All episodes

Jacob Torrey, Head of Labs at Thinkst Applied Research

Apple Podcasts Spotify SoundCloud

Jacob Torrey, Head of Labs at Thinkst Applied Research is our guest this week. News from Orbit Fab, Edifice2120, Secure64, Coalfire, Webroot, Red Canary and a lot more!

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript11989 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 223, the week of August 30th, 2021. Alex, good to see you.

Good to see you, Rob. We have beautiful weather today, although yesterday was— the air was terrible. Yeah, the afternoon. I'm curious. I meant to look it up, but I never did.

Was there a fire around here, or is it still just smoke coming in? Because it seemed like it was different. It did. It seemed significantly worse yesterday than it had. Like, it smelled— it was gross yesterday.

Yeah. As gross as I think I've ever had it be in Colorado. Yeah, it was pretty nasty for sure. Well, hey, speaking of nasty, let's do some housekeeping. We do have a Slack community, and You know, we've, uh, we've surpassed the 2,000 member mark this last week.

Uh, that was nice. I like the little, little bugle there. Uh, yeah, it's, it's crazy. We, we got to 2,000. That's awesome.

Um, if you want to join the Slack community, go out to the website colorado-security.com and, uh, send us a little form. We'll get you invited. Or if you know someone that's already in there, they can invite you through the channel itself. Uh, We also have a mailing list. We send out show notes every week to that mailing list.

While you're on the website, you can sign up and get an email sent to you every week with the show notes. You know there's a new episode. We'd also love it if you would rate us and subscribe on your favorite podcatcher. That'll help other folks find us. And of course, it'll make sure you get the show in your inbox every week.

Because this high-quality conversation doesn't come without a little bit of effort on your side. That's right. Also, we'd love it if you tell a friend, let them know all of the great things happening with Colorado Equals Security. You know, we were just talking about before the show, Rob, in the Slack channel, there's a book club. So, you know, tell them if they like books, we have a book club.

They can come and read books and talk to other people about it. And big thanks to JD Burke, who's been running that. We appreciate your efforts to keep that really valuable thing moving forward. Also, we do have a Patreon campaign. If you'd like to support Colorado Equals Security financially, you can again go to the website and find the link to the Patreon campaign and sign up there.

All right, cool. Let's jump into the news. We have our first story is kind of jumping back in time, Alex. And there's a train— Wayne's World reference for those of you who are too young for that. The Big Boy number 4014 steam engine was built back in the 1940s, and it's going to be making a reappearance here in Denver soon.

Yeah. I've never been a train guy, but it was interesting reading some of the stats on this. The Big Boy 4014, which is the model of this number of this train, is the world's largest operating steam locomotive, and it weighs over 1.2 million pounds. That seems really big when you look at it and someone goes, man, that's big. What do you think it weighs?

Like a million pounds? Yeah, it weighs— it weighs more than a million pounds. No, no, it doesn't weigh 1.2 million, my friend. Yeah, it's gonna be big. So if you really wanna impress your friends or your kids or your loved one, take them by the— it's on Labor Day, it's gonna be by the— at WinCoop, 38th and WinCoop.

You can go see the Big Boy on display. It's gonna be there available from 9:00 AM to 3:00 PM. And I think there's actually tours you can go walk through it. And as you walk through, you can be like, you know, this thing was created in 1941, and initially it was coal-fired, but now it— coal-fired powered, now it's steam-powered, they converted it. Could be that guy.

You could be that guy. One other cool thing, to go see it and tour it is free, 100% free. Although they do note in the story that parking is not free. You might have to shovel some coal or something as you're there. Because 1.2 million pounds worth of train is a lot of work for people.

And they might ask the free people to do some work. Yeah, exactly. All right. Next story. You know, there are things that don't require coal to be powered, Rob, especially those things in outer space.

But when satellites are up there, eventually they sort of run out of gas. So there's a company moving their headquarters to Denver that helps refuel those satellites. Yeah, I had never thought about this. I had neither. So the name of the company is Orbit Fab.

Currently, it's a 15-person company with 3 folks in Colorado. Like you mentioned, they're bringing their headquarters here and plan to expand by as many as 196 jobs. So we're not kidding around. You know, when they do these, that always is a little funny to me. It's like, we're a 15-person company, but we're gonna expand by 196.

Not 195, not 200, 196. We had it all figured out. But the reason for the number is because they're getting some tax incentives based on, based on that number. So they had to be pretty specific. Anyway, interesting stuff.

The, you know, these satellites go get into orbit, and they have enough fuel to to correct any problems with their orbit for a certain amount of time. So that'll keep them orbiting the Earth. But eventually, they run out of gas. And when that happens, they make contact with the atmosphere, and they burn up, and they're no longer an effective satellite or a satellite at all at that point, right? And Orbit Fab, they're here to say, well, actually, we've got a whole tank of fuel behind us, you can go fill up your satellite on us and, and keep that thing working for for an indefinite amount of time.

Yeah, it's pretty cool. One of the things that I thought was interesting, and I guess I really never thought about it, the fuel source that they use is hydrogen peroxide-based fuel. Which again, if you would have told me, hey, what's the fuel for satellites, I would have not, not have said hydrogen peroxide. No, I would not have either. So that was pretty cool.

What do you use to make your hair light color too? I think you could probably— or you bleach your hair, isn't that frequently with hydrogen peroxide. Alex, isn't that what you use all the time? Every day I use that to bleach my hair. Also, this company was the first private business to resupply the International Space Station with water back in 2019.

So now I'm curious who did it before that. It was like one of the governments must have done it. Yeah, like NASA or not a private company, whatever. Russia's Russia. Yeah, yeah, there is.

Anyway, cool stuff. Looking forward to seeing Orbit Fab kick butt. It looks like they were looking for headquarters spaces in Broomfield, Denver, Boulder area. Very nice. All right.

Next, we have an update on a story from a man I feel like a long time ago. So Sports Castle, it's called the Sports Castle. It's the building on South Broadway where Gart Brothers, I think it was their first store. It was definitely the big cornerstone store here in Denver for Gart's and then also later for Sports Authority. Uh, when Sports Authority went, went teats up in 2016, um, the Sports Castle has basically been abandoned, uh, since then.

They haven't had any official thing on there. Well, now there's a new plan. Yeah. So, uh, this has been, uh, taken over by a developer and they're going to, uh, turn it into a multi-use, uh, building. First floor is going to be retail.

Uh, I think the rest of the building is going to be office space and then they're actually going to build some new space off of the roof. Um, which I think is gonna be used for events, but then also for the, the folks that are in the building. So, you know, you guys call it Sports Castle. I call it the Cullen Thompson Motor Company building, uh, because originally it was the, uh, Chrysler Automobile, automotive, uh, showroom in there in Denver. Uh, did of course later turn into the Sports Castle.

Um, I, I thought there was another interesting thing, you know, th— this construction to turn to, you were talking about where it's gonna be retail and and residential doesn't— or excuse me, an office doesn't actually begin until 2023. And until then, they've made a deal with a company that does— they'll do like an entertainment venue out of unused businesses. So it's going to be an event space by partnering with a place called Non Plus Ultra. And they basically work to do like concerts and other entertainment in this kind of venue. So maybe you'll be seeing a show at the Sports Castle over the next couple of years.

I think we need to have a Colorado Equal Security party at the Sports Castle. I can't see how that won't happen now that you've mentioned it. All right. Good stuff there. Moving on.

Denver has a new coworking space, and this is actually centered around women in construction. Yeah. I mean, holy smokes. That is an interesting nuance. I think of coworking as being like lucky if you can get anyone.

And they've— they're focusing on this. Market that's relatively small, which probably means it's going to be wildly successful because, you know, you're going to be around people who do exactly the same thing as you. I love that. Yeah. So, uh, Jennifer Acosta, uh, who is the founder of Environmental Consulting Services, which is a construction company, um, decided that, uh, she wanted to, to found this space.

She actually, um, has had a space and then part of it became open and she had been thinking about this idea for a while. I think, you know, for her earlier on in her career, she wanted a space like this where there was, you know, a supportive environment. And obviously, you know, construction has not been historically a female kind of business. So, you know, her thought was, hey, we can bring women together in construction and help move it forward. Yeah.

So the business or the new coworking space is called Edifice 2120. And I'm not sure what the 2120 is referenced to, but Maybe it's the address, and they're gonna have a monthly membership option. And those— the fees start at $850 a month. So if you want to be a monthly member and have access all the time, it's gonna cost you— that's a pretty penny. But, you know, the value is there's gonna be a lot of folks around you helping you be successful with your career.

Hey, Rob, did you know that the building is located at 2120 West 7th Avenue? I didn't know that. Well, hey, now you do. And that does make sense why that would be in the name. Putting the pieces together.

On this, on the spot journalism here at Colorado Equal Security. We're investigative journalists. Yeah, reading the story and figuring out what it says. Good stuff. All right, moving forward, we have a press release from Secure64.

You know, we haven't heard from them in a while, but really what they do is DNS at scale for, for large providers. So what are they doing now, Alex? They have released a new service, I guess, piece of hardware. Uh, that is a DNS proxy to help manage DNS over HTTPS traffic. And the, you know, the value prop they're talking about is, is for the providers who are customers to Secure64.

Um, you know, DNS over HTTPS has become very popular, and, and if their, if their end users are using it and the providers don't offer it, basically all that traffic is leaving their network. They're not getting visibility, and they're not getting the reliability that they'd get from knowing what's happening on the network. On the other side, it's, it's quite expensive and difficult to do DNS over HTTPS. So you don't want to throw that onto your existing proxy. So here's a brand new device that they can use for this to remove some of that load and, and keep providing those services to customers.

Yeah, uh, sounds pretty good. Probably not applicable to most of us, um, but, uh, but yeah, for all those service providers out there, it seems like an interesting service. I'm, I'm so confused though. Can you Can the service providers actually make you use their DNS over HTTPS proxy, or couldn't you just go to wherever you want because it's HTTPS? So how are they going to stop it?

I couldn't figure out exactly. Like, it sounds like they're saying don't let that traffic leave, like kind of make sure you keep it on. But is that— is there any way to actually do that? I don't know. It's a good question.

Um, I don't know if there's, uh, some header or something that you can key on to route the traffic to the right place or Yeah, who knows? We should probably call up like a Mike Benjamin or a Mary Haynes who would probably have some visibility into those things, traffic leaving their environments. They would have some visibility if they were using this new service from Secure64. Maybe we can make a sales call for Secure64. All right, next story.

The National Cybersecurity Center down in Colorado Springs has released a statement on the White House Cybersecurity Summit. So this was interesting. The, you know, as we know, over the past couple weeks, was it 2 weeks ago? They, I guess, or maybe just a week ago, they, the White House had a bunch of folks from various tech companies in to talk about cybersecurity, including Microsoft and Google and other things like that. And I think that the big news that I've seen out of that is that, you know, everyone's agreed to spend billions of dollars on security, which they were probably already going to be spending anyway.

But NCC was congratulating the White House on, you know, having this summit and also wanted to make sure that they were paying attention to the states as well, that, you know, there's a lot of good information there. And coincidentally, the NCC also provides training to states on cybersecurity. Yeah, I mean, if you're going to have the National Cybersecurity Center in your backyard, as we do, um, you're gonna have to talk about it when it issues these kind of statements. There's not a lot here, you know, you know, they basically pat them on the back and say, hey, by the way, we're doing some good stuff with states as well. That's all true, um, but it, but it's nice to see these guys engaged and, uh, looking forward to seeing, you know, what kind of next steps the NCC does that we can, we can help talk about for sure.

All right, moving forward into news, we got a blog from Coalfire. Uh, this one's interesting there might be some good conversation here. The headline is Crypto Vulnerability Management, which could mean anything or nothing, but really what it is, it's a blog talking about there's an inflection point coming. And the author of this blog post is saying, you know, you've been spending some time making sure your secure coding practices are good for web apps and other apps, but as we start to move to distributed computing, you know, call it blockchain, and using things like Ethereum for what do they call those contracts, like digital contracts, whatever the word is for contracts in Ethereum. As we start to use that, there are new things you need to consider in your applications.

And as security people, that's you, whoever's listening, as a security person, you should be thinking about how to get your company ready for doing coding in this new distributed computing fashion. Yeah, I think on one hand, this is really interesting because if you are developing those kind of apps, there are different considerations for sure.

They work, I think, fundamentally different than the way that we have been thinking around application security. So there are different threat vectors and different kind of vulnerabilities. And if you're not thinking about those, you could end up with some really bad things happening. On the other hand, I don't know about you, but from my perspective, Are people really developing many applications around this? Right.

You know, your sort of average company that is doing development? I don't know. Financial services companies that are building things, maybe. That seems to be where a lot of this activity is happening. But beyond that, I mean, are people building smart app or smart contract apps?

I don't know. So the way this is written, it feels a little bit like someone telling you about the cloud in 2010. Right? Like, the cloud's coming and you're all going to be using it. Get ready for it.

And by the way, that message was true, right? And, you know, if you got your security plan in place before your company moved over, you looked really good. And, you know, you've probably gotten a promotion since then. I just don't know if this falls into that same category. And I'm curious.

I'll be honest, like, when I heard— when I read it, I wasn't— I'm not ready for my programmers to start putting things on distributed ledgers. So, Now I need to do some thinking and determine, do I agree with the premise of this article? There are a few good links in the article as well. So I'd say check that out. There's a link to Ethereum security documentation.

There's also a link to a framework, the Smart Contract Weakness Classification and Test Case Registry. So I think if this is something that is interesting to you, why don't you take a look at those things and learn some more about it? Yeah. And there's also a couple other other blog posts earlier in this series that I don't know that we read that gives some more backgrounds if you're curious. All right, moving forward, we have a blog post from Webroot that's NIST's ransomware guidelines look a lot like cyber resilience and is talking about ransomware.

Go ahead, take it away. Yeah, I was going to say, I think that they were poking at the NIST guidelines a little bit. It sounded like Webroot had released some cyber resilience guidelines earlier. And later on, NIST came out with their ransomware guidelines. And, you know, from Webbert's perspective, it was very similar, which I guess is a good thing.

I'm not sure if they're poking or just trying to be like, hey, look, they're showing you we were right before. Yeah. Either way, it's, you know, there's good guidance in here. And really a lot of it is about being resilient against ransomware. That's how it felt to me is ransomware has become the number one thing that is destroying companies these days.

And, and they're really giving you some guidance for how to be prepared for it. And if you were wondering, while they are not bad recommendations, the NIST guidelines are not anything that, that you will be surprised about. Things like, you know, making sure that you have antivirus and other stuff like that. Oh, good guidance. Good guidance.

All All right, last piece of news for the week. There's a Red Canary blog talking about incident response planning and when to call the lawyers. So this is a different blog than usual from Red Canary. Usually we're in here and the first quarter of the article is written for folks like you and me, and then the rest of it is written for folks way more technical. This was written by Red Canary's general counsel, and it is really about preparation and when to include lawyers and really thinking about, incident response from a more programmatic risk perspective.

Yeah, um, it's actually a really good blog post. The, you know, they talk about, uh, the different phases in incident response and, uh, how legal plays into that. And, you know, as I read through it, I thought, oh yeah, you know, these are basically all of the things that I would have said if I was writing this blog post myself. Well, there you go. You could be, you could be the general counsel for Red Canary then.

I, I don't think you really want that, so, but I could be. So, uh, Matt, Matt Spahn, the general counsel there, he, uh, he previous to being at, at Red Canary, he was actually running a lot of incident response, uh, legal engagements as a, as a private practice lawyer. So, and interesting stuff. He has, he has an interesting perspective and has been through a lot of these. Awesome.

So yeah, if you're interested in, in that, take a look at the blog. Good stuff. All right, jumping over, we have a Slack message of the week. Big thank you to Andre Gaeta. Andre's been paying for this out of his own pocket.

You know, you are, uh, you're appreciated, Andre. Thanks for what you do. Each, each week we get to identify one winner who gets one item out of the Colorado Equal Security store. And this week is, uh, this week, Rob, uh, it was a very easy choice. Uh, the winner is Kevin Ekbatani, who was the 2,000th member of the Slack channel.

Yeah. Woo. Yay. So there was a, there was a little bit of controversy around this, uh, as as he joined and it said number 2,000, and then all of a sudden the number ticked up to 2,001 without another person joining, right? And everyone was like, well, what just happened here?

I— we need, we need to audit the, the election results. Um, good news everybody, I, I've looked into this and there's no problem. It's, it's all just fine. It was actually that there was a new invitation that had not yet been accepted that happened there that made it tick up by one, and apparently Slack counted the invitation as a plus one. Interesting.

There you go. You know, if I was getting married and all of the invitations counted as plus ones, then I'd be okay because those people probably wouldn't actually show up and then I wouldn't have to pay for them. I think you have to pay for it anyway. All right, moving over to events. It's just a reminder we have a calendar of events if you want to come see what's going on.

It's starting to get fleshed out a little bit through the end of the year. It feels like there's a trend where different organizations will, like, in January timeframe, post like their whole first half of the year, and then the summer comes and everyone just like stops posting their events and stops having events. And then people go back to school and all of a sudden the rest of the year flushes out. That's where we are. The rest of the year has been flushing out.

And if you want to go see what's going out through December, I think you can get a pretty good idea. Sounds good. First up, ISSA Denver is doing their September chapter meeting on the 8th of September. Then there is the— is it— I don't know how you say this. It's Women in Cybersecurity.

I think WISIS. WISIS is the name of the group. So WISIS is a national group that is women in cybersecurity, and they were supposed to have their national conference here last year. And then, you know, some kind of crazy thing happened to disrupt it. I don't know what it was.

Weird. I'm surprised they didn't have it. Yeah. And but they are, they are coming here now and it's going to be September 8th through 10th. This is an awesome opportunity to get to support women in security, whether you are a woman or you're not.

This is a great group of folks to get involved with. And if I remember right, they're doing that out at the Gaylord by the airport. On the 9th, SecureSet is doing a virtual Cybersecurity 101. And then on the 10th, we have the group that's really focused on AppSec that doesn't have a name doing their What Is Your Software Security Purpose? I think we really need to push Dustin to make a name for that group so that we can stop saying the AppSec group that we don't have a name for.

It's very awkward, isn't it? It is a little awkward. The meetup group that talks about security. Clearly, it's about us. It's all about us.

All right. Those are the upcoming events. We also have some jobs we want to talk about. Rob, any Red Canary jobs? Yeah, I got a few jobs worth mentioning.

I'm looking to hire a director of corporate security right now. I'm also hiring multiple product security engineers. That's if you're— I should mention, director of corporate security is like running the internal security program for Red Canary, protecting that company. Uh, right, the product security engineers. If you're a developer or someone who has a really good experience with coding and application security, we'd love to hear from you as we help embed security into our products.

And then a brand new one this week, we're hiring an IT support manager. This is, uh, the person who will help report to our director of IT and, and help make sure that we're giving high-quality support to end users. Nice. Uh, I don't know if this is, uh, DAT or DAT, but it's one of those. Freight and Analytics is looking for a Director of Information Security.

And then Frontier Airlines is looking for a Director of Cybersecurity. Maybe it's just me, but I feel like that job is open a lot. Red Robin is looking for a Manager of IT Security Operations. You want to work with our friend Jacob Rubin, who's the new CSO over there. Visa, I actually put this one in because I wanted to have the longest job title of the week.

Candidate. Visa is hiring a senior cybersecurity engineer, cybersecurity access management, enterprise systems. I think that's the winner. Empower is looking for a legal specialist for privacy. And finally, Coalfire, who we mentioned earlier, local security company, is hiring a vice president of customer success.

Well, that sounds fun. And that is it for jobs. That's it for the newscast as well. We do have an interview this week. Just a couple days ago, I sat down with Jacob Torrey, who is—I mean—he's been in the community for a long time.

He's currently the head of labs for Thinkst. It's Thinkst Canary. Yeah, but it's actually Thinkst Research Group, I think. But but Jacob's done a lot of cool stuff, and I think you're going to enjoy the interview with him this week. Awesome.

Thanks, Rob. All right, we'll talk to you guys again next week. Hello, this is Benjamin Edelen. Chief Information Security Officer with the City of Boulder. This is Colorado Equals Security for Colorado security professionals by Colorado security professionals.

Welcome to Colorado Equals Security. Uh, we're doing an interview today. I get to sit with a longtime friend, Jacob Torrey. Jacob is the head of Thinkst Labs at Thinkst Canary, a security company, but you are once again, after a little bit of a break, you're once again a Colorado person. Jacob, welcome to the show.

Thank you very much. Glad to be here. Uh, I, you know, we've, we've known each other for, I don't know, 5 or 6 years, maybe longer. And, uh, you've gone through a few interesting roles over that time, and I'm excited to talk about that and really kind of how you got into security. But first, I, I, I want to talk about this, I don't know, unhealthy obsession you have with putting your body through terrible, terrible experiences.

Can you talk to me about what you're training for? Yes, I guess, uh, I've been running a lot of ultra marathons over the last few years. I got into it actually when I was away from Colorado, uh, ran my first 50-miler out there and then Virginia. And, uh, basically been looking for, for fun races out here in Colorado that lets you, um, see a lot of terrain. Um, sometimes the ground in front of your feet as you're huffing and puffing, and that's all you can really do is stare down at your feet.

So I ran the good part of the Ouray 50-mile this summer, uh, Silverton 60K, and I have the Telluride Mountain Run coming up on Saturday, which is 24 miles. So technically not an ultra, but it does have almost 10,000 feet of climb. So it's still a long run. So you're talking about basically climbing, uh, you know, more than a 14er in as you're running a marathon. Is this, is this what you're telling me?

Yeah, um, it's, it's definitely a long day out, um, but you know, it's really coupled with, you know, a lot of the ability to kind of explore a lot of beautiful terrain in Colorado that's off the beaten path. You know, a lot of these are singletrack races and you're getting places that are, you know, there's no OHVs, there's no ATVs, there's no one else out there because, you know, you really don't want to go and hike 20 miles to get somewhere. So it's, it's a great way to see Colorado. What an amazing thing. How did you— I mean, were you running other kinds of running before you started doing this?

I'm just curious how you even got to think that this was a good idea. Yeah. So the, the, the level of what is crazy just keeps sliding away. So I ran a half marathon, uh, when I was living in Denver and I thought, that's great. You know, maybe I'll do a marathon just once in my life.

And I did a marathon. I was like, that's great. I don't think I ever need to do that. And then a couple months later, you say, well, 50K is really only another 5 or 6 miles, and that's, that seems reasonable. But a 50-mile, now that's crazy.

And then you do your first 50K and you're like, well, it's only another 11 miles. And then, you know, you just kind of keep ratcheting up until you get to the point where 100 miles seems pretty crazy. And then there's the 200 or whatever plus ones that are still crazy, but, you know, 100K is, is, is a pretty reasonable distance to go out and run. But It does slowly creep up on you. So, so, uh, you know, when do you actually enjoy the running while you're running, or is it all like retrospectively when you're done that you enjoy it?

Uh, it really depends on— there's definitely periods where you're enjoying the running, uh, when you're in some beautiful spot or you're, you know, kind of getting into the flow. And then there's also times where it really sucks until you're telling your friends about it over a beer. And then in retrospect, you're like, yeah, that was pretty worth it. Yeah. Uh, so anyone who's, who's thinking that they, uh, they want to get into ultra running, um, they need to start off small and just convince themselves slowly that they're not doing this and just trick themselves into it.

Is that your advice? That's my advice. Yeah. I, uh, I, I guess you could also just try to go and sign up for a 100-miler or something. I saw some show on Amazon about this comedian who tried running a 100-miler just at his first race ever.

Um, so that's another approach, not one that I'm gonna recommend. And, and this person did or did not die at the end of this documentary? Uh, so they didn't finish their first one. Um, their second one, I think they eventually did finish it, you know, very close to the cutoff. So, so kudos to them.

That's pretty amazing. All right, let's, uh, let's jump in and talk, talk about some more background. Where are you from? Where were you born? Uh, so I'm from Vermont originally, so of the many East Coasters that have moved out and made Colorado their home.

I don't think of Vermont as being the place on the East Coast that most people came from though. That's— have you met a lot of Vermonters out here? No, um, not very many Vermonters at all. It's— I, it is very similar to Colorado in some cases. There's skiing, uh, there's a good beer culture, um, it's pretty relaxed, but, uh, Other than that, yeah, it's a pretty small place, so there's not very many Vermonters to come to Colorado.

Yeah, so Vermont is, is, for me, it's unfortunately kind of on an island where it's really hard to go just visit Vermont unless like you're only going there for Vermont. So, you know, I've been in New England and I've been to the other states, I'm like, oh, I should go do Vermont. I'm like, I'm gonna drive like 4 hours out of my way to go do this? And so I, so I haven't ever been, I, but I really want to go check it out sometime. So maybe you can give me a some advice for the best things to see when I'm in Vermont.

What about for our listeners? Do you have any like top few things that we should see in Vermont if we get— if we make it there? Well, I think the main thing that people go to is the fall foliage because you have the oaks and the maples. You get a nice variety of yellows and oranges and reds. That's pretty spectacular.

And it's just, you know, I mean, our town was founded before the US was founded. So it's, you know, our house was 200 years old. The bricks were different sizes because they were ship's ballast that had come across, you know, in a an old ship hundreds of years ago. So it's got a lot of history. It's got a lot of, you know, rolling hills and picturesque farms, good maple syrup, good food.

Ben Jerry's, right? I assume you grew up eating a lot of Ben Jerry's. Yep, Ben Jerry's, definitely one of our well-known exports. I think Hattie Topper was for a while considered the best beer in the world, also a Vermont export. Awesome.

So, you know, you grew up in Vermont. Talk to me about, you know, did you end up leaving for college or how did you end up leaving Vermont? So from middle school, I moved to just outside of Amsterdam in the Netherlands. So going from a state of 500,000 people to the 3rd most densely populated country in the world, 16 million people and about the same size, that kind of opened my eyes up a little bit to see what was beyond the farms. When I came back, I took a university program called the Clarkson School, which lets you go to school early.

So you're a fully matriculated undergrad, but also you can finish out your high school requirements at the same time. So that's kind of how I escaped to upstate New York a little early. Why did— but why did you go to Amsterdam? What took you? I mean, obviously your parents, but what was the reason?

Yeah, my dad's job was looking to kind of grow and set up a bigger European presence. So he got to move out there for a few years while he got things set up and then hire some, some local folks to take it over. But I mean, what an amazing opportunity as a, as a, you know, pretty young kid, middle school age, to, to get to see this other culture. I'm curious, you know, as we look forward, do you think that that's impacted the way that you've, that you've made decisions about your own life? Yeah, I think so.

I mean, it definitely gave me the travel bug. I've been to around 62 countries, um, and that was definitely impacted by the fact that you can drive for a couple hours and then people speak different languages and have different food and different cultures. So that kind of got me that, that bug. And also learning different languages, being able to assimilate and kind of blend in a little bit has always been pretty fun. So I definitely think it was a great and impactful experience on my life.

Hmm, that's really cool. I'm jealous that I've never had such a— that kind of experience exactly. So really cool for you guys. All right, so you came back and you did the Clarkson program. Talk— tell me more about that.

Yes, I just did computer science. Basically my freshman year, which was still my senior year of high school, I interviewed for a job at the first company I worked for, Assured Information Security, or AIS. And I really enjoyed the technical people that I talked to at the career fair there. They were all about doing cyber before, you know, you could really mention that the government did cybersecurity stuff. So it was really fun to learn how computers work and make them do stuff that they're not supposed to do.

I think my intern project early on was to, to write a kernel driver that would display a bitmap image on the screen and you couldn't get out of it, which then I found out was used to hassle off my boss. So I basically wrote a rootkit as my intern project for my, my coworker's benefit. That's, that's pretty fantastic. What made you interested in, you know, obviously you got development background, but why cybersecurity? Why was that the area you wanted to use that?

Yeah, I mean, I think it's always fun to come at it from a development background. I've always been interested in making tools and kind of exploring the constraints of whatever system you're on. And that kind of led me into the more offensive side of security, but then I've always found it more challenging to flip it around and do the defensive side of things. That's great. Looking, you know, you got the opportunity to do the internship, you know, what did that turn into for you?

I think I know, I think I know, but, you know, tell us what happened next. Yeah. So basically when I was still partway through the internship, they said, hey, when you're done, do you want to come back and work for us full-time? And I was enjoying it at the time. And so I went there and spent a couple of years in upstate New York.

And really that was the biggest negative was upstate New York, not the most fun place. So I told them I was moving to Denver and either handing out my business card or my resume, it was kind of up to them. And they agreed to kind of send me out there and set up an office. And it was just me to start. And I think when I left, there was about 15 people out there.

So I definitely kind of grew that office focusing on low-level security. So talk about whatever you're allowed to talk about with AIS and what kind of work you guys did there. Yeah, so we did a lot of government contracts through Air Force, DARPA, and some others. A lot of prototype proof of concept. So we had some work looking at Using timing side channels to figure out if a cloud provider is snooping on you.

So if you spin up an instance, is that cloud provider doing something maybe that they shouldn't be doing? I think my— I broke into the security speaking world from some of the work I did for DARPA looking at real-time measuring of applications. So has an application been compromised in real time? Has someone injected into that process? And so that I got to present at a conference in New York City, and then that turned into encrypted execution.

And then I started the speaking circuit for a lot of different types of work there. And in your role there, I think you went from individual contributor to a lead, right? What was your responsibility there by the end of your time at AIS? Yeah. So I led the— we called it the Computers Architectures Group.

Again, a lot of kernel-level, hypervisor-level research. We wrote BIOS, UEFI, firmware, et cetera. So leading that from a technical direction, doing some hiring, and then a lot of business development. So I spent a lot of time in DC at various government organizations trying to see what their needs were, understand how we might be able to do some research that catered to those needs and push the ball forward. And that's kind of what led me to DARPA, actually.

I'm looking back at, you know, it was during that time that you got pretty involved with the security community in Denver and You created— I think the name has changed a little bit, right? The— was it Denver CitySec at the beginning?

Talk to me about kind of the foundings of that group and really what the vision was. Sure. Yeah. So I found just kind of throughout my life and my career, I really enjoy creating communities. I took over organizing BSides Denver for a couple of years and really enjoyed that aspect, just seeing people getting together and having interesting conversations and making those connections.

But I wanted something that was more than once a year. So actually, the, the NetSec subreddit has this notion of CitySec. So they're all around the world, and you meet up at a bar, there's no vendor pitches, there's no admission fee, it's just you meet up and chat with other people who are interested in security. And the Front Range didn't have one at the time. So I, I kind of just created the Twitter account.

And, you know, it started off pretty small, maybe 6 or 7 of us. And then I think at least some of the ones I went to, there were 40 or 50 people, and trying to organize that was you know, a challenge when we essentially showed up unannounced at some random bar or brewery in Denver. Yeah, and, you know, it seems like at the beginning there was, you know, sometimes just a few people and it grew over time. You know, as, you know, as your time doing it, did you, did you see changes into the structure, or was it just, hey, you know, we're hanging out and whoever hangs out is, is going to be there? How did you look at the structure of that group?

So it was pretty unstructured. And I was also happy I gave the account information to a number of other people to run ones closer to Boulder or down in Fort Collins and, or Colorado Springs. And so that was what was really interesting to me is to see the kind of growth and changing shape of the community across the Front Range. And it really started off that, you know, there was a tech space in Boulder and then downtown Denver was a lot more, you know, insurance and financial markets. And then there was a little bit of government work out by Buckley Air Force Base in Aurora, and then obviously a lot down in the Springs.

And now I would say that downtown Denver is really a hotspot for a lot of that, you know, high-tech work. And so it's kind of interesting just to see the populations at each of these different meetups kind of grow and ebb over time.

All right, so, you know, you were there at AIS for over 8 years. Um, looking at your LinkedIn, it was, uh, 8 years— oh shoot, I lost it— uh, 8 years and 4 months or so. Um, I know you got to do just kind of an amazing, you know, TV type of a job next. What, what was the next thing for you and how did it come about? Yeah, so, um, my next job was a program manager at DARPA, so the Defense Advanced Research Projects Agency.

Known for inventing things like the internet, GPS, and stealth technology, and Siri voice assistant. So basically, I was working for them as a researcher. So they have about a $3 to $3.5 billion annual R&D budget that they essentially send all of it out of house. So I was one of the researchers that they had contracted with. I guess they liked the direction I was going in, and I was kind of, you know, pushing for them to do projects in new areas.

And so eventually, maybe they just got tired of me bothering them, and they said, well, why don't you come and do all this yourself then? So, uh, I got to go out, move to DC, you know, military move. I was apparently equivalent to a colonel rank, so I got a special parking spot, and, you know, I had to have all these protocols when I went out to travel to military bases and whatnot. But yeah, it was a great opportunity. Basically, it's kind of a mix of, I would say, Shark Tank and Survivor.

So you show up on a term-limited appointment, you essentially have nothing to do but to come up with a pitch, and you make a 15-minute pitch, and you try to walk away with tens or hundreds of millions of dollars and a mandate to change the world in some way. So it's kind of an interesting little bubble within the government because everyone there is there for between 2 and legally no more than 6 years. So they're running around trying to get as much done as possible while they have access to that kind of funding and access, and then they move on. So it's, it's a pretty cool place to work and a pretty unique place to work. So I guess my first question is, What did you do or what did you show them to get yourself into that program?

Like to be hired in the first place? So that's my first question. Let's start with that. How did you entice them that Jacob Tory is worth bringing in? So it's pretty interesting, actually.

The interview process is pretty unlike anything. They aren't super interested in technical skills in the sense that you're not whiteboard coding like you would be for a Google interview or a Netflix interview. And honestly, they don't really care that much if you're a good manager not. They figure they can hire people around you to take care of the finances and the contracting and all of that type of stuff. It's more about, do you have a vision for a big problem that the commercial industry is not going to solve?

And, you know, that you are willing to drive and push that, that vision to reality. And so you essentially pose an open problem and say how you would like to have people work on that problem as your interview. Yeah. Are you, are you allowed to talk about what problems?

Yeah, many of them. Yeah. So I did a bunch of stuff in the cyber portfolio. So looking at— so step back real quick. So the last gig at AWS I did was looking at some red teaming of freight rail systems.

So I was specifically hired because I had never done a formal red team engagement. And the company, which is a rail company, figured that the NSA or the Chinese or the Russian government could probably hack into their stuff, but they were curious to know what essentially a moderately skilled attacker could do. And so someone analogous to a pissed-off kid in their mom's basement. So I was that pissed-off kid in the mom's basement. And so I was given a freight train and a couple weeks of time there with some other people that I hadn't met before.

And really what was shocking to me is all of our attacks, which were impactful, shall we say, were all done just purely through configuration. So we didn't have to write any memory corruption vulnerabilities. It was that a debug server was left on, on a high port, or that they had configured security to be based off of the source IP address rather than mutual authentication. And so that got me thinking that configuration is kind of this last space that it's very boring, no one really wants to play with it. The commercial solutions are all about trying to get you to buy one vendor's solution.

So if you buy all Cisco or all Juniper, they have pretty good solutions, but realistically large systems and DoD systems, you're gonna get a hodgepodge of vendors and there's really no good tool to look holistically and say, this system's supposed to do X, Y, and Z. Let's see how it's configured and let's trim off all that excess functionality. And I found a lot of data supporting that. About 75% of the vulnerabilities that the NSA finds in our own networks, our blue networks, are all based on configuration. Awesome.

So, so once you got over to DARPA and you're now— you're now living in an episode of X-Files, I assume. What did you do? Yes, I started a couple programs. I took over a couple programs. And so one of them was creating this configuration security program, which has not the most exciting name, but that was, that was kind of my first program that I started off, and I got a bunch of people together from all different facets of academia and industry trying to look at how you might be able to reason over these poorly understood systems that come from various different vendors.

So we had components of automatic firmware binary analysis to figure out what a configuration option does and what it doesn't do if you turn it on or off, automatically reading instruction manuals and system design documents. So there was natural language processing in there. And then, you know, very large-scale reasoning because you have— I believe, I can't remember, I think the The default ways that you can configure off-the-shelf Windows 10 operating system through GPO is roughly 10 to the 600. There are 10 to the 80 particles in the known universe or the observable universe. So significantly more than that is just a way that you could configure your default install of your operating system.

So it's a huge space, and reasoning over that is essentially intractable without some very clever techniques. That's, uh, that's interesting context. I bet that most of us would not have imagined the, the number of configurations to be, to be quite that large. That's a little, that's a little daunting, isn't it? Yeah, I, I actually, I gave a talk, a TEDx talk, basically on how we're, you know, now with software and machine learning, we're creating systems that we, we don't understand and we'll never be able to understand.

I mean, essentially machine learning works by creating a 4,000 or 8,000-dimensional function and then doing statistics in that weird space. It's like building an M.C. Escher painting in software and then magically hoping it works. So it's a pretty crazy thing that we've done with software. You can write software that shouldn't make sense and it somehow works.

That's— it's frightening and it definitely— yeah. I think an Escher painting seems like a good analogy to what we're talking about building there. Uh, all right, so, you know, when I think about DARPA, I think, uh, you know, huge things that change the world, you know, GPS and, uh, all kinds of good stuff. What has your work— any of your work gotten out to the world to make things better yet? Yeah, so I'd say that it's pretty rare for an entire DARPA program as visualized end up kind of being shipped like a shrink-wrapped product.

So some of the work that we did in very fundamental theorem proving and analysis and kind of scaling up reasoning, it was a paper that if you read it, probably you won't understand very much of it. I didn't understand very much of it. And then we got kind of a kudos from AWS's automatic reasoning group, And they were taking this work and they were using it as part of their Zelkova project, and then they're scaling it up. And so it checks everyone's IAM policies all the time, you know, looking at bucket configurations and, you know, assume role policies and everything. So little bits of that have come out and are impacting everyone that uses the cloud's lives in small, subtle ways.

And that was just essentially one paper of dozens that come out of each project. So there's a lot of little threads that come out of it, but it's— yeah, unfortunately I didn't have a home run where the entire project ended out like the factory that I envisioned. Yeah, but that's amazing to get to see your stuff used. Obviously AWS, the biggest cloud provider out there, they're using your value to make all of our lives better. That's pretty cool.

So you were at DARPA for about 3 years. Maybe talk about how that ended up wrapping up. Yeah, so, um, because they're starting new programs, and so at DARPA you're basically there for 2 years, um, which means they have a nice way of saying au revoir if you haven't done much. I was extended another 2 years, but coming on to 3, you know, looking at how long it was going to take to start a new program, and that was right about when COVID started We were running into a lot of delays with contracting. People were kind of unsure what was going on.

The government was working, you know, moving to a remote workforce, but then also there was some classified work and all sorts of things. So it was kind of a complicated time to be in the government. And so I kind of did an analysis too. I think I could start another program and see it far enough away to, you know, get it shaped the way I wanted to in a little under a year, or you know, did I think I should start looking for something else? And so that's what I ended up doing.

I actually, because of AWS's ability to take pretty, you know, out-there academic work and turn it into something that was so useful, that's where I actually went next. Yeah. So, so yeah, you made a move over to AWS and what was your role over there and what were you working on? Yeah. So I had a team in the AWS security organization.

Essentially, we were in charge of all new product security in the firmware, hypervisor, and hardware space. So everything kind of below the operating system was our security purview. So that was a pretty big scale of operations, as you can imagine. The cloud runs on metal and runs on actual physical components. And so there are a lot of them, especially at AWS scale.

And then also I got to look at open source dependencies. So looking at our open source supply chain, looking at all of the components that are ingested by us, and looking at how we might be able to improve the security of the whole open source ecosystem, not just internal to AWS, but for our customers who may be using them as part of a managed service from AWS or not. Yeah. So, I mean, sounds like a really cool opportunity there. You know, getting to work with the, the leading cloud provider.

Um, highs and lows, anything you want to share from that perspective? Uh, so I mean, the scale of AWS is pretty incredible. I mean, going live, uh, you know, with the product that we spent, you know, months working on and, and securing and facing some really difficult challenges, seeing it go live at re:Invent, and then, you know, watching the dashboard as, you know, one or two people started using it as soon as it turned on, and then You know, by the end of the keynote, there were, you know, thousands of people looking at this service. That's, that's pretty cool to see your thing, you know, basically being played with so quickly. I think that's, that was definitely the high for us is being able to have that much customer impact so quickly.

I think the low is just, it's a tough, very fast-paced environment. It's globally dispersed. So you have people that you're trying to support I personally had members of my team across 4 different continents. So the time zones were challenging. It was very long hours.

And, you know, everyone is trying to launch as soon as possible because customers want and need our products. So it was, it was a lot of stress. And there's a lot of big company stuff. It was my first time ever really working for a big company. You know, the DOD is a very large organization.

But DARPA is pretty small. There are about 100 program managers. So it's a pretty small environment, and it's also very proactive about being transparent and open. I could present work that I was doing at DARPA with very little friction publicly or release code as open source. It was a lot more review and checks and balances within AWS just from a competitive standpoint.

So it was very different for me having worked for only small companies like AIS, which was I think I was employee 80 when I joined.

Yeah. So AWS is a big company and lots of challenges that come along with that. So somewhere, I mean, just really in the last few months, you made the move to leave AWS and we talked about you went to Thinkst Canary. I've known Thinkst Canary for years. In fact, I looked at their products multiple times over the years.

Maybe you could just give a summary though for listeners, What do they do? And, um, and then after that we can talk about what you're doing for them. Yeah, so I guess I'm, I'm pretty new, so I don't have the full sales pitch, but basically Think Canary is a pretty low-cost, uh, high-signal sensor or thing you can plug on your network. You can distribute them across the globe as a hardware product or in the cloud or on virtual environments. You can make them look like you know, slightly out-of-date environments.

So you have that one Windows system that is one or two patches old that might be juicy for an attacker, and then you get, you know, real-time instant alerts when someone is touching that, and you get a lot of information. And they trigger all the time when there's pen tests or red teams going on. You know, they're not noisy. It's not like a SIEM environment where you're getting thousands of alerts that you need to sift through. It's there is someone trying to do something naughty on your network.

You should probably know about it and go do something about it right now. Yeah. And they're basically, uh, what they call tokens, right? Canary tokens. So, so yeah, so there's 2.

There's the canaries themselves, which are emulating entire systems, so kind of like a honeypot. So they have, you know, they could have SSH, RDP, VNC. And then there's the free part of it, which is the canary token, which are files that if they're ever opened. Um, not just files, I guess, uh, they also— things like WireGuard profiles. So you could leave that on your phone, um, and then if someone ever connects to it— another one that people, uh, really like is AWS keys.

So AWS access keys that, you know, you just leave, and it's so juicy for an attacker. They just have to know what they can get on your cloud infrastructure at the moment they, they talk to AWS with that. You know, your CISO or whoever gets an alert and, and you know that someone's on— exactly, because they're free, you can create thousands of— you can create a unique AWS key for every developer, every, you know, person in your company, and now you know exactly which computer they're on. Yeah, it's— I mean, it's such a, such a fantastic way to put tripwires all over the place and use those to, to know when someone's walking around, right? That's great.

So, but what are you doing? What is Excuse me, what does Thinx Labs mean? Yes. So back in the day, I think Thinx was started as an applied research company. So I think technically it's Thinx Applied Research.

Then they pivoted into the product space building Canary, and they had some labs work that they actually turned down and stopped doing so they could focus on Canary. Now that Canary's pretty established and is working in a good way, They're trying to reopen the labs and look for what's next. So new product ideas, keep doing interesting research. And also there was this product they used to have called Thinkscapes, which was a subscription. Essentially, they would read every conference talk, every paper from academia, and then give you the highlights every quarter saying, this is research that's interesting, this is maybe overblown.

There's some interesting kind of, you know, things to watch in this area. So one of the things I'm doing is actually bringing that back as a free publication. So it'll be a quarterly publication. And actually, I'm going to couple that with a very condensed podcast version. So a quarterly podcast, it just kind of goes through what some of our favorite papers out there, and then some of our, you know, takeaways from why we think they're interesting.

So how much time am I going to have to dedicate to staying on top of research if you're doing it for me? How much of my time are you going to take? Well, it depends on how quick a reader you are. But our podcast, I think I just got the first draft of it done today, and it's about 20 minutes. So if you can dedicate about 20 minutes every quarter, you'll at least have your fingers on the pulse.

And are you going to talk slowly enough that I can listen to it at 2x speed? That's, that's what I like to hear. I can make a special slow version for you, Rob. All right. So that's really cool.

What's the podcast called? Uh, it will be called Thinkscapes, though it doesn't exist yet, so I wouldn't search for it yet. Well, uh, I— we'll make sure we mention it on the show when it comes out because I will listen to it, and I'm sure that there's some other folks who are excited to listen to it as well. Um, you know, I, I feel, Jacob, like I really did a disservice at the beginning by not talking about where you live, because you do not live just down the street from me in Denver, or, or, you know, the north side of the Denver metro area. Where are you in Colorado?

I'm in the other half of the state called the Western Slope, the part that a lot of people forget about except on long weekends when they, they drive out here and come visit this small mountain town. So I live just between Telluride and Ouray, so southwestern Colorado, about 2.5 hours from Moab, 2 hours from Grand Junction, and about an hour and a half, 2 hours from Durango. Yeah, you know, we've had, uh, recently had, um, Rob Eggebrecht, the— who lives out in Grand Junction, on the show. So I've had some Western Slope folks, but I think you're the first one I've had from like the Southwest, uh, Colorado area. And I haven't had anyone from Durango, and certainly not from Ridgeway, which I only know because that's where you live.

Um, what makes it great? Why did you choose to live in Ridgeway? Well, the, you know, the the required is terrible, don't come here, tell all your friends not to come here aside, for us it's perfect. I mean, it's a lot cheaper than the Front Range. We have, you know, 5 acres.

All of our neighbors have 5 acres. So I— it's a dark sky community, so I see the Milky Way almost every night. It's got good food because we're close to Telluride. I'm 30 minutes from skiing at Telluride or backcountry skiing at Silverton. I did my first heliskiing experience this This last winter.

And then you've got the San Juans to explore and play in. You've got, as far as I know, basically every outdoor sport. There's even manufactured waves that you could surf if you really wanted to in town. So everything outdoors you could want, good food, small town. It's, it's a great place to live.

Yeah, well, that's great. I love, I love the sales pitch for the parts of Colorado that most of us don't know. And I have, ever since you've moved there, I've been trying to find a good time to make it out there and see the place because it sounds just beautiful. All right, Jacob, what did I not ask you about that I should have asked you about?

Well, I think you could ask the best day of work at DARPA I've ever had. Yeah, tell me what— hey, Jacob, what was the best day of work you had at DARPA? Well, so I got flown out to Phoenix, Scott Air Force Base, and I got to fly F-16s for a day. And I actually got to control the aircraft. You know, the other pilot who was supposed to be in charge was using both of his hands to film me with his iPhone.

So I got to fly, you know, loop-de-loops, barrel rolls, fly in formation. We did a combat takeoff where you, you know, get to about 400, 500 knots, 12 feet off the ground, pull the gear up, and then go vertical 10,000 feet like a rocket. And then we were flying through the canyons around Arizona at 500 miles an hour, 300 feet off the ground. So That, that definitely beats a day in the office. So you're telling me, like, when you said you got to fly it, I was thinking like, yeah, you got to, you got to make turn a little bit as you went, but you actually did like loop-de-loops?

And yeah, so fortunately the F-16 is pretty hard to crash. It has this auto ground collision assistance system. Um, and so once you're up high enough, basically it's pretty hard to screw up. So, uh, Yeah, I got to go and do that. We pulled 9 Gs, which is the, uh, the maximum the airframe is rated for, which feels like your face is coming off your skull.

So, uh, not recommended that part, but, um, but definitely a fun way to, to spend a day in the desert. Wow. It just feels to me like we should have led the whole thing off with this. That's just amazing. Uh, and, and now you, now you're trying to get into the Air Force.

Is that the punchline to the story? Yeah, I, I was actually young enough at the time that I could have gone in. Um, I think that you, as long as you're not 30, or if you're under 30, you can go in. If you're over 30, you need a waiver. So at the time, I was, I was not yet 30, so I could have, uh, could have joined.

But, um, it's rough on the body. Uh, you know, some of the pilots we were flying with were reservists who were finishing out their careers, and, you know, they can't pull too many Gs in one direction because their shoulder will pop out or something like that. So It's a lot of strain on the body and very fun to do when you get the chance. But I'm not sure if I— also, I didn't have anyone shooting at me. So that also, I think it makes it a little bit more fun.

I'm not sure I would have enjoyed that if, you know, there were alarms screaming and people shooting at me. Yeah. And you didn't get to shoot at anything else, right? Did you get to shoot a rocket off of that cliff or anything? So we did in the simulators, which are kind of full surround, you know, and you get to fly.

I did shoot down a few enemy aircraft with the heat-seeking missile. Um, a radar or like a radar-guided missile and actually with the machine gun. Um, but, uh, nothing, no live ordnance. Well, Jacob, what an amazing opportunity that you will not get working for Think Canary, I would imagine. I'd imagine that that's probably not a, uh, a good day at that company.

Yep, definitely the best day at work. Cool. Well, that, uh, I don't have any other questions for you unless you have anything else you want to go through. Nope, that's good. Thanks for chatting.

Awesome. All right, thanks, Jacob. Well, that is it for this week. Uh, it was great to get to meet Jacob in the, in the official podcast form, and we'll look forward to talking to you guys all again next week on Colorado Equals Security.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and and learn more about Colorado Equals Security. Reach out to Alex and Rob by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes