All episodes

Melissa Cooper and John Rosendahl @ Sovrn

Apple Podcasts Spotify SoundCloud

Melissa Cooper, Director, Privacy and Compliance at Sovrn Holdings, Inc. and John Rosendahl, Engineer at Sovrn Holdings, Inc. are our feature guest this week and are interviewed by Janelle Hsia. News from Whataburger, Frontier Airlines, The National Cybersecurity Center, Stack Hawk, Red Canary, Optiv, zvelo, Webroot, and a lot more!

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript10059 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 205 for the week of April 5th You may notice that this is Alex introducing the podcast this week instead of Robb, so that means that Robb is on vacation. So I have a guest co-host this week, Jay Wilson.

Welcome, Jay. Thank you. Nice to be here. Yeah, glad to have you. It's a beautiful day out.

We're outside. This is going to be fun. Yeah. I guess real quick, Jay, for people that don't know you, who are you, Jay? I am the CISO at Healthgrades.

I've also, you know, had the pleasure of knowing Alex and Robb for the last few years and actually did an interview for C=S, I think about a year and a half ago or so. Yeah, something like that. You've been on the show before. Yep. So not newbie to the show, and, you know, I think C=S is probably one of the strongest communities out there.

Really proud to be a part of it today. Awesome. Well, we're happy to have you. One of the other things that, that we've been doing together is the March Madness fantasy bracket through Colorado Equal Security, and both of us have been kicking ass. Yeah, yeah.

We're shooting for who's the biggest loser, right? Yeah, I mean, it's very possible that it will be me. We'll have to see. But I mean, you almost won that title for fantasy football last Why? We don't need to go like, you know, pointing fingers or anything here, Jay.

Um, but yeah, apparently my, my fantasy skills are not where they need to be. Um, I am from Ohio and I'm a Buckeyes fan, so I picked Ohio State to win the whole thing. I think if you've been paying any attention, they lost in the first round, so that's bad for anybody's bracket. Um, and I know, you know, you, you're do— we're doing at least a little bit better than me, Jay, but maybe not to Yeah, I mean, I just Christmas tree the entire bracket. At one point I was 4th place.

I am no longer 4th place. So I think that's fair. Yeah, totally fair. All right, well, let's jump into the news, but before we do that, we've got a couple of announcements. First, we have a Slack channel.

For those of you that aren't on there, you should be there. If you want to go to the website colorado-security.com, there's a link to get on the Slack channel from there. We've got almost 1,800 people in that Slack workspace, which is pretty incredible. We also have a mailing list. You can also find a link to that on the website.

Fill out your email in there and you will get one email from us every week letting you know the show notes from the podcast. We'd also love it if you would rate the podcast and subscribe. That way you get it delivered to you automatically every week and you let everyone know how great the podcast is. You could also tell a friend about how great Colorado Equal Security is and, you know, what great things were going on here. And get them to come and join us.

And finally, if you wanna support us financially, we have a Patreon campaign going on. So you can again find information there at colorado-security.com. We would love it if you signed up and supported us financially. It helps us cover the costs of everything that we do for Colorado Equal Security. All right, with that, let's jump into the news.

First, we've got an April Fool's story here. Uh, Jay, but, um, it's about Whataburger. You know, there's been all of this In-N-Out fervor in Colorado, but now, um, there is a story that maybe there's going to be a Whataburger in Colorado Springs. What do you think about that? Does that mean I can wait in line for 3 hours to get a Whataburger too?

Um, maybe even longer. Maybe even longer. Wow, that sounds amazing. Yeah, so, um, the story, you know, was talking about how Whataburger was coming all of these different places, and then someone in the comments said Well, but you're actually coming to Colorado Springs, which people apparently didn't know. And I guess that that part is actually true.

I know that there are some people that, that really like Whataburger. I've had a Whataburger. I think they're pretty good. But also like In-N-Out. I mean, it's a fast food hamburger.

I mean, if I were on the moon like the article was talking about, I think I'd be really excited about it. I'm not so sure I want to wait 3 hours or Whataburger here. Yeah, I mean, if you were, whenever the moon base gets set up, and like you heard the news that they were gonna bring a Whataburger to the moon, that would be big. Yeah, that would be good. But, you know, I could go get In-N-Out, I could go get Five Guys, I could go get, you know, whatever I want around here.

I can make a burger myself. You could make a burger, you know, it's nice out, you could just grill one up. Make a burger. Hey. Make a burger.

That's a good name for my own grill. Yeah, I don't know, you could invite people over for a make-em burger at your house. Exactly. Yeah, I think that's good. I mean, you know, I know it's not quite Colorado news, but on the April Fool's side, I just have to mention the whole Volkswagen thing.

You know, there was a little bit of Colorado connection here a couple weeks ago. There was a Colorado school district in— what was it? What was the county there, Alex? I don't remember. It was in the mountains somewhere.

Yeah, somewhere up in the mountains. And Volkswagen, or Volkswagen, yeah, they supplied this school, the school county, with an electric school bus, actually. That is pretty cool. Yeah. Yeah.

So, so I think that deserves the SEC investigation for sure. You know, what do you think? For those that don't know, there was an April Fool's joke where Volkswagen said that they were changing their name to Voltswagen because their gonna start putting out all these electric cars. And apparently there's gonna be an SEC investigation that may come from that. And so, I mean, I think they could lighten up just a little bit, but— Yeah, take a joke, come on.

Take a joke. Make a burger. Make a burger. If Whataburger can make a joke and there's no consequences, why can't Volkswagen too? Exactly.

All right, next story. Next story. Frontier Airlines, America's favorite airline. Most comfortable seats of all airlines. They have finally landed an IPO.

I think they decided that COVID was the exact time that they wanted to go public. They've been working on it for a while, as you said, Alex, since 2017. Not actually sure what took so long. So obviously they weren't trying to go for it in the middle of the pandemic, but they landed their IPO, right? Yeah.

Congrats to them for finally getting that IPO. I think that they started this process originally in 2017. That was when they first registered with the SEC. That's the first thing you have to do when you're going to do an IPO. But then, nothing really materialized from it.

I think that they were getting close last year, and then, obviously, the pandemic hit. Would be a horrible time to do it, during the pandemic, when you don't have anybody flying. But I guess now that we're coming out of the pandemic, either they didn't have any money left at all, and they needed to do an IPO to raise some money, or they figured now, as they're getting ready to ramp back up, was a good time. Maybe they made the seats more comfortable. They've had a year to do it, so anything is possible.

I know personally, I'm not a big fan, as I've We're just alluding here just because, uh, you know, it's just not very comfortable to fly on Frontier Airlines. But it's an experience. But hey, they are, uh, Colorado's only airline, only Colorado-based airline. So, you know, congrats to them. Yep, Colorado proud.

That's right. Uh, next, speaking of travel, uh, there was an article in, uh, Travel and Leisure about the best places to travel in 2021, and there were actually 2 places in Colorado that made it on the list. Jay, one of them I know is near and dear to you. One of them is my house, apparently. It is the neighborhood— Make-A-Burger— that could come to Make-A-Burger in LoHi.

Yes, number 13, lucky 13 on the list from Travel and Leisure, is Lower Highlands. I mean, I love my neighborhood, don't get me wrong. I'm excited to live in LoHi. I'm not sure exactly why it is on on the list, top 50 places to travel. I mean, there is a lot of great stuff in LoHi.

Yeah, but there are also a lot of great things that are in other places around Colorado, Denver, things like that. So I tend to agree. I, I mean, I love it, but, you know, come, uh, you know, have fun, enjoy. Um, and maybe you'll— maybe you— maybe I'll make a burger for you. I don't know.

Yeah, the other one was number 40, which was just the Rockies. Which, I mean, it's always great to get up into the Rocky Mountains, but that kind of seems to me like a little bit of the opposite where they were definitely not specific enough. Right? The Rockies are a big area. Maybe you could have narrowed that down to a little bit smaller place to go visit.

You know, maybe Rocky Mountain National Park or I don't know. But yeah, well, maybe there's a program where they just shove you off the plane while you're flying over the Rockies and you get that, you know, number 40 kind of experience. That's right. Yeah, you land and Bear Grylls is there. Yeah, exactly.

You know, you get to hang out in the woods for a while. And he says, hey, I'm gonna duck out, there's a Ritz-Carlton down the street. Right, exactly, exactly. But you know, as long as you're near Aspen, you're fine. Yeah.

Um, yeah, there were also some other interesting places on the list, and by interesting I sort of mean odd. Um, at number 5 was Birmingham, Alabama. And while I think Birmingham is probably fine, I don't know that I've ever been there. Number 5 on the list of places to travel? Um, I don't know.

Hey, don't knock it before you've done it. That's, that's true. Yeah. Also, uh, number 7, Buffalo, New York. Uh, yes, travel there in the spring or fall, maybe not summer or winter.

Um, but I guess, you know, it's close to Niagara Falls. That's something to do. And yeah, I don't know, maybe Buffalo is better than I realized. Who knows? Well, apparently it's better than Lower Highlands.

It's— yes, it is 6 places better than Lower Highlands. So go to Buffalo before you come here to Denver. Yeah. Anyway, all right, all right. So next up on the list is a champion crowned in the 2021 Tech Madness competition.

Yeah, so for those of you that have been following the podcast, we've been talking about this for the last few weeks. Uh, the, the Colorado Inno Tech Madness bracket is something that happens along with March Madness every year, you know, kind of a play on March Madness. So they They set up a bracket and do put startups into the bracket. And then there's a voting process for people to go and vote for which company they think would be better to invest in. And as last week we talked about the semifinals, which got StackHawk and Pie Insurance into the finals.

And so now we get to reveal the winner of the Colorado InnoTech Madness bracket.

And the winner is? The winner is Pi Insurance. So I'm a little sad about that because our friends at Stackhawk didn't win, but I mean, congrats to them for coming in second. And of course, you know, Stackhawk, when we talk about them on the show, we have to do a caw caw.

Wow, you did not give me that heads up. I'm sorry. I apologize, Jay, but since we are talking about them, we have to give them their proper due. So congratulations to both StackHawk and Pie Insurance, and maybe StackHawk can bring home the title next year. All right, next we have an article talking about election security in Colorado, which is always, I think, a good thing to talk about because I think we're one of the leaders in that area.

This is actually an article from But a publication called CS Indy, which is an independent publication out of Colorado Springs. I think the first time we've had a story from them. And there was a forum in Colorado Springs that was attended by Jenna Griswold, who is the Secretary of State, Sarah Johnson, who is the clerk for Colorado Springs, and Maddie Gullickson, who's a project manager with National Cybersecurity Center, because NCC does a lot of work with election security. Security, and they were talking through Colorado's election process and how secure it is and the way that they do things. Again, just highlighting how we are a leader in election security.

