All episodes

Luke McOmie, VP of Offensive Security at Blue Bastion

Apple Podcasts Spotify SoundCloud

Luke McOmie, VP of Offensive Security at Blue Bastion is our feature interview this week. News from Zillow, Stackhawk, CyberGRX, Todyl, Red Canary, Ping Identity, and a lot more.

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript13867 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is our newscast for episode 234. This is for the week of April 4th.

Alex, how you doing? I'm doing well. How are you, Robb? Fantastic. It's a I mean, gorgeous spring weather out here right now.

I don't know, like low 70s or late 60s, something like that maybe? Yeah, I mean, it's like actual spring, not like, I mean, I didn't mind it, but last weekend when we were in the 80s, that's a little too summery for the spring for me. Yeah, I love this right here. So good weather, good week. We're moving towards your birthday, moving towards tax day.

It's all coming up. Yeah, getting close. It— you're giving out some PII on the, uh, the, the podcast here. I didn't, I didn't mention when your birthday is or your Social Security number. Um, but the last 4 numbers are— just give me the— just give me the first 3 to validate that it's really you.

Okay. And then, and then later I'll validate with the middle, the middle 2. And then— okay. Yeah, perfect. That's great.

Hey, let's talk about the, uh, some housekeeping here. Yeah, let's do it. You know, Robb, we have a Slack channel. And, you know, it grows and grows. I think we're like over 2,200 now, something like that.

We— I'm sure we could look at the actual number, but that'd be a lot of work. That would be a lot of work. Lots of great conversations in there. I actually met some people from the Slack channel for lunch on Friday. One of the great uses of the Slack channel to coordinate social activities now that we can all get back together.

So that was fun. What did you eat? We went to Grange Hall, which is a food hall. So you get multiple choices by Troy Gard, by Troy Gard. Proprietor of Garden Grace.

Yes, I had a chicken mole plate. Oh, it was good. Interesting. Yeah. Is there there's a Mexican place in there now?

I think it might be like Peruvian or something like that. It's I don't think it's Mexican, but it's that's new South American. Interesting. Yeah. Hey, so in addition to Slack, which is how you we got on that very long tangent, we have a mailing list if you want to get the the show notes into your inbox directly.

We would also love it if you would rate and subscribe. Rate us on your favorite pod listening application and subscribe. So this thing drops into your inbox every week. We've actually had a lot of new listeners recently. I assume it's because we're doing it less frequently.

So they're less annoyed by us. And the less we do, the more they listen. I think it's based on the Russia-Ukraine conflict. They've, you know, Russia's got a bunch of bots out there trying to figure out what they can exploit. And apparently, they're, they're listening to our stuff to figure out where all the security weaknesses are.

Oh man, I wish I was ready for this with a really clever misdirection to give the Russians. Yeah, make sure you attack us just off the starboard bow. Yes, there you go. Uh, also, uh, we would love it if you told a friend about Colorado Equal Security, both the podcast and everything else that we have going on. Uh, and finally, if you want to help support the movement financially, we do have a Patreon campaign.

Thanks to all of the current patrons that they that we have. Uh, you know, they really help us with the costs of all the stuff that we do. Um, you can find more information about that also on the website, colorado-security.com. And, uh, several levels there. You get some cool stuff if you sign up.

Shirts, shirts, shoutouts. Yeah. All that kind of thing. Squeezes. Uh, that's right.

Like Battle Bears Beats and Battlestar Galactica. That's where I was right there. I was trying to come up with my own version. Uh, good stuff. All right.

We've got news. Hey, the first story. This is an important thing. Are you thinking about buying or selling a home? Well, if you're thinking about selling your home, Zillow has looked through different regions and they have specifically said when is the best day of the year to sell a home in Denver?

Yeah. And if you're thinking about that, you're already screwed because it was in March. But also early March, early, early March on a Wednesday that I thought that was interesting. Wednesday is the best day to list your home. I guess that makes sense.

You got a couple days before the weekend for people to figure it out, and then you can have everyone come and look at it on the weekend. And if you're thinking it only makes a little bit of a difference anyway, oh no, no, no, it can mean a whopping $30,000 more for your— for the seller. Yeah, I don't know what the number they were basing it off on, but you know, they have a percentage I think in there too, so we could probably reverse engineer the math. But that, I mean, that, that's a big difference behind March. April is the second best month.

So you do still have some time to get almost the best time to list your house. Yeah. What it's saying is in March, it is a 4.7% premium over a typical home. In April, it's a 4.2% premium. So you're still doing okay if you get this news and go, go post it now.

Probably better than waiting a year to get back to March. Yes. They also mentioned some times when you shouldn't. I think it was October that is the worst time. Yeah.

October is the worst. And you're selling at a 5.7% discount, $37,000 less. Wow. Wow is right. Wow is right.

And if you think to yourself, why is Colorado Equal Security talking about this? Because we want to. Right. That's what we do. All right.

Moving on to the next story. This, this one is a bit of a vanity story, pun intended. Colorado might soon allow digital license plates and Uh, here's why people and companies want them. When I first read this headline, I'm like, this is stupid. Why would we even want digital license plates?

What is a digital license plate, Alex? Um, so they mentioned it several times in the story. It's not for advertisements, just so you know. You can't put any banner ads on your digital license plates. Um, not yet.

Not yet. Um, but it's the way to set it up. So the, they describe it sort of like, you know, an e-ink Kindle. Right. So you've got something that digitally displays your license plate instead of being the stamped aluminum license plate.

They do also mention if this goes through, you will still have to have one aluminum license plate. But the other one could be the digital version. Some of the reasons that they, they mentioned for this is more for the commercial side. You know, if you're a fleet owner, and you need to go through and, you know, update the registrations on tens or hundreds of vehicles, you know, instead of having somebody go through and, you know, put stickers on all of the new trucks whenever they can find them so that the registration is up to date, then, you know, it sort of automatically happens once you renew it because of the digital plates. Yeah, it is something— I mean, I totally agree with you.

When I first saw it, like, a digital license plate, what? Why? I can't imagine ever needing this thing. I'm not allowed to just change my license plate number anyway. What's the benefit?

It's not for us. Right. Right. It really, there's not a lot of, there's not a lot of, you know, individual consumer use cases for this. Yeah.

And they don't talk about it specifically, but they do talk about its use as a, as a vanity plate. Um, you know, hence my pun, but, you know, custom license plates. And I don't know if that means like also you'll be able to change the theme of the license plate or something like that too. Um, which, yeah, I mean, that would make sense even if you can't do ads. Like, you know, some people have like the, the fishing license plates or the CSU license plate or whatever.

I mean, and like maybe if, you know, if you're someone who is going to drop your car and put like, what do they call those lights underneath it? You know, that, right? If you're gonna be that colored, maybe you have the ability to do something similar with your license plate while it still looks good. Maybe that'd be nice too. The other thing that they mentioned is that there's absolutely no way that this could be a security risk.

Well, I won't even think about that, right? Because the, you know, they're not allowed to GPS track you, and they use bank-level encryption. Oh, you know, so everything's fine. What level of encryption does the bank use? Exactly.

I hate— honestly, I hate that term. I see it every once in a while and it's like as good as military-grade encryption. That's— but that's both— they both mean exactly the same thing. Nothing. 256-bit.

Yeah. Anyway. All right. Hey, we have another story. This is a LinkedIn article about the top 10 cities for job hunters.

And Alex, no surprise, Denver is one of those top 10 cities. Yeah, I believe Denver was number 6, which it also held last year. So that's great for Denver or for job seekers in Denver anyway. I don't know about for employers in Denver, but good for everyone that has been, been changing jobs through the, the Great Resignation. You got a lot of opportunities.

It's an opportunity magnet, says the article. Wow. Opportunity magnet. Also, they mentioned our nemesis Austin was number 1 on the list. I hate Austin.

Yeah. What was really surprising, though, was San Francisco and Seattle were in the top few. But, you know, there's been a lot of jobs leaving those areas. So it's really interesting to me that while a lot of people and jobs are leaving the Bay Area, that it's still very high on the list for, for job seekers. Yeah.

I mean, my guess is that there are— most of the companies are not leaving those areas and the companies would probably rather hire you in those areas. So I'm assuming that that's, that's why. But who knows? I'm just— a lot of the data from this comes from job postings saying, hey, where are they looking to hire? And if it's posted in the Bay Area but they hire a person in a different city, right, it would have still shown as a Bay Area job.

Yeah. Or it could be, yeah, they list it as a Bay Area job, but also like sub-list, you know, 27 other cities too. And I don't know how that gets counted. Anyway, you mentioned Austin was number 1. Seattle's 2, Raleigh-Durham 3, Boston is 4, and San Francisco 5.

Good stuff. All right, moving on to our next article. There were 16 Colorado companies on Forbes America's Best Startup Employers list, and several of them are companies that we are already familiar with. Yeah, we know and love some of these guys. The highest Colorado company on the list is number 43, and it's SafeGraph, which I think we may have talked about before, but possible.

But I don't remember what they did. Yeah, I don't remember either. It does say that they track data across business listings, building footprints, and foot traffic for nearly four or simply seven million points of interest in the United States, tracking how often people visit different places. Yeah, and that I mean yeah, that that means mostly nothing. But well, they track data data tracking whatever.

It's a Peter Thiel company. I think the the cool thing is that number two, which was at 48 was Deepwatch, which is a cybersecurity company that is technically not based anywhere. Right. But well, I'm sure that they're, you know, they have legally a headquarters somewhere, probably Delaware. But, you know, they consider Denver one of their headquarters.

They say it's the de facto headquarters. And if you remember, Deepwatch was one that we first were scratching our head like, what is this company? They spun out from Guidepoint Security and they do— it's MDR, right? Managed security services. They're not the only MDR provider on this list though, as you'll see as we go.

We don't need to go through all of them, I don't think. You know, a couple other interesting ones to call out. Boom Supersonic is at number 132 on the list, and JumpCloud is at 172, which— JumpCloud is just so interesting how, you know, they're actually not all that new a company, but they've had a great renaissance the last few years. Yeah, they've been growing a lot. You know, a couple other security companies, Automox is on here, even though they misspelled the company and called it Automax.

AutoMaxx also a company? Yeah, they probably sell cars. I think they're like a car parts store. Yeah, something like that. And then many other companies we've talked about before— Strive Health, AmproBiotics, Red Canary.

You just skip right over Red Canary. Red Canary is at $277, right next to AutoMaxx. Yeah, I think there's a couple that we hadn't heard of before— Grassburger, which is based out of Durango. But anyway, lots of cool companies on here, and it's, it's great to see that We have some great employers in Colorado, and we'll we'll actually talk about some of those same companies again. Is it the next story where we get into the the Inno?

Oh yeah, I think it is. I just next. Yep. Yeah. So in the last podcast, we talked about the Colorado Inno Madness 2022, and so you know this is the sort of bracket style pairing of companies to try and see who it is that people think.

Are the, the best, uh, companies in Colorado that they would want to invest in, the most return. Basically asked which of these companies in, you know, in a round, round by round, which of these companies do you want to invest in all the way through. Number 1 seed at the beginning was JumpCloud, uh, number 2 was Guild Education, but we're all the way to the finals, Alex. We are. And this is, I mean, this has got to be a massive leap forward, a milestone for security in Colorado.

Yeah, there are 2 security companies in the final. Two out of two. Two out of two. Yeah. Yeah, that's awesome.

In case anyone's bad at finals, that means just two. The first company is Stackhawk. Caw caw! And the second is CyberGRX, which is also misspelled in the article once as CyberCRX. I don't.

I don't know that CyberGRX has a sound that we can do here. I feel like there's something of a disadvantage for them. I um I. What's the we don't like our vendor sound? It's like, wah wah.

Because because they find risk. Yeah. I you know for some reason CyberGRX makes me think of like a transformer sound. But yeah. Thank you for doing that.

That's why I didn't have to. But anyway, I I don't know how much longer voting is open, but actually I do know because it's right in front of me. It's open till till April fifth till Tuesday. So if you listen to this Sunday or Monday. Go get your vote on.

Let's let's put your favorite security company into the championship. Yeah, I think that you probably should use two of your email addresses and then just vote once for each of them. That's a great way to have no impact on the on the election. I think we want to drive the votes up because you know the more votes that are there, the more important it makes security companies in Colorado. So those Russian bots who may be listening, we've got a task for you guys.

Anyway, congratulations. It's awesome. It was great to see the security scene doing so well. 2 great companies, StackHawk and CyberGRX. Let's see who ends up taking it home.

We'll let you know in May. Awesome. Next, we have a funding announcement. Total, which we've had the CEO of Total on the show before, they have raised their Series A, which I guess is a little bit surprising to me because I figured that they'd already had an official Series A raise. But They have done that with a $28 million Series A. Yeah, I think they would— they called it seed round before when they had their— they had $3.6 million, which, you know, just numbers have gone up a lot.

Yes. $3.6 would have been a Series A, right, 5, 7 years ago. A $28 million Series A, that's a serious investment. It is. That's, that's pretty big.

Yeah. Good for them. If you're, if you're interested in going, we talked to John Nealon on the show Earlier last year, if you go look through the episodes, well, actually, I'll let you know in a little bit what episode it's in, but I don't remember off the top of my head. But just so folks don't forget, Total, they are sort of a, what's the, a platform provider for security capabilities. So you can go to them and use the Total platform and get multiple different security capabilities from them.

So it's awesome. Congratulations on their success. And we're looking forward to, you know, obviously raising is, is just the beginning of the work, right? But it's, it's really important beginning, and I'm glad to see it happen. All right.

Well, Robb continues to look, I will move on to the next story. Actually, don't do it. I've got it. It's episode 189, episode 189, if you want to, if you want to listen to the interview with John. Cool.

Next, we have a blog post from Red Canary talking about their annual threat detection report. Uh, Robb, what do we have going on here? Yeah, this is, it is really interesting stuff. So Red Canary has, you know, hundreds of customers with millions of endpoints and, and take all of the detections, all of the bad things that we see over the course of the year. And at the end of the year, we look at trends.

What, what are the, what are the trends of bad things that are occurring? Um, what, what attack, what OSs are attacked? What vulnerabilities are used? What are the precursors to successful attacks? All this stuff all packed in here to say, you know, to say, this is— these are the things you should be protecting in your environment.

I think it's, you know, similar to the way that Verizon has done their data breach incident response reports for years. You know, that's looking at successful incidents. This is looking earlier in the kill chain at attacks that were detected. You know, so most of those attacks were stopped. Okay, so how do we make sure those things continue to be stopped?

We don't have to turn into an incident. To learn from it. Yeah. This year there's also an executive summary report. You know, you don't have to read the 80 pages.

Thank God. It's a lot of content and it gets very technical in nature. Um, I think it's nice to skim the executive summary report and then from that, go take a look at the larger report and see which ones you want to dive into. Awesome. Good stuff there, Robb.

I can't believe that you did not include, uh, the Red Canary article about, uh, Red Canary's podcast this week. So, so Red Canary, So on April 1st, Red Canary released a brand new podcast, and and right to the highlight of it is people reading the the hashes out loud that you should be banning. So anyway, it's you should go listen to the Red Canary podcast. That's the only other one you should listen to besides Colorado Equal Security. But it's a one-time podcast.

It'll take you about nine minutes, and if you're if you're not laughing, I don't think you get it. Yep. All right, moving on. There's an announcement. It's this one's a little bit older, but still very relevant.

Cloud Flare, CrowdStrike, and Ping Identity made an announcement that they're going to be offering some of their services for free to critical infrastructure. Yeah, this is neat to see, you know, 3 public large security companies team up together and say, hey, we can cover some of the most important elements of your security for you— endpoint security, cloud security, and your identity. I mean, it doesn't get much more comprehensive than, you know, if you get to pick 3 things, those are a good 3 things to pick. And the fact that they're willing to offer together just to help those critical infrastructure areas is really cool to see. Yeah.

And this came out of the announcement from— was it the White House or CISA? One of them announced basically that their shields— it must have been CISA— their Shields Up announcement. Yeah. To say, hey, you know, with all the stuff that's going on in Russia and Ukraine, you know, be even beyond even more alert, you know, stuff is going to be happening. So because of that, they gave some tips.

And then here are some private companies that are sort of pitching in to help with that, to offer some services that can help you in those areas as well. That's awesome. All right. Next story, we have a press release from the National Cybersecurity Center, which is down in Colorado Springs. They have announced the launch of Project Pisces here in Colorado.

I had not heard of Project Pisces until I saw this, but it's a program that's already been successful in— was it Washington State, right? Yep. State of Washington, really around offering networks, outsourced network security for very similar to the last story, right? For public sector, municipal, you know, special districts that just don't have the resources themselves to get to watch their own environment. Yeah, there are some limits on who can take advantage of it.

It's aimed at the, you know, sort of really small water utilities and special districts and other things like that that are not going to have those resources. And basically, they have teamed up with Metro State University. And Metro State is throwing some of their cybersecurity students at this. They will be the ones that do the monitoring in the Pisces system to get another set of eyes on things that are happening at these utilities, because they probably don't have the resources to you know, hire a full MSSP to do this. So I think it's great.

It's a great program. I actually— they talk in here to Robert McNamee, who's the chair of the cybersecurity program at Metro State. I've been talking to him about this and actually hoping to get him on the podcast here pretty soon and do an interview. So maybe we'll hear more about that. Yeah, it looks like it's free or low cost.

So I'm guessing it's— there's a pay what you can pay type of a model. Yeah, right. If it's really, really tiny, it's probably free. And then, you know, as you get bigger, prices scale up. Yeah, that'd be my guess.

Anyway, cool stuff. And we've talked about, you know, what exactly does NCC do? And we're learning along the way. This is a good example of— this is something they do. This is a new thing that they're doing and it's pretty cool impact.

Awesome. Uh, last story that we have, uh, this came out just before our, or just as our last, uh, episode was coming out. And so we saved it for this one. Uh, this is a blog post I think it was this in Forbes. It was, yeah, Forbes.com, which is, I mean, hey, that's pretty cool, by Mary Writz, friend of the podcast, former guest interviewer on the show, friend of mine.

And she's talking about her lessons learned as a woman in cybersecurity. Yeah. So this was timed around the— was it National Women's Day? Is that right? Yeah, I believe so.

It was timed around National Women's Day. And, you know, I know that I saw quite a few. We had a couple of different stories we could have picked. To talk about that this month, but this is a good one because it's autobiographical, you know, her experience coming up very early in the security community, you know, going to conferences, you know, where she was often the only woman there and what's that dynamic look like and how has that changed and how is it still the same for folks coming up behind. She does a good job giving some, I'd say, relatively practical actionable advice for folks coming up behind her, you know, around building a network, You know, be true to yourself.

Don't feel like you have to conform just because, you know, you're in the minority. I love this one. You know, take up space, right? And like, not, you know, don't be afraid to be a presence in these places and find mentors who will help you and make you be successful doing that. And then moving forward and finding, you know, the path to better representation where she's talking about bringing up other people behind you.

And, you know, there's this whole cycle of life for, for making this thrive over time. I loved it. Yeah. And, and as part of this, Mary is saying that she tries to give back in that sort of, in that last section and, and be a mentor to people. So, uh, you know, I don't wanna talk for Mary and she'll probably get overwhelmed, but you know, if you wanna mentor, Mary is an awesome person.

So, um, I, she's obviously willing, so you could probably reach out to her if you're, uh, someone who, who's needing a mentor. Yeah. Good stuff. Hey Mary, thank you for writing that up. Yeah.

Good stuff. All right. That is it for news. Let's jump over to our events. We wanna remind you that we do have a calendar of events.

Um, that you go out to the website and you can see what's coming basically, I think, through June or July right now where we got quite a bit of stuff coming. First, uh, on the 14th of April, ACES is doing their Women in Security Coffee Chat. Same day, there is a Women in Cybersecurity Fireside Chat in Colorado Springs. If you want to do ACES's Women in Security chat in Denver in the morning, drive down to the Springs for the afternoon, you're going to have a fantastic Women in Security day. I think that's great.

Uh, ISSA Colorado Springs is doing their April meeting on April 19th. On the 21st, Denver ISACA is doing their April meeting, which is actually their general annual— their annual general meeting as well. On the 22nd, the Let's Talk Software Security group, uh, is going to be doing securing open source software. Same day, DC303 has their April meeting. They're, they're getting together in the evening there.

That's a good time to hang out and do some hacking. On the 23rd, ISSA Colorado Springs is doing their April mini seminar. On the 26th, the Cloud Security Alliance is doing their April meeting. On the 27th, ISC2 Pikes Peak is doing their April meeting. All right, let's jump over into jobs.

Um, there's a few great jobs at Red Canary right now if you want to come work with me over there. You know, I know that we have some IT, we've got some, um, some other stuff coming. This one specifically right now, we're hiring a GRC analyst, someone to help us drive forward our compliance and risk management programs. Speaking of jobs, Robb, I got a new job. You got a new job?

I did. And we're going to be building out the team. I don't have any jobs to talk about yet, but I would imagine I'm going to have some to talk about here in the not too distant future. What kind of people would you like to send you a Slack about this? I don't know enough yet, but if you're a cloud security person, I would, I would bet that that is a skill that I will need.

Awesome. Uh, speaking of other jobs, uh, Clover is hiring a manager of security engineering right now. Yeah, and I think it was, uh, Rishi Malik that posted this one, so I would imagine you would be reporting to Rishi or working with Rishi. You send him a note in Slack to ask questions. Yep.

Uh, ULA is looking for an information security architect 5. I'm not even kidding, that sounds like a really hard job. I don't know, right? Like, I know being a security architect, like, is hard, right? And now you're like the 5th one up the chain for a rocket company.

Like, this has got to be like a really hard job. You have to have some skills to be at level 5. All right. TrackVia is hiring an information security GRC analyst. Innovate— I think that's supposed to be Innovage— is looking for an information security compliance analyst.

The city of Littleton is hiring a cybersecurity analyst. Sumo Logic is looking for a security compliance manager. The Colorado Judicial Branch is hiring an information security manager. This is both the longest and I think probably the most interesting job that we posted this week. NERC is looking for an energy threat and analysis center, which is called the ETAC, security advisor.

So I think you're advising that council on energy threats. That sounds like a really cool job. That sounds like a cool job too. Yep. Uh, last one here, we have an intern job.

EchoStar is hiring a cybersecurity intern. Yeah, go, go work with Paul K. Sounds good. Awesome. Well, I think that that is the news for this week, but we do have an interview. Oh, and it's not for this week, it's for this month.

You're right. Yeah, this week it's, it's for both. Yeah, you can be forgiven. Uh, we do have an interview. We, we have, uh, Luke McOmie, uh, sat down and talked with, with, uh, Frank Um, Frank Victory.

Um, so thank you to Frank and Luke both for doing this. I'm looking forward to hearing all the insights, uh, from the interview. Yeah, should be good. I'm looking forward to it too. All right, Alex and everyone, have a great week.

We'll talk to you again next month. Thanks, Robb.

This is Jay Wilson, CISO of Healthgrades. Welcome to Colorado Equals Security, the podcast for Colorado security professionals by Colorado security professionals. Well, hello, Colorado Equals Welcome to this special podcast. My name is Frank, and I'm a guest host for this podcast here. Uh, my guest today is Luke McOmie, and he is an icon in the security industry.

You may know him for the founder of DEF CON SkyTalks. He's an extrovert, passionately supports the information security community. He's a featured speaker at various conferences, a published author, and an industry liaison for many businesses and organizations. He's proven himself to be highly effective at creating security programs. Luke has been involved with cybersecurity since it was a thing way back in 1994.

He founded his first company before graduating from high school and has worked as a trusted advisor, security leader, and mentor. He has founded and contributed to several industry-leading careers including startups, Fortune 100 enterprises, and federal agencies. He's also the Vice President of Offensive Security at Blue Bastion and a dear friend of mine who Welcome, Luke. Luke, how are you today? I'm doing great, Frank.

Thank you so much for having me. Thank you. Thank you. So, Luke, uh, before we get started here, I want to start with an icebreaker here. I— since I do know you a bit, I want to talk to you.

And the first thing I want to ask you is, what is the— I know that you have a huge thing for books. You love books. And we're going to talk about this here in a second. But what is the worst, or maybe even the best, book to movie adaptation that you've ever seen, or book to TV adaptation that you've ever seen? Oh man, that— and you only get to choose one, by the way.

You know, I'm gonna go with this just because it's fresh in my mind, uh, A Wrinkle in Time. Uh, okay. I absolutely loved Madeleine L'Engle's A Wrinkle in Time when I was a little kid, and when Disney came out and released the more modern version of it I really thought that they, uh, that they kind of chopped up and were mean to the story. So I'll go with A Wrinkle in Time. A Wrinkle in Time.

Okay. Well, my personal one I don't like is Ready Player One, and, uh, just because they changed the story so, so horribly. I'm a huge fan of that book and audiobook, and I've read it several times, but wow. So A Wrinkle in Time for you, uh, Ready Player One for me. Yeah.

And I'll tell you, now that you said that, the first thing that came to mind of how frustrated I was about how they changed the story would have been Starship Troopers, actually. So— oh really? One there. Yeah. Oh, okay.

Well, what did you not like about it, I guess? Uh, well, one, uh, my ex-wife and 2 of my ex-girlfriends were casted, uh, actors in the movie, so I was super excited when it came to shoot. Uh, I, I loved Robert Heinlein's books, and I, I thought his stuff was awesome when I was younger. They actually filmed Starship Troopers out in Wyoming, where I'm from. And when, when the movie came out, it was just horribly disappointing because it was just huge sections of it and huge points and main purposes of the story had been modified to make it more, I guess, agreeable for film.

Hmm. Okay. So they changed it. I mean, if I remember the movie correctly, there wasn't much of a story. It was just a lot of shooting and a lot of, a lot of violence.

Yeah, pretty on point. All right. So we started talking about books, and I know that you have a huge love for books. Do you want to talk about that a little bit? Yeah.

For me, you know, it's interesting. I grew up, like I said, in Lander, Wyoming, and I was always a bit of a book nerd. I always hung out in libraries. It's part of the thing that originally got me access to computers was, you know, our public library and our school libraries were some of the first places where we had computer systems that were available for public use, you know, way before they were really in people's homes. So that, that brought me there.

But my mom and dad, you know, where I grew up, they lived just a couple blocks away from our public library, and it was a Carnegie Library, and they just, they had everything. I used to go there and just spend hours endlessly browsing different types of books and different information. And it's funny because I, I have a love, um, probably more for nonfiction than I do, uh, fiction books. I've read a lot of fiction. Um, there are a lot of artists or authors that I really enjoy, um, but I find myself really getting lost in reference manuals and guides and in history.

So, oh, interesting, interesting. You like, you, you like to read the reference manuals. That's What do you find fascinating? I mean, like, most people would not sit there and say that they'd like to read manuals on their spare time. For me, it was always an ability to learn something, um, in, in a very— you know, I, I guess I liked the, the procedure and the structure of how they would write that stuff.

You know, people used to make the jokes that, you know, it was like reading stereo instructions, right? Or, or whatever that old adage is. But I, I really liked that. I, I liked knowing what each button did or what each little knob did or, or something else. So I, I would study that stuff.

I remember really specifically getting lost in, in books about electromagnetism and motors and radio. I had this, uh, a bit of a mentor when I was growing up. His name was Chief, and, uh, he'd been in the the Marine— or I'm sorry, in the Navy, uh, and had spent, uh, his time there. And he ran a small gas engine and machine shop, um, where he repaired people's electrical motors and, and engines and other types of things like that. And he was just wicked sharp at it.

But I remember, uh, when I was young, really young, he gave me a copy of one of these, uh, military manuals that really talked about how electromagnetism worked and how you could create a motor. And I just got lost in it. It was, it was just amazing. Okay, so, well, I guess the magnetism is great and the technology is great, but tell us about this mentor that you had. Um, Chief.

Yeah, about Chief. Yeah, yeah, he, uh, he, you know, he was pretty cool. He, he, he had this little shop and it was right, um, you know, about a block from my house, so I would go hang out there after school. Had a candy machine, other stuff like that when I was little. But, uh, really, I think one of the biggest things that I, I want to always sneak in back was that he had, uh, Playboy calendars hanging up on his wall.

I remember, I remember as a little kid just being like blown away by this, you know, by, by this guy that had these calendars hanging up. And, you know, the more I got to know him and talk to him, the, the more he was, you know, somewhat of a like a big brother mentor, you know, something like that. It'd be the right way to put it. But he, he always was a good man and someone who I saw that both my mother and my father respected and liked. So it was someone that, you know, I spent time around trying to kind of learn from and pick up some of the traits and, and just abilities and things that he had.

Like I said, I used to think his work was just magic. You take things that people have busted And he would put an hour or 2 of work into it and work like new or better than new. Do you think it's important though for people young to have a mentor, you know, someone besides their parents? Oh yeah, of course. I, I was blessed with the town that I came from.

Um, you know, my, my town, very small town in the middle of Wyoming on the reservation, and, uh, I would walk to school, walk to and from school every day. And there were all these little spots along the way that I'd stop at. Another one of my mentors when I was growing up was a guy named Tony Spriggs, and he had Spriggs Sheet Metal and Construction. And, uh, I, I would go in and hang out, and after getting to know the guys who worked for Tony, um, they started teaching me things, right? So like, as a grade schooler, I was able to— I knew how to fold boxes and, and do basic ductwork for like sheet metal.

I knew how to spot weld. I'd learned how to cut metal to where, you know, you wouldn't get these sharp edges and how to take an edge down on a grinder. And, you know, it again, growing up in a super small town in Wyoming, early '80s, that kind of a thing. You don't mind that your kid's going to make ninja stars in a local sheet metal shop. My parents, my parents were always just happy that I was hanging out somewhere and that they knew that, you know, I was, I was being decent or somewhat good.

Okay. Well, I want to kind of key in a little bit on what you just said here about growing up on a reservation? Yeah. Wind River Reservation. Amazing place.

Center of Wyoming, huge reservation. Wind River is run by the Joint Tribal Council of the Shoshone and the Arapaho tribes. Both amazing tribes and just exceptional people. So yeah, where, where Lander is my hometown, it's kind of this little island in the middle of the reservation. And, uh, where, where we grew up was where Chief Washakie, uh, had really set up base and, and where these tribes were at, uh, with one of the tribes.

And then the other tribe was moved there, uh, and became more populous, uh, when the reservations were established. But, uh, yeah, it's all along the Oregon Trail through running right through the center of Wyoming. Cool. So what do you think would be the best thing that has shaped your personality growing up there?

Oh man, there, there's no single individual that I could call out. I mean, my, my family are, are, you know, they all each individually played a key part in who and what I am today. Uh, but I mean, I, I would say that Lander as a town really, um, had a large contribution to that, right? They say it takes a village. Well, in my, in my hometown, everybody knows everybody, so it really does take a village.

There were countless people that I can tell you, from, from bowling alleys to, you know, shop owners. Uh, you know, I'll never forget, I— the one and first and really only time that I shoplifted in my life, I was a little kid and I got busted by the guy that owned our local hardware store. I was trying to steal a fuse, like really, really nothing important, just a fuse for like something electrical that I was creating. I can't even remember what it was now. I just didn't have the money for the fuse and I wanted it, so I pocketed it.

Totally got busted. And I remember, you know, the, the guy that ran the hardware store, he called up my father, and my father came down, and he was incredibly disappointed and frustrated in me kind of a deal. And I, uh, I ended up having to sweep floors for this hardware store, uh, for a couple of weeks, I think. It— very long time ago. I was quite little.

But I remember it being this thing of, you know, learning from it, where it wasn't the fact that I had I had stole this fuse or stole this fuse that was an issue. It was the fact that, you know, I had done something that had dishonored my family name, had dishonored, you know, myself and the way that people perceived me. And I think that when you grow up in a small environment like that, you know, you're held to account in the way that you behave and the way that you treat others. And I think that that Wyoming way is really something that shaped and kind of helped develop who I am today. Well, I think what you said was very important, especially with the learning and, and almost basically a sense of honor, because I'm sure that a lot of our listeners out here are parents.

And at one point, probably a lot of them would have to sit there and deal with things like this where their kids are shoplifting or committing other type of crime that may not be very serious, but gives you, you know, I think that what you just said will give them some insight as to maybe how to deal with it. Yep, absolutely. Yep. Right. So the other thing I know, uh, and I want to kind of— I don't know if this is really an exposure here, but, uh, you are named Pyro, or some people know you as Pyro here.

And, uh, do you want to kind of explain that? Yeah, more, more people probably know me as Pyro than, than as Luke, uh, interestingly enough. Um, I, I came from a fire— a family of Pyros. Uh, Lander, Wyoming, again, going back to what we've been talking about, is a place where On the 4th of July, from dawn till dusk— well, from dawn till dawn almost, it runs for pretty much straight 24 hours— this 1-square-mile little tiny town in Wyoming gets lit up like nothing else. There are countless families that, that come in, and we all compete to, to really try to have the biggest, baddest, you know, loudest, strongest fireworks show.

And I grew up really being influenced by my uncles and my father, who, you know, all had worked in mines and were all pretty quick hands at being able to create some pretty wicked fireworks. Where I'm from is also the home of Flying Phoenix Fireworks, which is one of the largest fireworks importers in the United States. I think maybe possibly largest to the west of Mississippi. And it gave me an opportunity. I started working at the fireworks stand.

I think I was 12, maybe. I remember I had to have a parent's signature to have permission to work that young. But I started selling fireworks and I was really into the chemistry of fireworks. And 12 years old, I guess I was 12, I had made some electrically triggered mines in my backyard. And when one of them went off, uh, the way it wasn't supposed to go off, you know, it clicked off and blew up in my hand, burned my thumb really bad, third-degree burns, ended up in the hospital.

It was just really messed up from it. And my mom came in and was checking on me, and she goes, you know, how's my little pyro? And the name stuck. Uh, interestingly enough, my parents being smart people and, and really good parents, they knew that they weren't going to be able to keep me from doing this stuff or looking into this stuff, so they kind of insisted that I got an education and that I did it right. So I joined the Pyrotechnics Guild International, which is a guild of pyrotechnicians, and I started studying all kinds of guides and books.

I think really the, the first book that was hugely influential on me was George Wingart's Pyrotechnics, and then probably second only by The Chemistry of Powder and Explosives. Both those books really helped me kind of learn the right way to do this stuff safely, and, and really with a focus towards doing it for beauty, right? The art of things. I've never been into explosives as something that is destructive. It's never been what has been attractive to me.

In fact, one of the big things I've done— anybody that's ever watched fireworks or, or show that I've ever put on, I'm really big about creating really loud, really bright type effects without it having any form of shrapnel, really. So it's— they're, they're loud and they're impressive and they're bright, but there, there's nothing that could hurt anyone, really. Wow. So how old were you? I mean, you were 12 when you started working there.

How old were you when you joined the guild? Uh, I think 14. 14. I was, I was working at the fireworks, uh, stand and these, this couple showed up, uh, Pam and Chip Atkinson. Uh, and at the time I believe that they were guild board members, uh, like secretary or treasurer or something like that for the guild.

And they showed up and they were kind of poking around there from Colorado. And they're like, hey, we heard Wyoming has really great fireworks. And I'm like, well, you know, all this stuff's Class C, meaning consumer grade. Uh, you know, it's not really that cool. Come check out this, you know, come look at this thing I, I put together.

And I walked out behind the fireworks stand and I lit off this little cannon salute that I'd built, things about the size of your thumb. And I lit it and threw it down in this ditch and it detonated and just rattled you know, the car windows and put a, you know, huge burst of water, probably 100 feet up in the air kind of a deal. And I remember looking at Chip's face and Chip was like, dude, no, you can't make this stuff. It's really illegal, really dangerous. Can't be doing this.

This is not okay. Like, any— and he kind of took me under his wing, you know. He's like, there's so much He goes, stuff that goes boom is like the simplest, most basic childish stuff. He goes, if you really want to get into some of this hardcore stuff with pyrotechnics, you know, learning how to create, uh, different effects and timing and, and different, you know, being able to judge the, the height of how large or how hard— high a shell goes before it detonates, because that's where this stuff gets really challenging. And, and is, and is kind of pushing me in that artistic route was really what, what got me interested.

And he handed me a copy of something called, uh, it's the PGI Bulletin. It comes out quarterly, and he— and it's this little, almost like a zine, uh, for pyrotechnics people. And he handed it to me and I read it, and in the back it was, you know, if you'd like to become a PGI member, please send a self-addressed stamped envelope and this amount of money to this address, and, you know, we'll start sending you the quarterly and a membership card and a patch and all this other stuff. And I joined and it was great because it created, you know, these are pre-internet days. You didn't have a way to be able to reach out to people and find people on the internet.

But it gave me a way to be able to find other people who were involved and interested in pyrotechnics. As I grew older, I started working on professional teams and have been lucky enough to share the stage with some really amazing talents in the pyrotechnic industry. I've been able to work directly underneath them for, for several shows and shoots and just have a lot of love and respect for it. So I've always said that when I'm done doing the computer and the hacker thing, it's, it's what I'm going to retire to do is just run a fireworks company that does displays and shows. That sounds awesome.

But it sounds like that's a good thing that Pam and Chip got involved with you in trying to change your direction from being destructive to being more beauty, that they, they kind of guided you to something different to put your creative energy in. Yeah, yeah, having a good mentor is everything. It can be life-changing. Perfect, perfect. Well, the other association I know you're, you're associated with, I guess, is the DC-303 group.

Ah, well, actually not really. No? Okay. And here's what I mean by that. DC303 is something run by Mantis, uh, and, and all of the other people who contribute and volunteer for that.

Mantis is a good friend. I love Kyle. He's great. Uh, props to him and everything that, that the folks with DenHack and, uh, the other organizations have really done to, to create DC303. DC Groups are, are a DEF CON group.

And DEF CON groups were originally started by Russ Rogers, a 303er and a good friend and fellow goon, a long time ago. And it made it to where, you know, once a year, a lot of these different zip codes and area codes and other places out there would only ever see each other at DEF CON, right? The rest of the time it was online or over BBSs, depending upon how long ago it was. And the DC groups made it to where people had this kind of focal point where they could come together and share and learn and, you know, be able to educate and train, and it's just great. So DC Groups in Denver has really been a focus around, you know, helping people come into information security and, and being able to pick up new skill and new talent.

Uh, it doesn't matter if you're super experienced or if you're brand new and you've never done it a day in your life, that organization is there to help people grow and mature. And there are a lot of people who are in DC303 that also belong to another organization called the 303. And 303 being the area code of Denver, which is why DC303 was also named DC303. 303 is one of the oldest, longest, strongest hacking organizations, uh, around. Um, there are no websites, there, there is no collective leadership.

It is a, I guess, a fraternity or a sorority would be the right way to kind of look at it. But, but no one is— there is no rank, right? There is no one above another. And it comes from a group of many organizations that over time has kind of come to know each other, trust each other, and become what is now known collectively as 303. Uh, some of this stuff goes way back, right, where you're talking Root Cellar, uh, the original hacking organization that I had before my first company, uh, TAC, TNO, Attrition, uh, those guys that were doing all the AOL hacking, right?

Like, the— these types of groups back in the day were, were small and very protected. Uh, I remember when I first saw the Hack Pack, right? FAQ. The, the very first time that came out, I, I was just blown away at all the information and detail that was in this thing. And it was written by, you know, Voyager and all these other people that were, were down in the 303.

And when I first came down to Colorado, I guess it would have been, uh, 1999, uh, 2000-ish was when I actually first started at hanging out with 303. I got invited to a going-away party of another member from Blue Knight, and Blue Knight brought me to this party, and it was— it's just kind of been history ever since. But when, when those groups and when those teams and everybody all started hanging out together and we were all in the same crowd, uh, 303 became more of the collective name that we kind of went by, right, versus it being broken out into these smaller organizations that were there. And what was once— we always joke, uh, you know, it's, it's not that we're a bunch of hackers, uh, it's that we're a bunch of drunks who have a problem, right? We— back in the day, the joke was that we all had, uh, we all liked to drink together, and we just all also happened to like computer security or be involved in different assets or different aspects, sorry, of the industry.

Um, but as time grew on, you know, what was kids once breaking into to Bell vehicles and into telephone company truckyards and stuff like that became people that are now CSOs and leaders of national laboratories and other types of amazing things. So it's neat to watch how things grow and mature over time. Well, I know that that's where I know you from originally was the 303 Group. Definitely, I think, I believe that was a motto at one point was, we're a drinking group that likes computer security. Before we move on to the next question, though, I do want to also enforce what you said with giving Mantis some mad props for running that DC 303 group.

I do help him out. I try to help him out a little bit with his DenHack and everything else. Great guy. I do have a next question, though, for you. What was it like— here's something that I don't think a lot of people have done— is creating their own security company at the age of, what, 16?

Yes. Yeah. So, so what prompted that? I mean, most 16-year-olds are getting in trouble or learning how to drive or shoplifting, right? You're out there creating a company.

So tell us about that. Um, big fish, small pond syndrome, I guess, is how it kind of came about. Um, you know, being in the middle of nowhere, Wyoming, there were very, very few people Again, this is, you know, really at the birth of the internet, and there are very few people who were into technology or computers like that where I was from. Uh, there are a couple, uh, some of my life influencers, but it just, just not many. And when I, I was 12 years old, uh, I had stumbled and gotten into some trouble with computers with my local school district.

Then again at 14 with an organization that I was doing some hacking with. I ended up doing some, you know, community service type work. It was a summer work program to help people learn how to, how to interview and how to write a resume and how to do all this stuff. But we would do an hour of that and then 8 hours of hard manual labor, right? Painting playground equipment with waste oil or, you know, whatever the stain is to keep it in place, felt like waste oil.

Painting snowmobile markers for Yellowstone National Park, digging ditches for Hudson, Wyoming, right, so that their irrigation would work. An amazing program run by a guy named Dennis Ullman, who ended up being the principal of my grade school. But those, those types of situations really led to me wanting to find others who were similar in mind and similar in aptitude and interest. So I, I created something called, uh, RCST, and it was Root Cellar Security Team, uh, but it, it wasn't known as that for many, many, many years, right? When we, when we first created it, 1994, it was HACC, Hackers Against Corporate Culture.

And a lot of people, it will— it'll raise their ears, but we had this symbol where it was an H in a circle, right? Instead of an anarchy symbol, it was like a hacker symbol. And when— with the way that we drew it out, it made it to where you were able, if you knew how to look at it, to see the letters H-A-C-C inside of the image. And I spun up a BBS, Searchlight BBS at the time, and did all these crazy, crazy amounts of hours programming it and creating RIP graphics so that it would actually have like animation in this BBS. It was so cool.

And all these kids down in Colorado, a couple in Utah, all of, all of my friends in Wyoming, they started dialing into this BBS and uploading different documents and information and talking on, you know, the message board that we had there and playing text-based video games, right? We had all these MUD-type video games that were part of the BBS, and it grew quickly, scary quickly, like to the, to the point of where, you know, my mom and dad's phone line was tied up all the time and, you know, it was just causing hell. And, and causing trouble. But I, I got to where I had all these different phone numbers of all these different people who were dialing into my BBS, and I started calling and talking to people. Sounds so creepy now when I say it.

I started calling people and being like, hey, I'm the guy that runs the BBS that you just dialed into, you know, last night. Really appreciate you uploading all this different stuff, you know, looking for other people like me. And, and it was just, you know, just scrambling to try to find people who could, who could just kind of hang. And I graduated high school in 1996. Um, the hack had been around for like 2 years, uh, had a bunch of members who I'm still close friends with today, by the way.

Uh, and in 1996, when I graduated, I went to Central Wyoming College, and our Our organization at that point started really collecting, uh, mass and speed. We had gotten the university to allow us to meet in the student center, um, once a week. And we had like a formal meeting where everybody'd come in and 2 hours long, right? We'd sit down and just shoot the shit and really talk about all the different types of things that we were learning and the different things that were going on. And, you know, here's how we were able to hack into this one thing.

You know, when the internet first started, it was really easy to compromise a lot of things because security wasn't even an afterthought at that point. It wasn't even a thought in a lot of cases. I always tell people one of the biggest hacks I ever did in my life was, you know, when I was 14, that the, the what was, you know, EarthLink at the time really became the AOL thing was because I learned that you could dial into a Livingston Portmaster, a bank of modems, and that it assigned an IP address to you And that IP address that it assigned as the gateway was the Livingston PortMaster. Well, this device would allow you to connect without really a username or password. It'd just give you a shell.

So we started being able to kick people off of the network, right, and mess with each other, mess with our friends, right? If you're trying to download something over a phone line, it takes 2 days to download something that'd be the equivalent of, you know, it's so tiny compared to now. But they'd be halfway through their download and you could disconnect their session and make them have to restart their download from the beginning. It was, you know, some of the very first internet trolling. And as it kind of grew mass, we got some attention.

I started working with a lot of different companies in Wyoming, helping with Bureau of Indian Affairs, several of the school districts out on the reservation. And we were, you know, kind of doing the day-to-day computer repair for them and technology coordination. And I got invited to speak at, uh, the Rocky Mountain Security Conference, uh, that was being held at Central Wyoming College in Riverton, Wyoming back then, way long time ago. I think this would have been 1998-ish. And this was, uh, yeah, 1998.

It was the first year I went to DEF CON as well, DEF CON 6. And I went and I spoke at this, at this conference, and we, we gave a presentation about the type of work that we were doing and the research that we were doing. And, you know, showed video of us breaking into these secure facilities and doing all this different work. And, uh, started getting hassled, uh, by this guy in the audience that was with the FBI. And he was talking about how, you know, I'm a punk criminal and how, you know, he knew my background.

He's familiar with who we are, and he's been watching us and just really harassing us. And John Perry Barlow, founder of the EFF, stood up in my defense and, uh, kind of shut this guy down. And it was first— I didn't know John before that. It was the first time I'd ever met him. Um, you know, I don't think EFF was even really rolling yet at that point, maybe.

Maybe it was just starting at that point. I can't remember. I have to go do my history. But, uh, John Perry Barlow stood up and he defended me and my, my team at, at this event. And at the same time, we were kind of being investigated, going back to the purpose of why the FBI guy was there, for some of the hacking that we were doing, uh, extracurricular type activity during some of our meetings at the student center.

And it turned out that we found out that one of our members had hacked a system out at Berkeley, and it had drawn a lot of really negative attention, and they didn't know who had done the hack, and they were trying to pin me for it. And, uh, when I sat down and we spoke to the investigators and everything else, I— we really took the stance of, we're not hackers, we didn't do this, we don't know what you're talking about. You know, we're starting a company, blah blah blah blah blah. And I was kind of freaking out about it all, didn't know what to do. Figured I, I thought I was going to get arrested and get thrown in jail, um, for having this group.

You know, I wasn't even the one that had done that hack that time. And, uh, it, it was great because what ended up happening is it kind of ended up being the fire that I needed to get going. And one of the members', uh, father was an attorney. And we went to him and we said, you know, listen, you know, we're, we're being investigated. We think the feds are coming after us.

Uh, really haven't done anything wrong, but, you know, they're just harassing us now and they're watching us and this stuff is just going sideways. What do we do? And, uh, my friend's father recommended that we incorporate and we create a business. And that is how Root Cellar Security Team was born. I ended up hiring a couple different people.

Uh, we had the first— my— it doesn't sound like anything special now, but it was amazing at the time. My first employees at Root Cellar were the kids who, uh, were the first to ever get their MCSE+Is before graduating high school. Wow. With Microsoft. And they worked for me, uh, for 3, 4 years.

And we, we had a pretty amazing thing going, a good company running. And then part of the fallout from my first divorce, we ended up dissolving the company and kind of went our own ways. And when, when that all went down and we shut down Root Cellar, I moved down to Denver and started work with the first EchoStar Communications, helping old ladies replace their batteries in their remotes, uh, and then ended up working for the United States Fish and Wildlife through the Department of Interior as part of the Norton Cobell litigation, uh, and the large cybercrime push that occurred, uh, due to congressional pressure at the time following that attack. In fact, funny enough, that's where I ended up meeting quite a few people who later became or were my goon brothers with DEF CON. Wow.

Well, I think it's really cool that, uh, a guy that you didn't even know from ENF defended you. I mean, got up there and defended you for something. Uh, that, that— I think that's really, really awesome. Uh, I definitely know myself about the computer security. I remember my first hack was posting up a website that if people visited it, they would show you the contents of your C drive.

Security wasn't even there. Like you said, it wasn't even a thing. My first hack that I, I'll call a true hack, uh, was on a Novell NetWare network. And this was the hack that I did to my local school district. And I, I'd gotten curious because I was watching the teacher who taught like typing and taught like computers at the, at the school.

I'd watched them enter a special command. And this, this keystroke command that they did gave them access to all these teacher functions and administrative functions. And I could not figure out for the life of me, because they would always do it super quick, right? Like they'd always hit the buttons really quick. And I couldn't figure out for the life of me what it was.

So I sat there one day just button mashing until I figured it out. And it was one of those things that when you went through there and you push that series of buttons, one of the commands that popped up was that it gave you the ability to press Ctrl+A, which would run a batch file off of a floppy disk. So I started playing with it. And I realized that it was just a batch process running in the backend. So I would hit Ctrl+A, and it would flash.

And because there's no drive in the computer, you know, literally, they physically removed the drives, it would, it would just return back to the menu. And I figured out that if you hit Ctrl+C and broke free from the batch file, right, interrupted it in the middle of its operation, it would drop you to, uh, the command prompt. And from the command prompt, I was able to switch my drives over to this drive that was the X drive. It was an administrative function drive. And one of the commands that was inside this— and again, I'm— this is months of me playing building up to this, uh, but one of the commands that I found was something called send.

And send would allow you to send a message to anyone else that was connected to the network. You just type send and then the username that you were trying to send it to and then the message, and you'd hit enter and it'd pop up on their screen, literally like a full-blown pop-up window. And my friend and I, you know, after I showed my friends this stuff, we, we kept sending each other nasty messages and stupid shit back and forth to each other, as you do when you're kids. But one day I was sitting there messing with a batch file and I was like, I wonder what it would be like if I used this command along with this drive access and I modified the startup file for all these network machines so that whenever they start up, it sends a command. That'd be pretty awesome, right?

That'd be pretty neat. Just make it to where every time the computer pops up, it sends a message to somebody else. And I could use it to figure out like who's online and all this other kind of stuff. Well, I sent— I, I set up the script as I was kind of testing it out, and I told it to send, and under the user I said everyone, and under the message I said I am God. And then I saved it and walked away.

Well, the problem is, is that these old Novell Network NetWare networks are token ring networks, meaning that For those of you who are born in the information age, token ring networks back in the day, when you sent a packet, it would literally send along a daisy chain of computers. And it would go from computer to computer to computer to computer until it hits destination. Really, really effective for what it needed to do, quite inefficient. But with the change that I had made, when computers booted up the next day, Every computer in the district started sending every computer in the district, I am God. So I effectively created a distributed denial of service against my, my local school district, and every machine that they booted would say this.

So they had to go in and figure out what I had done, shut down all the machines, get them to all pick up the new batch files for booting up. Then they were all able to boot and come up again. But it created a situation that brought down my school's network for a couple days, and it was just a huge nightmare, and it really got me a lot of negative attention that I didn't need at the time. Um, it was kind of, it was kind of my first true real hack. Gotcha.

Well, you know, we've talked a lot about the past here, and, uh, just to kind of talk for the last part of this interview here, What is— what about today? I mean, we, we talked a lot about this stuff. What are some of the greatest security challenges that are out there today, and maybe some ways to address it, to think about it? What do you think is the biggest challenge right now? Oh, it depends upon how you're looking at it.

Okay, challenge can mean a lot of different things. When, when I think about it from our standpoint, right, those of us who work in offensive security, I think one of the biggest challenges we face today is getting people to get it. And, and what I mean by get it is just understand why they're doing the things they're doing, why we give them the recommendations that we do, why they need to take this stuff seriously and make it a priority in order to protect themselves, their organization, their employees, whatever's out there. And I think that our industry has done a bit of a disservice. Um, you know, we, we have all these best quote-unquote best practices that we follow, but most of them are based off of, you know, ideas and concepts from 20, 30 years ago, and they're not necessarily as applicable, if at all, uh, compared to how they once were.

So I think that we need to think about how we approach security uniquely and differently Um, in, in a way that addresses the challenges and the complexity of today's modern environments and the challenges that we face when protecting against nation-states and malware threat teams and all kinds of other things where we just, you know, the concept of a hacker being somebody sitting there with a hoodie on drinking Jolt Cola, eating pizza in their mom's basement, yeah, it still exists. Not really the big threat you need to worry about anymore, right? Now it's, it's coordinated team armies of people, um, that are, are looking to gain footholds into environments and IP spaces in any way that they can. And they don't necessarily come in to just deface your website or to post a funny message on, on your board. Nowadays, you know, people all the time, they'll ask me, they're like, well, why would, why would somebody even take the time to hack me?

And it's like, your bandwidth. You know, as having a high-speed internet connection is one more ammo, one more piece of bullet for some of these, you know, for some of these people that are doing this, that it— that really enables them to be able to do things like these distributed attacks or to proxy traffic to where other people can't track or trace what they're doing. So I, I, you know, I think the biggest thing that people need to do And one of the biggest challenges we face is getting individual users to understand the responsibilities that they play and— or the role that they play and the responsibilities that they have in properly securing the environments that they live in, that they exist in, that they work, you know, day to day in. And it's— and just realizing that it's not up to the IT folks or to your information security people. You know, that's, that's their day-to-day job, but it really starts with, with the individual user.

Well, I think that's part of where some of the things we try to do with the Denver OWASP group is to address those users to make sure that they feel empowered, that they can do something about this, so that it's— that what we do is not magic. Uh, how do you feel about that? Um, it's— well, you, you know, uh, how I feel about that. You work with me. So it's very, very clear how I feel about that.

For those who don't work with me or haven't worked with me, I'm huge about value and making sure that we are clearly and concisely delivering the message in a way that makes it digestible and understandable. Doesn't matter if you're an executive who is a Luddite and completely afraid of technology, and never ever lays a hand on anything other than your phone to do your day-to-day business, or if you are, you know, some old graybeard Unix wizard sitting in the back of a data center somewhere with hundreds of thousands of images at your disposal, I, I think the focus really needs to be around taking approaches and programs that are applicable to the individual environment And, and really making it to where it delivers the information and the detail that you need in order to address the problems that are truly introducing risk, right? Just because NESA says something's high or critical doesn't mean that it's as important in your specific environment as something that may be flagged as like a medium-ranked vulnerability. Uh, you know, we talk about this day in, day out, but I, I really think that as we mature as an organization or as we mature as an industry, one of the biggest things we need to focus on is understanding our clients, having better communication, learning to listen, you know, not just trying to sell somebody a pen test because once a year their compliance says that they need to do a pen test, but selling them a security program that makes a difference and creates change in their culture, in their posture, in their security program as a whole. That's the stuff where I feel that you can really deliver and add value in the work that we do.

You know, that is awesome, Luke. And I think we're just about running out of time here. Again, in case anybody that doesn't know, Luke is the Vice President of Offensive Security at Blue Bastion. He can be found on LinkedIn. I think that's one of the great ways to get in touch with him.

And that's gonna be Luke, and his last name's M-C-O-M-I-E. My name is Frank. I'm with the Denver OWASP Group, and if you are in the Denver area, you want to come to a meetup, we can be found at meetup.com/denver-owasp.

And I do want to mention one thing. I want to give a thank you to both Robb and Alex, and we do have the RMISC. You had mentioned the RMISC conference earlier. We are going to actually try to have an in-person RMISC, Rocky Mountain International— sorry, Information Security Conference, in September of this year. I will be there with the student program.

So thank you for your time, Luke. Any last and final words? No, I, I really appreciate the time and the opportunity to speak to your audience today, Frank. I, I guess the last thing I'd say is, you know, really, I can't stress enough when people are first getting into the industry, ask questions. Uh, don't be afraid to admit that you don't know something.

You'll, you'll find that this industry, as, as scary as it can look from the outside, right? The movies sure try to make it look scary anyway. You'll find that people are here to work together, to learn from each other, and to make things better. So don't, don't hide in a corner, you know, go out, hit the conferences if you can do so safely, build relationships, find that mentor, and really, you know, take the time to learn and do it right. Well, that's awesome, because I know one of the things we talked about during this last hour was mentoring, and not only find a mentor, but be a mentor if you can.

If you are looking for a mentor or to be a member— or sorry, or be a mentor— there is the Slack channel, the Colorado Equal Security Slack channel that's out there. And we also have one on the Denver OWASP group. We have mentoring opportunities or a mentoring channel. If, you know, if you have any spare cycles, put yourself out there, be a mentor for somebody, because I can guarantee you one thing: being a mentor, you'll also learn a lot of things. About yourself, about other people.

So thank you again, Luke, and again, I appreciate your time, sir. Yep, talk to you soon. All right, thank you. All right, bye now.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado equals security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes