All episodes

Newscast

Apple Podcasts Spotify SoundCloud

News from Cherry Cricket, Ball Corp, Boom Supersonic, Casa Bonita, Optiv, Red Canary, SSO, zvelo, LogRhythm and a lot more.

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript5420 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 249. This is for the week of July 3rd Alex, happy Independence Day.

Happy Independence Day, Robb. As Sublime once said, it's summertime and the living's easy. Oh yeah, yeah, I haven't thought about that yet. Any big plans for the holiday? You know, we're kind of taking it easy.

We've got a few parties to go to and things like that. We're not doing any traveling. Really? Few parties is taking it easy? Well, over, over the— not on the 4th, but like over the 4 or 5 days around the 4th of July.

Our neighborhood always does a parade around the neighborhood, you know, some old cars and fire trucks and all that. And the kids, the kids like that. And then they have like some, some pool games. They throw a bunch of coins in the pool. Oh yeah, penny dive.

That's always fun. Yeah, we do all that kind of stuff. So it'll be, it'll be laid back, but we'll be hanging around the house. You know, I haven't mentioned on the show yet, I am fun employed now. You are fun employed.

We've talked about on the show for, for the last couple of years that I've been an executive over at Red Canary. As of early June, I I kind of decided to take some time off with the family. We've been on one big vacation. We have another one coming. It's been a lot of fun and looking forward to catching up with people in the at the end of the summer when when things slow down a little bit.

Well, congrats, Robb. I know it was a good run there at Red Canary, but excited for you to be able to take some time off and enjoy your summer and maybe longer and get pumped. I'm working out a lot, Alex. That's right. As you can tell, getting jacked.

I'm getting jacked. I'm taking a start. I'm not taking a start. Except for that rash. Anyway, we have some stuff we probably need to talk about before we get into the podcast.

Robb, we have a Slack channel. Oh wow, we do. It's— I don't even know the numbers these days, but there's lots of people in there. 2,500 and 3,000, somewhere in there, somewhere in that range. It's been pretty active lately.

I think we've been trying to get some people to, to talk more and be more active and own different parts of the workspace. So that's been good. And the ownership a lot of folks have had stepping up and, and helping drive conversation, it's been great. I've had I'll tell you, it's hard for me to keep up with. It is for sure.

So if you want to join, go to the website colorado-security.com, find the join Slack button, click that, and then submit the form. We'll get you added. And while you're there, you should sign up for our mailing list. You know, we send out the show notes each month as the, as the podcast gets published, but we also send out other important news like, like the upcoming volunteer opportunities we have and the picnic that we're going to talk in a little bit. This is your way to stay in the community.

The salary survey stuff we do goes out through there. We don't We don't send anything but stuff you're gonna care about. So you should get signed up on the mailing list while you're at colorado-security.com. Exactly. You know, if you're listening to this podcast, you're probably doing it on some sort of podcast app.

While you're there, it'd be great if you could rate us. Hopefully it's a good rating. And also subscribe so that this shows up in your podcast queue automatically. And if there's, if you wanna help us out, there's a couple things you could do to help. Number one, we would love it if you would tell a friend, help grow the Colorado security community.

It's already the best in the country. But it can be better if they're a part of it. It's going to be better. So help, help get some new folks to join us. And if you want to help financially support the show, we really appreciate those who, who provide cash.

We use Patreon as our platform to help pay for the cost of the show. And we do have a new patron this month. We do. Tracy Dawson, who is the CRO at Nereus. Is that how it's pronounced?

Do we know? Nereus. Nereus. Anyway, they're, I think, a new-ish VAR in town. And they're here in Colorado.

They're here in Colorado. Thank you for your support. We're looking forward to get to know you guys better in the coming days. All right. We have a couple more nonstandard announcements before we get into the podcast.

First, we are doing our second volunteer event with Colorado Equal Security Gives Back. That's right. Okay. Sorry, I forgot the name. I forgot the brand name.

Yep. And it is on August 5th. Yeah. There's been some information posted in the Slack workspace. I have a to-do to send out an email to the mailing list with some more information.

But basically it is on the calendar of events already. Okay. It's on the calendar. It'll be in the newsletter under events. Yeah.

So folks can look in the newsletter and folks can also go into the calendar to find all the details. Yeah. So we're going to be volunteering to help at a fundraising event for Brent's Place. Is that— that's what it's called. Chris Abbey is helping us organize this and it's a great charity and we'll be helping it at sort of a carnival event and making sure that that goes off really well.

So Brent's Place helps with costs for families of kids who are terminally ill. At Colorado Children's Hospital. Obviously just a fantastic charity. Like you mentioned, they do this big like block party or carnival type thing, and we're going to help them with setup and basically make sure that this is a successful event for them. Yeah. Looking forward to that.

Also, the second thing we're going to be doing, our second annual summer picnic that is going to be on August 26th, and we're doing that at Berkeley Lake Park. You know where that is? Yeah, it's like, it's I-70 and Sheridan, maybe. Okay, make it easier for our friends from the north. Yes, it is sort of centrally located.

It's by Berkeley Lake. So there's, you know, some water there, which will be nice. And we're gonna be sending out more details on that soon. We're still doing the organizing, but mark that date, the 26th of August. We would love to have everybody there.

Fantastic. Thanks, Alex. Let's jump into the news. Did you see that TSA is rolling out some new facial recognition software at Denver International Airport. I did see that.

It's sort of interesting. They're, they're doing this as sounds like as a pilot in some of the north checkpoint areas. The idea is that they'll be able to recognize you through the facial recognition, match you to your travel documents, and you won't even have to provide a boarding pass or, you know, any other stuff like that. It would just automatically do that stuff for you. Again, theoretically, you whisk right through security and, and all that kind of stuff.

That, that's about all I know about it. Yeah. I mean, it sounds very similar to what I get from CLEAR. You know, I use TSA Pre. TSA or just the CLEAR product in addition to that means that you can use biometrics instead of having to have an ID.

But you do still need your, your, your boarding pass in that case. And this sounds like it gets rid of the need for a boarding pass. Yeah. The thing that I don't remember them addressing is, you know, with CLEAR, you have to register, right? Like, so you come in and they take pictures of your eyes and your fingerprints and stuff like that so that you can use biometrics.

I didn't really talk about how, how the process works to match up your face with your stuff, right? Like, I don't think there's a registration process. This seems a little more creepy in that, that kind of sense. Yeah. I mean, the government is tracking where we go.

This is a step along the way of them tracking us more. Obviously, I think they're already doing it. Regardless of whether we get the convenience out of it. I get it if you don't like it. There's an opt-out option, but I think all you're doing is opting out of the convenience.

I don't think you're opting out of the tracking. Right. If you're going to go through the security checkpoints at TSA, they're probably still going to take your picture with the software. And they're probably comparing to make sure everyone who doesn't opt in is using the right ID compared to their software anyway. Yeah.

You're probably in the system. It's just a question. I'm just guessing. This is all alleged. Don't, don't come after me, TSA.

I don't know what you're doing, but this, this would make sense to me. Yeah. Anyway, like it or not, it's coming to— it's actually at DIA. I haven't seen it yet, but, uh, but it's seen you. It's seen me.

All right. Uh, up next, uh, Cherry Cricket, which is, of course, a, you know, beloved Denver hamburger restaurant, has opened a new location, uh, down near us in Littleton, Robb. Yeah, I, I'm actually excited to try it. You know, Cherry Cricket is, I think, frequently known as the best burger in Colorado, whether it's the best or one of the best, either way, it's obviously debatable. I was really surprised a few years ago when they put in a new Cherry Cricket right by the ballpark, right down in Lodo, and happily surprised.

I actually think I like that location better than I like the original Cricket location. It's hard to park at the original one. Well, and it's because it's so old, like all the tables are jammed together. It's hard to move around in there. I mean, there's some kitschiness to that, right?

Like, that, that's kind of how the original one is. But, uh, but yes, uh, that new one's nice and nice and big. Um, well, anyway, they have a new one on Littleton Boulevard, downtown Littleton. I haven't been there, but you have. What's the reviews?

Yeah, it's great. Um, the, you know, similar, same food to other Cherry Cricket locations. It's nice and spacious, and, uh, they have a little outdoor patio area with, um, cornhole and some other stuff like that. So kind of an indoor-outdoor kind of thing, and it's, it's very nice. I know I said— they said that they replaced the previous restaurant's parking lot with outdoor seating.

So are you now— you're parking on streets somewhere nearby? There is still some parking lot. I think that they added some additional parking to what was there before. We didn't have a problem parking even though it was crowded. So does it feel more like the Lodo one or the original?

It feels like more like the Lodo one, but, you know, sort of a suburban version of the Lodo one. Yeah, I'm looking forward to— I enjoy Cherry Cricket. You know, their green chili burgers are Probably the, probably the best thing there. Yeah, it's good stuff. All right.

Next, this is a really surprising story to me. At least it came out of nowhere from my perspective. Maybe those in the know saw it coming. Ball Corp., which is like the big company headquartered over in Golden who makes— they make all the cans for, I think, most soda and beer cans, really. Like, I know for Coors at least, right?

They all— they own a wholly owned subsidiary of theirs is Ball Aerospace. Yep. And they are currently considering selling off Ball Aerospace. Yeah, they didn't really go into any details about why they wanted to sell it other than maybe now it's a good time for it being— sounded like overvalued, like, you know, more value in selling it than keeping the business. And I mean, obviously, as a business, if that's the case, you probably want to do that.

Yeah, I mean, it could make sense. I don't know a lot about that business. I'm not going to pretend to. But, you know, you'd say hypothetically that you know, owning— if you're a manufacturing company that makes cans, the level of regulatory and industry nuance of aerospace, it's just different, right? And if there's a company out there, you know, think of like a Lockheed or a ULA, who, who's all they do is focus on that, there's a much lower additional cost by having all that other stuff added on.

And, you know, Ball Corp is a 10,000-person— no, no, it was bigger than that, right? 20,000-person company? Yeah, sounds right. I don't remember the numbers exactly. And I think Ball Aerospace was $6,000.

So it was, it was a significant portion, but not anywhere near the majority of the company. I would also think this would probably be a fairly easy transaction also, just because of the nature of the business. I have to believe that Ball Aerospace is probably pretty well sectioned off from the rest of Ball Corp, right? So it's, it's another entity anyway, just owned by the company. So probably easy to sell.

And, you know, if they get a good price for it, good for them. Just, just to correct myself, it's $21,000 for Ball Corp overall and $6,000 for Ball Aerospace. Okay, sounds good. All right. Moving on to the next.

This is actually— this is a story from a travel blog that I follow. And it's funny, I think this is the second or third time we've gotten a story from them into the, into the news. But this is about Boom Aerospace, or sorry, Boom Supersonic. And the title says Boom Supersonic inches closer to legitimacy as doubts remain. Yeah.

Interesting. We've talked about Boom Supersonic on the show a number of times. And as I read this article, I'm like, oh yeah, they made some big claims about timelines. They made some— they talked and made some splash about this, this, uh, you know, the sales they've made and this, this deal they had with Rolls-Royce to do the engine. And this article kind of goes through and says, hey, they made claims about timelines and they keep slipping, right?

You know, the sales seem to be mostly contingent sales. Rolls-Royce pulled out of their engine deal. So there was a lot of doubts about Boom's ability to deliver. And this article says, But recently, it's kind of turned around. Yeah.

So it sounds like they are getting close, closer to actually having things to test. And they have a new partnership for the engines, other things like that. I do think it's funny also that, you know, most of the articles we've read are local articles, either probably Denver Business Journal, or, you know, Denver Post or things like that. And, and they've all been pretty favorable. But it's, you know, hey, local company is doing good stuff.

So it is interesting to see the other side of that from, from some skepticism from some other people. I wouldn't call this necessarily like unfavorable. I would say that they're skeptical. That's a good word for it. Yeah.

And I think everyone's excited about the promise of basically sub— or what do you call it? Postsonic? What's above sonic? Supersonic. Supersonic.

Okay. That's the name of the whole thing. Yeah. Thank you. About supersonic flight across the ocean for— and they're saying the cost should be approximately the same as a business class ticket.

Like, okay. That sounds expensive, but man, if you're doing business travel, you can get there in a few hours instead of 10 hours. It probably makes a lot of sense. Yeah. Yeah.

So we'll see. Hopefully they continue to move in the right direction. And, uh, one of these days we have actual planes to see. All right. So I know I feel like we beat the Casa Bonita drum a ton, but I found this one really interesting.

Um, not all of the updates are all that interesting, but this one to me was, you know, they, they've opened, um, for kind of a limited release where people who are on their mailing list can get timed entry tickets to go to Casa Bonita. The first experiments taught them that with this experience where you buy tickets in advance, people don't tip. Right. That's been their experience so far. So did they put big signs on the door saying, start tipping, you jerks?

What did they do, Alex? Instead, they decided to go the other way and they just include tip as part of the price. So no tipping at Casa Bonita. Um, which, you know, there are some restaurants that have gone this direction, but for the most part, you know, in, in the restaurant industry, it is still a tip-based industry. So, uh, so I think that's pretty cool.

Uh, one of the things that I also learned from this article was, um, I, I think it's $40 a person, um, for a ticket for adults, uh, for adults. Um, and that includes food. Of course, you get unlimited sopapillas. Yeah. But it also includes, you know, a, a non-alcoholic drink also, like, Fountain drink.

Fountain drink. So, and I was trying to think, my original thought was, you know, $40. I mean, Casa Bonita is cool, but that seems like kind of expensive for, you know, you take you and your kids and your wife, whatever, you're at $120, right? Yeah, it's not cheap. But then when you think about it, if there's no tip, yeah, if there's, if it includes a drink, which these days, like you buy a soft drink at a restaurant, it could be $3, $4.

And if the food is good, which it's supposed to be, then you know that's not actually a horrible deal. I mean, there's experience there too, right? You don't go to Casa Bonita because it's the most convenient, fastest place to go, right? You're going because you want to have a night out at Casa Bonita, and for a night out, it's actually quite affordable. That's true.

And you know, if you're not going for 45 minutes, you're going probably for an hour and a half, 2 hours, right? I'm guessing. The article also mentioned that as they made the decision. To, to not allow tips, that they more than doubled the, the pay for all of the service employees. Yeah.

So they went from $14 to like $30. It was $14.27 an hour plus tips. They realized, hey, you're not getting tipped. So they went from $14 to $30 an hour. Yeah.

So pretty cool. I'm really glad that this is how it— what they chose to do. Personally, I would love to see this everywhere, like just standardized paying people the right wage. Jack my price up to the appropriate level so I can't pretend I can't afford it. Like, let's just do it, right?

And yep, I'm glad that they're leading the way. And the article also dropped the fact that they— that the owners dropped $40 million on the renovation. I know we talked about it before. It just kind of still blows my mind. It's a lot of money.

It's a lot of money. It's a lot of episodes of South Park. You're going to have to have a lot of people come through there to make that $40 million back. But about— about a million, right? About a million of them.

About a million. Yeah. Anyway. All right. Moving on.

Uh, let's get into the security, uh, stories. Uh, we have a blog actually from Optiv. Um, we don't tend to, to get a lot of Optiv blogs in here, so, um, it's been a trend lately though. It has been a trend. Uh, this one is talking about the changes to the 2023 OWASP Top 10 for API security, not the, the regular, um, OWASP Top 10 for AppSec, but for APIs.

Yeah, they, I mean, they, they list the whole 10 here and then, and then Optiv goes into describing the changes from previous years. Yep. Um, there's actually a, a new a new item on the list here. I can't read it and talk at the same time. What's the— what is it?

I forget which one it is. Is it the broken object— broken object level authorization? Or that's number 1. Yeah. Number 2 is broken authentication.

Number 3 is broken object property level authorization. It's the third one. It's the property level authorization. That's the new. So I can't read this and talk at the same time.

So rather than, rather than try to do that, let's say that if you are interested in API security, It seems like a good blog to figure out what are the new risks. For most of us out there, if you're not interested, it probably means you should be, because you probably don't have enough visibility into what APIs are on in your environment. It's worth taking a look at this. Yeah, the API top 10 is so great, partially because it is so different from the regular AppSec top 10. APIs are, you know, fundamentally different, and it's good to see that there has been that differentiation.

Anyway, moving on. Yeah. Next we have a blog from Red Canary. I find that, you know, Red Canary always does these really cool deep dives into stuff that you didn't know you should be interested in. And this is no exception to that.

This is talking about ROPC, which is a setting within— is it Auth0 or sorry, within OAuth? OAuth, I mean. Within OAuth that allows you, even though you require MFA for most identities, you can have specific accounts that do not require MFA. And the reason being, hey, I've got a legacy application that needs to authenticate. I gotta give it a static username and password.

Well, as you can imagine, you know, it's a nice feature to have for backwards compatibility, but it's also a really nice feature if you're an attacker trying to look through these identities to figure out which ones don't require MFA. Yeah, and then obviously you find those, it's much easier to attack Of course, with all Red Canary blogs, there's a whole lot of detail in here. They give lots of examples using Azure AD and going into, you know, what these grants look like and, you know, how you could see someone using them and other things like that. And also like figuring out which applications like you might be using that still need to support ROPC. You know, obviously if you don't need it, you want to get rid of it so that there isn't that loophole.

I think keeping a list of your applications that still have ROPC enabled as a thing for you to over time work through is a really good idea. You know, maybe put it in your policy exceptions wherever you track those things. And then on a regular basis, you just go back to it and say, hey, does this still need to be here? Are we at a place now where we can start turning these off? Otherwise they just linger forever and it becomes a way for the attackers to circumvent your MFA.

Exactly. Good stuff. All right. Next, we have a blog post from Ping Identity. This is around the benefit, the top benefits of single sign on and why it's important to your business.

So I was mentioning before we recorded, when I first read it, I'm like, yeah, this seems really like maybe marketing fluff just from the, from the, the title. But I dove in. I think there's actually some really good, um, some good points about why it's important. It's not, it's not for those of you who already have been doing MFA for years or single sign-on for years. This is for those folks who are, who are trying to figure out, does it make sense to put a project in place?

Yes, this is sort of the opposite of the Red Canary blog. There's not a lot of technical details here. But there is a lot of good basic information about SSO, how you would use it, why you should use it, and the benefits that you have from using it. So if that is of interest to you, check that one out. Yeah, we get a lot of folks talking about, hey, how do I get into the security industry?

Well, if you don't know about single sign-on, read this, right? And now you'll, you'll be conversational at least. All right, um, next, uh, we have a blog from Zvilo talking about AI and machine learning and cybersecurity. Um, I think, Robb, again, we were talking earlier, this one on the face of it, you think, uh, okay. Uh, yeah.

You know, more buzzwords, right? More, more buzzwords about what we're doing. But this, again, this is a really good, um, uh, article about AI and, and machine learning, talking a little bit about history, what it, what it is, and then, uh, where it is used in, uh, different types of applications. Yeah. The, the, the first section where they're going through the different types of of AI.

I was, you know, I've read that a lot of different places, a lot of different times. But the second section, they're talking about applications of AI and machine learning in cybersecurity. They've got a list of, I don't know, is it 15 or so specific examples of places it's used, you know, for fraud detection, phishing detection, vulnerability management, all these areas, and like, okay, like a paragraph describing how AI is helping enable that. I think it's nice. It's nice to read.

Where vendors have already started to find these places to be valuable. Yeah. I mean, some places that you might not have even thought about. And then, of course, after that, they do have a section also on the challenges and considerations you should have when thinking about using AI and ML in these areas, you know, risks and things to consider like bias in systems and other pieces like that. Yeah.

It's a good article. And once again, appreciate Zillow putting that out there for all of us for free. So, you know, take a read. All right, uh, last article. Um, this one, um, I think we just got in here just because it's sort of a celebratory article.

Uh, LogRhythm is celebrating 20 years. Hard to believe that LogRhythm has been around 20 years, um, but they have. Yeah, really cool stuff. They've obviously been one of the founding cornerstones of the security community in Colorado for the last couple decades. Um, they've, they've also grown their, their product, you know, beyond just, you know, I think of them as a SIEM company, but, you know, they have NDR.

They've got their Axon product, which allows them to integrate with a bunch of other tools. They're really— they're growing and trying to expand and really push things forward. And it's nice to see a local company still kicking and doing well after 2 decades. That's right. All right.

That is it for news. Next, we can jump over to our events. As a reminder, we do have that calendar of events at colorado-security.com. You can see all the stuff coming up this summer. Um, July actually has a good number of stuff.

June was pretty dead, but July is, uh, coming back a little bit. It's still slower than normal, but it's summer. But there are a few things anyway. First, um, on the 12th of July, ISSA Denver is doing their July meeting, both DTC and downtown. Yeah, if you want to do lunch in the DTC and dinner downtown, you can have 2 meals with, uh, with some security folks.

There you go. On the 18th, uh, we have Let's Talk Software Security, talking about Applying AI to AppSec. Hey, so this is, this is happening. Uh, on the 20th, uh, CSA Colorado is doing their July meeting, Getting Your Hands Dirty: Exploring Exploits with ChatGPT. All right, speaking of AI, right?

Right. Um, on the 26th, ISC² Pikes Peak down in the Springs, they have their July meeting. And then back on the 5th, we've got our, our Colorado Equal Security Gives Back event at Brent's place. Yeah. And just a reminder, on the, on the 26th, we don't have it out yet, but we would love to have you at the picnic.

Details coming soon. All right. Jump over to jobs. Let's do it. First, City of Lafayette is looking for a senior network and security administrator.

FirstBank, Colorado Bank for you. That's right. Is hiring an info security analyst. Proofpoint is looking for a security solution analyst too. Kaiser Permanente is hiring a VP.

VPs at Kaiser are pretty high-level positions. That is a high-level position. This is, this is not necessarily the same level as you'd get at most companies. They're hiring a VP of Technical Risk Management. Yes.

Is that Jason Zellmer's type of— That was— yes, that was his role. And it's been several people. Yeah, he left a while ago. But yeah, interesting. Maxar is looking for a product engineering information security manager.

Olympus is hiring a principal product cybersecurity engineer. And I didn't look at it too closely, but I assume that's the camera maker. So I actually did look because I was curious. It would— they do medical, medical technology, which I kind of wondered if it still was because medical imaging could be the camera maker. But at least this, this company that this is for does medical technology.

All right. Perforce is looking for a head of product security. The Federal Bureau of Investigations, the FBI, is looking to hire a special agent focused on cybersecurity. Yes. Fastly is looking for an IAM security architect.

And finally, Microsoft is hiring a principal security architect that can be located here in Colorado. It can. Awesome. Well, guys, that is it for the news. And we don't have an interview this week.

It's summer because we're slackers and it's summer and there ain't no cure for the summertime blues. As we start the show with one, we end it with one. Very good. We'll get another interview one of these days. And but you guys got to make sure you join us next month for our August podcast will be the 250th episode of the show.

That's a big milestone. And considering the fact that we're not doing weekly podcasts anymore, it's probably the last big milestone we're ever going to hit here. It's very possible that will be the last big milestone. 50 more episodes. That's, that's a long way in the future.

Um, but we would love to, to, to not only celebrate with you guys on the podcast, but celebrate with you in person at the picnic. Um, so we'll, we'll have some fun there to talk about it there too. Sounds good. All right, we'll talk to you guys next month. Thanks, Robb.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time. And remember, Colorado equals security.

Back to all episodes