All episodes

Newscast

Apple Podcasts Spotify SoundCloud

News from: mcSquares, Prieto Battery, Boa Technologies, Coalfire, LogRhythm, Intelisecure, Red Canary, Swimlane and a lot more!

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript4806 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 182 for the week of September 28th, 2020. Alex, how you doing?

I'm well. How are you, Robb? Doing fantastic. A little bit smoky this weekend. It is a little bit smoky, and I think wind shift a little bit.

And yeah, it's, uh, it's been killing me. The itchy eyes and throat. Yeah, all that stuff. No fun. It's gross.

Uh, we are almost 3 quarters of the way through the year though. It's hard to believe. Where's this year gone, Robb? So 6+ months of, uh, all the COVID craziness, and we're still around, so that's good. Yeah, so, you know, almost end of Q3.

We gotta close all our Uh, Q3 Colorado equals security deals, right? A lot of deals for us to, to get across the line, right? All right, uh, some housekeeping. We have a Slack channel, uh, over, over 1,600 people in there. You should join by going to colorado-security.com and clicking on the Slack button there.

That, that's a deal we closed, Robb. 1,600 people. Close that deal in quarter 3. Um, we also have a mailing list, Robb. You will get one email every week with the show notes from the previous week's podcast.

You can get that delivered right to your email. Go to Colorado equals secure Colorado dash security dot com. Scroll to the bottom. Put your email in. You'll be on the list.

And since you're already doing all of these clickings, why don't you go over to your favorite podcast listening app and rate us and subscribe there so people can find us? The more people who rate us and say not terrible things about us, the better. Do you think we'll ever get past things like click? Right. You know, most times you're not actually clicking anymore.

You're touching or you're, you know. Like dial a phone. No one dials a phone anymore. There's no dials. There's no dial.

Do you remember how annoying it was if your friend had like a 9 in their phone number and you had to wait? You had to wait for the thing to come all the way back from that. And like you weren't paying attention and maybe you went like 3 quarters of the way and like your finger slipped out of the hole and then it's like, I got to start over. Hang up. More minutes to call this number.

There's a lot of people listening who have no idea what we're talking about. Also, hey Robb, you could tell a friend about Colorado Equal Security, not necessarily about this you know, annoying banter that we're having, but how great things are. And if you think for some reason that this was worth paying for, we have a Patreon campaign. You could, you could help, uh, help subsidize the cost of this and, uh, kick in a little bit of money each month. We love our patrons.

Thanks to those who already do patronize us. Uh, go out to cardo-security.com to find the Patreon link. And then finally, if you would like to interview someone for the show, we do have a feature interview as part of most of these podcasts. Um, please let us know. We would love to have you interview someone.

Um, it gets harder and harder for us to get those interviews done. Uh, so if you want more interviews in your show, then you can help do the interviews. All right. And so last time, I think we're gonna talk about it. We do have a, um, we do have a pot or a salary survey that we're working on right now.

Um, so if you want to have data about the security positions here in Colorado, make sure you go out and fill out the survey because those who fill it out are the ones who are gonna get to have the data. There is another deal we're closing in Q3, Robb. Yeah. And now I bet that people are gonna expect, okay, this is the last time they're asking for new entries. I bet we'll get the results next week.

Probably not. Yeah, it's gonna take a little while to crunch all that data. You know what? We're gonna have to get some supercomputer time to, you know, have it run all the numbers and things like that, but it should be out pretty soon. Anyway, you know what?

We have some news to talk about. Robb, did you know that the city of Parker, Colorado is the number 2 best place to live in America? I did because I prepped for the show, but I didn't know before that. And I'm happily surprised. Parker doing pretty well there on the ratings.

Yeah, congratulations to Parker. This was on a list from Money Magazine.

The— they actually did not give a whole lot of detail on where Parker actually fell in the criteria. But they looked at things like employment, housing, economy, cost of living, diversity, health and safety, weather and lifestyle. Obviously, the weather here is usually pretty good and the lifestyle. So I think that those all help Parker get to number 2. So I'm, you know, I'm used to seeing Rochester, Minnesota be near the top of these lists, but I didn't recognize any of the top few here.

So number 1 was Evans, Georgia. Obviously, Parker number 2. Number 3 was Meridian, Idaho. So really some kind of dark horses coming in our 1, 2, 3 on this. Yeah.

Also, the city and county of Broomfield was ranked number 18 on the list. And if you want to be near Colorado but not in Colorado, Cheyenne, Wyoming was ranked 36th. Cheyenne's just kind of enjoying the glow from Colorado. That's right. A little, little spillover there.

All right. Our second story this week is that Colorado State— the state of Colorado, that is— has ordered workers to take unpaid furlough among this budget shortfall. Yeah, I think we all know that everyone is going to be hurting for budget. And I think we mentioned in a previous week the story about the state of Colorado and how it's not the worst-case scenario that they think is going to happen, but it's still pretty bad. So they are asking state workers to take furlough.

This is going to be based on how much money you make. So depending on your salary, you may have to take between 1 and 4 unpaid furlough days before the end of the year. Yeah, it was interesting because, you know, just last week we were talking about how we weren't going to have the worst-case scenario. And I guess, you know, even with this not worst-case scenario, it's pretty, you know, there's an impact. I, you know, one unpaid day off a year doesn't sound terrible.

Maybe 4, you know, it starts to be a little more painful. They say that this is going to save the state about $8 million, which doesn't seem like that much to me. Like, I mean, I guess every penny counts, right? Yeah. The— I think a lot of people in, in private industry have had to take pay cuts or have been furloughed 4 times or, you know, working part-time, other things like that.

So I guess it just— it doesn't surprise me that the state workers are also going to have to go through something like that. All right. Next story, we actually are doing a follow-up on one we talked about on our episode 173 on June 27th. MC Squares was a local company that was on Shark Tank. And we announced at the time that they had made a deal And there's an update to that deal.

Yeah. So in that deal, they had made one with what's his name? Mr. Wonderful? O'Leary?

Yes. I was trying to think of what his actual first name is. But based on that deal and when from the time making the deal to when it closed, they actually changed the deal structure a little bit. A little less investment from him and a little less equity. Yeah.

Apparently, at least the tone of this story is it's because they have done so well since making the deal. Right. That they have— they've been able to take less equity. So interestingly enough, we talked about it in June, or July rather, but the episode was recorded in June of 2019. So it's almost a year later, in May of this year, when they actually aired the episode.

And by then, there's been a lot of changes. So rather than giving a quarter of the business up for $300,000, they actually sold 11% of the business for $50,000, which is Uh, not quite as much from a, uh, like a valuation perspective, but they were able to maintain, you know, much more of their company. Yeah. I've never really thought about that. I wonder how those deals actually work.

Right. Do they not close the deal until you, the show goes on? Because that's sort of, you know, like the big sort of reveal and the, the, you know, one of the big values that they have. Um, I mean, that again, this protects the shark that way too, because if you're going to go out of business in the next year, you, It'll take a while to— right. Yeah.

Yeah. But on the other hand, I suppose it protects the business as well. If you do really well between the year of filming and to when they do it, you're potentially going to get a better deal. So anyway, pretty cool in any case for MC Squares. Next, Hercules Electric Vehicles and Prado Battery have announced a strategic partnership for making electric pickup trucks.

So I think we just put this one in because I had no idea that one of the the best, most innovative battery companies in the country is actually in Fort Collins. Dr. Prado is up there and she created this company. And basically they're, they're going to be helping get those batteries for the new electric trucks from Hercules, but not till 2025. That said, I didn't really know Hercules electric trucks. And so I did a little bit of looking around and they look pretty cool.

Yeah, they do look pretty cool. Also, I don't think it's 2025 when I think you're supposed to get the production company or production vehicles, but they're, I think as early as 2022, they're actually gonna be starting to make some of those vehicles. So the Hercules Alpha truck is going to be available next year. And I was checking a look on their website. If you go to Hercules, I can't remember the name of the website, but if you just look for Hercules electric vehicles, you'll find it.

I pulled out some stats about this new truck. It's gonna have 1,000 horsepower, but 300+ miles of range, 0 to 60 in 4 seconds, top speed 120 miles an hour, and it can tow 12,500 pounds. That will be awesome. I'll be able to tow my trailer at 120 miles an hour. That'll be sweet.

Camping will go so much faster. I can't see any downside to this, Alex. I suspect if you're towing at 120 miles an hour with a $12,000— a 12,000-pound truck, you probably can't make the 300-mile range. Yeah, that's probably true. There's probably some trade-offs here.

3-mile range. That's a 3-mile range there. Uh, now pretty cool though. Um, you know, both being electric vehicle owners, it's cool to see more and more companies coming out with electrical vehicles. Yeah.

Uh, there— this next one is another local company that, you know, I think we include these stories because it's interesting to know what the general company climate is in town. And another company has sold. Now this one's interesting. This is a— it's, it's called BOA Boa Technology, where they make— they say they make sports and fitness equipment, but what they really make are these like ratcheting dial-based shoe fasteners, which are used like for skiing and other things. And they sold this company that just makes those little ratcheting things for $454 million.

That's a pretty cool deal, Robb. I'm sure if you've ever snowboarded before, you probably have come into contact with one of these dials. Most— I don't wanna say most— many of the snowboard boots that are out there have the ratcheting dial system to lace them up. So I can see where there's a pretty big market for that. And so that Denver-based company, now they will not— I assume they won't be a Denver-based company anymore.

But, uh, anyway, good for those guys. And we love to see success here. It did actually say in the article that their headquarters will stay in Denver. If I had only read. If you had only read, Robb.

All right. Uh, next we have a, an article from Coalfire, uh, titled Offensive Security Testing Using Cloud Tools. So Rick Osgood was our, uh, was the writer of this. And really what interesting what he talks about is, you know, as a tester, A lot of times when you start doing your probing and, you know, analysis, you'll get your IP address blocked. And, and, you know, while that, that might seem like a good security control, actual bad guys will definitely figure out how to get around the IP address being blocked.

So he's looking for a nice way to automatically get around that type of a control and generate new IP addresses so he doesn't have to go through the pain of, you know, spinning up new instances. And that's what this blog post is about. It's basically looking for that way around that control. Yeah. And so he talks through, uh, some methods that are out there already, some existing tools.

And then, uh, sort of the second half of the article, uh, talks about, uh, him building a new tool, uh, I think called LamScan, um, that does exactly this. It uses AWS Lambda and some other things to, uh, sort of rotate those ports so that you can get around, uh, IP blacklisting. LamProxy is the name of the tool he made. And then LamScan is somehow related as well. Anyway, really cool stuff.

If you're an offensive security person and you're looking for a way to, to try and circumvent those controls, this is a good thing to look at. If you're a bad guy, please don't read this blog post. Yeah, leave it alone. All right, uh, next, LogRhythm had a blog post about the new Cyber Maturity Model certification for the DoD. Yeah, this is a follow-up to one they had done previously.

Um, their previous one was, hey, if you're a DoD contractor, you better learn what this CMMC thing is all about. It's going to be a certification that the DOD requires from you. And this is a follow-up to kind of understand what are the certifying bodies looking to expect from contractors. I was interested in this, and the reason we put this in this week is because I have heard rumor that this is going to be expected from a lot more than just DOD contractors, and folks who want to provide services to government entities can expect that this is going to be kind of a a measuring stick that's used for them. And for any company that wants to have a, you know, a DoD quality security control, this, this looks like the right thing to do.

It does. It is built on the, um, the NIST Cybersecurity Framework, and it's really a maturity measurement for your program across all the elements. Yeah. Um, I will say also in this article they talk about some of the, I guess, bumps in the road that have happened as part of the implementation of this. The, the way that they've implemented, there's an outside certifying body that the DOD is dealing with.

And there have been a couple bumps there. But I have heard recently, and I believe that they talked about in the article that they are starting to work through the certification process, people are actually testing to be testers. And so that's— Coalfire is one of those, right? I believe Coalfire is one of those. Yeah.

And also, Uh, they're talking about in the article how the, uh, the requisition process for the DOD needs to get updated so that they can officially include CMMC as a criteria for contracts. And that's expected to happen in November. Good stuff. All right. Next article we have is from InteliSecure.

Um, they have a blog post this week about Microsoft 365's endpoint DLP. Um, so, you know, InteliSecure is the local DLP company. They do a little managed security provider, but they all, they started with DLP and they're looking at the new Microsoft tool. Interesting. I knew that Microsoft had some controls there.

I didn't know there was a new DLP tool from Microsoft. Yeah, it was kind of cool. This, I didn't realize this was coming either. So now as part of Defender on the endpoints and the new Edge browser, you can use Microsoft tools to put DLP into those processes through through Defender and, uh, and Edge. Pretty cool.

Yeah, it's pretty cool stuff. So the blog post is actually titled, uh, Is It Ready for the Enterprise? So the actual intention of this blog post is to, to kind of look through and see, figure out, could you use this within your company? Looks like the answer is almost mostly, you know, mostly you can. Um, there is a couple of gaps, and, and one of the biggest gaps that really relevant for me is it's just for Windows, right?

You can't use it on Mac or Linux. And so if, if you have a significant number of non-Windows devices in your, in your environment, that's not going to work for you. But considering the fact that they have, um, you know, they've, they've put Microsoft Defender on, on Mac recently, um, I expect that this will probably come there when they can as well. Yeah. Um, I also thought it was interesting that the, uh, the controls that they're talking about here are a little bit siloed.

So they work in Edge and through Defender. But, uh, if you want those controls to also happen in Outlook, you know, through email, then that's a different place. You have to do the Office 365 DLP for email. So it's still a little bit kludgy, but I think you can definitely get it done. Yeah, good stuff.

Our next blog is from Red Canary, where they did another one of their really nice walkthroughs from a technical perspective. This one's called Nothing to Hide: Seeking Out Rootkits on Enterprise Systems. Yeah, occasionally they do an article that's sort of this style where it's, I don't know if I wanna call it a summary, but they they have a premise and then they have, uh, you know, several videos or other presentations that they use and embedded in the article to sort of, uh, go through that, that premise and, and get some more details on it. So this has a number of different videos from Red Canary folks and, uh, Atomic Red Team folks talking about what are rootkits, uh, how do they work, the different kinds, things like that. So lots of good detail in there.

Yeah. If you don't wanna read it too much, you don't have to read too much on this one cuz this one is, is mostly embedded videos. Kind of along the way, you know, define— start off by defining what is a rootkit, uh, talk about why they're useful to adversaries. There's like a 5-minute video there. So as you go, you get to learn different elements of rootkits and, and how to defend and protect against them.

And our final story of the week is from Swimlane, uh, talking about key takeaways from Gartner's 2020 market guide for SOAR. So Swimlane, who number one, uh, most importantly was kind enough to pay for the Colorado Equal Security stickers that we that we've been able to give away. We appreciate that, Cody and team. Um, but they, they do, uh, I love the content here because, you know, SOAR is still one of those areas that, um, it's conceptually perfect, you know, just amazing that we can get efficiency from our people. And in reality, the question is, okay, where can you do it?

How hard is it to get to accomplish? Is, does it actually balance out and can you be successful? Uh, and a lot of those questions are addressed here in this article. Yeah. And, uh, I think it's also, Always interesting to hear from Gartner on things like this.

Um, I, you know, I don't know that I officially or I, uh, 100% take their guidance as, uh, as gospel, but it is always good to hear what they're talking about. And, you know, they, they talk about several different areas in the, uh, the market guide itself. There is not a magic quadrant yet for SaaS, so just a market guide. Um, but just, you know, how people are implementing it, uh, why they're implementing it, Uh, things like that. Yeah, good stuff.

You know, how is SOAR being used right now? It's mostly being used for incident response and the workflow automation and orchestration of workflows. Um, you know, kind of details like that, like where, where do they actually see these things being used versus kind of the promise that a vendor might tell you? Yep, pretty cool. All right, uh, that is it for the news.

Let's move over to the Slack Message of the Week. Thanks again to Andre Gaeta for sponsoring the Slack Message of the Week. He has been doing that since its inception, and we really appreciate his support in that area. This week's winner will get to pick one item from the Colorado Equal Security Store, and that winner is Flip. Flip posted an interesting link to a story about universities in the day of COVID are requiring many of their students to install like monitoring software on their device that can see like where their eyes are looking or, you know, what's going on in the room around them, basically to try and circumvent cheating or to stop people from cheating.

These are super obviously privacy-invasive technologies, and as there's been pushback from students around this monitoring software, really interesting— interesting is probably not a good word— really what looks like bad behavior on the part of these monitoring companies who see someone post on Twitter about their technology and then ban that person's IP address from being able to get into the system. So if you're university requires that you install this software and you criticize it, and now the software vendor stops you from getting access to it. Well, you're in big trouble from your university, right? Yeah. Uh, it's, it's an interesting line.

I mean, how do universities deal with that too? Right. They're, they're paying someone for the software, but their users can't use the software. Well, obviously that's not gonna last for very long. Yeah.

That's a problem that's gonna have to get fixed. Uh, I, you know, I, you know, I'm a, I'm a pretty big privacy advocate. I also am a pretty big advocate of students not being able to just randomly cheat as much as they want to. Like, it doesn't do a lot of good for the value of university degrees. And obviously, I want people to come out of with those degrees actually having learned something as well.

It's definitely challenging. It'd be better to find another way to do this, but I don't know what that way is. Yeah, I don't know either. I mean, I'm sure the professors out there can tell us where, you know, maybe you can develop tests that, you know, like, I think SANS exams, for example, right? At some point they became, you know, open book, or at least open, you know, their books and notes, right?

And just the fact that there's enough, enough stuff to go through, enough material to go through, that even if you're trying to cheat, yeah, you know, you necessarily, you can't necessarily do it based on the time you have and the stuff that you have to get in there. But if I had like 5 people around the computer with me to help me answer questions. Like, it's just, it's challenging, right? There, there's definitely gonna be elements of this that, that you need some kind, man, I don't know how, I don't know how you do it without some kind of technology just to stop, you know, the 4 of us from teaming up to, to take a test. Anyway, good stuff.

Congratulations to Flip. We'll, you'll get your, uh, your prize as soon as you pick it. All right, moving over to our event calendar. We do have a calendar of events. It's a little bit light over the next couple weeks.

We just have 4 events, 2 each week, I believe. First this week, the NCC is doing a webinar, webinar on election interference and data breaches on the 1st of October. On the 3rd, ISACA Denver is doing their Community Day. We talked about this last week. Basically, they're going to a park in Denver and helping remove some flowers, I believe.

On the 8th, ISSA Colorado Springs is doing their October online series. I actually want to go back to the last one for just a sec. That's in person. You get to see actual people. If you go to this— an in-person event, Robb, that's weird.

You could go see people. So that's pretty good. Final event is on the 8th, and that's the Northern Colorado ISSA doing their October chapter meeting. Good stuff. All right, let's move over to jobs.

Robb, do you have any jobs this week? Nothing at Ping for me to hire. No. Yeah, me either. That's good.

Yeah, good stuff. We do. But we do have some interesting jobs to talk about. We do. Cognizant is looking for a senior manager of enterprise security operations.

It's Lunavi. I had— I did not know Lunavi, and in fact, I didn't know them so much that I'm like, oh, let's Google them, and they did not show up in any of my Google searches. Huh. But what I did figure out was that Lunavi was, until a week ago, was known as Greenhouse Data. So Greenhouse Data is a reseller of IT services here.

Don't they do some hosting or something too? Yeah, they do all kinds of stuff. Yeah. So those guys are hiring a manager of information security here in Colorado. Cool.

Western Union, who I know, is looking also for a manager of information security. IHS Markit is hiring a senior principal cloud security architect. Vail Resorts is looking for an InfoSec and privacy analyst. Visa is hiring a cybersecurity analyst focused on applied cryptography. I'm sure this person will be way smarter than me.

Yeah, I know that would look pretty cool. Red Canary is looking for a security analyst for cloud workload protection. And can be remote. And finally, IronNet Cybersecurity is hiring a Vice President of Worldwide Sales Operations. Yeah, IronNet.

I don't think that they are based locally. I looked at that when I put the job in here. But they're advertising it as, as being in Denver, although, you know, remote also. So pretty cool. Awesome.

Good stuff. Well, that is it for the news this week. We do not have an interview. We do not. So we— you are free to go about your day.

All of you listeners, you, you're done. You can go now. All right. We'll see you guys next week. Thanks, Robb.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado equals security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes