Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is your newscast for episode 226 for the week of September 27th. Alex, uh, Happy fall to you.
We are in fall now. We are in fall. Happy fall, Robb. It feels more fallish lately. That means that we're like for real most of the way through 2021.
Uh, we are almost into the fourth quarter. Next week when we record this, it will be the fourth quarter and we'll be like, holy smokes, it's the fourth quarter. Can you believe it? Yes. Can't wait for that.
That'll be fun. Hey, speaking of fun things, did you know we have a Slack channel? I did not. Oh wait, I did. You are one of the 2,000 and something number of people who are in there and great conversations.
We, uh, We continue to have new insights and people dropping news and dropping knowledge on each other in there. So I hope you will join by going out to colorado-security.com and clicking the join Slack button. We also have a mailing list, Robb. When you're on the website, you can sign up there, put in your email. You'll get automatically added to our email list where you will get one email every week with the show notes.
Usually it comes out Sunday, Monday, sometime around then. Whenever I feel like it. We would also love it if you would rate us and subscribe on your favorite pod catcher. And you know that one way you could also help the show is by telling a friend to go tell anyone you know that Colorado Equal Security is the best security podcast in Colorado. If you have a little extra change in your pocket and want to support us financially, we also have a Patreon campaign going on.
You can sign up for that. We have multiple different levels there. If you sign up for the $10 a month or greater level, then you will get a free t-shirt as well as a shout out on this very show. And if you're thinking to yourself, you know, I really want to help the show, but I don't have any money, and and I don't have any friends to tell about the show. How could I possibly help?
Good news: we have an opportunity for you. We would love it if you would help do some interviews for the show. You know, you know, generally the format is we do the newscast, and then we have an interview after. Say over the last month or two, we've been a little short on interviews as you and I have not had a lot of free time, and some of our other volunteer interviewers have also been. Busy with whatever's keeping them busy.
We would love it if someone out there is thinking, you know, I'd like to try an interview and, and look for an excuse to talk to an interesting person. We could help you out. Yeah. I mean, and you mentioned maybe if they don't have friends, the interview, you might gain a friend out of it too. Double win.
Double win. Double win. All right. Let's jump into the news. Denver International Airport.
Apparently the security lines have been awful. Yeah, that's what this article says. And I can attest a couple of times that I've flown recently. They have been awful. Now you're, you're Pre.
Is it still bad for you? So I have Pre, but I also pay for Clear. Yeah. I think if you just have PreCheck, it can still be pretty bad. They mentioned in the article that many times they only have PreCheck open on the south end of the airport.
So if you're not on the south end, or even if you are, then maybe it's a little crowded down there. For me, it is definitely worth it to pay for Clear to get through much faster. Um, but I mean, it like abysmally long lines is what I've seen, like stretching over around into baggage claim and things like that. Yeah, it sounds like a nightmare. It doesn't sound like it's always this way.
The article talks about Mondays, Fridays, and Sundays as being the, the times that this is most frequently a problem. But something to keep, keep an eye on. And I'll say pre-pandemic, you know, I traveled quite a bit. I had a real rhythm for like get to the airport, you know, 50 minutes before my flight, get to the gate 35 minutes before the flight, you know, walk on as they board at 30 minutes. I think that that wouldn't necessarily work as well today.
Right. You're going to have to give yourself a little bit more time. So let's be ready. There were some other interesting stats in here. They talked about the fact that we are down— what was it, 17%?
I think we're down 21%. And I think the on average everyone else was down 27% or something like that. So we being Denver International Airport is down 21% of capacity or of travelers as we were in 2019 at this time. So COVID, you know, sliced off that fifth of the travelers. But as you said, other airports are down 27%.
So relative to others, we're a little bit higher. Yeah. There's one other interesting kind of annoying thing in there is they mentioned that during COVID they turned off the ability to— the real-time monitoring of the line, right, the security wait on the website. So I used to look at that if I was ever worried about about travel to go take a look at DIA's website to see how long the security wait was. And apparently that's no longer working.
Yeah, I think they did say also that the— you can still get wait times with the My TSA app. So you might be able to do it that way instead of directly through the airport. I guess I got to take a look at that. Yep. All right.
Moving on to the next story. The Colorado Convention Center has finally started their $233 million expansion. This is a long time in the making. You know, there was a bond that was passed, I think back in 2015, which gave the money for this project. And then there was a bidding process.
There was, uh, some funky things that happened in the bidding process. And so they got put on hold for a little bit and then COVID. And so now we're finally in late 2021 getting underway with the construction project. Yeah. The, the funky stuff, it looks like there was some bid rigging scandals that took place.
Yeah. They ended up having $1.5 million fines that went to a couple of companies for for the bid rigging. They do in the article mention that neither of those companies are part of the work that's starting now. But to jump into what the work is, they're adding 250,000 additional square feet to the already 2.2 million square foot convention center. That's a lot of square feet, 2.2 million, man.
It is. You don't wanna get lost in that place. You don't. And I mean, most often when I'm there, it's for Rocky Mountain Information Security Conference or other sort of small, medium-sized events, you know, convention centers, size anyway. But then, you know, there's that whole upstairs, which is a giant cavernous area.
And so it's interesting, they're going to be building a new 80,000-square-foot ballroom, which I believe is upstairs, and then also a 50,000-square-foot rooftop terrace, which will be pretty cool. Yeah, it sounds like really good stuff. They're going to be done with construction by the end of 2023. So 2 years from now, basically opening it up to events in 2024. They mentioned that they're not going to have to stop doing any of the current events that they, they're not going to infringe on current square footage during this process.
So, you know, continue to have RMISC and other events going on there. One thing that they didn't say is if there's any plans to change the Blue Bear. I just, I don't know. I'm curious. I honestly wish the reporter would have addressed that.
I sure hope they don't. But my immediate thought on reading this was, ooh, can we have a reception or something for RMISC out on the new rooftop terrace in 2024? That sounds awesome. Yeah, I love that rooftop terrace idea. All right, next article.
We've talked about this maybe two or yeah, probably two times in the past. Grange Hall, which is operated by Troy Gard, the Garden Grace and a couple other restaurants restaurateur, is opening up a new hall food hall in Greenwood Village just down the road from me called the Grange Hall. It's where CB Potts used to be on on Arapaho, kind of behind the the movie theater and yep, what was it was like macaroni grill and stuff in front of it before. Anyway, it looks like a pretty cool place. Yeah, it does.
Like many of the different food halls that are out there, you know, there's going to be different vendors serving food as well as different beverage options. You know, one of the cool things that they, they talked about in there is there— it's a fried chicken restaurant that is opening up. And that sounds pretty cool. Troy Gard also has a restaurant or two. He's got bowls, some kind of bowls restaurant.
Boo Boo, I think, is his bowl restaurant. And then I think he also has a burger joint in there as well. Well, I, Alex, if anyone wants to join me for dinner, I'm going there tonight to try the place out. So if anyone's listening, it was yesterday. But if you, if you're able to make it there Saturday night, you know, come join us.
Yeah, that sounds good. I'm interested to hear how it goes. And that whole little area over there is kind of hopping now. They mentioned the article to Pindustri, which is just down at the other end of that little strip from it, is a sort of happening entertainment thing. I think they have bowling and other things like that.
But yeah, we went, we tried to go to Pindustri a few weeks ago, just my wife and I. Honestly, I had kind of in my head confused Pindastreet and Grange Hall, like what it was going to be. So I walked in thinking it was going to be a bunch of restaurants, but there's not. There's, there's one like bar and they might do a little bit of food, but it's really not a place to eat. It's a place to do bowling, play video games, cornhole.
Like it's an entertainment spot, not so much as it is a dinner spot. Well, sounds fun anyway. All right. Up next, 2 Denver companies have landed on LinkedIn's list of top 50 US startups. So, Robb, what is this list?
Yeah. So in order to qualify for this list, startups had to be 7 years or younger. They have to have at least 50 employees and be headquartered in the US. And then LinkedIn used some secret sauce, a little bit of magic dust that they sprinkled to see like how people are searching for these jobs, which ones they're applying for, to determine which startups people are most likely or most desirous of working at. And one thing they did mention was one element of what makes it desirable is that folks are leaving the big FAANG companies, you know, your Facebooks, Amazons, and so forth, to go to these new companies.
And, and, and 2 of our companies in town made the list. Yeah. So congrats to them. They are Guild Education, which we have talked about many times on the show. They help folks in various different industries get higher education and move on to something else.
And Boom Supersonic, which, you know, they are aerospace company making supersonic planes that come 2029, I think, or something like that, are supposed to be flown by United. Yeah. I found it interesting within the article that we link, there's a link to the original survey. And I clicked through it to look and some companies that you've heard of and a lot of companies you never heard of on the list. And I found it interesting, some, some consumer products as well, not just, not just technology.
So kind of a fun list to take a look at. Yeah. And I thought looking at it, okay, of companies in town that are really cool and that like the things that they are doing are really cool. I think Guild Education and Boom are on the top of that list for me. So it makes sense they're on this list.
From memory, there was a couple of of security companies. Rubrik was one, and OneTrust made the list as well, who, you know, they just grown like crazy. No surprise. Yeah. I wonder if they're popular or just they have so many jobs right now that people are really looking to go there.
Yeah. They were number 1 on the Inc. 5000 recently. All right. Moving on. We have a follow-up from a story last week.
You remember T-TECH had been hit by ransomware that was covered by Krebs, and we briefly talked about on the show. We have a statement from NASDAQ, and I assume they must be listed on NASDAQ. Basically saying that they have resolved the attack. Uh, they only, only, there's not a lot of detail here, very little, but the one detail they do give is that, uh, they became aware of the incident on Sunday, September 12th, and then closed it this last week. So, you know what we're talking like less than 2 weeks.
Yeah. So I'm sure for the, the people who they're doing call centers for, I'm sure that was a pretty big amount of time. Uh, but in, in terms of, uh, completely eliminating a ransomware attack, that seems like a pretty good turnaround. Yeah. It doesn't sound so bad.
Yeah, I'm sure it was a lot of work for them. And so I hope those guys are getting some rest now and hope that everything is back to normal. I think they're probably a little ways from the rest there. They're probably working pretty urgently on whatever things they uncovered during this big incident. All right.
Next story. Coalfire has a press release announcing that they have appointed Michael J. Sullivan to their board of directors. So Coalfire, obviously one of the big security companies here in town, and we love to talk about the great news going on over there. And Michael Sullivan is another one of the kind of stalwarts of the security community here in Colorado. He worked— his most recent, I think his last actual job was as the CFO for Ping Identity.
And being on the board of directors is not an actual job, Robb? Well, this is what I'm saying. Yeah. Now he lounges and gets to drink martinis while people bring him board decks to read. You know, Mike and I worked together at Ping, and I got to know him.
He's been on the board of directors for SailPoint, and oh man, another company, help me out. They mentioned Scram Systems. Vertafore and SNL Financial. Yeah, so he's, he's obviously helping a lot, giving his experience to a lot of different companies, and I think his security knowledge and industry connections is only going to help Coalfire. So congrats to both Coalfire and to Mr. Sullivan.
Yeah, congrats. All right, uh, our next story, we have a brand new series of, of, uh, news that's coming out from Red Canary. They're calling it Intelligence Insights, and this is the September 2021 edition. Basically, they've bundled up a bunch of the intelligence that was previously used internally to help make the systems at Red Canary work great and, you know, share with some customers as well. And basically, we're just making everything public that we can.
It's pretty cool. Yeah, so this contains all the data that you guys collected in August, uh, put into the September report. Some interesting things in there. One of the things I noted is that adversaries continue to exploit enterprise apps for initial access into companies, things like WebLogic and Confluence. There are some big Confluence vulnerabilities this past month.
They also go into a number of different other things talking about cryptors as a service, you know, things that are happening in the ransomware underground and some detections that you can use in PowerShell to help find some of this stuff. Yeah, and if you love, like me, if you love pretty charts, they have a great chart at the beginning showing the, the name of the threat and then what percentage of their customers were impacted by that threat during the month. That's pretty cool. Yeah, I mean, if you, if you're running a SOC and you want to know, hey, what's actually hitting the world out there, this is just invaluable information. Yeah, definitely.
All right, uh, next, a blog post from Ping Identity talking about a survey that they have been doing over many years, but now this year's, uh, talking about that there's a greater appetite for password alternatives that make logging in easy as well as prioritizing privacy. Yeah, I think that for years Ping has used these surveys to get a feel for how, how companies and how culture in general is is adapting their expectations of authentication and identity, especially in the consumer side of the world. And this is really what this reflects, is the desire more and more now that, you know, having to require your, your customers— not your employees, your customers— to log in in order to get your services, it's frowned upon. And really, companies are expecting to move away from that and get to passwordless sooner rather than later. Yeah, they had, uh, sort of 3 high-level findings here.
Consumers demand easy, fast experiences, talking about the fact that there's a large number of consumers that would abandon a service if it's too hard to get registered and to get into that online service. As passwords are getting worse, and I think by worse meaning harder for users to use, more complex and other things like that, that passwordless or other authentication is looking better. And then finally, that privacy should be transparent and simple. A large number of people are interested in learning how online services share their personal information, but almost as large a number said that it is difficult to figure out how people actually do that. Yeah.
So I think it's great stuff. Obviously, Ping is coincidentally, they'll help you with your customer access issues. That's crazy. They'll do it securely and with privacy in mind. But great information in here.
And I think it's worth, worth taking a read. All right, last we have a blog from LogRhythm around detecting AWS unauthenticated cross-account attacks. And this is a— I mean, I'd say that this is like the technical depth we don't often see from LogRhythm. Yeah, I love it. There's a lot of really cool information here.
Yeah, so this is specifically talking about AWS and how there are problems potentially around cross-account users. So if you're in multiple different AWS accounts with a single user, the ways that you could potentially get access inappropriately to different places because of that. Yeah, I think that this is a small corner of the AWS world that very few people have spent enough time in to really get good at. And, you know, I'd say most folks who've stood up AWS have focused on how do I make sure I get the systems stood up right? And maybe they're throwing some kind of perimeter security in, but you got to understand in this AWS world, roles with within, um, well, the IAM policy is going to dictate the vast majority of access.
And this does a good job diving into one element of that. Yeah. And of course at the end, um, if you are a LogRhythm customer, it talks about how you can, uh, do some detections to help, uh, detect this in their product as well. Yeah. Really cool stuff though.
I'm excited to see that come out of those guys. All right. That is the news. Let's jump over to upcoming events. Robb, what do we have upcoming?
There's just 2 events in the next 2 weeks. I'm not sure what's happening the first week of October, but everyone's Taking a break, I guess so. But this week on the 28th, SecureSet is doing an introduction to social engineering. This is a virtual event, or maybe it's not a virtual event. Maybe if you click that link, you're going to be giving away your social security number.
I don't know. Hey, it's an intro to social engineering. Who knows what's going to happen when you join this meeting? Are they doing it the easy way or the hard way? Uh, the only other event on the 30th, ISSA Denver is sponsoring a job fair for Dish Network and a number of other companies as well.
Dish is sort of the headliner, but I think there's multiple companies that will be there that have open roles. Yeah. Interestingly enough, and usually we only go 2 weeks out, but the event immediately after this is a separate job fair. Spectrum or Charter is doing one on the 13th and 14th. Apparently, folks, there's a lot of jobs out there.
Yeah. And if you— if your kids or your friends are looking to make a change to a new career, this is probably a great time to consider moving to security. Yeah. And this ISSA event is an in-person event as well. I believe it's at some sort of fun place, like an arcade kind of place.
So you can have fun and get a job. Yeah, I think you're right. I think it was at an arcade. And now I'm clicking to figure out where it is. It is at the Super Awesome Fun Factory.
That sounds super awesome and fun. Super Awesome Fun Factory Private Warehouse Arcade at 39th Avenue in Denver. So that sounds like RiNo area. Yeah, like, yeah, definitely. Cool.
Speaking of job fairs and jobs, Robb, Let's jump over to jobs. The list of Red Canary jobs is shrinking as I've got to hire a few of my folks recently. Excited that, that I got some new folks joining the team soon, but I do have some open stuff anyway. We're looking to hire a product security engineer or 2 or 3 right now. So if you're someone with a development background, cloud security background, and want to help us secure the products that Red Canary makes, love to hear from you.
You can reach out to me on, on Slack. And we're also still hiring an IT support manager. This job doesn't show up on the website, but it is open. We just got inundated with folks applying. So send me a note if you, you or someone you know or love is interested, and I'm happy to, to get it to the right place.
We've talked about this one before, but it still appears to be open. Graebel is looking for a chief information security and privacy officer. I don't think it was a privacy officer before. Well, you know what? Now that I've read the title, it was chief information security officer before.
I don't know if they had privacy tacked on there. I think that they— I think they added privacy to the, to the, to the job description. So that's cool. Good opportunity over there at Graebel. Splunk is hiring a director of risk management.
Culler is looking for a director of information security in GRC. Yeah, Culler, I didn't hear— I'd never heard of the company, but they are here in town and it's— they're a healthcare company and a tech-enabled healthcare company. Western Union is hiring a manager of information security. Oh, you know what? I think I skipped one.
Splunk is looking for a director of risk management. Western Governors University is hiring a manager of IT security operations. Ping Identity, who doesn't get the top billing at the top of the jobs anymore, is looking for a senior GRC specialist. They're also looking for a junior one. I just threw one of the 2 jobs in there, but if you wanna go to Ping's careers page, there's actually several jobs open there in security.
Prologic is hiring a cloud security engineer. That's Prologic, not Prologis? It's Prologis. Okay. I wrote it and said it wrong, so there you go.
Grand Rounds Health is looking for a privacy manager. So good stuff. All right. That is it for— that's it for everything this week. We are— that's it.
We're done. We're done. We'll talk to you guys next week and enjoy the— enjoy your drive. All right. Thanks, Robb.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.