Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. Uh, this is the newscast for episode 172 for the week of July 20th. Uh, this is Alex Wood, and as you can probably guess, if I'm the one leading off the podcast, Robb isn't here.
Robb actually is taking vacation, believe it or not, and since he is not here, I've got a special guest co-host, Brian Beyer. Welcome, Brian. Awesome, thanks, Alex. Uh, Brian is of course, uh, with Red Canary. Um, how are things going, Brian?
Things are going well. Yeah, wild and exciting as everyone would imagine in 2020, but Red Canary and all of our team has done well. And we, as you can imagine, have no shortage of problems to solve for our customers. I'm sure. You staying happy and healthy, family good, all that kind of stuff?
We are. There are a lot of parts of this that I've enjoyed a ton. Losing the commute and getting to now be on time for dinner at least 90% of the time has been a big benefit. And after the first, the first month of this, I did not prepare correctly from a I started using the office that I would use one day a week and learned very quickly I need the standing desk at home. I need a much better chair.
So now I'm set up properly and it's been great. Yeah, that makes sense. It took us a little while here to get things going too, mostly because, uh, you know, I have 2 teenagers and my wife who also works. So we all needed our own space throughout the house. So we had to make sure everyone had their own space.
Um, I had to buy a couple extra monitors and some other things like that. But once we got everybody set up, it was actually fairly smooth. That's good. Not too bad. I did at least prepare for monitors.
The second we closed the office, as I walked out, I was like, I don't think I need anything else here except for my monitor, so I'm taking that with me. Nice. All right, well, let's get into it. Before we talk about the news, we've got a little bit of housekeeping. We do have a Slack channel.
Did you know that, Brian? I did know that. So if you want to come and talk to nearly 1,500 of your closest Colorado Equal Security friends, go to our website, colorado-security.com, click the Slack link, And you can join and have great discussions with everyone else that's in there. It's vibrant, lots of stuff going on there, lots of good things in the Slack channel. We also have a mailing list.
If you want to get the show notes emailed to you every week, go to the website as well, scroll down, there's a form to put your email in there. You will get the email on Sunday usually with the show notes, as long as I'm good about doing that. We'd also love for you to subscribe to the podcast, and while you're there, rate us. This means that you'll get the podcast downloaded to your favorite podcast listener every week automatically, and you can also let people know how great the podcast is, and maybe they'll find us on their own. But beyond that, you could also tell a friend, let them know all of the great things happening with Colorado Equals Security and that they should come hang out with us.
And if you want to support us financially, we do have a Patreon campaign. Again, you can find more information about that on on the website colorado-security.com. At certain levels, we will even give you stuff like a free t-shirt and other things like that. So please come, uh, we would love to have more Patreon supporters. We also want to thank all of our Patreon supporters that we currently have.
Thank you, we couldn't do it without you. Uh, okay, before we jump into these, one other thing. We're almost there. We are doing the first Colorado Equal Security book club The July meeting is going to be on the book Start with Why, and that is on the 23rd. If you want more info on that, jump into the book club channel on Slack.
That is this Thursday, I guess that is. So if you haven't started reading, you better start. All right, let's jump into the news. All right, to start off, Denver's Bye Aerospace landed $10 million for all-electric airplanes. When I first started looking into this, my immediate jokes came to mind about really not wanting the batteries to run out on that and wondering what the use case was.
But it actually was really interesting as I looked more. The first initial use case is on building all-electric airplanes for training. Yeah. And so it's 2-seaters because obviously, like, I don't know if you've done anything to get a pilot's license, but I did a bit of that when I was a kid, and you have to spend a tremendous amount of hours on training planes, and they're looking at the amount of CO2 that they can save by converting those to electric. And it's perfect, right?
Because you have short in-and-out flights around. It doesn't have to be super long distance. So really neat use case. Yeah, for sure. Um, it looks like they're building the 2-seater, and then also subsequent to that, they're gonna build a 4-seater.
But still, both of those, I think, aimed at that training market. Um, I mean, it seems like a good first step too. Like you mentioned, they're going to be short flights. You don't have to worry about running out of battery, right? But, you know, then you can also prove the technology, and then maybe someday we're going to have electric jetliners.
Yeah, you know, who knows? Exactly. And if you think about how many of those small 2-seater planes can be kit planes, right? Imagine how much easier a kit plane is when you're plugging in an electric motor instead of anything, you know, traditional. Yeah, yeah.
So, uh, good on them. It sounds like they had gotten, uh, $5 million earlier and then just closed the second half of the round with another $5 million investment. So Hopefully that keeps them going and we can see some electric planes soon. Uh, next, a Portland-based logistics tech company is choosing Denver for its second headquarters. So this is pretty cool.
Um, the, uh, this— the solution here is around, um, around trucking. So this is a company called DAT Solutions, and they make I want to call it a bulletin board, but that's probably being a little, a little too simple. But it's a service that connects people who want to ship things and, you know, smaller independent truckers and trucking firms that can ship things. And, you know, they've been expanding, adding things like, you know, ML and other analytics to their solution to help match people up automatically. And because of that, they're adding more people and they're going to be doing it here in Denver.
Yeah, these, these companies are awesome. Having grown up around a family business in trucking, it is— there's not a lot of technology normally in that business, but there's a couple of companies like DAT who have really focused on taking really great software engineers and data scientists and figuring out how do you optimize that? Because it's the world's biggest optimization problem, right? How do I get stuff from here to there as quickly and cheaply as possible? Right.
You would think that that would be an easy thing, but there's a, there's a little complexity involved there. I mean, when the majority of your truckers are all owner-operated, like they are people, right? Like they are not massive companies. They are people. You are connecting individual people with a company who wants something in a different location, right?
It's fascinatingly complex. For sure. On the other side of things, we had a 1,000-job tech firm focused on emergency communications. That is actually moving to North Carolina instead of Colorado. So it was Colorado versus New York and— or I guess Rochester, I think it was.
Yes, and that's still New York, the Triangle Area. Yes, not Manhattan. Not Manhattan. What I, what I thought was interesting, you know, everyone may have different opinions on this, but we ended up losing because we offered $10 to $11 million in state benefits or credits to them Rochester offered $12 to $15, and Triangle offered something like $33 million of incentives. Yeah.
Yeah, I mean, I think that the, the Denver Economic or Colorado Economic Development Commission is usually pretty good. They, they're happy to offer incentives, but don't go crazy over the top. Right. You know, hey, we'll bring you here, but we're essentially gonna pay for your company to be here forever. Um, and that, that doesn't help anybody here, right?
Yeah, yeah, you get some more jobs, maybe there's a little bit of ancillary benefit, but, you know, we've got plenty of people here. I'd like to get more jobs, but, you know, we don't need to, uh, to mortgage everything to get people here either. So exactly, yeah, not the worst thing in the world. Sad we didn't get them, but oh well, it's the way it goes. Um, next, you know, Brian, we were talking earlier about everyone working from home.
We had an announcement from Visible, which is a mobile phone startup backed by Verizon, that said they're not going back to the office. They're actually getting rid of their office and all of their employees are going to be remote permanently. So that's pretty interesting. I guess this shouldn't be much of a surprise considering the company itself is based on the fact that they don't have any stores to sell their phones in, right? It's an all-internet-based sales model for, for their mobile phone service.
So I guess it, it makes sense that they wouldn't have an office for their people either. Definitely does. And also has the caveat next to it that it was a WeWork office, right? Not physical real estate they had and owned and everything. So it makes it easier to make that decision or change their mind later.
Yeah, when you can just tell WeWork that you're not coming back, it makes it a little easier than having to negotiate yourself out of a lease. Exactly. We also had Brad Feld, who's probably one of the most well-known venture capitalists coming from Colorado, up in Boulder. He has a new book that's focused on talking to startups about dealing with the unknowable, which comes at a really important time right now as a lot of companies are seeing their worlds turned upside down. Yeah, so he either wrote this book really quickly, or, or he is actually a smart guy and can kind of see the future.
So yeah, so the article itself is a little bit of a Q&A with Brad, talking a little bit about some of the stuff that's in the book. This is with TechCrunch, and they do a pretty good job in there. So if you want kind of a sneak peek of some of the things that they talk about in the book, check this out. And I guess go get the book, and I'm sure it's pretty good. Yeah, highly recommend it.
A lot of his writings were very helpful to us at the beginning of Red Canary, and in the 3 times I've sent him an email, he was a super nice guy. Yeah, you know, it's funny, um, you know, Robb interviewed him for the podcast. I've never met him in person, but he seems like a super approachable, super nice guy, um, you know, who's also one of the most influential people in venture capital, right? So pretty cool. Uh, next we, uh, have an announcement, uh, from StackHawk.
StackHawk, of course, is the software as a service company here doing AppSec. They have hired Simon Bennett Who is the founder of ZAP. So if you know ZAP, Zed Attack Proxy, which is a web app testing tool, they've hired him to help with the company and to continue to work on ZAP, which is one of the things that is leveraged in the StackHawk product. Very cool to hear. Yeah.
Logarithm's Virtual Security Conference, or I guess Logarithm's Security Conference, is now a virtual security conference, and it's going to be entirely free to everyone in the community. So this is neat to see from them, and I think is a trend we're going to see a lot more often over the coming years of companies trying to figure out how do their user conferences look and how can they best serve the community. Yeah, I've actually been to the Rhythm Roll conference a couple times. It's a good show, and it'll be interesting to see how it works online. But yeah, I mean, it's— there's kind of been this model for companies to have user conferences that are for pay.
I don't know if it's a profit center or not, or if they're really using it as, you know, just to cover costs and things like that. But, um, it'll be just interesting to see now that most of these are going to be online, you know, can you still justify making people pay for them? Are they all going to be free now? Right. So yeah, we'll see.
I'll definitely say if anyone is looking for a billion-dollar startup idea and wants to write some code very quickly, someone please go create a virtual event system that doesn't look like it came from 1995 because I don't know what your experience with them has been so far but they all look terrible. Yeah, it's not a great experience. It's not, it really isn't and most of them, they're not meant for like full conferences. They're meant for like a webinar and then you try and build a whole conference around that and it's painful. Yes, it is.
Next, Coalfire, they've released their annual cloud security report. This is, I think, the 3rd or 4th year that they've had this report. You know, they take insight from, I think, from some surveys that they do, as well as, you know, they do a lot of pen tests and things like that to figure out what is the state of cloud security. So some pretty cool stuff there. I did not read the full report, but they do have some highlights.
One of the things that I thought was interesting was that they thought that— oh, where is that one?
They thought that it is important to have a management steering committee for people who are moving to the cloud, but less than 40% of people said that they had a management steering committee for moving to the cloud, even though they all thought it was important to do.
Another one that the— I think we all know it can be risky to use your legacy teams that aren't used to managing things in the cloud to do a move to the cloud, yet only 20% of the people that they talked to planned to augment those existing teams with outside experience that was necessary. Definitely some interesting insights there, so you should check out that report. Yeah, good stuff. What did you think about the stat that 67% of respondents plan to use code and automation for operations? So that's one of those ones where I think it's probably aspirational.
Yes, we would love to use coded automation, and you would think that that number would be 100%, right? Exactly, yeah. But I think 67% is somewhat more realistic, but I think that the The actual number is probably even half that. Maybe a third of the people, at least right off, are going to actually do that just because of that previous stat that I mentioned that, hey, we're not going to bring anybody new that knows how to do the code and automation around the cloud, yet we're expecting to do it anyway. So, yeah.
All right. Fun stuff. Similarly, Optiv released an Azure API Management tracing helper. So the team over at Optiv found that there are ways to tell Azure when making a request to it, you know, hey, turn on tracing mode so that I can debug these requests and figure out what might be working or might not be working. And if you don't know about this and you haven't configured your controls correctly, you might allow a user to query an Azure API, turn on that debugging information, and then get debugging information back that you didn't want to expose.
So maybe perfectly in line with what you just said, as you go to the cloud, make sure that people on your team are brushing up on how the best practices work for that cloud platform to make sure you've turned things on or off. Yes, this seems like the perfect example there. If you have folks that are used to legacy environments that are setting up the cloud, they might not realize how easy it is to misconfigure something and put you in a bad place. But that was definitely a good article by Optiv, in-depth talking about that. The API management stuff in Azure.
So good stuff from them. Next, we had a blog post from Secure64 who— they're talking about the Alina point-of-sale malware and the importance of DNS security. Brian, surprise, surprise, Secure64 does DNS security. But this is a good blog post talking about the fact that this particular POS malware does DNS tunneling. So it's trying to exfiltrate credit card data and things like that through a DNS tunnel.
Coincidentally, Secure64 can help protect against that, but I think just in general, DNS tunneling and that sort of threat vector is not something that people think about very often. It's not, and that's not just at corporate security teams. Obviously, you know, with the level at which we work with different endpoint security vendors, we have this type of conversation with them a lot about why different types of telemetry are very important, and many times we've had this conversation where we say, we really need to see what DNS requests are being made and what the responses are, and the common response is, well, why do you need to see that type of network connection? We're gonna heavily rate limit those because DNS happens all the time, right? And that's too much data.
