All episodes

Dan Moore, Developer Relations at FusionAuth

Apple Podcasts Spotify SoundCloud

Dan Moore, Head of Developer Relations at FusionAuth is our feature interview this week. News from Frontier Airlines, Whataburger, Evolve, Lares, Coalfire, Ping Identity, Red Canary and a lot more.

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript10387 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood.

Welcome to Colorado Equals Security. This is the newscast for episode 232 for, uh, was it— we call it the week of March now, right? For the month of March. For the month of March. Yeah, I was gonna say the week of March 7th, but yeah, it's really for the for the month of March 2022.

Yeah, that's pretty exciting. I can't believe we're already in March. Yeah. So this, you know, as we record, spring is starting, Alex. Right.

And in Colorado, that means it's going to snow and then middle of the week, it's going to be nice and then it's going to snow again. Yeah, there's big fat snowflakes dropping outside the window as we record right now. It is very pretty. And not quite spring yet. Not quite spring.

But spring will be coming here before our next podcast release. Yeah. So happy spring, everybody. Happy spring. Yeah.

Hey, let's talk about a little bit of housekeeping stuff. We have, we have a Slack channel. It's a vibrant community of 2,000 of our closest friends here in the Colorado security community. If you want to get to know what's going on in the area, looking for a new job, looking for advice on tools to buy, go out to colorado-security.com and click the Slack button and we'll get you an invite. We also have a mailing list.

If you go to our website, colorado-security.com and sign up there, you will get show notes sent to you when the podcast is released. And that's about it. Also, we would love it if you subscribed to the podcast and rated us so that people know how great the podcast is. You could tell a friend as well if you want to help spread the love. Tell— if you tell 2 friends and they tell 2 friends and they tell 2 friends, eventually everyone will know that Colorado Equal Security is the best podcast in Colorado.

I'm sure someone out there will be able to tell us exactly how long it will take. You know what that kind of growth is called, Alex? It's called exponential growth. Oh, indeed. Exponential growth.

Indeed. Yeah. Colorado equals security squared.

And finally, we do have a Patreon campaign. If you would like to help support us financially and cover some of the costs that we incur for running Colorado Equals Security, we would love if you came in and signed up. There's also information on that on the website. And thanks to all our current patrons. We, we appreciate your support.

And yeah, everything that you guys have given us throughout this whole process. All right. Once again, thanks to our patrons. All right. Let's jump into the news.

There is an article this week in the Denver Post about a survey. It's actually a national survey about the best neighbors and who enjoys their neighbors the most. And guess what Denver did? We were right near the top of that list, Robb, which is pretty cool. Yeah.

Denver, apparently we're good neighbors to each other. We like our neighbors. We are less likely to try and hide from our neighbors than other cities. Across the board, it's a pretty good place to live. I really liked the actual headline of the story, which was survey finds Denver or Denver neighbors rank among the best in the country for being least annoying.

Yeah. So so we're the least bad. We're the we're the least. Or what? We're some of the least bad people.

I mean, if we're gonna have to have neighbors, let's have the least bad neighbors. Anyway, it's a pretty interesting survey. I think it was Home Advisor that that does this every year. It was Home Advisor. Yeah.

And a Colorado company, local Colorado company. And then I think we're glad that we are— well, we're not in Texas. The most annoying cities or most annoying neighbors, I guess there are a couple in Texas, Fort Worth and El Paso, as well as San Francisco. Yeah, Denver did come in 4th. 1st was Phoenix.

2nd was Boston. Oklahoma City was 3rd. Then Portland rounds out the top 5 at number 5. Good stuff. All right, moving on.

A couple weeks ago, it was announced that Sprint and Frontier Airlines were going to be merging. And we have a story here. Spirit. Yes, Spirit. Not the telephone company.

Not that, you know, almost the same letters there, Robb. Spirit. And they could be bringing over 1,000 jobs to Denver because Frontier is headquartered here. Yeah, it sounds like so. Of the new company, the joined company that they have not yet officially announced what the name would be, although it sounds like it might be Frontier, the 51% control will be with the Frontier board.

So the board of directors for Frontier will be the ones making the decision about things like company name, headquarters location, other good stuff. So there's a reason to believe that the jobs may end up moving to Colorado where Frontier's headquarters has been. However, There's also, I guess, a decent-sized chance that it's going to be in Florida, which is where Spirit is. So there's a little bit of a battle coming in this regard. Yeah.

Spirit has just started to build a brand new corporate headquarters down in Broward, Florida. So that would seem like a good indication that maybe you could use that building. But who knows? Well, maybe they're like, if we spend the money, they have to let us have the headquarters. Exactly.

Exactly. Although, you know, real estate's always getting more expensive, so they could just sell it anyway. All right, moving on. You know, this norm— you know, a year or two ago, this would have probably been higher on the list, but we've had so many new restaurants come to town that this is getting a little passé. But there is another new burger chain coming to town, and it actually happened a couple weeks ago.

It's the Whataburger from Texas. Yeah, so Whataburger opened their first Colorado location in Colorado Springs, and they're gonna be opening a couple more down there over the next year year or so. I've, I've had a Whataburger before. It's a hamburger. Yeah.

You know, good stuff. They, they apparently, which I've never had, have like Dr Pepper milkshakes or something like that. I didn't know that till I read the article either. Yeah. I agree with you.

I'd heard people talk about Whataburger. I went to Texas and I made sure I stopped and got it. And I'm like, I literally like nothing stood out about at least In-N-Out. You're like, well, this is a different preparation. Like, Right.