That's awesome. It's— it's glad that they're doing— I'm glad they're doing this. They probably need to continue to. Yeah, because, you know, our votes can't be safe enough. Exactly.

I mean, it is, is probably the thing, one of the things that we need to secure the most, right? That's right. And I know that they're doing great stuff, and hopefully they continue to do that and continue to make sure that those elections are safe. Well, speaking of National Cybersecurity Center, they recently launched a nationwide cybersecurity initiative with Google. That was also announced.

Yeah. So, yeah, this is a new announcement from NCC, and this is a pretty cool program that they announced. You know, some of the stuff that the NCC does, I don't know, it's a little— I'll call it interesting in my opinion. Interesting is always a word you use for things that you don't want to use other words for. Right, exactly.

But this one is actually really cool. And so they started a program, as you mentioned, with Google where they are going to be educating legislators and lawmakers around cybersecurity issues. So there are a couple people that have signed the charter for this, including Frank LaRose, who is the Secretary of State for Ohio, and of course our own Jenna Griswold, the Secretary of State for Ohio— or excuse me, for Colorado. Ohio, Ohio, Ohio. You know, mental slip there.

And, you know, they're gonna be putting this program together to help educate the folks that are making laws in states and other places so that they know what cybersecurity is, and then hopefully they can make good laws around that. Seems like a really good idea. More knowledge, better. We need this. Training and awareness is always high value.

So go NCC here. Yeah, I think this seems like a really good program. Seems very, very interesting.

It is very, very interesting. Yeah. And hopefully that will be very, very interesting in a good way. Yeah. All right.

Next, into our solid security stories here. We teased this a couple weeks ago, but Red Canary has released their 2021 Threat Detection Report. And so they've put out a blog post talking about that, of course, with a link to the report itself. One of the things I like about this article is that they have several videos and webinars that are kind of embedded in the article. So if you want to learn about different pieces of the report without reading the full report, you can check out some of those videos.

Also, as part of the report, they break things down into the top 10 threats and the MITRE ATT&CK techniques that go along with those threats. So based on them, it's very easy for you to pick out the things that you need to make sure you're detecting based on the threats that they're seeing. Yep. MITRE is good. MITRE is good.

Yeah. They're also talking about ways to detect this, the tools that you need, making sure you have the right data sources, all that kind of stuff. So definitely check out the threat detection report from Red Canary. It's definitely worth a link. It's probably worth typing your email in and actually getting the report.

Yes. It is a— you have to give up some personal information to get the report. But maybe if you jump on the Slack channel and ping one of the Red Canary guys, because you don't want to give them your email address, maybe they'll give it to you anyway. Yep. All right.

Next. Next up is Optiv Security. They launched an enterprise lab focused on IoT.

Yeah, so good stuff there. Obviously Optiv, big Colorado company.

I think we also know that IoT, in this case, they're talking about enterprise IoT, which I think is probably different than regular IoT and industrial IoT and every other IoT that's out there.

Because we need to differentiate. But they've launched this lab in conjunction with Tenable and Palo Alto Networks and I think Gigamon. To be able to show how it is that you need to secure enterprise IoT as well as— Super valuable. I mean, depends on the industry you're in, but IoT is probably one of those just gaping wide security holes if you haven't paid any attention to it in your enterprise, definitely. Yeah, I think most IoT devices we know were not built with security in mind.

So making sure you understand the way that they work and the things that you need to do different from your normal enterprise security priorities, to be able to secure them is super important. Yeah. I mean, it's like those smart TVs that aren't really that smart, right? Right. Well, I mean, they're smart at taking your information and smart at being vulnerable in your network, but— That's right.

We actually— I found a smart TV on our network once, and it was so smart that it was broadcasting out to the internet. That, hey, if you come here, you can gain access to me. You don't really need any credentials or anything. You just come in and it's like a free pass, right? Yeah, ease of use, right?

We want to make things easy for all our consumers, right? User experience. Yeah, got to have a good user experience. By that I mean vulnerable and easy to jump off from. That's right.

Cool initiative by Optiv. Glad that they're starting that, and definitely an area that needs a lot of work. Next, there is a blog by Zvilo. Not Zvelo. Not Zvelo.

Zvilo. And not Velo. The Z is not silent. Correct. We were saying earlier, this sounds like it should be a drink that you would get up at the cantina in Star Wars.

Or at least a drink you get in LoHi. Well, yeah. And if you travel to LoHi, you can go to one of the the wonderful establishments there and ask them for a Zovilo. Good luck with that. So this is an announcement that they put out that they're launching a new product.

They, I think if you've listened to the show before, we've talked about how the fact that they're sort of a white label kind of behind the scenes company, not necessarily to end consumers, but they're now launching a service for cybersecurity professionals to help with malware analysis, threat hunting, and looking at sort of brand vulnerability assessment. So that's pretty cool. Yeah, very exciting. Going to expand that intelligence out to a broader set. I don't know who they power.

I don't think Alex does either. But if they're doing well enough to expand into this kind of side, they must be selling their intelligence to some players that matter. We're probably already using Zvelo or We're drinking the drink. Yes, you're already drinking their Kool-Aid somewhere. That's right.

Maybe just not directly. But yeah, I think it is cool, and this is a, especially sort of the brand and external threat hunting stuff is an area that's really expanding anyway. Whether it's the attack surface management category or other things like that, there's a lot of products that are coming out like that, so good to see that they They saw that and took the initiative to put a product out there for that. Yep. All right.

And then our last story today is from Webroot, and this is talking about why managed security service providers— excuse me, managed service providers need to shift from cybersecurity to cyber resilience. And Jay, what the heck is cyber resilience? Well, I mean, I guess with a word like resilience, it might mean that something is able to withstand something. Yeah. Have I got that right?

I think that that's right. That's right? Yeah, so, you know— I don't know anything about that.

I think we all know that, you know, for a long time it was security thinking like, hey, we got to stop everything, we got to, you know, make sure we can do everything to prevent, right? And then the resilience part more thinking, yeah, you want to prevent, but something bad is going to happen sometime, so you have to be resilient when that happens. Sometimes words matter, and I think in this case, cyber resilience really describes that from a security perspective, it's not just about documenting how something does come back to life, but actually how it does come back to life. We need to take that reactive stance more and more. I think it's interesting in that The resilience term has been used more and more often.

And I wonder if our industry would be different if we had started out as the cyber resilience industry instead of the cybersecurity industry, right? With security, I think we sort of always set ourselves up to fail, right? Does it mean you have to wear a black t-shirt where it says resilience on the back instead of security on the back? Yes, it does. Oh, I don't know.

I mean, I know that's not quite as cool. No, definitely not. But, you know, I think that's always been an issue for security, right? It's like, well, your job is to secure things, but you're always failing, right? Well, if your job is to be resilient, it's much easier to have resiliency to be able to recover from things than it is to have perfect 100% security.

Yeah, easier metrics to go after too. Maybe we'll see a continued shift in that direction. Yeah. So, all right, that is the news. With that, let's jump over to the Slack message of the week.

Thanks again to Andre Gaeta for sponsoring the Slack message of the week. He has been doing this since the beginning of the podcast out of his own pocket. And every week we pick one winner and they get to pick one item from the Colorado Equals Security store, compliments of Andre. And this week's winner is Bradley Crowe. Congratulations, Bradley.

He is a new member of the Slack workspace, or newish. And in one of the channels, the Boulder Lunch channel, Doug Brush mentioned the fact that people should ask him to stop his rant if— I don't remember the exact context, but basically then Bradley said, I didn't think that we were able to stop your rants because Doug Brush just kind of rants all the time. And I thought that was pretty funny, and so I thought that was worth a mention for Bradley. So congrats, Bradley, on being new and poking fun at people right at the beginning. Hey, I also wanted— yeah, I also wanted to point out that for those of you that are willing to see people in person these days on the Slack workspace, there are— there's a Boulder lunch, there's a downtown Denver lunch, and there's a Tech Center lunch channel.

So if you're interested in getting together with people, check those out. Maybe you can have lunch with someone in person. In LoHi, I think. You could. That's not really downtown.

But it is number 13 on the travel list. I think we should organize a lunch in LoHi as a travel experience so that we can all travel there. Yeah. All right. Congratulations again to Bradley.

We'll get you a link out and connect you up with Andre so you can get your swag. All right, let's go over to events. Again, we have an event calendar on the website, colorado-security.com. Check that out for all of the upcoming events. On the podcast, we like to highlight the next 2 weeks of things that are happening, but there are many more events that are on the website, so go look at that.

First, we have ISSA Colorado Springs is having their April chapter meeting on April 6th. And April 10th, Colorado Springs is having a mini seminar. On the 13th, CTA is doing a webinar on the Colorado Privacy Act, which should be interesting. And on the 14th of April, ISSA Denver is having a chapter meeting. And then finally, on April 15th, which also happens to be my birthday, ACES is doing a Women in Security coffee chat with Katie Jump.

So you should jump into that and have coffee with Katie. All right, those are all the events in the next 2 weeks, but again, check out the website for more events in the future. So final thing, we'll talk about some jobs for this week. We've got a couple interesting jobs. First, TrackVia is looking for a security automation engineer.

That sounds exciting. Red Canary is looking for a senior incident handler. OTS, which is a group that I think provides services to credit unions, and I think this one is specifically for work with Bellco, is looking for a DevSecOps engineer. Check Point's looking for a CISO in the West. Yeah, that's like a pre-sales— a client-facing CISO.

Client-facing CISO. So if you're interested in that kind of opportunity, sounds like fun. Randori is looking for an HOC attacker. So if you want to help build their platform, which does attacks, then that sounds cool. Oracle is looking for a Senior Assurance Engineer.

Spectrum is looking for a Security Engineer 1, and I think that they actually had multiple jobs this week, so lots of stuff going on at Spectrum. Brownstein Hyatt Farber Shrek is looking for an Information Security Analyst, and that of course is a law firm because only law firms or CPA firms have names like that. No, isn't that a startup? Yeah. Wouldn't that be interesting if people did that for startups?

Like, don't come up with a name, just like put all the founders' names. That's right, just 4 names back to back. I think that they should start doing that. It'd be better than coming up with something that's like starts with Cy, like Cy blah blah blah, you know, whatever. We could start a trend here.

We should. Colorado Judicial Branch is looking for a network security engineer. And Conga is looking for a lead information security analyst. Awesome. And those are the jobs for this week, and that wraps up the newscast.

We do have an interview for this week. Our interview this week is with Melissa Cooper and John Rosendahl of Sovrn. So this interview was done by Janelle Hsia, talking a little bit about privacy and things that are happening over there at Sovereign, so I'm pretty excited to, to hear about that. Jay, yeah, no, this has been fun. It's been great.

You know, I'm really excited about the check you're gonna write me later. That's right. I'm gonna have to go find my checkbook, I guess. But again, this has been fun. I appreciate you filling in for Robb.

Robb should be back next week, and we'll be getting back to normal, so Cool. Thanks everybody, and we will talk to you next week. This is Robert Wood, VP of Security at Alps Fund Services. This is Colorado Equals Security, for Colorado security professionals by Colorado security professionals.

Welcome to Colorado Equals Security. This is Janelle Hsia, and today I'm excited to interview Melissa Cooper and John Rosendahl. I hope you guys enjoy our conversation. Welcome to the podcast, guys. So how are you guys doing today?

All right. Yeah, we'll start with you, Melissa. Yeah, things are great. Waiting for the snowpocalypse to hit. Exactly.

We are the weekend before what's supposed to be the largest snowstorm in I don't know how long they're saying, but every time I look at the news, it's more and more. Right. Right. Yeah, so Melissa, why don't you tell us a little bit about yourself? Oh, absolutely.

So, um, I've been here in Colorado since 2001 and have been working in the privacy and security space for roughly 6 years, a bit longer in security alone, but certainly focusing on those 2 concepts, um, for several years now. And as it relates to privacy timelines, we are still a fairly young career path, I guess you could say, because it has been embedded in with security concepts for so long and really came into this space up through security. So folks listening to this podcast are well aware that privacy is definitely embedded into security processes and programs and separating the 2 practices apart doesn't segregate the 2. It just means that the 2 get a slightly different focus. So yeah, I like how you said that, and I do think that each one deserves its own person in the organization and its own focus.

I like how you said that. And John, what about you? I grew up in Colorado. I've been here for a long time. I just got into ad tech about 4 years ago.

And from timing-wise, that's been super interesting because that's exactly when all of this privacy and identity stuff really came to the forefront. And I saw it as something I needed to pay attention to. And so I have been. That's cool. So have you been in security kind of in this technical role for a long time?

I'm primarily an engineer. However, I did do a lot of security consulting earlier in my career through the Bioterrorism Defense Act. Doing cyber assessments. Oh, okay, great. So tell us a little bit about Sovrn.

You guys both work for Sovrn. What is that company? Where are they located? And you mentioned ad tech, so they're in the ad tech space, but exactly what do they do?

Sure, I can jump in with that. I'm also new to the ad tech space. I leaned into this position specifically to learn, and what I appreciate about Sovereign is its mission to help publishers do more of what they love and less of what they don't. It was really important to me to jump in with an organization that supported the concept of a free and open internet. That's, that's really why we're here in the digital advertising space.

And Sovereign specifically is headquartered out of Boulder. And I like that it's a local homegrown company, but we also have offices in New York, London, and San Francisco. And we're, we're quite a mature organization. We were founded in 2006, although it's still run like a startup, which makes it super fun. And I'm curious to hear what John's perspective is on that, because I am just at a year in at Sovrn, so still new.

I've never worked in person in the office, still waiting for that first day of work, so to speak. Yeah, I mean, that's, that's one of the great things about ad tech is every 6 months you're in a completely different industry. Um, so Sovrn has to move fast, and, and we do, and it's with a good culture. Yeah, and it's funny, Melissa, so I actually interviewed somebody at Sovrn a couple years ago, so I guess I beat you to having been in your offices. Exactly, you sure have, for sure.

Yeah, it's a beautiful facility. Um, yeah, so when you get to go back, I will be very excited for you. So, and I liked how you said free and open internet, and I think that that's kind of something I really want to dive in today and one of the reasons I was excited to interview you guys. Um, so what does free and open internet mean? And we'll start, John.

What does that mean for you and for Sovereign? So the majority of the internet is controlled by a few big players. That's Facebook, that's Google, that's Amazon. But the majority of the content and the majority of the value that people get out of it actually comes from all these small publishers who are really talking about either their passion or something they're really interested in or putting out a podcast. And it's that, it's those people and how they're actually managing to make a career and a life out of creating that content that we're most concerned about.

Because you don't really make any money making Facebook posts, and you can't turn that, like, hobby or that passion into, like, a real business without a lot of agreements from a free and open internet where everyone can participate. Yeah, I like that. And how about for you, Melissa? Yeah, likewise, I would echo what John said. What I find most interesting about some of the conversations that's happening in the ad tech space today and around digital advertising and targeting through behavioral advertising is kind of this sense that we're diving into people's lives in an invasive kind of way.

But I guess I'd I like to point out that we make inferences about people all the time, right? You, you walk down the street and you make assumptions about a person. That is similar to what's happening in the digital advertising space, and it is a free and open community. And if it weren't, we have to consider the folks who wouldn't be able to participate in that community. And so, you know, diversity is another topic that's top of mind for a lot of folks, um, in society today.

And if we don't have a free and open internet, then we don't have a diverse community online as well. Yeah, no, I completely agree. And I think that, uh, you know, and even for myself, right, I'm in the privacy space. This is This is what I do. I live and breathe protecting people's privacy.

But then when I put on my hat as a small business owner, right, like I have to do marketing. I have to reach an audience, right? So how do I do that in a privacy-preserving way while still meeting my business objectives? So yeah, I think— and the piece about diversity, Melissa, I completely agree with you. My biggest concern as well is that we're going to create paywalls and that people are going to have to pay and that there's going to be people who have access to content and people who don't have access to content.

