Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is your newscast for episode 248 for the month of June. Alex, it's summer.
Basically, it is summer. And you know how I know it's summer, Rob? No. RMISC is over. RMISC, wow.
Although last year that wouldn't have been a useful— No, not last year, because we were in September. We got hosed last year with our convention center access. But great conference. I got to go for just a little bit on Friday, and I was out of town previous to that. Any highlights from your perspective?
Apparently I talked a lot because my voice is still a little bit hoarse.
A lot of great stuff. I saw some really good sessions. Some folks on my team, uh, Stephen and Tara did a presentation on ChatGPT, which was, which was awesome. Yeah, I saw a really good leadership presentation by Andy Ellis. Yeah, lots of other good stuff too.
Yeah, I mean, it's just such a great chance to get everyone back together again. You know, it is a vibrant community here in town, and RMISC is one of the, you know, one of the keystones of that. Love to see it. Um, why don't we do some, uh, some quick housekeeping? You know, we would love it if you would join us on Slack.
We have a Slack community with, again, a lot of people over at RMIC. Yeah. Um, really, I'd say that, you know, over the last few weeks we've revitalized a lot of the channels and a lot more conversation going on. If you've been there in the past and dropped away, we'd love to see you come back. We also have a mailing list.
Uh, so when this podcast drops, you will automatically get an email from our MailChimp with the details of that. That's really all the mailing list is used for. Occasionally a couple other things like these, the salary survey, but, um, you should go there to join. Go to the website, sign up through the form, and you will get this whenever the podcast comes out. Yeah, while you're on the website, that's where you sign up for Slack.
I forgot to mention that. Yes, join Slack by clicking the link on the website. Uh, we'd also love it if you would rate the podcast and subscribe on your favorite podcatcher. You know, ratings on those things add some credibility to the show. Love it if you'd help us expand the reach on those things.
And while you're helping us expand reach, you could tell a friend, let it— let some other folks in the community know about what we're up to. And if you'd like to help us financially, we do have a Patreon campaign going on. You can also find information there on the website, colorado-security.com. Depending on the level that you sign up for, you will get some, some cool stuff as well as potentially a shout out on the show and other stuff like that. But thanks to all our patrons for supporting Colorado Equal Security.
Awesome. Let's jump into news. Uh, starting off, we, uh, now we've talked about this in the, in the past. Frankly, the news has been getting worse for Denver every year here. Um, you know, a couple years ago Denver was in the top handful of, of, uh, cities for the, um, best places to live.
And as of the 2023 version of this list, um, it's all the way down at like number 99. We've dropped a long way. Yeah, it, it's one of those things where I think, you know, we're starting to be hampered by our success, right? More and more people have come to Colorado, and the drawback to that is that it's really expensive to live here. And I think that is one of the largest reasons that we dropped so far.
Also, you know, there's a geographic problem, and that which causes some of the air pollution that we have here. That was one of the other reasons, I believe, that we dropped some air quality, especially with these fires over the last few years. It's not been as healthy here as it should be. And some something to get worked on, but I'd love to see, love to see more work done on that for sure. Yeah.
Um, we did still make the list because people want to live here and it's a great place to live, but, uh, obviously some negatives now too. You know what's interesting though is Boulder was way up near the top of the list. Yeah. And their cost of living is even higher. And, and, you know, I would imagine that their air quality is not significantly different, right?
Yeah. They, they didn't have a lot of the, you know, the juicy details here, but that one kind of stuck out to me too. Also Colorado Springs. Colorado Springs is on the list ahead of Denver also. Um, that one I guess makes a little bit more sense.
Colorado Springs is expensive, but not as expensive as Denver. So, but Boulder's more expensive, right? Like, right. Boulder's more expensive. And I would imagine that the air quality is just as bad in Boulder as it is here.
Interesting stuff. All right. Uh, moving on. Uh, some, some interesting news here. I'm, I'm interested to see how this goes.
Uh, 2 Coors Field bars are becoming the first to use biometrics in age identification. Yeah, so this is, this is them leveraging that Amazon product where you can use your palm, a palm reader to, to pay, number one, and number two, to validate your age. You know, they tried rolling this out at Red Rocks and it got shut down. Yeah, people, the artists complained against that, but they have already rolled this out at Amazon, like Whole Foods and other Amazon stores. It's been working successfully.
Mostly when I've heard about people talking about doing this biometric for paying, I kind of shrug and go, yeah, why bother? But actually, this is a really interesting use case where I don't know about you, but when I go to a baseball game and if there's a line to buy a beer, I'm just not going to get a beer, right? I'm not going to go miss an inning and a half of the game to do it. And if this makes it like, which it sounds like it does, you can just go in, get the thing and walk out. Right.
Like that really changes the game. Yeah. So, you know, Amazon has their, um, grab and go stores in various places where you walk in, you pick what you want, you, you do, um, your automatic checkout on the way out. And some of those are, as you mentioned, are using this, uh, this biometric to do the paying. Um, and it's, I believe it is the same way at these places in Coors Field now.
So you just walk in, grab your beer, swipe your hand over the, the reader and, and you're gone. What I'm interested to see is if there is any pushback against the biometrics itself. Obviously, it's a little bit different than Red Rocks in that there's not a group of performers that could potentially, you know, give pushback against this. But I would still think if there was that much pushback from artists that there might be pushback from other people. But who knows?
I think that the point though is it's all optional. You know, you don't have to use biometrics ever. You can just do it the other way. It was optional at Red Rocks too. So yeah.
Yeah, yeah, it, it, it— I, I, I think it's interesting. I can see the other side of the story where, you know, this looks like one step along the way toward being tracked everywhere you go, but you got a credit card in the po— in your pocket and a cell phone in your pocket that's tracking you. Like, yeah, is this, is this a significant step or not? I don't know. I don't know.
Yeah, anyway, all right, uh, next story we have, it's a follow-up. Um, we've, we've talked about Fluid Trucks, I'd say handful of times on the show over, over the last couple years. Um, they're They're a truck rental company, and and they have just recently entered into a a deal with Lyft to help electrify Lyft's pickup services. Yeah, so Lyft is going to be using fluid vans, electric vans, as part of the process to go around and pick up scooters and bikes for charging. And I don't know.
I guess I don't know what they officially call restocking. I guess wherever they they need to go back to once they're charged. Um, and this is, uh, an aim that Lyft has to become, uh, you know, more carbon neutral as part of their services in general. And it sounds like instead of them doing it themselves, it was much easier just to sort of outsource this to Fluid. And, uh, sounds like a win for both.
Yeah, it looks like they're gonna— they've agreed to replacing 20% of the pickup vehicles in Denver with Fluid trucks. Uh, it doesn't sound like it's not just Denver they're doing this, but don't Denver's the only place they gave us a specific percentage for. Uh, you know, what was interesting to me is I thought that part of the, the business model for these companies, these scooter companies, was that a guy like you or me could sign up to be a recharger for them, right, who drives around and picks things up. And if that was the case, then obviously I don't know how they'd even give the vans, right? Like, I'm not sure how this works exactly.
It's just an interesting idea. Yeah, I wonder if that has gone by the wayside. Um, you know, it's great if that actually works, but if people aren't consistent about it and it doesn't actually happen, then, uh, then maybe— I don't know, maybe they're not doing that anymore. But I do remember that as well, that at least early on that was part of the, the appeals. Um, you know, you could sort of do a side job as picking these things up and charging them and putting them back.
Gig economy thing. Yeah, like an Uber driver type. Um, a couple other interesting stats from the article: Lyft is licensed to a fleet of 2,930 scooters and 586 e-bikes here in Denver. So I mean, 3,000 scooters, 600, um, uh, e-bikes around, and they're only one— they're one of the two, right? The other one is Lime, right?
So, you know, I imagine that what I'm hearing is there's probably, you know, 6,000 of those scooters around town, which makes sense. I see them all over the place. Yeah, that's a big number though. They also say that, uh, they— the people in Denver average 8,400 trips on— I think that's on the scooters and e-bikes combined. So you're talking a little bit more than 2 trips per device per day.
I, I don't know how that works out, uh, from an economics perspective, but I found those stats to be interesting. I found one other interesting thing about this article, Alex. Uh, the Denver Business Journal apparently no longer edits their articles. I don't know if you read this, but like, did, uh, did ChatGPT write this article? Well, like, the— I mean, did Just, there was like obvious typos and stuff that like, come on now.
Yeah. Anyway, we pay a subscription to have access to this. We do pay a subscription. High quality editing. Uh, get some more editors.
Uh, anyway. All right. Moving on next. Uh, some sad news. Uh, Guild Education has announced a round of layoffs and they are eliminating 172 jobs, uh, from their workforce, which is, it was a decent percentage.
Yeah. I think they said it was, oh, 12% of the, the workforce. This, it says there's, there's 1,400 workers and, and I haven't done the math to figure out if that's post or pre layoff, but 1,400 workers, 172 laid off. That's, that's a, a significant portion that, you know, people are gonna feel. Yeah.
Yeah. And it's sad. Um, I believe this is the first time they've had to do a layoff. Um, but you know, we've talked about Guild a number of times and they've been growing rapidly. So, uh, just like everybody else who has been doing layoffs recently, it's, not surprising given the, the current economic climate that, yeah, that maybe they had to pull back a little bit.
And I think it's just worth reiterating for folks who, who don't have a lot of visibility here, it doesn't necessarily mean that they're not performing well. The valuations on these companies were so much higher a year ago that companies were raising money in order to fuel growth that assumed a certain multiple. Like, it only makes sense for us to, to hire these people because they're going to help us grow at, you know, 10x our revenue or 15x our revenue. When that multiple comes down, those— the investment no longer makes sense to, to hire that many people because you're just not going to get the money back out. So Guild may very well still be growing and still be successful on every metric that matters, but the, the macroeconomics mean they have to pull back or they won't be able to raise money next time.
So I don't know that that's the case with Guild. I just know that that's many other companies that have had that statement. Same situation. And, and we shouldn't necessarily assume things are going poorly there, just that they've, uh, that they know the macroeconomics have affected them as well. Yeah.
And it's too bad. Hopefully the, the folks that were there, uh, land well. I did, I've seen some LinkedIn posts and things like that. So I suppose if you are hiring, it sounds like there are some good people that are available. Um, there was another, we don't have it in the show notes, but we, there was another Guild story this month.
Uh, they actually have changed their name. They're no longer Guild Education. They're now just called Guild. Guild. And I think to broaden their, you know, the kind of perception and the brand of the company.
Yeah. All right. Next, speaking of ChatGPT making news articles, we have an article here about how 4 Colorado companies are innovating using generative AI. Yeah. You know, I don't know that— I think I'd heard of one of these 4 companies before, but why don't we just quick go through them?
I found them all relatively interesting and different what they do. The first one is called Farmers Business Network. They're an agricultural tech company up in Brighton. They launched an AI assistant called Norm, which is named after the guy who apparently revolutionized crop productivity. And it will help farmers figure out things like when to plant, what kind of— what they need to know about soil, weather, animal health, all kinds of stuff that apparently, you know, now AI can do for you.
Yeah. The next one was a company called Quantiv, which I don't think I had heard of before. But they make software that helps you track your OKRs, which, if you don't know, are objectives and key results. And they— goals, your goals. Yes.
Things that you're trying to accomplish and how you're accomplishing them. They, they added AI capabilities into their tool. And I don't know, it's a little squishy in the article about what exactly it is doing. But I'm, I'm assuming here that it's helping you you know, make better OKRs and that sort of thing. Determine what are the OKRs that will help your business be successful.
Yeah. Maybe even give you suggestions on what the key results should be from an objective you came up with. Things like that. Yeah, it makes sense. The third one is one I definitely had heard of, Valiant AI.
We've actually talked about them on the show a couple of times. They do— they've been doing AI assistance for restaurant drive-thrus. And I think we talked about like the first one they did here in town. Apparently they have now upgraded their AI with the use of a language learning model. That basically to speed up how quickly they can be onboarded.
Previously, it used to take somewhere between 4 to 8 months for a restaurant to onboard the AI, which is an awfully long time. And now this reduces it down to 4 weeks. And the last one we have is a company called Veritone, which I don't believe I was familiar with. I'm glad you got this one because I have no idea what they do with this. Yeah, I was a little— they don't really talk about what the exactly what the company does, and they don't talk about exactly what the AI is doing.
But they say that they work with people like ESPN, NCAA, FedEx, Oracle, etc. But it seems like it's a multimedia kind of application. And they, they do say that instead of their technologists just analyzing data that is coming in from their customers, now they can use generative AI to help create new data. Yeah. Uh, one of the things that they mentioned on here was, um, for the sports pieces to do AI-powered sports commentary and play-by-play, which I thought was interesting.
Right. Yeah. I can have my, my rec league volleyball team have AI commentary for us as it goes. So I, I'll be interested to, uh, to listen to one when the, um, when the chatbot, uh, hallucinates and starts saying things that are clearly not happening. Right.
That's good stuff. Okay, uh, next we have— moving over to the security companies in town— we have a new release from Red Canary. Uh, Red Canary has released a new product. It's called the Readiness Exercises. Alex, you want to talk about it?
You want me to talk about it? Yeah, go ahead. Readiness Exercises is Red Canary's, um, basically kind of a cross between a pen test and a tabletop, kind of purple teaming type of a platform where they will find really discrete attack techniques to help you run against your environment and use their platform to, to discover, did you detect it? How do you respond to it? And then you get like the tabletop element of it as well.
All right, do you have to pull some logs? Who do you, who do you talk to for communication? Really getting the full breadth of what do you do about really discrete attacks out in the wild. Yeah, it's, it's such a great idea. Um, that, you know, training for an incident response is so important.
And tabletops are wonderful, but they can only go so far. And, uh, you know, I've, I've had to design these things in the past and, you know, you want to get more and more in-depth and interactive, but it takes a lot of work if you really want to do that. So having a provider that can do this for you, um, is super important. And, uh, Red Canary already having, you know, Atomic Red Team and other things like that where you can do some of that actual testing and, you know, generate real data that you can act on. Um, I think it makes it a perfect marriage.
Yeah, and it's, it's great because they, you know, in general in life, one of the, one of the things that makes you better is if you go from doing one big thing to doing that thing spread out more times over, over time. And, you know, that's pen testing and, and it's AppSec review— reviews, excuse me. But it's also these, uh, these, these business continuity tests, which, you know, maybe you spend a whole bunch of time doing it and you only do it once a year because it's a pain in the butt, right? Here, this is going to make it really bite-sized where you can do it and, you know, like Tabletop Tuesdays or whatever, you know, every week you get a little bit of exercise over lunches, um, and, and with very little effort to make it happen, you can continually get people better and improve and not have to put all that upfront work into it. Yeah.
All right, uh, moving on, uh, next blog we have something for Ping Identity. It's called Breaking Chains: Blockchain and Sidechains in the Age of Decentralized Identity. Rob, there's a lot of words there. Yeah. Uh, You know, we love to— we love these blogs that, you know, give a nice tutorial on something that maybe you hear as buzzwords.
And decentralized identity is a thing that's here today, and it's going to be much bigger in the future. I really do believe that. This goes into describing what decentralized identity is and how distributed ledger technologies, which, you know, blockchain is the best known, and sometimes people just use blockchain as a cover-all for, you know, for things like Ethereum, but just distributed ledgers and decentralized identities aren't necessarily the same thing. You don't need to use distributed ledgers to do decentralized identity. However, like most of the time, that's how it's going, right?
That's partially because there's nothing in this entire world that only blockchain can do, right? Like there's always another option. Anyway, it's just a question of who you trust. Exactly. Yeah.
And I think, you know, you and I were talking about this before, before we started recording. They do talk about sidechains in here. Well, stepping back from that a little bit, most of the stuff they talk about in here is things that we have probably heard of before. They talk about PKI, they talk about distributed ledgers and blockchain and a little bit about decentralized identity. But I don't think either of us had really heard of sidechains before.
But it's essentially a separate blockchain that is related to the main blockchain. They're connected but different. And used for things like scalability and other things like that. Speed of processing. If the main blockchain takes too long to get everywhere, you can do a little sidechain where you can get through it much faster.
You could have a sidechain that's controlled by one company so they're able to get like their identity verification done through it. I assume Ping probably does this now, which is probably why they mentioned it. But, but, you know, this gives you the ability to have it connected to the blockchain and usable on the blockchain without having to have some of the overhead of the blockchain. Right. Yeah.
You know, you have that one customer that wants theirs to go faster than everybody else. You can use your, your sidechain to help them out. Yeah. Good stuff from, from Ping Identity. Uh, next we have a blog post from LogRhythm, another kind of intro-ish one about zero trust.
And, and this is, you know, LogRhythm as, you know, not necessarily a zero trust company talking about, hey, there's no such thing as a zero trust company. You're not going to buy zero trust You know, there's no— there's a stamp of approval that you get on your product because it's zero trust. And, um, they're going through to describe what are the steps in order for you to, to think about architecting in a zero trust way, and what do you need from your products as a result of that. Yeah. And, um, and I think some of it is the, you know, internally, I know, um, LogRhythm spent a lot of time making their own systems, uh, you know, in a zero trust way.
So I think some of this is probably related to that as well. But, um, you know, a good sort of basic primer on, on zero trust and how you might start on your zero trust journey. Good stuff. All right, uh, last news item for today. This is a blog from Optiv, um, and, you know, we don't often actually get Optiv blogs in here, um, so good to see something from them, uh, talking about privacy concerns and that they're not just for big companies anymore.
And, uh, really this is talking about the FTC guidance that came out a couple years ago around the standards for safeguarding customer information and some changes to that, basically broadening the scope of who this applies to. Yeah. I know that FTC safeguards— I think officially, the FTC has the ability to regulate any company that is not regulated by another regulator. Right. So I think they can get literally anyone.
Generally, they have— their safeguards had only been applied to some larger companies, some higher-risk industries, but it sounds like they've really broadened this out, and just about everyone maybe now has some expectations from the FTC. Yeah, they do note in here that if you are already subject to things like GLBA, SEC regulations for stockbrokers, and NCUA for credit unions, you are exempt from this. Because you're already regulated by those. But there's many other different industries that now fall under the— specifically under the safeguard rules, including travel agencies, mortgage lenders, payday lenders, colleges and universities. I mean, that's a big one.
Wire transfers, collection agencies. A lot of financial firms are in this list that were not specifically covered by one of the financial regulations previously. Good stuff. If you're interested in understanding how this might impact you, take a look at this this blog from, from Optif. Before we jump over to events, um, we, we should have, we should have talked about it before we started recording.
We have a picnic that we want to do. Oh yes, we want to get it. We don't have a date set yet, but I think over the next week or so we probably will get that date set up. And we would love to have you guys join us out there, probably a Saturday morning in August. I think that's what we're thinking about.
Um, so, so look for that in the Slack channel. Uh, we'll talk about it next month on the show, but that's a ways off. That's a month away. So in the meantime, take a look on Slack. Yeah.
And, you know, Rob is saying this because it's on my to-do list to figure out the date. And so it's his gentle reminder to me that I need to actually get out there and figure this date out.
We'll get that out on the website here soon. All right. Speaking of events on the website, we do have a calendar of events. If you want to go to colorado-security.com, see all the stuff coming up. There's not a lot going on here in June, but there's a few events.
Yeah. I think there's a lot of vacations going on, which is why there's probably not a lot of events. First, on the 14th of June, Lyft is doing a Splunk Game Fest. Come play all your favorite games. Is that what that says?
Oh, oh, one, one, why? I don't know. I don't know. Anyway, let's talk software security has an event on the 23rd. Software security training and education.
Then on the 28th, there are two events. ISC2 Pikes Peak is doing their June meeting. And Lyft is also doing a mentorship hike. That sounds fun. Lyft is carrying the weight for events this month.
Yeah, we— let's talk about jobs now. Some jobs are available here coming up. What's it called? Oh, I can't read it from here. Legend.
Legend Technology is hiring a director of cybersecurity. S&P Global is looking for an associate director of security automation. Oh, that sounds fun. U.S. Bank is hiring a senior technology risk manager, corporate and wealth management technology. Longest title of the week, you think?
I'm going to guess that wins. Visa is looking for a senior cybersecurity engineer for applied cryptography. Western Union is hiring a senior information security engineer. RTD is looking for a manager of security operations— cybersecurity operations, sorry. Dish Network is hiring an information security risk and compliance manager.
Stripe is looking for a program manager for security risk management. Paylocity is hiring a Director of Information Security Operations. And Plant Moran is looking for a Managed IT Consultant, entry-level. Yeah, entry-level position. We— I always try and add entry-level when I can.
Not a lot of them popped up this month, but there's one. There's one at least. All right. We do have an interview this, this month. Big thanks to Janelle Hsia, who sat down with Chelsea Kelleher.
Chelsea is an attorney who helped Work on the Colorado Privacy Act, and is now at Michael Best, right? Yeah, yeah. She was previously at the Attorney General's office and now works in the the private sector in at Michael Best, and so interested to hear about privacy stuff. Awesome. Well, that's it for the news.
Stick around for the interview, and we'll look forward to talking to you guys on Slack pretty soon. Thanks, Rob. This is Rob Winter, Chief Information Security Officer at Boulder Community Health. Welcome to Colorado Equals Security, for Colorado security professionals by Colorado security professionals.
Welcome to Colorado Equals Security. This is Janelle Hsia. Today I'm excited to interview Chelsea Kelleher. I hope you enjoy our conversation. Chelsea is the associate attorney at the law firm Michael Best.
Hi Chelsea, welcome to the podcast. Hi Janelle, thanks for having me. So some information that we're going to be talking about today might be time sensitive. So I want to make a note that today is a beautiful sunny day in the first week of May, and we're at the end of the work week. So how was your day so far?
Doing good. Busy, but good. Privacy is very busy, and we'll talk about that for sure today. Well, before we start, tell us a little bit about yourself. Sure.
So I'm originally from the Houston area. I went to college in San Diego with, you know, my undergrad in political science, which is kind of what you do before going to law school. And then I served 3 years in the Peace Corps. I served in a very small country in Africa called Lesotho. And after finishing my service there, I moved to Denver in 2015 and worked in the nonprofit sector before going to law school and then spending some time at the Colorado Attorney General's Office before transitioning to Michael Best.
Um, but I love privacy, um, fell in love with it in law school, and very, very fortunate to practice in this area now. Um, so tell us a little bit about your current company, Michael Best. Sure. So we are an AM Law 200 firm. We're based in Wisconsin.
Uh, we just opened up a new office in Denver this year, so we're really excited about that. But we also have another office in Broomfield, um, and our privacy team consists of 3 partners and 3 associates, including myself. We're based all over the US. And our practice is really dedicated to providing comprehensive privacy compliance services for any size business from startups to Fortune 500 companies. And we really pride ourselves on taking a practical implementation approach that's right for your company.
That is a practical implementation approach. I would say the exact same thing. Like, you know, make it Make it something that's sustainable for organizations. Well, you mentioned that you were with the AG's office. What did you do for the AG's office?
Yeah, so I had a 2-year stint there where I got to cut my teeth in privacy law as part of their fellowship program. And I am such an advocate for this program. They have different streams, so you can be really focused on privacy or other areas of law like environmental law, but they also have general practices as well. And what I did was very much centered in privacy, and my time was broken up between the Consumer Protection Section, where I aided in our enforcement practices under the data security and breach notification laws. And then part of my time was also served with State Services, and that was being counsel to our state agencies on any, you know, questions or concerns or compliance initiatives surrounding privacy and security under usually state laws or federal regulations applying to those agencies.
And then another part of what I did that was really cool and unique to the office is participating in the Data Privacy and Security Impact Team, which was an initiative started by Chief Deputy Attorney General Natalie Hanlon-Leh, and it's a cross-section of attorneys and support staff from across the office. And we got together on just really cool, um, civic-minded initiatives that are rooted in privacy and cybersecurity. And so getting to participate in some really unique activities there too. That's amazing. And, you know, I think that that kind of why I wanted to talk with you, because you really blend that cybersecurity and privacy components.
Um, and at last year's RMISC, you were on the big stage talking about Colorado's security and data privacy laws. Did that affect how you want to talk and educate the public about CPA? Um, actually not really, because the Consumer Protection Section at the AG's office, their mission is to educate the public on all of the laws that the section enforces, um, and how it protects consumers through its work. So, you know, it does this in several ways, like through, you know, guidance on the website, social media platforms, but a major component of that is speaking at conferences and webinars and things like that. So we had actually already done a number of presentations on both of our security laws and the Colorado Privacy Act leading up to the RMISC last year.
But we chose not to focus on the CPA during that particular discussion because we were part of— we were in our rulemaking process. And so we wanted to honor that process and comply with it. And so we kind of focused our presentation on our security laws during that time. But really, it was just lockstep with, um, you know, the practice that we were already doing to get out into the community. And that's one of the things I love about our AG's office is that I do feel like they are very pro-cybersecurity and pro-privacy.
Um, and that, you know, it's exciting that we're the 3rd state in the United States to have published or to have pass privacy laws. So, you know, kudos to us. Yeah, definitely. Yeah. Well, let's dive into CPA because I think people are going to be very interested to what you know.
And I kind of want to just start with the definitions. So definitions are a big part of all of the regulations. Are there any definitions in CPA that you think organizations will have a difficult time understanding or that are, that are sort of unique to our regulation, our law? Absolutely. So, um, before kind of diving in there, I did want to preference that, um, I worked on the Colorado Privacy Act, um, when it was passing, going through the legislature, um, and then also helping to set up our rulemaking process at the AG's office.
I think I failed to mention that earlier, so maybe your, um, uh, listeners are like, why are you asking her about these questions? But that's why. But yes, happy to discuss the definitions in the act. I think they are really unique, especially Colorado being only the 3rd state to pass this kind of law. And so the first one that I'd like to talk about is profiling.
And really what we're talking about there is automated decision-making. And a lot of people actually think that there aren't any laws regulating AI or machine learning, but that's really— that's false because a lot of these state privacy laws that touch on profiling are talking about AI. They're talking about automated decision-making. And so what profiling means in the context of the CPA is really automated decision-making that's meant to make decisions about a person or inferences about a person that have legally or similarly significant effects. And so What are we talking about when we say that?
And that really means decisions around people's, you know, really important points in a person's life, like their creditworthiness. So if they apply for a mortgage and a bank is using an AI-driven program to decide whether to give that loan to that person or what interest rate they're going to give to that person, that would be something that would fall under the act. Another thing could be whether an applicant is going to be a successful employee or are they nice to work with? You know, we're seeing a lot of these AI-driven technologies in the job market. And so those are the kinds of really big decisions that we're talking about when we talk about profiling in the CPA.
And then of course there are, you know, with the regulations coming out, there's additional restrictions and obligations based on the level of human involvement in this kind of processing that's going on. And this also impacts in particular the data processing assessments that companies that, you know, undergo this kind of processing are going to have to do. So there's 3 different tiers. One is solely automated processing. One is human-reviewed automated processing where there's, you know, the human is probably looking at the result of the processing and they can either, you know, go with the recommendation or go against the recommendation that the software recommended.
Or there's also human-involved automated processing. And so this is the highest level of human involvement during this profiling process to where the human understands and is trained on the software. They can interject in the software and they can— they have a whole lot of autonomy about whether to go with that software's recommendation or not. And That's really important because companies can actually deny consumers opt-out requests to opt out of this kind of profiling. So these kinds of tiers actually make a big difference.
I'd like to also talk about dark patterns. And a lot of businesses that I'm finding actually aren't— they're not aware of this concept. This is a new concept for them. This concept has has been around for quite a while though, but within the CPA, it comes into play when a controller is trying to obtain consent from a consumer. But you also see it in other ways too, like when they're trying to compel a particular action from a consumer, like to buy a certain product or to click on a certain ad, for example.
And, you know, companies usually aren't aware of this concept because they're going with whatever design is preloaded into their website. Software or their mobile application design without realizing, you know, what this design is actually doing to subvert, you know, consumer choice. And, you know, a lot of the thinking around this concept has developed in the recent years. I think that not only are state laws deciding to really grapple with it, but also the FTC has been really active in this space. I'm sure you're familiar with their September 2022 report, Bringing Dark Patterns to Light, which if anyone's looking for more information on this stuff, that is a great place to start.
It really categorizes all the different types of dark patterns. So companies can't really, or regulators can't really do the, you know, you'll know it when you see it kind of thing. There really are a lot of boundaries set up around this kind of concept now, which has been really interesting to watch over the past couple of years. And then finally, I'd like to talk a little bit about sensitive data inferences. And this comes into play when businesses use personal data to infer or extrapolate information or characteristics about a person, and that inference amounts to sensitive data.
So you, like for, you know, Google Maps, for example, could be following a person to a healthcare center, and then they are going to infer that that person's, you know, health is compromised, or maybe they're pregnant, and then they use that data to infer targeted advertising on that person. And so that's kind of what we're talking about when we're talking about inferences that amount to sensitive data. The tracking of that person's geolocation, if it's general, is not sensitive information, but can amount to sensitive information if you're using that to infer something about that person.
And that's going to go into play when profiling consumers, but also using targeted advertising as well. Wow, that was a lot. And I wish I had time to unpack each of those because I think that's totally— Agreed. But I do want to ask about the sensitive inferences because that was actually one of my follow-up questions because I know that there's this definition of revealing. And you mentioned, you know, while precise geolocation information at a high level may not be considered sensitive, precise geolocation which is used to infer.
But I noticed that in the sensitive data definition, precise geolocation isn't listed there. Do you think that's an oversight? That possibly could be. Yeah, well, I'm not sure. I would have to look into that.
But I know— yeah, the only reason I noticed, Chelsea, was because I was looking at some of the other— I'm doing a sensitive data document, like a dictionary, and I was like, precise geolocation is in all the rest of the regulations that I've seen so far from the states. And I was like, Colorado, come on, I'm sure that it's in there. And then I was like, well, it's under the revealing definition. Um, so anyways, um, I just think there— that may be one of those that is not necessarily called out in sensitive data, but I, I totally, as I was reading this, I would say that that precise geolocation, um, is considered sensitive. So, and as of today, and I keep saying that because I know that there's a couple states that are looking to pass regulation or that have passed and they're looking to have the governor sign any day now.
And I haven't even read the— what's passed lately. Iowa and Indiana, is that right? Yeah. And Montana and Tennessee as well. Right.
And so I'm, you know, I'm like, as of what I can remember from the 5 that we have. But so part of that too is so CPA is the only US regulation that applies to nonprofits. So can you talk a little bit about why Colorado decided to include nonprofits? Yeah, sure. So this actually had a lot to do with, um, Senator Rodriguez, who was one of the bill sponsors, and he kind of stands by this in saying if you collect this kind of information, then you need to be a good steward of that information.
Um, and when the bill was written, it included nonprofits as well as government agencies, and I think a lot of You know, lobbying efforts, you know, were able to redact the government agencies part of it. But apparently the senator didn't see a whole lot of pushback when they were including nonprofits. Maybe nonprofits just weren't aware that they were included in this act at the time. But he also said, you know, people who pointed it out didn't really offer a whole lot of solutions or alternatives. To, you know, kind of meet in the middle.
And so they just kind of kept it in. But also, I think that you just saw kind of the larger conversation that society is having right now. I think the Blackbaud data breach kind of put a spotlight, for better or for worse, on nonprofits and kind of alerted the privacy and security community as well as consumers to some of the information that nonprofits collect about them. Um, you know, for example, a lot of nonprofits collect very detailed information about their donors, like where their children go to school, whether they're going through a divorce, their medical information. Um, and so a lot of really sensitive, um, and sometimes embarrassing information.
And then I also think that, you know, really equity comes into play here because nonprofits often serve the most vulnerable of our communities in achieving their missions. And so, um, I think not only is it really, you know, important for nonprofits to protect donor information, but for an equity sake, I think it's also really important to point out that, you know, just because someone's underprivileged doesn't mean that they also have privacy rights. And so I think nonprofits are an important part of that discussion. No, I completely agree. And, you know, looking globally at privacy regulation, you know, from my understanding, you know, globally nonprofits are generally in scope.
I think it's just in the United States that we kind of scope them out or exclude them. Agreed. Yeah. Yeah. Yeah.
So one of the other things that is a little bit unique about the CPA is this universal opt-out mechanism. Can you give us a little bit more information on that? Like, how did that come about? And, you know, we— most people know about the GPC, the Global Privacy Control. Maybe a little compare contrast and help our listeners understand from a technical perspective some of the things that they have to do.
Sure. So the Universal Opt-Out Mechanism or UOOM or OOM, trying to find ways to shorten this acronym, is a— it's mainly thought of as a digital tool, and it's meant to communicate a consumer's wish to opt out of certain processing activities as allowed under the Act. And this should be able to be broadcasted to all controllers or businesses that fall under the CPA when a user visits their website or interacts with their mobile app. The activities that fall under the OM include targeted advertising and the sale of personal information. And so the reason behind having the UOM included or the OM included in the CPA is to ease the burden on consumers when trying to effectuate their opt-out choices.
And this is because we're just living in this opt-out framework, not only in Colorado but throughout the US. And so if we didn't have the OM, we would be saying, hey, consumer, in the thousands of businesses that you interact with online on a daily or weekly basis, you actually have to go to their privacy policy, find the web form or whatever process that company uses, and submit your opt-out request. And we can just imagine that consumers would say, This is so burdensome, I'm never going to take the time to do this. So having this kind of mechanism is a way to shortcut that and ease some of that burden.
And what's kind of unique about the OM under the CPA is that it can be a browser signal or it can be some other kind of tool. There was one business that submitted some comments during the rulemaking process that said, hey, you know, I think that our tool could fit the OHM framework, and they kind of had a do not sell list, like under the TCPA kind of tool where the business would constantly ping this list. And so we could see something like that, like the, the Colorado Attorney General's Office saying, hey, this also fits the framework. So it's not constrained to just browser signals. In contrast, California's law recognizes these global opt-out signals, and they've really broadcasted that the global privacy control or GPC fits the requirements under California's law's framework.
And so this signal is also, you know, constricted to usually a browser signal or a signal sent through someone's browser or device. And it also doesn't really apply to targeted advertising. For example, if a business just did profiling and targeted advertising in-house. However, if they shared or sold that information with a business partner, then that kind of activity would come into play. And that's usually what we see when we see targeted advertising.
It's a retailer that is, you know, using Google Ads, for example, to do targeted advertising for their customers or other consumers that would be interested in their products. So even though there's these slight differences, I do think that they, at least for right now, are— could, because the OHM isn't operationalized yet until next year, They're mainly operating very similarly. But there are some of that distinction that we might see be teased out in the future. Yeah, and you said so many words in there. I wish we had time to go into like what is the definition of a sale of data and targeted advertising versus ad tracking and profiling and retargeting.
But I will just ask one question on the OHM and then we'll wrap this section up. So it's not on by default. So can you talk a little bit about the difference between like when something's by default and then when it has to be configured? Because I think from a personal perspective, like that's going to be important for consumers to understand how to actually execute the signal. Absolutely.
So what's unique also about the OHM is that it has to signify consumers of affirmative choice to opt out. So that means that the consumer has to take an action in order to effectuate the OM. And so that would mean that the— and we see this in the regulations— is that the OM would be effectuated if maybe a consumer included a browser plugin or if they downloaded a a browser that has been marketed as privacy protective and sending this kind of GPC signal like DuckDuckGo, Brave. There's several of those on the market. However, if maybe if you're setting up a new phone and it comes with a browser that has this signal implemented by default, that would not be compliant with the CPA regulations.
However, in the same scenario, if you've got a new phone as part of that setup process, they're saying, hey, you know, do you want us to download your contacts from your previous phone? And, you know, hey, set up your email. And also we have this privacy signal that you can enable on the browser that comes with your phone. Click yes here. And then, you know, if the user decides to enable that, that Signal on their device, then that would be privacy compliant.
So you just can't have this, you know, Microsoft Edge or something that comes pre-downloaded on a device and has the Signal already in effect. The consumer has to take some sort of action to download the browser or the Signal or to enable it on their device. Yeah, so it sounds like a little bit of the difference is if you have to, like you were talking about DuckDuckGo or Brave, those are things that you install install by choice. But if there's an operating system or an app that you have no, no choice on when you get a new device, then that has to be configured. Absolutely.
And then there's also this separate explanation in the requirement— in the regulations that kind of differentiates browsers that are specifically marketed as privacy protective, like DuckDuckGo, Brave, etc., and you know, some other browsers like Microsoft Edge, like Firefox that do a multiple multitude of different things that might draw a consumer to download or use that browser in addition to your ability to enable this kind of signal. So then I guess we're going to have to hope that Brave never becomes preinstalled on our devices.
Exactly. No, so that's actually one area from a technical perspective I'm super interested in watching how that rolls out over the next couple of years and seeing if, you know, like 90% of the people turn on the, you know, on Firefox, they turn it on, then maybe by default will be okay in a couple of years. Yeah, absolutely. But we'll definitely see. I, again, you and I, I think we could spend the next hour talking about this, that, but that's That's awesome.
Any piece of the CPA that I didn't ask you about that you want to, you know, let the audience know about? Um, I think in the interest of time, um, I, I won't mention anything. Um, but there's so many different things that we could be, um, talking about. We could do, you know, organization of privacy policies, protections for children. Um, there's a lot to unpack here.
Um, as, as you can see how quickly our conversation went by. But, but for now, I think we'll save that for a later date. Yeah. And let me just— I did print out the rules, the 47 pages, just so the audience knows, 47 pages. So happy reading with that.
It's hefty. It is very hefty. As we wrap up, I usually ask, what do you do for self-care? How do you make sure that in the crazy world that we're in that, you know, your mental health stays in a good position? Um, I think that is such an important question, Janelle.
Thank you so much for asking that and calling that out today. Um, as a Coloradan, um, pretty generic answer, I try to get outside, um, and enjoy the mountains. Um, whether, you know, it's snow or sun, um, often you can find me hiking out there for sure. That's definitely my, my zen moment. That's awesome.
And then I— sometimes we talk about giving back to community as well. Are you doing anything that you want to highlight or draw attention to? Any particular associations or anything that you're passionate about outside of work? Absolutely. So the homelessness situation in the Denver metro area is definitely something that pulls on my heartstrings.
I worked for a nonprofit that really focused on this community out in Aurora along Colfax, mainly families living in motels and other transient housing. This issue has been really important to me for a long time, and I would just like to give a shout out to the Colorado Coalition for the Homeless, as well as the Action Center in Jefferson County. I think they're doing really great work in this space, although there are numerous organizations that, that do really important work, and I think it's really great for, for those who feel the need to get involved here because it's very, it's very important. Thank you. No, I would agree.
It definitely tugs at my heartstrings as well. So, well, where can people find you? Well, I think you can just Google my name and my contact information will pop up on Michael Best's website. And feel free, any listener, to reach out. Happy to connect on these topics.
Well, thank you so much. I know our audience is going to very much appreciate all of this information before CPA comes into effect at the beginning of July. Um, so thank you so much. Thank you so much for having me. All right guys, that's it for today.
Uh, thank you for listening to Colorado Equals Security.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Rob by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.