Nothing stood out about Whataburger for me. Yeah. But, you know, just like anything else, everybody loves their Whataburger or whichever is your favorite. So congrats to people. You can now drive down to Colorado Springs and, you know, be in line in the drive-thru for a while to get a Whataburger.

I assume that many of our listeners will be in line right while they're listening to this because, because that's, you know, it's a long line. And I don't know if it will make the, the April show, but I saw an article this week, too, that said El Pollo Loco is going to be opening in Colorado, which is sort of another culty Although not burger, chicken, chicken chain. That's— is that going to be in the Springs as well? I don't know. The Springs have some like have some pictures of someone so they get all the good food first or what?

How does this work? Maybe there's cheaper retail space, you know, maybe so. I don't know. I don't know. Anyway, logistics, probably logistics is definitely it.

All right. Next, a new Denver-based— not new— Denver-based Evolve vacation rental company has raised $100 million after their busiest year yet. So I, I think 2020 was not a good year for them, but then they rebounded great in 2021 when everyone was tired of being cooped up in their house and wanted to get a vacation rental. And now they have, they've gotten some more cash to help push them through that. So is this, do you know, is this just like, hey, we're, we're not Airbnb, we're someone different, but we're the exact same?

No. So, so they are, they're a management company. So they're the ones that will actually manage your vacation property for you. List it through Airbnb or something. And yes, but not only just list it, but it's, you know, they'll take care of it and clean it and, you know, do all that kind of stuff for you.

So you own a property somewhere, you want to, you want to turn it into a rental, but you don't want the headache, right? They take care of it, right? And I mean, there are, you know, tons and tons of rental management properties, companies like this. But I think a lot of them are, you know, like, oh, we're in Breckenridge, right? We focus on people in Breckenridge.

These guys are, they're technology focused. And they're, I think, nationwide. Yeah, they had, I know they had a lot of units. So it was like hundreds of thousands of units that they manage. It does say that they, they have 800 total employees and about 750 of those are here in Denver.

So they are, they are a local company in most ways. If you're a security person involved, reach out. We'd love to know it. Yeah, that'd be pretty cool. All right.

This is, I don't know, we've been doing the podcast for, for a little over 5 years. Maybe this is the 5th or 6th time that we've done this. It's the, the Colorado Inno March Madness bracket. So each year there's the, the top, is it 64 or 32? I think it's— 32.

The top 32 technology companies in town who people get to vote which of these companies would they most like to invest their own money into to see who the winner, who is the best innovative company in Colorado for investors. Yeah, and of those 32, there are some names that we have talked about before. What's the number 1 seed overall, Alex? Oh, who, I didn't even look, Robb. The number 1 seed overall is JumpCloud, which is a security identity company.

They've really evolved over the years. Um, you know, since they, they founded, I think, quite a while ago, but, uh, they've invested a whole lot of money recently in new, new product and, and new marketing. And, uh, they, they really have, uh, have been coming on strong as a competitor to folks like Okta and Ping Identity. Yeah. Uh, number 2 is Guild Education, who we've talked about a number of times.

Um, also on the list are, uh, some other security companies, uh, such as StackHawk. CyberGRX? No, no, you, you missed it. Caw caw! Thank you.

Sorry. Thank you. We're out of practice. This is what happens when we don't record very much. Uh, CyberGRX is on on the list also.

Um, was that it? I think that might have been the only security companies. Yeah. I mean, there's a couple other companies. Pax8's on the list.

Um, Amp Robotics we've talked about before. Fluid Truck Rental. Yeah. There's a lot, there's a lot of familiar names on there. Yeah.

A lot of familiar names, just not necessarily any more security companies. As you know, we'll get back together in a month and we'll be able to say who actually won the tournament. You know, one that I think is, uh, interesting on there is, uh, the company Shinesty. I don't know if you've ever heard of Shinesty. I have not heard of Chinasty, but they, they make funny clothing.

So if any of you guys have been to our holiday party, or you've seen me around the holidays, I have a holiday suit that I wear. Those are the type of clothes that they wear, that they make. It's interesting to see that they're listed as a technology company. Yeah, interesting. Yeah.

Anyway. All right. Good stuff. Go ahead, Alex. All right, moving on.

Next, we had some We've had some exciting news. Have we talked about this before in general? I don't think we have. So friends of the podcast, Rock Lambros and Matt Sharp, released a book recently called The CISO Evolution. And, you know, they've been getting some good, good press for that.

And there was an episode of The Cyber Wire that they, they showed up on talking about the book. And so we got a link to that. I don't know how much you've got into it so far, but it's a really interesting book, the way that they they go through a number of scenarios a CISO might be in and how they should think through those things. And, and there— and before that in the book, there's a bunch of like principles of business, you know, kind of your, your mini MBA that you might get as a security leader, rather than being just from a general business perspective, from a security perspective. Here, here's how you can think about business.

Um, really, really good book. A lot of work those guys put into it. I know they put, you know, years of very hard work into this, so I recommend taking a listen to the CyberWire and maybe picking up a copy of the book. And I'm sure we could help you get that thing signed once you get it. Yes, I'm sure we can.

Good stuff. All right. Next, we have a very short blog post from Laris. Laris? Is that how I say it?

Laris? Laris. Yeah. This is by Andrew Hay, and it's a summary of some new guidance from the NSA. And specifically, NSA issued some guidance about how you can configure your, your network technology to avoid it being used by adversaries.

Yeah, and, uh, it's, it's great guidance came out this week. I did take a quick scan of that, uh, earlier in the week, and a lot of it is stuff that I don't think will surprise you, you know, best practices and things like that. But there are, you know, a few nuggets in there of stuff that you might not have thought of or are, you know, different perspectives on, uh, securing your network infrastructure. So That's pretty cool. And I think anytime, uh, an agency like the NSA says, hey, here are things that you should do to, you know, potentially prevent people like us, if you were an adversary, uh, from getting into your network, I think that's something you need to listen to.

I, I think you can assume that NSA is not only aware of other companies or other governments that have been using these vulnerabilities, but probably they do it themselves. Yep, for sure. So good stuff there. All right, next we have a blog post from, uh, Coalfire. Uh, this is actually a press release talking about that they are launching an application security solution powered by the ThreadFix platform.

Yes, so ThreadFix is and was the, um, software that was, that was created by Denim Group, which, you know, you and I have known for a very long time. Yeah, Denim Group was acquired by Coalfire last year. They, as they've been moving it into coal— into into Coalfire, um, they really looked at this holistic approach to securing your, your software, your SDLC. And ThreadFix is a technology that helps, you know, helps you integrate like findings and vulnerabilities into your SDLC. But, you know, with all the other services that Coalfire has, you know, now they have a relatively comprehensive look at AppSec throughout the SDLC.

Yeah, and I'm not sure how much, uh, that is being announced here is actually net new, or if it's just more of the formalization of all of the things that they had now in a cohesive AppSec offering. Yeah, my read is it's probably mostly repackaging of services they've had, but now they have a robust package of services. For sure. All right, next we have a blog post from Ping Identity. There was, you know, we have a month, so there was a lot of options to look through.

This one was interesting to me, and the reason I picked this was it's, well, it's called How Can Your Enterprise Grow Securely in the Metaverse? And I'll be honest, I know almost nothing about like the current state of metaverse. I know that there's this idea that, you know, we're all gonna live in a virtual world and interact there. And to me, it's, you know, 30 years in the future and maybe not a future I'm all that interested in. But this blog post is talking about like, well, okay, what actually exists today?

And, you know, I did not know that there are currently 4 different metaverse worlds that one can go be in, meta in, and verse in. And this talks about, you know, the fact that there are a number of companies who have already significantly invested and have a big presence in these places— Samsung, Coca-Cola, Nike, Adidas, and Burberry. And apparently, like, you know, there's big money in doing this already. Yeah. Yeah, things like, you know, building digital twins in the metaverse, NFT-based items that you can buy and have in the metaverse, and, you know, lots of other things like that.

Yeah, I read this and I— it was basically all brand new to me too. It's funny, in the early 2000s, I don't remember if you remember Second Life. That's— I was still at IBM when Second Life came out and IBM had a big push to, to do things in Second Life. So I actually spent a whole lot of time in Second Life, like during work time, because it was encouraged. I think that they were, you know, 2 decades too early, but they were, they were thinking that there was, you know, this was gonna take over and everyone was gonna live in Second Life.

Yeah. It's kind of taken me back to that. But yeah, it was interesting to see all the stuff that is actually happening now. And, you know, I think at the end here, you've got a list of risks, which are interesting as well, talking about the things that you need to think about that are risky in building or being in the metaverse. Yeah, I think there's not a lot of meat in the risks area.

But I think you started a good conversation. You know, hey, what are those risks? And right, did we get them all here? Did we not get them all here? Can you go, can you go and did more depth on them.

I think there's probably a lot more depth we could find, but, you know, it's a good start for the conversation. I also think that if you are, you know, running security for a customer-facing company, at some point there will likely be discussions of whether you should be involved in the metaverse, and having some background will be good. Yeah. Read this article, and you, like me, can take a drink while we do it. All right.

Next, we have a blog post from Red Canary. Uh, talking about taking MDR beyond the endpoint and, uh, and some new product updates that Red Canary has. And Robb, I'll probably leave it to you to talk about them. Yeah, this is super exciting to me. So, um, once again, another blog post that I was excited to do.

Red Canary has been around for, what, 7 or 8 years and has almost exclusively been focused on endpoint until, like, call it last year, where there's been a big push to to enrich detection and response with, okay, endpoints the best place for data, but there's a lot of other data out there that's worth getting. So, um, as of, I think it was last of, last of December, um, we released a thing called Threat Investigation, which, which means not only taking in alerts from other tools but really diving into the details of those alerts for things like email security, network security, identity systems, more and more security tools being covered by the Red Canary MDR service. So that's what the press release is about, or the blog post. There's an associated press release with it too. You know, it's just much broader coverage for customers' threats.

Robb, does that mean that Red Canary is now an XDR?

XDR is a relatively loaded term that I was going to avoid saying, but sure, Alex, we could be an XDR. Sweet. I love it. Extended detection and response. That's all it stands for.

Yes, you've extended. We've extended. Congratulations. All right, one more news story to talk about. We've got some very exciting news here.

We've talked about it previously and in previous years that the CTA every year does their Apex Awards and the award ceremony for that just happened. So we have a brand new CISO of the Year. Robb, do you want to do the honors? Congratulations to our friend and previous host on the show or previous guest on the show, Artie Wilkowsky. Artie is the CISO for Dish Networks, and, you know, he's been there for what, 3 or 4 years now?

Quite a while. Well-deserved. Great, great CISO, great leader. Excited to see Artie get recognized in this way. Yeah.

Also, the other 2 finalists were Sue Lapierre and Julie Cicillo. So congratulations to them as well. Yeah, absolutely. It's a great, great slate of finalists there. All right, let's jump over into events.

As a reminder, we do have an event calendar on the website if you want to come see the things that are going, especially since we're doing this monthly. Not all of these events show up frequently enough, so you can keep taking a look through the month to see what pops up. But coming up in the next couple of weeks, we've got— go ahead, Alex. First, on March 9th, ISSA Denver is doing their March chapter meeting. On the 10th, I almost said ISIS.

ACES, the physical security group, is doing their happy hour Fort Collins in Wyoming. So it's up in Fort Collins. On the 15th, Denver CSA is doing their March chapter meeting. On the 17th, Denver ISACA is doing their March meeting, Security and Controls in AWS. On the 18th, Let's Talk Software Security is doing an event, Hiring, Developing, and Retaining Software Security Talent.

On the 22nd, ISSA Colorado Springs has their, their 9th annual Colorado Springs Cyber Focus Forum. This is a, I think it's a 3-day event. So it's a pretty significant amount of time if you want to go learn and grow with some folks in the Springs. This is a good chance to do it. Awesome.

We have 2 events on the 23rd. ISC² Pikes Peak is doing their March meeting and Denver ISSA is doing a DEF CON Cloud Hacking Village CTF. That's pretty cool. That's pretty awesome, huh? Yeah.

Final event for the month. On the 31st, ACES is doing a women in security brunch called Soldiers in Petticoats. Okay. All right. I don't know what that means, but, uh, we'll have to check it out.

All right, let's jump over into jobs. Uh, I, I am looking to hire— I have a couple positions on the Red Canary website right now. I think there's 3 or 4 security positions, but— and also IT. But this one we're gonna highlight is a GRC analyst. We're looking for someone to, to help with programs like ISO and SOC risk management, maybe a little bit of FedRAMP if you've got that experience, we'd love to talk to you.

Elevations Credit Union is looking for a VP of Information Security. Looks like that the base camp for that is based out of Broomfield.

SSR Mining is looking to hire a Manager of Cybersecurity Operations. This is with our friend Curtis Letson. He just moved over there, what, a month or so ago? Yeah, maybe 2 months ago. So it looks like he's trying to build out his team.

RTD is looking for a senior cybersecurity engineer. Dispatch Health is hiring an information security manager. Global Medical Response is looking for a senior cybersecurity engineer. Air Methods is hiring a cybersecurity analyst. Ball Aerospace is hiring a cybersecurity professional number 2.

So no amateurs. They're going to make you a professional if you aren't. Trustwave is hiring an information security advisor. And finally, Couchbase is looking for an IT and cybersecurity auditor. All right, that is it for the news, but we do have an interview this week.

Alex, tell us who you sat down with. Yeah, so, uh, had a great interview, and, uh, we're talking to Dan Moore, who is, uh, in charge of developer relations. And, uh, I think that we had a great conversation. We talked about many different things related to application security and, uh, All those types of things was really great. All right, sounds good.

Well, look forward to listening to the conversation with Dan, and then we'll regroup again here in April. Awesome. All right. Thanks, Robb. Hello, this is Benjamin Edelen, Chief Information Security Officer with the City of Boulder.

This is Colorado Equals Security for Colorado security professionals by Colorado Security. Professionals. Welcome to Colorado Equals Security. This is Alex Wood, and this is our feature interview for this week. Um, excited to be back with a couple interviews coming up, and today we are talking to Dan Moore of FusionAuth.

Hi, Dan. Hello, how's it going? Good, thanks for having me. I'm excited to chat. Yeah, uh, Excited to chat to you as well.

Why don't you start off by telling us who you are and what you do, and we can take it from there. Sure. So I am Head of Developer Relations for FusionAuth. As you mentioned, I work there, and I've been in Colorado for about— professionally for about 20 years, and I spent most of my life as a developer. And a couple years ago, I've transitioned into developer relations, and in particular for this company FusionAuth, which is an identity and access management company.

And so I have found myself getting more and more involved with the security aspects of software development. So that's kind of my background. Yeah, yeah, that, that's great. So, uh, so in your history, what sort of, uh, development stuff did you do coming up? Yeah, so I've done kind of soup to nuts.

I've worked for 2-person startups. I've worked for companies as big as Oracle. I've mostly done web applications and kind of data database-driven things. Um, yeah, uh, that's primarily been it. I'm trying to think if there's anything else relevant.

No, um, you know, a lot of CMSs, but a lot of like custom applications as well. Nice. Uh, I also noticed on, uh, on your, your background that, uh, that you've been a mentor at, uh, at Galvanize as well. Uh, that's pretty cool. I'm just curious how you got into doing the mentorship piece.

Yeah, so I actually have written a book about you know, with advice for new developers called Letters to a New Developer, Letters to a New Developer. And I have a blog of the same title. And I think I did a presentation or 2 at Galvanize about that and just took the opportunity to see whether they wanted me to be a mentor. And they said, heck yeah, sure. Although, to be honest with you, things have died down a little bit in terms of that focused program.

With COVID Although I will say there's— if you are a senior person in security, in software development, there are gobs of opportunity for you to mentor right now because there's a ton of people come on the market. I actually had a call today with somebody who went through a boot camp and was looking for some advice on how to get more plugged into the community that he was trying to get a job in. Yeah, definitely. I mean, that's something that I see a ton also. Whether it's, you know, either people just coming out of, you know, full-time school or boot camps or other things like that, career changers, you know, lots of opportunity out there for mentoring and trying to get people where they need to be.

So definitely cool to see that you're doing that. So thanks, appreciate you doing that. Yeah, and I will say it is amazing how many— after you've been in the workforce for a couple of years, it is amazing how much stuff you've internalized that you don't realize that somebody just coming in won't, won't know. Like, they don't even know what they don't know sometimes, and just even having a 15-minute conversation can open their eyes to what to learn more about. Yeah, I mean, there's so much stuff that we take for granted, right?

Um, that, uh, that maybe you didn't even realize that you learned, but now that you know Uh, you know, whether it's technical pieces or just, um, you know, navigating within a company or, uh, you know, other stuff like that. Uh, that's, you know, I try and do some mentoring myself, and, um, I think it's really important to you to help give back and do that stuff. Definitely, definitely. Awesome. Um, so, you know, you, you sort of pivoted from a, uh, a trad— well, I'll say traditional, um, a more developer, uh, focused background, now, you know, moving more into, into security.

Was, was security an area of focus for you or was that just sort of something that happened by coincidence? Yeah. So, I mean, I, I remember in 2002 actually reading about the OWASP stuff, you know, and actually I think I might have some email messages from that mailing list a long time ago, but I never— it was never really a focus. It was always, you know, it was always one of the nonfunctional requirements for every website that I built. And I've done stupid things like build my own authentication system with MD5 hashes for the passwords for a small application I built.

I've done wise things like defer to open source systems and, you know, open source libraries, uh, like, or frameworks like Rails, which have a whole ton of very smart people focusing on security, um, built in. Right. So it's like batteries included and there, you know, Rails is the one that I'm most familiar with, but there are definitely those kinds of frameworks and libraries across every application or every programming language for app developers. So I would consider myself kind of aware of security, but definitely more of a consumer, right? More of a, hey, I need to check the box.

Oh, I know what, you know, I need to know what those scary words mean, but I don't necessarily need to be able to implement them. Definitely a consumer of security that was provided by others. Yeah, yeah. Um, and I'm curious on, on your take on this because it is interesting to hear you, you talk about that. Um, I think being a security person, um, and, you know, I've been doing some form of, uh, information or cybersecurity for, for 20-ish years, and, uh, you know, there's always been the, the feeling from security people Um, you know, like, oh, you know, the— those dang developers, um, you know, they're, they're not paying any attention to security.

They're building in, uh, things that are insecure. They're making our jobs harder. Um, I'm curious for, for your, your take on that, um, and maybe, you know, historically, uh, because it sounds like, um, you know, maybe your opinion would have changed over the years as well. Sure. So I mean, I think that security folks are not wrong, right, when they think of developers as being kind of frustrating or just trying to make their lives hard.

I think that the converse is true as well. And, you know, a lot of developers think, well, gosh, why can't I have this, right? Or why can't we just do this to deliver this feature? And I think the truth is, and this is no blinding insight, but the truth is that people have competing objectives and developers are not measured unless there's a disaster. They're not measured on how secure things are, right?

It's not a KPI necessarily, although you can start to bake things into the process. And I see more and more of that happening, which is fantastic. But, you know, developers come in with their own set of objectives and I think that the answer to, to, to solve that problem, which is not a question you asked, but I think I'm gonna kind of go there, is, you know, kind of twofold. One is you want to set up guardrails, right? Like make it as easy as possible for a developer to do the right thing.

And that's why I reached the example of Rails, right? Rails has stuff like CSRF protection built in, encrypted session tokens, and, and I, as a developer, don't even have to think about it. All I have to think about is like upgrading to the latest version of Rails. And the second is, can I continually educate people? And, and that's something I've done more and more in my current position, uh, you know, a very narrow focus of, of security, but still a relevant piece.

But I think as a security professional, it's incumbent on you to, to help sell the benefits of security. And that doesn't mean you need to be like Uh, you know, sleazy about it, right? But it does mean that you need to like help illustrate the benefits of security. And, um, most developers I've found at most companies are very, very interested in learning, especially about new domains. And so I think there's some really cool things about security, right?

Like especially with some of the stuff you can do in the cloud now, um, the automation piece, the monitoring piece, the logging piece. And doing education around that to your developers, I think, will help open their eyes a little bit about how, um, the end goals of both consume— you know, the end goals of both groups are really to deliver value to the end user in a way that isn't going to cause issues. Um, an example of that actually right now today is I was actually reading this section of the 3rd edition of Security Engineering by someone Robinson, I think, and ended up buying the book. But it was just talking about all the enemy actors that are out there that are trying to break into systems. And that was something that I hadn't had a lot of experience with.

But I think if a security person come into my organization and said, hey, I want to teach you guys about this. I mean, how cool is it to learn about spies and like non-state actors and like what they're trying to do to break into systems? I think most developers would be super into that. Yeah, it is always fun to hear about the, uh, the cool aspects of security, right? And, uh, all of the— well, it's not usually that exciting, but you know, the, uh, the potential cloak and dagger or, uh, you know, hacker type things.

Do you think that, that, you know, the, the attitude of, uh, of wanting to learn about security has changed over the years? Um, or do you think it's just that, uh, you know, maybe security people are doing a better job of talking to or influencing, uh, developers? Or maybe just, you know, that security is, uh, is cooler now?

That's a hard question because, you know, all I have is my perspective, and it could be— you didn't offer the 4th option, which is Dan's finally getting smarter. Um, no, but I mean, honestly, I'd probably say the 5th option is I think security is more on people's minds because there's more scale, there's more ransomware, there's more visibility into attacks, um, and there's just more commerce happening online, so there's more money for bad folks that aren't necessarily looking— that are looking to steal things. So I don't want to focus just on that aspect of security, but I think that developers respond to incentives. And I think the same way that developers have become much more aware of, say, user experience, because all the people around them have iPhones in their pocket and they can see beautiful user experience, I think that they've also become more aware of security because there have been all these things that are, you know, front page in the New York Times about the Colonial Pipeline, right? Like, that was a huge thing that, um, I think a lot of people who maybe aren't interested in learning about security might have shook them a little bit.

Yeah, that makes sense. Um, you mentioned, um, incentives. And, uh, you know, one of the things that was, uh, sort of popular on the security side, uh, fairly recently, but it was, you know, more around, uh, gamification of, of different things in security. And, um, I think, you know, in development there are some potentially easy opportunities there, right? It's, um, there is data that you can track, number of bugs or Um, you know, lots of other data around that thing, uh, those things that, uh, the developers are doing.

Um, you know, I think it's a slightly different tactic than just education. Um, and to your point about being sleazy about it, I think in some ways it could be taken as sleazy if you're trying to, to game people to do one thing or another. But, um, do you feel like something like that works related to, uh, to developers and, uh, and trying to, to get security more baked into the development processes? Can you make that a little more concrete than just saying gamification? Like, yeah, so say, um, you know, you're rewarding people for, um, you know, number of security bugs fixed or something like that, right?

Um, yeah, and then you provide some sort of leaderboard, um, or, hey, uh, you know, you guys have, uh, 27 vulnerabilities per 1,000 lines of code and, hey, you know, this project over here, you guys have, you know, 53, the, you know, the lower number is going to get, you know, some prize at the end of the month or something like that. Yeah. You know, I mean, so my gut is you want to— it's an interesting idea, right? And I think that you want to maybe present that to developers and see, hey, if they would respond to it, because there are some teams that might and some teams that might roll their eyes. I do think you want to kind of walk like a line because you don't want it to be silly because people won't take it seriously, but you also don't want it to be too big of an impact on people's— how do I put this gently— livelihood, right?

Like, you know, because then people will game it. You know, they'll open security bugs to like close them or other things like that. But I do think that as kind of a complement to education, it's a great idea. And one thing that I've heard mentioned, which I haven't actually seen implemented extremely well, is to, you know, find those developers that are more interested and have them be security champions in the teams, because developers talking to developers is really just is more effective than security folks talking to developers, right? In the same way that security folks talking to security folks is more effective than developers talking to security folks, right?

If you're— if someone's a member of your tribe, you're more likely to— they're more likely to have credibility to push things that may be tough. Because to your original question, right, like, not all of security is easy, and sometimes it does impact timelines and features. And things that developers are judged on. Yeah, yeah, definitely. Um, I, I think that, uh, I think that's a good segue.

Um, the— I love the security champions, uh, topic. I think it's a great, uh, way to think about it and getting people, uh, you know, who are interested in security to help push that. Um, sort of more relating to you, um, I don't know exactly what someone in developer relations would do. Are you sort of a, you know, a champion in your own right, whether security or otherwise, for, you know, what you're doing in your day-to-day role? The Office Space question.

I love it. What is it that you do here, Dan? What exactly would you say you do? Yeah, so the way I see developer relations is, and especially You know, well, so there's developer relations in general, then I'll talk about it in relation to a security company like FusionAuth. There's developer relations is really about educating developers about your product.

And that could be kind of very top of funnel, like, hey, this kind of product exists, or even this kind of problem exists. Or like, let's pick observability, right, which is slightly different than authentication, which is my focus. Observability exists. These are the reasons why you might be interested in it, all the way down to, oh, you've chosen to use our product. These are the things that can help you succeed at using our observability product in your current situation.

So that's kind of the general world of developer relations. And you can think of it kind of as marketing, but really an education-focused marketing, not like a more typical consumer marketing. That has a, um, kind of a definitive end of a purchase path. Developers are, in my experience, and I think most technical people in general are pretty cynical and pretty sick of being marketed to. And, um, how do I put this gently?

Um, have kind of a— lay it all out there. You don't need to be gentle, Dan. Well, fair enough. Um, they have a low tolerance for BS. But what they have a very high tolerance for is being educated.

And so developer relations, a big chunk of what I do is educate people. And so in my specific context around security, around FusionAuth, we're focused on authentication authorization. And a big chunk of what I do is just try to get folks to realize that they can fundamentally make their application more secure by not writing their own user authentication authorization system, but by using FusionAuth, or frankly one of the other many options that are available out there, and making it less scary, right? Because I've been a developer and I've, you know, looked at the OAuth grants and looked at like how I can do— how I can protect my APIs from a security perspective and just an abuse perspective. And it's the kind of thing where you do it once or twice, but you're not doing it all the time.

And just like anything, when something is high risk and you don't do it often, it becomes petrifying or scary or frustrating. And so my job is to just kind of try as many ways as I can to make analogies, to try to illustrate the value proposition for doing this particular thing, to educate developers on multiple ways that this will help make their life easier. Uh, and again, I get paid by FusionAuth. I like to eat, so I like to do a good job for them. But I also, I want to make every developer less scared of this particular aspect of security.

And that's one of the things that I'm really passionate about with this job, that I get a chance to do that. Yeah, I think that's really interesting. And I'm curious from, from what you see, um, you know, is authentication something that the developers understand or that they're understanding more. You know, I know from a, you know, a security technologist perspective, that sort of stuff is not my forte personally, but, you know, I do understand its importance and I could see where, you know, if someone else felt the same way, developer, I suppose, or somebody else, that, uh, you, you know, you may have those feelings where it's, um, you know, you're not as, as comfortable with it as you should be? Yeah, I mean, I think that the, the root is, you know, I think that like I, I said originally, like when I was not in this field, I was, you know, aware, always aware of security as a non-functional requirement.

I said authentication is more functional, but it's this non-differentiated piece of functionality. And so I think that, uh, it does depend on where you're— where your company is, right? What your company's security maturity is. But a lot of companies come to us at FusionAuth and they've built their own system, and I have never pushed them to understand why, but I can only surmise that they were trying to get something out They didn't have experience integrating other, other systems out there, or conceivably it was around before there was the prevalence of systems that there are now, because there are just tens or hundreds of different options that are, again, some commercial, some open source, uh, some hosted, some, some, um, embeddable. But there's plenty of people who come to us with their own really custom implementation.

And I think that's the kind of the worst of all worlds, right? Because now you have this scary thing that is high risk that you actually have to kind of manage and feed and, you know, take half a developer, a developer a year to maintain this functionality. I don't know. Does that answer your question? I feel like I might have skirted it.

Yeah, no, you're good. But you did— you touched on something that I think was interesting there. And, you know, there are lots of ways to solve this problem, whether it's open source solutions, whether it's commercial solutions.

Why do you think that there are so many solutions?

The problem of like users logging in? Yeah, I mean, providing, providing authentication and access control, other identity access management functions, right? So, you know, if there are, you know, hundreds of potential ways to solve this, yeah, I mean, one, why do you think that there are so many? And secondly, you know, if I was a developer, how is it that I'm supposed to navigate all this stuff?

Yeah, great questions. Um, so I would say that, you know, the reason why there are so many of these is One, they start out being kind of simple. And so I think that it is pretty common to, you know, say, I'm going to create my own open source library to do this. And then you realize how complicated they are and you kind of accrete functionality. But by then, you know, you're— you've done this for a particular language or a particular framework.

And oftentimes, actually, and this is where FusionAuth came from, is actually came from another product that needed login authentication, and then we actually split it off. And so I think that happens a lot. Um, the other thing is that you think that this is simple, right? You think this is just somebody logging in and putting a username and password and then getting access to the systems they want, but it actually turns out to be surprisingly complicated. Especially when you get to larger organizations, they have multiple identity stores, they have really interesting kind of boutique workflows that they want to have for their business reasons.

And so you end up with multiple different providers, and there are some that actually focus on just certain aspects of authentication authorization.

And so I think that leads to the explosion. That's my answer to the first question. The second question is, I think that asking a developer how they can navigate this environment is very similar to asking a developer how they can navigate any of the myriad of choices that developers have to do, right? Like whether that's which cloud provider to pick, whether that's which framework to pick, I think there's a couple of ways to look at it, right? The first is referral, or actually I think the foundational one is what you're experienced with, then it's referral, then it's like Google search and like trusting Google.

Um, and I think it's— they're all kind of underlaid by you should always kick the tires of anything you choose to the extent that you can, right? If you can do a spike to test out some library or some other piece of functionality. That's going to get you familiar with the API or the library, like calling functions. That's going to get you familiar with the documentation. And, you know, unfortunately things are moving so fast with so many pieces of software development that what was best of breed 2 years ago might not be best of breed anymore.

So other than those other sources, if those other sources are relatively recent, that's great, right? Referrals of somebody who's used a tool recently, that's awesome if they can trust— if you can trust them. But it's got to be experimentation too.

Yeah, yeah. I mean, that, that totally makes sense to me. You know, I've been some places before where I've interfaced with the development teams And, you know, it's always great when, you know, you come across either a team or individual developers that are, are willing to take a little bit of time, um, you know, whether it's on their, uh, their own sort of personal time or whether they do have, you know, enough bandwidth to put in a spike to do, uh, you know, some, some sort of side, uh, project, uh, related to security. Uh, you know, as a security person, uh, that's, that's always been something that I've, uh, I've received well, and that, um, you know, those are the kind of people that you end up trying to recruit for being, uh, you know, security champions. Sure, definitely.

Um, yeah, so the— I think one of the, the other things that, um, that I, I often see is that even with, with solutions for things like authentication or, or other pieces like that, you're still having to build in a bunch of, you know, pieces of the puzzle yourself, whether it's standards, you know, making sure they're using the correct standards, or, you know, whether it's being able to meet, you know, the ever-changing requirements for, you know, things like password policies or other things like that.

You know, how is it that you either work with developers or help them navigate, you know, not just the products to use, but, you know, configuration or best practice or other things like that? Sure. I mean, I think that the honest truth is that No secure— anybody who tries to sell you a security product that's developer-focused, or frankly even consumer-focused, that says it'll solve all your problems with no work is, to use the words we discussed earlier, you know, a little bit sleazy. Security is hard work, development is hard work, and so I think that there's always going to be a kind of a set of integration that you're going to need to do. And That will, you know, like anything else, right?

You can pay now or pay later. So you can pay now to like learn the, learn the, the tool or the library you're integrating and get like a mental model of it, right? And you don't need to understand everything down to the bare metal, but you need to— having a kind of a critical component of your application be a black box is a little bit worrisome, right? So I think you can need to spend some time doing that as a developer. You know, ways that you can help with that are— again, I keep going back to proof of concept where you basically try to de-risk things as much as you can, playing with free trials, reading documentation, watching videos.

I don't know. I don't know that there's like a magic bullet for that because it is so varied, other than to just kind of accept that this is something that's— if you're not— if you're doing cookie-cutter like implementations over and over again, then it's possible you can bring some of that knowledge, whether it's codified in documentation or people's heads or in scripts. But a lot of the things that I see in my role aren't the very simple problems, right? They're the ones where it's kind of complicated, kind of, um, bespoke solutions. I don't know, I feel like I definitely didn't answer your question that time.

