mostly stay on the base or did you get to explore the area too? So I mean, I mostly stayed stateside, mostly doing working out of the base.
And then I would travel, you know, in that region sometimes. The other thing is there's only a handful of computer crime investigators in OSI, so we would support all the different bases that had smaller detachments. So if they had certain cases that they needed assistance with or education, we'd fly around a lot to that. But a lot of my time was spent at Travis. How many folks doing your job were there across the whole Air Force?
I used to know this number. I want to say it was between 30 and 50. You know, we'd have— That's a small number. Yeah, it's a small number. We would— now keep in mind, Air Force is a really large organization, so there's a lot of other people doing kind of similar things, just not in OSI and for different different reasons, but the amount that we had was, was pretty small.
I think at our office we'd fluctuate between, you know, 5 to 10 folks at any given time, and then we had 5 major offices that, that people were at. And was it pretty competitive to get in, or did you— were you aiming for this, or was it like someone just randomly, you know, picks your name out of a hat and says you're up? Um, yeah, so it was, it was really competitive to get in, especially out of ROTC or if people come out of the Air Force Academy.
So you have kind of the end of year and then the middle of year when people are commissioning based on when they graduate school. And then from that, you know, they typically only take like 2 to 5 people out of the entire pool of people graduating ROTC and the Academy to go into OSI. So there's, you know, the whole year before it was you know, I did like a summer program where I interned at a detachment for 3 weeks, and then you have this whole long application process, you know, background checks, going through that whole part. So definitely really competitive to get in. A lot of people in OSI, you, you can't go there like if you enlist like straight out of boot camp like you do in other careers.
You have to spend so many years and make it to certain ranks before you can cross-train over into it. Okay. So yeah. All right. So you were there for about 4 years?
Yep. What happened at the end of that 4 years? So at the end of the 4 years, you know, I was kind of making my decision of, you know, do I stay in the Air Force? Do I go in the private sector? At that time, a lot of the prior people I had worked with went on to Mandiant.
And so like Kevin Mandia, was prior OSI as well, and some of the other people in there. And I think kind of at the end, I was working on a lot of cool stuff, but I was concerned about, you know, kind of moving every 2 years. And the biggest factor for me is I really enjoyed what I was doing, and I knew, like, as an officer, that it would take me out of the specialty. Eventually, I would go into more generic roles. I wouldn't be doing leadership roles.
Just leadership roles. Yep. Gotcha. Exactly. Mandiant was quickly building a reputation as the go-to in the private sector for doing incident response and dealing with these type of things.
That was the natural fit, and that's where I ended up going next. Yeah. What did you do for Mandiant? This is before FireEye acquired them, right? Yep.
This is pre-FireEye. 2011 to 2013. So actually at that time they had a really strong need for people with skills specific to network forensics. So a lot of the consultants at the time were doing forensics on Windows boxes or reverse engineers for malware analysis, and they were just kind of spinning up like kind of a network— we called it the Network Threat Assessment Program, but kind of the network side of the house. So I'd done a lot on the network side before, and so I kind of split my time between the professional services doing incident response and then the managed services.
And essentially what we'd do is I would analyze the network traffic that we were collecting. I would go through it and then write a report. So for instant response engagements, a lot of them were super active. This was during the time where, you know, there's big breaches in the news and kind of Mandiant was at the forefront of that. So we would spend time going through the network traffic decoding, you know, command and control that we were seeing and then writing reports on it.
I remember certain engagements we went into, we'd have 5 to 7 different APT groups operating at any given time. Sometimes it would be the full day of going through the different protocols that we were seeing and then documenting out what they did and seeing if they were doing anything new, if they were stealing any data, figuring out what the data was, and then passing that on. Any particular incidents you can talk about, with or without the details that identify the incident, just to give a flavor of what you might have run into?
We saw a lot of kind of the same groups doing a lot of same stuff. So I was there when the APT-1 report came out and helping. Maybe some folks listening who don't know what that is. Yeah. It was a big deal, I remember.
Yeah, so APT-1 report was a really big deal in that at the time that it came out, there wasn't a whole bunch of open threat intel sharing. Going on, there was a lot of kind of things in the news about, you know, state-sponsored attacks and stuff like that. And so APT1 report was basically disclosing one of the groups that we were tracking and throwing attribution to who they were, you know, how we came about that, who some of the personas were, how we gathered that information. And specifically that group was really interesting because before it came out, they were everywhere. They were at so many organizations.
They were really large, and they were notoriously bad at OPSEC. So that's kind of how they were easy to track. One of the reasons that they got picked for the report is, you know, they, since their OPSEC was so poor and they'd kind of grown past their capacity, the thought of kind of burning some of their TTPs Kind of the risk-reward, you know, was a bit favorable there. So this report came out and, you know, it was a really big deal because I think after that report it's changed how we share threat intelligence publicly. So now, like 2019, we talk about different APT groups all the time.
We talk about their naming, we talk about what they do, we write reports on them, and a lot of it's really public. Before that, I mean, things were very close-hold, and the advantage of the things being very close-hold is they're a lot easier to track and they're a lot easier to detect. But on the other hand, like, all these companies are just getting hacked into over and over, and, you know, there's nothing that we could really do about it. So you didn't mention it, but it's public knowledge APT1 was one of China's state-sponsored groups, right? I seem to recall, it's been a long time now, I seem to recall some controversy about the report.
Was there, am I making that up? Do you mean recent controversy? I thought back at the time that there was some skepticism about some of the details. It's been so long now. Yeah, I think the biggest thing at the time is there was a lot of people who were afraid that it wasn't properly coordinated with, you know, different people in DC.
How we disclosed it. Yeah. But, and I wasn't part of any of that, but from what I understand, there was a lot of coordination, there was a lot of buy-in, there was a lot of different folks representing. Not busting operations that the government was doing against these groups. Exactly, exactly.
So there was a lot of coordination. I think the biggest thing is, you know, other people who were tracking them who may not have been involved in it, whether it's like private companies or something like that, may have been, you know, a little upset about like, okay, this might burn some of our monitoring ops and things like that. So there's definitely people on both sides of the fence, but it seems to have made a really big impact, I think in a positive way, since then, just because, you know, the amount of public disclosure around, you know, Chinese-attributed hacking in the US seems to be in general a lot lower. Yeah. Well, you were there for about 2 years in Southern California, right?
Yeah. So I was there for a little over a year and then wanted to get back to Colorado, so I moved back and worked remotely for them. Okay, so you, when you were at Man Yet, you moved back here? Yep. Was it, and that was just like wanting to come close to friends and family, or what was the reason?
Yeah, so, um, both myself and my wife are from out here, and then both of our parents live out here. My wife and I met out here in, in Arvada, and, you know, we'd been out of state for about 5 years, and a lot of it was like, you know, kind of want to get back to Denver, get back closer to family, things like that. And, you know, I really missed the mountains and stuff like that. So that kind of motivated that move back here. Yeah, that's great.
So you moved back here a year later. It looks like you made another change. Maybe you could talk about that transition for you. Yeah, so I was working remotely for a while with Mandiant, and this is This is still pre-FireEye acquisition. I had always kind of had an itch for the startup side of the house, and the— I think I joined Mandiant when it was like employee 150 or something like that.
So I kind of was wondering more what the early days were like. How do you build a business? How do you build this from scratch? Things like that. And then through just kind of a crazy chance meeting, I met the founders of ProtectWise, who said they're working on a full PCAP solution in the cloud.
And as a network analyst, usually the one thing we were missing was, you know, having all the PCAP that we wanted. So that sounded like really exciting because one, it was a really cool idea, and then two, it was the opportunity to get a front row in a startup and kind of see how that works. So I joined there really early on, I think I was employee number 8 in the early days there. So, I started working for them at the end of 2000— I think it was '13. Yes, September 2013.
Yep. So, started there as an individual contributor just doing security research. So, why does a company as small as that— you said you were employee 8, is that right? Why does an employee with 8— or excuse me, a company with 8 employees need someone doing research at that point? Yeah, so a big part of it was, one, there was the opportunity and timing.
So, you know, as far as, you know, the amount of people in the Denver area at that time, you know, local, you know, probably not a lot of folks with the same background that I had. And then I was specialized kind of in the network side of the house. But more importantly, as you're building the product, having someone who can inform as that product gets built, like, you know, like how, what are the important ways that we detect threats? Like, you know, what are some of the things that you see in the past? Like, how can you kind of inform that as you go?
It's really being a big part of the roadmap of the product and what are the features that people really need. Yep. Okay. Now I know your position evolved there over the years you were there. But I am curious, when you first got there, was there the heavy focus on the UI that there was later, or did that develop over time?
Yeah, so we always had a heavy focus there.
We had a lot of passion around the user experience, because you see in a lot of security products, usually user experience, UI, is kind of a secondary thing. From the very beginning an integral part of the design. Yeah, that's one of the things that stands out about ProtectWise is that it doesn't have, you know, the command line, the DOS, the DOS on the web feel that you get with a lot of, a lot of products. So you were individual contributor doing research for a couple years, and how did that develop over time? Yeah, so, um, then over time as, as we started to grow, um, I moved into a director position there and then started to build out team, which was my favorite part, was kind of building the team and watching it kind of grow over time.
It's really nice when you can start collaborating with folks and be a force multiplier and kind of shaping what you do. So that was a few years in, and then eventually we called ourselves the 401 Threat Research Group, and then 401 Just being a hat tip to the HTTP response code. So it was kind of our forbidden threat research group. And so yeah, we had a good time doing that. And then— And what kind of work did you guys do as 401 TRG?
So we did quite a few things. We supported a lot of product initiatives. We'd have different agile teams that we'd embed with, and if they needed someone with specific threat expertise, whether it's researching a protocol, learning what are the important attributes of that protocol we need to pull out, that was a big part of it. Another part of it was seeing what was going on in our customer environments. So we'd manage the threat intelligence that we'd apply.
We would also look for issues with false positives or any interesting findings that we could pass back to our customers. That was a really big part of it, and then just working with others in the community, like sharing whenever we could, whenever we'd find something new or interesting that we could pass on, or just tips and tricks. So one of the guys on our team wrote a blog about how to review SMB as security analyst, like what you look for and things like that, like a practical guide. And that was really cool. We got a lot of great hits and a lot of great feedback on that.
And so that was neat seeing that what we were putting out and producing was, you know, helping others get better at their craft. We certainly covered a number of your guys' write-ups on the podcast as well. We appreciate what you guys contributed out to the industry. It sounds like you had kind of a dual focus internally helping your guys' product and and your teams internally get better, but then also just generally helping the industry. Pretty cool.
So yeah, I know you're not there anymore, so talk to me about that. Why'd you leave? Yeah, so I'd been on the kind of traditional enterprise security side of the house for a long time, really hyper-focused on the network side. I never really spent too much time on endpoints, spent a little bit of time on malware analysis, and time on threat intelligence. So, you know, I've been getting excited about, you know, what's going on in the cloud because there's so much adoption going there.
There's— we're really changing the business model and how we deliver applications. And to me, this seemed like, okay, this is a really big, you know, possible new attack surface, and not everyone really has it figured out because it doesn't really fit into our traditional paradigm. So to me, it was, it was an opportunity to kind of get at the beginning of an emerging market and start doing research into an area that's a little bit more unknown, and then kind of broaden the skill set and background that I have. So tell me about Lacework's, you know, assume someone's never heard of it before, which many listeners probably never have. Yeah.
What do they do? Yeah, so at Lacework, We do quite a few different things. We do cloud workload protection. And so I think kind of one of the best ways to think about it is kind of in 3 parts. So we do configuration compliance auditing for the major cloud providers, so GCP, AWS, Azure.
And so what that is, is, you know, for example, in AWS, you know, monitoring CIS benchmarks, We add our own benchmarks in and this is things where you can get alerted right away where it's like, hey, you got an S3 bucket open or you got, you know, a new user who doesn't have multi-factor setup or you just set up a security group that's open to the world. Those type of things and it's interesting, they're low-hanging fruit but we see a lot of the root of a lot of bad things that happen in the cloud start there. The other thing that we do is we do anomaly detection on different resources. So for example, in AWS we can ingest CloudTrail logs. We do some machine learning where basically we understand the relationships of the different entities in your CloudTrail logs, and we look for deviations from that.
So, you know, maybe users logging in from unusual locations, you know, things along those lines. Then we also have a Linux agent that you can deploy, and it does host IDS. So we monitor, you know, what processes are going on, what your applications are doing, what the network traffic is. We do baselining of that to look for anomalous behavior. We can— we have visibility into containers and orchestration systems like Kubernetes.
And then we also— you guys have visibility into like a Docker container? Yeah, so we, we have host level. Yeah, so for example, let's say you have like an EC2 instance and then you have a bunch of different Docker containers. Our agent will reason that, you know, the traffic that we're seeing, which containers it's coming from, details about what the containers are. So it's not like, for example, like a VPC flow log where you just have, you know, IP addresses and stuff.
We can really map and tie all that together. Okay. And then we do a couple other things. We do like file integrity monitoring. So, you know, if a new file gets written, we check it for known bad stuff, you know, malware, things like that.
Traditional threat intelligence, so cryptojacking is big, so alerting on connections to mining pools, all that. So pretty robust amount of things that we're doing, trying to give a single pane of glass because we see a lot of people have They're doing hybrid models where they got some things in Azure, they got some things in AWS, and they want to come to the same place and use the same set of tools. So what do you do for Lacework? What's the reason that they said, we need to hire this guy? Yeah, so I do a few different things.
One is work with the product team on adding new things around FQDN. So, you know, we're coming out with the new system where you can write rules for what the agent sees. So developing what those rules are, adding new types of threat intelligence, things like that. So anything efficacy-related, testing, you know, do we catch this, do we catch that, you know, informing along those lines. And then, you know, there's the whole thought leadership side of the house.
Too. So letting other people know what we are and what we do. So we do this through blogging and speaking at conferences, webinars, things like that. And then the other part is working with our sales team to make sure that we arm them with the knowledge they need about what the current threat landscape is and what they can kind of expect, and also monitoring what's going on in our customers and alerting when we see something interesting there. Now, you did the ISSA talks, was it in February, right?
Yep. And really talking about Kubernetes, or I guess more orchestration more generally, but Kubernetes is the big one. Yeah, so the talks were pretty specific to Kubernetes, and so I've been going around, been doing a lot of specific research into Kubernetes. The reason is, is Kubernetes is really at the intersection of a lot of these different technologies coming together and these different shifts that we have. So everything from people migrating to public cloud to people moving to containerized applications and workloads.
Then you got Kubernetes just like really taking off especially over the last couple of years. Seems like they're totally winning the orchestration kind of arms race. So with that comes you know, a new area that looking at the security side of it is this will get more under a microscope as more people use it for, you know, attackers. So we've been kind of going around since Kubernetes is new to a lot of folks and doing some education around, you know, what are some of the security threats behind it, how are ways that you can harden it, what are things that we're finding. So that's what those talks have been on.
That's great. Let's just take a step back. You've recently made the transition from the traditional enterprise data center approach to getting more cloud-focused. I made that transition a few years ago. I think there are a lot of listeners who either are thinking about they're going to have to make that or are in the midst of it and they don't know how to do it.
What kind of guidance would you give for someone who's thinking about, hey, this is coming up soon and I need to get my mind in the right place and understand how to do this? Yeah, I think that's a really good question. So it's an area that I wanted to dive into sooner, but I was always a little bit kind of intimidated by it because it was a lot of new technology, a lot of new concepts I wasn't too familiar. But from a security point of view, like if it's a traditional security guy looking to get into cloud security or DevSecOps. It's really a shift from, you know, the security folks have always told the developers like you need to become more security savvy.
Well, now it's a little bit flipped. It's more like security folks need to become more dev savvy. So I would say kind of the big thing for someone outside of that world is, you know, understanding what DevOps is. Where did DevOps come from? Like why is that important.
Understanding how the major cloud providers operate, more specifically shared security responsibility model, is really big. And then once you kind of get there, it's learning a lot about the toolings and then kind of the landscape around what are kind of the risks that are associated with this. And I think what you see is now we have a really big emphasis on speed, speed of innovation, and in the old days security could kind of block that, but now we need to be more of guardrails. So getting in that mindset of how we can deal with that and deal with lower visibility and figure out how to bridge between teams. Those are kind of the big takeaways with making the transition.
One of the challenges I've seen from people trying to move over previously is if they'll trust their vendors, their legacy vendors, about how to move to the cloud. There's just an awful lot of, well, just move over the same technologies you've always used in a data center into the cloud. Just setting aside Lacework and what you guys do, what would you say are the biggest technical differences in like how we implement controls in a data center environment versus how we do it in the cloud? Yeah, so I think the biggest one, especially as a network guy, is, you know, you don't own the network anymore, right? Everything is virtualized, so a lot of those traditional controls that you have, like, I don't think they port over well.
And then the other big thing to really understand is, you know, before you're dealing with servers that people access and people's laptops and workstations. And we had bring your own device, which started to change things as far as building a moat around your enterprise. But now one of the big things is just understanding like ephemeral workloads, like workloads are going to come up and down. How do you reason about that? What do you need to track?
What do you need to save? What do you need to log? Those are all kind of the big pieces there. Yeah. Okay.
I'm gonna do a little shift away from that. And you're a Colorado native. You chose to come back here on purpose. I'd love to understand, do you get involved with the Colorado security community outside of your employers? And if so, how do you do so?
So I hadn't done a lot with the local Colorado security community. So before, I previously, like in the past, a lot of the security communities that I really interfaced a lot with were either on the East Coast, like Washington, D.C. folks, or, you know, on the West Coast, you know, Bay Area folks. So when I came back, I was actually really unaware of, you know, what all was going here. And the thing that I've— that's been really exciting in the last, you know, couple of years is there's more and more kind of happening. So now that, you know, I'm working remotely, one of the big things I'm trying to do is get a lot more involved with Denver.
So like you'd mentioned, I did some talks at ISSA, went to the CSA Summit, had a good time there, want to get more involved with CSA. OWASP as well is another one I'm looking to do. I actually haven't been to Armistice before. There's usually— you gotta make it. So I'll be there this year.
So yeah, just, just looking to really get, get involved in those groups. Yeah. Have you ever done the CitySec stuff? Those? No, I haven't done CitySec.
I've done BSides. Seems like a group you'd like. They get together once a month at different beer places. They— I think they, they have the Denver one and they also have the Boulder one. I don't know which one would be more convenient for you.
Um, you know, probably the Boulder one, but it would be cool to at least check out both. I've seen on the Slack channel and just following Colorado Equal Security on the Slack a little bit more, but yeah, I've seen some postings for that. I'll have to check it out. Well, you know, that's it for everything I wanted to make sure I asked you about. Is there anything that you wanted to talk about that I didn't bring up yet?
Um, you know, I think kind of the last thing I would add kind of on the cloud security side is there's a lot of uncertainty out there because we have a lot of open source projects kind of dominating the landscape. When something new comes out, a lot of traditional people are like, this is going to be the end of the internet, everything's going to break. But I really think the way that we're deploying and running applications in the cloud is a much more secure and safe model than it was before. And a lot of times what we run into is the biggest issues come from not fully understanding the capabilities and initial configuration. But after that, you can have a really cool model of keeping the bad guys out.
So I think that's exciting, and I think spreading some of the optimism about security, because you get a lot of cynicism in this space, is really important. That's great. I agree, the cloud is our best chance to make, you know, to get more secure, but we do need to RTFM, right? Read the freaking manual. Yeah, you got to know what you're signing up for.
Yeah. Well, thanks so much for your time. This has been a lot of fun. Yeah, thanks for having me. Hopefully we can catch up again soon, and I look forward to hearing how Lacework goes in the future.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.