Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 265. This is, uh, August 2024.
Alex, uh, this is our last summer podcast. You know how I know it's August, Drop? How do you know that? It's 1,000 degrees outside and everything's on fire. Um, well, that sucks.
It is, but that's August. Yeah. And, and I mean, there's now fires burning in Colorado, but yeah, you know, the biggest impact around here has been the smoke from the Canadian fires, right? It's been, it's been gross. Yeah.
Uh, one of the, the fires, the one kind of in Deer Creek Canyon, uh, down off by C-470, is right by my house and It was pretty smoky the day that that started, but seems to be blowing the other way these days. So not quite as bad, but still no fun. So we're recording Friday night. Yeah. Any containment updates?
You want to be the on-the-moment news guy? I can still see smoke, so it's not out, but it does seem less smoky. So I'm going to go out on a limb and say that they have it a little bit contained. Well, Let's, let's hope that by the time people listen on Sunday, that the fire is completely contained and everyone is relaxing at the, at the pool. Or if you're listening sometime in the distant future, hopefully, um, there are still structures standing and everyone's built back and everything's back to normal by then.
All right. Let's, uh, talk about our housekeeping. We have a Slack channel. We love, we love having new folks join us in Slack. We've had a bunch of new folks in the last couple of weeks.
If you want to join us in Slack, go to colorado-security.com and go to the Slack link there. We'll get you joined up. And while you're there, why don't you go ahead and also join our mailing list, which will get you the show notes and occasionally news like our upcoming picnic that we have and our salary survey, which we, we actually just got the results of that released this last week. So if you, if you submitted your details, that should be in your inbox. All kinds of good stuff if you sign up for the mailing list.
Yeah, and we'd love it if you rate us and subscribe on wherever you get podcasts from. Go, uh, give us a thumbs up or something. I don't even know what you do on YouTube for liking some— I guess it's like and subscribe. Like and subscribe. There you go.
Smash that subscribe button. That's right. Do it. Um, also tell a friend about Colorado Eco Security, um, not just the podcast, but also all the other great things that we do. And if you want to support us financially, we do have a Patreon campaign.
It helps pay the bills around here. So If you want to sign up for that, we would appreciate it. One of the things that money is used for is our summer picnic, which we have coming up a little bit later this month, and I'm sure we'll talk about it in events. And just a huge shout out and thank you to the current patron supporters. We've had folks supporting us like the whole 7 years we've been doing this or thereabouts.
Thanks so much for your loyalty and keeping it going. It's— it means a lot to us to know that there's folks who, who keep financially supporting the show. So thank you to those folks. All right, let's jump into the news. First story is a big one.
This is talking about changing something that's been going on for 50 years. Southwest Airlines, which has a big hub here, is changing their policy on seating. Yeah, you know, this isn't especially a Denver story, but like you said, it's got a big hub in Denver. And, you know, you and I fly a lot of Southwest. So I know this perked our interest.
The news is basically, you know, they dropped a few things at the same time. They're going to start doing red-eye flights. You know, who cares? I can't remember. There was one other thing.
But, but the big news was they're going to do away with the open seating policy they have now. And they're not only going to have assigned seating, but they're going to have more premium type seating with extra, extra legroom that people will be able to get either for more money or based on status. They haven't made that clear yet. Yeah, I think the article says that they have an Investor Day coming up in September where they're going to give more details on all of this stuff that they've announced. So we should have more details in the future.
But I'm hopeful it'll be a good thing. It seems like everybody wants it. I think they said 83% of their customers want assigned seats. So, well, everyone who responded to their surveys wants it. True.
Because those of us who didn't want it, why would I respond to that survey? They're never going to change that. Right. Right. Did you get an email today?
I got an email from their CEO like, hey, don't freak out. It's going to be okay. Yeah, maybe if I did. I haven't read it yet, but yeah, basically says I won't freak out now. Basically says, hey, we really, we really want you not to leave us.
So wait around and, you know, see what the changes are before you, before you freak out. So there you go. Don't freak out. What are people going to do? Leave them for another airline that already assigns their seats and charges for baggage?
Right. Yeah, it's hard, hard to, hard to leave. All right. We have some other news, maybe a little, well, sort of Denver focused, right? Denver ski companies, Alterra Mountain Company and Vail Resorts, are going to be hosting the 2034 Winter Olympics, which are happening just across the border in Utah.
Yeah. So obviously, there's a lot of skiing events in the Winter Olympics. And there's a couple mountains in Utah that are going to be hosting different things. I don't have the details right in front of me. I've got it right in front of me.
Hey, Alterra's Deer Creek— or Deer Valley Resort, which is right near Park City, is going to host the free freestyle skiing events, including moguls and aerials. And Vail Resorts Park City Mountain is going to host men's and women's snowboarding halfpipe, snowboarding slopestyle, freestyle skiing halfpipe, and freestyle skiing slopestyle. Those are hard words if you haven't practiced. That's a lot. It's a lot of words there.
You know, I feel like sometime in the last 20 years, Utah had the Olympics, right? The Winter Olympics. They did. 2004. Somewhere in there.
Somewhere in there. While I've lived in Colorado, I remember that thinking, oh, I could go over there and then not doing it. Right. Yeah. Maybe this time I'll go do it.
What is it? 2030? Is that— 2034. 2034. Good stuff.
All right, moving on to our next story. We've talked about this a number of times, but more details on Colorado being a quantum hub. There's more details now about how Colorado and New Mexico are going to use the federal funding that came in from the being named a quantum hub. Is it, is it possible that I just totally missed the fact that it wasn't Colorado, it was Colorado and New Mexico combined for this quantum thing? Yeah, I feel like I may not have realized that either.
Anyway, the two of them combined for this bid. Most of which it looks like is in Colorado, but they're, they're getting $40.5 million of federal money, which unlocks another $77 million in matching funds from Colorado, and another $10 million from New Mexico. So there's like $120, $130 million-ish that they're getting. But what was really interesting to me is what they're going to use this money for. One of the things is they're going to build this quantum facility that's intended to basically become a resource that other startup quantum companies can use, right, to do their own quantum work.
So instead of having to build their own, you know, data center of quantum computing, they can use this just like we are able to use AWS for our infrastructure. And that's, that's maybe the centerpiece of what this investment is going to look like, right? And I mean, honestly, for trying to jumpstart an industry, that seems like a really smart thing to do. Make it easy to get in, right? Right.
They said it'll be a couple hundred thousand dollars to get started instead of millions of dollars. Right. They do also mention that I think $13.5 million of that dollars is going towards workforce development. I think we talked about that maybe in a previous article that, you know, there's a lot of sort of support services and other things that go around the quantum industry that, that are lacking. And so this is going to help build those, those folks up.
They drop one more fact in here. There are currently 3 job openings in the, in the quantum field for every 1 qualified person. So you can go get three jobs if you're good at this. Good times. All right.
Next, we have a story about AI that may or may not be about AI. The headline—they threw headline AI in the headline to get picked up. Maybe just like they did with the VC presentation. It says AI and security. So we were like, "Ooh, let's talk about this story." So the headline is Colorado company strikes AI partnership.
For security at car dealerships. Yeah, so it's called what? Bot— oh shoot, BotDoc. BotDoc. Yeah, BotDoc is a company that's going to work to help deploy driver's license and other ID verification out to auto sellers.
Apparently, this is a serious problem for auto dealers where someone will show up to go do a test drive, they'll give their driver's license, and then they'll go steal the car. Because, um, they're not validating these are actually like legitimate driver's licenses. So they're having a lot of auto theft as a part of this. Yes. Uh, it says about 80,000 cars a year are stolen for people from— with people with fake driver's license.
Yeah. So, so who knew? BotDoc is going to validate that these are legitimate, um, identifications on the spot and, and help, help reduce that theft. And if you're like me, you read this article in the end and you say, Well, where's the AI in that? Right?
You're just checking a, you're just checking a driver's license against, against a database, right? I, or, or maybe they're not checking it against a database. Maybe they're looking at it to see how likely it is to be stolen. I don't know. So, Robb, the, in my mind, the only time that they actually talk about artificial intelligence is in the very first sentence.
And it says that BotDoc struck a partnership with artificial intelligence developer Trust Stamp. So, so we know now that they're an artificial intelligence developer because they said so, even though they don't say anything else about how they do it or what they're doing. Well, I am, I am looking forward to hearing more about this. And if, if BotDoc can help solve somewhere in the ballpark of 80,000 car thefts a year, this is a great partnership indeed. All right.
What do we got next? We are into, oh, oh yeah. This is the CrowdStrike follow-up, right? So in the last month, I'm sure everyone listening heard about the, the, the significant issue that was caused by a CrowdStrike or was affected by. Yeah, exactly.
Either heard about or was affected by or laughed at those who were affected by. Not me. I did not laugh. The— but this article kind of goes into the regional, the local impacts of it. There's quite a few impacts in Colorado.
Yes. The first, there was a lot of disruption to RTD trains. Uh, there were— they had communication problems, so they were unable to safely run trains. So they had to cancel a lot of trains. You know, those trains are going like 10 miles an hour right now anyway.
Yeah, it's crazy because the tracks had some, like, some, uh, structural problem. It's pretty brutal to take an RTD train. Yeah, I don't think it's everywhere, but yes, there's many stretches on the south part of town where I am. Yeah, yeah. Um, but RTD was not the only impacted— what, there was a long list here.
The The Division of Motor Vehicles, the Colorado Department of Revenue, Arapahoe County Clerk where I live, they ended up having to close for the day based on the impact. Quite a few more as well. Some emergency services were affected. Big, big effect, obviously everywhere, but also here in Colorado. 911 systems, really a big impact.
You know, I know, you know, this is, CrowdStrike has been a huge success story for cybersecurity and for a lot of their customers, right? Um, and this just kind of shows the, the flip side when you, when you get really dependent on one technology, it has a big impact when it's down. Yeah. I mean, I think it also shows like how big CrowdStrike actually is, right? Like this was, you know, major, major impacts to the entire world because of, you know, one vendor.
Uh, so our next, so that is the CrowdStrike story. Next we have a story by Ballard Spahr in their, uh, Was it Cyber Advisor? Cyber Advisor blog around comparing the AI regulatory frameworks from the US, UK, and EU. And I'm going to admit, I didn't watch the video. I watched a very little bit of it.
I actually, I still have the tab open in my browser to go back and watch it later. Because this is something that I want to know more about. And I, this seems like a really good overview to listen to. You know, partially because the the EU Act just went into effect. So it's it's something that that we all need to know about if we're doing any business in the EU.
Yeah, I I have a forcing function myself where I shared the link with our head of privacy and our head of AI to say, "Hey, we should all look at this." So I also will need to watch it. But for those listening, maybe you can tell me what you thought because I probably won't have finished it by Sunday. Yeah, and this is Greg Swicek over at at Privacy. Advisor with Ballard Spahr, and they do a lot of good stuff there. All right.
Well, we— our next one I thought was actually a pretty interesting story. This is a follow-up on a story we've talked about, which is the merger of LogRhythm and Exabeam. But this story is a little bit juicy. The way it's written is kind of like a gotcha journalist. And, you know, we need to be careful that we just quote.
We're not suggesting that any of these things are facts, but it's an interesting story. Yeah, of course. This is in the Register, which is always a little bit cheeky. But this is talking about the Exabeam and LogRhythm merger, which I don't know, more or less in the end, it seems like the Exabeam side is getting the better of that. They're keeping the name, the technology, the technology in many cases, but not the team, right?
The CEO of LogRhythm is the CEO of the new company. And we know the deputy CISO from LogRhythm is the new CISO for Exabeam, which congratulations there. But this, this article has a few facts. We did know that there was a big layoff a couple of weeks ago. The— this article says that one reader reported that there was a— the executives had said there was a 30% reduction in force.
Pretty, pretty deep cut. It also says after Exabeam had a 20% cut earlier in the year, which if you add those together, that's a big— that's a big cut. Yeah. Also, like, you know, like you mentioned, kind of cheeky, the former Exabeam CEO, And I'm going to read the quote here. We're told that he would drift away beneath a significant golden parachute.
So apparently that's— That would make me laugh. I'd like to have one of those someday. Yes. How do you get one of those things? I mean, it doesn't even have to be a significant golden parachute.
Just give me a little parachute is fine. I think if it's golden, it's significant, right? Last element there that I found really interesting that the article says, under the terms of the now completed transaction, Exabeam common stock shareholders stockholder shares have been canceled with no consideration. Basically, the assessment, the judgment here is that there was no value in those shares and they have just been taken away. Yeah.
And there was, I believe, an immediate lawsuit from a shareholder to open up the books and figure out, you know, what's going on here, which was dismissed. But then now there's another one to get to the bottom of that. Particular stock. Definitely feel for the, for the employees who, you know, put in years at Exabeam, you know, vested shares, thought that this merger could be the thing that took them over the top. And then, you know, their, their equity is, is canceled.
That's, that's tough. That's tough. Yes. Next, we have a blog from Red Canary. This is talking about halting a hospital ransomware attack.
This is another one of the not quite as deep technical as, as many of their blogs, but, but fairly technical talking about, you know, how this ransomware was detected, Um, IOCs, other things like that. It does show the specific way, you know, detections and the specific lines of code used at when it was being executed in the wild. So you could look in your own environment for these types of attacks. And I love the, the way they, they, they just uncover the mystery, right? I think sometimes those who are not super in the weeds can look at, oh, we stopped ransomware as some magical thing.
They just show you exactly how they identified it, what they did to stop stop it. And I love that. Yeah, it's good stuff. Uh, our next story is, uh, another blog post from Laris. We've been doing a number of blogs from them recently.
They seem to be a little bit more prolific these days in the, the, uh, the news that they're putting out there. So this is talking about enhancing organizational communication and culture through purple teaming. I feel like they've done a— this has been a theme for them in the past. I don't think this is the first we've heard of this. Yeah, maybe not this exact angle, but purple teaming definitely seems like something that they're pushing hard.
Yeah, and really I'd say that the focus here is as much around the organizational culture of having a company where the defenders and the attackers work collaboratively as it is anything else, that it's opening up the communication, the awareness among these different teams, bridging the gap with leadership, to make them aware of it. And this idea of a shared responsibility for security, you know, not a, you know, hey, we're here to go poke holes in your thing while you try and defend. Yep. Yep. Overall good blog.
Good story. All right. We got one more here and this is Webroot and it is 7 tips on keeping your data private when using AI. Yeah. And they're tips.
They are tips. You know, this Webroot, obviously, uh, consumer sort of focused AV. And so most of their posts are, you know, a little, a little more basic, a little more focused on the, the every person, not, you know, sort of an enterprise security kind of— I mean, I would suggest this list of 7 things is as applicable to any technology as it is to AI. Yes. I don't think there's actually any of these 7— we'll just go through them real quick— that are AI specific.
So number 1 is understanding the technology. You need to do that for— that's important. Important. Number 2, know the vendor's privacy practices. Again, that should be everywhere.
But I mean, special emphasis on GenAI because it's possible that they're using your data to train their models and other things. It's a slightly different risk. It's any place you put data, right? Any place you put data, you'd want to know what they're going to do with your data. I think we sort of have a heightened, heightened thoughts around that one right now.
All right. Number 3, avoid putting in private data. Which is, once again, I think that goes back to number 2. Like, private data is okay if you have, you know, high level of confidence there. Number 4, use strong passwords.
Number 5, keep your software up to date. Number 6, protect your devices. And number 7, always a good idea, use multi-factor authentication. Yes. Most of those have no relation, but yes, all good practices.
All right. That is it for news. Let's jump over to our— what are we going to next? Events, right? We have an event calendar.
Things are starting to pick up as the fall approaches. If you want to take a look for events coming in the next few months, you go out to colorado-security and look at the event calendar. But there are a good number of events here in August. Uh, first on that list, on August 13th, ISSA Colorado Springs is doing their August meeting. On the 14th, Denver ISSA has their August meeting, which is around incident response.
Also on the 14th, the Let's Talk Software Security group is talking about vulnerability remediation fixing problems or creating new ones? I think the answer is yes. On the 17th of August, ISSA Colorado Springs is doing their August mini seminar. Oh, I get to do this good one. On the 24th of August, Colorado Equals Security and the Colorado Cloud Security Alliance are joining forces.
Yes, we are. We are going to— This is breaking news. This is breaking news. If you— I don't know hardly anyone who knows this news. We are, we are going to be doing our picnic together.
Originally, we had scheduled our picnic and we— and then CSA happened to pick the same day to do a picnic. And we reached out to those teams and we said, let's, let's do it together. Why don't we just do one big picnic? It's like chocolate and peanut butter. That's right.
Peanut butter and jelly. We're, we're so that we're going to be all together at DeCovan Park for— I think we're doing 11 a.m. to 2 p.m. and we're going to have Chipotle. And we're gonna have some drinks and some games. And we'd love to have you there. Yeah.
So register with either Colorado Equals Security or CSA, but not both. We will deduplicate, but we don't want to have to. So one or the other. Especially since a lot of these CSA people use pseudonyms. That's right.
Yeah, that'll be tough. All right. Moving on. On the 28th, ISC² Pikes Peak is doing their August meeting. And Denver ISSA is doing a special interest group on AI and ML.
All right, let's jump over to jobs. Speaking of breaking news, as of today, this is Friday the 2nd, um, Pax8, we are hiring a GRC analyst. If you are interested in getting into GRC, if you have maybe a little experience, we don't need someone who's been doing it forever, uh, we'd love to talk to you. We're looking for folks who have a third-party risk, uh, interest and maybe help with some incident response type work. Yeah, this must be breaking news because when I looked at the show notes earlier, this wasn't there.
You got it. City and County of Denver is looking for a CISO. Yeah, that's going to be a fun job. Yeah. Lumen is hiring a vice president and deputy CISO.
I mean, deputy CISO for Lumen, that's a big job. Yeah, it looks like it. I would bet that they have maybe several deputy CISOs. This looks like it was focused on a couple of different areas of the business, but still a great job. Cobank is looking for a director for internal controls and operational risk.
IT. Uh, Westerra— is it Westerra Credit Union? Is hiring a director of information security. It is a hybrid role, but you must reside in Colorado. Meta is looking for a security partner for mergers and acquisitions.
And if you didn't know, that is abbreviated M&A. Thank you for that. Robinhood is hiring an enterprise risk manager. The state of Colorado is looking for a cybercriminal investigator 4. You sure it's not IV?
It could be related to— is this a medical position? Fastly is hiring a senior manager of security detection and response. I'm excited, Robb, because I don't have the last one. Motion Recruitment is also hiring a GRC analyst. So work for Robb instead of Motion Recruitment.
But if you don't like Robb, go apply at Motion Recruitment. You can tell me how many words this is when I'm done here. The Trade Desk, and our friend Joe is over there, is hiring a senior staff product manager, data governance and policy applications, trust and security. Yeah, that's a lot. I didn't count it, but it's a lot.
Yeah, that's, that's more than your fingers. Exactly. I couldn't quite get to my toes fast enough. All right. Well, that is it for news.
However, do we have an interview? We have an interview. Who is it? Um, we have an interview with the CEO and founder of Dapple Security, Gadalia. I got a chance to meet her, it might have been maybe just last week, and Frank sat down with her and, and did an interview.
And really fascinating background, and I'm looking forward to hearing all of their conversations. Yeah, me too. Should be fun. All right, well, that is it for August. We will circle back in September when the kids are back in school.
Sweet. Thanks, Robb. Hi, this is Chris Arden. CISO with Newmont Corporation. This is Colorado Equals Security, for Colorado security professionals by Colorado security professionals.
Good morning, good afternoon, and good evening. Welcome to the Colorado Equals Security podcast. My name is Frank. I think some of you are familiar with me. Today, as my guest, I have Gadalia Montoya Weinberg O'Bryan.
She is the, uh, Dapple Security CEO, and she served as a cryptomatician on the National Security Agency, the NSA, for nearly a decade and has built a successful career as a senior technology leader and founder, right? She graduated a degree in mathematics from UCLA and invests energy into fostering an interest in STEM fields, increasing equity and representation in technology, and trying to use it for good. So with all of that, I'm gonna ask you a really odd question here. With your background, do you ever have a problem balancing your checkbook in the end of the day?
Thanks so much for having me, Frank. It's actually funny that you asked that question because I'm quite horrible at arithmetic.
So despite being a mathematician, it's actually sometimes a very different kind of mindset than thinking about, you know, accounting or numbers. I do quite appreciate doing financial work and thinking through it kind of from a strategic level, but I always have someone else check my work when it gets down to the nitty-gritty because, yeah, the details elude me a bit. Yeah, well, that's interesting that So what you're saying is that being a cryptomathematician in some ways doesn't have anything to do with basic math? Yeah, you know, I think when I started to feel at home in math is when you start to use letters instead of numbers. Okay.
And so, yeah, kind of, you know, being able to think about things again in cryptography. Through the lens of abstraction and, you know, algorithms and compute and whatnot. Yeah, it is. I know it sounds funny, but it is fundamentally kind of a different part of your brain than doing arithmetic. Okay.
Well, how are you, you know, and how was it working for the NSA? And before you answer that, I'm going to look outside and check to see if there's any black vans outside or, you know, See if there's a helicopter above. You know, I just want to make sure before we answer that question.
But working for the NSA couldn't have been an easy task.
No, it wasn't. It was extremely trying and stressful, but also I'm a very mission-oriented person, and so it was very satisfying in that regard. I actually joined shortly after 9/11, which is why it really was my motivation for wanting to serve my country and knowing that math was the thing I was good at. And so, you know, if I could put that to good use. It is probably the only time in my career that I have literally run to my desk from my car because I was so excited to get to my desk and see the result of something that had run overnight, you know, see if we had had a breakthrough and things.
So that was thrilling. Worked with some of just the smartest people that probably exist on this planet and learned so much from them. And the math community there is pretty amazing. So yeah, I'm just so glad to have had that experience in my career. There's really nothing I could replace with it.
So priceless. Well, I think that's awesome because I think that a lot of the people that are listening to this podcast have passion about their job, right? It's not just a job. It's actually a career. And sometimes I'd like to say it's more than a career.
It's more of a lifestyle because while it may consume every part of your life, it's not stressful. It doesn't feel like, oh, well, this is actual work, right? Yeah. Whenever you can achieve that, it's pretty special. Yeah.
Okay. Well, working for the NSA, obviously, I'm sure that there are certain parts you can't talk about. But is this something that you would recommend to other people? I mean, because working for the NSA, you obviously have to have a very deep background check on you, but it's going to affect the people around you. Is that stressful for those people?
Um, yeah, it's, it's, I often reflect on kind of the difference in my work life, um, between when I worked there and, you know, what I do now as a startup founder working from home. Primarily. There are some good things about it from a work-life balance perspective. You literally cannot bring your work home with you, which is in some ways really, really nice. And there's a pretty strict, you're working a 40-hour week, no more, no less kind of thing.
But yeah, the flip side of that is you can't always talk. You'll have a stressful day and you can't necessarily talk to your family about what's going on. And I think that's hard for, you know, both, both the employee and the family members. So, you know, as with any, any job, I guess there's kind of pros and cons. I, like I said, you know, would, would never— I've never regretted having that opportunity in my life.
And from a perspective of being a mathematician and having a job that put my skills to good use and really pushed me forward in my learnings and my understanding of the, of the security field. Yeah, I would absolutely recommend it to a person in their career. You know, there are, there are, of course, nuances to every administration. And I think, you know, I, I did my best to sort of keep my nose down and shelter myself from some of that. But, you know, I, it, I'd be silly, you know, not to mention, you know, towards the end of my time there is when Edward Snowden happened.
And like, you know, you, you, You are exposed to some pretty immense national and international events that happen. Um, and so that has to be something that you're, um, both interested in and okay with. Okay. Well, I'm going to go somewhere and, you know, this may or may not be a good thing, right? Okay.
But it's just based on what you said here. All right. What do you think about the whole Snowden thing? Right. Yeah.
Yeah. Yeah. He's gonna try to cause some controversy for your podcast here. It's, it's actually really interesting for me to have conversations with folks who haven't worked in the intelligence community. It's challenging because there's viewpoints that you can only have from kind of being And from that inside perspective, and that you can't necessarily give the background behind because it is classified.
But in general, I will say it was pretty horrifying to be driving in my car and hear on the radio, you know, details of projects that either I had worked on or that colleagues had worked on that I knew were going to put people's lives at risk because they had been exposed. And, you know, putting aside the question of whether or not some of the things that he leaked should have been known to the public, putting that aside, the way in which it was done that put American lives at risk, to me, was horrifying. Yeah. Well, of course, I, and, and I agree. I think that was completely wrong.
But at the same time, I guess, think Part of the question is, is what about privacy reasons? Like, how do you feel? Should the NSA have that ability to go through your personal communications, through your stuff, and decide, right, whether or not, you know, they should act on it? You know, do you have a right to privacy here? Yeah.
So again, there's lots of nuances here that I You know, I can't really talk about. One thing I will say is, well, I'll say a couple of things. One is there's nuance that I think is really hard to understand unless you are very, have very intimate knowledge of, you know, the law, the situation, the mission, etc. I will say though that privacy has evolved as something very important in my career and my mission, my own personal mission. And that time absolutely informed some of that, you know, seeing the upsides and the downsides of what happens when personal privacy is violated.
And so, so yeah, I guess like the bottom line that I can share there is that that was definitely an informative time for me and kind of proving the value to myself of privacy and technology and wanting to bring that forward in any solution that I build. Okay. Well, I guess things, one of the things that was kind of interesting here, and this is all, of course, rumor. We don't, I don't really know or not, but they said that they had used that type of data to catch a car bomber actually out here in the Aurora area. They were able to raid the person's apartment, seize him before he was able to do any damage.
And apparently the plan was to actually go to a very populated area somewhere like New York Times Square and set off a car bomb. With that in light, and that area of, of, you know, invasion of privacy where it turned out to be good. How do we take a good balance in that? Yeah, and obviously, I, you know, I can't comment at all on the details of that particular example, but it's a very typical kind of example, right, where you're thinking about privacy and security as kind of competing things. And I think it's actually quite an interesting paradox in the security industry that we do have to balance constantly.
And there is no broad strokes we can paint that I think can provide an answer in every scenario. But anytime we can find a solution that balances both security and privacy is almost magical in my mind, because then you don't have these as competing priorities, you have them as sort of, you know, motivated in the same direction. It's not always the case, and in that case you have to kind of take it on a case-by-case basis and evaluate the risks and potential benefits. But yeah, and some of this I'm like alluding to things we'll probably get into later, you know, about some of the stuff I'm building with Dapple. But yeah, like When you talked at the very top of the conversation about trying to use technology for good, in my mind, those are exactly the kinds of things you have to think about is, you know, how are we balancing both security, which is important, and privacy and sovereignty, which are important?
Yeah. Well, I mean, as you can see in my background, I am a Marine and we're both patriotic, obviously. To me, that's worth it. But it is also something that's very controversial. I can understand why some people like their privacy and, and like certain things.
So, um, um, yeah, yeah, absolutely. Um, agreed. Yeah. Okay, well, here we go. We get an offer, or you get an offer from the NSA, and you actually decide not to join right away.
You will move back to Colorado. What was your motivator? Why After working so hard to get a job interview and get a job with the NSA, would you defer it? Yes, you're right. It was quite a process to actually get to the point where, where I got that job offer, and it was a very exciting day when I did.
So they do give you the ability to defer up to a year, and you can kind of do that without having to reobtain your security clearance and all of that. I don't know if they still do that, but they did in those days. And I did take advantage of it. And this is not something I actually talk about much, but my childhood friend at the time was unfortunately dying from brain cancer, and she was here in Colorado, and I really wanted to spend her last year with her. And so I did defer.
I worked as an academic advisor up at CU Boulder. CU in Boulder. And that— I actually really liked that job helping students. It was quite fulfilling for the small time that I had. It was kind of a weird one-off in my career.
But yeah, you know, I'm so lucky that I was afforded that luxury of being able to be with her. And thank you for letting me talk about it. It's— this September will actually mark the 20th anniversary of her passing away. So kind of a fun memory for me and something I'm really glad that I was able to do before I kind of started off on my career for real. Well, I mean, I think that shows that you're not only a good cryptomatician.
I mean, we think of people that work for the NSA as being, well, quote, feelingless, right? Or robots. I think that really shows, though, that you are a person and that you have real feelings and You actually went with what is the most important thing to you instead of pursuing a career, a very, I guess, assuming fruitful career with the NSA. You chose essentially family instead. Yeah.
And I think that is, you know, constantly you're balancing those choices as you, you know, start a family and are taking, you know, now I'm taking care of aging parents and Yeah, like, you know, those are, those are things that I, I think we don't always talk about, um, as much as we should when, you know, when, when we talk about careers and choices and stuff. Um, but there's, there's always so much that goes into it, and some of it has nothing to do with your actual career. Yeah, yeah. But it is driving to you as a person. And, you know, again, I think we have a lot of similarities.
Both of us have aging parents. We live in the same area, and I actually work for CU at times as an instructor for them. Oh, I didn't know that. Yeah, very cool. Yeah.
All right. Well, you're sitting going through your home, and all of a sudden you find some magazines, some weird magazines after moving some furniture. What was that about? Oh, no. Yeah, actually, no, this was, this was while I was working for the government.
The— those buildings sometimes are just like these time capsules, just these ancient relics where, you know, the building itself, but also the carpet and the furniture, and nothing has really changed in like many, many decades. So yeah, I think we were just rearranging the desks or something, and we just found this pile of magazines like fell out from behind the desk, and they were literally like Time magazines from the '70s. So it was kind of one of those moments where like, I really am living in a time machine here at work. But just You know, one of those sort of endearing stories about working for the government. Well, the hard part is then what did you do with them?
Did you send them to the Smithsonian or— I'm trying to remember what we did with them. I think we just sort of put them like in a stack in the corner as a nice talking piece when people came to visit our office. Like, oh, isn't this funny? It's hard to throw things like that away, even though that they probably have no real use anymore. Yeah.
Very true. Yeah. And I, I don't know that they're, you know, it's not like they were in great shape or anything, so I doubt they were collector's items, but yeah, they were, they were a fun sort of little mascot to have for my office. Okay. Well, you've done work for the NSA and then you're also finding some stuff out about NIST as well.
Oh yeah. Yeah. So, um, NIST along with several federal government agencies, um, award these small business innovation research grants. Which, you know, for others out there who are building tech companies, very great programs to be aware of. They're often referred to as SBIR or SBIR.
So Dapple did actually get awarded a NIST grant just a couple of months ago, a SBIR Phase 1, which is super exciting. I'm really, you know, NIST is really thinking a lot about modernizing digital identity and around biometrics. And so really just thrilled to get some of our research funded by them and to be collaborating with them. But, but it again, sort of like along the lines of endearing, funny government stories, you know, we applied for the grant in December, I think, and come mid-May, still just hadn't heard anything. I was really curious, anxious to know, you know, to get that kind of formal email that we had gotten a grant or not.
And my CTO noticed a press release from NIST that listed Dapple as one of the awardees. And so we were like, well, I guess we got the grant because they just published it on the internet. But it actually took another couple days for us to actually get the formal notice. So yeah, I, you know, we just kind of chuckled to ourselves and we're like, yeah, that's, you know, kind of the funny and veering government process that's a little bit out of order that they announced it publicly before even telling me. Yeah, I didn't even know, right?
Yeah, I think, you know, other people saw it and were congratulating me and I was like, wait, what? You didn't even know about that? Well, I'll definitely have to introduce you to an organization called SCORE. They are helping a lot of small and medium businesses out, not from a funding standpoint, but from a mentorship standpoint. I just got involved with them.
Or I'm just starting to get involved with them now. And they will have a meetup, an in-person meetup in, I believe, September or October. So yeah, thank you. That'd be great. Yeah, I'll definitely have to introduce you to that.
And if, or of course, anyone that's interested in listening to this podcast, just let me know and I'll see what I can do to, to, you know, get those introductions set up. Um, how do you feel though? You went from a very giant NS organization, the NSA, that was involved with NIST and everything else, to being part of a, essentially a startup company, a small company. That's obviously a very big change. It is, yes.
And so, uh, that change actually occurred, um, more like 10 years ago, not with my current company, but, uh, with another startup that I joined that was called Coverse. Um, we were A data security company, and that company was founded by a couple of my colleagues from the agency who started their own company. And about 6 months into their journey, they asked me to join them and convinced me to join. And you are not wrong. It was a huge decision.
I really had fancied myself a career government employee. I loved the mission. I loved this, you know, the job security of it. And so making the change from that to going to a tiny company that said, we have 6 months of runway, you know, do you want to join, was a really big decision. What I learned though is that I love startups.
I love building things from the ground up. I love having to wear multiple hats. It's the only place I can be that I feel like all of the parts of my brain are, you know, firing on all cylinders. And so it's, you know, it's one of those sort of fortuitous things that happen in a career where you maybe never would have imagined it for yourself, but then once it happens, you can't imagine it not happening. So yeah, that was really— I was there for 7 years and we exited in 2020.
And I now have the startup, you know, startup bug and, and now have started my own company and I doubt I will ever get out of this world. I really love it. Okay. Well, I mean, I think that's one of the things that we get asked a lot. You know, I'm part of the OWASP organization out here in Denver and a lot of our board members run their own company and they'd like to ask that question.
It's like, how do I start my own company? It's a little scary. Most probably. I mean, was it terrifying for you to go to a startup? It's still terrifying every single day.
Okay. And I think the only reason you can sort of justify that terror is the, just the satisfaction that comes from building something and knowing that you are building a team and giving people, you know, employment and Whatever you're building as your product that you're hopefully, you know, serving that end customer really effectively. And, you know, being able to sort of be the master of your own domain and direct things in the way that you want to, and that are consistent with your vision and your values, which is extremely different, you know, than being a cog in a machine of, you know, tens of thousands of folks working in the government, for example. So yeah, there, you know, I think on most days I have a pretty equal balance of like, what am I doing? Why am I doing this?
And oh my gosh, I love this so much. And they really are both present there pretty much all the time. Does that change from possibly hour to hour or maybe even minute to minute? Absolutely. Yes.
Yeah, it's, I think the hardest question to answer as a founder is, you know, how are you doing? Or how are things going? It's, you know, it's like an impossible question to answer because it really does change from minute to minute. And there are so many— it's just such a loaded question in terms of, you know, all the things that are going on in your brain at any one time. Would you say that would be a core motivator in your career?
Yeah, for sure. Especially, you know, I think like the common thread that ties you know, the different things I've done in my career together is really mission. You know, obviously we talked about some of the mission at NSA and then, but yeah, now just thinking about my current mission of really helping small and mid-sized businesses have access to better security. And, you know, included in that things like balancing privacy and security and being able to build a product with those values in mind always. Ways.
And so, yeah, absolutely. I think, you know, having that sort of driving mission is, is core in, in, in what I did before and in what I'm doing now. Would you say that that is the biggest challenge in security today? Now, what is— is that the biggest challenge? And now I'm not necessarily saying that you have to solve it, but what do you think is?
Do you think that really is the Best or biggest security challenge today? Yeah. So I guess we, we kind of haven't touched on that explicitly. I mean, first of all, right, it's, it's almost impossible to say in security, like, here's the one thing that you need to worry about. You know, something that was drilled into me early days at, at NSA and consistently something that I tell customers now is it's all about layers.
And so thinking about, you know, what am— what layer am I contributing to that is important? And it really is the problem of stolen logins. So, you know, think phishing, but other related attacks, you know, where the wrong person is logging into your business's assets. And all of the big attacks you see in the news these days, I mean, it's pretty predictable that that's how they start. The end result may be ransomware.
It may be a huge data breach. It may be some kind of financial fraud. But it's almost without exception starting with some sort of stolen login. So that really is the problem that I'm trying to address in that sort of layer of all the problems. And especially for SMBs, for small and mid-sized businesses, because hackers are starting to realize that those are the folks who are vulnerable.
You know, we, and I say we because I'm an SMB as well, don't have access to affordable and easy-to-adopt solutions. And so it's kind of this greenfield for hackers. And we're getting attacked. Sometimes it's easy to sort of feel insulated or safe, like nobody cares about me. I'm a small business.
But because we're more vulnerable, we're actually getting attacked at 3 times the rate of larger companies. Okay. So you're being attacked more. Right. But one of the things, as you probably know, as an advisor at CU, and of course, one of the things that I teach a lot is defense in depth.
And you're talking, of course, again about layers. The hardest question, I think, is how often or how many times have you seen the lack of layers or the lack of defense in depth in companies? Right. And why do you think they not try to do anything about it? Yeah, I think you're spot on that that is actually why SMBs make an easier target is enterprises can afford financially and from, you know, workforce perspective, employees in IT to put a lot of those layers in place.
Whereas an SMB might have zero layers, they might have one, maybe 2 if they're kind of on the more mature end of things. And, you know, when, when, as an example of layers, you know, maybe you have some phishing detection software, maybe you have an intrusion detection and response system. Again, those tend to be sort of the more mature postured SMBs. So, I mean, it all comes down to money, right? Money and time, and time really is money for a business too.
And so again, I sort of equate being SMB to being like a teenager where you feel like you're invincible. Like, oh, you know, I'm young, I'm new, like nobody's looking at me. I can kind of get away with anything.
But yeah, unfortunately, we're really seeing the landscape change in that regard. So a lot of what I am usually trying to do is just a bit of education on that front. And let's, you know, like, let's think about what are like the Okay, let's say you can only afford to do 2 things. Like, what are, what are the 2 things that are gonna make the biggest difference for you? Like MFA, right?
Yep, exactly. Okay. And, you know, I actually work with a lot of clients and have to maintain, I think, somewhere around like 7 different MFAs and types of these tokens. Yeah. Are they all equal?
I mean, one over the other? No, and this is like, this is my soapbox. This is one of the things that is actually kind of frustrating me right now about honestly just us as a security community. I think we've been preaching MFA for a while because it is extremely important. But the nuance that's getting lost in that message is that any MFA, you know, is as secure as any other.
And unfortunately, most of the MFA we have in place today is not really any better than just using a plain old password alone. And unfortunately, it's more of a pain to use. So when you think about a code being sent to your text message or your email, or even if you're using some kind of app that, that gives you a one-time code, again, that's gonna be slightly more secure than the text or email. But, but even those can be pretty easily intercepted and it's, it's extremely efficient and affordable for hackers to stand up a website that looks just like, say, your bank's website and get you to enter not only your password, but hey, that one-time code. And then they're able to impersonate you just as easily.
So yeah, you know, I think even last year NSA and CISA released a joint report. That kind of mapped some MFA solutions on a spectrum. And really, you know, on one end, you sort of have password alone, and at the very extreme on the other end, you have, you know, phishing-resistant MFA, which is really the strongest thing that exists out there today and in various forms. And then there's some things in between that kind of fall on that spectrum. So yeah, in addition to saying, you know, MFA is one of the things you can absolutely do that will make the biggest impact.
Also consider, you know, what kind of MFA it is and whether it is truly gonna be phishing resistant. Okay. Well, we mentioned phishing, and then you also mentioned ransomware. And those are, at least in the past, have obviously been very big issues. Yeah, they still are.
Now the big one is AI, right? Yes. And AI is being used everywhere. We've had several talks about AI. And how it can benefit us inside the workplace, of course, how— what the dangers are.
What is your feeling though about it? Yeah, so I, I think a lot about AI in particular as it relates to the identity security space, since that's the space that I'm in and that I think about every day. Um, and I think there's some things about AI that are actually very challenging for that In particular, I don't, I don't know if you've seen kind of an evolution of the phishing texts or emails that you have gotten over the past, say, 3 years, but they're really much better now. You can't as easily detect like, oh, this isn't maybe, you know, a native English speaker who's composing this. The grammar is much better.
They're much more tailored to the individual person, and they might even know something kind of specific about you. And that's all really coming from, from AI helping hackers compose these texts and send them out en masse. And you can, hackers can actually purchase these toolkits for like $200 to wage these exact kind of attacks that are powered by AI that are specifically targeted to be a phishing campaign. So yeah, it's sort of like the flip side, right? Where, you know, a lot of companies I think are trying to employ AI to combat But they have the same tools and they're using them against us as well, even in the identity space.
But, but there are a couple of good things I think that AI can be used for in the identity space, even, you know, around biometrics, things like anti-spoofing and liveness detection. Those are really all driven by machine learning algorithms in the background, and those are a really important piece to being able to use biometrics. Securely. And then I see lots of companies doing cool stuff with like risk-based authentication, where it's not just maybe the, the, you know, password or, or other credential that you're using to log in, but also where is this person? What time of day is it?
You know, what's their normal behavior? And again, all of that kind of pattern matching and, and anomaly detection can be driven by machine learning in the background. So Yeah, there's some good things that we have too. And as usual in security, right? Like, it's just the game of cat and mouse that we're always playing in terms of, you know, red team and blue team having the same tools.
Okay. Well, you mentioned— I do wanna dive into something that you'd mentioned here, biometrics, right? Because that's— this can be very, very controversial. We all know that if I create a password at a company, that email and everything, That becomes property of the company. That is theirs, that email address, even though it's my name, etc.
But if I start using biometrics at the company, how can they say that they own that?
Yeah, it's almost like I planted you in the audience with a question or something.
No. So this, and this is, so we are using biometrics with our solution, with our authentication solution at Dapple. And this is, This is the perfect example of, you know, what I was talking about at the top about privacy, you know, being a core value of mine and, and core to any product that we're building. So the cool thing about the, the secret sauce that we kind of have that's math, that's math, you know, fundamentally, but is that we're able to do biometric authentication without ever having to store the biometric itself. Which again makes it so that just because the user is employing biometrics to log into their employer's assets, they're not having to hand over that biometric data to their employer.
We basically process it, turn it into a digital key, and then it is, you know, destroyed, and it never leaves the device even during that processing. So Yeah, like, I think that's where we have to get creative as we move forward with more sophisticated solutions and even the use of biometrics. And this was a huge part of me starting the company, is knowing that biometrics are going to be an important part of our ecosystem and that there had to be a better way to deal with it so that we weren't giving up all of this really, really— I mean, that's the most private data you have about yourself, right? Well, hang on, hang on, hang on. So we've seen this in TV and movies, and we know that, of course, that's gotta be absolutely accurate.
Of course. Yeah. And everything else. But are you saying that as I put my fingerprint into the authentication, you— there's no chance of us being able to export that data and making that fake fingerprint mold so that we can unlock that biometric safe? I would never say never in security, right?
But, but yeah, it becomes much, much harder because you'd have to have access to the physical device and wait some sort of side channel attack or something to get it, you know, as it's actually being captured, which is very different from a traditional scenario where the biometrics have to be stored on a central server so that you can do the comparison every time that users are coming to it. So You know, when you think about, say, a biometric system at the airport that you might be using, or to get into sports stadiums, like those biometrics are being stored centrally on a server somewhere. And if someone hacks into that server, oh my gosh, right? They've got everything and you can't revoke it. Once it's exposed, it's exposed.
So we're trying to really like minimize that attack surface to where, again, it would be much, much more difficult. Um, to actually get access to the raw biometric. Okay, well, we are coming towards the end of our time here. We've had a lot of interesting things, and I'm sure probably the audience is walking away with more questions than answers at this point. I have the feeling that we could keep going on this for the next 3 to 5 hours, right?
Yeah, but we are running into that. We've talked a lot about the biometrics, how It's such an issue these days. But I think the other thing that would be really interesting to talk to you, or at least continue the conversation with you, is about how all MFA is, is not equal and what the differences are and things like that. If you want to continue talking to Gadalia about this kind of things, she is the CEO of Dapple Security. Why don't you tell us a little bit about that?
Yeah, right. Thank you. We've definitely alluded to it a bunch here, but yes, we are trying to specifically help SMBs combat phishing by building a phishing-resistant MFA. So you can think of it as replacing your password with your fingerprint, which makes it really easy for the user, but it's also much more secure, and we're doing it in a privacy-preserving way so that that biometric is never stored. The bottom line, I think, to SMBs who are worried about phishing and worried about ransomware that starts with phishing is that I like to call this just next-gen MFA.
And so if you have an MFA in place now, you know, perhaps it's worth thinking about having phishing-resistant MFA. If you don't have anything in place now, you know, you can kind of leapfrog to the best of breed. So, yeah, I'm always happy to talk about that or nerd about— out about really anything. So folks can always reach me at gadalia@applesecurity.com. And I'm happy to just have a chat.
Okay. Well, Robb and Alex will put that in the contacts in the show notes along with your LinkedIn. I would again wanna thank you for your time. Again, my name is Frank. I am the Vice President of the Denver OWASP chapter.
I'm also an instructor here, so we'll go ahead and put those in the link notes as in the show notes as well. But again, thank you for your time. I appreciate it. For anyone that is listening, please feel free to join the OWASP group meetup.com/denver-owasp and find out about our next meeting. We're going to have a very exciting meeting in September featuring Jason Haddix.
So again, thank you for your time. I do appreciate it. Thank you so much for having me, Frank.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.