No, I think you're good, Dan. Um, I think one of the, one of the things that has, uh, always stayed the same in security is that it's always changing.

And, you know, we— I mentioned a little bit in my last question, you know, the, you know, password requirements are constantly changing. The technology is always moving forward. You know, the things that are offered, whether it's, you know, we started out years ago with single sign-on and then, you know, going through You know, lots of other different things like that. What are things that, that you see coming in the future around, around authentication? Sure.

Yeah, so there's a couple things. One is OAuth is actually getting an overhaul. It's been— it was released in 2012. And so if you use OAuth to protect your own APIs or your own services or to access third-party services from, from companies like Google or, or Facebook or whatnot, you should be aware that those changes are coming down the pike. It's not going to be a quick rollout.

They're still working on the specification, but they're basically consolidating a bunch of things, a bunch of best practices. And also, frankly, the world has changed, right? Like in 2012, mobile apps were very, very new. And so they're consolidating all those into a specification called OAuth 2.1. It's not going to be— as indicated by the .1, it's not going to be a radical overhaul, but it is something that is going to be a good thing to keep an eye on.

There's also a new effort called GNAPP, which tries to take OAuth and the idea of the secure delegated access into the 2020s with things like, you know, not using— well, I don't want to get too into technical details, but basically making it more like what people expect around APIs today. There's that. Another thing that's on my horizon is the demise of third-party cookies and how that's going to affect federation. And that's something I'm really just digging into, but I think that you mentioned SSO Um, when you're doing things in the browser, uh, there's a big push to kind of lock down cookies in the browser. And the unfortunate thing is, from what I've read, um, some of the bouncing around that you do when you click on an ad that some of the browser vendors might want to locked down because of privacy concerns, right?

A bunch of redirects to make sure that every, every ad network gets to set their cookies on your browser so they can attribute things. Uh, that looks a lot like bouncing around when you're being federated around between different identity providers. And so there's actually a W3C working group that we recently joined that, um, has been kind of thinking about this for a while and, and working with the browser vendors to say, hey, how can we accomplish this noble goal of more privacy without really affecting something that I think a lot of people depend on, which is the ability to easily kind of SSO between different applications, right? If you, if you use Google and you click on Gmail, then you click on Google Calendar, essentially you're SSOing between those 2 different applications. Um, and we don't want to lose the We don't want to throw out the baby with the bathwater.

Yeah, for sure. I'm curious, how far down the road is that working group? Is that something— is there going to be something that comes out of that soon, standard or something else, or is it just sort of initial talks? So it's been around for a number of months. It is a— I should be careful here.

It's not actually a working group. It's what's called a community group. Which means it doesn't actually produce a specification. It's more like a bunch of people who are interested get together and like try to form some kind of rough consensus. But I think that they'll probably pass off to another group.

I think a community group maybe has a less high standard to be created, but I think they're gonna try to pass off some agreements to other groups to standardize, but it's, it's still pretty early days. And as I mentioned, it's early days for them, but it's even earlier days for me. Like I'm just getting into that. I'm just trying to kind of read up on of the things that they've worked on. But, um, I can definitely share some of that so we can put in the show notes if that would be helpful.

Yeah, that'd be wonderful. Um, and then, you know, you also talked about the, uh, the updates to OAuth. Um, is that, uh, are those the 2.1 specification? Is that complete at this point? And when should people, uh, expect to see that being rolled out?

So I Uh, the standards, uh, bodies move at a, at a pace that, um, is that they wish they were snails? Is that what you're saying? They're probably, they're probably not as fast as they would want to be, right? I mean, I think there's a lot. And, and the thing is, especially when you're updating a standard like OAuth, I think they're— one of the benefits of using a protocol like OAuth is there are so many edge cases that are handled for you that people have thought about.

One of the downsides when you're trying to update it is there are so many edge cases that people want to make sure get handled. So I wrote something like, what's OAuth 2.1 about in April of 2020? And I think that they are still working on that specification, but I think it's like, I want to say it's been through like 11 or 12 drafts. So I haven't checked in lately to know how close they are, but I know that when I looked at that in 2020, they were hoping to be done in a year or so. So they are not, um, as far as I know.

I have not seen an announcement, which I would because I'm on that mailing list. So, um, but I would say in the next year maybe or so. And then of course it needs to get rolled out, like re-implemented, right? Although I will say that based on what I've read, it's not a big reimplementation, right? It's more like disallowing certain things.

Like an example that I think is still— was moved out of the OAuth 2.1 spec when I looked at it, and I believe is still the case, is the implicit grant. Um, is it's not ruled out, but it's no longer one of the blessed grants. And so that will be something that, like, the implementers will have to decide, well, are we going to continue to support the old implicit grant or deprecate it, or how are we going to deal with that?

Awesome, sounds good. Well, Dan, we are getting close to being out of time here. Is there anything that you wanted to talk about that we didn't touch on? You know, no, I think that it was really interesting, and I appreciate you guiding the conversation around you know, that interface between developers and security, because I think that, you know, hand in— they really need to work more hand in hand. And anything we can do to help developers understand the value security brings and security to understand the situation that developers are working under is helpful.

So no, thank you. I'm good. Awesome. Well, it's, it's been great talking to you. I appreciate you spending a little bit of time with us.

And, uh, this has been Colorado Equals Security, and we will talk to you next time. Thanks. Bye. Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes