Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for September 23rd and episode 134. Uh, today Robb is off on a wild adventure again.
And what you were supposed to hear was some witty banter between myself and Brian Beyer, who is filling in as guest co-host. However, having some computer issues and that's not going to happen. So you're just going to get me all by myself today. So let's get into some announcements and then we'll jump into the newscast. First, we have a Slack channel.
So if you haven't checked that out yet, please do so. Go to the website colorado-security.com. Click the Slack button and you can join that way. Also on the website, we have a mailing list. If you scroll to the bottom of the page, add your email, and sign up, you will get the show notes every week in your email box.
Also, we'd love it if you could rate us and subscribe, whether that's on iTunes or Google Play or whatever podcast service you use. Sign up so you get this every week downloaded directly in your podcast player. Please also tell a friend, spread the word about Colorado Equals Security. Also, if you'd like to give additional support, you can join our Patreon campaign and pledge a little money to help us defray the costs of the podcast and all the things that we do here. And finally, if you want to volunteer to do interviews for the podcast, we would love to do that.
Please reach out to us. We actually have a volunteer interview this week as part of the podcast. All right, so let's jump into the news first. Uh, big news this week, Ping Identity goes public with a valuation of more than $1 billion. So congratulations to Robb and Andre and all the people over at Ping.
Um, that is one of the reasons why Robb isn't here this week. He had to go out to New York for the ringing of the bell and all the cool stuff as part of going public. And then took a little break, a well-deserved break. One of the things I thought interesting about this story was that Ping is the city's 6th largest tech employer at 350 employees. I guess that, that was a surprise to me, but pretty cool for Ping.
So congratulations to them and best of luck as a public company. Next, this week was Denver Startup Week. So lots of stuff happening downtown as part of Denver Startup Week. One of the things that I thought was interesting, we have a couple stories in here. The Denver Downtown Partnership, which is a trade group and helps organize this, said that they're tracking 875 startups working just in downtown, employing more than 5,400 workers.
That is pretty cool. And if you look back a decade ago, there were fewer than 100. So that's some gigantic growth in startups. Also, there was a story about Cypherskin, who is a Denver-area startup. They make a smart mesh which has sensors in it which you can use to simultaneously register several data points, in this case about people.
So it could be body motion, heart and respiratory rates, oxygen levels. You can wear this, you know, sort of as a suit or a sleeve or something like that, but it provides real-time feedback on the person that is wearing it. So this was started because they wanted to see how they could help with biomechanics and get more real-time feedback on people. Pretty interesting to see the stuff that they're doing there. Also, it looks like they have some non-people applications for this.
You could put the sensors on pipelines or other things like that to see changes that happen. So cool stuff from Cypherskin. Next, NASA picks a Colorado company to help experiment to return U.S. astronauts to the moon. So this is pretty cool. Advanced Space won a $13.7 million contract with NASA to help develop a small satellite that will be used to try out the company's automated spacecraft positioning software.
The satellite will also test the unusual elliptical orbit which NASA plans to use to put a lunar outpost where they can dock before astronauts descend down to the moon itself. So that's pretty cool. This is part of the challenge of getting our astronauts back to the moon prior to getting them out to somewhere like Mars. So pretty cool that Colorado is participating in that. Also, the Colorado Secretary of State announced that Colorado is the first state to stop counting ballots with printed barcodes.
So as part of ballot machines, there's a barcode that gets printed out when you enter your votes, and there is fear that if these systems were hacked, that the votes that were cast as part of that ballot would not actually match what is in the barcode itself. And of course, as a person, you can't really tie that barcode back to what the votes are themselves. So the idea instead would be just to have the actual votes tallied on the— on a printout that could be used for confirmation, and then a computer system would have to count that as opposed to using a barcode. So this is actually a national story, and since Colorado is a leader in election security, it's likely that other states will follow our lead. Also, a Bay Area fintech company is looking to get some money through the Colorado Economic Development Commission.
So an early-stage fintech is looking to potentially bring 800 workers here over the next 8 years in a project codenamed Project Feline. So this is a company that provides users with technology-based financial planning and other financial literacy as part of the program. So that would be pretty cool if we can get another Bay Area startup here as part of that program. Another company that did that, Checkr, they moved their, what they call their second headquarters here back in July. Just announced a Series D round of funding of $160 million, putting them at a valuation of $2.2 billion.
And that's pretty cool. Back in July, they brought an initial team of about 20 people from its San Francisco office to Denver, and they've hired more than 50 people in that time, going from, from 20 to now 70 people. So pretty big growth for Checkr, and congratulations on their funding round. Automox had a blog post this week talking about their launch of a community to help organizations automate cybersecurity hygiene best practices. So Automox, which is a patching and configuration management platform out of Boulder, they have what they call Automox worklets.
And these are basically worklets that can be script-based modules or other things like that that help with configuration. So they launched the Automox Alive community as an ability for their customers to share these worklets so that they can help drive cyber hygiene across their customer base. Pretty cool. So if you come up with something good, you can share it through the community and then other folks can use it as well. There's also a blog post from CyberGRX this week talking about compliance versus true cyber risk management.
Of course, CyberGRX is a local company that does third-party vendor risk management functions, and I think that's always a good thing to think about risk management as opposed to compliance. In the article, they talk about a couple things and some good questions that you can think about when, you know, going to your third parties and thinking about their risks. You know, how likely is a breach given the context that you deal with this vendor? How bad would that be if it happened? You know, is there another company you could use that has a more secure product?
Are there other things that you need to do if you are going to use this vendor to lower your risk, such as insurance or other things like that? But interesting blog post from CyberGRX this week. Webroot also had a blog post about keeping your vehicle secure against smart hacks. So this was one that I thought was kind of interesting, and I'm sad you guys aren't going to hear the discussion that Brian and I had about it. While I'm wholeheartedly for keeping your car secure, some of the suggestions that they have here I think are a little bit beyond the reach of most people.
For one, it says, you know, update your car's firmware and keep it that way. For the most part, you know, people are not updating their firmware themselves on a regular basis. And I have heard that it is actually fairly difficult in some cases to do so. Also, it says don't be a beta tester. I don't know that I've ever heard of a beta test program for firmware on a car unless you're talking about Tesla, which is essentially a software program on wheels as opposed to a car.
I'm not sure that there are any beta tests out there for firmware that I'm aware of. Also, some other things like only use a trusted mechanic. Which I think is, you know, pretty standard advice, but I'm not sure even how you would determine if your mechanic was trusted to update your firmware on your car. So in any case, interesting article and thoughts. I'm not sure how practical it is for most people, but make sure that you do what you can to keep your car secure.
There's also a blog post from Red Canary talking about advanced persistence and thinking like a cybercriminal Excuse me, thinking like a sysadmin when being a cybercriminal. Bottom line here is that there are lots of things that system administrators do— scripting legitimate functions that have elevated privileges— that look like they may be a cybercriminal, and cybercriminals will take those and try and mimic those actions so that they can get persistence in your network and maybe not have you think that it is actually a bad thing going on. And then finally, we had an additional article this week about the Coalfire pen testers that were arrested in Iowa. This article has a link to some of the contract details and other things like that. Since we talked about this last week, both the— both Iowa and Coalfire have issued press releases talking about what's going on.
Some apologies have been issued. And, you know, overall, it looks like the scope of the pen test was, you know, just a little bit unclear. There was the ability in the contract to do physical testing. But I think that, you know, maybe some more care should have been taken as part of this just to make sure that everyone was clear on what exactly was supposed to be going on. So, all right.
That is it for the news. Let's jump over to the Slack Message of the Week. Thanks again to Andre Gaeta for sponsoring the Slack Message of the Week. Andre sponsors this out of his own pocket, and the winner each week gets a $25 credit to the Colorado Equal Security store where you can get some cool Colorado Equal Security merchandise. And this week, the Slack Message of the Week goes to Brian Heilman.
Brian actually responded to a post by Douglas Brush Douglas was asking for a place where he might be able to find some, some test PII data that he could use for something he was doing. And Brian responded and said, sure, I know the best place. It's a website that I maintain called dlptest.com. And checking that out, there's all kinds of test datasets that are on there that you could use for this exact person— excuse me, purpose. So congratulations, Brian.
For, for winning this week, and good job on keeping that site up. It's pretty neat information there if you need to get some, some test PII data. So jumping over to events, of course we have an event calendar. You can go to colorado-security.com to check that out. A couple upcoming events that I wanted to talk about.
First, Ballard Spar is having their annual Colorado Cybersecurity Summit on the 2nd of October. Colorado Equal Security is a sponsor of that, so you should go check that out. Additionally, after the event, they are doing a beer tasting as part of the Great American Beer Fest. So even if you don't want to come hear about the events, you should definitely sign up just for that. And also coming up a little bit later, end of October, beginning of November, the, the annual SecureWorld Denver conference is happening.
So check that out. We are actually going to be doing one of the keynotes, a live version of the podcast as part of that. So looking forward to SecureWorld coming up at the end of October. Okay. On the 24th, Women in Security Denver is doing their September meeting.
Also on the 24th, SecureSet is doing an expert series with Dorn Cybersecurity. A security program boot camp. On the 25th, ISSA Denver is doing a happy hour. Also on the 25th, ISC² Pikes Peak chapter is doing their September chapter meeting. One more on the 25th, ACIS Denver Mile High is doing an event called Understanding the Security Job Market.
On the 26th, CTA is doing their Insight Series, Next Generation Customer Experience. Using Data Analytics and AI to Drive Differentiation. On the 26th and 27th, the Finance and Accounting Professionals Group is doing their 2019 Rocky Mountain Area Conference. On the 28th, ISACA is doing part of their series for their CISA and CISM review. This is Domain 3 for CISA and Domain 2 for CISM.
So you should check that out if you're interested in taking either of those tests. As we mentioned, the Ballard-SPAR Security Summit on October 2nd. Also on the 2nd, the Denver IAM User Group is doing their meetup at the Boiler Room Speakeasy in downtown Denver. Finally, on the 2nd, Colorado Springs is doing their Cybersecurity Summit and Industry Day on the 2nd.
Splunk First Thursdays at Topgolf is happening on October 3rd. The CTA is doing their Global Blockchain Summit on October 3rd and 4th. On the 4th, SecureSet is doing a capture the flag with cybersecurity games. And finally, the next ISACA CISA and CISM review session for Domain 4 for CISA and Domain 3 for CISM is happening on October 5th. All right, so that is it for the events.
Let's jump over to jobs. Uh, Laris is looking for an application security consultant. Institutional Cash Distributors is looking for an information security manager. Denver Water is looking for an IT security architect/program manager. Red Rocks Community College is doing, uh, this is a part-time job, for a cybersecurity apprenticeship employer relations and coordination.
The State of Colorado OIT is looking for a cybersecurity administrator. PANA is looking for a DevSecOps engineer. Wells Fargo is looking for an Info Security Engineer 5. The Colorado Judicial Branch is looking for an information security analyst. Checkpoint Software is looking for an entry-level security engineer, West, and Maxar is looking for a cybersecurity operations analyst.
And that is the end of the newscast for this week. Let's go ahead and jump over to the feature interview this week. As I mentioned, we have a guest interviewer. Joe McCallister is actually interviewing Preston Buccotti, who is a privacy attorney and consultant. So look forward to hearing that interview from those 2.
So thanks again, and we will talk to you next week.
This is Brian Becker, Director of Information Security at Cronky Sports and Entertainment. You're listening to Colorado Equals Security for Colorado security professionals by Colorado security professionals.
This is Joe McCallister with Colorado Equal Security, and I'm sitting here with Preston Bukaty. Yep. Why don't you tell me where you're at now, kind of what you're doing too? Yeah, so I work for a company, British firm called IT Governance. Our US side is called IT Governance USA, but basically working as a consultant.
I mean, my background's in law, I have a law degree, but you know, standard lawyer stuff. I'm not giving everybody legal advice, all that sort of thing. So I act as a consultant helping companies with a lot of privacy law compliance stuff, but actually lately we're seeing a lot more activity on ISO implementations, especially 27001. And I guess I'm seeing some interest filter from the marketing and sales folks on— oh God, don't quote me, I should know this— I think it's 27001, the new privacy information management system framework, I think you can get certified too. But long story short, basically a lot of customers are going beyond the, hey, fix my policy, to I need an all-encompassing, like, fix this, give me a certificate so I can be done and move on with my life.
That's interesting because it seems like they're the thought process, and I could be way off base, so please correct me, but it feels like when we talk policy, we talk about a document we make and we want to update it very often, right? We want to make sure that it is overarching and applies over years where we can tweak procedures, we can tweak guidelines and standards and all that stuff. Yeah. Seems like a shift from just make my policy in line with something to, okay, let's actually get down in the nuts and bolts and start checking these boxes a little bit more fine. Yeah.
Is that accurate? Yeah, yeah, it is. And maybe it's the CCPA that's doing that? But you're right, it is sort of a shift from like, like sort of like I just talked about transparency. I think a lot of people who used to have the assumption that if you just explain in your privacy policy, that's good enough.
And the reason I sort of said maybe it's the CCPA is because that's starting to bring GDPR-style consumer rights, right? You know, like the right to deletion and other things. So maybe people are saying, oh my gosh, It's not just enough for us to explain what we do. We actually have to turn around and do this and, you know, like manage the confidentiality, integrity, availability on the front end, be able to alter, delete on the back end. And so, yeah, oh my gosh, hey, it's not just a 20-minute exercise to fill out a questionnaire and update some paperwork.
It's a, we got to build, you know, network infrastructure or whatever to manage personal information. And again, right, that's, that's distinct from what I'll just classify as information, maybe metrics, analytics, machine data, whatever, and kind of separating those even though they probably technically reside in the same spot. But like, in your mind, contextually, you have to separate the rules around how you use them and play with them and that kind of thing. Yeah, you know what's kind of interesting is I think that there may be in the near future, if there's not already, some sort of drama that could be inspired by the types of data protection that is necessary or seen as being like— I don't want to say a threat, but you kind of get the idea, right? Yeah.
Data privacy is becoming such an interesting topic, and it's starting to boil over outside of technical. Yeah. And we talked about just the fact that privacy and technology, IT, information security, all these teams have to start working together so closely. I work very closely with our privacy and our legal teams daily.
The person they pair me up with as a mentor is on the legal and privacy team. Okay, interesting. Yeah, so it seems like it's trying to do, I guess, a bit of knowledge share, both of you kind of? I think so, and I think it's also trying to build that bridge because there will be a lot of interaction there. Yeah.
And everything that we do from an information security standpoint, we have to do a very early stop and say, is this a— is this something legal needs to look at? And if it is, does it go over into their bucket so that they can look at it? And we kind of shut the door behind it so that legal can look over, say, a new tool or a new implementation. And privacy has eyes on that too. So then they can send it back.
So let's say I'm gonna collect a bunch of logs. Our privacy team needs to look at it because we're a globally dispersed company. We can't just go grabbing IPs and emails and all this of everything that comes through the environment. We can, but we also need to do our due diligence and kind of get our head around what it means internationally, and then soon enough what it means in California. Yeah, yeah, yeah, yeah.
And the weird thing too too, is like, when I think about it, it's just the idea that you even have like a privacy function. I feel like, I think a lot of people would maybe assume that should be a responsibility of legal, and it probably could be, but it is, it's like such an interesting, like, there are these privacy laws and regulations and they govern the use of data, but it's very like context-specific, right? It's not just like the wholesale use of data. It's, well, first of all, it's personal information, not data. And then it depends on whose and what you're doing with it.
And it's so like, it's like not so easy to write like hard and fast black and white rules because so much of it is context dependent. Like I got a question from someone the other day. They had received a request to delete data from a customer, but everything in their records showed this person was a Colorado resident. And they were sort of like, do we need to do this? Like, they're asking for GDPR rights, they're from Colorado.
And on the one hand, I was like, okay, well, like, residency doesn't matter so much to you. Like, it's much more about the legal application of the law to your business. And I wouldn't focus on where this person happens to be because that could change. And so many, you know, it's an issue and a non-issue at the same time, right? And But it was so like, I think they just wanted like a yes or no.
Do I delete it or not? Yeah, and I just kept coming back to what do you want to do? Like if you don't want to honor this request, there's logic we could throw at them, right? Hey, you're not an EU resident. GDPR doesn't apply to our business.
Whatever insert more nuances from there. On the flip side, and that's where I was trying to nudge this person, like you got to think about like the company you want to be. To be. Do you want to be that company that is always looking for an out, or just say like, hey, this is the way it is, and like, this is what this customer wants, and even if legally, technically they don't have a right to it, we can still honor that? I mean, you're deleting an account.
It's not like you're doing crazy, you know, you know what I mean? I'm sure it takes work, but it's not like they're asking you to move mountains. Yeah, the level of effort is, is somewhat marginal, right? And it's kind The argument of, is this the hill you want to die on? Yeah, type thing.
Yeah, yeah, yeah. And they were so hung up on like, well, it's a Colorado resident. And I'm like, I get it, but like, what's not to say they don't have rights in Colorado, Pennsylvania, New York, California, wherever they may be? Like, it comes down to you and your company and what applies to you and what you want to do with that. Yeah, it's an interesting kind of just concept in general with adherence to regulations and laws when I worked for Best Buy years and years and years ago.
But they would always essentially base their nationwide policies on California, okay, because they were the strictest and the ones that were, you know, maybe required the largest level of effort to fit within. But then if you did California, you were good. Yeah, exactly. Everybody else, right? Exactly.
And that's where I was trying to like condition this person like, hey, like, I wouldn't focus on GDPR and where this person is. Like, a user has asked you to delete their information. That seems like a reasonable request. And again, there's legal ways you could say no, but like, at the end of the day, do you want to work with your customers or say no? And you know what I mean?
Yeah. And there's an interesting kind of brand piece to that too. What happens. Yeah, and this is beyond my scope, and I imagine probably yours as well, but what happens when that hits your PR or your marketing team that somebody has just tweeted out, this company is refusing to delete my data? Yeah, yeah, and that's the thing too, right?
It's the transparency thing. Like, the more you're just transparent, people buy into that. Whereas if it's like, no, I'm not going to delete your data, why? What are you doing with it? Why?
What's so important? Now it's of raises questions where, yeah, I could see someone making a tweet and this becomes a bigger deal than simply being like, oh, you want your account deleted? Fine. That's definitely interesting. It's kind of— as I was kind of preparing and reading back through, I tried to read through at least most of the language for the CCPA.
And before I forget as well, what's the— you have a book out on CCPA, right? Yes. The title, oh gosh. See, I should know that too. I think it would probably be called California Consumer Privacy Act: An Implementation Guide, something to that effect.
Basically, I tried my best to break down the requirements of the law to, you know, get it from legalese to plain English, but then also sort of like, and here's what I would do to do that, right? So a little bit around building like subject access response processes, thinking through things like contract management and policies, right? Because the law may just say explain XYZ in your policy sounds easy enough, and maybe it is for 10 people, but if you've got, you know, a 200-person organization that's doing multiple different things, you may have a couple different policies, and bringing that all together requires a little bit more forethought than just banging it out and posting it on your website. Yeah, yeah. So I imagine if we search Amazon for your name, Preston Bukaty, B-U-K-A-T-E-Y?
No, no E. But no, no, you're all right, you're all right, you're right. But yeah, I am very easy to find on the internet. In fact, you know, probably the opposite of privacy. Yeah, I think it's always funny when security professionals and privacy people are so easy to find. Yeah, yeah, no, it's not like John Smith.
If you type in Preston Bukaty, it will be me, unless it's bad, then it's probably probably someone else out there. But yeah, as long as it's positive, it's probably me. And yeah, the book comes up on Amazon. It's short. I think it's like 100-ish pages.
It's meant to be sort of a pocket guide, right? And, um, for everybody out there, if you're worried about the length, I did actually include a copy of the statute at the time this went to press. So probably a good 20, 30 pages at the end is just the statute itself. And I did that to sort of, in part, Give the reader, hey, this is it. You don't have to go find it on the internet.
Just flip to the back. But also cognizant that this may change. So, you know, when I wrote this in May, June, that was based on the May, June version of the CCPA. It's pretty much substantially the same now, but like, who knows, 6 months from now, maybe some variations. So I wanted it to be clear that like, hey, if I said X in reference to Section 1798.13, whatever.
Like, this was what I— this is what I was thinking at the time. Cool, cool. So something good to have on the desk or on the bookshelf nearby just to grab. And yeah, yeah, yeah, hopefully. Yeah, yeah.
And again, I tried to make it so that it wasn't like too narrowly focused on the CCPA, cognizant that other states are doing, you know, marching in this direction. And so that's why a lot of the implementation guidance comes down to like, don't just do what the law says, literally start to think about, hey, you know, if I have operations in other states, what do I need to do to build it? If I have multiple business silos that are either, you know, totally siloed or maybe some degree of synchronization, how do we manage data sharing responsibilities between them and that sort of stuff? Awesome. We previously had a really good conversation regarding just privacy in general and You had brought up a conversation that happens quite a bit, the nothing to hide argument.
Yeah. And I'd love to kind of dive into that a little bit more and kind of— because I think you made an awesome point or an awesome counter-question in our original interview about, okay, well, open up your computer. Yeah. Yeah. Well, and I think that's— I find it— I don't know.
I say this. It's not like I've done like an extensive interview of people around the world, but I feel like American people people tend to sort of have this opinion of, yeah, if you've got nothing to hide, what's the big deal, right? Why is everyone so concerned about privacy, the sharing of personal data, nothing secret? I mean, and even like the Facebook Cambridge Analytica, I mean, you, you can make that argument to a certain degree. Hell, if you're already posting this stuff on social media, did you really have an expectation of privacy?
I mean, you may not have known it was going to Cambridge Analytica, But you knew other people were looking at it, certainly some folks at the Facebook offices in San Francisco. But yeah, that's sort of my thing is when people argue that— because privacy is like a societal construct, you know what I mean? It's this idea. It's not like life and liberty, sort of very drilled down like a human right you can sort of see, right? Someone's sick, they should be better.
They are hurt, they should not— you know, like, privacy is this idea that, like, we all have this right, in air quotes, to, like, a personal sphere that's not going to be intruded upon. And what I think people forget is that ripples outwards.
You know, the more people are comfortable in their own space to voice voice opinions that maybe are not favorable, to research things that are maybe uncomfortable like medical issues. You know, a certain realm of privacy is like a shield that lets people be who they are. And if your argument is we can break down or eat away at that shield because you're not doing anything wrong, number one, that's a stupid argument because who's to say what's right and wrong in the given moment, right? In Germany in 1945, all of a sudden it was illegal to be a certain religion.
And then on the flip side too, right, it's— if people don't think there is a true right to privacy, then that's where I'd argue, okay, don't you have aspects of your life that you want personal, private, that aren't shared with everybody? The location you You know, all the time. Where are you Saturday night? What is your internet search history, right? Have you ever used private browsing?
Have you ever cleared the history? Those sorts of things. We all do it, right? We YouTube gross medical weird things that I'm sure we wouldn't want shared. And at the same time though, and it's, it's really topical today because there's these protests in Hong Kong and you're seeing how so much Or at least me, and maybe it's the tinfoil hat that I'm wearing, where like you can start to see where that government is taking advantage of that, well, if you've got nothing to hide argument, right?
Like I read an article that the protesters in Hong Kong were using cash to take the subway because their digital MetroCard, they were afraid that the government could sort of track who was going where and start to get a list of who was attending the protests. And again, you're on the one side, it's like, well, technically they're not doing anything wrong. And if we think about it from a data perspective, we're only sharing location. What's the big deal? Well, if the government starts to put together a list of protesters, now they can figure out where you are, harass you.
I mean, it gets pretty dicey pretty quickly. And so that's where I always struggle with people that are just sort of like, that don't seem to care about it, because it's like you have things that you would like personal or private. And I guarantee everybody does. And yeah, if you don't, then crack open your internet history, let me see it, let me read your texts. Yeah.
And if you're comfortable with that truly, then I don't know, then agree to disagree. We're just— we just have different outlooks on it. And I hope that you're never in charge of the FBI or CIA. It is funny because there's a— I've had to have this conversation with my wife even, where my phone is a very personal device to me, right? Yeah.
Once in a while she'll need it, I want to show her something or see something, but then there's something in my mind that just— or my being— that is, once it's been in someone else's hands for too long, I just start getting uneasy. Yeah. And she's done the same thing, like, well, is there— not in a hostile way, she just kind of plays and says, you know what, let me just look at it a little longer, and I just start to get uneasy about it just Because there is, for better or worse, this device has become a huge part of me, my personality, my privacy resides on it. And I even think about stuff like I've been on WebExes where I accidentally share the wrong window, the wrong screen, right? And I didn't want somebody knowing that even I was on LinkedIn looking at another company, because what are they going to interpret that as?
You never really know what they're going to do, like you said, with location data. I don't know how they're gonna utilize that. Another great example being the FaceApp. I don't know if you followed that. Oh yeah, yeah, yeah.
And there was a, you know, hootenanny about it being a Russian-developed application, and I had to make the point to my wife in conversation too, like, it's— if they want to really apply depth to and intelligence to a photo, they've already done it. Like, they have. Yeah, you put that all out there. Yeah, you've done that really reasonable expectation of privacy, you've kind of got everything out there. And then I start getting tinfoil and start thinking about like, I need to shut everything down.
Yeah, I'm just gonna go up to Evergreen. Maybe that's not far enough. I'm gonna go to Glenwood and just build a cabin in the woods like Ted Kaczynski, totally disconnect. Yeah, it's a blessing and a curse, I think, of working in information security, and I'm sure privacy to the same extent, and law even. You start to look around at your surroundings and just— it could be news, it could be just, you know, the restaurant we're sitting in— and you start to see things that are like, oh my gosh, you know, paranoia, anxiety levels start rising about— yeah, more and more as you see it in the wild, right?
Yeah, no, and you, you raise 2 good points. Um, the first one being like, how is this changing our social dynamics? Like, like step outside of the confines of work, right? And the phone in a relationship is a great example, right? You know, like, same thing, right?
Like, I'm not comfortable with people looking at my phone. Do I have anything to really hide? No, because I delete the history. But, but like, at the same time, it's just something about you. Like, it's, it's almost like you're connected to me.
And yeah, it's just this weird, like, I don't know. And, and the other point you brought up was like the expectation of privacy, right? I've been going back and forth with some folks. You know, technology is on this crazy pace. We just happen to be born at this age.
And it's impacting the way we interact as humans, like as animals at the end of the day.
But you've got to remember, laws are constructed to govern society and govern for risk. And a lot of it is based on sort of like what do we think is, air quotes, normal in today's world, right? So like a reasonable expectation of privacy. If you go back to the '70s, it would be unreasonable for someone to know your location 24/7 because that would take so much work. They would have to physically follow you around.
Now, is that unreasonable? Because I'm like, I mean, like just in this room, how many of these users do you think have apps turned on that are tracking their location? Right now, right? And I've had that discussion with folks where, you know, your IP address can give some sort of like indicator of geolocation. And so over time, will there be an expectation of privacy with regard to your location and your IP address?
Like, just as technology evolves and we all sort of understand, hey, when you connect to the internet and websites and apps, they're tracking your IP address. For security. It's just happening. So in turn, every time you log into that website, you're giving up a little bit of location. If we just all sort of as a society say, well, that's— it is what it is, I want to get on the web and fine, then have we all collectively agreed that no one has a right to privacy in their IP address, in their location?
And it's interesting, I don't know that there's a right or wrong answer, but, you know, to bring it back like with the cell phone It just, it defines how we interact with other people and the world. And yeah, I mean, I'm probably like a curmudgeon, old soul, maybe. I don't know. I freak out about it and I'm trying to dial back how connected I am. But as I see people advancing in the world, yeah, I'm just like wondering about what this will look like in 10 years.
A great example, like you talked about that FaceApp. I mean, yeah, if you're worried about facial recognition, then guess what? Go back in time and never go to an airport for the past 5 years, right? Never leave the country. It's— your face is probably in a database somewhere.
So that's my only concern, like, being really into it, is seeing the pace of technology and it rolled out at companies faster than we as a collective species can sort of acknowledge how it affects us and how do we need to govern it. Right? Yeah. And again, I'm not saying there's a right or wrong answer, but like, it's just, it's just interesting. Yeah, they're interesting discussions because I think it's also— I mean, there are parallels even to health, right?
There are chemicals today that we're now discovering that cause cancer. Yeah. You know, weed killers that are causing cancer that people have been using for 30 years, and buildings they've worked in, and these types of things. And I think if you pull that kind of lens back out and apply towards security. We're moving so quickly, and a lot of times it's a sacrifice of convenience or the cool factor of, oh, look what this app can do, versus the security or the privacy portion.
I think those are the 2 kind of pillars that get left by the wayside to move fast and break things. Yeah. Or make some new great innovative app that now all of a sudden, a couple years later, the founder's in front of the Senate Yeah, having to answer some questions. Yeah, yeah. Well, and that's the thing, like, I think you're right.
There's a little bit of that cool factor and the mentality of moving fast and breaking things. But the weird thing about personal information, right, as a subset of data, is it can never really be changed. Your Social Security number gets leaked and it's tied to your name. I don't know, I guess maybe in theory the government gives you a new one. I have no idea how that works.
So I guess you're— I would assume you're just out of luck. I think you can, but I can't imagine the process. Yeah, and updating that everywhere. But like, even, you know, what about when the inevitable— and it will happen— some data store of biometric information, right? Like, God forbid Apple's fingerprint, you know.
And I don't know that they store them, and maybe I'm out of my depth here technically, but like, when we start losing biometric data, that's when I think people are going to be like, hey, What? Like, I can't change my fingerprint. I can change an account name, I can change a username. It's a pain in the butt. But I think where right now a lot of people are still like, it's not that big of a deal.
And that's my concern, is that it's already happened, and what has happened is a big deal. We just may not hear about it for a year or two when it's just going to be so late that it's like, what, what can we do retroactively? Yeah, that's That's a great point just because I think of companies like my wife and I explored the options of ancestry.com and 23andMe, and they're literally sequencing your DNA, right? They're getting you a profile, and luckily, I wouldn't say luckily because I don't know their practices and I didn't look that far into it. I just essentially said we're not gonna do this because I don't feel comfortable enough having that information stored by a company because I I haven't seen a company that is such a great steward of that information that I would trust.
And there's no guarantee that 23andMe is a money-making venture. Somebody comes along and buys them, what is then their kind of— yeah, where does the onus fall then on that data? And who really is going to do what with it? And there's just so many questions that come from that. It's a business after all, right?
Exactly. And I think it's kind of interesting because reading through CCPA, to kind of circle things back even to that, is I noticed, unless I was reading an editorial take on it by accident, which is definitely possible, there was a lot of language about companies not exercising due care and due diligence when it comes to storing data and personal information. So I'm kind of curious to see how, and you mentioned the different ISO certifications are kind of levels that companies are coming in and trying to get kind of to. Do you see a larger— well, just general, do you see more inquiries about this stuff on a daily basis? I think the easy answer is probably yeah, but do you see more companies that take it seriously as a core issue, or is it more of a checkbox?
Um, well, it depends, and I think it depends mostly on my experience, because a lot of the companies we work with I would say are traditionally classified as small, like 200 employees or less. And so for them, it very much is a check-the-box activity. And, and I don't— I'm not trying to lambast those companies, right? Like, I, I think they're just literally like, they are worried about keeping the lights on and making revenue. And for them, this is just one more regulatory hurdle that as a small business is, is just not something they can deal with yet, right?
Like, these are companies that haven't even hired a head of HR to manage labor law. They're just paying people, you know, they get a check from an investor and pass it straight through. I think at scale, like enterprise-level companies are taking it seriously because they recognize it's a new regulatory era. You know, it's a new thing. It's a new thing.
And they have to be covered on it. And so I think they are adopting that more holistic approach. But between those 2 extremes, it very much depends on, I think, a lot of attention, energy, people's own understanding of their risk. For example, if you're in a regulated industry where you think you're going to get your doors knocked on a lot versus, we're a small tech company, who's going to care? There's still a lot of that mentality, but that, that's what drives me nuts is like, you should care.
You are using my information. Like, do you not? Like, even if there was no law, I feel like it would be polite to like take care of my stuff while you use it, right? And again, maybe it's like an American versus European mindset, but like we just all seem to be comfortable with giving our info to technology companies because in return they give us some zippy cool service. And to your point, none of them have really demonstrated that they are good stewards of that.
They're just irresponsible.
So I don't know, I don't know what the answer is because, you know, when you talk about laws and governing societal risk, what can we really do? Slap these people with fines, right? Or throw them in jail. But for small companies, that can be life or death. So how do you regulate this harm without making it so expensive and difficult that only the big guys have the army of staff to be able to go do it, right?
And I think that's what the states are trying to all figure out right now. Like, the CCPA is not terribly onerous, but it's a heavier lift for small companies versus, you know, send it to the privacy team upstairs and then, you know, add it to their to-do list. Yeah, that's a great point. I, you know, I think sometimes when thinking of law and government in general, I think I maybe don't give them enough credit where it may be due to consider all of those sizes, right? Because it's easy to make a law, like I could probably draft a law that I think is great, but then you start thinking about still enabling small business to function.
And we talk about even, you know, one breach can put a small business out in less than a month. Yeah. Oh yeah. So there's a lot weighing on that. So it definitely makes sense as to— it makes a little more sense when you think about the timescale, right?
Like, I'd love to say that we'll see more data protection laws or consumer protection laws that include data and data privacy rolled out over the next 6 to 12 months. In reality, we've got a wall to build, there's an election, there's potentially China. There's— yeah, we got a lot on our plate. Yeah, there's a lot going on. Well, and honestly though, Joe, you raise a good point.
Like, I think a lot of people get frustrated with American politics because it seems like all we do is argue, but that is the fundamental way it's set up. It's meant to account for a lot of opinions and kind of reach a middle ground. Like you said, you know, if you want laws, you guys can vote for me in 2020. I will get stuff done. You just may not like how it actually rolls out, right?
I think it was a quote attributed— it wasn't attributed to, but it was about Benito Mussolini. You know, it was something negative, but he made the trains run on time. So it's like, you know what I mean? Like, I get it that it's a confusing, chaotic mess at the moment, but we're working on it, as opposed to just saying, hey, you know, I'm not likening it exactly, but GDPR is sort of a much more clear standard. Do it or don't.
And that's caused a lot of people heartache because some of it is just too hard to do. And I think that's maybe a good note to kind of— we've been a little doom and gloom. What do you see as the opportunity and what do you see kind of as the positivity of the landscape of privacy as we move into 2020 and beyond? Yeah, okay, so that's an interesting question and I've been coming around more to this idea of like a central data broker or service, like almost like a man in the middle. Because one of my concerns, and again, maybe it's the tinfoil hat that I'm wearing, is that as we see more of these breaches and as they creep towards biometric information, the value of that data is lost, right?
As an example, Social Security numbers, you could make an argument that that's not a very good validation technique anymore because, hell, they're all over the place. To the point where, as I understand, some of the credit agencies are looking at alternatives to Social Security numbers. And I would argue that it's probably because they're so far gone, right? So I think as a society, we need to think about this idea that we cannot keep giving copies of the same info to different people who are going to do different things with it. With it.
It's just too risky. It's like lending your car to 20 different people. Why not lend it to someone in the middle who is that person on the hook for the security and maintenance and access, and that's who we own the relationship with, and all of these other companies that want to use that data can plug in? Of course, that would be really difficult to manage and do, but I'm just coming down to like, like fingerprints or retina scans, for example. Let's say in 5 years that we have the technology that retina scans are really quick and simple to use, they put them on the doors at every major office building.
Do you want every single office building in a downtown area to have a copy of your retina scan? Like, or maybe they validate it against some government group, and then the question is, all right, the government has it. I don't know, but that's where I start to see it going, is pulling back from the proliferation of giving this out to so many people. And then I think the regulation side will kind of be a mix. I think in the US we'll see something that's very much around like notice and access, kind of like I was saying, you know, explain, be transparent in your privacy policy, explain what's going on, and then the onus is on the user to avail themselves of that service or not.
If a violation happens, then maybe that legal harm can be owned by the company and the user. And it's not like a government is fining Facebook, but hey, we've got a class-action lawsuit against Facebook. And in that way, like, it's a runaround to the same thing. Ultimately, these companies will get whacked financially. But what I think, by giving that power to the people by virtue of like a right of action, which a lot of these privacy laws are kind of shying away from because it would open up God knows how much litigation.
The idea though for me is that you would have an army of people overseeing it, right? If the CCPA is only going to be enforced by the California Attorney General, that's one man or woman who can enforce a law on the 6th largest economy in the world. There's no way they're going to capture everything. Whereas if you and I have a right to sue, there's going to be— yeah, there will be some people, you know, pursuing vexatious, unnecessary litigation, but there will be a lot of people keeping their eyes tuned to it. You know what I mean?
It's sort of that way. But that could be just me. Like, you know, when it comes down to issues like we're talking about, like police brutality or something, the Department of Justice can oversee it, but there's also a lot of value in all of us having cell phones and keeping an eye out and tweeting and raising the issue. And I would argue that we're in a better position because frankly we have more time, attention, and probably care a little bit more. Right.
It's, you know, like a lot of things, it seems to all kind of come back to accountability. Yeah. And kind of the democratization of that accountability might be a great thing. Yeah. Yeah.
I think companies are worried because, you know, it'd bring up, oh my gosh, we're gonna get sued by untold numbers of people. But if you write the law intelligently and give some sort of a safe harbor, that cuts out a lot of that junk. And then it really, it does become the true issues, right? Like the Capital One data breach. If someone sued for that, Capital One could be in the position, and I'm just kind of going off the top of my head, but like Capital One could be in a position where they said, hey, this wasn't a systemic organizational, we didn't have good security, this was a rogue employee.
Go after them. Whereas if it is falling on the organization, they need to be held accountable. And right now it's just like with state attorney generals, it's just not— nobody seems to be really buying into the lesson. You know, pay the fine and it's like a speeding ticket. You pay the fine and move on.
I speed all the time. I've paid speeding tickets. I will continue to pay them. Will it change my behavior? At $100 a pop, probably not.
But, you know, if I'm getting hit with multiple of those, now it's sort of like, oh my gosh, it's actually financially cheaper to just follow the law than to deal with this speeding ticket I get every once in a while. Do you see any sort of change in that kind of tide? Like, for example, the first governor that gets their identity stolen as a direct example or a direct correlation to a breach, right? Yeah. Is that what it's gonna take?
Honestly, I do sometimes wonder that. I do think a lot more people in Washington, D.C. would care about this issue if their information was blasted all over. And not to say they haven't been caught up in some of these things, but yeah, I think that that might be a huge shift in the paradigm. You know, like, I don't know if they've come out, like Donald Trump's tax records. If some kid on Reddit posted his tax records because he was able to hack his Gmail account, I can guarantee you that privacy and Google would be on the top of the news that Monday morning.
And so sometimes that's the only way to drag this stuff in front of the limelight is to really shove it up there. I hope it doesn't come to that, but we'll see. Yeah. Yeah, see, here we are with the doom and gloom again. Yeah, I don't think there's any way to avoid it because there are— there's consequences, right?
There's— yeah, some serious— well, I think to be optimistic then and turn it, I think what people really need to do is just be more cognizant of that aspect of how much information are they sharing out there, and they sort of need to take some responsibility for it right now until we've got better societal controls. Um, and yeah, and just, I think the other thing too is, is for users and consumers to sort of be armed with the knowledge and like, hey, don't— if somebody asks for your email address because you're buying a pair of shorts, ask them why. Like, you have an equal stake in this bargain. You've got the money to buy the shorts. So why do they need your email address?
And I think starting to challenge people and getting them to think critically will also help discourage a lot of superfluous data collection because then maybe consumers will be like, hey, the company is welcome to ask for it, but I know I don't have to give it or that it's not necessary. I know what it is used for and that helps articulate my decision-making. Yeah, I like that. Yeah, I mean, I'm just trying to like compare it to other things. It's, you know, it's sort of like driving driving.
When cars came out, oh, big— how are we going to manage all this? I mean, we all now have some degree of responsibility when we get behind a vehicle to be sober, check our surroundings, make sure the vehicle works, that sort of thing. And maybe it's not like a license to use the internet, but I could see someday, especially like kids, you know, maybe courses or education around like using the internet intelligently, safely, you know, being cognizant of who you give information to. Because when I was growing up, and I assume you, it was the Wild West, man. And so that's maybe I'm in this position where I'm like, okay, I kind of already— I'm walking, backing up from this.
But the people that are born into it, it's the world they live in, right? They have smartphones by the time they're in middle school, apps. I remember the first cell phone we had as a family, I was 14, and we would share it because I would go get picked up from refereeing soccer games, and I'd like give the phone to my mom for whatever she was doing that day. That's really funny because it brought me back to— I think my buddy had a phone that didn't even have a phone book, so he had to carry around a little sheet of paper with him. I think mine was— my first one was definitely one of the Nokias.
Yeah, wouldn't die. Yeah. Did you have Snake on it? Oh, of course. Yeah, yeah, yeah, the classic.
Buying faceplates for that thing. Yeah, that's probably where I first learned my lesson about spending too much on the cell phone bill, which I think a lot of these kids now are learning with Fortnite. Yeah, yeah, yeah, yeah. Well, but like, but then you, you like to bring it back to something you said earlier, right? Like your phone, you consider almost a part of who you are, and that's because it can hold so much more information, right?
If we still had Nokia brick phones, I don't care what you do with it. What are you going to do, call the 6 people whose phone numbers I have? Whereas this has pictures, messages, internet history, and so much more. And we're all coming around to that. An interesting case that worked its way through the legal courts years ago was around the idea of fingerprint access to phones.
Because hey, when you get pulled into the police department, offices, whatever you want to call it, you know, they book you, they take your fingerprints. Well, they take your fingerprints on suspicion of a crime. It's a physical evidence aspect. A lot of police agencies were like, well, heck, we already got their fingerprint, now we can get into their phone. But that is sort of a huge line in the sand, right?
Like, there's a difference between you saw my fingerprint on the doorknob of the victim's house versus you're gonna search my cell phone. And again, it's not just like my phone, but almost a personal computer that I keep on me 24/7 that has a lot of detailed information. And the Supreme Court, and I don't remember the exact details, but sort of came down and said, hey, that's a, that's a line in the sand. To get access to someone's phone would require that warrant level, you know, an extra step beyond just, I've got your fingerprint because I've arrested you and let me get in here, right? Yeah, and that's a great point, you know, Stephen.
Regarding our discussion about location access, you know, in pursuit of prosecuting a crime or, you know, positively identifying a suspect based off location data, you may be able to do that, right? You can more quickly, more accurately, potentially, yeah, identify an alibi, you know, validate an alibi or say that you were there at the time, yeah, that this crime occurred, right? So you can definitely see the law enforcement side of it, absolutely, but at the same same time, it's how much information are we giving out that is— that we know is being shared for the right reason, or for the reason that we intended it to, in the company that we intended to share it with. Yeah. And where, where are those lines?
I think there's a lot of shifting, a lot of dotted lines, a lot of, a lot of that stuff. And it's— I think when we see those instances of that being used, that's when it'll start to kind of maybe flip those switches for people, like, wait a minute, you got this information just off my Google Maps? Yeah, my, my parking location. Like, yeah, like, have you ever looked at your ad preferences on some apps and how they categorize you? I haven't.
No, it's like, I mean, you could do it on Facebook, or I showed a friend on Snapchat recently. Um, I mean, they categorize you based on your ads, but it is sort of like they do a pretty good job. Yeah. Um, you know what I mean? And, and again, like, kind of like It goes back to it's not the data alone, but it's what it's being used for.
Because some uses may be perfectly acceptable, normal, quote unquote reasonable, whereas others are like, holy cow, man, I didn't sign up for that. Yeah, a lot of people— Snapchat's a great example. You use your location to tag like, oh, I went on this great hike the other day. Oh my gosh, yes. So I just learned about this.
Sorry, I didn't mean to cut you off. No, no, go ahead, please. So yeah, so Snapchat, I don't know how It's all set up. As you can imagine, all my settings are like dialed down, and I did that a long time ago. But apparently if you don't turn it off— so don't quote me on this, I'm not a spokesperson for Snapchat— there is a location sharing setting, and if you play around, you can see where your friends are around the country and where like active Snapchatters are, like hotbeds of activity, right?
On the one hand, you can think, oh, that's cool. Find interesting, but I have personally seen recently through a friend how that can be abused in really creepy ways. And that's sort of the thing, right? Hey, I'm sharing my location with my friends, no big deal. All of a sudden an ex-boyfriend sees it and that's a huge deal.
But that puts Snapchat in this awkward position of trying to figure out what to use when and why according to your feelings at the time. Which is, which is difficult for them to do, and I appreciate that. But again, it's like, hey, you may just think, oh my gosh, how fun, my friends know where I am, until someone who's not your friend knows where you are, right? And then it starts to become all too real. And unfortunately, you know, it's all digitized.
You can't collect that paper and shred it. It's— they sort of already know where you are. Mm-hmm. Yeah, no, I'm— it's— I'm glad you reminded me of that. Yeah, basically a friend had gone out through— met a guy through one of these dating apps and it didn't, you know, it fizzled.
And I guess as some men probably do, which is unfortunate, he reacted really negatively and was like creeping on this girl's location via Snapchat. I was just like, ew. Yeah, like, oh, not okay. Yeah. Um, and I think like I, I told this person like, I think it's reporting that to Snapchat because not that they're gonna change the policy, but it's important for them to know that this feature, which they probably thought was cool and fun, can be abused.
And if they're going to collect this data and process it and spit it back out, there's some responsibility on them to do that, to at the very least not facilitate more crime. Yeah, to do so responsibly. Yeah, yeah, yeah, yeah, yeah. I think it's It's interesting in those cases too where you have to— I always take the stance of you might as well report it or have some sort of evidence that you did try to do your duty. And the same with Snap or Facebook or whoever else.
If they have a record of it, then I think it's easier to come back and point to either action or inaction. Yeah. And maybe, you know, down the road do regulation negligence, right? Because that's where it kind of really all comes right back to, right? Yes, exactly, exactly.
And you're right, under negligence, you know, there's the idea that there's a standard of care. And so you either, you know, you either did it or you didn't. You were negligent or you weren't. And I think that's what we're trying to figure out as a society. What is the standard of care for data security and the management of personal information so that we can start holding people accountable?
And it's hard to draw that line because it is— Facebook probably has more more than, you know, Fidelity versus, you know, insert whatever company name. And again, it's not just the data they have, but how they're using it, which is— that's so weird because that analysis can change if they decide— if they decide to use it differently. You may not even be involved, right? So yeah, I don't know, it's a weird— it's a weird space right now. Yeah, definitely.
Well, I think that's all I've got for you. Okay, cool. I thank you for your time, man. Yeah, no, I appreciate it, Joe.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next Remember, Colorado equals security.