All episodes

Newscast

Apple Podcasts Spotify SoundCloud

News from: Simon Beck, Encana, Sumo Logic, Ping Identity, Convercent, CyberGRX, VMWare, Webroot, DarkOwl, Swimlane, Red Canary, Automox, Optiv and a lot more!

Snow murals in Silverthorne? We’ve got that

Colorado is the best state for female entrepreneurs. Encana is moving their HQ to Denver, with a new name. Colorado has some great places to work. It also has a new CTO. Privacy rules are an opportunity for many companies. DarkOwl talks internet freedom in Russia. Swimlane reminds us that Windows 7 is end of life. Red Canary educates us. What should we do about nation state threats. Optiv teams up with Veracode for a new service.

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript4417 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 148 for the week of January 20th, 2020. Alex, how's 2020 treating you so far?

Uh, it's perfect vision. It's perfect. I like, oh man. Can't, uh, so well said. Oh man.

You're really articulating what, how I felt about this year so far too. I, I think you were setting me up for that. It's kind of a, and I kind of whiffed. Kind of a stuttering start to the year so far, isn't it? Yeah.

Just a little bit. Yeah. We're getting going though. Doing some, some traveling here coming up. So, oh yeah.

What's traveling? Uh, some more travel. So it feels like we're actually getting started. Start. I love it.

Yeah, the year started off with a bang. Um, enjoying, uh, keeping very busy. Uh, I'm happy to, uh, to start talking about some news, but before we do, let's do just a little bit of housekeeping. Let's do it. Uh, Robb, did you know we have a Slack channel?

We have a ridiculous number of people in there. There are, there are well over 1,200 people in there. I didn't even look at what the actual number is right now, but it just keeps growing. Lots and lots of conversations. I can't keep up.

Um, you know, back when we started, several times I was like, I read every message. Yeah, not anymore. Yeah, not even in a single channel. But we'd love to have you join us. Uh, lots of great conversations.

You can, you know, just join the different channels you're interested in. You don't have to be in all of them like, like we are. Um, uh, and if you want to join, just go out to colorado-security.com and find the Slack link in there. We also have a mailing list. So when you're on the website, uh, go to the bottom, put your email in, sign up.

You will get the newsletter in your mail with all of the show notes and details from each week from the podcast. And we would love it if you would rate and review us on your favorite podcast listening app. If you go to iTunes and just spend— what would it take, like 90 seconds to go say, I enjoy this podcast, 5 stars? Yes, that'd be great. Yes, you should listen, 5 stars.

Uh, also tell a friend, let people know the great things that are going on with the podcast and all the other Colorado Equal Security stuff. Um, just spread the word. The vast majority of our new listeners and folks who sign up for the newsletter come from referrals. Uh, so we, we do appreciate those of you who are doing it. Uh, speaking of support for the show, uh, we do have a Patreon campaign if you want to financially help support the show.

Uh, you can go out there on the website, um, you get, get joined up to help pay the costs of running the show every week. All that goes right back out to the community. Also, um, if you would like to be an interviewer and do interviews for the podcast, uh, we would love to do that. Robb and I get pretty busy and, and you may notice that we've been slacking a bit lately and not having as many interviews and not us necessarily doing the interviews. So if you are interested in being an interviewer or even being interviewed, if you think you're interested, interesting, and want to be interviewed, just let us know.

All right, let's go ahead and jump over to the news. This is a fun first story here. It's about an artist who, Simon Beck, who creates a giant snow mural up in Silverthorne. Yeah, so he does this by walking around. So he makes a pattern and then sort of traces his steps around to make, you know, giant snowflakes or, you know, geometric figures, things like that.

He— this is not the first time that he has done this. I don't remember the number that they had in there. But it's all— he has done a lot. And he is trying to do a lot more. So he's done 330 snow drawings and 120 sand drawings.

And he says he has a goal of 1,000 drawings by the time he's 80. What's really cool to me about this, number one, he's beautiful. If you go out to the link in the show notes, you can see a picture of the art he created. And he— it wasn't just him. He also had some volunteers who helped him do it.

But I just love the fact that, you know, it's such a temporary thing. You know, you're creating it for a day, a week, right? Very short amount of time. So those who get to experience it, you know, it's special. Also, it took him about 12 hours of walking back and forth to make the art that he did in up in Silverthorne.

So that's pretty cool. Pretty cool stuff. Like I said, take a look at the, at the link in the show notes and you can see, um, really what that picture looks like. Uh, next, Colorado is the top state for women entrepreneurs. It's pretty awesome.

You know, I know that we, you know, we know that there are a number of companies in town, especially Guild Education is a great example of one that's blown up with a woman as the founder and CEO. Um, but it's really cool to know that, you know, based on a whole bunch of metrics that Colorado has been determined to be the number one place for women entrepreneurs. Yeah. And this year, this is not the first time they've done this survey. The metrics changed a little bit.

So there's quite a bit of adjusting in terms of, of who was in what places. For example, we went— we being Colorado went from number 21 to number one. And also Alabama went from number 5 to number 50. What it sounds like just from reading it is, you know, they had a bunch of weightings on how good is it to be an entrepreneur. And then how good is it to be a woman in the state?

And, and, and previously that the weighting for entrepreneurs might have been higher than the weighting for being a woman. Now that they've kind of equalized that, Colorado has, you know, shot up to the top for sure. Next, we have news from Encana. Encana is, you know, really one of the well-known oil and gas companies really in the whole North America. But it has a big presence in Denver and it's about to have an even bigger presence here in Denver.

Yeah. So Denver was their North America headquarters hub. I don't know if it was— wasn't the headquarters in Canada? American headquarters? Yeah.

Oh, sorry. Yes, American headquarters. I guess Canada is also in North America. Really one of the 3. And they've decided that they are moving their headquarters from Canada to Denver.

And they are also rebranding themselves to Ovintiv. Ovintiv will be the new name for— in Canada. And it's actually not just a name change. They're actually doing a stock Um, what'd you call it, consolidation, where 5 shares of Encana stock will be worth 1 share of the new Oventive company stock. Uh, they're gonna be a Colorado-headquartered company taking advantage of more U.S.-focused, uh, investors.

I think that was really one of the reasons. And there's gonna be about 600-ish employees here in Denver. So I wonder if these companies all go to the same agency to get their new names. It seems like a lot of V's and X's and Uh, you know, other, you know, missing vowels in names. Uh, anyway, uh, that's neither here nor there, but, uh, Ovintiv seems like something that a marketing agency came up with, not someone who had a purpose for a name.

Well, Ovintiv is awfully similar to Optiv. That as well. The way it's spelled. Uh, and I don't know why it just somehow feels similar to Flexential to me as well. Exactly.

And there's an X, Flexential. Next, Built in Colorado came out with its list of 100 best places to work in Colorado in 2020. That's a lot of places. Also, Built in Colorado focuses on startups. Yeah.

So I'm surprised that there were that many best startups. Well, it's not all startups. There's big companies on the list. I guess that's true. They had the small companies, mid-sized companies, big companies, and they broke it down by category.

I just went through the list. I pulled out the kind of the most interesting to us. So, uh, number 1, Sumo Logic. Isn't that surprising? Number 1, Sumo Logic.

Congratulations to those guys. Yeah. So, I mean, they've been, uh, upping their presence in Colorado a lot. So we have a number of other security companies on here. Ping Identity came in at number 12.

Conversant, the compliance company, is number 17. CyberGRX came in at number 18. VMware slash Carbon Black was at 30. And Webroot, uh, now Carbonite, or, uh, who would they get bought by again? Uh, yeah, that's a lot.

Anyway, we'll just call it pressure right there. Webroot, uh, number 41. So congrats to those companies. It's nice to know that the security industry is taking up a real good chunk of that top 100 list. And a subcategory, best paying companies, top of that list was Boom Supersonic.

Boom. Boom. So they dropped the money and they dropped the boom, the bass. I guess they break the sound barrier is what they do. Good stuff.

Hey, let's go ahead and move over to our next story. We have a new CTO for the state of Colorado. I think we may have talked previously about the previous CTO moving on. But they've hired his replacement. Yes, Colorado named Alex, I don't know if it's Pettit or Petit, however you pronounce that last name.

Let's go with Pettit. We'll go with Pettit, it's just a little easier, as the new CTO. He comes from the state of Oregon where he was the CIO. So moving over here to take a slightly different role potentially. Yeah, and previous to being in Oregon, he was the CIO for Oklahoma.

So he has been working his way up the chain in terms of quality of states, Oklahoma to Oregon, now to Colorado. Yeah. Pretty good. There's really nowhere to go from, from here, right? True story.

Maybe, maybe if he goes to Mars when, when Elon launches to Mars, that's really the only other place you could go. Yeah. Start the colony out there. Exactly. Moving along, we have a story this week from, from Dark Owl around Project Hope.

This is a— this is some research that they had done into the freedom of information or the really the internet freedom in Russia. Yeah. So this is actually a really, really long blog post, very in-depth. You may remember back in July of 2019, a Russian government contractor called Cytec, they were hacked and had almost 8 terabytes worth of data leaked. And these were projects that various organizations were working on, on behalf of the Russian government.

And so one of the projects that was detailed in there was Project Hope. And this is the plans that Russia has to sort of cut themselves off or make themselves it possible to cut themselves off from the greater internet. Yeah. And I think really the thrust of this article is, number one, that we have a lot of details around what that project looks like and how they're trying to do it. And number two, that this really is, you know, a significant risk to the, you know, to the rights of the citizens of Russia who are really not going to have access to unfettered internet data.

Yeah. So there's going to be a Russian sort of intranet. And I would imagine that there will be a you know, a small bit of filtering on the information that goes into that intranet. Yeah. So maybe a little bit of propaganda there.

It'd be interesting to see what happens if someone in Russia tries to listen to this podcast. Ooh, what do they get? If you're listening from Russia, please send us a note. We'd love to know. We love all our comrades in Russia.

Absolutely. Anyway, good news. Good work to Dark Owl. You know, for those who don't remember, Dark Owl is a Colorado-based, like, kind of threat intel, you know, darknet monitoring type company. Yep.

Swimlane had a blog this week asking if you have any Windows 7 left in your environment. No, I got rid of all of it and I replaced it with XP. So I feel, I feel like I should be good. There's not going to be any vulnerabilities for that, right? I prefer to have Windows ME in my environment personally, but you're the one.

I'm the one. Anyway, you know, as you may know, this Patch Tuesday was the last Patch Tuesday for Windows 7. Unless you are paying for continued support for Microsoft, which is still possible. But who knows what is actually going to be rolled out for Windows 7 in that continued support. Anyway, the point being is Windows 7 is bad, you should replace it.

The article also talks a little bit about some of the good things security-wise in Windows 10, not just because you can't patch Windows 7, but other good things you can get when you move to Windows 10. So if you're listening to the podcast and this is the first you've heard that Windows 7 is end of life, maybe you should pause and go ahead and get rid of that Windows 7 from your environment and then listen on the way home. We'll wait for you here. You should start your own Project Hope to disconnect yourself from the greater internet because you don't want to be running Windows 7 anymore. All right.

Next, we have a blog post from Red Canary. This starts off interesting. They're talking about an infection that was in one of their customers. And a kind of interesting note you called out, Alex, was really, they start off by saying they did not— Red Canary are not the ones who recognize this in their customer environment, that the customer themselves reached out to Red Canary and said, hey, we see this thing. And Red Canary's kind of created some new alerting for them to be able to find this type of a risk of the future.

Yeah. Uh, and then the blog goes on to talk about, um, the AutoIT worm and, and what they found, how they remediated, uh, other things like that. But I think, you know, kudos to Red Canary to having a story where It wasn't just, hey, we found something and stopped it immediately for our customer because we're awesome. It's, oh, hey, you know, something sort of abnormal happened and, you know, we adjusted to that and things are good. Yeah.

Really cool stuff. You know, I think this— we've said this in previous shows. If you're a security ops person, these Red Canary blogs are really must-reads. They really walk through the details of how to recognize these things in your environment and what kind of alerts you can put in place to automatically find these things going in the future. Yep, exactly.

Next, we had an Automox blog talking about state-sponsored cyberattack risk and what you need to know. In case you hadn't noticed, Robb, there has been some escalation between the US and Iran. All of our adversaries. At least Iran, probably a few other countries as well. And, you know, there have been some warnings that have come out from government agencies in the US saying, hey, be on the lookout, there might be some state-sponsored activity based on us pissing people off.

So I've seen those warnings, but my question is, Alex, what should I do about those? Great question, Robb. It's not run around in panic because you're being attacked by nation-state level attackers. Should I do a Project Hope and cut myself off from the internet? You could do that.

Option 1. Option 1, unplug from the internet. If you can't do that, they list a couple of things here, you know, and these are, they're good suggestions, but they're, they're the basics, right? So it's inventory and control of hardware and software assets. Continuous vulnerability monitoring management, secure configurations for hardware and software, and maintenance monitoring analysis of audit logs.

Those are all good basic things that you should do. You could spend your entire career doing those 4 things, right? You'll always have work to do. Exactly. But it is— they're absolutely right that that is the way you not only stop nation states but stop everyone else as well.

Right, exactly. Our final blog post of the week. This is actually from a couple months ago. I don't know if you noticed this. I did not.

It slipped past our keen internet search filters and somehow we didn't see this story. We have to fire that intern. You're out of here. Back in November. However, I thought this was interesting.

So Optiv has partnered with Veracode and now Optiv is offering a, what do they call it? Application security development as a service. Basically, this is running Veracode tools with the Optiv MSP practices. Yeah, so if you don't have an in-house application security engineer, someone that can help you with Veracode, that can make sure that it's running properly to scan your code, that, you know, you have someone to answer questions with your developers about how to fix that stuff, you can do this as a service now and you don't have to worry about that. They can run all that part of it for you.

It's pretty awesome. Yeah, I did Definitely interested to see that. It's cool that Optiv is doing that. I know Optiv is working on a lot of different as-a-service offerings. So look for more of these stories to be coming here in this, in the near future.

Love it. That is it for the news. Let's go over to the Slack message of the week. Thanks to Andre Gaeta for sponsoring the Slack message of the week. He has been doing this for an awfully long time out of the goodness of his heart.

And we appreciate all that he has done for us and helping to promote the show. And this week we get to recognize one person for a message that we thought was, you know, a good conversation starter, and this is gonna be Cynthia. Cynthia posted a story about HBO's Westworld. There was a party at CES that was kind of a themed party. I clicked this link.

I don't click a lot of links in Slack. I saw this and it was super interesting. Basically, a reporter was invited to attend this dinner party and it was all themed like a Westworld thing, and if you haven't watched Westworld, it's sort Spoiler alert. Well, the whole point of the whole show is you're in a park, an amusement park where most of the people who you interact with are robots. Right.

So in this dinner— you just can't tell. Yeah. Of course, it's really, really good AI, really hard to tell. And then there's questions about how real do they get. At that dinner that this journalist attended, they couldn't tell who was another attendee and who was a plant.

Yeah. Also, it sounded like they had mined the social profiles of the reporters that were there. So, you know, periodically someone would come up and start talking to them about something that was, you know, that they didn't know the person, whether they were a plant or not. But that person knew them, you know, through their social media, through their friends' social media, through whatever. So it was kind of creepy.

My favorite part of it was that at one point someone walked up and handed a drink to this journalist's friend. And apparently it was a drink that that person had made up on their own and had posted on Twitter that, hey, I made this— what? I don't remember what it was. Yeah, I forget too. Margarita with a different ingredient added to it.

And they came up and said, here you go, we created this just for you. And it was his own recipe that he had created. And of course, he didn't expect anyone else knew about it, right? Yeah, it is. It's pretty amazing what people can figure out about you just from what you post on the internet.

And that the whole thing would have been really interesting, but also very creepy. Anyway, congratulations to Cynthia. You'll get to pick one item from the Colorado Equal Security store. We'll get you a note out about that. Let's go ahead and move over to events.

We do have a calendar of events on the website. You can go see what's going on out through really through the end of the year. A lot of stuff coming up in the next couple of months. This upcoming week, CSA is having their January chapter meeting on the 21st. Also on the 21st and the 22nd, ISSA Colorado Springs has their January meetings.

If you're down there for that, the ISC² Pikes Peak chapter is doing their January chapter meeting on the 22nd. On the 24th, SecureSet is doing a capture the flag event for beginners. So if you're interested in getting into capture the flag, that's your place to go. On the 25th, ISSA Colorado Springs is doing one of their mini seminars. This is a Saturday event for a few hours to learn some stuff.

I thought this was— this next was interesting. On the 27th, the Colorado Technology Association is doing a Scaled Agile Framework DevOps, basically about how to use DevOps to improve your time to market. If your company is looking to move from kind of a waterfall to DevOps and you haven't ever known how to do this, you know, get some folks over to this event at the CTA on the 27th and learn how it works. On the 28th, uh, Regis is doing a cyber summit, um, with the theme of Stronger Together. It looks like a full-day event, pretty cool.

On the 29th, Denver IAPP, that's the privacy professionals group, is doing a KnowledgeNet social event. So get to know some folks. This is also either National or World Privacy Day on the 29th. Holy smokes. Yeah.

Love it. On the 31st, SecureSet is doing a movie night with Hackers. Hackers is a terrible, terrible movie. Yes, but it's about hackers, so we have to love it. Go enjoy it, guys.

That is it for the events for the— through the end of January. Of course, we'll talk about February next week. We do have some jobs to discuss this week. There's a couple of jobs at Ping. We're hiring, we're still hiring our Senior Director of Cloud Operations.

This is the head of our SRE function, basically responsible for keeping our entire SaaS products live and managing those AWS environments. And I'm also on my team hiring a Product Security Engineer. So if you're someone with a security background, development background, kind of need both of those, definitely need a dev background, send me a note. We're looking to put that person in Denver if we can. Um, uh, you can send me a note through Slack and I'd be happy to talk to you about it.

Shapeshift is looking for a security engineer. Conga is hiring an information security risk and compliance specialist. Nelnet is looking for a cybersecurity engineer. Western Union's hiring a detection engineer, cybersecurity. I see a trend here, Robb.

Bank of America is looking for an adaptive threat replication engineer. I don't know what that means. I don't know what that means. Uh, either you have to replicate adaptive threats, um, or you have to engineer adaptive threat replication. Maybe you're just cloning attackers.

Maybe. I don't know why they'd want that though. That sounds like a bad thing. Uh, moving along, uh, Funding Circle is hiring a security risk and assurance specialist. Sunflower Bank is looking for an IT risk management specialist.

There's a lot of financial companies this week. Yeah. And finally, the City and County of Broomfield is hiring an IT security analyst. Sweet. So if you're up north— so this, this might be the first week that other than my ping job about SRE, we didn't have a single leadership role, right?

These are all individual contributors. They are. Lots of jobs for those folks who are looking to— we also didn't have any, uh, you know, level 1, 2, 3, 4, 5 jobs, right? Maybe they've realized we've been mocking them mercilessly, so they stopped it. Uh, maybe.

Anyway, uh, that is it for jobs. That's it for jobs. All right, well, that is it for the podcast this week. Like we said, we don't have an interview this week. Oh, shame, shame, Robb.

Shame on us. Shame on us. And shame for all of you listening who have not yet recorded a guest interview for us. Yes. So get on that.

All right. Well, that is it for this week. We'll look forward to talking to you guys again next week, and hopefully we'll catch you around town. Sounds good. Thanks, Robb.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, events and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado Equals Security.

Back to all episodes