Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 206, uh, for the week of— was it April, uh, no, 12th? Yeah, 12th.
April 12th. Yeah, this is very difficult. It's right in front of me now, but I, I still struggled through that. So we'll keep it. Rob, uh, you're unemployed, and clearly as soon as you become unemployed, your life falls apart.
Can't even think of what day it is. They say once you retire, you know, you— if you don't keep your mind engaged, you go pretty quickly. I didn't, I didn't expect it would be less than 24 hours before the mind went, but, but there you go. Yeah, so, so congratulations, I, I suppose, on, uh, being purposefully unemployed. Yeah, it was, it was actually, you know, super challenging to walk away yesterday at the end of a very— just like the highlight of my career getting to be the CISO over at Ping.
And I'm excited to get to take some time with my family over the summer before starting something new. But, you know, I, I didn't think it was going to be so difficult at the end, and it was. And I'm going to miss the team, miss the people over there. Don't regret the decision, but I do, I do definitely— I know, I know I'm going to regret it and— or not regret it, but I'm going to miss it and Um, certainly, uh, wish the best for all those folks. Yeah, well, congrats.
You deserve some time off, so, uh, hopefully you get a little bit here. Well, thank you. Hey, why don't we go through some housekeeping before we jump into the news? We have a Slack channel with well over 1,800 of our closest security friends in Colorado. If you want to jump into the conversation, the many, many conversations going on there, you can do so by going to colorado-security.com and clicking on the Slack button there.
That'll bring you into the Slack channel. I feel like we're, uh, really close to 1,900. I don't remember the last time I looked at the number, but, um, I think we're getting close anyway. At this point, it's really 2,000 we've got to be aiming for. That's true.
Yeah, yeah, I agree. Um, you know, Rob, we also have a mailing list, uh, on the— if you go to the website colorado-security.com, we have a form you can fill out and give us your email address. We will send you one email every week with the show notes. Also, if you'd like to rate us and subscribe to the podcast, that would be awesome. That way you get it delivered to your podcast player every week.
And we also get better ratings, hopefully, and people get to know how good the podcast is. There's a couple other things you could do if you want to help out the show. We'd love it if you tell a friend, help us get new members of this great community we're a part of. And if you want to financially support us, we would love if you'd get involved with our Patreon campaign. Just, we have a great group of folks who are helping financially support the community and, you know, pay the costs of hosting and other stuff associated with the podcast.
And speaking of that, we actually have a new patron this week. We do. Cameron Williams, thank you very much. Cam, you guys may know, was one of the founders of Overwatch ID. You know, they were acquired by SailPoint a couple years ago, but you know, we're a great Denver startup here.
And, and he signed up for the, the $10 a month level, so he gets a shout out on the show, but you know, also did, uh, did it annually, so paid it all up front, which is pretty cool. Uh, Cam also has got, I think, a new startup in the works that he's, uh, he's getting going. I think gonna hear some more about that soon. So did we get some of that sweet, sweet SailPoint money? Is that, is that what he's shipping over to us?
I assume so. That's awesome. Well, thanks, Cam. We appreciate you very much. And of course, we want to hear about the new, the new business as it gets going.
Yeah, so let's jump into the news. Um, Rob, big, big news this week. Denver is going to be hosting Major League Baseball's All-Star Game this year at Coors Field. Yeah, in this case, it looks like Georgia's loss is Colorado's gain, and we're going to get to have the game here. You know, I'm a pretty big baseball fan, and it occurred to me that basically the All-Star Game has not been in Colorado since I moved here.
I moved in 2001, and I think the last time it was here was like '97 or '98 or something like that. It's been a long time. It has been a long time. Um, I think the only thing better that could have happened from this is if the All-Star Game was originally supposed to be in Austin and then got moved here. Um, but, uh, but I'm pretty excited about it too.
I'm a baseball fan and I've never been to an All-Star Game, so maybe I'll see if I can find a way to, to sneak into some of those festivities. Yeah, I've, I've got the chance to, to go to a home run derby, and that's, that's an awfully fun time. And I think in Colorado, having the home run competition would be, would be even more fun. There'll be some big, big home runs hit here. Yeah, I mean, it might not ever end.
Um, I think that they'll just keep hitting them and hitting them. Yeah, they get tired after a while, so it'll be a question of stamina at some point. Yeah, in the article they do mention that there will obviously be some, uh, financial impact positively here in Colorado from the All-Star Game being here. I think there— the original first estimate was about $100 million in benefit, but I, I have since seen some people poo-pooing that, that maybe it's not quite that much. You know, $100 million, $80 million, whatever the number is, I'm excited that Colorado gets to have it, especially, you know, the impact is going to go to one of the most negatively impacted sectors from the, from the pandemic, you know, the hospitality, restaurants, hotels, that whole industry that's been just so badly beaten up.
It's really nice to see a shot in the arm for, for us in that area, even if it's not $100 million, whatever it is, I'm sure they'll definitely appreciate. I agree. All right, well, that is, uh, that is that story. The next story is an interesting one we've been keeping tabs on for a few years. Um, this is around the idea of having a Front Range passenger train system, um, and it looks like there's actually a new Senate bill, um, that's, that's going through that might actually bring this into fruition.
Yeah, so, uh, I think we can just keep getting, uh, closer and closer. I think the last time we talked about this story, they were maybe commissioning another, um, study to make sure that it was going to be feasible for the Front Range. But now they're looking to, through this bill, to create a, a new taxing district that essentially is, you know, around I-25 north and south, uh, in Colorado, that the— they would be able to use to generate money to then go ahead and build this, uh, commuter rail line. Yeah, I mean, I think we've talked about it before. We, we think it'd be great to actually have a train that goes all the way down from Pueblo up to Fort Collins.
That is basically the vision here for this bill, and it looks like it's got the support necessary to pass. We'll definitely update you guys when it does or does not pass, but we're right in the middle of the session right now. We should have some news pretty soon. I'm excited about it. Yeah.
I think the other thing, they mentioned that President Biden has potentially some money earmarked in the infrastructure plan that he has I think they said, you know, up to $80 billion for, uh, for rail. And some of that could also go through Amtrak to that, that Front Range, uh, rail project too. So that would be pretty cool and another shot in the arm for it. Yeah, good stuff. Yep.
Uh, next we have a story, um, that it's a little bit— I don't want to call it out of the norm for us, but it's, um, it's technology related. But there the local company Outrider, which is a pioneer in autonomous yard operations. And when you think about that, when I first started reading this, I thought, are they making automatic lawnmowers or something like that? But no, no, no. They're talking about shipping yards.
And they're in a partnership with another company called Righthite, who also does similar type things to help make these autonomous yards even more autonomous. So this basically is like the Internet of Things for, uh, for industry. This is industry IoT that for industries I had never really thought of. Is that, is that a decent summary for what we're looking at here? Yeah, I think so.
So, you know, one of the things they talk about is, um, you know, if you're in a shipping yard, you've got trucks that come in with trailers and you park them someplace and they get loaded and unloaded and maybe they need to get moved and, you know, so on and so forth. And Uh, these devices from Outrider help with that, the logistics of it, and actually moving things around to different places. And so they have a partnership here, uh, that's going to basically help, uh, make the technology better, better coverage across different industries. Is that, is that what the announcement here is? I think some of it, but I think also, um, Rite Hite does a little bit of a, of a different piece of the puzzle than Outrider does.
So Um, you know, Outrider has sort of the more autonomous operations piece, and, uh, Rite Hite deals with like the, the loading dock equipment and other industrial solutions like that. So working together, they can really, uh, help make these yard operations more automatic and autonomous. I'll say one of the things I love about the, the news part of the show is I learn about all these companies in town that I had never heard of, and, and frankly, probably never would have heard of without this podcast. And this is one of them. This is definitely one of them.
I can't say I've ever really thought about yard operations before. All right, good stuff. Uh, moving over, uh, this one's, uh, more a little closer to home for us. This is a, uh, a, a services software organization, I guess, really, um, focused more on outsourcing, uh, a place called Velocity Global. It's a Denver-headquartered company that, um, just raised $100 million, and they're going to be passing a billion dollars in revenue.
And I had never heard of them before this article. This one's really interesting to me. Yeah, I hadn't heard of them either. And, you know, what they do is actually really simple, but I think it's, it's something that it seems brilliant. Um, so if you are trying to set up operations somewhere else, um, I think that could be in another state or another country, um, but you don't want to actually, um, you know, put a, you know, set up an incorporation there and, you know, have to do all those things, you know, they will essentially do that for you, and they can— they will hire the employees to work for them even though they're actually working for you.
So they do that sort of backend business piece so you don't have to worry about your business operations in that particular area where you're— you want to hire people. Yeah, and they've only been around— was it— I think it was 2014. Uh, yeah, founded in 2014, and they're already going to be passing a billion dollars. And it's really a lot of mind-blowing stuff as a part of this article that really surprised me. Um, They were bootstrapped all the way up until this $100 million round of investment that they took.
They're calling it partnering. And basically, they've chosen to take in a partner because they wanted to make an acquisition and they acquired one of the other big players in this space called iWork Global. And basically, the idea is that this is going to push them just to be bigger, do it at a bigger scale, and really seize this opportunity of the market they're creating. Sort of like yard operations. This is something that I had not thought of previously but seems like it's a pretty good market to be in.
Yeah, this one, this one really interested me. So Velocity Global, I'm looking forward to, to meeting those folks, and maybe there'll be a— maybe there'll be an interest— interesting story we can get on the show later about these guys. Yeah, uh, speaking of Colorado companies, uh, the startup Cloudrise has moved their headquarters from Denver to Grand Junction. Um, I think this is maybe the first time I have heard of a, a company, uh, also a cybersecurity company moving their headquarters to Grand Junction. So that's pretty cool.
So we picked this one, um, you know, and I didn't know much about it before, you know, starting to read it for the show prep. And, you know, it said cybersecurity firm, like, oh, Cloudrise, I wouldn't have guessed. And then you open it and there's a big picture of our friend Rob Eggebrecht, who was one of the founders of BEW Global, now InteliSecure, now What now? They're part of, uh, uh, Proofpoint. Yes.
So, so Rob, we've had on the show in the past, and, uh, in— or maybe not on the show, but I interviewed him maybe for my, my blog before we started the show. Um, anyway, he's a— he's the CEO and founder of this new company, and I had never heard of it, and so I'm super glad that we came across this article. Yeah. Um, I, I believe I had heard of the name before, but I hadn't really known much about them. Um, and it sounds like they're you know, a, uh, partially a services company but also a little bit of a software company trying to automate some of the pieces around, um, cloud security, which is pretty cool.
Um, it also, you know, good— some, uh, good quotes here from Rob in the article talking about, uh, you know, the opportunity to move to Grand Junction. Um, you know, part of it was there some economic incentives for them to move there, uh, but also Rob said that, uh, because of his love of mountain biking, you know, he thought it would be cool to live in Grand Junction where there apparently is a lot of mountain biking. Yeah, it seems to me like he justified his desire to mountain bike in Grand Junction by coming up with a business. That's right. Which is awesome.
That's fantastic. If you're going to start a new business, you may as well do it where you want to do it. Pick it where you want to be. In terms of what they do, as I read through this, it feels to me like Rob, if you know the history of BEW Global, they were a DLP provider, basically a managed service provider who who helped manage your VonTu or your WebSense or whatever other DLP. I think that he, that's the problem space he knows best.
He's looking at, how do I solve that same type of a problem with the new cloud dynamic? It looks like they're also going to be creating some of their own coding to help customers do better, but my guess is that they're going to be using some existing tools to help customers solve these problems, and certainly a space he knows well from his time over there at InteliSecure. So this is going to be an interesting company to watch. Yeah, definitely. Of course.
And then, like you said, a Western Plains company— we have very few of those. I can't think of any others off the top of my head. So, you know, certainly they'll be, uh, they'll be unique and worth keeping an eye on. Yeah, maybe it's the, uh, the start of the renaissance of Grand Junction as a tech hub. I love it.
All right, uh, go ahead, Rob. Yeah, so the next article we have here, um, is, is a deep dive into some of the details about the new data privacy bill here in Colorado. I think we talked about it on the show a couple weeks ago, uh, but this goes just It's an article in the Denver Business Journal. It's getting into a little bit more of the detail around it and some of the detail around the folks who sponsored the bill, and then a little bit of analysis by some lawyers looking at what the impact could be for Colorado companies. Yeah.
One of those lawyers is David Stause, who we've had on before and a friend of the show. I think actually who we might try to get a new interview from here pretty soon. But yeah, I mean, Colorado seems to be going down a similar path to California and Virginia and the other states that have, have passed new privacy laws. So, um, I suppose good for us. I think this will, um, be a good thing for consumers in Colorado.
Uh, I think like many of the privacy bills that are, are coming out today, it's, you know, a little bit GDPR, a little bit CCPA, a little bit, uh, everything else, and, you know, kind of making things similar but not exactly the same as other privacy bills. Yeah, I mean, I think the question for many companies is going to be, well, what's the impact to us? And, you know, obviously we're going to have to see what actually gets passed, but it looks like there will be some impact to companies who have Colorado data. You know, really understanding your data flows, being able to respect the rights of those consumers when they want to be forgotten, when they want to know what you have about them. Those are going to be impacts, and it'll be interesting to see companies adapt and maybe have to change some business practices in order to comply.
Yeah, and right now the, the limits that they have are this is applicable to company— a company that is a controller or processor of personal data for 100,000 or more consumers, um, or deriving revenue from the, the collection or sale of data of 25,000 or more. So I mean, in terms of, uh, who it's going to affect, you know, those numbers are, are fairly low. I think if you do a decent amount of business, you're probably going to hit those numbers. And, and it is a very similar structure to what the CCPA, the California Consumer Protection Act, did, uh, but it— but the numbers, I think, are a little bit different, but similar structure. Yep, for sure.
