All episodes

Newscast

Apple Podcasts Spotify SoundCloud

News from: MycoTechnology, Impulsify, Flatfile, ArcherDX, System76, Red Canary, Coalfire, JumpCloud, Webroot and a lot more!

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript4693 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

Welcome to Colorado Equal Security. This is your newscast for episode 168 for the week of June 15th, 2020. Alex, uh, we're, we're remote again. What's going on here? Uh, well, the good news, it's not because of a flare-up of coronavirus, so positive there.

It's a flare-up of getting out into the world. Yeah, I'm actually taking a vacation. Can you believe that? I literally cannot believe that. It is weird in these times, but I am going out of town.

Nothing crazy, just going up into the mountains a little bit, which means it's easier for us to record remotely than to get together. Well, I miss seeing your beautiful face, but hearing your beautiful voice is just about as good. Oh, thanks, Robb. And now that we're done with that, let's talk about some housekeeping. We have some information like there's a Slack channel, lots of great conversations going on there.

You can join the Slack channel with all of your favorite Colorado security people by going out to colorado-security.com and clicking on the Slack button there. We also have a mailing list. If you go to the website colorado-security.com, scroll to the bottom, there is a form you can fill out with your email address. We will send you the show notes in your email every week, mostly at the same time, and it'll, you know, you'll get a little bonus information in there about the podcast. And if you like the podcast, why don't you go ahead and rate us on your favorite podcast listening app?

Tell us what we do well and what you'd like to see different, and we'd love to see that information. Of course, while you're there, you can subscribe and get the podcast in your inbox every week. That is a great bonus, no work. Also, we'd love it if you tell your friends, let them know how great Colorado Equal Security is, how great the podcast is, the Slack channel, everything that's going on. Tell them to come be a part of the community.

And of course, if you want to support us even more, there's a couple more ways you could do it. Number one, we have a Patreon campaign. You can help support us financially. You can get the details on that on our website. And also, we'd love it if you'd volunteer to help do some interviews.

You know, this podcast is usually a newscast followed by a feature interview. You know, due to COVID and due to some constraints for our schedules, we haven't been able to keep up with the interviews. So if you want to help out do it, we would love that. Somebody did propose an interview this week, Robb, as you know. And so, you know, we may have an interview coming up, but we'd love for more people to come and talk with us.

So absolutely. We do have one more reminder. We talked about last week that Douglas Brush had set up a new Colorado Equal Security Book Club. Once again, as a reminder, we're going to have that first book club meeting on July 15th, and we're going to start with the book Start With Why. Yeah, and just a reminder, you know, this is a business sort of book.

It's not a technical book. The why is not a variable there. It's, you know, it's about why you want to do things. And so— but it actually is a variable though, right?

In some senses, I guess it is. You got to figure out the variable. It's a question, right? But not necessarily a variable in a programming sense. So I have started Start With Why.

Why? I haven't started it yet. See there, I've started. I started with why. Yeah.

Well, I actually have started reading the book. I haven't got very far, to be fair, but I have started it. I'll be ready by the 15th. Well, I, you know, since I am going on vacation, maybe I'll take the book with me and I'll have a few minutes to read. That's a great idea, Alex.

Hey, speaking of great ideas, you know, in the, in the day of COVID when you're not allowed to go sit in a movie theater next to each other, you know what can really fill that gap? Um, don't say Netflix. Boredom. Drive-in movie theaters. Oh yeah, who doesn't like a drive-in movie theater?

And did you know that there are 10 drive-in movie theaters here in Colorado? Uh, I did because I read this article, um, previously. I don't know that I knew there were 10. I knew there were some, um, but actually, in addition to having 10 in Colorado, the Holiday Twin in Fort Collins is the busiest drive-in in the country. Pretty awesome.

And they said that on Friday and Saturdays in the summer, they are sometimes turning away 200 cars from getting in to see the show. That is crazy. Of course, due to social distancing, they're only allowed to take in, you know, half the normal audience that they would right now. But, you know, drive-ins are the original social distancing movie theater. So, I think it's a great way to go and see a double feature, you know, hang out in your car.

I always loved watching movies at the drive-in when I was a kid, you know, turn the car around, sit in the trunk. Good stuff. You know, I, I gotta wonder how— why are they making half capacity for a drive-in movie theater? It feels like they could probably get away without doing that. Yeah, my guess is it's probably one of those things where there's not enough nuance in the regulation.

I think there's lots of areas that could be improved, not just for the drive-in movie theater stuff in the future, knowing what we know now, but my guess is this is just a blanket thing that businesses in general can open up at 50% capacity. I think we need to start in a write-in campaign to get that changed for the drive-in movie theater business. That seems good to me. Call the governor, call your local legislator. Make sure that they increase capacity at drive-in movie theaters because they have nothing better to do than deal with us right now, right?

Exactly. Uh, next, there is a Denver mushroom startup that closed a $39 million Series D. Uh, this is not the mushroom you might be thinking though, Robb. When you're looking for hard-hitting news, this is the place to come, Alex. We go from drive-in movies into a mushroom food startup. Um, really, we're killing it all over the place here.

Yeah, so, uh, mycotechnology— they have used mushrooms and mushroom powders as nutritional ingredients in foods and to help with things like shielding your taste buds by temporarily blocking bitter tastes. This allows companies to put less sugar into products so that they don't have to be as sweet because you're, you're not having that bitter taste. So am I having déjà vu? Am I in The Matrix, or have we talked about this before? I don't think so, but, you know, it's entirely possible.

You know, I know we have talked about, uh, potentially decriminalizing magic mushrooms, but, uh, I don't know if we've talked about this or not. Could be. Well, they, they look like they're doing great. Of course, their flagship product, which all of us know, is called Clear Taste, which acts as a shield for your tongue, and it will temporarily block bitter tastes, which sounds amazing. You know, also, um, you know, this is their Series D, so it is possible that they're during their Series C or Series B or maybe even Series A that we did pick up the news.

Who knows? Um, well, and, and so when Clear Taste— or yeah, Clear Taste is blocking the bitters. Um, the nice thing about that is sugar becomes— comes out more, so you actually don't need as much sugar in your food to get that sweet taste. Yeah, companies can actually make it a little bit healthier. Kind of a cool idea.

And, you know, uh Mushrooms are, you know, a great source of umami, so you can add taste to your food too. Umami is, of course, my favorite flavor. Yes. My favorite flavor is despair.

Well, you're living in the right times, Alex. Alex has never been happier. Next, Impulsify, which is a startup here out of Denver that makes self-service kiosks, is moving into self-service kiosks for apartment communities. Pretty cool idea. So, if you've ever thought to yourself, I want to have all of the options of a 7-Eleven but without the impersonality of a vending machine, Impulsify is exactly the spot for you.

Yeah. It reminds me a little bit if the little sort of food area at the Courtyard by Marriott grew up and decided it wanted to be a little more automated. I think it's got, you know, some sandwiches and a can of Pringles or something like that. And then now it's in a vending machine for you to get without having to interact with anybody. Yay, COVID.

And I have to assume, because it looks like you could steal stuff, I have to assume there's some kind of electronics jimmied up here so you get shocked if you try and steal something. Most likely. Maybe there's a trapdoor that you fall through or something like that. Yeah, I think that's probably the right way. But pretty cool.

It's a Colorado company, obviously got this big deal to do this on the East Coast. We love to see our local companies succeed. So congratulations to Embulsify. Our next story is about another Colorado company that's succeeding, and this is a Denver startup called Flatfile. They just raised $7.6 million, really to speed the delivery of their new product called Concierge.

Yeah, kind of cool. You know, they're a data ingestion company, which I guess I didn't realize that that was enough of a market to have a company completely dedicated to that, but I mean, sure, why not? So, you know, they're Their product Concierge is a no-code solution for importing data into your organization. So that sounds kind of cool. When I looked at it, what I saw was like sharing between organizations, you know, what we maybe currently do via SFTP or some kind of share file system, they're doing through their SaaS application that just makes it easier.

Like you said, no-code, easier for less technical people to do business-to-business sharing. That's what I saw. And there's certainly a big business problem there. And if someone comes along and innovates, I think there's an opportunity for them to become the Zoom of that area, right? Before Zoom came along, you would have said, oh, there's way too many telepresence companies.

And then Zoom comes and makes it easy. And all of a sudden, they're whatever, they're worth $150 billion. Well, clearly SFTP is mature and automated, and there's no need for this. But beyond that, I think this is a good thing. If we can get out of people's way and let them do their business.

That's a good thing. So congratulations to Flatfile and their co-founder David Bostovic, who is here in Denver along with 5 other folks. This is their biggest office. So continuing on the good news, ArcherDX, a Boulder biotech firm, has filed their IPO for up to $100 million. That's fantastic.

They are going to be listed on NASDAQ under the trading symbol RCHR, or Archer without the vowels. And it looks like what they do is they create a suite of software products to help clinicians with patient care and to help biopharma companies accelerate drug development. Yeah, they also have a product that does, does cancer tracing. So that looks like a pretty cool thing. If you did read through the whole article, they did talk about the fact that, you know, there is going to be some risk associated with their IPO given that they don't make any money currently and that they're not expected to turn a profit for a while.

Sounds like Amazon. But hey, you know, that sounds like a good investment. All right. Well, we're talking about yet another local company. We've talked about System76 on the podcast quite a few times, but they have yet another big piece of news.

I'm excited to keep, you know, bringing the news from them. I know a lot of folks in the community, especially the security community, like their systems. They make really high-end Linux workstations and now laptops as well. And they're announcing that they're coming to market with a brand new chip design. Yeah, so they're going to be using the AMD Ryzen and AMD Ryzen Threadripper chips in their new portable Linux workstations.

And by portable, it means it is— it's technically a laptop, but they are using desktop-class chips, not mobile chips. So You know, it is going to be a, I think, a fairly clunky laptop, not one that you're going to want to take on a business trip where you don't have something to cart it around in. But looking at the specs, they've got some pretty good processors and pretty good graphics cards. So sounds like a lot of fun. Like a 1996 laptop?

Yes. Yeah, exactly. That's kind of what it looks like. Giant brick. Yeah.

I'll tell you, I don't keep up with chips all that much, but at least from what this article is saying is that AMD has very clearly leapfrogged Pentium. In terms of, you know, the chips that they're making. And now they're excited to, at least System76 is excited to bring those higher quality chips to their devices. They're killing it, Robb. Killing it.

Killing it. Good for AMD as well. Yeah. Next, we had a story from Red Canary. This is actually a republish of a story that was first in Silicon Angle talking about the Dark Basin hacking group.

And so Dark Basin has been running some campaigns. They were investigated by Citizen Lab and some other folks around their phishing and what they were doing. And, and Red Canary has some, some commentary in here about Dark Basin. Yeah, pretty cool stuff. The, you know, I've heard of Dark Basin several other places.

It's nice to see our very own lovely local company Red Canary quoted in here. Keith Rothi, Rothi, who is the Or excuse me, Chris Rothi, who is one of the co-founders there and the Chief Product Officer, really talking about what we've seen there and really how these guys are going about what they do. It's interesting. This is maybe the first time I remember seeing that it was an India-based ATP for one of these big groups. And really, the people they've been targeting are high-level hedge funds, government organizations.

You're not your run-of-the-mill ordinary ghost do wide wide spamming out to big groups of folks. Yeah, uh, so good stuff. Uh, glad Red Canary is, uh, is reaching, researching, and, and talking about that stuff. All right, next we have a blog from Coalfire, which is a strategy for cybersecurity strategy, and this is written by John Hellickson. You all might remember we talked about John last week as he signed up as a new patron for our show.

Maybe a coincidence, maybe not, but it's a pretty good article. Yeah, um, You know, maybe he signed up and maybe we happen to notice that he was the author of this blog, or maybe we just like John. Either way, or we know that Coalfire has good blogs. Anyway, they're talking about the CISO advisor function that they have at Coalfire and how they try to be a little bit different in looking at your cybersecurity strategy. This is actually the first in a series of blog posts.

So it's sort of laying out what that series is going to be looking like. It looks like the next topic that they're going to be talking about is around controls discipline, but also business alignment and performance management. So pretty interesting. I really appreciated John shared a little bit of his own personal experience. You know, he was the CISO for First Data, and he references in here— he doesn't say First Data, but you know, we all know that's where he was.

He mentions really that he wished at the time that he was CISO there, he had a little bit better perspective on how to make a business-aligned security strategy. And I think it's just really refreshing to hear someone talk that, hey, we're not perfect, we could use some help. And, you know, recognizing that just because you're in the position doesn't mean you're equipped to do it well yet. And I think, you know, going to someone like this for help or reaching out to the community like we do on the Slack channel to ask these questions is super high value. And really the most important thing is understand what makes your business successful and create a strategy that aligns with that.

Yeah, I mean, even somebody who can do it well Um, you know, you're always going to need some help, so it's good to know that that stuff is out there. All right, uh, next article we have is from JumpCloud, and it's around identifying unencrypted private SSH keys on user machines. Yeah, so I thought this was pretty cool. Um, JumpCloud, of course, is a directory company, sort of an alternative to Active Directory, and it sounds like one of the, the functions that they have for, uh, users and machines Excuse me, that are enrolled in that directory, you know, they can check your machines to see if the keys you have stored there are encrypted properly. So not anything that's crazy, but, you know, seems like a pretty good feature.

Yeah, I agree. It looks like a pretty good feature. It does turn a little bit into a sales pitch, I think, as they go, but I think understanding that those SSH keys are critically important and something that we need to be thinking about, making sure they're encrypted, making sure we know how they're controlled, That's a super important point, and anyone who's not already thinking about that, probably spend a few, a few minutes trying to figure out how to do it in your own organization. For sure. All right, and, uh, last article for this week, uh, this comes to us, uh, from Webroot.

It's called Your Data, Their Devices: Accounting for Cybersecurity of Personal Computers. Yep, so this is really one of the findings from a report they did was that personal devices are about twice as likely to be uh, to be breached or to be infected with malware as a, as a business device. And this becomes especially important, and I think the whole part of this article is when you're working from home in COVID and there's so much more BYOD, that fact becomes much more important. As a business, you need to be thinking about the fact that you've just potentially doubled the likelihood of getting some kind of malware on your endpoints. Yeah, for sure, and that's a great point.

Um, I think another great point, which is actually not in this article but was another article we didn't include this week is, you know, with this, the everyone working from home and the greater possibility of users using personal computers, you have to think about that fact for your vendors and third parties as well. You know, all of a sudden you've got an uptick that they might have in people using personal computers, and then they're going to have those same risks that you do. And then their party, their third parties and their third parties, and all of a sudden we're— we got everyone covered, right? Oh my word. All right.

Hey, that is it for news. Let's move over to the Slack message of the week. Yeah, thanks to Andre Gaeta, who is the sponsor of the Slack message of the week. We appreciate his support. He has been supporting us with the Slack message of the week.

And even before that, we did trivia prior to the Slack message of the week for those of you that have been around long enough to remember that. And he gives a $25 item from the Colorado Equal Security store every week to someone who we pick who made a great post in Slack. So Robb, who is our winner for this week? This week we picked Flint. We picked Flint.

He gave us an errata. We don't get a lot of errata on the show, which, you know, for those who aren't aware, basically if you have an error in a written word or in this case a podcast that we can come back and call out, that's what errata is. And he called out the fact that what we called a microburst last week is actually a derecho. Derecho. Yeah, so, uh, just to be clear, you know, Robb, you chose this because he was pointing out the fact that I said it was a microburst.

He basically called you a terrible person, if I remember correctly. Yeah, something like that, something like that. Um, but so yes, at the time when we recorded, I did not know that it was a derecho. I have since learned that, and I appreciate Flint for pointing that out as well. And we can get better.

And now Flint can look better wearing some piece of, uh, Colorado Equal Security swag, or maybe holding it, or putting it on his car, or I don't know, on his house. Do we have a Colorado Equal Security windsock maybe? If we don't, you could certainly turn something into a windsock. That's true. That is true.

All right, well, congratulations to Flint on that. Let's go ahead and jump over to events. We do want to remind you we have a calendar of events on the website. You can go see all of the wonderful things happening in the next few months, but we have, you know, for the next couple of weeks, let's go through those events. First, NCC, the National Cybersecurity Center down in Colorado Springs, is doing their 2020 Cyber Symposium on the 15th and 16th.

On the 16th, we have a couple of events. We have the CSA doing their June virtual meeting, and I think that was focused on how to build awesome security instrumentation to automate appsec testing and protection, which sounds like a really good topic. You know, I apologize, Robb, that's not what it is. I mispasted that from the OWASP meeting. That's actually the OWASP topic for this month, but once I pasted that comment in, I didn't have a way to remove it.

So I'm sure the CSA has a great topic as well. Well, I feel, I feel kind of like a jerk right now. I got to be honest with y'all. It looks like— okay, now I got to say what they're really doing. I clicked the link.

They're going to be talking about cybercrime as a crisis or in a crisis, and that's going to be talking about what changes Proofpoint has seen to cybercriminal activity during the crisis. Nice. As you mentioned, also on the 16th, ISSA Denver is doing one of the not RMISC sessions. Matthew Titcomb, DOD contractors and those supporting them, are you ready to get audited? Well done.

On the 17th, a little bit of a flavor of what we just talked about. OWASP Denver is doing their June meeting and they are going to be talking about how to build awesome security instrumentation to automate AppSec testing and protection. And I agree with you, that sounds really cool. It's going to be Jeff Williams who's doing that talk, by the way, from Contrast Security. On the 18th, ISSA Denver has Brad Rhodes talking using big data tools to understand your cyber environment.

On the 23rd, ISSA Denver has John Stock talking about securing connected devices and preventing wireless attacks. On the 24th, ISC2 Pikes Peak is doing their June chapter meeting. On the 25th, ISSA Colorado Springs— ISSA Colorado Springs is doing their June online series. Also on the 25th, ISSA Denver is having Toby Zimmerer addressing the need to dispose of data. Something that is good, but, you know, often overlooked.

All right, so I get to say this, this last word. On the 27th, it's Akomathon. That sounds right to me. Akomathon. What is Akomathon?

Uh, that is a great question. Um, I am clicking on the link. Yeah, I know it is Akomathon 2020. This is the conference that they've been talking about it, and we've actually seen a few notes about it in the Slack channel. Uh, basically, it would— their intention was for this to be an in-person conference.

Due to COVID, they've moved it to being digital, but it should be a in the future an in-person conference. And now there's some nice content. I'd say some more engineer-type level content if you're interested in getting some hands-on security information. Good stuff. Oh, and a capture the flag.

There's a big capture the flag as a part of it too. Yep. And that is also our last event for the next 2 weeks. Now let's talk about jobs. Alex, do you have any jobs you want to share this week?

You know, Robb, um, I don't know if I feel, uh, good or bad that I have a job and you don't. But yes, I am looking to hire a security program manager. This role will be someone that helps me implement the things that we have in our security program, work with all the entities that we support and oversee, and make sure what it is that we need to get done gets done. And what kind of technical skills are you looking for there? Yeah, so this job is just about 0% technical.

So skills like project management, communications, you know, people skills, getting to build relationships, as well as, you know, some knowledge of security are important things for this role. Awesome. Moving along, we have Synnex Corporation hiring a manager of IT security. Arrow Electronics is looking for a corporate IT auditor 1. Ball Corp is hiring a cybersecurity operations lead.

Uh, there are actually a few jobs from Ball this week, so if that one doesn't strike your fancy, look for some others. Fluent Stream is looking for a security and compliance analyst. Sierra Nevada Corp is hiring an information systems security manager 1. InteliSecure is looking for a vulnerability management program lead. InteliSecure is one of the local security companies we haven't talked about much lately.

I know they had some layoffs as a part of COVID but it's good to see them getting to hire. Hopefully that means they're They kind of got through the rough part there. Yeah. Real-Time Innovations is hiring a software engineer security. Crowe, which used to be Crowe Horvath, I think, is looking for a third-party risk manager.

I think this is a consulting position. And finally, Deloitte is hiring a cybersecurity platform engineer, and this is focused in Colorado Springs. They're looking to hire. Yeah, pretty cool. Well, Alex, that is it.

I'm excited to hear about your vacation when you get back. Maybe next week you can tell us all about all the COVID you got on the road.

I won't be able to because I'll be in quarantine, but maybe in 2 weeks I'll be able to tell you. Cool. All right. Well, that's it, everyone. Have a great week and we'll talk to you soon.

Awesome. Thanks, Robb.

Back to all episodes