And when you perform an investigation or you're trying to do detection of things, you have to see that because it's a great channel for communications, right? And frankly, it becomes even more of a nightmare with more of this moving to DNS over HTTP, and that then obfuscates even those normal requests inside of an HTTP connection. Yes, and then go one step further, then you've got DNS over HTTPS, so it obfuscates it and then you can't even see it. Exactly. So yeah, DNS security is important.
Talk to Secure-64 if you want more info on that. And then the final article that we had this week was from a blog post from InteliSecure. This one I actually thought was really interesting. You know, InteliSecure does some MSSP work, but, you know, their main focus is on data loss prevention. That's really their core piece here.
And they're releasing a new service called Aperture, which is basically To me, it sounds like an MSSP around DLP. So they're talking here about Microsoft tools specifically. And if you're a Microsoft shop and you're in Office 365, depending on your license, you probably have a decent amount of their DLP tools built into your service already. Almost no one uses them. And if you do use them, you're probably not looking at that data and that telemetry to know what's going on.
And InteliSecure here is saying, hey, give us all that data. We can help you out and monitor and help figure out what's going on with your DLP in the Microsoft cloud. So pretty cool. Very cool. All right.
So that is the news. Let's jump over to the Slack message of the week. Thanks to Andre Gaeta for sponsoring the Slack message of the week. He has been doing this for a long time out of his own pocketbook. So we appreciate that.
The winner will get one item from the Colorado Equal Security store, so you can get something cool like a coffee mug or a hat or a t-shirt just by posting something cool in the Slack channel. So this week our winner is Disown. That is the handle in Slack. Actually, the gentleman's name is Matt. I won't say Matt's last name because I didn't clear that with him first.
But he posted this week about the Windows DNS vulnerability that was just announced this week, which is potentially wormable among other things. It seems like it's pretty bad. But also, it seems like a trend lately of all of a sudden we've got a bunch of CVSS 10 vulnerabilities that are getting dropped, whether it's Palo Alto or Windows or F5, lots of bad stuff going on out there. So anyway, congratulations to, to Matt. We will be reaching out to you so that you can work with Andre to get your free stuff from the Colorado Equal Security Store.
All right, with that, let's jump over to events. We've got a few virtual events that are coming up. The first one of those, ACES Denver is hosting a Women in Security Coffee Chat with Dawn Gregory on July 21st. On the 22nd, OWASP Denver Boulder is having their virtual July meeting. Also on the 22nd, ISC² Pikes Peak is doing their July chapter meeting.
The next day on the 23rd, the Colorado Springs ISSA is having their July online series. Also on the 23rd, IronCore Labs is doing a webinar, Why SaaS Businesses Are Turning to Customer-Managed Keys. DC303 has their July meeting on the 24th. And then our last event in the next 2 weeks, Emerging Tech Fan, which I believe Jason Jaques is behind that, is doing an event called the Intelligence Explosion Hypothesis on the 28th. I have no idea what that is, but it sure sounds interesting, so you better check that out.
Yes, it does. If you want to see more information about that or anything else, go to the website. Colorado-security.com. There is a combined event calendar there, or you can check out the show notes as well. All right, with that, let's jump over to jobs.
We've got some pretty cool jobs this week. First, the Land Title Guarantee Company is hiring a security and compliance analyst. VMware Carbon Black is hiring a threat analyst too. FireEye is looking for a staff reverse engineer. Presidio is hiring a cybersecurity solutions architect.
Newspire, which I'm sure is the former GBProtect here, is looking for a security operations center analyst. Dark Owl is looking for a development security operations engineer for their DevSecOps team. Pretty cool. Fastly is looking for a technology compliance manager. Bank of America is looking for an information security exposure management specialist.
That's an interesting specialization. Yes. Charles Schwab is looking for a senior security engineer. And Azure Software is looking for a DevSecOps engineer. Pretty cool.
So that takes us to the end of the newscast. We do not have an interview this week, so this is all you're going to hear from us. Brian, thanks. Appreciate your time. Thanks for having me, Alex.
Good seeing you and good talking to you. Same here. All right. This has been Colorado Equal Security, and we will talk to you next time. See you later.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.