Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 244. This is the week, the month of February 2023.
We don't do weeks anymore, Robb. Well, it was a week. There's a week in the month. There's a day in the week in the month. Yeah.
February 6th. That's the day, even though we don't actually release it on February 6th. That's the Monday. I don't know. That's kind of a weird thing.
You can guess what day it actually is when we're recording this. Yeah. I'll say there's snow on the ground. There is snow on the ground. There's— it's sunny.
It is sunny. Yeah. Yeah. Yeah. We've narrowed it down to all of January or February so far.
All right, Alex, let's jump into some quick housekeeping. We have a Slack channel. It keeps growing. Lots of thriving conversation. How should people sign up if they want to be in Slack?
You know, Robb, we have a website, colorado-security.com. You can go there. There's a form you can fill out and submit that. We will get your request. And if you meet our stringent criteria, we will add you to the Slack workspace.
That stringent criteria is called being in Colorado and having an interest in information security. While you're on the website signing up for Slack, you can sign up for our mailing list and get the show notes delivered into your inbox every week. We would also love it if you would rate us and subscribe on your favorite podcatcher. And tell a friend. Let everyone who you know know that Colorado Equal Security is awesome.
You know, I was listening to a different podcast recently, Robb, and they actually changed their verbiage around saying that. They said subscribe or follow because I think on many of the things now you're not actually subscribing anymore, you're just following the podcast. So if, if you're on Spotify or one of the ones where you can follow, please follow us. That sounds really good. Also, we'd love it if you tell all of your friends about Colorado Equal Security, send them to the website.
Have them follow the podcast, uh, you know, all of that kind of stuff. We, we want more and more people involved in the Colorado Equal Security Movement. And if you want to financially support the show, uh, we do have a Patreon campaign. We appreciate those folks who, who keep us running, uh, paying for those hosting costs, the emails, the all of the things, the— yeah, the stuff that the, the, the distribution of our podcasts, um, costs money as well. So thanks for those folks who support.
If you want to go, Patreon is also on colorado-security.com. Yeah. So let's jump into the news, Robb. We've got a follow-up story on several stories that we've talked about over the last couple of years. Big, big news.
You know, we heard before that Casa Bonita is opening in May. They have now actually started hiring people so that you can have waitstaff and everyone else for, for that great day in May when they open. So apparently the first person they hired was Governor Polis to go do an advertisement for them for the fact that they're hiring 500 more people. Yeah. So the story we have is actually— well, I think there's a story, but also there's a YouTube video with Dana Rodriguez, who's the, the executive chef there, and Governor Polis talking about Casa Bonita.
They're hiring waitstaff, they're hiring cliff divers, you know, all of the security guards. Yeah, they're probably hiring the the person who has to be in the gorilla suit. I would imagine the gorilla is still going to be there. I have no idea. If so, do not get that job.
That sounds terrible. Cliff diving though sounds pretty awesome. I don't know. That's one of hey, I used to be the gorilla at Casa Bonita. That's a you know a good party line for like a weekend until until you realize that it's it's hard.
Yep. Anyway, so if you're if you or someone you know is looking for a job, that might be a great place to go. And of course. I'm excited we're going to have Casa Bonita open again soon. You know, there have been a lot of layoffs.
I think this could be a place where people go, look, go into Casa Bonita. It's a great place to work. I love it. All right. Another big cornerstone restaurant in the Denver metro area is The Fort up in— up below Morrison, right?
Yeah, it's officially— they are celebrating 60 years as a restaurant. They call it 60 Years of Old West Wonder. And my first question for you is, how do you pronounce this exclamation that apparently the server staff says? I would say, wah! Wah!
Is that what it is? Apparently that's what they say. And it's an old Western thing to mean like, all right, or yeah, I agree, or something like that. I have eaten at the Fort and I don't remember anyone wahing before. Me either.
But hey, you know, maybe no one was happy when I was there. So, you know, we I don't always read every word of every article. I did read every word of this article. I did too. It was kind of long.
It was kind of long. There's a lot of stuff in there, but it was interesting. Yeah. I mean, I didn't know that the— this was originally created as a home for the family that owned the restaurant, that it wasn't a restaurant initially. It turned into a restaurant later.
The daughter of the couple who created it grew up there along with a black bear named Sissy. Yeah. And apparently Sissy was was well known for hanging out in the bar and coming up to the bar to get some Coca-Cola out of a bottle. Probably not the healthiest choice for a bear or a human, but still interesting. Lots of interesting stuff here.
Apparently they had a diabetic black bear. But, but yeah, lots of cool stuff there. Talks about the history and, you know, how they navigated through COVID, opening a food truck and sort of, you know, pivoting and changing things like a lot of restaurants had to do. During that time. And so, you know, through the 60 years, the fort has been a lot the same.
Recently, it's a little bit different, but still the same. So a couple of— I just love the random facts and love sharing those with the folks. You know, I know that they sell bison steaks. I did not know that they are— this restaurant sells more bison steaks than any other restaurant in the United States. That's pretty cool.
I also did not know or did not remember that they sell gunpowder-spiked whiskey. If you want to go drink and also you want gunpowder, that's your— that's the only place I'm aware of to do that. It's the only place I am aware of as well. They talked about even one step beyond that where if you have the bone marrow, you can take the whiskey and put it in the— you can use the bone marrow, the empty bone, and yeah, sort of use it like a shot glass, I guess, sort of. And is it a shot glass or a straw?
Well, it's like a half. It's not all the way through. Yeah. So that's— so there's one of these questions recently going around on the internet is, does it— how many holes does a straw have, Alex? How many holes does a straw have?
Well, that's a good question. I mean, I guess you could say one because, you know, all the way through is one hole if you want to call both sides. But is it a tunnel? Does a tunnel have one hole or two holes? Yeah, it's— that's a great philosophical debate.
Speaking of great philosophical debates, if you haven't been up to the fort yet, you really got to do it. Are you really a Denverite if you haven't been to the fort yet? No, it's a lot of fun. Everyone should go there at least once. All right, next we have an article talking about apprenticeships, which are making a comeback apparently.
And these are not your grandpa's apprenticeships. So there's apprenticeships in lots of different things and lots of different companies around town are doing these programs. Some of this is based on a bill signed into law in 2021. Setting up the state apprenticeship agency, which will launch in July. Yeah, once again, a bunch of interesting stuff in here.
There are apparently about 5,800 active apprentices in Colorado right now. There, that includes 473 employers that have apprenticeship programs. So quite a few companies are doing this. It didn't, you know, as I started reading it, it didn't immediately remember, but most apprenticeship programs come from trades, right? If you're, you're, you are an apprentice to a plumber or an electrician or, or those things.
But they said a significant percentage has actually started to be in like white-collar office jobs as creating a path instead of having to go to college to learn these trades, like actually doing it, you know, in the job, on-the-job training. Yeah. One of the things that I thought that was interesting about this article is I, I never really understood the, the full definition of what an apprenticeship is. I mean, it's sort of obvious on the face of it, but, you know, they say all apprenticeships must be a mix of on-the-job training and classroom instruction, provide payment, and offer successful apprentices recognized credentials in their field, as well as supplying mentorship. Right.
So I usually think of apprenticeships like a slightly more formal internship. Right. Right. But this is— I mean, there's more structure around it. There's more to it.
The fact that you have to have classroom education and you have to have a mentor, you know, you have to have Uh, credential at the end. Credential. Yeah. All those kind of things. Uh, they, they give a great example of one, uh, a woman, is it Narai, uh, Navarro, um, who started as an apprentice at Pinnacle Assurance.
Uh, hello, Jesse. Uh, as a 16-year-old high school student, and she did that program for 3 years. As she finished up high school, they offered her a full-time job, which she accepted. And she, she came in there as a, ooh, I don't have the name right in front of me, a workers' compensation insurance Oh no, a claims agent. She came in as a claims agent.
So really awesome opportunity. They talk a little bit about her path and how much this gave her flexibility to go, you know, high school, 16-year-old high school student started saving at that age and was able to, to go get a home right after graduation. Pretty cool stuff. It is pretty cool. And of course, you know, one of the things they also talk about is with, you know, the rising costs of, of college education, you know, this is a path for, for people that may not be able to afford to go to college.
And still, uh, get a path to a great job. Yeah, I love it. And of course, I, you know, we have a lot of folks listening who, who help, you know, as leaders at their companies. I'd love you guys to, to see if your company might be able to figure out a way to, to invest in this and help, help reduce the cybersecurity, uh, talent or, uh, number of employee shortage we have. Yeah, I mean, thinking about the, that definition of what an apprenticeship is, I think security lent itself Uh, perfectly to that because, you know, at the end, if you, if you get somebody towards a, um, Security+ or a CISSP or something else like that, right?
Like that is, that's the end goal of an apprenticeship, right? Like there's, there's training, but there's also a credential and we've got those sort of built in. Yeah. And of course that gives you a really great way to bring talent into your organization and, and help create other, you know, help relieve the pressure we have right now finding all that great talent. Yep.
All right, our next one is talking about a new bill. This is a Senate bill here in Colorado, SB 2360, which is here to promote transparency and consumer-friendly practices for ticket purchasing. Now, you know, we know there's been a lot of controversy recently about, you know, how Ticketmaster especially handles ticket sales. This is an interesting bill that's, It's not necessarily around trying to break up monopolies, but trying to get around to do away with hiding of fees and, and, and stop having bots able to go buy a bunch of these tickets. Yeah.
And, and I think most of the, the bill is really changing definitions of, of what things mean. So it makes it easier to, to go after companies, people that are doing these things. For example, it expands the definition of deceptive trade practices to include use of automation to buy tickets or circumvent limits, selling tickets upfront without talking about the fees, as well as selling tickets before you actually have them. Yeah, one of the, one of the big reasons that bots go buy up all these tickets is that they create a market to sell them before they have purchased them, right? And they know that they're going to be able to, you know, because they're Bots are more effective at buying tickets than you and me just clicking into a web browser.
They're able to go sell a bunch of tickets above that ticket price, assuming that they'll buy them. And if they end up not being able to get as many, that's fine. They just cancel the sale. And like, you know, we as the consumer get hosed. So these are laws that will make that illegal.
Okay, so it's illegal. Now what? Well, now there's enforcement that has to happen, right? And no one at this point knows how enforcement will work, But until you have a law in place to make it illegal, you can't really do anything about enforcing. Yeah, another thing they talk about in the article that is not as favorable is, you know, some of the things that they talk about in the bill is essentially giving the ticket companies more power to do certain things.
And there is some concern from consumer groups that because the large ticket companies would have more power, it could, the law could backfire a little bit. Yeah, I was struggling to figure that out. I know that there were, opponents of the bill who are saying that this would give more power to the ticket companies, but I didn't see it. I don't understand how it would give them more power. As I read through this, it sounded like they, they would have a— and I don't know why they wouldn't have this power before, but the ability to, you know, essentially cancel ticket requests, you know, on a whim.
Well, basically, they could say it's because we think it's a bot, right? We think it's deceptive practices behind it. But it may be that they wouldn't have to really tell you the reasons behind that, right? Like, it could be, it could be capricious, right? Like, okay, we don't like you, Robb.
So we're just gonna cancel all your ticket requests, or something like that. Anyway, it seemed like it was probably something that should be thought about, but maybe not something that's a big enough deal to stop the bill from going forward. Yeah, that sounds about right. Anyway, good stuff. Moving on.
We have a story here about a quantum computing company, Robb, that has come to Colorado, working with DARPA to try and move quantum computing forward in a much faster way. Yeah, so we've talked about Atom Computing in the past, I think. At least I know I've read about them. And DARPA put out a call for companies who said, do you have any way that you have any leads on technical ways that we could try and fast forward the adoption of quantum computing here much faster than the currently expected about 10 years or so. So the— there's 3 companies that came back to DARPA's proposal: Atom and 2 other companies, Microsoft and PSI Quantum.
And they were— well, actually, there were probably more than that that came back, but those 3 were selected to try and push utility-scale quantum computing forward. In a, in a more rapid manner, I think. And the reason here is, you know, quantum computing is coming and the government wants to be ahead of it, right? Like, they don't want it to be something that we don't have a handle on if some other country gets there first. We want to be there first because it's going to be powerful when you can decrypt all of the, you know, the, the typical encryption that's based on, you know, mathematically difficult to produce numbers.
Right. Right. Anyway, this is interesting. I will say, and I read the part that described the different way that the 3 companies were planning to try and do this. And I didn't understand any of it.
Yeah, I didn't really understand either, honestly. Like, so you're going to like put all the quantum in a circle? I don't understand at all. I, I understood that one of them, maybe it was Adam, is trying to, to make something the size of a closet. Yes.
That's the only part I remember too. And then that made me go back to like, you know, back when IBM made the first main computers when they were like, you know, the size of a of a room, right? Right. And, you know, and of course, they got much smaller over time. And I'm sure this will happen here as well.
Interesting stuff. Really cool to see. Adam is planning to continue investing here in Colorado, growing out jobs. They plan to invest about $100 million in Colorado over the next 3 years as they scale out their technology and their staff. They have a 17,000-square-foot building up in Boulder, and they have plans to continue growing.
That's awesome. Love it. All right, moving on to our next story. We, you know, we, we have 2 stories this month about the governor. And this one also about him.
You know, he is either a geeky nerd or a nerdy geek, or maybe both. Yeah, this is not even like a story. This is just— so I didn't watch it. But I did hear a little bit of coverage of, of his State of the State address in January. And, and apparently he, he had some— he dropped some pop culture, you know, nerd culture references in that.
Well, this article is just talking— is just a rundown of the nerd culture references that Governor Polis had in that State of the State. Yeah. So, you know, a little bit of Lord of the Rings, some Star Wars, South Park, some other stuff in there. I mean, you know, Grant, you know, with the whole Casa Bonita thing, he's got to throw some South Park in there. And, and he apparently he referenced the Bible, which this guy says is like a Bible nerd thing.
Okay. Yeah, I guess anything could be nerdy, right? If you, if you know it well enough. Shout out to, to the great James Baldwin, literary nerd shout out there. You know, I don't know that I would have put, you know, a Jewish guy being a Bible nerd on my, my checklist for Governor Polis.
But hey, you know, Everybody's got their own thing. He's a politician, though. He's got to appeal to people. He's a Renaissance man. He's a Renaissance man.
He's got a wide understanding of education and both cool and uncool things, apparently. Yep. All right. All right. Next one here, we have an announcement that's— usually we don't get the names for these companies, but, you know, we've talked a lot in the past about the EDC offering tax incentives for companies to come to Colorado, invest here, you know, move their HQ to here, whatever it is.
Well, here the EDC approved millions of dollars in tax incentives for a cybersecurity company to, to have up to 500 new employees hired here over the next 8 years. And then we did get the name, right? Yeah. And this one was— it was interesting because I feel like there was an article that came out that didn't give the name and it was, hey, there's this potential project. And I don't know, like a couple of weeks later, like another one followed up.
Oh, yeah. Yeah, we got it. It's these guys. Yeah. Somebody leaked it.
Yeah, you and I couldn't get the leak, but somebody else got the leak. Anyway, the company is RADICL Defense. And if you're looking for R-A-D-I-C-L, we're missing an A. And they're, they're based out of Boulder. Chris Peterson, who is one of the— was he actually a founder?
He was a founder of LogRhythm. This is his new company to help security of small and medium-sized businesses. They've— I don't know, they started maybe right before the pandemic, beginning of the pandemic. I know we talked about them early on when it first came out. And like we watched, remember there was a video like describing it.
There was a video. And at the time it was very vague about what they were going to do. Their mission was clear, right? They want to help defend small and medium-sized companies against cyber threat. But the actual way they're going to do it was unclear.
I'd say whatever it is, 2 years later, still very unclear. We still don't know exactly what they're going to do. Granted, we haven't talked to them. So, you know, we could probably talk to them and maybe get some more details, but it's definitely not in this article. What is in this article is talking about the number of jobs that they're trying to create, which is around 500.
Over the next 8 years. Yeah. And they can get about $2.5 million of tax incentives if that happens. Yeah, it's neat to see. And, you know, if they're currently an 8-person shop, so, you know, very small.
And if you think going from 8 to 500 sounds unreasonable, well, that's exactly what they did at LogRhythm. I think that's the kind of the prototype that they're looking to follow, you know, that type of growth. And, you You know, if you have an experienced leadership team, it's not outside the realm of possibility that they can go execute again. And the reason that they got the tax credits is there was some discussion of them either expanding or moving this hiring to someplace else, specifically Florida. So tax credits were given to keep them here and keep those jobs here.
Well, I'm glad that we're keeping them here. I am disappointed that they, that they considered Florida, considering they've, they've had the sweet, sweet life of Colorado. Yeah. I could think of better. All right, uh, next story we have here is a, is a blog from the Red Canary blog.
You know, I think if you've been listening to the show for a while, you know that like the Red Canary blog is just fantastic in terms of, you know, really full of technical detail on how to find bad things, how Red Canary specifically has identified bad things in the past, how you can uplevel your own security operations using these things. And then no different this week, this month, when they've got one about how to detect credential access across your organization. Yeah, and, uh, I'm not going to go into too much detail on the blog, but there's a whole lot of detail in here. So if you, uh, you know, want to learn about, uh, detecting misuse of credentials and, uh, credential access, then definitely check this out. A lot of good detail in here, um, talking about various things when in Windows mostly, but in, uh, in other operating systems as well.
Yeah, it's really— it is really in-the-weeds technical detail that frankly you could think of as training for your team Um, they may not understand, uh, exactly how to see credential misuse across these environments, and this is gonna give 'em a bunch of specific examples. And you could use it to look through your current ecosystem. You could use it to create rules to detect on things that when they happen in the future, really, really useful. And, um, hopefully it'll give you guys a chance to, to up your game. Yeah, good stuff.
All right. Uh, we have a, uh, I guess it's a press release or report from, uh, from Laris talking about, uh, top 5 penetration testing highlights from 2022. Uh, so they, in all of the penetration testing work that they did, they, they had some pretty common themes, uh, that they saw. And, you know, I'm gonna go out on a limb and say these are not gonna shock people, but, uh, the first one is brute forcing accounts with weak or guessable passwords. Yeah.
Uh, second one, uh, and of, and of course, by the way, brute forcing accounts, like something that folks do. You've gotta have MFA in place though, right? So this is, this is for organizations who didn't have MFA. Yeah. Number one, or number 2 rather, was Kerberoasting, which was misusing Kerberos tickets to get unauthorized access.
Next, excessive file system permissions. I can't imagine ever seeing any excessive file permissions anywhere. Still after all these years, misusing the WannaCry/EternalBlue vulnerabilities. And then the last one was using WMI or Windows Management Instrumentation for lateral movement. So built-in tools in Windows.
To get around and stay persistent. Awesome. And I do love this. I think every year they give this like top things that they learned from pen testing the previous year. Look forward to seeing it.
I, I remember looking at it last year and I'm looking forward to seeing it again next year. All right. Our last story this week is, uh, it's a nice one. It's, it's about a local security company or identity security company called Strata who just raised $26 million to become the market leader in identity orchestration. Uh, that seems like a good thing to be, uh, trying to do.
Uh, so they are, are trying to tackle some areas that they think that other identity providers haven't done in the past well, which is, uh, being able to combine, um, sort of legacy auth and cloud auth and other things like that under one platform to make auth easier and more simple. So hopefully that happens. So this is their B round. Um, so I'd say this is kind of a smaller B round than we have seen over the last year or two. It feels like Bs have been getting much, much bigger recently.
This is probably healthier, to be honest with you. Those $100 million Bs are just encourage folks to go spend a ton of money on sales and marketing and blow a lot of cash. And, you know, the world has changed a little bit here. Yeah, obviously more reflective of the current economic environment. Yeah.
So I do think the way you just described it was exactly how I would have summarized it. You know, this central platform where you can put all your identity providers into Um, but that is like the, the value prop of a Ping and a Ford Rock 2s. And so it feels like, you know, directly head-to-head with what those guys are doing in a pretty well-established market. Um, love seeing local companies be successful. I'm curious what that's gonna look like.
Yeah. You know, I think it could be, uh, coming into that market, um, you know, sort of fresh as opposed to some of the, the providers that have been around a little while and kind of put those things together as, as stuff is, uh, come together. Anyway, uh, good luck to them. All right, uh, that is the news. Uh, moving on, we have events.
So, uh, got a lot of events coming up this month. Uh, we have a calendar of events. We even have a calendar of events. You want to go see all the events we're going to talk about and a lot more, you can go out to colorado-security.com and click on the events link. The first on that list, on February 8th, ISSA Denver is doing their February meetings, lunch and evening.
In transitioning to ISO 27001:2022. The ACES Denver group, the physical security group in town, is doing a biometric access trends meeting on the 15th. On the 16th, ISACA Denver is doing their February meeting in person with IIA. The CSA Colorado February meeting is happening on the 21st. ISC Pikes Peak is doing their February meeting on the 22nd.
On the 23rd, ACES Denver is getting back and having a coffee chat with Misty Shepherd. I don't know Misty, but maybe you can go get coffee with her. I like coffee. On the 24th, the Let's Talk Software Security group is doing a meeting on vulnerability tracking and reporting. And then on March 2nd, one of the biggest events of the year is happening.
This, we were just talking about it. We can't believe how quickly it's come upon us. The SnowFROC Conference, OWASP's big annual event, big AppSec conference. So people will come in from around the region. They're gonna be here in, I assume, back at the Cable Center.
I believe so. Like always. And, um, it's a great conference, great speakers, great content. And the last event we have, um, also beginning of March on the 3rd, Colorado Springs, uh, is doing their Cybersecurity First Friday. Good stuff.
All right, let's jump over into jobs. Um, starting off the list this week, we have a security, uh, is it an analyst or engineer here? It's a IT security administrator. Oh yeah, IT security administrator from Noodles Company. And they're looking for someone who has some experience with CASB systems.
Sierra Space is looking for a Cybersecurity Analyst III. The University of Colorado is hiring an Information Security Officer. Torumo BCT is looking for a Product Security Engineer. Maximum is hiring an Application Security Administrator. The City and County of Denver is looking for an Information Security Architect.
Looks like a pretty good job too. I was looking at that one. Yeah, it looked really interesting. Cool. Prologis is hiring an IT Governance, Risk, and Compliance Manager.
Western Union is looking for a group leader in cybersecurity engineering. Marathon Petroleum is hiring an internal auditor. And finally, RTD is looking for a senior cybersecurity engineer for access management. Good stuff. All right.
That is it for the newscast. We do have an interview this week. Hallelujah. Hallelujah. We, we had Douglas Brush, a friend of the show and also has his own show, Cybersecurity Interviews.
He sat down with David Stauss, a counsel at Husch Blackwell, and they talked about all the new privacy regulations around the country. We'd tell you about it, but it's private. And we had David on the show, I think, about 2 years ago. It's been a little while. Good to have him back on.
And, you know, of course, great update for us to stay on top of all this, these changing laws. Ever-changing. Looking forward to hearing it. All right. We'll talk to you again soon.
And when we talk next, it will be March, which will be even crazier than February. Yes. Thanks, Robb. All right. Hi, this is Mary Haynes.
VP of Network Security at Charter Communications. Welcome to Colorado EcoSecurity, for Colorado security professionals by Colorado security professionals.
All right, David, thank you for joining me yet again on another episode of Colorado EcoSecurity where we're talking an update in the data privacy stuff. We talked about a year ago, and you and I have obviously talked between then, but what we thought would be kind of great for the audience is to give people a better idea of what has changed because even in You know, pre-COVID, there was a lot of stuff going on in 2008 in various states. And now even in this year, as we get into 2023, there seems to be this evolving cadence of new and upcoming laws. When we spoke at lunch recently, you know, I kind of jokingly said, I'm sure you and all your privacy attorneys are all doing rich now that, you know, there's multiple state laws in effect as of January 1st, and everybody must be rushing to enforce it. But really, what's the reality of what we're seeing versus what are some of the state law changes over the past year or two and where that's going to lead a lot of people and how they have to worry about their privacy programs as it relates to security.
Yeah, yeah. Well, first, thanks for having me again on the podcast, and, you know, thrilled to have a chance to talk to your listeners again. To answer your question, we have now 5 state privacy laws. California was first, and everybody knows that. The California Consumer Privacy Act That went into effect in 2020.
And the big piece of the puzzle there is that that law was substantially amended on January 1st of this year when the California Privacy Rights Act amendments went into effect. And also the business-to-business and the employee exemptions sunsetted, which are the big things as of January 1st. We're still waiting for California to finish the regulations around the new updated version of the law. That could be done pretty soon. We expect that final regulation's published and then, hey, you have to go through an administrative process of getting those to be legit with a couple of votes and reviews.
Separate from that, we have Virginia that went into effect. That was January 1st. The Virginia Consumer Data Protection Act went into effect. And then we've got 3 other states that will be following. Colorado and Connecticut will go into effect on July 1st of this year, 2023, and then Utah happens at the end of the year.
So that's what's done right now. What is still on the way are, you know, the state— it's right, we're recording is January 24th, just that, you know, dates are kind of important, uh, given how fast things are moving right now. But we have now 10 or 11, depending upon how you look at the bills, states that have introduced, uh, proposed consumer privacy legislation similar to these 5 state bills. We've got Oregon, Oklahoma, Hawaii, Mississippi, Tennessee, Kentucky, Indiana, Iowa, New York, Massachusetts. And, you know, if you count the bills, New Jersey that rolled over into this session, there's more to come.
We expect to see bills in Michigan and Minnesota get introduced in the coming days and the potential for other states to join in as well. The other piece of the puzzle now that we are closely tracking is we have these broad consumer privacy bills, but we're also getting these sectoral bills that are getting proposed on a state level. And so what that means is we are seeing children's privacy bills, health privacy bills, biometric privacy bills, algorithmic discrimination bills, and automated decision-making bills get proposed on a state level. So we are rapidly adding to the amount of stuff that we need to track on the state level. And it's becoming much more nuanced around, you know, not just that there was a bill introduced, but, you know, what would it do?
What industries would it impact? And how would it change, if anything, the existing structure of these 5 state privacy bills that we have, laws that we have, I should say? Yeah. And with that, you know, it's, I always find it interesting because people, maybe correctly or incorrectly kind of conflate a lot of the privacy and data breach notifications, laws, statutes, and various forms of regulation. What really kind of was the thinking around that?
Because I think that that's an important part to say, well, you know, there's no— there's, there's obligations for many organizations to notify a potential data breach and notify participants or people that could be impacted. But really, what is the difference when it comes to data privacy? It seems to be more about, you know, what's being collected, how it's being stored and managed, and ultimately disposed of. Yeah, right. It's, you know, our typical data breach laws are— all 50 states have them now.
If you lose data, obviously, if you have a breach and it involves a certain type of data, and that's a much more narrower set of data— name and Social Security number, name and credit card information, those types of things. Then you've got to notify people, you know, consumers and maybe the Attorney General's office, maybe consumer reporting agencies. These privacy bills are, like you said, these are around transparency and rights around, you know, the individual consumer's right to transparency. So, i.e., your privacy notice, what you collect, how to use it, how do you share it, your rights around that. So the right to access, delete, port, correct, opt out of targeted advertising and sale of information.
And then they also have some other things, aspects to them, things like data protection assessments. So an upfront requirement to vet your privacy processing activity— I'm sorry, vet your processing activity and ensure that it's doing the right things. And then also to enter into contracts, data processing agreements. Those 2 aspects are really taken from the European Union's GDPR, and now they're part of the state privacy bills. And then we get, so, you know, and I mean, we're in Colorado and I was remiss to not mention that the Colorado Attorney General's Office is engaging in rulemaking right now around the Colorado Privacy Act.
And, you know, there's a lot of nuance in the regulations. There's a lot of nuance between these state privacy bills. For example, in Colorado, at least as it exists right now in the draft rules, they talk about sensitive data inferences and rights around sensitive data inferences. And other nuance. So there's commonality among these laws, but there's also nuance that really matters when you go to comply.
A lot of it seems to be too, and some of the challenges I've seen coming from GDPR is what constitutes private data. Different states, regulators, countries can have different ways of identifying what is concerning, for example, and some of the APAC territories, there's concerns about information around adoption, and that becomes a high privacy. Do you see— where do you see that playing out in the United States? Where there— is there going to be challenges for organizations to have to comply with all these different things because everybody's kind of doing it in a hodgepodge? Or is there some kind of common ground that somebody can apply to their privacy program and not feel like they're spending all day chasing the tangentials?
Yeah, it's a great question. I mean, it's what we talk to our clients about pretty much daily, right? Is, you know, can we have— I have one client who, you know, the one ring to rule them all, the Lord of the Rings reference, to address data privacy.
And, you know, there's a lot to that, right? I mean, we try to develop programs and disclosures and agreements data processing reviews, the data protection assessments I referred to earlier. We try to develop those that they comply with all the state privacy laws. And even if you have federal ones that are wrapped in, I mean, there are still federal laws that may be implicated here depending upon exemptions and exceptions to the laws. So in any event, we talk a lot about exactly those issues.
I think that California stands alone, right? California has a model that differs from the other models, and it's important to understand sort of the background here. California passes its law, and it's the result of a ballot measure. I think people know that story. The other laws that have passed in the other 4 states are based on a different model.
They're based on a bill that was drafted by Senator Carlyle in Washington State. It never passed Washington State, but that bill was used as a basis for lawmakers in Virginia, Utah, Colorado, and Connecticut as a basis for their laws. And so those 4 states, there's a lot of commonality. There's differences, but there's a lot of commonality there where that's becoming, you know, the predominant model in the state bills that get proposed, that Washington Privacy Act model. We tend to look at those and we tend to say, okay, is it more Is it the Virginia model, which is a middle-of-the-road model?
Is it Utah, which is extremely business-friendly model of the law, of the bill, I should say? Or is it, you know, Colorado, Connecticut, which are more consumer-friendly? So we take those 4 and we kind of group those together. And then we look at the nuances of California when we're trying to come up with, you know, one approach to it. And there are pain points.
Generally, I think the definition of personal information, personal data, in those laws aligns. California has a much different approach in Section 1798.140. They define it really by a prescriptive list of things, but there's also a catch-all phrase of like anything that's reasonably capable of being associated with the individual consumer. So there's alignment there, but, you know, where we find problems are around like the privacy policy drafting, how prescriptive California is in its approach and the rules versus the other states, which You know, we'll see where Colorado lands in regulations, but the other states are less prescriptive. And we still have a lot to learn about California as well.
There's partial rulemaking happening right now in California, but there's going to be further rulemaking on cybersecurity audits and automated decision-making and a few other topics.
Yeah, I think we talked a little bit about this recently, but, you know, what is really driving a lot of these states to to really take action on this, to start passing some of this legislation? I can certainly see it being a nice bipartisan issue that anybody can get behind. But what's really the kind of motive and impetus for a lot of these? Yeah, and it's simple. It's federal inaction, right?
And so we, you know, I don't want to plug my own podcast on your podcast, but we run a podcast in which we interview state lawmakers. And I can't tell you how many we're up to, maybe 10 or 12 state lawmakers who have run these consumer privacy bills. And I always ask that exact question. I say, why? Why are you doing this?
And it is always the same answer, which is the federal government needs to do this and it won't. And so state lawmakers, they see a big issue that needs to be tackled and they are going to tackle it. And each one will tell you that this should happen on a federal level. Now, what that looks like is a whole different story. And we had, you know, we had a federal bill, the ADPPA, get very— well, very far is not the right way— further than any bill in recent memory.
And it got out of a committee, a House committee, and it actually got killed by California, of all places, because the California delegation, the governor, the attorney general, they did not want the federal bill to preempt these state laws. They wanted the states to be able to go further in regulating this, and in particular around the idea that this is a rapidly changing area, the states should be able to go further. So it's interesting now, like the state, the existence of state bills is now becoming this really interesting pushback on passing federal legislation. I don't know that we would've gotten across the finish line anyway. There was a huge roadblock in the Senate with Senator Cantwell.
She didn't like the federal, she didn't like the bill, the ADPPA. But by and large, to answer your question, it is federal inactivity. And Like I mentioned before, the conversation's changing, and yet that nuance is really important because, you know, these other issues, these general consumer privacy bills that have gotten passed in these 5 states, lawmakers are tackling other privacy topics. Last year in California, they passed the California Age Appropriate Design Code. Assemblymember Wicks was a bill sponsor on that, and that seeks to regulate children's privacy.
It's a very controversial bill. It's going to be subject to a lawsuit that's going to challenge it based on First Amendment and preemption issues and Section 230 issues and void for vagueness issues. But, you know, California has gone on and they've pursued that legislation because the federal government won't. And then other topics, like I mentioned before as well, like data broker bills, that was part of the ADPPA, the federal bill. We have 2 states that have passed it, California and Vermont.
Other state bills are looking at it. Oregon has one. Delaware had one last year that did not pass. The Michigan bill that got introduced last year and will be reintroduced this year— well, it had one last year. I understand it'll have one this coming year as well.
Biometric privacy bills, you know, those are those nasty BIPA bills where you get to sue and have a prior right of action over the collection of biometric information. Those bills have started to creep up in a number of states this year as well. So until the federal government does something, these state lawmakers are going to keep legislating and it's going to be on more and more topics. And I think I mentioned at the beginning that AI algorithmic discrimination, mark my words, that that is going to be something that in a few years from now we are going to be talking about those bills. It's like, it's like you're seeing the softballs before I throw them.
I mean, that was kind of where I was going because I know there was, you know, a kind of a takeaway from, you know, particularly at the federal level where the White House in September pushed out, you know, the enhancing competition and platform accountability. Now, obviously a lot of that was based on antitrust focus, but underlying that was a lot of data privacy stuff and particularly around AI. Do we see that maybe the federal government's going to pick up along those routes as something to kind of maybe differentiate their lawmaking as opposed to some of the states? Yeah, I think if you're a betting man, right, the answer to anything that the question of will the federal government, the answer is no, right? If you're a betting man.
Yeah, they came out with an AI Bill of Rights, the White House did over the summer. Like you've said, there's been general tech legislation. There's been privacy legislation that's been proposed. There's been a Kids Online Safety Act proposed in the in the Senate. There's been no shortage of talk on the federal level on a bunch of different issues, but nothing has gotten across the finish line.
Now, you know, a big caveat there would be the Federal Trade Commission is engaging in potential rulemaking now around commercial surveillance. And so, you know, that is a, that is a long process that needs to go through with the FTC, but that could be a game changer if they came out with rules and how broad they were. And that's, you know, there's no draft right now. Basically, they put out requests for comments on a number of different topics. And so we're going through that process now.
It feels like given where we are on federal legislation with the House flipping to Republicans, it feels like things have stalled legislatively. So maybe the FTC is going to be the answer, but You never know. I mean, things can change. Last week, President Biden wrote an op-ed talking about, well, at a minimum, we need to address children's privacy. And there is general alignment between parties that children's privacy needs to be addressed.
And we see that at the state level, we see it at the federal level. So that might be one area where they can carve off and they can actually do something on an area that everybody Um, that everybody seems to, to believe needs to be, needs to be addressed. Yeah, you know, to quote The Simpsons, won't somebody please think about the children? It seems like an easy one to get behind because who's really gonna say, I don't, I don't care about kids. Yeah, I mean, it's, it's, you know, it's funny, right?
When these bills, these bills are subject of extensive, um, lobbying efforts and stakeholder efforts, but typically when it gets to the to a vote on the floor, typically you see very few no votes, right? Because who is against privacy, right? And to your point, like, who is against children, right? I mean, it's just, it's, it's a, it's, it's not exactly, uh, something that you want to run against where your opponent can say, you know, this was the guy who, who voted against children's privacy, right? It may have been because the bill didn't work, but, you know, do, do your constituents, you know, appreciate that?
Type of nuance, right? So, uh, that's why, you know, so much of the action here happens, you know, before these get to the floor votes and committees. And, um, yeah, we've been a part of that with, um, working through that process for some. And, and it is a very robust process, that stakeholder process. Yeah.
And I think that's an important thing to note. You know, I think a lot of folks, you know, like really with any law, does they— people just don't know how really the sausage is made and the amount of parties that get involved with that. So maybe if you can walk through some examples of how, you know, we talked about Virginia, we all know there was a heavy tech focus on that. But, um, no, quite frankly, things don't happen in a vacuum, and there's a lot of competing interests and competing voices. But kind of, it just kind of maybe shed some light onto that because I think people just don't know.
Yeah, so I mean, it can be a pretty lengthy process, right? I'll give you an example. Uh, Michigan, right? I mentioned that before. So Senator Bayer there introduced a bill in September.
Well, legislative session closed in December, so she knew when she introduced a bill that it was DOA, right? But the thought was, I'm going to introduce this bill so that way I can have, you know, the stakeholders who are interested in this contact me. And so it's not like state lawmakers are sitting there and, by and large, you know, sitting there with a Rolodex of people who care about a bill. You'd be surprised at the types of entities that might care about a consumer privacy bill. I mean, there was In Connecticut, it was a restaurant association was very engaged in the discussion.
In other places, it could be like grocery chains, those types of things, because, you know, these things can touch a lot of different areas, right? Small businesses can be very concerned about it. It's not just the big techs of the world. And sometimes big tech is the least of the problem because big tech is sophisticated on these issues and they're complying with GDPR and they want to keep things, you know, to what they know for sure. But, you know, like Microsoft actually tends to go out and support all of these bills and has people testify in support of them.
So like that, those distinctions really matter. But, you know, so you'll put out a bill, you'll go through the stakeholder process, receive a lot of comments on that one. And if you're at the state level, you know, the resources are kind of limited, right, for state lawmakers. It really depends upon the individual state about how much resources they have as far as, you know, legislative research, looking at other state laws. It really depends too about whether the state attorney general's office is engaged in the process and whether they are out there doing the research and doing the negotiation.
So, in Oregon, for example, Oregon had a work group this past summer and the fall where they work grouped and worked on each section of a bill with a work group of about 40 people. There's a small table of about 10 to 12 people and a larger table of about 40 people. So there, you know, they've tried to build the stakeholder process into the bill before they introduce it. That happened in Connecticut last year as well, where Senator Maroney ran a workgroup. His bill had failed the year before.
He ran a workgroup and got alignment around various issues. And so people couldn't say that they hadn't had their opportunity to talk and to comment. And that's a big piece of the puzzle too. So yeah, you go through this process, right? And you go through the process with, with the stakeholders, you know, which tend to be lobbyists.
Um, and they, they, it's a full gamut. Like I said, I mean, you can have privacy advocates, you can also have tech advocates, um, and you can have, you know, people who don't fit into either of those, right, have individual interests. Um, and you try to make the bill work and you try to get alignment, and then you have to deal with you know, your fellow lawmakers and get, and get co-sponsors, and you want to get bipartisan sponsors, and you want to get bicameral sponsorship. Because great, you got your bill through the Senate, but it died in the House. And that happened a bunch last year because, you know, you got to line up advocates in both chambers that are pushing this legislation and are invested in it.
And like I said, the Attorney General's Office is a big piece of that puzzle too, because these, these laws are enforced to date, these laws are enforced by Attorney General's Office. And it's been the case where, you know, you want to have AG support behind a bill. And if you do, that's a good indication that you got a lot of traction. So, I mean, I think for listeners who are out there, it is a long and laborious process. And I've said in other venues, and I'll say it here, it is very hard to pass a good consumer privacy bill.
It is very hard. It's easy to pass a bad one. You can get a bad one passed in 3 weeks. But to pass a good one that tries to do and tackle a bunch of these issues, every issue you throw into a bill is going to be subject to debate. And you need a— you need an advocate.
You need a bill sponsor who's passionate about this and is going to sit down and spend the long hours to navigate through these extremely thorny issues.
Which then kind of begs the question is, okay, we go through this process. And then there's enforcement. I think we've seen this with a lot of things. Any law, any bill can pass that says, hey, thou shalt, but what does the enforcement actions look like? You know, some of the things that I've picked up from the different countries and entities and territories inside GDPR and other states, it's great.
A lot of this was passed. We believe in it, but then there was just not enough people to do the enforcement actions. Could that be a concern here? Yeah, that is the give and take is, you know, privacy advocates will tell you these bills need prior rights of action to be enforceable. And then, you know, business advocates will tell you that AG enforcement works and that there's a huge risk with private enforcement.
Yeah, and I'm not here to opine on either. I have my own opinions on that. What I'll say is we honestly don't know yet whether AG enforcement is going to work. The California law is the only one that's been on the books to date that had a right to cure that sunsetted January 1st. But the AG's office was required to give you a notice that said, hey, here's your violations.
And then you had an opportunity to cure those violations. And they did, by their own statements, they did hundreds of investigations, notice letters, and only one company, Sephora, did not cure the notice, and they were fined $1.2 million. So that is the only public enforcement action that we have right now is $1.2 million. But, you know, the threat of enforcement definitely got a number, many, many companies to get aligned. The other states, you know, if you look at the other 4 laws, Utah and Virginia have rights to cure, and those rights to cure do not sunset.
So, you know, if you get written up for a violation in Virginia, you're going to have the right to cure that. I think it's 30 or 60 days. I can't recall off the top of my head. And that's going to exist. I mean, so, you know, does that, does that create a strong enforcement mechanism?
I mean, make your own opinion there. But, you know, if you had the right to cure, then the AG's office is, you know, motivated differently. Now, Connecticut and Colorado are similar to California. California in the sense that once those laws go into effect in July of this year, there's going to be an 18-month period in which you will have the right to cure, and after that it sunsets. So in a couple years' time, what you're going to see is you're going to see what I call the 3 Cs of state privacy law— California, Connecticut, and Colorado— that are going to have the ability to engage in multi-state enforcement actions because they don't have the right to cure, right?
So they can come out of the gate, they can file a complaint, they can do their investigations, And the companies don't have the right to cure those violations. Meanwhile, you know, Virginia and Utah, to the extent that they wanted to jump in, would first have to, you know, allow the companies to cure the violation. Maybe they do, maybe they don't, but it just really changes the enforcement mechanism. Last piece of the puzzle then is the California Privacy Rights Act created a new agency called the California Privacy Protection Agency. That agency will have shared enforcement responsibility with the California Attorney General's Office.
So, you know, that creates a whole other dynamic. There's administrative enforcement through the California Privacy Rights Act that doesn't start until July of this year. And so we really have to see what that's going to play out. But the enforcement issue, I do think we will see, you know, at least in those 3 C's, I do think we are going to see enforcement. Those attorney generals and the California Privacy Protection Agency, they are motivated to do things.
And you did touch on something I do have to pick at the scab a little bit. I mean, I have to wonder too, again, I'm biased based on some of the work I've been doing in data privacy litigation lately. Is there going to be an uptick in data privacy litigation, data breach litigation? Because I can certainly see the plaintiff's bar looking at it from perspective of saying, as these laws— there's obviously more awareness about them. And with these laws coming in, could there be civil actions as a form of enforcement?
Because hey, look, you know, consumers were harmed, and we can, we can make an argument for that. And there's been the private right of action thrown around in a couple states. Is, is this something that could potentially get momentum? Yeah, this is a great question. So, uh, in California, there is a limited private right of action for data breaches.
Um, it's not for the general privacy rights, it's for data breaches. Now, that, that did not stop plaintiffs from filing, uh, lawsuits over CCPA violations, and they try, you know, to articulate arguments around that, to use general consumer privacy statutes to argue there's been violations of the CCPA. But, you know, each of these laws passed to date says this law will not create a prior right of action, right? Except for that one caveat I gave you in California. I think what we are seeing, though, is really— I mean, we've got our BIPA litigation, so that's our Illinois Biometric Information Privacy Act.
Set that aside. That's, you know, tracking. And, you know, there was a huge judgment or huge jury verdict over the summer in the hundreds of millions of dollars against the company. So that's its own beast. But what we're seeing a lot of now are plaintiffs' lawyers getting very inventive in looking at very old statutes like the Video Privacy Protection Act or Invasion of Privacy Act statutes and claiming that there's privacy violations for things like session replay technology, the use of the Facebook Pixel in certain instances, and chat features as well.
And so we are seeing these opportunistic lawsuits filed alleging privacy violations. And that's really becoming— it's hard. It's hard for clients to drive compliance. We have our own things that we do with clients to mitigate the risk there around disclosure and consent. But, you know, every— it seems like every 6 months a new theory around tracking technology litigation pops up.
And, you know, we're trying to, you know, work it through the court system. And, you know, a lot of that, it depends upon the location. California has been more favorable to consumer complaints, Florida less so. And it depends on the statutes at issue as well. So You know, it's, it's maybe it's a popular refrain, but I mean, it's just, there's just a ton going on out there.
I mean, it, it makes you really want to have one federal standard to comply with. And we just don't have it right now. Well, as you know, as we kind of look forward, just even on the state side, what are just to kind of, kind of earmark some of these things and we touched on them, but if you can kind of maybe tell me what is looking forward for Colorado this year? You know, what are some of the things that consumers and businesses should be kind of keeping a track on? Yeah, so in Colorado, I mean, the big piece is July 1st of this year, the Colorado Privacy Act goes into effect.
The AG's office is engaged in rulemaking right now. There's a hearing on February 1st. Maybe this publishes after or before, I don't know, but there's a, there's public hearing on February 1st. And, you know, we'll see revised rules at some point in time. I don't pretend to know the schedule.
It hasn't been published, right? But they need to get it done. I think, you know, reading the tea leaves, I think we'll have it done by April. But, you know, who knows, remains to be seen. So if you're subject to it, and, you know, you should look, it's the threshold issue is 100,000 consumers in a B2C capacity.
You need to be processing that information in controller capacity. And there's a bunch of exemptions as well. Like if you're a GLBA, there's a straight up exemption. So it's important to look at the law and see if you're covered. But that's it, you know, for— that's the big piece.
And there's a lot of nuance there. We have yet to see any bills filed in Colorado on consumer privacy this session, but the session's not over. And, you know, we've got some time to go. So I think, you know, looking to see whether we get any bills filed on things like children's privacy or biometric information privacy. You know, because, you know, Colorado is now a very blue state.
In the 2020 election, Polis won and Democrats extended their majorities in each of the chambers. And obviously Weiser is the attorney general in Colorado and very interested in particular. He had a recent LinkedIn post saying that one of the things he wanted to do in his second term was focus on teen mental health. Well, a big piece of teen mental health is privacy, teen privacy, I should say. So anyway, yeah, I mean, the big upcoming iceberg is the Colorado Privacy Act for people to kind of get their arms wrapped around, either because it's the first time they've had to deal with privacy if they're a regional company, or because they're trying to figure out how to fold that into their California compliance program.
Excellent. And I'd say finally, as we kind of wrap this up, you know, how can people get involved with this? You know, you kind of hear some of the things that— some of the takeaways I have here is that, you know, the legislative branches and lawmakers look for input, you know, but I think people don't know where to start looking for that. Are there organizations? Are there ways that folks can be engaged so they can have their voice heard as these laws develop?
Yeah, so great question. And, um, Yeah, for the, the Colorado rulemaking is ongoing right now. If you want, you can go on the Colorado Attorney General's website and you can put in comments, uh, to, to the Colorado Attorney General's office. It is a public, uh, it's, it's a public comment period. Like I said, there's a hearing.
Anybody can testify at the hearing. I think, you know, the Attorney General's office has encouraged everyone who has an interest in it to, to, to have their say. And I, I encourage people to do that as well, right? I mean, Don't think just because you may have, you know, you may not have everything figured out, you may have something very important figured out, right? Um, and I think the more voices you get and the more people who are engaged in the process, the better, uh, the better the process is, is my opinion on the whole thing.
Um, as far as, you know, when the bills come out, um, I think the best methodology is if you, A, read it, read the bill when it comes out. If you feel passionately about body, you feel like something needs to be changed. I think that's the kind of the benefit of state lawmaking. I mean, state lawmakers, you can email them and say, hey, here's my, here's my, you know, thoughtful comments on your bill. And I think you should do X, Y, and Z.
And at the state level, people tend to listen. They tend to listen. I can't say what it is on the federal level, but the state level, like, you know, that's backyard hometown lawmaking. And it's kind of lawmaking in my mind, it kind of, it's in its purest version, right? Where, you know, a lot of these guys who are, and women who are in the state legislature is not making a career out of it.
They want to make, they want to do it right and they want to listen to a bunch of voices. So yeah, I think, you know, encouraging people to raise your hand and engage in the process and, you know, it's tell people that it's important to you and it's important that it gets done right.
Well, David, thank you so much for this year's update. Hopefully we can do this again next year. Year. There'll be even more to talk about, but where can folks find you online to kind of keep track of what you're doing and all these things as they're emerging? Yeah, thanks.
So we run a privacy blog. It's called bytebacklaw.com, B-Y-T-E-B-A-C-K-law.com.
We push out weekly updates when the legislative sessions are hot. We push out weekly updates on all these bills that we've been talking about. So if you'd like to Track us, then that's the place. Subscribe to bitebacklaw.com.
Awesome, David. Thank you. We'll make sure that gets gets pushed out there in the show notes as well. But thank you again for your time today, and hope to see you out there at different events. Thanks, Doug.
Really appreciate it. Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups. A calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.