Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 161 for the week of April 20th, 2020. Alex, once again, we are, we are remote, we are distanced from one another.
I feel like the weeks are just flying by at this point.
Everything is going fast and slow and everything all at the same time. It's, it's very confusing. Yeah, there's, there's a saying that the years are fast, the days are slow. I feel like that's, you know, the weeks are fast, but the days are, the days are slow. And I'm actually, you know, getting around like to not, not hating it so much.
Things are okay. The new normal, as they say. Well, you know, it is our— it is 4/20 here in Colorado, which is a couple of different significances here, right? Of course, there's lots of folks who like to partake of what used to be illegal on the 20th of April, but it's also Memorial Day, right? Yeah, well, I mean, first of all, we are lucky that dispensaries are essential businesses, so everyone should be able to do all right with their supply on 4/20.
But, you know, 4/20 is also a not as happy day in some respects. It was the day of the Columbine shooting, but out of that is a good thing. Every year on the 20th, all of the students at Columbine use that as a day of service. And this past week, the governor signed a proclamation that 4/20 is Colorado day of service, or I don't know the official term for it, but it is now a state day that on the 20th everyone should take some time and do something good. I think we can all get behind that.
My— yes, my only recommendation is, you know, don't smoke pot and then do service. You might not do it very well. You never know. All right, let's go ahead and jump over. We do have some housekeeping reminder.
We have a Slack channel, man, a lot of good folks in there. We continually having great conversation. It is at least one thing that will keep you informed about what's happening in the in the area and give you some other new friends in the security scene. If you wanna join the Slack channel, go out to colorado-security.com and click the Join Slack button. We also have a mailing list.
If you go to the website, scroll to the bottom, there is a form there to sign up for the mailing list. Once you do, you'll receive the show notes delivered to your inbox every weekend prior to— as the podcast is released. So you'll know exactly what's happening. When it's happening. We'd also love it if you would rate us and subscribe on your favorite podcast listening app so you, you get them directly into your inbox.
And of course, by you rating us, uh, you will help others find the show and hopefully get us some new listeners. Also, feel free to tell a friend, uh, let them know in appropriate social distancing, uh, manners how great everything is at Colorado Equal Security and what they can learn here and why they should be involved. And if you're looking to help support us, we could use your help for financial support. Our Patreon, which you can also find out on our website, helps pay for the cost of the podcast, the hosting, all that good stuff. We do want to do a big thank you to the current Patreon supporters.
We have a good group of people who are helping keep the show from going under financially. Thanks to all that you guys do. We do appreciate you. Yeah, and as we've mentioned several times, you can find all of that and more on our website at colorado-security.com. And Robb, you know, I'm using this downtime for good.
I updated our secured organization page on the website this week. We now have a new look there. That's fantastic. So if everyone— number one, if you don't even know what he's talking about, well, get out to colorado-security.com, go to security organizations, and you can see all the different groups in town that have been moving their meetings to virtual. So you can still meet with these folks, just you'll have to jump onto the internet to watch them versus going in person, at least for now.
Exactly. So let's jump into the news. Uh, first we have, uh, some records that were broken this week. Uh, Boulder is America's snowiest city and it's not even close. Yeah, I was, I was shocked to see this.
Number one, I didn't think that Boulder would be close to the, the snowiest city in the country. Um, there is some details here. Uh, in order to be defined as a city for this, this article, you have to have at least 50,000 people in the city, which makes sense, right, if you're going to call it a city. But they've had 145 inches this year and it's It's, you know, quite a bit more than the next closest cities. It's actually more than twice as much as what Denver, Fort Collins, and Colorado Springs have this year.
Yeah, and I guess I hadn't realized that it had been so snowy in Boulder, but apparently there's been a lot of upslope snow events this year, and that is what hits Boulder the hardest. You got the Flatirons there, so when the weather comes in from the east, it hits those Flatirons, goes straight up and makes snow. So interesting stuff. I, you know, like what— like you, I didn't know that this was such a big snow year for Boulder. There are a bunch of cities that generally have quite a bit more snow than Boulder, like Buffalo, New York, Rochester, Albany.
Also cities like Grand Rapids, Duluth. Those usually have more, but this year, you know, they're not even close. We're like under 90 inches for most of those, you know, so we're almost twice as much. So go Boulder. Yeah, I also saw it was either Boston or New York only had like 15 inches or something all winter, which is crazy.
Boston was 15 and New York had like half an inch. It was like not even close, right? Really down snow years for a lot of places, but not for us. Very strange. Speaking of weather that's worth talking about, so that's kind of a cool fun news on the, on the Boulder side.
Not such good news on the Western Slope where our policy, our Palisade peaches are at risk due to a really cold temperature they had last week. Yeah. I think as everyone in the local area knows, we have had some cold weather within the last week. And it got very cold out there on the Western Slope down into the teens, which is, has a potential effect to freeze off some of the buds on the peach trees and then make a subpar peach crop this year. Yeah.
It looks like, you know, there's several quotes in here. Some say, you know, more than half were destroyed. Some say almost all, like close to, close to 100% of the buds were destroyed. So I think it'll take a little bit for us to know, you know, how big the impact is, but it's possible that you will not be seeing Palisade peaches in King Soopers this summer. Which would be, you know, for me personally, kind of a bummer.
Yeah. I mean, I guess you, my guess is you'll probably see them. But there will be fewer of them and they will be more expensive. Well, you know, that could be also, it could be because of that, this, or it could be because of COVID and everyone's buying them all up. Right.
Who knows? You never know. You never know. Uh, next, uh, Molson Coors and a company called Hexo are working together to make non-alcoholic CBD drinks for the Colorado market. So I don't know if you remember this, Alex, but we actually talked about this in 2018 when they first announced the partnership.
What's, what's different here, the update on the news is now 2 years later they've decided they are going to target Colorado as the first market for them to bring the CBD non-alcoholic drink into. So we're gonna get to try it out. Yeah, sounds pretty cool.
Everybody seems to think that CBD is pretty magical in terms of its anti-inflammatory properties, so we'll have to check out these drinks. I have no opinion about that. I have no idea, but I did find it interesting in this article that they mentioned there are other breweries who are doing this, including Left Hand Brewery, who's in Longmont. They have their own CBD sparkling waters. So it's not, you know, Molson Coors is not going to be the first beer maker to have a Colorado CBD non-alcoholic beverage.
Yeah. Also to note, this will not be made out of the Coors plant out in Golden. It will be made out of a different location. Yeah, I did see that. They haven't said where yet, right?
And they also haven't said when it's going to hit market. So we got to wait and hold our breath for that CBD water. Exactly. We have an update from an article. I think it was maybe from 2 weeks ago where we talked about a new broadband network that was released in the Western Slope and up in the mountains.
If you remember Project Thor, this is an interesting update from the Colorado Sun. Tamara Chuang, who is always fantastic, really giving some more insight into that story, a lot, a lot deeper than what we had previously. It looks like, you know, the real impetus for this project was because the, the commercial, the for-profit cable companies up there just were not, you know, we're not fixing their networks quickly enough. And things like hospitals were continually suffering outages that, that were putting them at risk. Yeah, this article really brings the hammer down on some of those.
Hey, hey. But yes, it sounds like there, there were lots of outages, not great service up there. And so, you know, this was really a win for a joint group of governments that got together to get this project going. So that's That's pretty cool to see. Yeah, it was interesting as I was reading it, you know, there's a lot of, you know, the only people who were really opposed to Project Thor were the cable companies, the telcos.
But as I read through it, it really looked like kind of across the board, everyone recognized that the private industry just wasn't responding to the needs here. And this was a good time for government to step in. And it's just interesting to hear, you know, some broad agreement around something like that, which is a little bit controversial. Yes, and this was also the first time I've heard the term middle mile. They mentioned that a couple times in the article that the Loop in Project Thor is the middle mile.
It's not the last mile to the house. It's not the backbone, but it's the middle mile in between. Yeah. Next, we have a story here from American Inno, which is kind of a local look at technology in Colorado, and it was talking about a new Denver IoT— it's not new, I guess, but new to us, new to me at least— an IoT supply chain company called Is it Parasyl, probably? Parcel?
Parcel, maybe? That sounds like a funky way to spell parcel because it's about shipping. Parcel has raised $15 million in funding, and I thought what they're doing is pretty interesting. Yeah, it is. It's an IoT device that shippers can use to understand where things are moving and help to ensure goods as they move through the supply chain.
That they're better accounted for. It's a little weird to me because you're right, there's an IoT device there, but there's also— it looks like they're also an insurance company. They're approved by Lloyd's of London to do cargo insurance in Alaska, California, Colorado, Louisiana, Maine, Massachusetts, well, some other states as well. So number one, they're going to use this money to broaden into new markets where they can do this insurance. It's just kind of an interesting combination of they're a technology company making their IoT device But they're also an insurance company.
You'll see that a lot. Yeah. So, I mean, it is sort of interesting. It's functionally using the technology so that they can not have to make as many insurance claims, right? So, if you keep the things going to where they need to go, people don't have to use insurance and maybe you can be more profitable that way.
Yeah. I'm looking forward to seeing more from them. Hopefully, right now with what's happening with the world, supply chains getting thrown into a loop, maybe what they do becomes more important than ever and this could be an acceleration for them. Let's hope. Yeah, for sure.
Next, some acquisition news. In this case, Swimlane, which is our local company here in the SOAR market, they acquired a company called Syncurity to help bolster their product. And it looks like Syncurity is a sort of complementary product that works in the incident response and sort of ticketing space to help automate those processes. Yeah, I was super excited to see this. We are big fans of Swimlane here in town.
We've had them on the show a few times. We talk about them quite a bit. Really cool news. We did get a quote from Cody Cornell, who's co-founder and CEO over there. Summarizing, at a high level, it makes sense for both companies.
They're going to be stronger together because they have unique products and they have unique customer bases. It's going to help them extend their offerings to both. Kind of moving back over to the details here, the Syncurity company is actually headquartered out east in Bethesda, Maryland, which is another cybersecurity hub, not quite as good as Colorado, but they do, like you said, do IR flow. They actually came out of the Mach 37 Cyber Accelerator, which is fairly well-known. So they look like a good company.
I'm excited to see what they bring into Swimlane to make them better. Yeah, sounds like a good match there. All right, uh, moving on. Some more. Oh, this is good.
We're not in person, so we get to talk over each other. I love it. Let's do it. Maybe we should both read this story at the same time.
Um, uh, some other, uh, news for local security companies. Optiv has announced that they are getting a new CEO, their second. Yeah, this is pretty exciting, and this is something that, um, you know, has been talked about kind of being in the, in the works for quite a while. They've been courting a man named Kevin Lynch, who is a senior partner over at Deloitte, for over a year, and it looks like they've come to terms. He's ready to start.
He's going to start as the new CEO for Optiv on April 17th. So not only is this Optiv's second CEO ever, I think it's actually, if you go back to AccuVant's history as well, it's going to be the first leader of that organization other than Dan Burns, who was a co-founder and has been the CEO over there for almost 20 years.
As a general statement, since he started on the 17th, it's always great to start on a Friday. Perfect day to start, you know, get one day in the office and then get a weekend. Right. Well, he's not gonna get in the office probably. That's true.
One day on the job, I guess that's a better term for it. He's remoting into a different company's laptop for that one day, right? Right. So congratulations to Optiv. This sounds like great news for them.
This seems like the guy that they were looking for, and hopefully he comes in and helps make them an even better company. I do want to just throw out there that Dan Burns is staying on, at least for some amount of time, as an executive advisor. So they'll have the old CEO around to help with the transition, and the new CEO will be able to get up to speed hopefully pretty quickly. All right, moving along. We do have a story this week, a blog from Ping Identity, about 5 authentication experiences that drive customers away and cost you revenue.
Now, we don't We don't usually go through a lot of the details in blogs. I found this to be actually kind of interesting, 'cause I don't think a ton about customer experience in my websites as a security guy, but most of these made sense to me. They started off with mistake number 1 is using knowledge-based authentication. So the, what was your, what street did you live on when you were in 9th grade, or what was the mascot of your high school? And that as a bad usability experience and also as a bad security.
Step. They talk about, you know, my favorite one, probably number 2, poor authentication via customer service phone calls. Yeah, I don't know about you, but number 1, I hate automated phone systems, and I hate when authentication fails and there's like nothing you can do to, to go further. I think they call that one out, is super frustrating. I hate it when authentication succeeds and then you get to the next person in line and you have to do authentication again.
Oh my God, you know, so it's, you know, you call and there's, uh, you know, an automation, you give it give it your stuff, and then you get to a person and they're like, oh, I just want to verify that you really are who you are. Well, we already did that. And then, you know, maybe they pass you to somebody else and you have to do it again. No fun. No good.
Mistake number 3, confusing password policies. You know, everyone hates when— it seems like on the Slack channel every once in a while we'll see someone pasting in a snippet of like just a terrible password policy somewhere, you know, limiting it to no more than 7 characters or, you know, whatever the— whatever the errors there are. Mistake number 4 is a really lengthy registration process, too many fields. You know, I'm— I can't tell you how many times I've gone through registration and I get frustrated at some point and stop doing it. Uh, last one is a burdensome account recovery process.
You know, if you only sign into a website once a year to, to pay your taxes or whatever it is, and it's really tough to get your password back, that's no good. So anyway, it's good feedback. Um, I will say, alluding back a little bit to mistake number 1 for knowledge-based authentication, You know, that was something that was obviously pretty common for a very long time and that we all know is not a good security practice. And it's amazing to me how much companies have gone away from that. And so, I mean, now if I go to register somewhere and they're asking me those knowledge-based questions, I'm almost shocked that they're doing it anymore.
Yeah, it's definitely become a standard not to do it. So next we have a— oh, go ahead, Alex. So next we have a blog from Zavilo talking about tips to secure your home. So they're pretty practical tips in here. Frustrations like, what do I do because I have too many passwords?
Well, they recommend using a password manager. What do I— you know, there's a significant risk around having IoT devices or routers with default credentials. Well, they tell you you should change those credentials, right? So pretty basic tips, probably something you should give to your family. Using 2-factor authentication.
I think that's great. Anywhere you can turn on multi-factor, you should definitely do that. They're also talking about, you know, patching and some other things like that. Obviously, if you're in an enterprise, you probably have someone that takes care of that for you, but as you are the admin of your home network, you need to make sure you're doing that too. Yeah, it's really a bunch of good tips.
Like I said, probably good reminders for us, for those of you listening, but even probably better reminders for those in your family who who don't spend a lot of time listening to security podcasts. Probably a good thing to share with them. Next, we have a story this week. It's actually a LogRhythm blog with takeaways from the 2020 SANS Women in Security Survey. I thought that this was great content, not just for women, really anyone looking to further their career, but of course, especially for women who are, who are trying to get better diversity in the field.
Definitely. And they go into detail into these areas. In several different places, but just real quick, some of the points that they make. First, that women must be proactive to get ahead. I think we have seen the stats several times.
We've talked about it in many different articles about how males need— I think it's about 60% of the requirements from a job to feel comfortable in applying, whereas women need to have a much higher percentage before they generally apply for a job. Number 2, that a degree can help you break into cybersecurity, but you need to make sure you're doing ongoing training and potentially certification to make sure that you can get there. And then number 3, that mentoring is really important, and that is not just something that's important for women in security, but important for everybody. Yeah, and I'd go further and say that in terms of mentoring, it's critically important. It might be the most important thing you can do to help your career, and it shouldn't be as intimidating as you make it out to be.
The vast majority of security leaders and really industry leaders in town are going to be happy to help. Just, you know, be willing to reach out and make the ask. And as the mentee, be willing to do the work. You know, come show up ready to learn and, and kind of understand what it is you're trying to get out of it as you talk to those folks. Definitely.
And then our final story this week is a blog post from Red Canary talking about their open sourcing of their Invoke Atomic Red Team PowerShell framework. Yeah, so this is really interesting to me. We, we love what they've done over there with Atomic Red Team and creating, you know, just high-level summary, Atomic Red Team gives you ways to test whether your security controls work at a really, uh, granular level, right? Uh, you say you have the ability to stop, uh, this kind of malware from, from executing on your laptop. Well, let's, let's test it.
So they create a bunch of scripts to be able to test each of these controls. Well, the Invoke framework is a way for you to actually fire off those tests easily in an automated fashion versus having to manually do it or create your own scripting to run those tests. So this open-source framework for running those various tests is the thing that they're talking about here and have open-sourced, and it looks like it's really grown over the last couple of years. Yeah, it sounds really good. They go into a lot of details here.
They even have, uh, some features in the framework to help you create new atomic tests. Um, it used to be pretty manual to do that, and so they built this in to make it even easier to create new tests on your own. Good stuff. Check that out. Thanks to those guys for the work on that.
Uh, moving over to the Slack Message of the Week, big thanks to Andre Gaeta, who is, uh, as always, the supporter of this. It was his idea, and we love, we love the fact that we get to recognize someone from the Slack community each week. That person is given a $25 $50 gift card to pick something from the Colorado Equal Security store and hopefully, you know, wear that thing proudly as they don't leave their house. Exactly. And this week our winner is Ian, or Jan, depending on how you might pronounce it.
And the post was regarding a free digital forensic course from Autopsy. This is a $500 value, which is pretty cool. I think a lot of people now have either one of two things. They either have some, you know, potential free time because working at home, they're, you know, maybe a little more streamlined and not having to worry about, you know, some of the things that take up time when you're in the office. But also, you know, probably a little bit of monotony doing the same thing over and over again.
So if you want to spend some of that time that you have doing education, I think this would be a great way to do it. Yeah, so this course that Ian shared is actually still available. I think it's open until mid-May. Get out there, $500 course. I'll tell you, I shared it with my team at work and I recommended folks take it.
I know some are taking it up on it. So really good way to spend some time, and like I said, $500 free course. So anyway, congratulations to Ian. You will get one item from the store. I'll send that information over to you, and we look forward to seeing more great messages on Slack this week.
Awesome. Let's jump over to events. Again, the— we have an event calendar on the website, so check out colorado-security.com. Make sure that you do go into the events on the calendar and check the links because they may or may not be remote at this point. We're hopeful that many of them are, and we're, you know, talking about those here, but there may be some that we haven't captured that are remote that are still on the calendar.
All right, so the first event this week on Monday the 20th, the Software Freedom School is doing a Security+ peer study group, exam prep, and Nazgûl slaying, which I assume means there's Lord of the Rings involved somehow. Yes, maybe you can find your rings and get your Security+. CSA Colorado is doing their April virtual meeting on the 21st. And DerpCon, this is the virtual conference, is going to be happening the 30th through the 1st of May. 2-day thing, all virtual, all local folks.
The intention for this group is to actually start doing a physical conference in future years, but for now, last I saw just a day or so ago, they still had their CFP open. So if you want to talk, there might be a chance to do it. I think it's going to be a great way to get to meet some folks and hopefully some good content as well. Yeah, organized by local folks, should be good. So check that one out.
So let's jump over to jobs. Robb, does Ping Identity have any jobs this week? Yeah, I do. I have a couple of jobs open. I'll just talk about our GRC analyst focused on business continuity and incident response.
I'm hopeful that we, uh, we actually have some really good candidates right now, so it might, might be too late by now. But, uh, if we talk about it next week, you know that there's still an opportunity. Of course, do apply. I'd love to hear from you if you have questions as well. Charter Communications is looking for a senior manager of network security operations.
Staples is hiring a senior application security architect. Elevations Credit Union is looking for an information security engineer. And I think you mentioned that their VP of Security position is still open too, so leadership role there as well. Cisco Talos is hiring a Senior Incident Response Commander. Uh, now this next one, don't be confused by it, but the state of North Dakota is looking for a Director of Cybersecurity Operations.
So the reason we have that on there is this position can be remote, so you can make North Dakota money but stay in Denver. That's what I hear. That's what I— sorry, that's a joke for everyone. So Slack is also hiring. They're looking for a staff software engineer focused on product security.
I hear that there are actually a few jobs that are open at Slack. Caterpillar is looking for a senior exploitation specialist. That's pretty cool. Uh, SnapDocs is hiring an application security engineer. And Divinity— excuse me, Dominion Voting Systems is looking for an IT security engineer if you want to.
We've talked about those guys, Secure the Vote. Check that one out. It's a good time to do it. Well, that gets us through the news, Alex. We made it.
We do have a feature interview this week. Angel, also known as AI from the Slack channel, is our featured guest, and John Hubbard sat down with her. She not only is— she has— she's a security professional, but she's done a lot of work volunteering in the community, including she's now the head of the of the Denver BSides meetup, the, the conference, and she's also one of the directors for SkyTalks. That is awesome. I look forward to the interview.
All right. Well, thanks everybody. You have a great week and we'll talk to you again soon. Awesome. Thanks, Robb.
This is Artie Wilkowsky, CISO at Dish Network. Welcome to Colorado Equals Security, the podcast for Colorado security professionals by Colorado security professionals. Hi, Colorado Equal Security Community. This is John Hubbard. I'm sitting here with Angel.
Angel, how are you today? I'm doing very well. Thanks, John. Good, good. Well, glad to have you here.
And to get us started, you have an important awareness topic that you want to mention to the information security community. Let's talk about that. Yes, I do indeed. Thank you for letting me talk about that here. I want to talk about a trend that I'm seeing a lot of organizations that are fraudulent organizations that are advertising to assist especially women in tech, but just people period, professional folks.
These organizations have advertisements and a lot of them have advertisements on LinkedIn and people tend to think of LinkedIn as being a professional platform, so they are inclined to trust those ads and not look that much, that far into it. So these, these organizations, they'll probably that they'll help you network with a bunch of other women in tech, or they will promise to help you get paid advisory positions. That's a big one I see, one on almost every single LinkedIn page I visit, and it's maddening. So these guys will get you on the hook, and the ones that I have heard about for women specifically seem to have very high-pressure sales. So they'll get women on the phone, And then they will pressure them into making these purchases and giving credit card numbers for what eventually ends up being at least $1,000 worth of charges.
That's a lot of money. It is a lot of money. And there's— they'll slip it in, oh, and there are no refunds. I've seen a number of stories on different fraud report sites about that specific technique where they don't say you don't have no refunds until they've actually got your credit card. Yeah, so, so are these active members, like I'm sending you LinkedIn messages trying to get you to call me, or is it just advertisements that would show up after I log in?
I've only ever seen the advertisements after logging in. I've never gotten a direct message, thank goodness.
But they're kind of, you know, be a little cautious about the companies that are asking for large amounts of money to be a member of their organization. The legitimate organizations for the most part hover between $100 and $300 for an annual membership, and that seems reasonable. So if they're charging a lot of money, question, make sure that you're getting your return is the correct value there. That's a way of putting it. And check around for reports from other people.
Check your BBB, check with the Colorado Equal Security Slack channel. We're all here, all professionals to support each other. You can also check the ripoffreports.com or just punch in the name of the organization and fraud or scam into Google and see if you get anything. Yeah, see what comes back when you do some research. Yeah, so that's, that's a very important message.
There are lots of legitimate information security organizations out there and we want to mention those as well, but You know, these ones that offer a one-time high-dollar amount offering seems like they're the scammy ones. Yeah. And the ones that are sort of target every opportunity they have for money. So the ones that are charging a large amount for your membership plus a large amount to attend the conferences plus any— they'll often have additional service fees to do things like revamp your profile or publish an article with your name in it. I've seen that one a lot.
I've never actually seen an article come out of it. But yeah, so a lot of them change their names, but they seem to sort of use similar names like World Association of Women Professionals. That's not a real one. That's one I tied together with just their, their buzzwords. International or national seems to be a big deal, or global.
They want to make themselves look like they're a nice big organization. Oh, and the advisory ones. They say you can make $500 to $5,000 in advisory fees, but they don't actually promise. There's no promises behind that. So just if you see that kind of thing, be really careful.
If you have been taken advantage of by one of these offers and it's been less than 60 days, file a report with your credit card company. There's a decent chance you can get your money back. Get the charges reversed. Yeah, correct. Well, great.
Thanks for bringing that up. That's buyer beware for sure. Unfortunately, there are companies out there that prey on folks like us who, you know, want to have an impact on the world, right? Well, oh, and people who are looking for jobs. Those networking ones.
Yeah, they hit people who are looking for jobs really hard because we are looking to network. We do need to do that in order to find a new job. So it makes us ask extra vulnerable. Sure, sure. And as you mentioned, the Colorado Equal Security Slack channel is a great way to reach out and say, hey, has anyone ever heard of this organization?
Have they served you well? Because we should be looking out for each other. Have you always had a suspicious mindset and, you know, kind of a little cynicism with these things your whole life? Um, yeah, pretty much. When I was quite young, I decided I wanted to grow up and be a spy.
And ever since then, I've just, you know, I'm always thinking, how can I get in there? How can other people get in there? So it was really very natural for me to end up where I am. Yeah, that intellectual curiosity of how does this work? How can I get around it?
Can I take it apart? Sure. When did you start getting interested in technology? You know, I was really a very lucky kid of the '80s. I was one of the unusual female teenagers whose mom brought them home a computer.
They were, you know, marketed in the boys' section of the toy store, so it just was not a natural thing. But I— and I really don't know why she suddenly thought it would be a good idea if I had one, but she did. And she brought me this Commodore 64, and I got to— if you remember those, oh my, you probably don't, I'm old. But yeah, so got to learn to program program it in BASIC, and for a long time I didn't have any way to save the programs. So I would literally have to put them back in every time I wanted to do anything.
That's a lot of typing. It was. And I got really excited when they came out with like the Radio Shack tape player and I got my hands on one to use the metal oxide tapes to go ahead and record my programs. And then I could play them back into the computer. It was really fascinating.
What really caught me at that point was the difference between typing what I'm typing, and then apparently there's some way of saving that, that typing as a sound wave or some other thing on the— on the tape, right? I know how it works now, but when I was a kid, I didn't know it. It was magic. Sure. Okay, and technology has progressed a little bit since the Commodore 64 days.
Yeah, how have you kept up with the ever-changing field of technology? Um, you know, it's funny, so I guess I go back to school periodically. That's one of the ways. Um, when I first started in, uh, technology, I was working as a— what was I— a mobile systems technician. So we would get you know, calls from just random people who got us out of the phone book.
And then we'd hop in our cars and go to whatever the site was. Okay. Fieldwork. Yes. Figure out the problem, find a solution, get it in place, get paid and leave.
So that right there will teach you, um, a really, my best, most helpful skill, which is figuring things out very quickly and how to use Google. Thinking on your feet. Oh my goodness. Yes. Thinking on my feet.
So, um, And I just have a natural curiosity for things. I'm always poking into stuff. But I started going to school while I was doing that, and I got my associate's degree in networking there. Computer networking, TCP/IP, that sort of stuff. Yeah.
So I was kind of a network engineer to begin with, but even then I was already working with security stuff. A lot of our calls were malware, especially when the, uh, it was like, 2008, 2009, somewhere in there, where individuals started getting really hard hit with the ransomware, the early ransomware, when it was actually targeting individuals instead of corporations, right? So we got a lot of those. So I got to learn how to reverse engineer that, and that was fascinating. So what was I talking about?
Oh yeah, how I got started, or no, how I keep up. Yeah, and the answer really seems to be I do, I keep going to work or finding different things to do, or I mean going to school or finding different things to do. I got my associate's degree and then it was like 2 years later I started my bachelor's degree because it seemed like I needed one in order to attain those higher roles that I was after, senior, whatever.
So that has helped a lot. And then I keep in touch with a lot of people in the community. I've got my fingers on a lot of different pulses. I get notifications about all kinds of different things that people are doing. Sure.
Not just in the Colorado Equal Security Slack, although that's been great. I love our news channel. Well, you guys' news channel, but also other different— the DEF CON and the SkyTalks and all of those things. BSides. Yeah, let's talk about that.
So you're involved with BSides Denver? I am. I've been involved with besides Denver for several years. I started out volunteering and then, I don't know, I really don't know how this happened, but just one day Banshee, the woman that used to— who was the president for a really long time, she was like really the figurehead for a really long time. I've got big shoes to fill, by the way.
She asked me if I would like to be on the board of directors. And I said, neat, heck yeah! And so I was on the board of directors just as a director for several years, and then she went on to work with the EFF out in San Francisco. Lucky her. So she left Denver?
She did, and we needed a new president. At the time, I was unfortunately unemployed. I had my position at Arrow had ended and I hadn't found a new one yet, so I had all this time. So I was doing all of these things for B-Sides just to get us ready so that we— when I got a job, I wouldn't have to think about it. It would already be done, right?
And as a side effect of all that organization, I was— I said, okay, well, I'm already doing a bunch of this stuff. I guess I can be president. Nobody else was stepping up.
Yeah, I'm sure somebody would have if I had refused, but nobody else was eager. So yeah, now I'm president. That's great. And we put on our BSides Denver in 2019 and it went fairly well. I'm very happy that there were no disasters.
I was very nervous. Will there be another one in 2020? Yes, Yes, we're planning for that. It should be in September, mid-September. Specific dates yet or still to be announced?
Oh, you know, I'm so embarrassed. We have a specific date, but I forgot what it is. All right, stay tuned, listeners.
Yeah, and we plan it, we are planning it, and a lot of people will be happy to hear this. It will be bigger than last year. We did make a really small one last year because we didn't want to bit off more than we could chew. I remember tickets went pretty fast, right? Yes.
Yeah. I felt bad about that, but it was just— it was very exclusive. That's how you can frame it. It was exclusive. Very family.
We're all, yeah, very family here. We're all close-knit. So yeah, more people will be able to attend next year. Okay. So you're involved with B-Sides.
You're also teaching a class. I am. I teach a class out at Metropolitan State university. This right now, I'm teaching one in SCADA and ICS, so industrial control systems and security. And that's been interesting because although I've been exposed to a certain amount of that, I have never personally had a job where that was my primary responsibility.
So you're learning? I am, at a very rapid rate, but fascinating. Frankly, this stuff is fascinating to me, so it is no bother to learn it. This is great. I'm so excited, and I'm actually thinking I might maybe try to pursue a career more in SCADA later.
Interesting. Yeah, just because it is so much fun, right? The only exposure I've had was working for an organization that did water treatment, so they had SCADA, and it was serial cables and RJ11 air-gapped network, thankfully. Is that similar to what you're seeing now, or more things going IoT, TCP/IP, over Ethernet? Yeah, here's the deal with that.
A lot of those— a lot of the devices that are being controlled by those networks are large, difficult to install, expensive, difficult to change. So we're seeing a lot of need to convert these old styles of things to new styles, and that's great, and there are ways to do that, but there are areas where people need to be a little more cautious because systems will come with things like Wi-Fi connections that are not immediately obvious. Sometimes they'll actually be little hotspot transmitters and those will be active in a secure area and no one will know, right? Because they didn't really check to see what the specifications were. And it's because, you know, systems on chips come in prefabricated.
They're just, you know, oh, well, we use this chipset. It has all the capabilities we need. But any capabilities that they don't need, they don't necessarily tell the purchaser about. Hey, you need to disable the SSID on this. It's going to broadcast by default, that sort of thing.
That would be it. Okay. Okay. And one thing I also remember is that most of those environments, they don't have a dev and a test, right? There's only production.
So you don't have a test power grid, or you don't have a test water treatment plant. Water pump that you can have as a sandbox, right? There's only the live things that actually ships water to someone's house or that actually opens the valve on the pipeline or something like that. That is getting better, but yes, for the most part, you are still correct, unfortunately. Well, yeah, there have been a few system owners who have figured out that it's not a good idea to do tests in dev and so have invested in things like virtual machines.
I mean, a virtual environment for SCADA is absolutely possible. They make simulated dam controllers and simulated irrigation systems and all of those things are available. It's nice because the manufacturers of the systems themselves have figured out that it's a critical necessary thing and in some cases actually provide these virtual environments on their own. So that's really nice. Okay, and your semester ends in May.
Do you plan to teach past that as well? Um, I don't know that I'll teach during the summer. I had some plans for visiting family over the summer instead, but if they want me to come back, if they've got another class for me to teach, I'm— yeah, this is fun, let's do this some more. Great, great. So in addition to B-Sides and Metro, do you have other employment as well?
Oh well, I have a full-time job, but I'm also— let's see, I'm also on the board of directors for SkyTalk. If you're familiar with them, right? So SkyTalks. And yeah, I work full-time at— I actually work at Denver International Airport. Okay.
Yeah, as a— what am I— senior cybersecurity engineer. Yeah, out at DEN. So do you drive out there every day? I do not. I work primarily from home.
Yeah, stay off Peña Boulevard. Yeah, yeah, yeah. Oh my goodness. That place is kind of a bear to get to. Yeah, it's a big operation out there.
It is. Yeah, doing lots of different things too. So are you involved at all with the ATC systems, or is it mostly backend, you know, standard corporate environment? No, the majority of what I touch is standard backend corporate environment stuff. I have done— I did do, when I first came on board, I got a tour of the train system.
And did a physical security. I worked with the fellow who's in charge of the train system out there, and we did a sort of a superficial— I mean, I wouldn't call it really in-depth, but at least a superficial physical kind of check of the systems to see where are we exposed, are we exposed, what kind of things could happen if someone got into the train system, that kind of thing. So we did do that. Cool. I imagine there are some OT ICS SCADA things involved there.
There are, yes. I've never seen a driver on those trains. That's correct, they are completely and totally 100% automated. That's pretty remarkable. Yeah, really is very cool.
And just, just to reassure everybody, there is a control room where they have this huge bank. It looks like Starship Enterprise There's huge banks of computer monitors and you can see the signal for the train moving along the tracks and you can see the route that it's taking and if they have an emergency stop and there's always people in there. There's like 2 people on staff at all times watching what's happening, watching the cameras, watching the routing, making sure everything is going as programmed and smoothly. To make sure there's not a runaway train. In the tunnels below.
Correct. Yes, exactly. Excuse me, DEN, right? Isn't that what we're supposed to call it now? I don't know.
I keep calling it DEN. I'm as bad as they are.
Okay, cool. What are some other cool projects you have for 2020? Oh gosh, that's, you know, I'm considering having a whack at either like the Certified Ethical Hacking certification or the— what is the other one— the OSCP. I don't do a great deal of actual hands-on manual penetration testing. I'm more— I am definitely a shading towards the blue side purple teamer, and I'd like to develop those skills some more.
I've been watching someone else, another professional that I know go through the process of studying for the OSCP and taking the test, and it looks really hard. I'm feeling a little trepidatious, but I feel like, you know, that looks like a cool challenge too. On the other hand, it also looks like a really cool challenge. Yeah, yeah, a good goal to have. I've heard if you get your feet wet with some capture the flag exercises, that'll get you going towards the OSCP.
Oh goodness, yes. I've heard it is challenging. HackTheBox is a website that's a really great resource for anybody else who's thinking about it who hasn't heard of HackTheBox. I mean, everybody's heard of HackTheBox, right? Yeah, that's the only one I know off the top of my head though.
Okay, so maybe a little more red team in your future, get some exposure there, see if you like it. Yeah. Okay, let's talk about your education. You kind of, you said you went and got your bachelor's degree, right? Did you pursue anything past that?
Not yet. I am definitely considering going for a master's, and then at some point— I know this is so dumb— I want to, I want to be a doctor of cybersecurity. That's a, that's a legitimate thing that they have. There's a program where you can be a doctor. Really?
Who's offering that? Oh, right now I can't remember who it is.
So if you wanted a PhD after your name and you didn't want to study medicine, you can study cybersecurity? Oh well, you can study all kinds of things if you want a PhD after your name and you don't want to be a doctor. There are a ton. But if you're like, hey, I've spent my whole career in cybersecurity, it's time that people call me doctor, you can do that, huh? Yeah.
Okay. Well, and it's might lead into, you know, doing this teaching gig, I think, has opened up the door for me. Maybe after I'm retired, I can continue to teach as a part-time job, but I can only teach undergraduates right now. If you want to teach graduates, then you yourself must be a graduate, which means you have to have, you know, a master's or PhD. Yeah, and I figure if I'm gonna go to the effort, I might as well finish the whole thing.
So I've avoided getting a master's degree because I've heard you have to write so many papers. Oh yes, that sounds right. There's a lot of papers. I require papers of my students, and you should hear it. They— how am I supposed to know if you know it if you don't write me something?
Yeah, so it's more than multiple choice and all that. Oh goodness. Write a 10-page paper on this topic. Well, I haven't given them 10-page topics, but we did do an interesting— we recently, just recently did an interesting project where I had them write up an outline for a training program for an ICS environment and to include, you know, something specific about the ICS environment that requires training on and just a general cybersecurity sort of training and awareness of users mostly, you know, users, this is what you have to look out for. Sure, and who is the target, like the end users was— you weren't targeting information technology, information security professionals with that training?
No, we were mostly looking for— mostly I wanted, you know, this, that the end users are usually your most vulnerable point. So how do you want to educate them? What do you want them to know? And how would you design that so that they would listen to what you said? Any winning strategies that you found that your students had turned in?
You know, I was really interested to note how many of them— we also talked about policies and the fact that you have to have a policy to tell people what's required and what happens if you don't do what's required. I was surprised at how many of them had very sharp policies. If you screw up more than like once or twice, then, you know, you're fired. Wow, okay, I don't know if that's a winning strategy, but it was interesting to note how many of them wanted to be very, very hard, a hard line about that. I thought that was interesting.
Put everybody on thin ice. Whereas me, I am a lot more likely to approach it as, well, we're all here to accomplish the same things. Without security, the company can't necessarily thrive. There are a lot of very bad things that can happen to companies with insufficient cybersecurity. So let's all work as a team together.
Let's be the friendly face. We want Smokey the Bear, not, you know, don't shame people, don't slap their wrist with a ruler. I was very clear about that. A place where people can and will report their errors is only a place where they feel safe doing so. If you make them feel like that's a— yeah, if you make them worry about the punishment, then they will never come and talk to you about the vulnerabilities that they see, or if they really did mess up.
Yeah, there has to be that trust. There does, that's right. Well, I believe that's a really important lesson because you're shaping the next generation of cybersecurity professionals, and it's not just, hey, this is how OT and ICS and SCADA works. It's also how security interacts with the rest of the business, and that's just as important, right? Yeah, how to treat people and how to build bridges.
I would say so. Yeah, it's a unfortunate because we have— cybersecurity has kind of an ugly rep at this point. The vast majority of corporations have cybersecurity departments and they don't get along with the rest of the organization, especially IT, if they're two separate— right, if they're different organizations, right? Then there's a lot of hostility and just general not getting along. And of course, the end users view cybersecurity as the people who say no, who tell them you can't do this or that.
There was a lot of those training policies had a lot of notes about not surfing the web, not going to social media sites, not checking your email, all of those things that really technically are quite necessary that make users unhappy. So trying to find ways to make that message more palatable is important. So do you have any advice? You said cybersecurity might be viewed negatively in a lot of organizations. What can we do about that?
If you've got this mouthpiece, what do you want to tell all the information security professionals? You know, that's a hard one. Some part of it is that cybersecurity for a long time attracted— well, technology in general attracted a certain type of people, and that was who ended up in them. And not— I mean, I myself am sometimes not great at social interaction either, so I get it. But it is— it's about finding— if you do have a department that doesn't have anyone who's naturally good at talking and smiling and making themselves kind of the face of your department, the friendly face, right?
Then you need to hire somebody who can do that. Yeah, just look for those kinds of skills in your next hire. You want that sort of friendly interactivity. You can teach tech skills. Find somebody who has the good soft skills who can make your department be popular in the organization.
Right. Yeah, I think that's good advice. Most security job postings that I've seen say computer science degree or information security degree and 4 years of experience with the SIEM that we're using and all these things, but nobody's looking for a marketing degree or a public relations degree or a sociology degree or something like that. Can they talk to people? Are they comfortable doing that and willing to do that?
Yeah, so there's, I think, some entrenched things that just have to come a little more unstuck. Yeah, and developing those soft skills that don't always show up on a resume. They never show up on a resume, are you kidding? Well, no, I guess they kind of do. I see a lot of people like me who are volunteering for things like SkyTalks and BSides, and there's— there are BSides all over the globe, so it doesn't— it's not just strictly Denver.
Look for people who are trying to participate in those kind of organizations. Those tend to— those folks tend to have a little bit more in the soft skill areas. That might be something to look for. And they're passionate, right, if they're out there volunteering on their own personal time. Oh yeah, there's that too.
That's always a good skill to have. Alright, so let's talk about the industry at large. Cybersecurity is obviously very dynamic, constantly evolving, can be a challenge to keep up. So what do you see as sort of the next big trend in information security or technology? I have no idea.
I really am not good at that kind of thing. Your crystal ball is a little foggy right now? Yeah, no, I— well, you know, I don't think it's going to be a great big change from what we have seen already. I think that we are going to see a continuation of many of the things that we've already seen, which means there are going to be a lot more— the state actors are not going to go away. They're just going to get more organized.
And same with, you know, we have organized crime who is getting very good at doing organized crime online where it I don't see that going away. Basically, if it lets people sort of flex their natural greed, then it will probably continue, which is a shame, but there it is. And also, let's see, we can talk very briefly about a lot of this trend has been— there has been a recent trend, sorry, toward artificial intelligence as a tool for cybersecurity. You see that in a lot of marketing materials right now, you know, we will solve your problems with AI. You sound skeptical.
It's a lie. There's no such thing. There is not currently actually a real legitimate artificial intelligence implementation in any tool that I've seen so far. It's all advanced machine learning, and that's not necessarily a bad thing, but machine learning is a lot like— well, for anybody who is old like me and remembers bubble sort, it's just a matter of prioritizing these things, and it just keeps reprioritizing the list until something bubbles to the top. And as far as it's concerned, that's the right answer.
But it doesn't have any capability of double-checking. It can't look at that and say, is this obviously wrong? Like a human can. So is that the difference between artificial intelligence and machine learning? Is the AI could say, actually, that answer is incorrect?
It can't yet, but I'm hoping that eventually it will be able to. There are a lot of additional checks in an artificial intelligence neural network, especially the complex neural networks. There are— it's multiple sections working toward the same identification. Like if they're trying to identify a picture, you'll have one set of the neural networks doing one small portion, and then when they get to— when their bubble sort has gotten to the top and they've gotten their most likely option, they compare it with other sections to see Does that look the same? Does it look like that to you?
Yeah, so there's some level of consensus where they check in with each other. You know, it's funny, there's this old science fiction, I think it was Robert Heinlein, that wrote about the artificial intelligence ships that had what he called an I tell you 3 times mechanism. So there were actually 3 artificial intelligences working together, and that way if there was one consistent outlier, there was probably something wrong with it. You could tell. So each of them would analyze the problem separately and compare answers, just like our artificial intelligence now.
Right. Yeah. And then if one of them was way off, they would have a little trigger to say, hey, what's going on? Exactly. And would that have prevented the 2001: A Space Odyssey with the HAL that kind of went— have you seen that movie?
Yeah, it's been a while. I don't know, maybe. Um, well, no, yeah, it would have because only— I can't imagine more than one going rogue, right? But didn't he go rogue because there was something actually mechanically wrong? I think so.
Yeah, so I don't know, it would depend on whether they had separate systems. Obviously a good reason to have redundant systems in place. So is no one using artificial intelligence as you define it today in the security space? Is it mainly still in academic research then? Um, I don't really know who's using real artificial intelligence.
Machine learning would be like I'm going to examine the behavior on this laptop and look for, you know, for 6 weeks I'll learn a baseline and then anything outside of that is an anomaly. Is that more— that's definitely machine learning, and it is that— that is the level of the majority of the tools out there, which is the problem because it's not a— there's no way for it to actually know What is a genuine outlier? The— what do they call it— unmonitored machine learning, I think, is what they call it. Basically, the one where nobody is confirming you got this right or you got this wrong. Those are terrible because you can have things already in your environment.
A great many organizations are already breached and don't know it. Or are hosting malware and don't know it. So that can be part of the baseline. The machine learning just learns that, oh, that's normal here. No, it isn't.
Well, I mean, it shouldn't be. It is normal here, but it's wrong. And that's where the humans come in and say— that is where humans should come in. Yeah.
But yeah, this baseline learning and then alerting. I work with Splunk a lot, and I— so I've monitor the patterns of the alerts that we get from the systems, and I can see where something new will get added to the environment. And that happens all the time, like on a daily basis practically. The system is just adding it automatically? Well, no.
So like, say for instance, I issue a new laptop and the person with the laptop is going to Florida, and then the laptop is doing something different. It is— it's new, it's a new laptop, and on top of that, it's from a different region. Now that's guaranteed to make any security pro— you know, any security tool freak out and tell you about it. Sure, sure. And but for our environment, that's normal.
We, we knew that was there. We don't need it to alert and tell us about it. But there's no way to— yeah, there's just no way to fix that.
So that's where the security analyst comes in and says, yes, this is expected. I think we're always going to need people. Yeah, I don't think that that's ever actually gonna go away. Well, that's good. That's good.
I know there's people out there who are worried about loss of jobs due to artificial intelligence, machine learning. The other problem with machine learning and artificial intelligence tools is that corporations don't realize how much work they are to implement or maintain, primarily to implement. And then yeah, there's still maintenance that has to go along. Your environment changes, and every time your environment changes and you— oh, I don't know— transition from one type of database to another, your artificially intelligent system isn't really artificially intelligent. It's only machine learning, and it's not going to understand what just happened.
So yeah, is there a way to prime a machine learning algorithm to say, hey, this person is going to be logging in from Florida this week because they're on vacation or they're a remote employee or something like that? Nobody has a mechanism in place to do that that I'm aware of yet. Because I can call my bank and tell them I'm going to be traveling to Costa Rica, please allow credit card charges while I'm in Costa Rica. And that would be great if we could do that. That if we could, but that would require a couple of other things, not just on the machine side, but the organization would have to be organized enough to be able to notify the security department, hey, you need to tell them, you know, the system that— and honestly, as many people as— the larger the organization, the more difficult that is to scale.
Sure. Right. So if it's like 5 people, that's easy. It's 500 people, a little harder. Yeah, you can't keep track of everyone all the time, their locations, all of that.
Yeah, and even if you had a centralized system, like many companies have a centralized vacation calendar, even if you did have one, that wouldn't really necessarily— that wouldn't consistently help you because people forget. Right. People would forget to put their stuff in, or unexpected things would come up, and it wouldn't be the calendar. And yeah, so just life's messy. Yeah.
And maybe we'll put the same caution that we started the podcast with, right? Buyer beware. If a security product is saying we incorporate machine learning and AI to reduce your overhead, maybe you should understand what that means, right? Yes. Understand that it will still be a lot of work to implement, deploy, and make it effective.
Well, we're coming up on the end of our time. Angela, is there anything you want to be sure to cover before we sign off? Let's see, I had some notes. Oh, I was going to briefly mention, you know, one of your questions was about certifications that I found really valuable, and, you know, as I thought about it, I realized that the one that I really think of as having been the most valuable getting started was actually the CompTIA A+. Okay.
And that's kind of— I think that that might be an unusual thing. I just— it gave me such a really good foundation of learning about how things work in general in computers. I, you know, that was how I learned about clocking and how the timing of RAM works and why it has to be like that. It was just a really good fundamental thing. So anybody who's looking at getting started, if you can squeeze the A+ in there, it's a really good helpful thing.
It'll help you understand the basics of what makes up technology and so why things do the things that they do. Yeah, yeah, I agree. I know there's a segment out there that really just wants to get straight into security, right? But without understanding the computers and the technology underneath it, there's only so much you can do. And certainly wouldn't want anyone to be held up by a lack of understanding in their security career if they didn't have those basics.
Well, and basic things will, will bite you almost, almost consistently. Yeah, if you leave a basic thing open, somebody will find it. Great. Yeah, that's great. Anything else?
Um, no, I don't think so. I think I'm good. Okay, I think we covered everything. I hope you had some interesting— got to hear some interesting things. Absolutely.
Well, thanks so much for your time. Really appreciate it. It was fun. Thanks. Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security.
Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado Equals Security.