Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is your newscast for episode 261, April 8th. We're in, uh, Q2.
Yes, we are. Robb, it's almost my birthday too. Another year around the sun. Everyone every year is looking forward to April 15th. They're thinking, man, what a great day.
I can't believe you just spilled my PII on the internet, Robb. And your Social Security number is 123456789.
That's— so we get your birthday month. Spring has sprung, although today is not We're, we're recording on Saturday. Today is not quite as great, but the rest of this week was unbelievable. Yeah. Uh, today it's supposed to be a little windy.
Um, I know that they, uh, they've canceled some things around town, like potentially 100-mile-an-hour winds. That's, that's a little windy. I, I tried to play pickleball yesterday afternoon in the beautiful, whatever it was, 70-degree weather. And yeah, well, I didn't try to, I did play. And, but the ball just, you know, you know, if you played pickleball, like these little wiffle balls, they just like stop when the wind.
So it makes some for some great drop shots when the ball starts going backwards away from the person. So Robb, is this your, uh, you telling the truth that you're just not good at pickleball? Is that what you're saying? I did still win. We would have been like, really put it on the table.
I did still win. All right. All right. All right. Uh, hey, uh, we probably have some announcements and some things, uh, admin stuff to talk about.
Yeah. You know, let's, let's jump into things like our Slack channel where we have, uh, thousands, literally thousands of security people in Colorado who get together and talk about things. Just this week, I made a couple of different requests from the group and got some great insight. I was looking for an audit partner, and some folks had made some suggestions there. So, great group.
If you want to join the Slack community, go out to colorado-security.com and click on the Slack button, and you can get in there. While you're there, join our mailing list. You can get an email with the show notes sent to you when we have a new podcast. We periodically send some other things like volunteer opportunities and other stuff like that, but it's not a spam list or ads or any of that kind of stuff. So we'd love it for you to be on that list.
Also, we'd love for you to rate us and subscribe on your favorite podcast player. That way you get the podcast every month when it comes out and everybody knows how great a podcast it is. Yeah, I don't, I don't know like exactly what the ratings do other than make us feel good. Right. So there might be some actual benefit to it, but regardless, doubtful.
A very important thing is to give us warm fuzzies. Yeah. Also, you know, tell a friend, let them know about Colorado Equal Security. And if you want to support us financially, we do have a Patreon campaign that helps pay the bills. Web hosting, those sorts of things.
So check out the website for all of that stuff. And yeah, big thank you to our current patrons. You know that we have— we've had a great group for— what's it been, like 5 or 6 years that we've had the Patreon? We didn't start it right off the bat, but for years, a great group of folks who have been helping financially support us. Thank you so much to those who do that.
We really appreciate it. All right, let's jump into the news. All right. What do we got first? First story.
The historic Stanley Hotel is being sold and it's being sold in an interesting way. Robb, who's going to buy the hotel? Well, it depends. If you ask ChatGPT, they will tell you it's a private equity firm, but it's not. It's the state of Colorado.
And it's a little confusing, honestly, the structure of the purchase. There's a fund that's used for kind of some public good stuff, the Colorado Education and Cultural Facilities Authority. They're, they're going to take the ownership of this. And really what it looks like is this is going to keep the Stanley Hotel as a, as a tourist destination, as a place for education, as a place for us to go enjoy for generations to come. Yeah, it is interesting.
Originally there was an Arizona firm that was going to buy it and that the Colorado Educational Fund was, was originally going to put up the bonds to make that happen, but then the Arizona people backed out. And so now, uh, that fund is just buying it themselves. This is the, the first building that they're actually going to own. Uh, mostly they are the ones that put up bonds for various things like this just to, to make them happen. Um, but yeah, so they're actually going to use this sort of long-term to get some funding for, you know, additional opportunities like this to to get those bonds and save more historic buildings.
This story reminds me, reminds me a little bit of the Casa Bonita story in that there's a purchase price, which is $169 million. It's a lot of money, don't get me wrong. But there's a $450 million big price tag, most of which is going to general renovations and upgrades. They're going to be building a, a new film center at the Stanley Hotel, a $54 million film center. Apparently horror movie The Shining is a draw.
And so people want to come there. And learn about films, and it's going to be a good place to do that. Yeah, they'll be able to hold events there and other things like that. It sounds like they have one coming up where it's, you know, a bunch of directors are coming there to do an event. And so they'll be staying there and that kind of thing.
So it's going to be a tourist destination, will be a film destination. Pretty cool for Colorado. Good stuff. Moving to a completely different Colorado story. Boom Supersonic has announced the successful initial flight of the XB-1 demonstrator aircraft.
So Boom Supersonic, the local company that's looking to make supersonic air travel popular, great again. Yes. Is this— is this where we make it again? Right. Because we're not really doing it now.
Yeah. So we— they're— they have one of their— one of their planes and they've got it. They just recently— was it like last week, I think— had their first flight. Yeah. And so this was the first test flight of the test plane.
So this is not the version that will be the airliner. It's a much smaller version, single-person plane. Obviously, the airliner wouldn't make much sense to only fly one person at a time. So when they build that version, I think it's between 60 and 80 or something like that, people. But yeah, it took its first test flight.
It met all the criteria that they were trying to meet on that flight. One of those criteria was not getting to supersonic flight. It was really slow, wasn't it? It was only like 200 and something miles an hour, which is, I don't know, like 0.3. It's like as fast as 3 or something like that.
As fast as you drive when you're more or less getting over here. Yeah.
Maybe a little faster than that. I don't know. Something like that. But anyway, but pretty cool that they actually had a test flight, that they're on the way to supersonic flight here soon. It's a milestone.
It's nice to see that they're getting things done. You can't slideshow your way through a test flight. Right. Exactly. They've actually created something.
No Boeing here. The doors didn't fly off or any of that kind of stuff. Well, this is— this next one is our, you know, one in a long series of somewhat sad posts about losing Foundry Group and Techstars here in town. We mentioned, was it last month or 2 months ago, that Techstars is going to be leaving? Well, they just kicked off their final class of companies here with 5 local companies are going to be a part of it.
Yeah. And this is Techstars Boulder's 20th program. And as you said, the last— there are some Colorado companies here, and then some not from Colorado, but good, good crop of companies participating, including Denver-based Butterfly, spelled strangely, of course, how all company names are spelled these days, which is an engagement and announcement platform for product teams and end users.
There's one called Flight, also spelled strangely, which is a Denver-based private aircraft booking platform. Looks like if you want to get your company plane, that's what it does. Yeah. Also one sort of close to my heart based on my job, Maven Energy, which is an energy advisor company that's starting up some things there. Sounds like maybe a similar product to ones that Uplight offers.
A couple other here in Colorado. We've got IrisMed, which is a medical coding company, and Noli, which is an AI-driven knowledge engine, which doesn't tell us anything. No, doesn't say anything. But hey, who doesn't like AI and knowledge? But all these companies are going to get the chance to, to take advantage of this, this tech startup accelerator here in town for the last time.
And we're looking forward to seeing these companies kick ass. Speaking of startups or young companies, Robb, the Colorado InnoMadness, which we seem to talk about every year, Happens at the same time as, you know, March Madness basketball. This is sort of a bracket competition where people vote on which company I think basically that they'd rather invest in. That's kind of how they do it for, for deciding these things. And we are down, I believe, to the final 4 companies.
That's true. Just like, just like the NCAA men's tournament as of, as of now, tonight, it will not be. But interestingly, you know, I hadn't looked at the status, you know, since we talked about it coming. The first round saw the 2 security companies face each other. So, yeah, Total and Dapple Security with an upset with Dapple Security beating Total.
But in the— Dapple ended up going down in the second round. And our final 4, we've got 4 companies that I had never heard of. We've got BiteWell, which is around— it's like insights into your food and healthy eating, I believe. Magic School AI, which is an AI company helping teachers create content. Good— was it Goodbye Gear?
Shoot, I looked this up and I don't remember. Goodbye Gear. What do they do? I don't know. I'm trying to remember what they do, but it's also— they're an online— I don't remember now.
They're an online marketplace for used children's items where they like— they put— they take them in, they assess to make sure that they're safe to use and resell them. So you're getting a little bit higher value used kids stuff. And the last company is called Tilt, which is a workplace leave management platform. Oh, right. I remember we've talked about them in the past.
Yeah. So pretty cool stuff. And I believe you still have the opportunity to go out and vote. So if you, if you look at the link in the show notes, you can go vote on which 2 companies out of those 2 pairs you'd like to see move on. Once again, speaking of startups, we're going to talk a little bit about Ibotta.
Ibotta has been a local company for quite a while, and I'll tell you, I got my impression of what they do, whatever it was, 5 years ago, 6 years ago, and it hadn't updated. And apparently my impression of what they do needed to update. Yeah. So I've known Ibotta as the place where you install an app as a, as a consumer, you install an app on your phone, you scan your receipts because of whatever things you bought, you get some kind of perks, rewards, cashback type stuff. That is no longer the thing that's driving their business.
And because of their new line of business, which is B2B, they are actually had amazing growth. They became profitable and they're going to be going public here in the next couple quarters. Yeah, yeah, I think, uh, I think the new line is, is a B2B2C, right? Technically. But, uh, but yeah, I, I didn't know that either.
I just still thought of them as like coupon cashback kind of, um, business. But seems like they're going, uh, going gangbusters. This new line I think grew like 700% last year or something like that. So that's what's positioning them to, to go for this IPO. And what they're doing is they are the, the loyalty program behind Walmart and some other really big companies.
And you can imagine that if you're going to go land one consumer company to be, to be behind, it's probably Walmart that you want to be, right? Yeah. Walmart or Amazon. Those are the two that you would want. And Amazon probably less likely to do it.
They're probably doing it themselves, right? Yeah. Whatever it is. So, so they're, they're, they're looking, they became profitable this last year and they've grown in profit. They, I mean, honestly, their numbers are in this TechCrunch article are pretty impressive.
Yeah, they look like they're going to be a formidable company in the future. And, you know, congratulations to that whole team. Yeah. Look forward to the IPO actually happening. All right.
Next up, jumping into the security-specific stories, we have a blog from Red Canary talking about best practices for Azure Active Directory. Yeah, they do a top 8 things you should do, configurations you should change within Azure AD to make it more secure. Actually, it's not even Azure AD anymore. Now it's Entra ID, Robb. Yeah, you're right.
It seems a little out of date. And honestly, it's not even a recent change. It was like, like almost a year ago that they changed it. Well, it's such a dumb name. No one wants to use it.
I mean, not that Azure Active Directory is great, but at least everyone knows what Active Directory is. Allegedly dumb name. Allegedly. Allegedly. So the top 8 things to take a look at.
I'll say I went through this and I was surprised by some of the things on this list, and I immediately sent it over to my team and said, hey, could we make sure we go through this and and review to make sure we're, we're doing all these things. Yeah. And I— one nuance here is they show you what the default setting is in this blog post and then they show you what the risk of the default is. Basically, the point of this article in my mind is the defaults are not very secure, right? You might want to change the defaults for your, your Entra ID.
Yeah. Some of these, you know, the first one, restrict external collaboration to specified domains. That seems smart. Yeah, there's— I mean, I don't know if we need to go through all of them, but there was a couple like under default user permissions. Basically, by default, users are allowed to register any new application they want.
Basically, this becomes shadow IT, right? This is how you get that app sprawl. They just show, just turn that off and people have to make a request through IT to do it. Yeah. The other one that stuck out to me was limit access to the Microsoft Entra admin center, right?
Like, hey, that seems pretty smart. We don't want anyone getting to the admin center that shouldn't be there. Yeah, we might want to talk to Microsoft about adopting some of these different defaults. Exactly. Well, our next blog post is, uh, is around crafting a secure or successful vulnerability management process.
This is an Optiv blog, and it's actually the third of a 3-part series where they went through technology and people as a part of vulnerability management. And this last one is about process. I, I think process is the most important part of it, and they, you know, they go through a lot of different nuance here. Yeah. Um, and I don't want to say that there's any, anything, um, that, that doesn't, you know, there's a lot of stuff in here.
It doesn't surprise me, but it's all good stuff, right? You need to make sure that you are creating robust processes when you're doing this. The, you know, the challenge for me in vulnerability management is always actually, uh, the sort of the last mile part of the process. It's easy to, I don't want to say easy, but easier to, uh, to find stuff, but it's, it's always harder to get things actually fixed. So, making sure you have a good process in place to, to close that loop on your vulnerability managements.
Good stuff. Well, next we have a blog post from LogRhythm going through the key components of a robust cloud security maturity strategy. I feel like that's a lot of words, but the way I look at this is, is how do you look at your, your corporate cloud security posture and, and figure out how you go from where you are to something that you're more comfortable with? They give us a nice framework for how to do that. Yeah.
Um, again, this is, uh, straightforward stuff, but also good stuff. You know, thinking about setting baselines, figuring out where you want to get to. Um, and, you know, developing a risk management framework of, uh, what are the things that you need to do to get to that? And I would argue that a lot of it is, is just similar to an overall security program. You know, you're going through those, but also looking at incident response and recovery.
How do I do incident response? And how do I do that in the cloud? Thinking about continuous monitoring. Well, how do I do that in the cloud? How do I do that when I don't own the systems?
You know, making use of automation. How do I automate between these systems? It's probably very API-driven, right? A lot of this nuance that you, you might be thinking about in your overall program, this just gets into how you specifically do that in the cloud. Yeah, good stuff.
Uh, all right, next we have a blog from Webroot. We don't often get Webroot blogs, uh, into the, the show anymore, but, uh, excited to have one of those. And this is talking about understanding brute force attacks and really brute force password attacks is really what this is talking about. Yeah, they— it's just, it's just going into, um, what that type of attack looks like. I will say I learned a thing.
I didn't realize that one of the uses for GPUs, the specialized uses it's being used for, is for password brute force attacks. You know, I know it's been very popular for crypto mining, uh, based on the number of simultaneous actions it can take, but that same capability means GPUs are being used by bad guys a lot for password breaking. Yeah, one of the other things they talk about here is, uh, is RDP and, uh, its role in brute force attacks, right? Um, if you have RDP exposed to the internet and people can try and brute force passwords on that, that those are the things that they want to get to because, you know, once you're in on RDP, you, you know, it's like you're sitting in front of the computer. So what do we do about it?
Number one, strong password policies including MFA, account lockout policies, you know, a certain number of Failed logins, you lock it out. Having, they say, network-level authentication. I feel like this is kind of an interesting recommendation, and it's the kind of thing that will work in a small percentage of places, but if it does work, great. You know, if you're doing network-level authentication, you know, you're still authenticating. VPN usage, so, you know, you can only try to log in through the VPN.
That's a solution. And then finally, monitoring and alerts, keeping an eye on this stuff. You know, I worry most personally about password spraying, more than I worry about hammering one particular account. If you hammer one particular account, we're gonna see it. But if you password spray across a really wide number of accounts, it's much harder to see.
So monitoring and alerts can be useful for that as well. Yeah, good stuff. All right, final news item of the month. We have an announcement from the National Cybersecurity Center in Colorado Springs talking about the Cyber Future Foundation. And the NCC and the 9th Annual Cyber Future Summit in Colorado Springs.
Yeah. So this is jointly put on by the National Cybersecurity Center and the Cyber Future Foundation, which I didn't know Cyber Future Foundation, CFF, but I clicked the link to learn about them and they have, I don't know, 100 people on their board. And you've probably heard of some big names. 99 and a half of them. Well, no, but you've heard of a good chunk of them and there's some pretty big names.
On the list. They're coming to the Springs to do their event September 11th through 13th. It's going to be at the Cheyenne Mountain Resort. And it's about security at the speed of innovation. Sweet.
And there will be AI and quantum discussed there. Of course. In case you were on the fence, there you go. I'm trying to think of some quantum joke now, but I can't think of a good one. Well, if you did think of it, then you would not have thought of it.
All right, right. I don't know, close enough, close enough. Anyway, I did my best. All right, uh, that's, that's our news for the month. Let's, uh, move on.
We'll talk about events. Yeah, we have a calendar of events if you were not aware at colorado-security.com. You can go look at the calendar, and you know, sometimes when I'm adding things to the calendar, I'm, I'm ambitious and I put all the details of the event, and sometimes it's just a link to the, to the original one. So, you know, go, go play a little exploration and see how lazy I was when I put that event in. Speaking of which, we have an event on the 10th of April from ISSA Denver.
They're doing their April meetings in downtown and in the DTC. So if you want to go to the DTC area, that'll be over lunch. Downtown will be for dinner. And they have the same speaker at both. If you are interested, on the 17th, there are 2 events.
ISSA Denver also has an event that day. They're doing their Veterans Special Interest Group, and Denver OWASP is doing their meeting, AppSec 2.0: Reimagine AppSec with Runtime Analysis. On the 18th, we've got 2 events. There is the ISACA annual meeting. I would, you know, often for these we'll put the title of the talk.
This is like an 8-hour event. Yeah, their annual meeting is a big one. It's a big thing. I think it starts at 8 in the morning. And goes till 4 in the afternoon or 6 in the afternoon.
I can't remember which. Either way, it's a big event. It's also a really good time. I've been a couple times in the past. If you're looking for CPEs, if you're looking for a fun event, that'd be a good one for you to hit up.
But also on the 18th, if you thought, man, I got 8 hours there, but I could really use something to end up my day, the Colorado Cloud Security Alliance is having their event, AWS Token Theft: Stolen Identities and What to Do About Them. On April 23rd, uh, the Let's Talk Software Security group is doing one of their meetings. How can offsec enhance your AppSec game? Is that just like turning off the technology? Exactly.
You know, it's not secure unless it's, uh, turned off in concrete. Smart. Uh, the 14th, ISC— excuse me, the 24th. That's April 24th. ISC² Pikes Peak is doing their April meeting.
Uh, we got a bunch on the 26th. Colorado Equals Security is doing our first annual, uh, Security Leader Summit. Is it annual, Alex? Uh, well, it's our inaugural. Inaugural.
Yeah, one of those words. We haven't decided on time-bound cadence necessarily, but we're, we're, we decided, you know, we've been doing this, this whole community for about 10 years and decided we'd like to get together with the security leaders. So, so in the summer we'll do our picnic, and, and this is our first time with a kind of a large group, uh, for education, uh, for security leaders. So if, if you're a security leader in town, you haven't already signed up, go out to colorado-security.com and find the, the summit link. Um, and we'll look for doing more of these in the future.
Also on the 26th, uh, there is an event, Making Every Dollar Count: Maximizing the Impact of Your Security Spend. I, I believe this is a vendor-sponsored event. Yeah, I didn't, I didn't, there wasn't like a group necessarily, but it looked interesting. And then finally, on the 26th through the 28th, ISACA Denver is doing an event, Empowering Women in Tech CISM Bootcamp by She Leads Tech. Yeah, ISACA has another event on May 2nd, which is around Alteryx exploration.
It's a technical training, a workshop on Alteryx. Kind of cool. Very nice. And then on the 8th of May, ISC² Denver is doing Navigating the Cyber Landscape in Operational Technology, or OT. Challenges, threats, and solutions.
So this is the first time we've talked about ISC² Denver in years. Yeah, it's been a bit. So they, they went, they kind of went away, their website died, um, then a new group of leaders took over, they revitalized the website. I think that this is their first event since coming back. I, I found a link to register, although it— the registration button didn't work, so I'm not sure if maybe they're sold out or maybe they just had to get up.
But either way, it's worth taking a look. All right. That's it, I think, for events. That's it for events. Jump to jobs.
Cool. We've got some great jobs this month. First, Cologix is looking for a security engineer too. The U.S. Army Corps of Engineers is hiring an IT specialist focused on InfoSec and network. The City and County of Denver is hiring a senior IT security analyst at DIA.
Oh, cool. DIA. First Bank Holding Company is hiring an IAM systems admin. CableLabs is looking for a principal IoT security architect. That sounds pretty cool.
The US Bank is hiring an information security technology risk manager. Bank of America is looking for an information security identity and access management architect. Prologis is hiring a senior analyst of IT governance, risk, and compliance. This will be working with our friends Sue and Tyler. Replicant is looking for a staff cloud security engineer.
That's— I don't know if James Brown is hiring that or not, but you'd be working with James Brown. That's great. Well, finally, Janus Henderson is hiring a senior IT security— excuse me, a senior IT audit manager. Very good. Yeah.
Well, that is it for the news. And Alex, we do not have an interview this week, so people are free to run amok for the next half hour. Not this week. Not this month. Yeah, um, if, if you, if you miss it so much, you can just go to Slack and talk with someone there.
There you go, much better idea. All right, all right, everyone have a fantastic April. Thanks, Robb. Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.