Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 160 for the week of April— what is it, April 20th? No, no, man, I don't remember the date.
I think it's the 13th. 13th. The 12th is Easter. Yes, 13th. Yes.
Yeah, Monday the 13th. Obviously not prepared for recording. This is, you know, we're just one big series of days that blend all together right now. I've seen lots of memes on social media about, you know, what day it is and those sorts of things. So, I can't blame you, Robb.
Well, we are flattening the curve. It looks like we're having some positive results. The projections for number of deaths in the US and Colorado has gone down pretty dramatically from what we had even just a couple weeks ago. Yeah, definitely. Things seem to be making a difference.
I think that we're also learning how to get along better with our families and get around to the things that we usually get to put off because we have other things that are better to do. So both good things. Is that the honey-do list that you're getting through right now? Uh, yeah, I mean, some of it is, is honeydew. Some of it is just, you know, things that I've wanted to do anyway or should do anyway.
Yeah, so it's, it's my own-do list. Well, I love it. Making progress. Uh, jumping over to some housekeeping, we have our Slack channel. I think you all know that there's a way you can go connect with about 1,400 of our closest friends in Colorado.
Go out to colorado-security.com to find the button for joining Slack there. You can also check out our mailing list if you scroll to the bottom of that same webpage, colorado-security.com. There's a form there that you can fill out with your email address and you will get the show notes delivered to your email every week. And while you're at it, if you wouldn't mind going out and rating us and subscribing on your favorite podcast listening app, your ratings out there do help us get more new listeners. We'd love it if you'd spend a few minutes doing that and of course And of course, by subscribing, you get the show in your inbox every week.
You could even tell a friend virtually, of course. You know, you could tell them through FaceTime or through a Zoom happy hour, or, you know, maybe just make flyers and post them around your neighborhood as you take your dog for a walk. But, you know, let folks know about Colorado Equal Security and the podcast and all the great things that we're doing. And of course, if you want to help support us financially, we do have a Patreon campaign open. You can go out and help kick in some of the funds for, you know, the hosting hosting for this and the domain that we own at Colorado Dash Security and any of the other kind of random administrative stuff that we pay for as we run this podcast.
You know, of course, the lease payment on your Ferrari also. Yeah, obviously. All right, moving. Let's go ahead and jump over to our news. Starting off, there's a bit of news, a little bit of sad history here in town.
For the first time in its 128 years of existence, the Brown Palace Hotel has closed. Yeah, it is. I mean, I guess it's not surprising, but it is sad. Up until this week, they still had a few guests that were there, but they finally threw in the towel and decided that they were just going to go ahead and close. I think on the positive side, it looks like they're taking this downtime to do some renovations, updating their conference rooms, and then after that, it looks like they're going to do some updates to their guest rooms as well.
Pretty good stuff. When you say they had a few rooms, literally, they only had 5 rooms occupied as of, I think it was Monday of this week. And that was, I guess, enough of a motivation to get them to say, it just doesn't make sense to keep this thing open considering the current state of things. Yeah, I mean, and the Brown Palace is also attached by a skybridge to the Holiday Inn Express, which was closed a couple weeks earlier. So, they were really, really scraping the bottom of the barrel.
So, it doesn't surprise me that they went ahead and closed. Closed. Yeah, so sorry to hear that. Obviously we look forward to them opening up very soon and parading a bull through the lobby at the Brown Palace Hotel. If you don't know what that is, maybe you should Google it.
On more positive news, a new high-speed broadband network has gone online across northwest Colorado, and it's named after a Norse god. Are you talking about Project Thor? I am indeed. Yeah, I don't know anything about it other than it's called Project Thor. And once I heard that, I just, I got so excited.
I couldn't stop reading the story. Yeah, yeah, yeah, we can move on. I don't need to, you know, Project Thor is good enough. Seriously though, this is a fiber network that was put in place partially through some grants. It's a loop that starts in Denver, runs west, and then goes up to places like Meeker and Craig and Steamboat Springs and then back through Grand County.
But this is, it's a, I guess, a little bit of a backup. You know, many of these areas don't have the greatest broadband access. So, this is giving another way for them to get that broadband access. And this was a pretty big priority for Governor Hickenlooper, and it looks like Governor Polis as well, trying to make sure we have good internet access for the rural communities. This is going to really go a long way in that direction.
I think it was, what, 2, was it 250 gig or 450 gig, I can't remember. There was anyway significant speed. There was an old 400 gigs that was going to be provided by this. A lot of capacity there, obviously, and they had the ability also to expand that capacity. So pretty good stuff.
I'm glad to see, you know, they're going right up 400-mile loop or right up I-70. And obviously help out the rural folks, make sure they're connected as well, which is more important now than ever. Yeah. And of course, this is just the backbone part of the network as well. You know, local providers or other folks that are there will be able to connect to it and, you know, use it as backhaul.
So that'll be good. But it's not a, you know, fiber to the home kind of project. Yeah. So, you know, as a, as a general trend, we try to mostly have good news on this show. There's a lot of bad news out there.
It's not so easy to find all good news stories during the coronavirus outbreak. But we do have yet another bit of good news here. In the last few weeks, Colorado has seen a significant decline in air pollution. Due to the changes in the economy. Yeah, and while we only care about Colorado, this actually has been happening all over the US and all over the world as well.
As people are not driving as much, as industry has been shutting down, there's been a large drop in the air pollution that we're seeing, you know, things like carbon monoxide, silicon dioxide, some of the other pollutants that can irritate your lungs as well as cause smog. So really interesting. You know, for other parts of the world, we had heard from like satellite photos that it looked like China was less polluted and other places as well as they went through this. Here, it's not looking at satellite photos, it's actually getting samplings of the air. And we see an almost 50% decrease in fine particulates and a little bit less, about 40% decrease in large particulates.
These are the kind of things I think, you know, I'm not an expert, but I think these are really related to manufacturing and the factories that we have, those big smokestacks that are pumping out these things. As we see those things being less busy, we see significantly less pollution. That's just good news, right? Yeah. I mean, I think this is strangely a benefit of the fact that Colorado has pretty poor air quality in general.
And because of that, we've been on the EPA's hit list for a while, and they've had these sensors that are around the Front Range. So since those sensors are there, we can see what they're measuring and how much the drop has been, which is pretty cool. And another thing I saw from this article was kind of interesting idea that, that this, this kind of snapshot of what it might look like to, to decrease air pollution, excuse me, that we're getting during the coronavirus actually might teach us how we can go ahead and get better in the future. There's kind of a nice just one variable that's changed, that we can start to figure out what does the path forward look like to really clean up the air long-term. Exactly.
Next, we've got a little bit of a soap opera story here in the business world. Maxar Technologies raised $729 million in the sale of their Canadian business unit. I say this is a soap opera because the way that Maxar was put together was the Canadian unit actually bought DigitalGlobe in the US so that they could get into the US market and do defense contracting. Now, they've turned around and sold that Canadian unit once they've become Maxar to try and reduce some of their debt. I remember when the story happened that they bought DigitalGlobe, what was that, 2 years ago, whenever it was, we were a little bit nervous that jobs might move to Canada, we might lose this this big staple of the Colorado economy.
And it actually obviously went the exact opposite way. It feels a little bit like, Alex, you know, if I went and bought a house, and then that house sold me, is that basically what happened here? You know, somewhat like that. I've heard of that happening a lot, houses selling people. So, you know, that's a pretty normal thing.
More like a smart house, like AI, AI house. Yeah. So I think one of the reasons that this happened is there's been a dip in some of the markets that Maxar has traditionally played in. And so I assume that they had some projections that said that they were going to do certain things. Those, I don't think quite came to pass.
And so in order to reduce some of that debt, they needed to sell off some of the business units. I would imagine that this was not the original plan. I would assume that they wanted to keep everything together, but just didn't work out that way. So obviously good news for the folks in the Colorado area, which are still going to be obviously going to be the headquarters going forward and kind of the center of that solar system. Looking forward to seeing what's coming next for Maxar.
Moving over to our next story, you know, I'm sure you've heard of this by now, Alex. Some companies have started making their employees work from home. Due to the stay-at-home order. There's an interesting article here in the Denver Business Journal this week where they highlighted 5 different tech companies and how they're handling having this rapid work-from-home situation. Yeah, it was actually an interesting read.
I was surprised that some of the companies on here didn't have more of a work-from-home program in place already. You think technology company, that must mean that people work from wherever they are. But in fact, based on what some of these stories are saying, it wasn't the case. Yes. So Strive Healthcare, which is the only one on the list I think I didn't know previously, excuse me, Strive Health, and they're a kidney care startup.
This was really a new thing for them, but they've embraced it kind of full steam ahead. They're doing every day, they have a, what do they call it, the Strive cafeteria where you can opt into choosing to just basically eat on Zoom with your coworkers and have a little bit of a social element to your lunch. And they have these, these kind of rotation of different social events going on as well. So they're trying to make sure that there's at least a feel of camaraderie, even though everyone's working from their own homes. The next one was Twilio SendGrid.
And this one I thought was really interesting because, you know, my assumption would have been that, you know, they're a— well, at least half of them is a, you know, Bay Area technology company and the other obviously a Colorado technology company that came together, I would have thought that they would have been, you know, really embracing this. And it sounded like, you know, while some people did work from home, it was, you know, a little more scattershot, a little, you know, not as formalized. But, you know, again, they are— they're all in. Same kind of thing, making sure everyone can connect on Zoom or other things like that to make sure that there is some socialization going on still. Conga was the next company on the list.
Conga is a tech company headquartered up in Boulder, I think it is. They have about 500 folks now working remotely. Interestingly enough, for Conga, one of the things they make is remote productivity tools, specifically for doing e-signing and some automated business flows that work better remote. They've experienced some challenges going remote, and I think it's probably more from a cultural perspective. Where I think it's standard.
And I'd say at Ping as well, where I work, people like being in the office, like being physically around each other. And the move isn't so difficult from a technology perspective, but more of a cultural, like, how does your— how do you see your workday going when you're not there in person? And it sounds like that's the stuff that they're challenged more with than the technology part of it. Yeah. Next on the list was Guild Education.
Their story was kind of interesting because they just moved offices. And as part of that move, they told everybody to work from home for a few days while that move happened. So, this was just before everyone started to do the working from home and social distancing. So, they kind of got a preview of this and got to work out some of the kinks in their work-from-home process before they actually had to do it. So, that was pretty cool.
That's awesome. Last company on the list, I think it's a little bit cheating to put them on a Colorado tech company list, it's Slack, and we have about 140 Slack employees in Denver, you know, out of their thousands that are, you know, worldwide. But they, you know, Slack is— they're one of the technologies that most other companies are using to help adapt to working from home, so they're probably better situated for this than just about anybody else. It sounds like they're doing a pretty good job with the, the adaption. Yeah, for sure.
Okay, next, there was a blog post this week by Webroot talking about the 2020's most and least cybersecure states. So they do some, uh, a study every year to try and figure out, um, peop— how the people in each state are doing in terms of cyber hygiene. And, uh, and they've got some results here. So I know I remember us talking about it last year. We probably talked about it 2 years ago as well, but I don't remember the results from last year.
So this is, this is all new to me. Um, when I look at the, the details here, for the most part, it kind of looked like the, the worst hygiene was correlated with the most online tech-savvy states. And when you looked at those, those states that got the worst rating were the most online, like California was top of the list, Texas was near the top, Colorado, we were 10th. And then you go to the other extreme. And it looked like it was really the less populated states, the states you'd expect to have, you know, a smaller population or percentage of their population online as well, that actually had the better hygiene.
So it's a little counterintuitive to me. Yeah, I think some of it may be, you know, overconfidence or, you know, something like that, you know, people thinking that they are tech savvy when maybe they're not really as savvy as they think that they are. And then you add that together with the, you know, the amount of people that they have that are online, and you get more that way. But yeah, I agree, it was, it was not the outcome that I was expecting. So riskiest 5, number 1 is New York, number 2, California, Texas is 3, Alabama and Arkansas at 4 and 5.
And then on the least riskiest states, you had Nebraska at 50, New Hampshire, live free or die, at 49, 48 Wyoming, 47 was Oregon. That was actually the one that kind of surprised me the most because I think of them as being a fairly connected state. Honestly, I think of them as being very similar to Colorado in a lot of ways. And 46 was New Jersey. It's interesting that New York is number 1 and New Jersey is number 46.
You know, sharing a border. Yeah, I don't know. It was also interesting that there was only a spread of 15 points that, that separated the riskiest from the least risky. So we're not talking about a great difference from best to worst either. So there might be some noise inside this, uh, report, huh?
Yeah, it could be. All right, moving along. We have a press release from Layers. It seems like Layers has been, uh, kind of kicking out the news lately. Uh, this is the, the release of their 2019 Um, pen test findings report.
I think we talked about this a week or two ago, but they actually have kind of come out, you know, as a news to say this is out here now, use this as a resource to help you, you know, plan your own defenses. Yeah, there's a link to the full report that you can get, uh, through this article. Um, I actually requested the report and I'm still waiting on it, so I can't give you what the top 10 are. But you didn't, you didn't like text Nickerson to be like, what the hell? I, I could have, but it was, you know, not at the top of my list.
Maybe I'll get to it. Um, but I'm sure it is wonderful, and the, you know, all 10 of them are super important, so everyone should go and maybe we'll talk about this next week and see what those are. Uh, next, some news from LogRhythm. Um, it seems like we've been talking about LogRhythm and their executive team a lot lately, and, um, they have appointed another new executive a new chief revenue officer. Mitchell Rowe is the new CRO, and he joins the company from Ivanti.
So he was the CRO for 3 years. So chief revenue officer, you know, call that the C-level position for the head of sales. Some companies will have a chief revenue officer who's over both sales and marketing. Sometimes marketing goes to a different area. But this is obviously a big position in tech companies, especially before he worked for Ivanti.
He worked at Landesk. He also worked for Pitney Bowes. He was at EAM business unit, at the EAM business unit over at InfoGlobal Solutions. And he was also at Applied Materials. So he's had a number of stops at some companies I've heard of very well and some that this is the first time I've ever heard of.
In the press release, they were quick to note that Landesk is a Thoma Bravo company, obviously LogRhythm also owned by Thoma Bravo. So Seeing a little, little connection there, maybe how they pulled Mitchell into getting this job. Yeah, makes sense. So next we have a blog post from SecureSet. This is their how to hack, how to break into computers.
And basically what they're going through in this blog post is an introduction to if you want to learn how to hack, here's how you, how you get yourself started. They talk about how to get a hypervisor installed, how, what kind of hardware you need, how do you start doing this kind of hands-on hacking in a safe way that's not gonna, you know, screw up your— the machine you use every day. Yeah, the blog post is a little bit cheesy, but it does give some good info about how to get started, how to get a hypervisor set up, how to sort of, you know, build your own lab to start testing things. So, you know, if you know someone that wants to get into computer security, this might be a good thing to forward to them. So are you telling me the reference to a Preparation H commercial was a little bit cheesy?
There's also a picture from Zoolander, so— and he does, after making the Preparation 8 reference, they do say something about soothing. So it's obviously, you know, a little bit tongue-in-cheek throughout the article. Yeah, and moving on to our final news story of the week, we have another blog post from Optiv this week talking about container compromise to infrastructure as a service recon. So this is building on the blog post we talked about last week, but this is another series that they're starting. So previously, they were, you know, they were looking at how to compromise a container and could you detect that.
Now this is taking it one step further. Once you've gotten into that container, can you break out of the container and then, you know, use Kubernetes to, you know, figure out what other hosts are running and get more information that way. So pretty good detailed technical article here. Yeah, this is to me not only interesting that they're getting more into technical stuff, which I love, it's also really relevant technology for a lot of companies right now as we're moving to containerization. If you haven't got to Kubernetes yet, you're probably going to get there.
I would share this not only with your security operations team, but, you know, those sysadmins who are running your container infrastructure or who will be running it to start to understand, you know, what are the risks? What are the ways someone could try and abuse this? Once again, good job to Optiv to getting some high-quality content here. Definitely. So that is it for the news.
Let's move over to the Slack Message of the Week. Thanks again to Andre Gaeta for sponsoring the Slack Message of the Week. We give a prize every week to someone who says something that we like on Slack, and the winner gets a $25 credit to the Colorado Equal Security store. Courtesy of Andre. So Robb, who is our winner for this week?
This week we get to recognize Colin Grady. Colin has done a lot of good sharing lately. I want to call him out specifically for sharing a really funny, and as a parent whose kids were reading Dr. Seuss not that long ago, really relevant video he had. I don't know who the guy was, but some guy is, is performing Dr. Seuss's Fox in Socks to some Dr. Dre beats. And my goodness, it's high-quality stuff.
Alex, if you haven't heard it yet, you need to to take a few minutes to listen to that after the podcast here. I'm gonna have to go check it out. There was lots of talk this week in various channels about '90s hip-hop music. So this is another one of those conversations. So congratulations to Colin, you will get one item from the Colorado Equal Secure— Equal Security store with our new logo.
So we're happy to have you get those. And of course, we look forward to seeing you around town in that sometime after we're back out of our houses. Um, so Robb, I think we actually have a couple events this week that we can talk about. Yeah, 3. It looks like 3 virtual events that we can go through.
So now, of course, we will remind you we do have an event calendar on the website. I'd be really careful using it right now because most of these events have probably been canceled. Um, you know, maybe not officially canceled yet, but they're definitely not going to be happening. And some are moving to virtual. We're trying to capture those that are moving to virtual and include those in the show notes and talk about them here each week on the show.
First event, OWASP is moving their chapter meeting to a virtual meeting, and that is on Wednesday the 15th. On the 16th, ISACA Denver is moving their meeting to a virtual meeting. And on the 20th, the Software Freedom School is doing their Security+ peer study group, and it starts on the 20th and then it goes for several weeks after that. All right, swing over to jobs. There are— we do have some jobs available.
There's a couple jobs at Ping I'll highlight. Number one, in the security area, I'm looking We are looking to hire a GRC analyst focused on business continuity and incident response. And in our operations area, we are looking for a manager of our SRE area. So this is the folks who keep our website— not our website, our SaaS products running, make sure we have all of our DevOps-y, containerized, cool microservices running in production. So we need a manager for that team here in Denver.
So reach out to me if you're interested, and I'll get you hooked up. Janice Henderson is looking for an IT operations risk and business continuity manager. Maxar— and once again we get to talk about those guys— they are hiring a cybersecurity architect. You know, the drawback to that job though is you'll probably have less opportunity to go to Canada. Oh, uh, Pulte Mortgage is looking for an information security compliance analyst.
Ahead is hiring a cloud security architect. Department of the Interior is looking for an IT cybersecurity specialist. PwC is hiring a cybersecurity and privacy associate. Coalfire is looking for a senior paralegal and contracts manager. And finally, LogRhythm is hiring a professional services engineer.
Well, Robb, uh, once again we have done it. We've made it through the newscast. That's pretty good stuff. We do have a feature interview yet again this week. Big thanks to, um, to Jason Jaques, who's been our interviewer doing this for us.
The, the Featured guest this week is Aaron Cure. Aaron is a well-known, super smart researcher here in the area. Looking forward to hearing this interview. Yeah, Aaron's an interesting guy. I'm sure it's a good interview.
All right. Well, that is it for us this week. We'll look forward to talking to you guys again next week. Stay safe, stay at home, and of course, reach out if you need anything from us. Definitely.
Thanks, Robb. This is Tim Coogan, Chief Information Security Officer of Denver International Airport. Welcome to Colorado Equals Security, for Colorado security professionals by Colorado security professionals. Colorado Equals Security. This is Jason Jaques, host of Emerging Tech Fan.
I recently attended the SnowFROC conference put on by OWASP Denver. While I was there, I conducted several interviews. This first interview is with Aaron Kuerer, a principal security consultant at Cypress Data Defense. Here's the interview. Enjoy.
Aaron, thanks for being here. You bet. Glad I could make it. We are at a conference called SnowFrock, and, uh, you are one of my interviews out here today. This is, uh, this is interesting.
I've never been to this conference before. Yeah, it's a great conference. Um, been going on for, I don't know, probably close to 20 years now, and it's the OWASP conference for the OWASP Denver chapter. Yeah, it's called SnowFrock. It's the Front Range OWASP conference and snow, obviously, because half the time we're here it does snow.
In fact, last year we had that cyclone bomb roll in and about half of our speakers couldn't show up. And so we were scrambling trying to get people in front of podiums and microphones and all that kind of fun stuff. And it was, uh, it was challenging. Troy Hunt came in from Australia last year. Okay.
And he was supposed to be our keynote, which he was at 6 PM. He got stuck in LA for 24 hours and then 36 hours and then came back and Finally made it into town. He's like, all right, I'm at the airport. I just have to find an Uber. Okay, I'm in an Uber.
And so we were supposed to end at 5 and it became 5:30 and then it became 6 and he finally showed up and he jumped on the stage and he just knocked it out of the park. You know, he's Troy Hunt. Come on. So he, he showed up in time then? Oh yeah.
Yeah. We held the conference. We rented a few extra hours here at the Cable Center and had room for him to show up. And everybody was— it was a fantastic presentation. He's such a great guy.
So we had a whole lot of fun. Hey, so let's take a step back. What is OWASP? Educate me. Sure.
So OWASP is the Open Web Application Security Project, and it's just a nonprofit organization that's whole mission is to help developers write better code, to help testers test that code, and to actually help us be more secure as an organization, as a development group, as a community, right? So the better security we have, the less chance that we're all going to end up on the front page of the news. Yeah, that's, that's definitely a noble goal right there. Yeah. So they have a lot of free resources on the website, things like that to look at and just kind of educate yourself as well as their chapters in lots of cities.
Denver, I think, is the 3rd largest in the nation. So we put on a good group and we meet here every other month at least. We're pushing for every month this year to actually just get together. And it's a great way to meet the security community, to get introduced to the security community, to pick up some new skills and things like that. Okay, so it's a national organization then?
It's a national organization with city chapters that are organized by local people who just kind of care about what the mission of the chapters are and what the mission of the organization is and to help people get together better. Okay, awesome. So last year there was a snow bomb. Yeah. This year there's a different kind of a bomb, a coronavirus bomb.
Yeah, we've had a couple of speakers that had to cancel because their companies have said, hey, we're sorry, no corporate travel. Yeah. Okay. So we've had to scramble with a couple that had to cancel and put them in, put people in their places and stuff. Has it affected attendance at all?
A little bit. We've had a few people that have emailed and said, hey, we just can't make it. We're not allowed to travel. We're not allowed to attend conferences, things like that. But overall, I think we still have about 250, 300 people here today.
So it's not a bad turnout for a local chapter conference. Right, right. What were you expecting? We were expecting about 325. So we're down about 50.
Okay. So that's not much really. No. Okay. Yeah, it's, it's exciting out there.
I was walking around and meeting some of the people involved in the conference. You guys put on a good show. It's a lot of fun and we have a great caterer. So if you only come for the food, it's totally worth coming. That's all I came for.
Amen. Wait till the lunch. You thought the breakfast burritos were good? Yeah. Yeah, that's funny.
So are you from Colorado? I actually was born here, born in eastern Colorado, just inside the Kansas line. You could probably call it Kansas more than you could Colorado, but it was technically Colorado, so I'm a native Coloradan. So, you know, whatever rights and privileges I get for claiming that. Then when I was 15, we moved to Arizona.
I joined the military from there and kind of lived all over the world. And then when I got out, we lived in Arizona for a couple years and then moved back here to Colorado to attend a school for my daughters called Alpine Valley School. Okay. And so that's— they both graduated from there, and now we just kind of like living here. Let's talk about your military travels.
Sure. Where did you live? Rattle off the places. Lots of places with sand. Okay.
You know, like Monterey, California. Hmm. What, no sympathy? Come on, that's the worst duty station ever. Yeah, I'm sure.
Yeah, so I went to language school there to spend a year learning Russian, which I then never used in the military, but they still paid me to learn it. Okay. And then I went to Germany for 3 years. That was fun. I was in Frankfurt and Darmstadt.
So, you know, again, really terrible places. Hey, we know you're only 19, but you'd like to come drink beer for a living? Well, yes. Yes, I would. Right.
So, right. So Germany was a lot of fun and had a great time traveling all over. And then when my enlistment came up, they're like, well, so what do you want to do? And I'm like, well, I want to go to another long school because I had such a fun time in Monterey. Yeah.
They're like, well, how would you like to be a satellite repair tech? What is that? I'm imagining, you know, you get on the shuttle, you shoot on up, you pull things into the cargo bay. I mean, that sounds like a lot of fun. Yeah, yeah, that was not it.
No, no. So I actually went to Georgia.
Which Georgia? Yeah, that Georgia. Well, you mentioned like Russian or whatever. Yeah, so I actually went to Augusta, Georgia. Oh, okay.
And our Georgia. Yes, that Georgia, not, not the other Georgia. We don't, we don't play nice with them. Yeah, so at least at that time. So no, I went to Fort Gordon, Georgia.
And, you know, Augusta, where the Masters is. Yeah. Yeah. That's the one part of Augusta that's real nice. Yeah, sure.
Yeah. And then there's the rest of the parts. I've never been there, actually. It's not too bad, but it's the worst summer I have ever spent in my life. And I grew up in Phoenix and I'm used to 123-degree temperatures.
That's fine. Georgia is a whole different thing because, you know, it's 98 degrees with 98% humidity. And growing up in Phoenix, I thought that 98% humidity meant it was raining. I was completely wrong. 98% humidity is where you just make your own rain.
I know, you walk out, it just pools on you, and then you run out of sweat. You're just like, ah, and you're just nasty as soon as you walk out. Not a fan. Yeah, no, neither am I. Uh, so what languages do you speak?
So I speak Russian, I speak a little bit of French, some German. Spanish. Yeah, let's put a bit of English. Let's put you to the test. How many languages can you say Colorado equals security?
Oh, maybe one. Okay, let's, let's try it. I'm fair in English, so Colorado equals security. Other than that, you nailed it. Yes.
No, but you can't, you can't give us a Russian version of that. Probably not. We didn't learn words like security. We learned words like, hey, your tank is coming towards me. Remember, the Army's the one that put me through this training, so Okay.
Can you say, hey, your tank is coming towards Colorado?
Not much. It's really bad because my next-door neighbor is a native Russian. Yeah. And so he will always come over and he'll throw something at me in Russian, and I have to think about what he's saying and then think about how to respond to it. And yeah, it just doesn't work well.
So that's funny. Yeah. So what do you do for hobbies? I do all kinds of stuff. I Like to play ice hockey.
I picked that up in Phoenix because, as you might imagine, at 120 degrees outside, yeah, it still has to be sub-40 inside the ice rink. Yeah. So that was a pretty good way to get rid of the heat any time. So I started playing with my brother about 20 years ago. Did you play in school at all?
No, not at all. We didn't start until when I was traveling all the time. I used to spend about 50 weeks a year on the road. And so these games would be on the weekends, and he called me up one day and he said, hey, we're gonna go and join this roller hockey team. You should come play.
And I said, um, well, I'll come check it out. And I walked in, and it was an old furniture warehouse, and they didn't have a good ventilation system, and the locker rooms were just kind of these boxes built out of plywood. And I walked in And the smell, the overwhelming B.O. of men exercising just hit me in the face so hard. I said, that was fun.
I'm out. When you decide to play ice hockey, that'll keep the stink down. Let me know. And like a month later, they're like, hey, we're going to go play ice hockey. All right, sign me up.
So I went out and got some gear. We'd been maybe ice skating 3 times in our lives. Okay. We grew up in Phoenix. There's not a lot of ice there.
It's not like you can run out to the pond behind you. So we started skating and put on some pads and went out and started playing and been playing ever since. It's a blast. Okay. So do you still play?
I haven't played this year. My daughter, my oldest daughter, decided that she wanted to start playing 4 or 5 years ago. So she just jumped out and took some lessons and has been playing with me. And we're kind of looking for a team right now, but will hopefully play this fall. So I hear there's a team called the Avalanche.
And, you know, it's funny because my wife used to work for Frontier Airlines and they had an after-work party and we were just sitting around, you know, at the bar, just kind of talking to everybody. And this— I was talking to some woman and she said, oh, so you play hockey? And I'm like, oh yeah. She said, oh, so do you play for the Avs? So of course I laid in typical security fashion.
Yeah, actually, that's why we moved up here. So yeah, I was playing for the Coyotes down there and then they brought me up and they said, hey, you know, you want to play in Denver? And I'm like, hey, it's closer to home. Yeah. So yeah, apparently I speak a little Canadian too.
There you go. So yeah, you must have stayed up there in your military travels. I never stayed there, but I visited a few times. Okay. Yeah, I kind of wish I had taken up ice hockey.
It looks a lot of fun. You know, it's never too late to start. There are so many beer leagues out there that if you know you can't skate, at least you can drink. So, yeah. So tell me about this laser systems consulting that you do.
So a few years ago, I bought some software locks that you use a hardware dongle, you plug it in, and then you program the software to not start or to constantly check that key and make sure that it's still entered as a way to kind of keep your software license together. And so I ordered a set of the keys from the manufacturer to kind of test them out for my own stuff and see if they're any good. And then out of the blue, I'm driving home from a vacation and I get this phone call from a guy in Phoenix who says, hey, I need to use this software. And I was talking to the manufacturer and they said that you're the guy to do it. Okay.
Um, so it ended up being a 20-year friendship that we built all kinds of crazy systems. That he was a custom laser systems integrator and needed software written to drive the lasers, user interfaces, read files. And he was a really good salesman and would just sell anything. And then he'd call me up. So, hey, do you think we could do this?
Yeah, yeah, probably, probably. Good, because I sold it and they gave me a deposit, so we need to deliver it in 3 weeks. There you go. Okay, send me the hardware. I'll figure out how to put it together and make it work.
And so we'd spend all kinds of different time writing different things. And, you know, we did bottling plant lines where they had a knife that would cut the labels on 2-liter bottles. Okay. So as the labels and the bottles are coming down the line, they would spray glue on the label and then spin the bottle around to put the label on it. Well, then they would cut it with a knife.
And the glue on the label would get on the knife. And about every 30 minutes, they had to stop the bottling line and change all the knives. And so he said, well, why don't we just replace that with a laser? And they're like, that's a great idea. And so we replaced the knife with a little CO2 laser.
It just cuts that bottling line, and they haven't shut it down since. Oh, wow. And a lot of things like that. We did a custom metal engraving system for a weapons manufacturer. And so they would engrave custom designs onto the barrels and the can grips and all that kind of stuff.
And so just create the software to do that and move it around underneath and find things with a camera. We did a project for a chip manufacturer for the government projects. We'll just say, okay, things that fly in the air and blow up. And we would engrave serial numbers and chip things on top of things that are smaller than your fingernail, and there would be 150 of them on a sheet. And we had to find and locate, move each one underneath the laser, and then inscribe on each one.
And oh, they may not be laying perfectly. So figure out what rotation they're at and then rotate the image so that they line up perfectly. You know, typical things like that. Oh, absolutely. Everybody does this stuff.
Exactly. And the best part was the whole reason I got into computers in the first place was because I'm terrible at math. I mean, the worst. Okay. And so I figured out that I could program a computer to do all the math and it got it right.
Yeah. So then I started doing things like this and they're like, all right, well, you just have to figure out what it is and then figure the rotation angle. Oh, and yeah, figure out the offsets. And, you know, I took geometry in high school. I took AP geometry.
I passed it, but I didn't know anything. I had no idea. And then to come in and actually apply, oh, that's what a tangent is. Yeah, cool. That makes a lot of sense.
So I learned a whole lot of math on that job just because I needed to use it. So you're still doing a lot of laser work? I haven't done it in a while. I kind of backed off, and, and he sold the business a year or so ago. And so I still have one in my basement.
I've got a 60-watt laser that you can cut steel with. So, okay, I have some fun playing around with that. Did you ever mount a laser on top of a shark? You know, I thought about it, right? Because we need some freaking sharks with some freaking lasers.
Yeah, exactly. You know, the problem is they're so high voltage that when you get them in the water— so then trying to teach sharks to walk on land, and then of course they're knocking on the door, land shark. Yeah, so you know, it's a thing. Yeah, so nobody's really thought that through. They really haven't.
We just need a better application. I don't think, you know, maybe lasers aren't the way to go. Maybe plasma cutters. You know, I have a plasma cutter too, and it's a lot more fun to cut steel with. And yeah, but still, again, high power.
I don't know, I don't think we've cracked that nut yet. Okay, well, keep working on it. Yeah, sounds good. Like the rest of us, you're probably super plugged in to the digital world every day. A little bit.
What are some of your analog hobbies? I don't consider lasers an analog hobby. I feel like that's kind of a digital hobby too. It is a digital hobby. Most everything I do with it is programming.
We have stepper motors and that kind of stuff. And so, yeah, it's kind of analog in the fact that I'm moving things around underneath the laser and I'm targeting things with a camera. But again, it's still a super digital thing. Yeah. So what are your analog hobbies?
Analog hobbies? I like to— other than ice skating? Other than ice skating, I like to collect antique tractors. I shouldn't say ice skating, I meant ice hockey. Whoops.
Okay, so sorry. Well, you know, the only difference between figure skating and ice hockey is a toe pick. So yeah, toe pick, slip of the tongue. Yeah. Anyway, so yeah, no, let's go back to the tractors.
Sure. Yeah, so I, I like old stuff. My dad was a farmer. And so he always had a few that he grew up with, and he started collecting them probably 20 years ago. And as we started going to tractor shows and things, it's like, oh, that's kind of fun.
And so I bought my first one, and I was kind of hooked. You know, when I bought it, the engine was stuck. Yeah, but, uh, one thing that you'll find pretty often is it was running when I parked it. Okay, okay. That is the equivalent of you're screwed and the engine's stuck.
So, you know, it's a thing. So you gotta pull the head off, you gotta free the pistons, you gotta hone the cylinders because, you know, the pistons were literally rusted shut. And but they're old equipment. You don't have to have a computer to hook up to them and get them to work. You can actually work on them.
You can replace parts, you can find parts for it. And so we've got things from as early as 1939 all the way up to '59. Wow. And we've got things as small as like 13 horsepower all the way up to 60-horse kind of beasts that weigh 8,000 pounds. So they're just kind of fun to put together and get them going.
And, you know, we'll do parades and stuff. We usually do the stock show parade every year. Okay. And then about 3 years ago, I bought a 1930 1-ton Dodge pickup. And surprise, surprise, it had engine problems.
But, you know, it was running when they parked it, right? So it's got no compression in 2 of the cylinders, but it's got the old flathead 6-cylinder Dodge Brothers engine. It's actually a 1930 Dodge Brothers pickup. It was before they dropped the brothers and sold it. And so it's a really interesting truck.
It's kind of got that old truck feel. And it's a, you know, it's a stick and it's a lot of fun. So that's my current project. I'm working on it. So how many of these have you I guess brought back to life over the years?
Probably 20 or 25 that we've done over the years. I think we still have 10 or 12 left that we keep going on a regular basis. And some of them are on protein— protein— some of them are on propane, some of them are on gas. We have one that starts on gas, and then you flip a lever and it changes the compression in the engine and goes from using the carburetor to using injectors and runs on diesel. But all in the same cylinders in the same engine.
Oh, interesting. It's crazy. So it was in the days before glow plugs. They did some really, really interesting things. Yeah.
Yeah. I've never heard of that before. Didn't know that that was a thing. It's pretty crazy. And then I raise goats.
So, okay. Meat goats because milk goats suck because, you know, you have to milk them. So I'm out. That's a, that's a too much work kind of thing. How many goats do you have right now?
We have 7. In about another month, we should have probably 15 or 16. So between 1 and 3 apiece. So it's a lot of goats. I don't even know where to go with that story.
I'm just your typical security guy, you know. I got goats, rabbits, and chickens. Yeah. So in fact, we just got baby rabbits about 3 days ago. So got 8 little bitty black fuzzy rabbits that every time you put your hand near them, they think it's mama and they just start If you've ever heard baby birds chirp, that's what baby rabbits sound like when they think mama's there.
It is so weird. But so yeah, do they just nibble on your fingers then? They just kind of start looking up for it, and luckily their mouths aren't big enough to get around your finger yet. So yeah, they won't take too long, about another week and they'll be big enough that you can barely hold them in your hand. And 3 weeks and they'll be making real new, new rabbits.
Yeah, yeah, actually 6 weeks. Oh, is that what it is? Yeah. So then you got to be real careful about getting them separated real quick. Yeah.
So let's talk about how you got into the industry. Sure. What, um, what kind of led you to, uh, I guess tech in general, but cybersecurity specifically? Well, when I got out of the military, I was looking for a job, and having done satellite communications, I was pretty technical, and I started doing some programming at the end of my Army career just because I'm lazy. And so that's kind of our company motto is hire lazy because we're looking for people that are inventive.
Yeah. People that aren't just going to follow the process because it's the process. Hey, wouldn't it be easier if we did this? That's absolutely what I want to see. Work smarter.
Right. So I started programming when I was in Kuwait and we had 2 systems, one that was actually on the satellite system and one that was in a tent. The one in a tent was connected to a network that we had to put all of our report into and then send it. And the other one we had to get all the settings off of. And I did that about twice and I'm like, there's got to be a better way.
So I wrote an application that would run when you stick the disk in. And this is back in the days of floppy disks. You'd stick the disk in, it would copy all the settings onto the local disk, and then you took it over and you put it in the other computer and it would pull all those settings and stuff them into a Word document and send the report. So I got a little success there and I said, you know, this is fantastic. I'm totally gonna do this.
And so I got out and got a job at Motorola working on the Iridium system. And as we all know, that was a huge success. I don't know anything about that. Really? That's weird.
You know, such a giant thing like that, you would think everybody knows about it. Oh yeah. No, sarcastic. Yeah, it's huge. They had this great idea that we're gonna, we're gonna put birds up in the air.
We're gonna make telephone calls through them, and you'll be able to call from anywhere on the planet. It was a great idea, just the technology wasn't quite there. So it was analog instead of digital. Okay. It was very big and heavy, and they produced a lot of heat.
So there was a commercial at the time about a guy walking across Antarctica, and his phone rings, and he pulls off like 40 layers of clothes and pulls out his phone and answers the call, which was a really great commercial. Because the phones were so hot at that time. It was actually probably keeping him really warm, and so he didn't need to worry about anything else. If it— nothing else, it was a great heater. So I worked as a database administrator and did some customization of software and that kind of stuff there, and kind of grew into, I really like this IT thing and I'm gonna do it more.
So when that project tanked, we moved out and I got a job as a consultant doing call centers of all things. And so I'd fly all over the nation and help integrate things. Like we wrote the first web services before web services were cool and we were writing both sides of these endpoints. So it was a cellular company that would sell prepaid minutes on whatever carrier was close to you. And so at that time there weren't any real supranational carriers.
So if you bought something in Georgia, you would get an AT&T BellSouth cell phone. And so we would reach out to them, create a number if there wasn't already one, and then charge it up with a number of minutes that they would keep track of and things like that. So it was this whole gigantic operation to create a prepaid phone system, and they were kind of the first ones. And this was back in the days of the you know, the whole dot-com boom. Yeah, so this is late '90s.
Yep. Okay. And this was South Beach, Florida. You know, there are worse places in the world to spend 6 months. Sure.
So, you know, we were a block off of South Beach, and there were 6 or 8 of us usually there every week. So you'd fly in, you'd go, and, you know, they, they tend to have a lot of convertible cars at the rental car companies in South Florida, so You'd come in and they're like, hey, you guys want a convertible this week? Oh no, twist my arm. And then we'd drive out past Star Island and get out to South Beach and stay there. And then there's about a billion places to eat there that are just fantastic and a few places to drink on the beach, you know, if you're into that.
I don't drink anymore, but I don't drink any less. I just don't drink anymore. Okay, there you go. You know, it's a good way to— but it was kind of fun. I'm gonna steal that.
There you go. I stole it. We might as well share it. So you can watch the cruise ships leave out of the harbor there. And so you just sit out, sit on the beach with a drink in your hand, watching cruise ships sail off into the ocean.
It, you know, there are worse gigs in the world. You know, I've had a few of them. I think— you ever been to Kuwait? Uh, no. Yeah.
So yeah, let's— moving on. Let's not— so yeah, unless you want to talk about Kuwait. Well, I spent about 50 weeks a year on the road in that call center job. Okay. And I got to see a lot of really cool places and see a lot of really cool things.
I worked for a company one time who said, hey, we'd like you to do this change for us. Okay, cool. So, you know, I went in and I made the change and then I documented it and then I moved it to the testing system and I tested it and then I documented the tests and got everything moving and I moved it forward into production and then I made sure that everything worked there, made all the database changes and then Came back the next week and they're like, you know, we want it to work exactly opposite of that. We changed our mind. No problem.
So I went in and I commented out the code that I had and I put in new code to do the new functionality. And then I documented it and then I moved it forward into the test system and I tested it. And then I moved it over into production. I tested it there. And then I, you know, did the whole delivery setup.
And then I came back the next week and they said, well, we've decided that we actually want it to work the first way again. Okay, no problem. So, you know, the whole rigmarole, did it again and again. Finally, the 5th time I went in and they said, okay, wait. I said, you realize this is costing you $5,000 every time you make this change.
Wait, what? Well, I have to write the code, then I have to document the code, then I have to test the code, then I have to promote the code. It's a process. Those are hours. You're paying by the hour.
That's a— and so till that point, they literally had no concept of there was an actual cost associated with these decisions. And they said, so you— what you're saying is we really need to figure out what we want before we have you code it. Imagine that. Yes, right, exactly. So kind of gave me this whole understanding of the business doesn't understand business requirements, and it's not necessarily natural for them to do that.
And so As consultants, we really need to help them focus on not only functionality requirements, but security requirements and just understanding what the whole environment is and how we move things forward and how things actually need to progress through the whole lifecycle. Yeah. So specific to cybersecurity, how did you pivot and get into this? Well, after I played this long enough, I got to the point where my daughter was in kindergarten And she said, Daddy, can you come listen to me give a speech? And I was going to be out of town that week.
And that was the week that I decided I'm coming off the road. So I got a job at a local bank and worked as a developer there for 10 years. As I was working there, I'd been there about 5 or 6 years. My buddy, who was also a developer, moved over into the security department. And he calls me one night late at night after they'd gotten back from the bar, and he said, oh dude, you gotta come join this department, it's fantastic.
And I said, oh yeah, rah-rah-rah, okay. No, no, seriously, we just went out for this great steak dinner, it was fantastic, it's the best steak I've ever had in my life, and I know you like steak. And I said, I do like steak. And then, you know, the whiskey was flowing. I do like whiskey too.
And he said, I know, and the boss took care of everything, we didn't have to pay for anything. I think That is fantastic. How do I get a job? And he said, we're posting a rec. You just need to go ahead and apply for it.
And sounds great. So I applied for it and they took their time kind of putting things together. And when I finally got approved, they kind of had an issue with the banks. I don't know if you heard about it, but they actually had this issue where they wrote a whole lot of home mortgages that weren't super solid. And then You know, this is mid-2000s, like 2005, 2006.
Yeah, yeah, you've heard of it. All right, so it wasn't just a small banking niche thing. No. So yeah, then they're like, um, no more trips, no more spending money, no more steak dinners. Oh, that's the only reason I got into security.
Come on, you came into cybersecurity for the perks. That's it. And then the perks went away. And then the perks went away. That's not right.
No, that's what I said. It made me cry a little bit. Yeah, but things have rebounded. There's perks again. There are some perks again.
Yep. I'm headed off to Singapore week after next and, you know, I'll go teach a class there for a week. So steak dinners, there are worse things. There will be one or two steak dinners and one or two whiskeys as a matter of fact. All right.
Well, congrats. You, uh, the perks finally came around to you. Yeah, exactly. It only took me what, 20 years? So, uh, you've been doing, um, cybersecurity as a, uh, I guess kind of focused on the, uh, cybersecurity for developers for then the past, what, 10, 15 years?
Yeah, just about. I kind of started off doing static analysis and just looking at code. And what I realized is that I see the same problems over and over and over again. And when you start thinking about it, it's because we don't teach developers how to write secure code. No.
What we teach them how to do is get the job done. And then we turn around and we put unrealistic deadlines on them. And say, okay, I need you to make this and it has to be here. Well, when can you have it? I can do that in 3 weeks.
We need it by Friday. Uh, okay, um, let's do 2 weeks. Yeah, Friday. I already told the business, so we just have to get it to them. So we write sloppy code, yeah, we slam it into production, we don't test it, and then we're surprised when places get hacked.
We shouldn't be surprised at all. And even if we do educate developers, there was a book on how to develop for ASP.NET. And on one of the first chapters, it was, here's how you connect your application to a database. And the example code on the first page had SQL injection in the example code. So we told them, hey, here's how you connect to a database and here's how you get hacked.
So things like that are just the way we've done it in the industry for years. And so the last 10 or 15 years, there's been a big kind of shift to do more secure development. And a lot of the development frameworks have integrated security in there. So we can actually use those frameworks and get some security perks so that even if the developer doesn't know what cross-site scripting is or how to mitigate it, At least the framework takes a basic stab at doing and reducing it about, you know, 90%. If we get to the 90% mark, it's still not secure, but it's better than it was, right?
So yeah, so that's really interesting. And then I got involved with, uh, an organization called SANS that does professional training and started teaching. What do you do for them? Oh, so you're teaching? Yeah, so I actually teach for SANS.
I taught the DEF 544, which was a secure development in .NET. And I taught that for 5 or 6 years. And then I've recently started teaching the Security 542, which is a web application pen testing. And so it's, I get a lot of developers in there too. The secure development courses have gone away, but just developers wanting to learn more about what is this hacking thing and what's going on and how do they do it.
And so it's been a lot of fun just walking them through the basics of, here's a web application, here's how you get attacked, here's how you execute these attacks, here's what you can do with them. And then we usually talk a little bit about mitigation strategies. How can we fix them? How can we do that kind of stuff along the way? So what do you like about teaching?
I like that look in people's eyes when they get it right. I love teaching people new things. I love helping people discover something they didn't understand, something they didn't know, or make that final click between, oh, I've heard about SQL injection for years. I never knew what it was. And it's so easy to do that.
When I was doing static analysis, I cited cross-site scripting and SQL injection 1,000 times. I never knew how to do it. I didn't know what it looked like on a website for years. And then finally I volunteered to teach a class for the OWASP chapter, um, in like 2005, maybe. It's been a while, maybe 2008.
And I'm like, okay, I'm going to show you how to do all these attacks, knowing full well that I had no idea. So I jumped on and I became good friends with YouTube and just wrote some code because I knew how to write sloppy code. I'm a developer. Yeah. So I would write example code and then find tools that would exploit it and did a talk.
And I still have people coming up to me today and say, oh, I remember that talk that you did several years ago. That was great. I really enjoyed it. And then I'm like, that's really it for me is just watching somebody go, oh, that's really cool. And then see them come back 5 or 10 years later going, oh, I'm teaching this now.
Or I just got this job at my job because I knew this stuff and it all started from you. And it's so fantastic. I love that. So in fact, I had a guy come in to check in this morning and he goes, I don't know if you remember me, but I was in your .NET class in Vegas in 2005. Wow.
Oh, cool. He's like, yeah, so guess what I'm doing now? So it was awesome. Yeah. Yeah.
So how much of your time do you spend still teaching and speaking at conferences? I teach about one week a month and then I speak at conferences whenever I can. I just did a 19-day cruise to Antarctica. To speak at a conference. Some, some friends actually put together a conference on— I'd like to go ahead and pause this podcast for a public service announcement.
Cigars are bad. You should not smoke cigars, and you should definitely not smoke 2 cigars the night before doing several podcast interviews. Otherwise, your throat might be on fire and angry at you. That's all. Now back to your regularly scheduled programming.
So some friends actually put together a conference on a cruise ship that left out of Chile, went down around Cape Horn down to Antarctica, spent 4 days in Antarctica, and during those 4 days we actually hosted a conference. And then came back up and ended up in Buenos Aires. And so then they're like, hey, you want to speak South America? Which has kind of been my goal to speak on every continent, which is why I did the whole Antarctica thing. And South America was one of the ones I hadn't checked off yet.
I'm like, yes, yes, I would. So we went to a facility there in Buenos Aires and gave our talks, and then it's like, all right, check. So now I have Australia left, and I need to technically speak in Africa. Okay, I've been there. I went to Casablanca 2 years ago, but I didn't get to speak there.
So I'm hoping there'll be a conference in Morocco in November, but with this whole wonderful thing that's going around, who knows? Yeah, there we go. Oh, sorry. No worries. I'll have to clean up that part for sure.
Yeah, or you can leave it. It shows your humanity. Ah, yeah, I did not clean up that part.
Okay, so back on track. Sure.
Do you have any good hacker stories? Hacker stories are always fun. Yeah, it's, uh, other than you exploiting your own code. Oh, that doesn't count? No.
Then, uh, let's, let's talk other hacker stories. Actually, one of my favorites, we had a customer, uh, 5 or 6 years ago that wanted us to come test their systems, and they were HIPAA systems, so they had medical records in them. They were high value, you know, high dollar value items. Yeah. And we had a new intern Literally day one, hadn't done anything, was just kind of interested in what we do.
And so I'm like, well, why don't you come sit with me? We'll, you know, do a little paired hacking and kind of go through and see what we can find. He's like, all right, sounds good. So it's 9 o'clock in the morning, we're just getting ready. I sat down with my first cup of coffee.
Well, let's be honest, it was 9 o'clock, it's probably my 5th cup of coffee. Yeah, but sit down, just get ready to go start, and he says, I think I found something. I said, James, you didn't find anything. No, no, I think I found something. Okay.
And if you know anything about interns, they always think they found something. It's like, oh, I just broke into the White House. No, you went to the White House's website. That's different. So they— I'm like, all right, show me what you got.
He says, look at this login form. Yeah, it has SQL injection.
Holy cow, it does. So we're literally 5 minutes into the test and I am calling the customer and I said, okay, so you're having us test 7 web applications? Yep. And they all use the same authentication code? Yep.
And you realize you have SQL injection in your login form? What? And I have all of your records from all of your HIPAA systems And since you've been online with these systems for 7 years, I'm pretty sure everyone else in the world does too. Wow. How would you like us to handle them?
And there was a long pause. Yeah, I'm not sure why, but we'll get back to you. Sounds good. And then somebody got to do a breach notification. Wow.
Yeah, yeah, that's scary. Yeah, so it was, uh, but it's always interesting, you know, because it you never know what you're going to run into, right? And it's always the fun things. I, I love puzzles. That's what I loved as a developer.
Writing code, yeah, it's kind of fun, but actually debugging, my favorite, because you can spend hours just running the Google and trying this and trying that and trying this. And then it's that feeling of satisfaction when you get something to go, get it actually to work. And it's the same when you're doing like pen testing, dynamic pen testing. I was doing a test on a system that had a credit card number, and I went into the credit card and I put a single tick in the credit card field, which with SQL injection, it usually blows up. And it didn't blow up, but it didn't act the same as it did when you put in a real credit card number.
So I started playing around with it and trying this and trying that. I finally, after about 2 or 3 hours, which admittedly is probably more time than I should have focused on it, but they actually had a full-blown SQL injection vulnerability in there that I had to use time-based SQL injection to— if it took longer than a second because it was actually running that background logic, then that was going to be controllable. And so I could move things back and forth and actually was able to pull all the data out of their system. It was so well hidden and so hard that if I hadn't noticed that 1-second screen flicker that one time when I did it, I could have jumped over it. And the scanners, web scanners will never find anything like that.
So it was fun. I love those little kinds of things because they're just, they're a blast. And you get that feeling of, woohoo, I am the best developer. You feel like the guys in the movies, you know, and they're, I just cracked the password. You did not stop it.
Yep. So let's, uh, let's talk about your community involvement. So you are obviously on the board for Denver OWASP, but you're also on the board for a school, right? Right. So that's the school I was talking about earlier that we moved up here for.
It's called Alpine Valley School, and it's a school that a lot of hackers and a lot of developers should really get into because it's called a democratic school. Okay. I don't know what that is. Yeah. Yeah.
So the idea behind a democratic school is that it's your education. You should own it. So there are no set classes. There are no teachers. What?
You choose what you want to pursue. You choose how you want to do it, and you decide when you're done with it. Hmm. So there were some students a few years ago that wanted to learn Chinese. So they went to the procurement and said, hey, I want— we want to bring in a Chinese instructor to teach us.
And school said, sounds great. So the 5 of them sat there 2 days a week with an instructor and studied on their own time and, you know, learned Chinese. And after a couple of years, they're like, okay, this was fun. But there were always requests for like, I'd like to take a creative writing class. Sounds good.
And so the instructor showed up the first day and they showed up the first day and said, okay, this class runs until you stop showing up and then it's over. And that's the way it would go. And sometimes they would go for a year. And sometimes they would go for a couple of weeks and then— and that's fine. That's just the nature of it.
So you decide what you want to be. But I've never heard of a school like this before. Yeah, how many of these are there? Um, there's maybe 20 or 30 of them worldwide. Oh wow.
So there's not a ton of them. But okay, and what's the school called again? It's called Alpine Valley School. Okay, it's alpinevalleyschool.com if you want to look them up. Interesting.
So, and it, and it caters to what ages? It's basically everything from 4 and a half to 5 years old all the way up to as old as 20, depending on when you graduate and when you're ready. So it's really an interesting school in the fact that because you took control of your education, you choose what the requirements are to graduate. So you say, you know what, to graduate, I'm going to write a thesis on how I've prepared myself to graduate, and I'm going to present it to the assembly, which is all the parents, the students, the past graduates, the faculty, and they can stand up and present it and defend their thesis that says, hey, I'm ready to be an adult. And they can grab a diploma and head on out just like any other school.
I feel like I would have done that at the age of 6. And that's totally a thing. My oldest daughter, she did it when she was 18 because that's when you were supposed to do it. And my youngest daughter at 16 said, I'm done, I'm out. And she was just going to leave.
And her friends convinced her that said, no, if you're going to do it, you do it right. If you're going to leave, this is how you leave. And so she went through the process and graduated. Now she looks back and she says, you know, I'm glad I did it that way. I'm proud of what I did and I'm happy the way I did it.
But it's a completely different environment, you know, in, in public school, there's a teacher, teacher, Jimmy hit me. And In Alpine Valley School, you write up a case that says, you know, this person broke this rule. And there's a rule book that they— the law book, they call it— that they all adopt at the beginning of the year that says, yep, we're going to do this, and this is the rules that we're going to be held to as a society. And then they'll write up a case about, you know, this is the incident, this is what happens, this is who was involved. And then it will come before the judicial committee.
And the judicial committee is made up of one younger student, one middle student, one older student, and one staff member. And they hear the case, they get witnesses for both sides, they then make a decision and dole out punishment based on the merits of the case and how it does. If the person who was accused isn't happy with that outcome, they can actually appeal that to the student meeting, which happens every week. And they can say, hey, you know what, I'd like to plead my case in front of the entire student body, and then they make a decision. And the entire school is run by Robert's Rule of Order.
So until you see 5-year-olds making motions using Robert's Rule of Order, you have not seen meetings properly run. It's a pretty amazing thing. I don't even know what that means. So you never address each other. You can speak 2 times on any topic.
You only address the chair. It's run by a chairman, chairperson, and there's just a whole set. It's actually probably a 300 or 400-page book of Robert's Rules of Order that actually are ways to run a meeting that you avoid the contention, you avoid the general hostility that you end up with a group of 100 people trying to move things forward and work their own agendas. How do you see the students as, I guess, differently prepared or better prepared for the world beyond school? So I think it's definitely differently prepared.
When your average student graduates from high school, they don't have a lot of direction where they want to go, what they want to be when they grow up. And so now we've convinced everyone that they have to go to college. College is the right answer for everyone because that way we can rack up a whole bunch of student loan debt. So the notion that everybody needs to go to college is ludicrous. There are so many jobs that you can get into that you don't need a college degree— good-paying jobs.
That there's, you know, it's right for some people. And if that's right for you, great. I'm not saying don't do it, but I'm saying everybody doesn't need to. But when students come out of a school like Alpine Valley School, they have an idea what they want to do because they've had the opportunity to explore. A lot of them the last couple of years will get a job or an internship at a company and try things out.
They're like, hey, this is a lot of fun. I definitely like doing this. I'm going to move forward with this as a career. And so they kind of know what they want to do. They get out and the entrepreneur rates are actually really high too.
So that's kind of interesting where out of public school, I think it's about 3% of the student body will actually take an entrepreneurial role and start a job or something like that, where it's about 13% coming out of a democratic school. So I would imagine because that's, that's definitely a I mean, that's your mindset if you're, you're going to be in a school like that, right? Yeah, you just— I'm taking control of my life just like I took control of my education. Just like— it's also interesting, you don't see the big lashing out issues with teenagers that you do in a typical school, because when they're in school, they feel like they have no control, right? Alpine Valley School has an open campus after they're 9.
So do you feel like walking off and going to Taco Bell for lunch? You can do it. You sign yourself out and you sign yourself in and you're responsible. That's the whole thing is about responsibility, right? Act responsibly and you'll be treated responsibly.
And so it's a really cool model that turns out some really interesting people. Yeah, that's fascinating. Aaron, you're going to speak in about 50 minutes. You've got a talk here at SnowFROC. What are you going to be talking about?
I'm actually talking about passwords. Passwords are kind of the bane of our existence as security people. They sure are. And just as the general population. In fact, I'm going to put my favorite password up on the screen several times, mainly to convince myself that I should stop using it because it's now been exposed to the rest of the world, but also to show people that I can create a password that meets all of your password construction rules, and still sucks.
And so my whole point is to take some of the new stuff that's coming out about password construction and how we should do it and how we should have people do it and just kind of show people that, hey, when we talk about passwords, let's not use the same stuff. Let's look at the fact that, you know, the manager in NIST who came up with the original password rules said, much of what I did, I now regret. I mean, that's an amazing quote because it says that we're doing passwords wrong. And anybody that's sticking to that, you know, 8 characters in length and 1 upper, 1 lower, 3 of the 4 characters, all that kind of stuff, we're actually doing our users a disservice and we should start forcing them to do more secure ways and making it more usable and much less painful. There are so many different ways to do passwords that We need to change.
Yeah, we definitely do. I'm ready for a world without passwords, right? Yeah. Well, thanks for being here, Aaron. I, uh, I appreciated you taking some time and, and, uh, talking to me.
Yeah, well, thanks for having me. It's been great. That concludes my interview with Aaron Kurer from the SnowFROC Conference. Thanks for listening. Be sure to follow and support Colorado Equal Security on Patreon.
This is Jason Jaques saying Be safe out there. Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals Security.