All episodes

Newscast

Apple Podcasts Spotify SoundCloud

News from: McSquares, Pax8, UM Systems, Ping Identity, Coalfire, Webroot, Optiv, and a lot more!

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript4978 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 173 for the week of July 27th, 2020. Alex, uh, can you believe July's almost over now?

Oh man, this, uh, for the— this being the longest year ever, it is actually starting to fly by. Yeah, we're, uh, I think we're now what, oh, 4, but just about 4 months, actually like 4 and a half months into this whole, uh, COVID stuff in, in Denver, right? Something like that, mid-March. Yeah, it was, uh, the 13th, I believe, is when they told everybody to go home. Friday the 13th, got sent home.

Yep. Yeah, fun stuff. Um, you know, I am feeling good though, Robb, because things seem back to normal since you're back this week. I know, it's— this is exactly the way it should be. Uh, we're back and we're ready to educate you on all of the things going on here in Colorado.

Um, and that is a lot. There's a very lot going on. Before we dive into that, we'll want to remind you about some, some facts here for the, the podcast. Number one, uh, you know, we are part of a much larger thing than just a podcast. We're also a Slack community.

We get together with people in person occasionally. If you want to learn more about about it, go out to colorado-security.com and you can see more about the movement to help amplify the cool stuff going on in security in the world. And while you're there, click on the join Slack button there and that'll get you into our Slack community with about 1,500 of our closest friends here in Colorado security. You can also sign up for our mailing list while you're there. The mailing list will get you one email every week, exactly one, And it will have the show notes once the podcast that week is released.

And that is it. That's all you get. But we would love you to have it. You know, if you want a little bit of insight into my psyche that makes no sense, you know, we get people joining the mailing list on a fairly regular basis, and I get almost no joy from that. But I— it hurts.

It hurts so bad when someone unsubscribes. Yeah, don't leave. We don't care if you join, but don't leave. So if you want to mess with my day, Go get people to unsubscribe from the mailing list. And all of those emails are like a little dagger.

But if you want to help us, we would love it if you would rate us and subscribe to the podcast so this is in your inbox every week. We, of course, we love it. It helps us find new people if you guys do rate us and give us nice reviews on your favorite podcast listening application. Yeah, you can also just tell a friend. Let them know how great Colorado Equal Security is, the podcast, the Slack channel, the website, the event calendar, all of it.

Tell them, have them join up and be a part of the crew. The witty banter. Yes. Of course, if you want to help us more, there's a couple more things you could do. You could help sponsor us financially.

We have a Patreon to help pay for the costs of the podcast and the website and all that. You can get the details on that on our website. We'd also love it if you'd help us do interviews. You know, we frequently will do these newscasts along with a feature interview. You know, during COVID it's been tough for us to get those.

But we'd love it if you have someone you want to talk to and you want to interview for us, reach out to us and we'll help you figure out how to do that so we can move that forward. Yeah, I think even if you know somebody that you want to have interviewed, even if that's yourself, I suppose, let us know as well. Sounds good. Our first thing this week is not necessarily news. It's more of a kind of an announcement.

I was talking to Tyler Warren over from the Cloud Security Alliance here in town, and they're doing a couple of cool things. Number one, they have their call for papers open for the Fall Summit. So the, you know, one of the big conferences here in town every year is the CSA's Fall Summit. I assume they're going to be moving virtual. I don't know if all the details are out there yet, but regardless, the CFP is open, and if you guys are interested in talking to a really good group of cloud security folks, that would be an opportunity for you to get involved.

Yeah, and then they're also going to be doing their CCSK training. I believe it said when it was posted on Slack that this was going to be an in-person training. I'm not 100% sure on that. Anything in person these days seems sort of weird. Not sure about that, but the point there is that they're offering scholarships to just graduated students who are interested to come and take that CCSK training.

Yeah, they're looking to do that. It's— they're giving away 2 different vouchers for this. They're also going to be— so not only would you get the in-person training, you also get a voucher to take the test itself. It's worth about $2,000 for the scholarship. Folks who are eligible, you have to be a resident of Colorado, you have to be a current student or a recent graduate from a security program.

So that's all we're looking for. Yeah, but, you know, cloud is a hot topic, so definitely something you should check out. All right, let's jump into the actual news. You know, it feels like we've been doing this long enough now, Alex, that this is kind of a recurring theme. We have this year's version of the CBRE ratings of top tech cities, and Denver has once again moved up the list.

Yeah. So, congrats to Denver. We are— last year, we were number 8. This year, we are number 7. So, that's pretty exciting.

Passed right by Boston. Boston's— we did pass by Boston. So, screw you, Beantown. We're better. But yeah, so, they look at lots of things.

You know, CBRE is a real estate management company. So, I think that they're using some of that data as part of this, but also, you know, people who, um, who have degrees and the amount of new tech jobs versus people with degrees that, that came and, you know, other things like that. Um, you know, all in all, it's a good bit of criteria that they use for this. So, uh, good to see that we keep climbing up the list. Uh, they had a little note at the bottom of the article that in addition to this, uh, top tech list, there's also an up-and-coming city, um, which is, you know, those cities that are growing in tech world.

And Colorado Springs made that list at number 4. So, they are, you know, 2 Colorado cities looking really good on these lists. Yeah, you know, one of the things that I also noticed, I'm trying to find the exact number in here. But it was talking about the cost of running a tech company in each market. And it is more expensive to run a tech company in Denver than San Diego, or Los Angeles.

Yeah, it was like, that was kind of crazy. Yeah. And it really wasn't as much cheaper than San Francisco as I would have guessed either. I think, yeah, I mean, not a whole lot. I think, you know, San Francisco, not surprisingly, is number 1 at $62 million.

But Denver was $48.3 million. So yeah, super far. What is it? 20%? 20% less?

Yeah. And that includes salaries. So it's not like that's, it's not like that's, you know, out of the picture. Anyway, interesting stuff there. Definitely.

Next story. So we talked, I think, about this competition or, or something similar to it. Maybe that they were going to be doing this, but there is a competition where rural startups are competing for some venture funds in Colorado. So yeah. So yeah, I'm sorry, I didn't mean to cut you off there.

We are doing it remote today. So there might be a little bit of that. What?

The Greater Colorado Venture Fund is investing at least $250,000 into some of these finalists. And they have— they've come down to 7 finalists where they started with over 100 companies. These companies are coming from anywhere in Colorado except for the Front Range urban corridor. So you can't be from Fort Collins, Denver, Boulder, Colorado Springs, basically. Right.

So we have a lot of companies coming from kind of interesting, kind of random-ish places. Yeah, um, so we have, uh, Glade Optics from Breckenridge. We have Hacker Noon from Edwards, which is— that's not our kind of hacker. Not, not— yeah, not our kind of hacker. Um, we have Nomad Reservations, uh, from Buffalo, Wyoming, um, which I guess they're close enough that they're— they're— I think they said they're moving.

They're moving to Colorado, I think, was this. Okay. Um, Product Movement Company from Grand Junction, Quicker Stuff from Grand Junction, Tankmates from Pueblo, and the reason that we have this article in here, Cyber Privacy from Pueblo. And cybersecurity for smart homes. I was poking around on their website trying to figure out exactly what they do.

It looks like they're pretty small right now, but basically they're trying to help secure your smart home. So, all of, you know, your smart thermostats and lights and all that stuff. Helping people come up with a solution for that. Yeah, it looks like maybe they have some, you know, home router security gateway kind of things potentially. That's kind of what I got from the website, but I think the website needs a little more info.

But, but yeah, I think, you know, as we talked before this, it'd be interesting to get to talk to those folks and figure out what exactly they're doing. Yeah, we'd love to have them on the show. If anyone knows someone from that organization, have them reach out to us. That'd be fun. Yep.

Next, we have kind of a similar startup in town that's had a real big breakthrough. So it's a company called MC Squares. It's written McSquares, but it's called MC Squares. They were on Shark Tank back in May. And what they do, really interesting that this company's taking off right now.

It doesn't seem like something that would have been great in the pandemic, but they offer a line of eco-friendly reusable sticky notes, dry erase tiles, and desktop whiteboards. And they're moving from their previous office in downtown Market Street, Market Street in downtown Denver, to Thornton Parkway, where they're going to take 25,000 square feet of what was previously a Hobby Lobby. Yeah, so they're, they're going to be moving to a space that's basically 4 times bigger than what they were previously, which is awesome. I had actually heard an interview with the founder on one of the other podcast, Colorado podcasts that I listened to. And I thought it was interesting because they do most of their production here in Colorado, as opposed to, you think most production happens in China or Vietnam or wherever else things get produced these days.

But they felt like they had an advantage doing things here because there was a quicker cycle time. If something was happening or went wrong, they could easily pivot and change the production pieces. So they're gonna use that new space for more production. Yeah, it sounds like they're saying basically at least until they get the first like $20 million in revenue, they're planning to stay local. So hopefully, you know, that new space will give them the ability to go faster and better and keep growing and bring another fun company here to town.

Oh, I do wanna say they have 14 employees currently and they're planning to hire 10 to 20 more here in the next year. Awesome. Yeah, I think that what they make is cool too. So, you know, if you've ever been part of an agile team, You know, you've probably been in a physical room where there's a whole bunch of sticky notes all over a wall that you're moving for, for, you know, different development cycles and things like that. So they're basically making things that you can use instead of that, that, that are reusable instead of all those sticky notes.

So pretty cool. Awesome. Well, we have yet another company here in town that's growing. And we've talked about Pax8 a couple times on here before. But we do have an update from them.

You know, we talked about that they got a grant to do some rural hiring here in Colorado. And when COVID pushed everyone remote, it looked like that might have been at risk, but no, they are moving forward. And actually, they have their first hire coming up here in 2 weeks. Yeah. So they are continuing to move forward with that.

I think the focus of this story was mostly on the fact that they did take some PPP loans as part of the pandemic response to help them keep their current employees and then allow them to continue to move forward with the plans that they had to hire new employees. One of the things we had had a story when they, they got the, those grants before, but I don't know if I remembered the fact that, that the, this is the largest employee addition that the, the Economic Development Committee has done in 11 years. So that's pretty cool. So they're really trying to hire like over 1,000 employees here in Colorado, especially considering the fact that they're coming from currently at 400 employees. It's just massive growth.

And really cool to see. I love a tech company that's able to kind of find their niche helping people find the right cloud services. Definitely. Next, there was a Colorado company called UM Systems that is doing a Kickstarter and they've raised over $1.5 million for a UV filter mask. As we all know, masks are super important right now.

So for those of you who are mostly just like listening but not paying attention, this is actually pretty cool. You should go click the link, check out their Kickstarter. So they're almost at $2 million. By the time you listen to this, I bet they will be at 2. That was like 1.9-something when I looked a little bit ago.

They got this mask that it combines the filter system of like an N95 mask respirator with this new technology they've created that uses ultraviolet light to sanitize the air. Basically, what they're saying is, and they've had third-party tests, they have ISO testing, all the good stuff, they're saying that they have raised the level of efficiency to 99.99%, so 4 nines, in their ability to kill to kill the viruses like, like the COVID Sorry, Robb, I don't do anything unless it's 5 nines. Yeah, 5 nines, please. 5 nines, that's it. Baseline.

Or 9 fives. Well, you know, maybe 10 fives. And if you're thinking to yourself, well, but I could never afford something like this, I have good news for you. Yeah, it's only 2 nines. Exactly right.

$99 for Kickstarter backers. I would imagine once this moves beyond Kickstarter and they start selling these retail, it would be a lot more than $99. Well, they Kickstarter says it's gonna be $200. So I think it was like just a little bit more, like $240 or something per mask. So if you want to go out there and get, get one for $99, you can get 2, I think it was, it was like $190.

So a little bit of a discount even further on that. They look pretty cool. And it comes with, if you do it through Kickstarter, you actually get 10 replaceable filters. And you get the USB charging cable for the batteries that power the UV light. Yeah, it's pretty cool.

Seems like a pretty good deal. I think everybody should go up and sign up for one. All right, let's go ahead and move over into the security news. You know, I think we should talk about APIs. What is an API, Alex?

An autonomous ping pong interface? See, you should read this article here. It's on the Ping Identity blog, and it's basically titled, What is API Security? I was expecting I was expecting this to be one of those marketing blogs that's, you know, 300 words and, you know, it talks about the ABCs. 300 words, Robb.

This is like 3,000 words and it's written by a highly technical person who will basically teach you everything you need to know about API security. Uh, this blog was 5 nines. There were a lot, a lot of words in there. It was very good though. Long article, but lots of good information in there talking about APIs and API security and Seriously, just about everything you can think of around API security.

Yeah, I'm going to make everyone on my team read it because I know that not enough of them understand API security and we need to get everyone more comfortable with it. And I think it's worth reading. Even, even you, Alex, could read this and learn a couple things. There might be one or two things in here you don't know. So, so are you saying that I didn't fully read it for this podcast?

I'm not suggesting that. I'm, I'm claiming it though. Yeah.

But, but, but, you know, the funny thing is APIs are such a trend that this is not all the API news we have this week. That's right. Our next article from Optiv is about their new REST API Goat. So, you know, you can have that and throw it in your backyard and it'll eat tin cans and mow your grass. It's— I think it's, it's taking the name or kind of a next iteration of WebGoat.

And anyone who's not familiar with WebGoat, it's a, it's a really easy to set up website that is very vulnerable. So as you're trying to do, like, learn about security— how do I attack a website, how do I secure a website— WebGoat's a really nice resource for that. So they've created one of those for APIs, so you can look at what an insecure API looks like. Yeah, so you could provide this to your developers, you know, they can play around with it, see all the bad things that they already know how to do, and then, you know, hopefully make better choices. Yeah, I think this is cool.

You know, it's awesome when someone creates this kind of free resource for the community, makes us all better. Good, good on Optiv for doing this. Yeah. Next, we have a Coalfire blog. This is not one of the, you know, more technical Coalfire blogs that we've seen, but it's about Privacy Shield and the fact that it doesn't exist anymore.

Yeah. It's cool when one of the local companies talks about big national or global news like this, so it gives us a chance to talk about it on the show. Coalfire does a really nice job basically summarizing what happened. So a big European court struck down Privacy Shield in the same way they struck down Safe Harbor— what was that? 4 years ago, 5 years ago.

And unfortunately, there's no grace period here. They struck it down, what was it, the 16th, and it was invalidated as of then. So all the companies who had been depending on Safe Harbor are now scrambling to quickly figure out what they can put in place to take the place of that. Yeah, and it's a bit of a mess, I'll say. So the problem is that there's not many great avenues right now to replace Privacy Shield.

There are still The possibility of using standard contractual clauses in your contracts. But even then, it's not— you can't just throw a clause in there and expect it to work. The DPAs are going to be a little more stringent on that. Make sure you're actually doing the things that you say you do. You know, there's other methods, binding corporate rules.

But, you know, even then, I think that's even a little harder to get because you have to go to each DPA. In each EU member to make sure that you can do that. So, you know, Privacy Shield was sort of the easy button, and there is no easy button anymore. Yeah, and I know most companies were doing Privacy Shield as a stopgap. I know that's what we had it in place, but then you're also putting standard contractual clauses in place so that, you know, in the event of something like this happening, you have something.

And fortunately, you know, at least for now, standard contractual clauses look okay. We still have the ability to transfer data under that. Yeah, I think this is going to be a still-developing story to figure out what comes next. All right, so, you know, on a weekly basis, I think it is, Webroot does a kind of rundown of interesting security news, and this week's was interesting to me because they highlight that one of the big ATM manufacturers, Diebold Nixdorf, has identified that there is a successful campaign going out there in the world where folks are able to get access to the ATM and they can jackpot it. They can make a lot of money quickly.

Yeah, so for those that don't know, jackpotting an ATM, essentially you can— it used to be there were some hacks where you could do this. I think for this particular attack, they were sort of replacing the firmware, but basically it just starts spitting out money like a jackpot, you know, if it was a slot machine as opposed to an ATM. It's a great day for one person and a really bad day for somebody else. Exactly. No one wants to be on the, the wrong end of an ATM jackpot.

Um, moving on to our final story this week, um, this is, uh, from the Cyber Advisor blog over at Ballard Spahr and talking about, uh, a GLBA safeguards rule workshop that the FTC held. So, uh, for those, uh, that don't know, the Gramm-Leach-Bliley Act is, you know, one of those regulations that out there— is out there for financial institutions talking about security that they need to put in place in order to protect the information of the folks that they work with. And so this gave a little bit more background on the things that the FTC is thinking about in terms of proposed amendments to the GLB Safeguards Rule. Yeah, I don't know that we've ever talked about this. We haven't had that all-important conversation yet where I would tell you that my very favorite security standard is GLBA's safeguard rule.

And the reason is I think that it's written in such a way that if you do what it says, you're actually gonna build a pretty good security program, unlike, you know, kind of arbitrary requirements from a lot of them. I'm not saying it's perfect, but I think it's a whole lot better than most. And it looks like the recommendations here are not gonna step on that too much. You know, there are— they're not hard and fast requirements that you must, you know, you must have MFA on every login. It— but they do have requirements that if you're not going to do MFA, then you're going to have to have compensating controls, and those will have to be reviewed and officially approved.

Yeah.

I think that it is— that these things would move it slightly in the direction that you're not fond of, you know, being a little bit more prescriptive. But, you know, I think for the most part, they are good things, and I think will help shore up the safeguards rule, which hasn't really changed in a long time. 2003, that was a kind of a surprise to me how long it's been unchanged completely. Yeah, and I think to your point, if you do the things in the safeguards rule, then you'll be— you could be good and have a good program if you take it seriously. You could also do those things in sort of a, you know, half-ass or, you know, less than perfect way, and you might be able to meet the requirements and still not have a great security program.

And Alex will never go half-assed. He's always full-assed. Yes, I will not make a joke. Never go— you never go full-ass.

All right, well, that was the news. Slack message of the week, that's our— that's our next thing we're gonna talk about, right? We got to thank Andre Gaeta. Andre has been sponsoring this for us for forever now, and as a result of that, we get to recognize one person who contributes to the Colorado Security Slack channel and makes conversation there better. And that person gets to pick one item from the Colorado Equal Security store, a shirt, a bumper sticker, a tattoo, whatever it is you like.

It could be a mask. We have masks in the store now. And this week's winner, we already actually talked about this, but not specific to the Slack message of the week, but it's Tyler Warren. This is for posting about the CSA's CCSK scholarship. And all the stuff that they're doing over there.

So congratulations to Tyler. I love to be able to recognize the volunteers in the community. I know Tyler's not getting paid for doing CSA, but he puts in a lot of his own time and helps build that community. So definitely appreciate that, and we're glad we can recognize him in some small way here. All right, so we'll get him hooked up with Andre and he'll get his free stuff, and we'll now talk about the upcoming events.

All right, there's just 2 things coming up in the next couple weeks. It looks like, you know, probably because Black Hat's starting, maybe because people People are on vacations, not, not as much as normal going on. But we do on the 28th, we have an event by Emerging Tech Fan, the Intelligence Explosion Hypothesis. Yes, very exciting. And then on the 6th of August, the Colorado Springs ISSA is doing their first session in their August online series.

All right, and then we'll jump over into jobs. We have some good jobs this week. LogistiCare is hiring a Chief Information Security Officer. Yeah, I'm very curious about this job because it has been out there for a long time now. I think it seems to go up and then go away and go up again.

So don't know much about it, but people should check it out if they're interested. SugarCRM is looking for a Director of IT Security and Compliance. I'm trying to figure out how to say this one. Entirety, it's Entirety, is hiring a Risk Governance and Compliance Manager. It's like they wanted to switch the GRC wording around just to, just to mess with my head there.

Ball Aerospace is looking for a Cybersecurity Professional Associate. AWS is hiring a Program Security Officer here in Colorado. Oh, that sounds exciting. Western Governors University is looking for a Program Chair for their cybersecurity program. Yeah, isn't that interesting?

Yeah, that's pretty cool. I assume you're also teaching in the classroom, but You would think, but who knows? I don't, that's for sure. Neither do I. Western Union is hiring an identity and access management governance and compliance leader.

T-Tech, formerly TeleTech, is looking for a cloud/systems engineering architect for remote telecommute. I don't know if that is what you're trying to secure or how you can do it. I think that that's how you can do it. I think they're saying basically don't worry about having to come into the office. And then finally, Carbonite is hiring an advanced threat research analyst.

I was interested in this because, you know, Carbonite is the company that bought— well, they bought Webroot, and it doesn't say Webroot, so I'm guessing that this is not a Webroot role. I think that this is probably with them directly. That's pretty cool too. And you know what, Robb? That's it.

That's it. We made it. Well, congratulations, Alex, on making it through yet another successful podcast. You too, Robb. This has been great.

I'm glad we could do this. All right, we'll talk to you again soon. All right, thanks, Robb. Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember Remember, Colorado equals security.

Back to all episodes