All episodes

Newscast

Apple Podcasts Spotify SoundCloud

News from: Atari, Russell Stover, Cipher Skin, Webroot, Zvelo, Ping Identity, Red Canary, Coalfire, Intelisecure and a lot more!

Space Invaders or Pac-Man?

An Atari hotel is coming to town, and we can’t wait. Russell Stover is leaving town, and that’s probably best for my diet anyway. Colorado is #1 for… robocalls? Cipher Skin is not a porn company. Zvelo talks the future of ad tech. Ping talks the future of passwords (hint: less). Red Canary talks .Net. Coalfire talks buffer overflows. And Intelisecure talks AI for security.

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript4583 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 149 for the week of January 27th, I think. Is that right?

I think that sounds right, Robb. Tomorrow is the 27th. All right. Well, we're just about done with January. Congratulations on that.

Yeah. Made it through 1/12 of the year. Well, you know, 149 is not all that significant a number, but it's pretty close to a significant number for us. Yes. 150 seems like a, you know, sort of a round, round number, bicentennial.

And I mean, so sesquicentennial, not bicentennial. Oh, wow. I didn't know there was a word for that. Sesquicentennial is 150 years. Well, it also for us will actually mean 3 years of doing the podcast.

So, so next week we're going to have our 3-year anniversary and we also have a little surprise as a part of that. Yeah, we've decided we're stopping. We're done. This is it. That— no, just kidding.

We're not doing that. But we do have something for you. So we'd love it if you guys would tune in next week and listen to see what's, what's changing at Colorado Equal Security. Ooh, Robb, now I'm intrigued. What is changing at Colorado Equal Security?

Well, let's talk about it next week. Before we do that, why don't we go ahead and talk about our housekeeping? We have a Slack channel. This is an opportunity for you guys to, to get to talk to your, you know, your favorite 1,200 folks in the Colorado security community. A lot of great conversations on there.

We'd love to see you join. If you want to join the Slack channel, go out to colorado-security.com and look for the Slack channel button. Also, when you're there, you can sign up for our mailing list. If you scroll to the bottom of the colorado-security.com website, there is a form for you to fill out with your email address. We will get that, we will add you to our list, and you will get the show notes in your mail every week.

If you're listening, you've probably already rated us, right? Right? If not, hit pause, go ahead, come back, and then, uh, and then Now you can continue. Oh, they just did that. And we should have told them first to say nice things in the rating.

Oh man, too late. But if you haven't also subscribed, you can get the podcast in your, in your inbox or into your favorite listener every week as well. We'll just fix that in post-drop. Yeah. Also, feel free to tell a friend, spread the word, let them know about Colorado Equal Security, all the stuff we have on the website, the podcast, the Slack channel, all that good stuff.

There's 2 other ways you can help us. Number one, if you're interested in helping support us financially, help pay for the cost of the Colorado Equal Security movement, there is a Patreon campaign you can join on our website. I mean, how often, Robb, can you say I am part of a movement, right? If you can hardly even move, it's pretty good. Also, we do interviews on many, most, some of the podcasts.

It, you know, it is getting harder and harder for Robb to— Robb and I to get Freudian slip there— to get the interviews in. So we would love it if you would volunteer and be an interviewer, find someone who is interesting and interview them, and we'll get them on the podcast. And if you are interested in doing those interviews, we would be happy to set you up with folks. We do know folks who are worth talking to. We just haven't had the time to talk to all of them.

All right, moving into the news this week. Alex, I'm pretty excited about this first one. There's a new hotel coming to town. Yeah, it's 1983. Is that what's going on here?

The Atari Hotel? Yeah, the Atari Hotel. So there, Atari is partnering with a Hotelier, and they are bringing hotels with an Atari theme to several cities including Denver. So which is your favorite Atari game? Well, I mean, you have to go back to the original.

Who doesn't like Pong? Well, Pong was its own freestanding device first, and that's, that's how I was introduced to Pong. Yeah. And then of course there was Pong on Atari. My favorite Atari game though was Space Invaders.

I was, I was decent at it, but my dad liked it. So I think I probably liked it because he was a Space Invaders player. I was— not that I didn't play Atari, I never owned an Atari. So I was, I was more, you know, into arcade games. Yeah.

I don't know if I'm a Galaga guy. I don't know if Galaga was ever— I think Galaga was on Atari. I believe it was. Super Breakout was my mom's favorite, just in case those who are wondering. Dad was Space Invaders, mom's was Super Breakout.

Perfect. Next, in a little bit of sad news, chocolate maker Russell Stover is going to shutter their Colorado factory in Montrose, Colorado. Yeah, you know, I did not know that Russell Stover was actually a native Colorado company. They were— they opened here, was it 1923? Yeah, that sounds right.

So almost 100 years. You know, they could have waited a few more years before this, don't you think? Well, it looks like they had been purchased a few years back by Lindt, and the headquarters actually isn't even in Colorado anymore. I believe it's in Kansas now. Right.

Kansas City, Missouri. Yeah, well, close enough. And so they are— they're doing some restructuring. This is not necessarily a bad thing for Russell Stover themselves. It sounds like they're just shifting to be a little bit more consolidated, moving to some other factories.

They're also going to be closing some of their less performing retail stores as more people are actually buying chocolate online. Yeah, I mean, it is a bummer for Montrose. This is one of the largest employers there in Montrose. It's going to impact about 400 people. Who are going to have the opportunity to move to a different factory.

I would assume that, you know, you're not going to get 100% uptake on that. So, so negative impact for those folks. Just like all the coal miners, all the chocolate makers should learn how to coal or learn how to code. Is that what it is? All right.

Next. So this one's interesting. Colorado is the number one state for robocalls in the US. Yeah, I was, I was surprised by this. I think that is actually a per capita number.

Not a, not a gross number. It would be surprising if California or Texas or, you know, somebody else with a large population didn't have more actual robocalls than Colorado. But it is interesting to know that we get more per capita than other folks. It's a pretty poorly written article, I felt like, because it didn't actually clarify which things were per capita numbers and which were just gross numbers. Well, just throw them under the bus, Robb.

Well, okay. I'm sure the Denver Post is not listening to this right now. But interesting things on this. We did increase by 15%. From 2015.

So the last— I think it was a 2019 survey. So the last 4 years saw a 15% increase, which is versus a national increase of 14%. So, you know, obviously pretty close to the national number. Yeah, I think the sad part here is that there is an increase in robocalls, right? It seems like something we should be able to solve pretty easily.

A couple of interesting things on here from my perspective. Number one, the AG for Colorado Phil Weiser has pledged to protect consumers from robocalls. He's working with it to try and get that taken care of. And number 2, about this survey showed that about half of all cell phone calls in the US are spam, are robocalls. Half the calls.

Yeah. Well, I mean, if you go back to when, when email spam was king, when it wasn't like, you know, 97% of all emails or something like that were sent were spam. So I guess it's not too bad. I believe there was also some— a national law that was passed or changed around robocalls, making it— I don't wanna say harder, but more larger fines for folks doing robocalls. Was it a law or was it a regulate— like a ruling from FTC or something?

Either way, we don't know. We don't know. Next, Denver startup Cypherskin has got an investment from Boyett Petroleum. We've talked about Cypherskin before on the podcast. They make a I guess we'll call it a membrane that can be used for various different things.

And in this case, Boyett was interested in using it for pipelines. So you put this membrane around a pipeline, you can detect vibrations and potential leaks and other things that are going on in the pipeline. So that's pretty cool. Pretty cool. It, it'll actually create a, a 3D visualization of whatever it is around.

So you can see, you know, here's your map of what it actually is versus here's what, you know, some, some GIS thing said it was going to be, you know, before it was built, right? So pretty cool stuff. CypherSkin also talked about that they've been talking to sports teams, water companies, military, and other folks about trying to use their materials for other uses. Pretty, pretty neat. There was an article in the Channel Daily News, Robb, about OpenText, one of my very favorite periodicals.

I'm sure it is. About OpenText and their purchase of Carbonite. Last week, strangely enough, we were talking about Webroot and Carbonite and couldn't remember who it was that bought them. It was actually OpenText, Robb, that bought them. The cool thing about the article is talking about how OpenText is very excited about the security capabilities of Carbonite as part of the acquisition.

Yeah, it really sounds like the, the Webroot portion of Carbonite, it was a big part of OpenText's reason for buying and the fact that it's going to allow them to bring those consumer and, you know, endpoint type of AV protections into their enterprise customers. They were talking about that, you know, many of OpenText's customers have hundreds of thousands of employees, and those folks are using their personal devices to connect. And some kind of combination here where they're using Carbonite/WebRoot protections could really help protect those enterprises as well. Yeah, definitely. Um, OpenText is also one of those weird companies to me where I hear their name fairly often, but if you wanted me to pin down exactly what it is that they do or one of their products, I'm not sure that I'd be— DNS.

DNS. That's, that's what I've got for you. Yeah, I'm sure that there are a few others too. All right, next we have an article here from Zillow. This is— I actually found this really interesting.

This is educational, especially for those of you listening who are, you know, who are not in the marketing space much. This is talking about how online ads have changed over the years and what the future looks like there. So they start talking about the contextual ads that we're all familiar with, you know, call it 10 years ago where, you know, if you go to a a biking website, you're going to see an ad for biking parts. And if you go to the San Francisco Giants website to look at how they're, how they've been doing, you're going to see ads to buy a San Francisco Giants hat. That's all contextual advertising.

Well, in the last decade or so, there's been this massive explosion of what they call behavioral advertising, where we're dropping cookies on your, on your laptop to track you as you go through the web. And we're going to, you know, build a profile of you based on all the different places you go to and say, well, I'm going to buy a, I'm going to send this person a Giants branded, you know, bicycle pump because this person likes bikes and likes the Giants, right? Or they know that you've been searching for new mattresses online. And so every ad that you see everywhere is for mattresses. Yeah.

Or maybe they listen to your phone to figure out what you do. I don't know. That's, that's an ad. That's a rumor, at least. Yeah.

I mean, one of the interesting things they're talking about here is that how the, the behavioral model has been the norm now for a long time because of both compliance and the push to get rid of cookies in browsers. It's really sort of swinging back the other way to the contextual model. Yeah, so this is interesting. GDPR, CCPA are places that are really requiring opt-in consent to be able to drop cookies and track people on the web. And then to your point, the browsers that have made these rules about third-party cookies.

So when Chrome is disabling third-party cookies, the only people who will know where you're going is Google. So of course now Google's gonna have the ability to sell that, but, you know, and Facebook will have that kind of visibility within their app. But these things really change the dynamic. And what I, what I thought was interesting is it's not just we're gonna go back to contextual. It's they're, they're going back to a much smarter type of contextual, and they're gonna be able to deliver personalized-ish ads, not based on your behavior, but based on the context of how you got to the website.

It's, it's interesting, but it, it, it's, you know, there's a lot more nuance here. I think it's worth reading. Yeah, it is. It's a good blog. Fairly long, actually fairly detailed.

Next, there's a blog from Ping Identity this week. Talking about what does PingID— or what does Ping— what does passwordless really mean? Yeah, so, you know, the definition— they even start off this way— the definition obviously means any authentication that doesn't require a password, but I think that's not a very practical way to define it right now as we're trying to go from a world where we, where we have passwords everywhere all the time to a world where there's, there's less passwords. So it's really looking at how do you go from logging in every, every session to getting assurance that's the right person without using a password for each session and whether that's moving away from password as the first factor to a second factor on a less frequent basis. They go through a bunch of different use cases.

I found it interesting. And if you're looking to make a change either, you know, especially for your workforce, this is probably a worthwhile blog to read. And then the other side that there's a little bit discussed is consumers. And as you know, Amazon is probably the ideal example of this, that, you know, they don't require passwords very much just for those critical things where they're worried about fraud. Right.

Yeah. I mean, and using different things besides passwords, other authentication methods, you know, they mention in here YubiKeys, for example, you know, other kinds of tokens or biometrics. Biometrics. Yeah, that kind of thing. All right.

Moving along. Next blog this week is from Red Canary, and this is talking about detecting attacks that are used in .NET. So I feel like we spent a lot of time in the last few years talking about PowerShell as, as a way for attackers to compromise environments once they're in. Um, and, and this is talking about people who live off the land using .NET and what does it look like to discover those .NET attacks in an environment? Yeah.

And so really, uh, talking about using, uh, some of the, the, you know, the types of shells that come from those programming languages, languages like, uh, C#, F#, and, you know, potentially building things in those languages, uh, to run. And they're just talking about ways that you can detect this. Um, needing the ability to look into memory to see what's exactly going on, the ability to understand how APIs are interacting with each other, um, to see what actually is happening. Uh, so again, um, interesting, very detailed blog. Uh, this is pretty standard from the, the Red Canary folks really digging into the topic and getting some good detail.

Yeah. Same as always recommend if you are a security operations person in a company, you know, take, give this a read. I think this will only make you better at your job. You can probably call this continuing education for your certifications too. Just tell them Robb said so.

Perfect. Uh, yeah, put down when you go for your CISSP renewal, just put the sponsoring organization is Colorado Equals Security for your— we're happy to back you up. We'll provide receipts. No big deal. All right.

Next we have a blog from Coalfire, and this one's another kind of deep dive into technology. Uh, this is around what a buffer overflow in Win32 looks like. You know, I know you spoke of CISSP when I, when I got mine, you know, not that long ago, a couple years back, a couple years back, uh, I remember reading about all these different exploits and being really interested in those. And, and this looks just like that type of research, kind of showing how does, uh, how do you do a buffer overflow? How do you protect against a buffer overflow?

Um, so I think if, you know, for those who aren't aware of this type of vulnerability, uh, it's definitely worth a read. Yeah, definitely good background information. Uh, and our final news item for the week, uh, there was an InteliSecure blog talking about AI for information security. Where is the missing innovation? Yeah, this is an interesting one.

I think the main point here, uh, is, is that in techno— in security, we have all these different kind of siloed technologies. Call it your endpoint, you know, your EDR, your, your application security with, you know, static analysis, uh, your, your SIEM, all these different technologies that don't do a great job of what they— what he calls in the article the connective tissue between them, so that you understand how, you know, how a vulnerability in one area impacts the, the threat landscape in another. So the, the issue with AI is you can only apply AI to those areas where there's a core, you know, cause and effect between things. So AI within your EDR is going to do great understanding what an EDR is finding, but it's not going to do anything for you in terms of figuring out what does that mean for those other technologies. I think the article is talking about the need to create that, that bridge between them.

Yeah, and normalization too, right? So if, if you have you know, one technology and you're using theoretically artificial intelligence there and it's spitting out some kind of results and you have another thing, it's spitting out a different kind of results. Really having those normalized across the different environments really makes it harder for an analyst or, you know, even if you had some sort of automation across them trying to come up with results, that normalization is really important. So that is, I think, a great use for it as well. I'm just thinking about the you know, the parallel between this and our move from like monolithic applications to more DevOps containerized applications where you have discrete services that interact with each other, you know, based on a contract, you know, what are they supposed to offer to one another?

And it feels like that's kind of the model that security needs to get moved to where you understand what's the bucket over here and what's the service supposed to accomplish and how does it talk to your other services more discreetly? Right now it feels like it's kind of ad hoc in security. Definitely. Uh, everything has a different output. Everything has different scales and scores and everything else like that makes it hard to, to have that contract between them.

Yeah. All right, cool. Uh, well, that's it for the stories this week. We can go ahead and move over to the Slack message of the week. Uh, big thanks to Andre Gaeta has been sponsoring this for us for a couple years.

Um, the winner of the Slack message of the week gets one free item from the Colorado Equal Security store. Uh, Robb, this week's winner is JD Burke. Congratulations, JD. Uh, JD posted about the Rails Girls Summer of Code. This is a, I guess you could call it like an internship.

I think they used a different term for it, but basically women can apply to this to get a stipend to work on existing open source projects and help contribute to those to help get skills in coding. That's awesome. So congratulations, JD. Thanks for pulling that out. We love to, to get this kind of visibility and of course amplify it here with our, with our podcast.

If you're interested, we'd love to see you guys apply to that Rails Girls program. And, you know, JD, we'll get you something out of the Colorado Equal Security Store. Also, if you want more information on the Rails Girls Summer of Code, which is a mouthful to say, go to railsgirlssummerofcode.org. No spaces. It's a mouthful to type, too.

It is. It is a mouthful to type. A fingerful. All right. Well, that is it for that.

Let's go ahead and move over to events. We, we do want to remind you there's a calendar of events on the website. Lots of great stuff going on there. You can go see what's happening through, through February and, and really through the rest of the year. First, CTA is doing their Scaled Agile Framework, SAFe, DevOps, Improving Time to Market with the Scaled Agile Framework on the 27th.

That was a mouthful. That was a lot. That's a long, long title for an event. I think CTA is basically doing an Agile DevOps event. That's, that's my summary there.

That the title was not very agile. Yeah, that's not an agile timeline. All right. On the 28th, NCC is doing a Data Privacy and Cybersecurity Compliance Toolkit for Small Businesses event. Pretty cool.

Also on the 28th, Regis is doing their Cybersecurity Summit: Stronger Together. On the 29th, Denver IAPP is having a KnowledgeNet social event. On the 31st, SecureSet is doing a movie night with hackers. On the 5th of February, SecureSet is doing a capture the flag. Uh, on the 5th also, ACES is doing their 2020 kickoff meeting.

And finally, on the 6th of February, Splunk is doing their First Thursdays at Topgolf. If you want to go golf with some Splunk people. Yeah, fun time every first Thursday for infinity and beyond and beyond. All right, a couple of, uh, jobs here at Ping. We'll move over to the job section.

I do have a couple folks in security I'm looking to hire. Number one, we are hiring a security engineer— a product security engineer, excuse me. So someone who's got a coding background, either with a security background or a passion to get into security, would love to hear from you. We can put that position here in Denver. And I'm also hiring a person on my GRC team who's going to be helping be responsible for our incident response, business continuity, and disaster recovery programs.

So if you want to be a part of Ping Identity's GRC team and really be the leader of those response capabilities, you know, reach out. Love to hear from you. Elevations Credit Union is looking for a VP of Information Security. That sounds like a pretty good job too. SomaLogic is hiring an Information Security Analyst.

Wells Fargo is looking for a Risk Strategy and Initiatives Officer. Uh, in the WIM Business Risk and Controller Office. Why am I getting all the long titles this week, Robb? I was just about to say, I'm really glad you ended up getting that one. That one's, uh, that was definitely a mouthful.

It wins the longest job title of the week award. Comcast is hiring an Architect VI. Whoa, VI? I don't think we've ever had a VI. And they, they just totally abandoned Roman numerals for this too.

They just went straight to the digit. Uh, it's an Architect VI Cybersecurity Architect. I got to tell you, the only reason I picked this job is because it had a VI in it. Elastic is looking for an InfoSec Senior Security Assurance Analyst. Dish Network is hiring a Senior Cybersecurity Threat Hunter.

The US Department of the Interior is looking for an IT Cybersecurity Specialist. And I actually got reached out to personally about this one to help find the right person. Not because they want me, because I'm clearly not educated enough for this, but Colorado State, or excuse me, Colorado Mesa University is hiring a assistant professor of cybersecurity and computer science. So they're looking to build out their capabilities in security and would love to have someone who's, like I said, more educated than me go be a professor there. That's interesting.

Is that in Grand Junction? I believe Mesa is in Grand Junction. It is in Grand Junction. Wow. Yeah.

So pretty cool. So maybe one of the people at Russell Stover will want to go from Montrose over to Grand Junction. They're going to have to get on it, get a little education here first so that they can be ready for it. Like you said, just, just learn to code. If you learn to code, if you're a cool person.

Yeah. All right. Well, I think that's it for the news. That is it for the news. And that's it for the podcast then.

What? I'm looking forward to, to getting together next week and seeing what's new for 2020. But I think for now we can let everyone go home and, and just be without us. I'm not going to be able to stand it for an entire week, Robb. All this anticipation.

You can sit then. I'll sit. All right. Thank you. I appreciate that.

Well, that's it. Thanks, everybody. Have a great week. Thanks, Robb.

Learn more about the Colorado security scene at colorado-security.com. Where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado Equals Security.

Back to all episodes