Uh, we'll have to see how that goes and look forward to hearing more about that. Uh, all right, uh, next, we, uh, we heard about the, uh, winners of AFSEA's Rocky Mountain Cyberspace Symposium Capture the Flag. So, uh, The, the— there was an AFCEA conference, the Cyber— excuse me, Cyberspace Symposium, last month. Um, and the NCC, uh, along with that held its first high school only capture the flag competition. And as part of that, we've got an article here talking about the fact that, uh, Pine Creek High School was the, the one that won that competition.
And there's a picture of the, of the winning team out there. I love to see those, those kids who, who obviously worked super hard for this and I'm sure they're very proud and they should be very proud of what they've accomplished. It's funny because everyone is wearing masks, you know, it's pseudo-anonymous, right? Hard to tell who they are except their names are right down below. But really cool to see.
And it looks like, you know, the intention is that there's going to be another competition coming up in September. And, you know, I know that this is something that NCC wants to keep doing and scaling out bigger and bigger. So I'm looking forward to seeing these impacts and maybe one of our kids will get involved, Alex. Maybe they will, um, or, you know, we'll get to hear some, uh, some other winners hopefully in September. Yeah, good stuff.
All right, next article here is a blog post by Red Canary, uh, and they're announcing a new capability they have within their platform. Uh, you know, they— Automate is the platform that Red Canary has that's about, um, basically obviously automating your response to different activities, and they've added some new capabilities underneath that where, uh, one of you have 2 new features you can have automated. Number one is, um, to ban IP, a bad IP address, or to— the other one is to ban a bad domain name. And that's an integration that they have with Microsoft Defender, right? I guess Microsoft Defender is probably providing these, these bad IPs.
Is that how that works? Well, so basically what you can do is you come up with, uh, with something that is bad, um, could be through Defender on one of your endpoints, or it could be through something else, and then automate it with, uh, with Red Canary and then they send it to the network protection component in Defender. And so that spreads to all your endpoints, um, which is pretty cool. I actually didn't realize— I guess I probably should have— that Defender for Endpoint had this network protection feature where you can add in your own custom network indicators, whether they're domains or IP addresses or whatever. So it makes it a pretty easy way if you have a distributed workforce to be able to send those ban lists across all your endpoints.
One of the big challenges we have, you know, especially now that we've acknowledged we don't have, you know, all our employees behind a single firewall, is getting those network-level controls pushed out to all your endpoints. And it sounds like a great way to do it, like I said, at an automated fashion and making sure everyone's up to date and kind of synced up across the organization. Sounds like a pretty cool thing. Yeah, I mean, it's been pretty cool to see, uh, the Microsoft products continue to evolve too and add more and more features like this. Yep, good stuff, good stuff.
All right, uh, next, uh, we've got a blog from, uh, Coalfire talking more about the ISO 27701, uh, certifications. So some of this article is talking about, uh, the— their accreditation, which we, we talked about last week or maybe the week before, um, how they are now accredited with multiple different organizations to certify people for this new ISO certification, which is based on privacy. But also, um, you know, talking through a little bit with the journey of, um, this getting released and, and market demand for it and things like that, um, you know, basically saying prior to ISO 27701 being released You know, if you were trying to certify someone, you know, for their privacy practices, it was essentially, you know, making it up on your own, um, for what you felt like best practices were, and then, you know, an auditor attesting that you're, you're meeting those best practices. So, um, it seems like there's been pretty good demand for, uh, more forward privacy-thinking companies, um, that want to show that they are meeting a privacy standard, uh, and want to get certified. Yeah, I mean, we certainly didn't plan it this way, but, you know, we did just stop talking about a privacy law going into place in Colorado.
And, you know, there's dozens, hundreds of other privacy laws around the globe that are going into effect. And, and really, there is not a great universally acknowledged standard. You know, ISO has a couple of different privacy-focused standards, but, you know, you got to choose what's going to be best for you. And it's just great to see more focus on creating a standard. And I think that's what Coalfire is working on here.
Really, really appreciate that. And obviously there's still work to do, but they're moving in the right direction there. Definitely. All right, final story from the news this week. We have a blog by Layers.
This is Chris Nickerson's company. You know, we had Chris on the show, what, just a couple of weeks ago? And here he's talking about visibility within emails and macros and, and really why this is so important. Yeah, so this is one of their, uh, more technical blogs, and they're actually reviewing the Splunk Microsoft Office 365 email add-on. So this is, uh, the ability, I guess, for Splunk to pull more data than you can normally get through logs from Office 365— things like DKIM records and SPF and other things like that.
As well as if you have macros that are embedded in emails and other things like that. So, you know, within Splunk you can do threat hunting or do other things against that data to help you figure out, you know, when someone is potentially doing a business email compromise or sending you malware or other things like that. Yeah, I think the metadata about your emails is probably something that we don't spend nearly enough time looking at as a security industry. And, and I think that this is a really nice intro to how one might do that and what kind of value you get out of, out of making that investment. Yeah, and I feel like some of that has historically been just because it hasn't been super easy, right?
Um, you know, even with, with running your own Exchange servers, it's a pain to get those logs. Office 365 previously was, um, you know, kind of a pain to do that, so you kind of relied on a you know, a third-party provider, whether that's your Mimecast or Proofpoint or, you know, Microsoft's tools or, you know, whatever they might be to do this stuff for you. But it was kind of a black box. You just had to assume that they were doing, doing the good stuff. So now it looks like you can get more detail and do some more threat hunting and do some of this, uh, in your own team.
Fantastic. Well, that is it for news. Why don't we, uh, jump over to upcoming events? Yeah, so We have some good-looking events coming up. Speaking of the Colorado Privacy Act, on the 13th of April, CTA is doing a Colorado Privacy Act webinar.
Yeah, and learn a lot more about it there. It's probably a good idea to join that. On the 14th, ISSA Denver has their April chapter meeting. On the 15th, ACES is doing a Women in Security Coffee Chat with Katie Jump. On the 16th, there's a new group in town.
So this is put together by Dustin Lair, who's a member of of the community, and, and he's really just getting a bunch of AppSec folks together to have roundtable discussions. And this, this one on the 16th is called Put the Sec in DevOps: Security's Role in Quality— excuse me, in Software Quality. I think the first meeting they will, uh, have to decide where do you put the sec in DevOps? Is it SecDevOps? Is it DevSecOps?
DevOpsSec? I, I don't know. Yeah, maybe it's a site, maybe it's silently hidden in there, who knows. Yes, the SEC is silent. Um, on the 20th, ISSA Colorado Springs is doing their April meeting.
Uh, also on the 20th, CSA, the Cloud Security Alliance, is doing their April meeting. And fine— oh no, we're not finally— sorry. Um, ISSA Colorado Springs is doing their Cyber Focus Days also starting on the 20th but going to the 22nd. Yeah, it's a few-day event down there. Um, it's one of their big events of the year, so if you're, if you're looking for some some, some learning, that might be good to sign up for that.
On the 21st, OWASP is doing the joint meeting. And, you know, during the pandemic they've been doing a combined Denver and Boulder set of meetings. And so this is another combined meeting on the 21st. Right. And now finally, on the 21st through the 23rd, ISACA Denver is doing their April general meeting.
Um, and yeah, it's 3 days long and they say you can get up to 9 hours of CPE. So if you're, if you're looking for some education and you're interested in the ISACA space, this is probably a really good thing to join. I do feel like in like late, late March and sometime in February too, we didn't have a lot of events going on and people are making up for it now. April is, is very event heavy. A lot of stuff you can go do this month.
Yeah, it's, uh, it's spring. People want to get out and do stuff and that includes virtual events. So, all right, uh, let's move over to jobs. We've got a lot of great jobs this week, Rob, uh, starting with our first job, which is the CISO for Holland and Hart. Yeah, James Johnson is a, you know, he's been on the show once or twice, and he's a friend of the community.
He was a former president of ISSA Denver, just like you and I. Um, he has been the CISO at Holland and Hart for years, and he's— I think he's now the interim CIO, and he's getting to hire a backfill as CISO. So if you're looking to, to to have an opportunity to work for a very large prestigious law firm as their CISO, this is a good role for you. Yeah, sounds cool. Um, Lunchbox is hiring a VP of Infrastructure and Security. I don't know Lunchbox, but, um, they— it looked pretty cool just poking around on their website for a little bit.
Yeah, I think that they make, um, restaurant like menu apps and things like that. That looked pretty cool. Yeah. Uh, Alteryx is hiring a Manager of Cybersecurity Security operations. Um, speaking of hard-to-say names, Nutanix is hiring a manager of security engineering.
CommonSpirit Health is looking for a privacy information security analyst too. Workiva, another name that's hard to say, Workiva is hiring a cybersecurity compliance engineer. Uh, RingCentral is hiring a security engineer. Uh, Red Canary is hiring an information security specialist. McAfee is hiring a sales engineer for the West.
And finally, Redwood— Redwood Trust is hiring an information security analyst. Very nice. All right, well, that takes us to the end of the newscast. We do have a feature interview this week. Uh, we've got Josh Datko, who is the, uh, The founder of— hold on, let me pull this up unless you have it ready to go.
Founder of Cryptotronix. Cryptotronix. That I wanted to make sure I didn't miss a syllable there. Um, Jason Jaques sat down with him or something like that. Uh, Jason Jaques sat down with him this week.
I haven't listened yet. I'm excited to hear what Josh is up to over there and, uh, and get some more learning about local companies that I should probably know more about. Awesome. Sounds good. I look forward to it too.
All right. Well, you guys have a good week. We'll talk to you soon. Thanks, Rob. Hi, this is Sam Masiello, Chief Information Security Officer at Gates Corporation.
This is Colorado Equals Security for Colorado security professionals by Colorado security professionals.
Hello, Colorado Equals Security. I'm Jason Jaques. My interview this week is with a security serial entrepreneur. Josh Datko. Josh is the founder of Cryptotronix, among other things.
Here's the interview. Enjoy. Hey Josh, welcome to the podcast. Thanks for joining me today. Yeah, thanks Jason.
Let's start off— there's, there's a whole lot of interesting things we can get into here, um, but let's, let's start off with some background. Where are you from? Yeah, so originally I'm a one of these, uh, you know, horrible Colorado transplants. Uh, so I've come from, uh, East Coast though. So it's the right coast.
At least it's not the left coast. It's the right coast. And, uh, so, uh, Philadelphia. So I grew up around Philadelphia. Uh, then, uh, I was in the— joined— I was at the Naval Academy.
So Naval Academy is also on the East Coast in Annapolis, Maryland. And then, um, I was 10 years in the Navy and most of it was also spent East Coast. So all the way up, uh, I was in Kings Bay, Georgia, all the way up to, um, Portsmouth, New Hampshire, essentially all up and down the East Coast. Okay, so you, um, you grew up in Philly, and then, um, is— and then from there you joined the Navy? Yep, yep.
Okay, and then, um, I, I do know some of your, uh, some of your background. Since, since you mentioned Navy, let's actually get into that because that's a lot of your formative years, correct? Yeah, for sure, for sure. For good or bad, that's, that's the truth. Yeah.
And you were in the Navy for how long? It was a total of 10 years. I had kind of a different career. I was active duty, then I was reserves, then I was recalled to go to Afghanistan, then I was active duty, then I was out. So I was kind of in and out of the Navy for a total of 10 years.
Wow. Okay. Okay. And then within the Navy, that's how you really ultimately got into kind of the tech space and even security, right? Yeah, for sure.
So started at the Naval Academy. I did this thing called Trident Scholar, which was basically like 5 people a year get to do this research. Mine was in computer science. I was a computer science degree and I got to do some like authentic— don't read my thesis, but basically it was authentication protocol kind of stuff. And then, uh, then I joined the submarine force.
So I was a submarine officer. So, you know, I've got to learn to operate a nuclear reactor, something about radiation is bad for you, et cetera, et cetera. Then, uh, when I was on the sub, I got to be the radio, uh, communications officer, and who's also the, like, crypto officer. Uh, so that kind of got back into, uh— so after a few years of, like, babysitting a nuclear reactor, kind of got back into doing, like, the communication security and stuff like that. Yeah, which was funny.
Um, I want to know more about this, uh, this role that you had on board the sub, because if I remember right, you were telling me a story about how you would do— you almost kind of made it comical about how you were shooting missiles. What is that about? Yeah, yeah. Well, so I was on a Los Angeles-class submarine, and we had— so one of the missions of submarines is Tomahawk missile strikes, and so we routinely practice for Tomahawk missile strikes. So basically, you sit in the ocean, you wait for the order, and you shoot up a couple missiles, and they go.
And so, you know, it's kind of a serious deal. Submarines have been involved from the Libya conflict to Iraq War. So I mean, yeah, we were just doing training, but a lot of times it's super boring. It's like basically the Navy likes to pretend. It's a bunch of grown men pretending to do stuff and you get paid for it.
So, uh, you know, we're pretending to shoot Tomahawk missiles. And, uh, so I'm just sitting there, I'm the comms guy, it's super boring. And I got, you know, this laptop open. I'm in this— it's like Microsoft Chat was the thing that we were using back then. So Microsoft Chat has this mode where you can go to comic mode.
And so instead of the boring IRC, you can switch it to comic mode. And what it does is just, it kind of like makes it into a comic strip. And so like the, you know, now it's a dog talking to a cat talking to an alien. And so, except what our, what ours was, was, is like, you know, our submarine talking to the squadron and it was like, squadron was like, shoot tube 13. And, but it was a dog telling the cat to shoot tube 13.
And the cat was saying, shoot tube 13i and all this stuff. But it was, it was, so I thought it was hilarious. Uh, So it was entertaining me, but then the captain walked by and he just like blew his lid. I mean, he was like, what? What is going on?
Why is a dog telling the cat? Why is our squadron commander an alien? And I tried to explain to him, like, no, sir, that's all— it's all client-side. Like, they can't see this on the server. It's just the client.
He didn't even really get computers. Uh, so, uh, so yeah, so after that I had to give— I had to make sure that no one either mistakenly or on purpose changed the Tomahawk strike shot to comic mode. Uh, that's, that's definitely pretty funny. Um, but these— this was just practice, right? You weren't— this one, this is only practice.
Yeah, well, the Navy does it. You do a lot of— you spend a— I spent a lot of my life looking at the tops of waves and looking at a reactor that's not going to go anywhere. And, uh, you pretend like there's a fire, you pretend there's a radio, you know, radiological accident, you pretend all this stuff, and then you do all these drills. But largely it's, uh, It's 1% excitement, it's 99% boredom, basically. Yeah.
Any of the excitement that you can talk about? Yeah, we did. I mean, so I got to do some pretty cool stuff. The sub I was on sailed around the world. So we left Groton, Connecticut, we went through all the way to the Med through the Suez Canal.
We pulled in Goa, India, then we did around India, we went to Singapore, we went to then Okinawa, we went to Yokosuka, Japan, Uh, Hawaii, back through the Panama Canal, back through the Caribbean, back home. So that was a 7-month deployment. Uh, super, super fun. I was 27 at the time and this was like, uh, yeah, this was one of the, I mean, honestly it was one of the best times of my life. Um, then I was sent to Afghanistan as a submarine officer just to make sure that the Taliban didn't develop a submarine force.
So I was successful in that part. Uh, other parts of our, yeah, other parts of our Afghanistan things are not going so well, but They won't develop submarine force things. Yeah. At least they don't have subs. That's true.
That's true. I did my part. You're the one person that definitely was successful over there. Well, let's just say that. Yes.
That's pretty funny. So how did you— let's talk about how you actually got into security though, as a part of being in the Navy. How did that come about? Yeah, so the Navy now actually has a lot— is dedicating to like the cyber— I mean, as people probably aware, a lot of cyber resources. Um, so I mean, yeah, they have to use the buzzword cyber, uh, but if you look past that, you know, that's— the Navy is really committed to that.
In fact, the Naval Academy— I went back to the Naval Academy just a year ago before COVID and they have a whole cyber division. So none of that existed when I was there. Uh, it was definitely not a thing. I kind of, um, the, the I'm sure now it's on submarines and ships, the cybersecurity is much more improved than it was when I was in. So that wasn't really a— definitely wasn't a focus.
Um, but when I left the Navy the first time, uh, after a brief stint of helping design instrumentation and control systems for nuclear reactors, I ended up working for a defense contractor that was essentially building some of the crypto equipment that I used on the sub. So I mean, that one was obviously, uh, like my My first kind of professional, uh, it was like AppSec, hardware sec, uh, like a lot of embedded development in, in, in software, uh, security for sure. I'm going to show my lack of smarts here. Are subs connected to the internet? They are.
I mean, that, I mean, yeah, so that's okay. I mean, the most common questions I get are actually before that, it's like, where does the poop go? How do people eat and how do you get oxygen? But if we want to jump to how the subs are connected, I mean, I'm just, yeah, yeah. I'm just thinking like, um, in terms of security, I, I guess I just always assumed they're completely like disconnected from the world, but I never thought about it.
Yeah, so I mean, it's no— I mean, so like, uh, I mean, let's take the, the thing that's— that everyone's talking about, which is the Starlink, uh, the Starlink, um, satellite connections, right? So I mean, oh, I mean, basically you can have TCP/IP over, over, uh, satellite connections. So I mean, that's not, uh— I mean, I don't think I'm telling any government secrets to to say that satellites are being used by the military.
Uh, I don't know, maybe we should cut this out just in case. I mean, that's okay. I think we're— I think we're okay. I'm pretty sure if we can Wikipedia it. Yeah, yeah.
Well, so, okay, so you're in the Navy for 10 years, and then, um, and then what? So you got out, you worked for— I got out contractor. Before that, I worked for 3 months trying to design nuclear reactor instrumentation control equipment. Okay. And that one was, uh, like going from a race car driver to driving, uh, like a toy, uh, Tonka truck.
I mean, so I'm, I'm a proponent of nuclear power, but that industry moves in decades, not in days. So at that one, I just couldn't, I just couldn't sit still and do that job. So then, yes, then I worked for a defense contractor. Uh, but doing that, I actually re— kind of like rejoined the Navy as part of the reserves. Uh, so I was doing a defense contract without a defense contractor.
Then also doing the 1 weekend a month, 2 weeks a year gig. That was a pretty epic time. I got to go to the European Command headquarters in Stuttgart, Germany. So I'd go there and then have weekends in Belgium at the Belgian beer festivals, and then I would hike around Germany and stuff. So that was super fun.
But then there's karma, right? So I had to pay for that. So then while I was working at the defense contractor, I got recalled to go to Afghanistan. So then I went to help the counter-IED Basically, I was helping them with jammers to prevent IEDs with the EOD divisions over there. Yeah.
How did that work? Let's talk about that. They're very effective if you turn them on, the jammers. So, I mean, what I was doing was essentially training— there was a few things. It was supposed to be a year and a half, then I ended up only being there for 4 months due to a bureaucratic error, which is a whole story in and of itself.
But Basically, one of the things I did was help train Army, uh, they're called electronic warfare specialists, to how basically the fundamentals of RF, um, like energy, how do, you know, radio, how does radio work, how does a jammer work, how did, how did these things, uh, like work, and how do they protect you. So it was kind of like a very crash course, uh, on, uh, essentially RF jamming. Yeah. Okay, I'm guessing with, with kind of that role Is it safe to say that, you know, you successfully, I suppose, helped some of those people, like, I don't know, save lives? Yeah.
Well, yeah, if I'm not going to be my cynical self, I mean, for sure. So that— I mean, that's the— I mean, the purpose of it was to, uh, I mean, so, so not everybody— I mean, so, you know, the military, I, I'm— it does a great thing in that it takes 18 to 20-year-olds, it gives them an opportunity to kind of do a lot of advanced training and get everything Problem is not a lot of these, uh, 18 to 20-year-olds are necessarily experts in like physics or, you know, they're joining the Army because they want to do Army things. And sometimes they're getting told, oh, by the way, you're going to be the like radio comms expert. They may not have studied in high school physics or even taken high school physics. So, uh, in order to kind of— in order to use this equipment, it was like best to have a kind of understanding of what it's trying to do at a basic level.
So that was kind of the mission over there, was to help train these guys so that they knew Hey, when we're out here and we're dealing with these IEDs, uh, you know, what is a threat? What techniques do we have to defend against it? How do these things work? Yeah, yeah, yeah, that's very cool. So then how did you find your way to Colorado?
So that was largely my wife's doing. Uh, she is a physician, and so not many people know how the physician world works, but you actually don't get to pick really where you get to move. So out of the first 10 years we lived together, I think we only lived together for 2 either a result of her school— we got married right after college— and then either her training or me being in the Navy, we hardly lived together. And so that's because anytime you switch from residency to fellowship, you basically, you don't get to pick. You put in a request and then it's like a ranking system.
It's like a Harry Potter sorting hat kind of thing. So you don't actually get to pick where you have to go. You get told. And so, um, she was fortunately on the East Coast, but eventually she got to pick and then we— she is now working up here at UC Health. But, um, you know, she went out here.
We'd never been to Colorado. We looked at the place and we're like, this is it. Let's, let's, uh, man, there's no reason for us to be on the East Coast. I mean, our family's still there, but there was no job tying us to the East Coast. So we're like, let's come out here.
Yeah, that's fascinating. I had no idea that you, you don't get to pick where you, where you go. Yeah, it's, it's a, it's, they call it, they call it the match. So it's like you put in It's— I mean, you actually don't even get to pick what field of medicine you— I mean, so like you could say, like, you could want to be a surgeon. And so this is dated, and I'm, you know, my wife's a physician, not I, so I could be getting a lot of this wrong.
But, you know, essentially you would say, hey, I want to be a surgeon, and they're like, well, you can't be a surgeon at Penn, but you can be a, uh, like children's, uh, um, like psychologist at this, this hospital, right? So there's, there's 2 things they're sorting. They're sorting program, and they're sorting, I think, the type of doctor you can be. So I mean, it's, it's really less, uh, yeah, it's, it's kind of an interesting— it's a very, very stressful time because you've interviewed at like 11 places across the country, and then you just— it all falls into, uh, uh, like, how do they rank you? How do you rank them?
Yeah, well, you got pretty lucky. I mean, um, Colorado, and, and, um, particularly up north where, where you guys are at in Fort Collins, um there's a lot worse places. Oh, for sure. Yeah. I mean, uh, yeah, fortunately, uh, UC Health, uh, worked out really well for her.
And, uh, yeah, we, we've been up here since, you know, 7 years. Uh, that's kind of when I started, uh, doing Cryptotronix is when we moved out here. And yeah, Fort Collins is great. It's got a— we both lived in big cities and Fort Collins is a nice small college-ish town. Yeah.
And, uh, it's, it's a nice— we then the, the being apart from your wife kind of thing also doesn't help to having kids. So unsurprisingly, now we have 2 daughters, uh, yeah, once we're out here. Yeah, right on, right on. Well, let's, um, you know, so, so you got into the industry obviously in the Navy, but then, um, then you left Navy, you eventually found your way here to Colorado. Um, you're, uh, you're really a serial entrepreneur when I, when I look at all the different things you have going on.
Is that— I try a lot of things. Yeah. Yes. Okay, let's, let's talk through some of this because some of this fascinates me. Um, so there's 3 different companies you've got going on, at least 3, um, which, uh, so you've got Cryptotronix, yep, you've got KeyLabs, and you've got Advanced Security.
Yes. Which one of these do you want to talk about first? Yeah, so it depends on what hat. Yeah, I gotta— I just have to go get a different hat for each company. Maybe, maybe let's, let's talk about Cryptotronix first.
Okay, yeah, that was the first one. So that one, uh, basically what I do with that company is we do embedded security consulting. So I am essentially 98% doing embedded device security. So if you don't know what embedded device security is, you might know as IoT security, but hardware, software, firmware for essential physical things. And so, uh, it's, it's myself and I've got 2, uh, 2 employees, 2 other engineers.
And, you know, for the last 7 years, we've really been consulting, contracting for people who are trying to build devices that want some extra security. So, um, this typically is something like they want to do secure boot, and unlike Windows or Linux, secure boot is different for every chip that you have to do. So we have to build some of this stuff in. They may want to use special cryptographic, um, uh, chips, and some of those require domain knowledge and stuff like that. So these are the kind of like drivers.
We also do a lot of, um, like hardware security pen tests. So I get a lot of devices where it's like, okay, try to You know, you know, a lot of times that for a software pen test, they'll be like, oh, the hardware is out of scope, hardware is out of scope. Basically, I do a lot of the stuff where the hardware is not out of scope because it's physically in someone's hands, and then what can you do with it when the hardware's in scope? Yeah, so this, this kind of reminds me of, um, or I guess, uh, the way I'm, I'm thinking about this, this is kind of the evolution ultimately of what you were doing in the Navy, right? Yeah, exactly.
So I, I've always Starting in the Navy really kind of got into more electronics. I mean, I did ham radio and to be a naval officer, you have to take electrical engineering, for example. So I had to take it and then I had to take it again in power school. So I had computer science by degree, but you have to take a lot of electronics and electrical engineering classes in the Navy. And then, yeah, the defense contractor, I made little black boxes.
And then this is now I can make little black boxes that I can talk about a little more. Yeah, yeah, very cool. And so your customer base for, for this company, Cryptotronix, is this like the Department of Defense? Is this like some of the contractors that do business there, or what? Generally, so yeah, we haven't done any government work.
Largely it's because I don't really like the paperwork. Uh, oh yeah, yeah, I can imagine. It's— I've been going, I've been going my whole career has been going from more paperwork to less paperwork. Yeah. Uh, so that's smart.
Yes. Yeah. So, but you know, it ends up being a lot of industrial. So I mean, a lot of people wanna, you know, make the jokes about the IoT kind of environment and a lot of consumer IoT, you know, definitely has that sense. It's like, why do I need to see what's in my fridge?
Right? But when you start to get into industrial IoT, there's a lot of things that really make sense from a business automation point of view when you have fleets of devices or sensors that are hard to access. So these are the kind of things that, uh, like I think IoT adoption is happening, uh, a lot more than just the, like, I need more beer, please order it for me. Right, right. Well, I do need more beer, so hopefully— I mean, I mean, I would take that.
That would— I mean, I mean, Drizzly. I mean, there's some local security people here that do Drizzly, I think. Yeah, right. So I mean, that could— they could— they should add the webhook, put the thing in your fridge, order the more beer with Drizzly, get it delivered to you. Yeah, there you go.
That's funny. Well, let's talk about the next one. So then the next company you've got going on is, is something called KeyLabs, and I think your, your website is wallet.fell. Yeah, so yeah, so Wallet— so we— so KeyLabs is basically what we've done with 2 other partners, Dmitry Nitesposov and Thomas Roth. And with that, we, we gave a present— so I've done a few presentations at DEF CON, CCC, HOPE, Black Hat, and, uh, one of the ones at CCC that we gave was basically we took— we looked at cryptocurrency hardware wallets So, uh, yeah, so this, this is a trigger warning for people that don't like cryptocurrency.
I'm going to be talking about cryptocurrency, uh, but, uh, the way it works is, you know, you've got, uh, in order to basically make a transaction on the blockchain, you have to sign something with a private key. And the idea, the general idea is, well, if you do it on your phone or your laptop or whatever, that's not secure. So let's move it into hardware where we know all hardware is secure. So they make a custom device to do this. And then we looked at some of the problems with, uh, with doing, with doing that.
And one of which we basically can show how to do a complete break of, uh, if basically if you had the device, we could, uh, essentially recover the private key from doing, uh, what's known as a glitching attack on the device. So, so how often do you, do you do that? Do you help like recover wallets? Do you? Yeah.
So thank you for asking. I do not recover wallets. I get— okay. So, so I just— so this is good. I'm glad you're asking because I get an email probably once or twice per week of someone asking.
So I mean, this is— so I, uh, I, you know, I like some aspects of cryptocurrency, right? There's some things I think that are positive. We have to get into it so that everyone doesn't shut off the podcast, but there are some aspects that I do like. However, uh, because of this talk, and I routinely get, I've lost my PIN, I can't access my wallet, can you do this recovery? I do not do— I do not do recovery of pins.
That's right. Yes, you jogged, you jogged my memory because, um, when we first talked about this, what was actually in the news was that, um, yes, the person that, that, I don't know, had lost $180 million of Bitcoin. Yeah. And, uh, and yeah, you were telling me that, um, that's not what, what we do. Yeah, yeah.
So I, I, that one, yeah. So I'm, I, I, I kind of hope Bitcoin goes down a bit just so I get, I personally get less emails about people asking me to recover, because basically it's proportional with how high Bitcoin is. Bitcoin's almost at $60K now, and then everyone's emailing me. Back when it was at $20K, I had lived a nice quiet life where no one was asking me to recover their wallets. So, um, the thing, the thing I'll say is that that talk, we've, we disclosed everything, so you could do it yourself.
There's, there's nothing I'm holding back. It's just that I do not do this as a paid service. Yeah, yeah, that's very funny. So are you a, um, Um, a cryptocurrency guy yourself? Do you, uh, do you invest in some of these coins?
I do. To be, to be full disclosure, I have basic— I have like, uh, what's called is like, um, I just have like a small amount. Like I don't, I basically got rid of all my personal position in cryptocurrency. I personally, while I'm a fan of it and I think there's good aspects to it, I think it's kind of overvalued at, uh, at the price it is now. So I do.
Yeah. I'm right there with you. Um, okay. Anything else notable or interesting to share about KeyLabs? Yeah, no, that, that's, that's essentially, yeah, that's essentially the KeyLabs equals cryptocurrency is kind of the short answer with that one.
So do we do all the consulting stuff? Your blockchain consulting company? Yep. That's right. That's right.
Your final company is Advanced Security. Tell me about this company and how did this come about? Yeah. So Advanced Security, again, it's the same kind of group that I was working with. Uh, with KeyLabs.
What we, uh, essentially, that's a— it's a hardware security training company. And the kind of— and there's, there's a bunch of those. Um, but the kind of difference that we think we bring is that we really jumped on the kind of streaming online training, uh, thing as that happened, uh, with COVID-19. So, you know, we were supposed to give— Dimitri and I were supposed to give an in-person private training for a private client like April of last year. And as things kind of developing was clear, like, this isn't going to work.
And then we're like, all right, let's try it. Let's try it online. And, uh, you know, since then we built basically our own streaming platform. Um, so I mean, I have, uh, I mean, we were chatting before this podcast, but I've got like the streaming lights, I've got the camera, overhead cameras, I've got HDMI switchers. And, uh, we do hardware security training in a way where you can see it.
Like, it's, it's more of like a Twitch stream than it is, uh, like a Zoom call. So when a student is taking our classes, they see an HD, full HD recording, or livestream rather, and they can interact with the chat and they will see top-down cameras that our oscilloscope has an HDMI out. So we're really trying to mix in a bunch of different video feeds and kind of like really focus on online hardware security training. Have you noticed that that's, I guess, picked up, the kind of the online virtual training now, obviously with With kind of quarantine and COVID and yeah, I mean, I think, I think any training, I mean, so the thing is, you know, companies have training budgets and they, and they also have, uh, like they're constantly hiring. So, I mean, largely, you know, I mean, fortunately to the technology industry, we know largely wasn't, you know, I mean, it was one of the industries that, I mean, every— everybody was affected, but I mean, uh, it was one of the industries that could obviously adapt better than some of the other industries.
So I don't, I don't think from a training point of view, there's still demands that have to be met by companies to get their employees trained. So, um, and then with lack of— I mean, certainly with a lack of a physical, uh, in-presence, I mean, uh, I mean, that's kind of what we saw was the opportunity to kind of take this online. Yeah. Do you ever see in-person training, um, kind of returning to, to what it used to be? So I, I think it will.
Uh, I mean, so I think there's going to be— so I think 2 things about this. So I think, so I think So for sure, people are going to want to do in-person training. I also don't think online training or online or hybrid remote work is going to go away. And so I think what— and the kind of— I kind of believe that like that joke that's kind of like everyone sees on like LinkedIn and Facebook is like, who led your digital transfer transformation? Is, you know, A, B, or C, and C is COVID-19.
Yeah. Um, so, uh, I mean, I think there's lots of benefits to— I mean, so there's lots of benefits to doing the, um, the training in this format, both for the students and the instructors. So the students The thing is, you can be watching the recording or the stream, and then you can pause the stream. So if someone— you got to go to get Amazon or UPS signature, you can pause, come back. If there's something you missed, you can rewind it.
So these are things that you can't do in an in-person class. Now, the downside is that obviously you kind of have to manage your own time, manage your own focus and concentration, but I mean, we've all had a year to basically practice that. So I think A lot of the— and then with hardware, what typically comes up is like, how do you do this with hardware? How do you, how do you look over someone's shoulder and, and see that they're plugging the wires the right way? And a lot of it was we just adapted to, uh, you know, focus on, uh, hardware where that is easier to do.
And because of that kind of camera setup I was mentioning before, you know, you, you— the students almost can see what we're doing, uh, even better because now I can zoom in with a microscope and zoom in and see a chip where, you know, You wouldn't be able to see that before. You can see the oscilloscope screen instead of being huddled over a table. So there's lots of benefits, I think, to actually doing it online versus in person. Yeah, yeah, that's great points. So what is, uh, what's next, um, for, for you?
And, um, I'm guessing that the 4th company you'll eventually create. Yeah, yeah, I, I, I think for now, yeah, so for now there's no, uh, there's, there's no 4th one in the mix. Uh, I did try to, uh, I mean, I, I've, there was, uh, I watched a lot of Black Sails this last weekend. I was thinking of some pirate company that maybe you could do, but unfortunately there's a lot of legal repercussions to doing pirate companies, but I highly recommend that show Black Sails. Um, yeah, no, we're, uh, those, those 3s are keeping me pretty busy.
Uh, I think the trading is, uh, I mean, especially with that format, I really have liked doing that. Um, fortunately, there is a lot of, uh, I think the IoT— as the IoT stuff keeps picking up, there's a lot more to do with security. Um, and I think that's getting more attention. Uh, so I think that's going on. And like I said, the cryptocurrency thing, as long as it's that— the amount of inquiries we get in that is directly proportional to the price of Bitcoin.
So, right. And then, uh, we should mention, so Advanced Security, um, your website is advancedsecurity dot training, right? That's right. Okay, perfect. Make sure we get that, that plug in.
We've got just a little bit more time. I know that you're involved in something called Engineer in Residence. I want to get to this before we run out of time. Tell me what this is. And yeah, how did you get involved?
Yeah, so this is a super cool program that CSU is doing up here in Fort Collins. And it's with the local IEEE chapter that kind of started it up. And essentially what the idea is, is they get, uh, so it's not necessarily security related, it's more like electronics related. Um, but what they do is they get, um, they've gotten kind of, uh, because, you know, HP is up here and, um, uh, Agilent and, you know, so there's some big electronics company up here. And other— essentially what the idea is, you get these kind of industry, uh, professionals to kind of go— pre-COVID, we would go to CSU And we would sit in their electronics lab and we would help mentor undergrad computer engineering students.
And so they would come in either with their project or CSU undergrad students have to do a full year-long project. So their last culminating year is this giant engineering project where they got to work on a team and build something, and we would help mentor them. And so just like everything else, COVID hit, and then we just do that online now. Uh, but like the, the group I'm mentoring now is— just happens to be, uh, cybersecurity related. There's these 2, uh, students who are doing this vehicle cybersecurity study of trying to do machine learning for, uh, on-vehicle, uh, like CAN bus kind of data to do, uh, intrusion detection.
So they've got a really cool project, uh, and essentially they meet with me, like, I think it's like once a quarter. We kind of do like a check-in, a status update. I give them ideas. I give them some like, hey, this is, this is what worked in industry that wouldn't— maybe you should look in this direction or not. And so this is going on all throughout there.
Like, there's basically an equivalent of me paired up to every team at CSU. So it's a super cool program that the IEEE chapter here is doing. Yeah, that's very cool. How did you get involved with that? I think so.
I was on the IEEE mailing list, you know, just like I'm an IEEE member. And so somehow, you know, they put out this call and I was like, oh, you know, that, you know, I remember I mean, so I remember, so like I said, I was computer science when I was an undergrad. And despite me, I mean, I call myself an engineer now, but when I went to undergrad, I actually had no idea. I didn't know what an engineer was. So, um, like to have somebody, there's a really big disconnect, I think, between academic engineering and then what is actually done.
And so this, if someone was to like come back to me as an undergrad and be like, oh, this is what you do as an engineer, this is what an electronics engineer does. And then that would, I was just like, I mean, if someone just spent 5 minutes telling me that, I mean, I would've clarified a lot of questions I had. So I mean, I thought this was a pretty cool way to kind of share some of that experience. As we look towards the future, you got a lot of different kind of areas that you specialize in relative to security. What do you kind of see as the next 5, 10 years and how the industry and where things are going to change?
How are you viewing that? Yeah, it's, uh, I mean, I think to a large degree, I mean, there's, I mean, so there's a couple of things. And one is that there's like the, uh, the, one of the reasons I like security is that there's always this constant change, right? So it's, it's, uh, the attacks are always getting better and the defenses are getting better and there's this constant cycle of changing it. So, so to a large degree, I don't really see any difference in that.
It's the only thing that really changes is the technology and the techniques. But basically, for, you know, uh, I mean, so it's, you know, the started off like web security was horrible, you could do all these easy things, and then that spins, that gets more mature, that eventually kind of plateaus, uh, the attacks get more sophisticated, they get more sophisticated, and then they actually get more— they get, they get more damning to a way, right? So because they, you know, more sophisticated attack, the more damage it can do. And I think it's just that just rotates to every new industry. So Internet of Things security Uh, is, uh, you know, as everyone kind of thinks, it is, it's definitely lagging as far as maturity, uh, as far as like some of the cloud security.
But there are, there's improvements in that as well. So I mean, I mean, I think, um, that's where I spend a lot of my time is on the embedded side. I think that is going— the defenses are going to get better there. But also then we're going to go through another cycle, the tech's getting better, and then it's just— I mean, that's the— that's to cynically summarize the security industry. I think that's the That's, it's always in a constant churn of responding to these attacks.
Yeah. Yep. Jobs are always going to be there. That's kind of how I see it too. Yeah.
I don't, I mean, the fundamental, I mean, I think the fundamental problem is that, you know, the computers that we're using are general purpose computers that are Turing capable and can do, they can do whatever computation you give them. So the fact that it tells you not to do something, uh, I mean, it's, it's only like a smoke and mirrors game to prevent you from doing it. I mean, like the hardware is capable of doing anything. And so that's kind of one of the reasons I'm interested in the hardware, because it's— I mean, that's where I think you start with the security foundation. Yeah.
Yeah. Very cool. Very cool. Well, any final thoughts for the Colorado Equal Security community? I know that you're on the Slack channel now, which is awesome.
Yeah. Thank you for that. Yeah. Yeah. What do you think of it?
And yeah, final thoughts. Yeah. I mean, this is— I mean, it's kind of impressive. I mean, I think I joined and then It's the one of the reasons I kind of faded out of it because it actually got so big. I mean, which is both— I mean, it's both a blessing and a curse, right?
I mean, it's, it's pretty impressive to see the— I mean, I, I wouldn't— I mean, in Colorado, uh, I mean, like, you would think, like, you know, these other hotspots would kind of— which I won't name to give them any, uh, credit— but you, you other ones would come there. But I mean, it's pretty impressive to see that this is kind of the nexus for the security industry, uh, kind of. I mean, I, I think there's a growing— I'd like to see obviously more hardware security people, more embedded, uh, but there's the operational security channel, uh, which I think is where everyone's hanging out who's got, uh, some electronics kind of background. So I, I, it, you know, it'd be nice to always see more of that kind of side of security. It's just from a personal bias, but it is pretty impressive, that group that y'all have been meaning to grow.
Yeah, very cool. And I'm definitely, uh, definitely glad you joined me today and that you're a part of it. How do people, uh, find and follow you on social media? Yeah, so LinkedIn is kind of the one that I am. So I'm just Josh Datko on LinkedIn.
Uh, that's the kind of one that I, I do. I'm pretty— I try to be pretty active. I do like short little 5-minute security, uh, they're like non-markety kind of just like what is, uh, this hardware security concept. So that— I'm there. Cryptotronix.com is that one.
KeyLabs and then advancedsecurity.training. Yep. And you have your own YouTube channel, or is it the company's? Yeah, basically I do. Yeah, I'm not— I, I, despite me doing streaming, I, I don't consider myself a YouTuber, so all the videos that I do end up back on Cryptotronix.com if you want to see.
Okay. Uh, yeah, so we have it, we do a video, but I, I, I, uh, yeah, uh, YouTube, I, it's— I think I'm a little too old for the, for the fun of YouTube at this point. But yeah, well, Josh, thanks for joining me today. This has been a lot of fun. Yeah, it's been super fun.
Thanks for having me. That concludes my interview with Josh Datko. Be sure to follow and support Colorado Equal Security on Patreon. This is Jason Jaques saying be safe out there. Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado equals security.
Reach out to Alex and Rob by emailing info@colorado-security.com.
Until next time, remember. Colorado equals security.