Absolutely. So there's a lot of acronyms and some terminology that I think people may not be familiar with. And so I kind of, you know, I look at this as, you know, like a little bit of bingo. So I'm going to throw out just a couple terms. For the audience that they may or may not be familiar with.

And the first couple of them are DAA and ad choice and the IAB and the NAI. So Melissa, if you want to tell us what those are, I'd really appreciate it. Yes, of course. So well before the GDPR and CCPA came into our lives, the FTC had taken a position where they really wanted to make sure that consumer choice around targeted advertising and ability to track movements around the internet were put squarely into the individual's hands. And so as a result, several in the digital advertising space, several folks within the digital advertising space came together to create self-regulatory bodies.

So what you're finding in doing your research in digital advertising are organizations like the Digital Advertising Alliance, which is DAA. They host a platform called AdChoices, and any consumer can go to their web choices or to their website at adchoices.com and choose to opt out of targeted advertising. And then you have companies such as Sovrn who participate with these organizations and uphold what I, what I call internally good advertising advertising principles. And essentially what that does is it allows a cookie to be dropped on your browser that says, hey, I do not want to be tracked, I do not want to be served targeted advertising, and then only contextual advertising is served. So it's, it's a way to really put that control back into the consumer's hands on where they do and don't want their information to be tracked as it relates to behavioral advertising.

IAB is another organization that has been crucial to upholding these good advertising practices, and their Tech Lab is the organization that brought folks within digital advertising together to come up with a technical specification for sending consent signals. So when you think about the CCPA, there's a US privacy consent string. When you think about the GDPR, there's the TCF, which is a framework that supports tracking and, and sending consent back to companies such as Sovereign so that we can understand what the wishes of the individual were without each publisher having to communicate that directly to us. So that alphabet soup serves a great purpose for allowing us to demonstrate that we are upholding these good advertising practices and we do care about everyone that's in the advertising ecosystem, not just the advertisers or brands. Yeah, and if I can ask a question about ad choices.

So I am familiar with them, but I don't necessarily know how they work. And I know that when I have run, I've done the app where I've like got rid of my cookies, It says that there's about 140 or 150 websites that I can opt out of automatically, but I know that there's like thousands of websites. So do companies opt into being part of AdChoice, or how does that work? Yes, it is a self-regulatory participation, and so it— the FTC, while They have put quite a bit of pressure on the industry to allow for consumer control. It's not required to participate.

So that's what you're seeing whenever you visit the website and see that disparity between the numbers of participating companies and those that you're aware are out on the World Wide Web. So like I saw, like Google's on there, Facebook's on there, and Sovrn, like you mentioned, is on there. So if I do, if I opt out and Sovrn drops a cookie, does that mean all the publishers that you guys host, if I go to their website, they understand my choices? Or is, I mean, like, how does the publisher play into the, that, that cookie that gets dropped? So John, maybe we'll pass that to you.

Yeah, so, um, yeah, a lot of publishers use the same suppliers. Um, that's Sovereign's role is to aggregate all the publishers in order to serve ads on those publishers. So it's Sovereign's responsibility to actually respect your choices with regards to tracking. So when the publisher sends the request and we sense that it's supposed to be data-free, we then drop that data before we send it on to our partners. Okay.

So if it— so like for some publishers have, or some people have sites or they're publishing all over the internet. So even though you may respect the do not track, if they're publishing somewhere else, they may not. And that's why I might still see their ad. Is that kind of what you're saying? Well, I mean, ads can be served in contextual form.

Like, so you're out on the Yoga Journal, you might see a yoga-related ad. We don't have to know very much about you to know that that's a good idea. So it's just the act of actually tracking that user and creating a profile of that user. That the ad choices opt-out creates. Okay, and then, I don't know, do you— can we talk about like super cookies and then ever cookies?

Is that something that you guys are comfortable talking about?

We can say that, I mean, super cookies are a marketing term.

What it comes down to is there are third-party cookies. First of all, a cookie. A cookie is just a small piece of information that a website can place into the browser, and it allows that website to know who someone is and what they've been doing. You know, it's a little bit of tracking. And a third-party cookie— we use cookies for everything.

We use it for authentication, we use it to, you know, show different widgets on a screen, all sorts of things like that. A third-party cookie is a cookie that comes from a website that is other than the website that's in the address bar. So if you go to newyorktimes.com and it pulls a sovereign ad, which it wouldn't, but nonetheless, uh, it pulls a sovereign ad, uh, we would place a cookie on that site on the New York Times and under— be able to understand who that user was. Um, however, uh, that's the functionality is being removed from the internet right now. Um, at the end of the year, we're going to no longer have third-party cookies, and that is going to make tracking users different, and in ways it could make it better, because it's going to force ad tech to become more transparent and more accountable.

And hopefully, we'll be able to put in place technologies that will get us similar results. So are you, are you alluding to what I understand to be the federated learning of cohorts, this FLoC that's coming out? Or is it something different that you're alluding to? Well, I'm alluding to The third-party cookies are used for a lot of different things within ad tech. They're used for creating user profiles.

They're also used for frequency capping, making sure you don't see too many ads. They're used to measure the performance of a particular ad, see what you did after you saw it. FLoC is an interesting proposal that involves interest groups. So instead of a third party collecting data on you and watching everywhere that you go and aggregating all that data, They aggregate that data in the browser and then store the— and then send out the results of that aggregation as a signal that buyers can act on in order to determine that this is someone that they would like to show an ad to. And so is that by like having categories for people so that everybody has like tags associated to them, kind of like we see in, you know, like I have a Google account right now.

And when I go in there, I can see— and I forget what they call it— categories or something. Yeah, it is the same approach. It just moves kind of the fulcrum of that from Google or any other person that's creating those profiles to the browser. And that means you have a little bit more control over the creation of those segments and who they get sent to. Okay.

And then you said super cookies is just like a marketing term. So can you— and I hate to kind of push into that, but that's one of those things that people ask me a lot about. And I honestly, like, I just understand that it's a persistent cookie that's difficult to get rid of. And that's as much as I can say about super cookies or like ever cookies. Yeah, I mean, cookies clear when you clear your browser.

So that's— there's— the cookies can last as long as you want. I think that was more of a problem in the past when things were a little bit less advanced on the browser framework, on the browser standpoint, but I think generally those practices have more or less ended. Okay. No one cares about the individual. They care about the inferences they're able to make.

So when they take this group, they say, okay, we all— all they're using this data is to say, oh, this is a person that likes, uh, these 4 different things, and they say, okay, so that would be a great person for, uh, Ford Motor to advertise to. Just like you see, you know, just like this, we— you make the same kind of suppositions all the time where you're going to see a different set of ads in Forbes that you're going to see in, uh, Sixteen Magazine. Um, so it's, it's a way to keep ads relevant to the user. They're not, they're not really interested in what you're doing. They're interested in the results of the model that they're creating.

That just tells them a little bit about what you might be interested in. Yeah, and I have to say, my husband is in love with personalized ads. He does not want to see an ad for something he does not want. So he is your target audience. On the other side of the spectrum, you have me, right?

So I would like to see ads that you would place in Ebony and in Sixteen magazine and maybe Bride because I think the dresses are pretty, right? And so yeah, you have this spectrum of people. And in my house, this is a conversation we have unfortunately frequently.

But so that's how third-party cookies work today. So what does that look like? Kind of what does the future look like, Don? What do you see that as? And I think that there's something that like as far as like encrypted tokens and how we can use that to understand how people want to be tracked.

I don't know if you want to talk about that a little bit. Yeah, so one, one of the options— I mean, the ad tech industry is really moving towards transparency and consent. And so one of the options is to just ask users, hey, would you like to be tracked? If you'd like to be tracked, please log into our website, and that will allow us to create a user profile for you, and you'll get personalized ads. You won't see the same ad over and over again, and honestly, you'll be helping that site make a little bit more money.

And that might be the difference between content you love being available and content you love not being available or being behind a paywall. So in those cases, what they can do is they can generate a UID, a user ID, that is good across the entire internet once you log in. So every site that you log into understands that the same person is tracking against across all those sites and they can build a profile based upon that and get all of the original value we were getting from the third-party cookie, but in a way that's super consented. You actively had to log in and approve your— the use of your data in that specific way. And so, and if I can ask another question, so you talked about it creating a unique ID.

My understanding was that we kind of already have unique IDs that the data aggregators are able to consolidate information upon. So how is this going to be different? Well, I mean, the third-party cookie is essentially a unique ID for each person that browses, but you unless you actually said okay to the cookie module each time, you haven't clearly and transparently consented to the use of your data. And that's really what we're changing. We're proving that that particular user has consented to using her data in that particular way.

Got it. So you're really going after— so this would be from the ePrivacy regulation, the cookie directive in Europe. This actually would be compliant with that new regulation is what I'm hearing.

And maybe compliant is a strong word, but you're— that's kind of the goal, right? Like, you're, you're looking towards having that true transparency and consent that is being required for all these cookie banners that we're seeing, right? I mean, it— I would disagree with you slightly because cookies are also able to be compliant under the ePrivacy Directive. It's really like John was saying about that transparency and consent, and we already have have mechanisms in place in order to be able to gather that consent. What John was referring to around the encrypted tokens around consent is making sure that that consent is preserved across different environments, right?

And so just to kind of bring it home to Sovereign's operations today, if any publisher on our ad exchange sends us a consent signal from an EU reader, for example, that says, yes, we, we have consent to be able to use the data for targeted advertising, for building profiles, for creating audience segments, all the things that we do to support digital advertising for advertisers and for publishers, then we can take that consent signal and process it accordingly. Now, we will also take that consent signal and forward that on to our third-party partners. And by having encrypted consent token in place, and you can ensure that similar to a chain of custody, right? And John, jump in here if I go off the rails at all, because that's why you're here, is to set me straight from the technical perspective, because I am just the privacy compliance person at the end of the day. But essentially, it's as he was saying, making sure that everyone in the supply chain, anyone who gets a hold of that consent signal, is aware of what the individual wishes were of that reader who offered the consent to begin with.

The authentication piece that he referred to where you actually sign in and then you know that that person is exactly who they say they are is important, and it's nuanced in this space. And I don't think a lot of folks understand this because, you know, you— I'll use my own household as an example. We have a family iPad. Anyone can be holding that device at any given time browsing around under the same profile, if you will, of that iPad because we don't have it set up for each individual in the household. So you might have my youngest daughter all the way to, you know, if I have visitors in the home using this particular device.

So if someone clicks consent on that device then it's tied essentially to the device that the person was holding. So when we talk about targeted advertising and individuals and understanding who individuals are, we really don't know who the people individually are because we don't collect personally identifiable information or PII. We only collect indirect identifiers, which are things like mobile advertising IDs, which is what would be tied to that iPad. It's an iOS device, so it's an IDFA that is tied, and that is how the consent is gathered and tied back to what's an individual, which in this case could be many people. So the, the authenticated consent would require an individual to log in, so then you know whether it's someone who's under the age of 13, over the age of 13, and whether they're using their own profile or an actual device.

So that's kind of the difference there. So, you know, the ePrivacy Directive and trying to be compliant to that has everything to do with transparency and consent, whereas where the digital advertising space is going is really trying to make sure the individual has offered that consent and not just someone who randomly picked up a device. No, thank you, Melissa. I think that's really a good delineation between those 2. And I think, you know, kind of talking about it from a personal data perspective, you know, it sounds like what the ad industry is trying to do is create individual profiles for each person so that their consent can be managed better, right?

Is that what I'm hearing you say?

I don't know that individual to each person is completely accurate because again, I don't know that it's Janelle that's looking at wedding dresses, right? I just know that there is someone who seems a lot like Janelle, appreciates the beauty of wedding dresses and, and may benefit from serving an ad to you. So the individual part— and this is kind of— I'm stumbling a little bit here because this is where, you know, deprecation of third-party cookies is supposed to be the benefit of the individual, yet we're moving towards this space where you actually have to use personally identifiable information to say you are who you say you are when we don't— to John's earlier point, we don't really care that it's Janelle, we just want to make sure that the right advertisement is getting in front of the right person again, because at the end of the day, we're here to maintain this free and open internet. And unless you go and purchase that wedding dress, which it sounded to me from earlier conversation, you're already married. I don't know if you have daughters or not or other folks in your life.

Right. Anytime soon. Correct. Exactly. And so, you know, as much as you might appreciate seeing an because you appreciate the beauty of a wedding dress, it doesn't do that brand any good to show you that ad if it's not going to turn into money changing hands in some way, shape, or form.

Yeah, no, you're absolutely right. And I think that's funny. And I think that's kind of— and unfortunately we are out of time and I have so many more questions. You have no idea. And I'm sure our audience has more too.

But I think this is kind of where I'd like to end it is the fact that it's such a complicated conversation. And, you know, I'm so grateful that we have privacy experts and security experts who are working on this in, in like our own backyard in Boulder. And I think that it is going to be really interesting how we use that personal information and how, like, do we need more personal information so that we can be less intrusive, you know? So it's kind of like this dance that we do with this data. But transparency, I think, is going to be excellent for everyone.

So agreed. I couldn't agree more. Yeah. And so I usually like to end by just talking about giving back to the community. Um, and so I know Sovrn has at least one program.

Melissa, do you want to talk about the— how Sovrn and how you give back to the community? And then, um, John, you can always jump in as well. Certainly. So we have a couple of things that we do, um, from a corporate perspective, um, What you're alluding to is the particular area that I individually contribute is Sovereign does maintain a route through the Boulder chapter of Meals on Wheels. So I have an opportunity to get back out in the community and help some folks who need an extra helping hand.

And the rest of the Sovereign drivers are super proud to contribute to that organization. But I do want to also give credit where credit's due. Credit is due, Sovereign, as part of the holiday season, puts together a drive where we help out a couple of different organizations in the community as well. And I know I'm new to Sovereign, so maybe, John, you can add some color here. But last December, we contributed to the EFAA, so Emergency Family Assistance I forget what the last A stands for, and also the Boulder Humane Society.

Yeah, that's something we've done every year for a while, and it's been really nice. It feels good. We have those folks come in and speak to our group. And part of the Meals on Wheels efforts, the Sovereign volunteers got together and hosted an internal drive with Sovereign where we wanted to continue contribute to their patio brick campaign, which we, we only needed to hit a $500 donation amount in order to purchase a brick to support the new facility and funding the new facility, and we exceeded that triple fold. So, and quite proud of our sovereign community and the way we contribute back.

That's awesome. And then, Melissa, I can't not ask you about the fact that you worked at Ping Identity and you worked with our own Robb Reck. So I don't know if you want to give a shout out to him as we wrap up the interview. Oh yeah, for sure. It was great working under Robb.

Having had the experience of seeing the different approaches various CISOs take in running their organizations, he was just instrumental in coming into Ping. We started roughly the same time. We were a month apart from each other. He was there before I was, of course, but he built the security program essentially ground up, and it was just really cool to watch the way that he pulled folks into Ping and built out this program, and it's thriving today. So yeah, it was a great experience to get to work under his leadership.

That's awesome. Well, as we wrap up, unfortunately, I think we are out of time. So thank you so much. So Melissa and John, it has been truly a pleasure talking, and thank you for being so open about what Sovereign does and the challenges that we see and the advancements and how we protect people's people in protect people's information in the ad industry. So as we wrap up, I don't know if you want to just give the audience a last goodbye and then we'll close it.

Sure. Thanks for the opportunity. Happy to be here. And I can be found on LinkedIn, of course. So if anyone wants to continue the conversation, I encourage you to reach out and happy to chat anytime.

Yeah. Thank you so much for having us. I really appreciate it. I can be reached on LinkedIn as well. Awesome.

Well, thank you guys. This is the end of our interview. Until next time, thanks everyone for listening. Bye-bye.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes