All episodes

Jason Haddix, CEO/Hacker @ Arcanum Information Security

Apple Podcasts Spotify SoundCloud

Our feature guest this week is Jason Haddix, CEO/Hacker @ Arcanum Information Security. We’re also trying something new with our interviews and Jason will be doing an Ask Me Anything in the #AMA channel on Slack. Head on over there to ask him any questions you might have! News from and a lot more!

Come join us on the Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Upcoming Events:

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript17744 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Equals Security. This is the newscast for episode 274. This is for May of 2025, right, Alex?

Is that right? That's correct. Well, the toughest part of the show, we're, we're full on into spring. It's getting nice out, a little rain here and there. You know, we got to expect another snowstorm or two, right?

Right. Yeah. Don't, don't plant your flowers yet. This is the Colorado Equals Gardening podcast telling you wait till Mother's Day to, to go plant your flowers. I did see that some of these storms that rolled through recently, there was a good bit of snow in the mountains.

So I think if you still want to ski, you can still ski. I love it. Get out there, ski and snowboard. And while we're talking about things that people in Colorado love to do, let's talk about Slack. There is a Colorado Equal Security Slack channel where we've got, you know, 2,000+ folks and we're kind of, we're kind of reviving this thing right now, right?

We are. And I'm looking forward to talking a little bit later in the show to one of the activities we're going to be doing this week. But we'd love to see you out there in Slack. If you're not actively engaged, get in there. Let's make sure we keep the conversation going.

And how do you join? So head over to the website. Actually made some reasonably significant changes to the website this week. So there's now a consolidated form for signing up for Slack and the mailing list. Also a few other things.

So make sure to poke around in there and find all the stuff that I screwed up and let me know about it so I can fix it.

Also, it'd be great if you rate and and subscribe to the podcast in your favorite podcast player. That way we get, you know, a couple more listeners on the listener count and we know how great the podcast is. Awesome. We'd also love it if you tell a friend about the community, get them plugged in with the podcast, get them plugged into Slack, get them coming to events in the area. That's what we're here for.

With that, let's do a thank you to our sponsors. We have a few annual sponsors now. Thank you, Armis. Thank you, CrowdStrike, Red Canary, and Zscaler. We appreciate your support.

All right, let's jump into the news. First story, we love the airport stories, Robb. And this one is actually about the rental car facility at the airport. There's a proposal to build a new $150 million rental car facility, which is a consolidated facility instead of the multiple car lot facility that they have today. Yeah, right now they're all kind of in a line out there a little ways away from the terminal.

They're looking at building this one big building where the employee parking is right now. It would allow them to have all of the companies in there have the ability to go from, you know, individual vans that currently run from the terminal to pick folks up and drop them off at the different lots to having one kind of a community or transportation solution and maybe even change the way they do that transportation. Yeah. Also for companies that have multiple brands like Enterprise and Alamo, I think are basically the same company. They can be co-located instead of having different facilities.

So all good stuff. The article does mention that this would save potentially 250,000 round trips per year. That's like a quarter of a million. That is like if my math is— if my math is right. Yeah.

It's getting late on a Friday, so I'm not positive about my math. Anyway, interesting story. It has to go through a committee with the city and then it has to go through the full city committee, city committee, and then it has to go through the full city council to be approved. So this is not a done deal at this point. But this is, you know, the new CEO CEO for the airport.

He's, he's passionate about this and he wants to get it done. Seems like a good idea, so hopefully it does. All right, moving along, we have a story. Oh, what is this one? Oh, this is about Denver's home situation, right?

That, you know, generally over the last— we've been doing this for 8 years— over the last 8 years, there's been a lot of stories about how tight the, the housing market is and how, how few homes there are to buy. What's this story say? Yeah, um, Denver is a leader in how fast unsold homes are piling up. So basically, yeah, yeah, inventory is increasing faster than homes are being sold. So that's kind of the opposite of what things have been for a long time.

Nationwide, the home inventory has been going up by about 32%. So all of the major metro areas are seeing more inventory, more home options. But Denver is more than double that with like 67%. Increase in inventory. This doesn't take us like you might think, well, this is great.

Now it's finally going to be easy to bargain down these sellers. Well, maybe not so fast. Yeah, it's definitely better than it was, but still below historic trends where historically the average over the last 4 decades has been about 13,000 homes for sale in Denver. Right now we're just under 10,000, like 9,700. So still below average, but way better than it was a year ago.

So you might be able to pay list price instead of paying over list. There's a funny quote in the article from a realtor who says, yeah, okay, home sellers, I know that you haven't— you know, you're going to have 40 offers on this house, but couldn't you please clean the bathtub? Like, maybe, maybe the sellers are going to do a little bit more work to sell their house. Yeah. All right.

Moving on to the next story. Boom Supersonic has chosen a new test site to test their— the engines for their supersonic planes. Uh, we have had several stories about this. Most recently, I think, was the, the test flight that they had for, uh, for one of their, their test, uh, jets, which went well. And now they're, they're building this test site in Adams County, uh, to, you know, really get going on testing these engines at the Air and Spaceport, right?

This was— I remember we talked about this a couple years ago when they, when they made it a spaceport, and they're like, yeah, it doesn't really mean anything now, but Maybe in the future. Well, here you go. This may be part of the future. So this is at the Colorado Air and Space Port, formerly known as Front Range Airport. That's right.

So there's a few stats in the article about the future. They have already sold a number of their, their jets, you know, for future delivery. And United was one of the big buyers, but they anticipate going live in 2029. And they say that in 2029, you should be able to buy a ticket from New York to London for somewhere between $4,000 and $5,000, and the flight itself will take, um, about 3.5 hours. So pretty good, right?

About the same amount of time as it takes to get from Denver to New York in the first place. Yeah. Uh, all right, moving on to our next story. A little bit of sad news here. Uh, the Denver coding school, the Turing School of Software and Design, is closing.

Uh, sort of, you know, a harbinger of the, the current economic conditions as well as the, uh, the potentially, you know, effects of AI on, uh, hiring for junior software developers? Yeah, there's some, some things that exacerbated this, you know, since, uh, you know, as AI gets, you know, much more widely used, there's this belief that it's going to more seriously impact coders than it is most other professions. And so there's a lot of companies that are slowing down on hiring coders, especially entry-level coders. And of course you know, these, these coding schools, that's what they generate, right? Entry-level coders.

Um, and you know, the, the, uh, owner of it has a, has a quote in here where he says, you know, there's something of a moral hazard where, you know, he's being paid to create people where he's not sure if those jobs are going to exist in the future. And I appreciate that he acknowledged that. At the same time, there's some exacerbation that when COVID came and, and, you know, everyone started working from home, touring actually went fully remote for their courses. They stopped using the building that were— that they had space in back in 2020. Well, over the last 5 years, they were in a lease and they've actually had to pay this rent.

They paid it through 2023. They stopped paying in 2024. And they, you know, they were sued by their landlord and ended up— the landlord won the lawsuit and they were, you know, handed this big, you know, almost half-million-dollar bill to pay back rent. And I think that you combine the decreasing enrollment the, the lack of a future for entry-level coders with that big bill, and they said this is just the time to throw in the towel. Yeah, I think as a general statement, it's going to be interesting to see how this plays out in our industry.

Um, you know, companies aren't saying they're not hiring, you know, senior developers, senior coders, but, uh, if you don't have any junior developers that get experienced and then become senior, eventually that pipeline is going to dry up. So I don't know how you go from not knowing anything to being a senior or experienced developer if there aren't any of those entry-level jobs available anymore? I mean, now we're just waxing philosophical. It feels to me like, by just the very nature of it, people will have to get better educations, right? Yeah.

What is it that they want from a senior developer? Well, they want someone who can accomplish some set of 10 things. Well, they're going to educate people to be able to do those 10 things. And I'm not saying it's easy. Maybe, you know, it's more apprenticeship-like.

Maybe, you know, maybe there's other ways that you get there, but it will get solved. It won't get solved in 2025 probably, but it will get solved. Yeah. I mean, in my experience, you learn fundamentals in education and then you get better at those and become experienced by doing things. And, um, that, that's not normally the, the role of education, right?

I don't know how you get from the fundamentals to being an expert at something without having a role of, of doing those things, uh, for a long time. And if you're not getting paid to do it, there's not going to be many people that do it because it's fun. Yeah. It's a, it's a hard question. Yeah.

All right. Well, there was a few other interesting stats in there. Uh, Turing had been, uh, had been going for like 11 years. I think 2014 they started, they've graduated 2,500 folks and made a big difference in those people's lives. Generally they had a couple hundred people in any given cohort.

And right now they were all the way down to 37 in the current cohort. So they're, they're going to graduate those 37 folks and then, and then that's when they're going to let it go. All right. Moving on to our next story, some other sad news. Everyone's favorite dialysis treatment company, DaVita, made an announcement a couple of weeks back that they had been the victim of a ransomware attack, which I think that they are still not fully recovered from.

And we have a story in here talking about that as well as a link to DaVita's 8-K that they had to file, uh, which is notice of a security event. Yeah, I don't know a ton about what DaVita's been through over the last few weeks. Uh, I, I do know that the good news is they've been able to keep patient operations running and, and patients are being seen. Patients are getting the life-saving care they need. That's the great news.

I've heard rumors that, you know, systems internally are not working great, that folks, you know, they've— they shut down email for a while. They They shut down a lot of other systems as they were kind of containing this. I don't know where they are in recovery. I'm sure those folks have had a really tough month of April and, you know, look for them. I hope that hopefully they're, you know, getting some coffee and getting some time off to keep going because this is a long incident at this point.

I'm sure they're getting pretty tired of it. I'm sure that they are. Yeah, we wish them the best. Get some rest. Hopefully this is over soon with the best possible outcome.

All right. Jumping over to update about the— there is an update that has been proposed for Colorado's AI law. Right. Last year, Colorado was the first state in the nation to pass an AI law, an AI regulation. Well, this year, a week before the end of the congressional session, they proposed an amendment to that.

Alex, what's the amendment look like? Yeah. So the amendment has a couple facets to it. One, The original timeline for implementation of these regulations was 2026. This would push that out to 2027.

And one of the other major provisions was the original law applied to companies with 50 employees or more, and this would change the requirement for that to be 500 employees or more. Yeah. So pretty big changes. So the article in the show notes goes into, you know, what's the positives of this? And then there's some pretty serious opposition to this.

I would say that the opposition isn't to the amendment, but really to the thing it's amending. There's not a lot of— these folks are unhappy with the level of expectations that would be on the tech companies and maybe make Colorado a less attractive place for tech companies to work. A lot of expectations on transparency with the end users and how this works. I'll say, you know, you mentioned that, you know, pushing out the effective date of this another year. I'm of two minds about that.

On the one side, it would be better if we weren't trying to jam in these changes a week before a session ends. On the other hand, like, AI is coming now, right? If you're talking about implementing regulation 2 years from now, I think we're a non-factor at that point. If there's something worth doing, it probably needs to be done this year. I don't know how you get there.

I don't know that a special session makes sense for this, but man, if we're going to do it, we got to be ready to go. Yeah, something more along the lines of a slower ramp-up, you know, some of the provisions go into effect sooner and then others go in later. Uh, who knows, but hopefully it gets ironed out. All right. Well, our next story, moving over to the security blog section here, we have a blog from Red Canary around cybersecurity metrics that matter.

Um, and, and this is, I'd say maybe not so much cybersecurity metrics, but really specifically SOC metrics or security operational metrics that matter. Yeah. And, uh, there's a good bit of this blog that talks about the fact that sort of traditional ways to measure security operations effectiveness is around mean time to something, mean time to response, mean time to containment, other things like that. And this is, you know, talking a good bit about how maybe that's not the best way to measure these things. Just because you do something fast doesn't mean it's effective, doesn't mean you're really accomplishing the things that you want to accomplish.

Yeah, it's interesting. He talks about, you know, all those mean times generally are focused on dwell time. How long are they in the environment before? But what was the second type of metric. Was it breakout?

Is that what it was called? Uh, yeah, I believe so. So basically, how long are they— how long are they in the system is dwell time. And then breakout, you know, how do they go from that initial foothold to getting else, you know, pivoting in the environment and starting to really understand, yeah, it sucks that they're sitting on that one endpoint, but there's not a lot they're going to do from that one endpoint. All right, when they start to move from that, that's when it gets really interesting.

And that, that visibility, trying, trying to get measurements that make it that can tell you how well you're doing at preventing that might be a useful thing as well. Yeah, so they go into a good bit of depth talking about quality metrics, not just beyond timeliness. Things like accuracy, you know, how many false positives and false negatives are you detecting? You know, volume, how many threats are coming in and how many of those turn into actual incidents? And, you know, can you get the, the things that don't turn into incidents down so that you only are paying attention to things that really matter, as well as timeliness, and really more around detection and things like that, which is important.

Yeah. Anyway, good blog post. Like, the Red Canary blogs are almost always great. We appreciate them putting those out there. With that, let's move over to an Optiv story.

This is about a model for SASE, SASE, Secure Access Service Edge, the kind of the one of the new buzzwords in security. Basically, the idea that you know, you're not defining the access of your— the edge of your environment based on firewalls, but it's really based on where people access from. And it's maybe it's a little bit more dynamic, it's more flexible than the old, you know, static environment. But SASE is the new hotness for how do you define that access. Yeah, and SASE also generally has, you know, multiple capabilities in one platform, uh, so you can do multiple different, uh, security capabilities as part of that whole service edge.

Yeah, they say that the 2 core elements of SASE are the WAN service edge and the security service edge. I think as you, as you dive in more, there's a lot more capabilities like secure web gateway, cloud access security broker, you know, cloud firewall. There's, there's quite a few other capabilities, but at the height, it's, you know, connecting all of your environments together and then securing the edge that you just created. Yeah, and some of the highlights from the article, you know, they kind of have 4 key points. One, talking about rolling this out, having alignment with business objectives.

Obviously, that's key for any initiative that you're doing. Second, getting, you know, a comprehensive assessment before implementation, figuring out what it is that your goals are. You know, of those capabilities that are in a SASE platform, you know, not all of them may be your primary capabilities, and knowing which one of those ones you're trying to achieve is is important. Doing a phased implementation, again, multiple capabilities, so thinking about how it is that you're going to roll those out. And then obviously continuous monitoring and optimization.

Once you've done that initial deployment, going back, making sure it's effective, rolling out additional capabilities so that you have a great SASE implementation. Good stuff. All right, let's move on to our next story. We've got a blog post from Laris. This is focused on ransomware.

And, you know, ransomware has been big for 15 years, maybe since the— what was it? Cryptolocker. That was the first one, right? Yeah. Um, it's been a big deal for quite a while.

Uh, this blog post just kind of starts with what does ransomware look like right now? They throw some stats out there that 76% of companies who've experienced ransomware had data encrypted during the attack. 46% of the companies who had data encrypted paid the ransom. Of that 46%, an average of 63% of the— well, of the people who paid the ransom, 63% of the data was returned, restored. We don't know exactly what that means.

Does that mean that 63% had all of it restored and 37% had none, or everyone had something but not all of it? We don't know. But it's an interesting stat to say 2/3 of the people who paid got their, got their data back. 30% of ransomware, um, where encrypted— sorry, 30% of ransomware where stuff was encrypted also had that same data stolen. So it wasn't just encrypted, it was taken offsite.

Multi-pronged kind of attacks. Yeah. And finally, the most common way for stuff to get in there, 30% of the attacks were through email. That was how most of them got in there, or not most, but the biggest minority. This blog also takes a bit to break down a specific ransomware attack.

In this case, they use WannaCry as the example. Um, and then they give some, uh, best practices for you to aid your recovery. And, you know, these aren't going to be earth-shattering, um, but, you know, good recommendations nonetheless. I think, you know, with ransomware, if you are doing fundamentals really well, you're going to be preventing a lot of ransomware attacks— things like backing up and user training and being able to recover. All right.

Uh, let's move on to our final story, which is from Ping Identity. This is talking about, uh, why strong digital identity is essential and how it relates to Executive Order 14144. Alex, what is Executive Order 14144? Uh, Robb, I am glad that you asked. Uh, this is a fairly recent executive order, um, and it talks about the need for improved digital identity verification, fraud prevention, and secure authentication measures.

The blog post goes into some depth about how the executive order and some of these things relate, but also, you know, maybe why you should be doing these things whether or not this executive order exists. Yeah, I feel like Ping Identity does a good job of staying on message here, like a good politician. They're looking for opportunities to talk about, you know, in this new world with AI, in this, you know, world where folks are attacking online, you need to verify who you're talking to with a high degree certainty. You know, just recognizing a voice on the other end of a Zoom call may not be enough anymore. Yeah.

You know, what does that look like to get new verification? How do you get risk-based decisions about who— how confident am I about who this person is? And, you know, of course, Ping offers those solutions, and they're tying it back to a very timely piece of news. Good stuff. All right, let's move over to our calendar events.

Obviously, we're going to talk about some of the events here in May. But if you want to see the full calendar of events, you can go over to the website and check it out there. Lots of good stuff all the way through the end of the year. Uh, first on the calendar, on May 7th, uh, ACES, the physical security organization here in town, uh, is throwing their Colorado Corporate Security Symposium. This is an all-day event, and there is at least one cybersecurity track in that, so you might want to check that out.

Yeah, we'll crash that event. On the 13th, ISSA Colorado Springs has their May chapter meeting. On the 14th, the Let's Talk Software Security group is doing Is Using AI Really That Insecure? On the 17th, ISSA Colorado Springs has their mini seminar. That's that Saturday morning few hours of training where you can get some nice CPEs.

Also starting on the 17th and going through the 18th, ISSA Denver is, is sponsoring and hosting a ISC² Certified Cloud Security Professional, the CCSP, exam preparation. So folks who are looking to take that test can go sit with our friend Mike Pedrick, who's going to be doing this. There is a charge for it, but if you're looking for the cert, this could be a great way for you to get that certification. On May 20th, LIFT, which is the women in security group associated with the Cloud Security Alliance here, is doing, uh, the first in their hiking series for this summer, hike number 1. So if you want to go hiking, check that out.

Take a hike, Alex. It's at 5 PM. I looked it up to see what time it was. It is at 5 PM. On the 27th, ISC² Denver is holding an event.

It is Enhancing Privacy and Security in the Age of AI-Driven Social Engineering. On May 28th, ISC² Pikes Peak is doing their monthly chapter meeting. And also the 28th through the 30th, um, we've got obviously the, the biggest security conference of the year, uh, the Rocky Mountain Information Security Conference. So if you haven't registered for that yet, you should do that and, and go check out all the good stuff at RMISC. And since we don't know when we'll be recording in June, let's go one more event forward.

On the 6th of June, ISSA Denver has their event, How ISO 20045 4001-24001 aims to promote trustworthy AI. You want to learn about AI and what trustworthy AI looks like? That looks like a good meeting for you. Sounds exciting. Well, that's it for, for the news, but we do have an interview this week.

I'm actually really excited. You know, we have Jason Haddix on the show. Jason, great tech guy who moved out to Colorado, what, 4 or 5 years ago? Excited to talk to Jason, but we're also kicking off a new, a new Colorado Equal Security kind of hybrid thing. So we're gonna, you know, Frank is gonna talk to Jason here in the interview.

You can learn about Jason. And then when you think, man, I'd like to know more about his answer, that's perfect. Come over to Slack, join the Slack community, and in the AMA, the Ask Me Anything channel, we're gonna have Jason there ready to answer your questions. Yeah, so this will be a little bit async. I think for approximately a week or so, Jason will be available.

To, uh, to answer any questions that you might have. So go post them in there and, uh, and look for the answers. Excited about that. Awesome. Well, that's it for this week.

We'll, we'll talk to you guys next month. It will be in June. Holy smokes, it's going so fast. Almost summer. We'll talk to you then.

Thanks, Robb. Hi, this is Jesse Dubin, IT manager for the city of Wheat Ridge. Welcome to Colorado Equals Security, for Colorado security professionals by Colorado security professionals.

What good morning, good afternoon, and good evening, State of Colorado. My name is Frank. This is the Colorado Equal Security Podcast. I am a guest host, and today we are lucky enough to have a local star with us, Mr. Right, and I know people don't usually call you Mr., but Mr. Jason Haddix with Arcanium.

If you don't know who Jason is, if you live in the state of Colorado and you don't know who Jason is by now, I have to ask the question is, what cave have you been living in, right? I mean, no, no, I mean, uh, it's, it's nice to be part of the community and be appreciated, but, uh, we have a lot of talent in Colorado, honestly. We do, we do. And, um, but Jason, you know, you have my very dear gratitude myself, Vince, and everyone else from the Denver OWASP board because of the contributions you made to our SnowFROC conference. So anyways, how are you today?

I'm, I'm doing well. You know, we're, we're getting ready to head into RSA time, and that's always a, you know, a crazy time because you're presenting, you're volunteering. And so there's just so much going on next week. So we've just been preparing building tools, building CTFs, building, or like getting our talks ready and stuff like that. So it's been quite the week.

Well, in case you don't know who Jason is, right? Jason is the CEO, CISO, right? He is a former CISO for not only Arcanium, but for many other companies. He's been a director of operations, head of global security. I can keep going on, but we would spend the next, what, hour just reading off all his titles and all the things that he's done.

So Um, before we get started, I have a very big tradition here, Jason. I'd love to throw an icebreaker out there. And to be absolutely honest to the crowd here, Jason does not know what this question is going to be, right? No. Okay, Jason, if you were in the Olympics, what sport would you compete in, right?

And how would you fare? Um, you know, when I was in high school, I played football, but the offseason sport was track, track and field. And so, you know, like most football players, I did discus and shot put, and I really enjoyed discus a lot. I wasn't super great at it, even at the high school level, but I just thought it was fun spinning around and throwing the disc and always was a good time in the offseason just to be doing something with the team. And so I'd probably do discus and, you know, Olympic discus throw.

Yeah. Now, are we talking regular diskettes? Are we talking more like the disk of Tron type of stuff? You know, I am a huge Tron fan. In fact, it is one of the things— actually, let me see if I can grab it here— is, uh, one of the things when you go to DEF CON is, uh, you know, badge life.

And this is one of my favorite badges I've ever collected right here, which is the Tron badge from, um, this is from a company called Ironwood Cyber. So this came out 4 years ago and I'm, and I'm such a big Tron fan that I have set up— I didn't get an opportunity to buy it 4 years ago at DEF CON and Ironwood Cyber builds these badges that are amazing. It like lights up and does all kinds of cool stuff. It has integrated games and everything like that too. But yeah, see, here you go.

Okay, well, so I'm a huge Tron fan and when it came around on eBay, I had set alerts up on eBay to find it. If anyone ever sold theirs. And I paid a pretty penny for this badge. So that's how big of a Tron fan I am. So let's, let's say Tron.

Yeah. Okay. Well, let's, let's ask this kind of thing since we've, we've kind of mentioned RSA off because RSA, would we call that the premium conference in the United States? Or, or, right, would we compare that more to DEF CON? And I know that I am telling you we're comparing apples to oranges or possibly apples to, you know, cars or something like that, something absolutely ridiculous.

It's fine. Yeah. So they are, they're similar and different. They're both cybersecurity conferences, right? So in the summer, you have what we call Hacker Summer Camp, which includes BSides Las Vegas, DEF CON, and, or Black Hat, and then RSA.

That all happens the same week. It's about 10 days in a row of conferences if you go to all of them. And that's the Vegas Hacker Summer Camp. We've been calling it that for years now. For most of us, we actually get 2 of these summer camps.

We, we, we get— we don't get summer camp, but we get like early, you know, quarter 4 camp basically. And that is the RSA week in which you have BSides San Francisco on the weekend, and then you head into RSA for the rest of the week. Now, the difference between the content, the, you know, the content of those shows is, is, you know, highly different. So RSA is more of a vendor-focused show with a huge expo hall. They actually fill both sides of Moscone Center's expo floor, which is giant.

So security vendors all out there trying to sell their stuff or demo their stuff to people, make a splash. But over the years, RSA's talks and villages, which they invite village people, you know, like the Red Team Village, AI Village, the Cloud Village, you know, same kind of villages that go to DEF CON, has been getting more and more technical, honestly, in the talk and in the kind of programming. So I actually really enjoy RSA. It's in San Francisco and not Vegas, so that's a nice switch up. And it's just another opportunity for me to see my friends who I've worked with at every company that I've been to, right?

Because everybody's gonna be in San Francisco for that week and have dinner and we're presenting and having a good time and stuff like that. So where it's— but it is very much more businessy than where Black Hat and DEF CON are much more hackery. So I'm— and I'm on the board for Black Hat, so I'm gotta keep it hackery. Gotta keep it hackery. I will.

Do you think we lose something in these more business type of things when we go to these conferences and we say RSA and Is that there, and I've only been to RSA once, but RSA is getting more businessy, right? And then we go into Black Hat, and if we compare Black Hat and DEF CON, some people will say is that Black Hat is more def— more businessy.

Where does that belong in, in a skill if we're looking at our entire, you know, quote, cybersecurity lifecycle, and we look at all our tiers? Yeah, I mean, I think, I think they both have their individual, like, merits, right? I definitely do think that Black Hat and DEF CON are definitely more hackery. And so if you're going to learn the latest techniques or you're going for some, you know, awesome free training, because there's a lot of free events that happen around DEF CON and Black Hat that you can just drop in on, that is definitely the place to be for, you know, technical knowledge. And I would say more people consolidate on going to DEF CON every year than probably RSA, right?

So you'll, you're more likely to see your friends or people who you look up to giving talks and stuff like that. So RSA and RSA is definitely more businessy. There's a lot more analysis talks, you know, by, you know, leadership and, but there's, you know, they are, they are succinctly trying to, or they are desperately trying to add more programming that is technical. So more and more of the RSA schedule is very technical talks, which is really great. So that's really nice.

And then BSides San Francisco, which happens before RSA, so that actually happens this weekend, Saturday and Sunday, is one of the best BSides I've ever been to. It is highly AppSec focused. So everything about application security, defense and offense, It is one of the— they always choose the best speakers for this con, and it's inside the Metreon Theater in San Francisco. So you see these talks on giant movie theater screens. It's really comfy to sit in the movie theater chairs.

You get movie theater snacks and watch people present about topics you like. And so that's the one that we go to first, and we'll be doing the Bug Bounty Village there. I'm a big participant in bug bounty and And yeah, so, uh, we'll be running the Bug Bounty Village at, uh, BSides San Francisco. So, but how would you compare that? How would you say is that, let's approach this from somebody that's in their mid-level career, right?

And they've been hands-on keyboard and they don't know where they want to go with this. Do they want to go in the more businessy side? Do they want to go on more technically side? And you've kind of answered that a little bit. But what about cross-pollination, right?

Like, do you believe that— can you be a full hands-on keyboard person and not really do any of the business stuff? Or on the other side, right, be on the businessy side, more on the risk and talk about controls and talk about threats, but not have any hands-on keyboard experience? And I know this is going to be a very, very touchy subject. For all involved, and I think especially for you and I. Yeah. Yeah.

I mean, I think that, I think that once you have been in the industry for a little while, you realize that you, you can never just be hands on keyboard, right? There are always portions of our jobs like reporting and communication to developers and other stakeholders in the business. Like security doesn't exist in a vacuum. So, you know, like no matter how much I would like it to exist in a vacuum and just use my tech skills that I think are super cool and fancy, I'm never gonna have that opportunity. And in fact, in my career throughout going from super technical, then into leadership and then back into technical, I have found that sometimes those non, you know, hands-on keyboard, you know, technical skills or, you know, some of those non hands-on keyboard skills are the most valuable skills that I have in, you know, my arsenal really.

Communication, writing, presenting, storytelling, Um, you know, all that kind of stuff. So relationship building. Yeah. Okay. So if I've been a hands-on keyboard person and I want to go and say, how do I make myself more valuable to the company?

Right. We can say, well, okay, attend these conferences, but what specifically? As, as you know, uh, with RSA, with, I'm assuming B-Side San Francisco, with SnowFROC or any of the conferences that are out there, and notice I always have to throw my conference in there, right? But, but notice, what would you say is gonna be the most value and impact for that person? Yeah.

So going to these conferences, you know, can be daunting for a new person. I would say that every year I make a point to go to these, these 2 ones. There's the, you know, the Hacker Summer Camp with DEF CON Black Hat and RSA Week. I just feel they're the best networking opportunities. In fact, I have 3 mentees coming this year with me to RSA Week and BSides Week in San Francisco because the hallway, we call it hallway con, right, where you get an opportunity to meet people and talk to people.

Hallway con is the best networking you can do. And both conferences have excellent hallway con. And you can do it on a budget too. So the BSides ticket for admission, I mean, it's not nothing, but it's definitely not a big ticket like Black Hat or RSA. So you can just attend, you know, BSides, and they have a wonderful area, you know, on the, on the patio where like a lot of people just chill and talk about security, not even in the talks, right, at the movie theater.

And then for RSA, they have the expo floor, which is, like I said, it fills up Moscone Center, both sides of the, you know, the basement convention center. It is huge. Like when I say huge, you, I mean, unless you've been to a big vendor thing before for another job or something like that, you have never seen how big The vent, you can't imagine how big the vendor floor is. I mean, I have been to dozens and dozens of conferences. Yeah.

And I will have to say, I absolutely agree with you there. While some of these conference halls are great, I've been to that one in Moscone Center. And I think the best word I can describe initially would be overwhelmed. It is very overwhelming. Yeah.

Yeah. Even Black Hat doesn't stand up to what is at RSA. Yeah, yeah, yeah. And, you know, so, so going to that, you can get an expo ticket. A lot of vendors get expo-only tickets that are usually— they run like $200 to $400 if you want to buy that outright, or maybe even more these days.

But a lot of vendors give those away because they get, they get several of them that they can give away as raffle, you know, things or whatever. So most of my mentees who are coming are just getting an expo pass so they can just go to the business floor, you know, but that's where everybody is congregating anyway unless you really want to see a specific talk. And then they have like this advanced ticket that you can get that's more than expo, it's called Expo Plus, and that gives you access to the villages. And the villages actually, I think, are one of the coolest parts of RSA. The AI Village, the AI XCC project led by DARPA is going to be there this year.

There's the Cloud Village, the Cloud Village I'm speaking at, releasing some tools and doing a talk. There's like 4 or 5 villages in this village space and there's a satellite area to present that kind of has smaller presentations that are kind of on the bleeding edge of, you know, different topics. And so I love that area too. So even if you just spend a little bit more on an Expo+ ticket, you can get into that like sandbox area and village area. And I spend a lot of my time there.

So, and for new people going, right, it's, we talk about this a lot. We do a class called Hacking Your Career here at Arcanum. And we do this class, we talk about, you're like, well, how do you network, right? And then, you know, really it just happens to be right place, right time where you have to put yourself into places and positions that, you know, that are gonna be advantageous to you. So, you know, if you're a threat hunter, and that's what you really want to do, or a DFIR person or whatever, right?

Go watch the satellite talks at that. Go talk to the vendors that are in that space. Hang around the booth, you know, look at their demos, talk with them about their capabilities. You'll start making these relationships. Talk to the speaker after they get off stage, ask intelligent questions.

And this is, you know, the start of building relationships that ends up to networking. And then you never know where it goes from there. So, well, I mean, I I was— of course, you gave your hacking your career at SnowFROC, I believe twice, right? Yeah. And I remember that trying to go into there, I couldn't, right?

Uh, because I couldn't even open the door. I mean, conference, and, you know, hopefully there's nobody from the fire department, but we, we couldn't even open the door. We were breaking some rules, and Julia was okay with it, so I was okay with it. Yeah, but it was Absolutely amazing. And the feedback I got from that class was incredible.

Oh, awesome. Very good. But my question for you though is, and, and I'm going to lead into a very explosive type of question here, is how important is it for to network and to build these relationships? Because you mentioned hallway con, you mentioned, you know, just hanging out sometime. I know what the value is, but let's talk about that for a little bit.

Yeah, I mean, you know, I was just talking with a friend of mine the other day. Luckily, he just landed a job, but he was on the job search in the cybersecurity kind of realm for, I wanna say, about 6 months. And he had runway. He had, you know, some money saved up so that he wasn't, you know, in any type of trouble or danger or anything like that. So, you know, he was comfortable, but many people are in situations where they're not as comfortable.

And they need to find, you know, like a job or whatever. And we were talking about this, and one of the things that we were saying is that since we're in kind of a recession right now, in the US at least, there are cyber jobs. But what's happening is that they're mostly getting filled by referrals. Like, not many of them are making it to your LinkedIn job postings or your Indeed job postings. And then when they do get there, at least from my experience when we've hired at Arcanum, You get thousands of applicants, like thousands, and it's really hard to go through all of these, and everyone seems very qualified.

And so what I tell my students is like, don't forego that part of just applying to roles that you think look cool. But more likely what's gonna happen is you're gonna meet somebody at a con, you're gonna meet them at a meetup, you're gonna meet them hallway con, you know, whatever. And you're gonna have an interesting conversation. They're gonna understand that you're passionate about this thing. And then when the time comes around, if they have your contact information, they might contact you and be like, hey, or you can contact them and be like, hey, you know, I'm still looking for a role if you hear of anything.

And you might get access to apply to a role that hasn't even gone out to the job market yet. And this is what's happening a lot in cybersecurity right now, right? Like, I have, I have a lot of experience in the gaming industry. I was the CISO at Ubisoft, and, and I, I hear of recs or job openings all the time, but they're private. They're, they're private.

And, you know, people just like, do you know anybody who has this skill set? We want to work with a cool person. We don't want to go through, you know, like, whatever. So it ends up being a referral of some sort. So, yeah.

Okay, well, let's— I mean, and again, I know that you have plenty of experience with this. So do I. But one of the things that gets people into this space, or makes the people in this space, or however we want to call it here, is that they're introverts. Yeah. What advice could we give to the introverts that are listening to this podcast, assuming that they're listening at all?

I mean, believe it or not, I am, um, I am also most of the time an introvert, even though I do podcasts and I talk at conferences and stuff like that, I tend to think of myself as a charged battery. And after I'm done teaching or after I'm done on a podcast or doing a talk or whatever, my battery is run down and I need some introvert time. You go to the hotel and chill or, you know, whatever. So it is possible to force yourself through those situations for some people, not everyone. Now, if you're an introvert and you're going to a con, it can feel very isolating sometimes when you don't know anyone.

I usually love going with a friend, right? So if you know somebody else who's in the cyber field and they want to take a couple days and go to a con and, you know, hang out, and so you don't feel so isolated, and, you know, having your security wing person there can be amazing. So have you introduce them to people, both go off on your own for a little while, come back, you know, mingle with people you've met. But like I said, I think some of the coolest things are Or like the easiest ways to get involved is anybody who's there for a village or a talk is there to disseminate knowledge and teach, and they have to be pretty passionate to get up in front of people on stage to like do a talk, right? And so that means that they want this information to get out there.

They're excited about their tool or their topic or whatever. And so just go up to speakers after, you know, they like— don't mob them as soon as they get off stage, but like wait till they got out and then like ask intelligent questions. Say, hey, I really like your research. You know, a lot of times, you know, people who speak, you know, want to collaborate on research or need help or whatever, like offer that. One of my mentees, I met him and he offered to moderate our Discord because he knew Discord a little bit.

And he was like, hey, I see that you have this Discord, but it's kind of run amok. Do you, you know, do you need any help with that? And I was like, I absolutely do because I'm not good with Discord. If you could teach me. And he's like, well, I can teach you and you know, like, I can run it for you.

And so, you know, he ended up just kind of hanging around, like, and just being around. And so everybody knew who Ryan was, you know, at some point. And then I started introducing Ryan to people, and then I'm like, okay, well, let's make this official. Like, you'll be one of my mentees, I will train you, you'll come to all the courses. And then, you know, he got a job in security, and he, he's one of those success stories where he was, uh, before security, he wasn't— he was driving Uber, right?

He, he new computers, but he wasn't even in IT. He went straight from like a driving Uber job, and then before that, I think, you know, he wanted to get into welding, to being a pen tester basically. Went, you know, like skipped, you know, the whole IT part, but is a great pen tester. So, so yeah, there's opportunity there, and he just hung around, like he was everywhere. He was in Discord, he was coming to conferences, you know, he was offering to help with projects, you know, if I needed research help or anything like that.

And so those are the type of people that when they're around you all the time, they get opportunities because, you know, people want to help people who help them. So yeah, yeah, absolutely. And, you know, one of the things that I'm very, very proud of is that I've helped over 20 students, 20 people coming into this industry, get that initial foot in the door and I think that's one of the things I have a reputation for. Um, I myself are a bit of an introvert. I, I know it doesn't sound like it, but I am quite a bit of an introvert.

So I fully understand when, you know, probably when I get done with this podcast, I'm gonna go sit down in an isolated room and just be by myself for a little bit, right? Yeah, exactly. Yeah. But I want to go back to something here, and this is very, very important. Something that you had said is about that passion.

Right? Because I always like to say is that, you know, what we do within cybersecurity, right, is not a job. In fact, a lot of times it's not even a career. It's more of a way of life. How do you feel about that?

I mean, I definitely think it's correct what you're saying. I hate, like, I mean, there's definitely like a a difference in kind of my boomer perception of, you know, like what, how I think about my job and how kind of modern research says you should treat a job, right? So I wanna put that out there that this is my learned experience and that nobody else has to take my advice or whatever because it's not healthy to only have one piece of your identity, you know, like being cybersecurity and that's all you are. But for me, I realized very quickly that offensive security was my passion. I love the, I love the magic of, you know, breaking into something, feeling a little bit like a bad guy.

I love, you know, the tricks, the whole, the whole, you know, discipline is based around tricks, you know, learning, you know, learning these different tricks, different misconfigurations to break into systems. And so I knew right away that that was my passion. And so I could put you know, instead of your, your common 8 hours, I could put 10 to 15 hours a day sometimes into work, unquote, right? Whether it's free time projects or actual work for my full-time job. Um, and most of us end up in this place, at least, at least I would say 80% of my friends who are very successful end up in that place where they do put a lot of time into the security domain, whether it's through their work or through individual projects or research or speaking or just trying to keep up with everything that happens because the whole domain is, you know, moves so fast.

And the very successful ones are always researching. I am always researching. I mean, I have, you know, feeds open right now. I'm, you know, parsing, you know, so, but, and so you'll get far, but, you know, you also have to watch out for things like burnout and things like that. So I don't wanna tell everyone that's the, that you have to be like that.

But one of the things we talk about in Hacking Your Career Right is if you are If you are doing this and you don't have any previous experience, it's the hardest way to get into the industry if you don't have any previous experience. And so you do, at the beginning of your career, have to invest some of your free time usually to build a portfolio, just like an artist does. We talked about like artists and, you know, how they have to have like video content and, you know, drawing content and paintings and exhibits and stuff like that. As a security person, you have to have that too. You have to have like a GitHub where you're showing people that you're doing, you know, open source projects.

You might need a blog to post your opinion on things or show your learning journey, or, you know, you might do YouTube or you might do whatever. And these are the type of things when, you know, I'm a hiring manager and I'm hiring for a role, it's the first thing I do, right? Because I'll look at a resume and usually it ticks a couple boxes for me, and then I'm immediately Googling that person. And what's gonna come up is their GitHub or their YouTube or their LinkedIn or whatever. And I'm gonna see what they're talking about, and I'm gonna see if they're investing the time in, and to see if they're passionate, as passionate as I am, you know, in this thing, because I want to work with other passionate people.

So although it might not be the healthiest thing, I do think that, you know, at the beginning you invest a lot of your free time into it and it is a big part of your identity. So yeah. Well, let's address that. I mean, I've got 2 notes on that, but let's address the first one is I always recommend to everyone that I meet, to anyone that ever asks me for any advice, solicited or unsolicited, right? Is you've got to have something non-technical in your life as a hobby.

You do, yeah. Something outside of that. And if you don't mind sharing, do you have anything like that? I do. I mean, well, first of all, I have 3 kids, so it takes up a lot of my free time.

Right. But they're amazing. And I would say being a parent is the hardest and best job in the world. Absolutely agree with you. Absolutely.

I mean, the swings are crazy. Like someday it's like, it's like I'm doing this right. I, you know, everything's great. My kids are happy. We did things together.

And then, you know, other days it's like everything's falling apart. But, but yeah, so that takes a lot of time. I can definitely relate, Jason. Okay, great. Great.

1000%. And that is like still daily for me actually. Yeah. Yeah. But I mean, my passion has always been video games.

So They, like the video games I play are very data involved, right? So it's not just like, I don't just play like shooters, like I play the most complex, you know, role-playing game, not role-playing games, but action RPGs. So I play Path of Exile, which is one of the, you know, the most complex like Diablo type games that you can play, which involves min-maxing gear and, you know, doing strategies. So there's a lot of research involved to be at the upper echelon on that game. And it tickles my brain in the same way that security does.

And it's fun. I get to play, you know, something and for a while just turn off my brain. And so I've always loved video games, not only for the act of playing them, but also about the community that they bring. I feel like it's like an underserved discussion a little bit is when you play video games, normally you're playing with like your friends and it's friend time. And I've had some of the most deep and meaningful or funny and memorable conversations and times with my friends over Discord just playing games, right?

Where it's low stakes, everybody's just, you know, hanging out, doing a, you know, if you're playing WoW, you know, doing a dungeon or something like that and just, you know, talking about your day, giving life advice, you know, telling funny jokes. And so I think that the community that you build around gaming is really powerful, especially for young people who struggle with social anxiety and stuff. You can find your tribe through gaming. So a lot of people frame that badly in the gaming world or in like the, you know, social media world that we live in today. But I actually think it's a tremendous value to young people these days.

And, you know, when we were kids, there was no option to do anything professionally in gaming. Now there is. You could be a streamer, a content creator, you could build games at a video game company, you could stream on Twitch, you could be a professional esports player for the game that you like. I also like that it gives, you know, like the kids these days have more options than ever to be involved in gaming as their, you know, kind of primary thing. Okay.

All right. Well, and I think that's good advice. What about anything physical? So myself, I have taken up biking, right? Just cycling, nothing crazy.

Couple, you know, 10, 20 miles a week, something like that. Yeah. And I try to make sure that it has nothing in front of a keyboard, right? Right. Let's just be honest.

One of the bad things about being in cybersecurity is that you are sitting all the time. You're inside most of the time. It doesn't have a lot of great health benefits. It does not. No.

So I do— I mean, if you're around in Colorado and you do airsoft or paintball, those are my 2 things. When I was a kid, I remember going out and doing paintball. My dad's friend at his work actually was a— he was a semi-professional player back when paintball was really big. And he was like, hey, come out and like watch this tournament, to my dad. And my dad took me and I was like, I have to do this.

So I've been, you know, I've been paintballing since, you know, I was in high school and then more recently got into airsoft as well. And I really enjoy physical activities where I don't, like, I don't realize I'm working out, right? So those 2 are very like that for me where, you know, I get a great workout. I'm outside all day and I don't even realize that I'm, you know, I'm really working out. I'm so involved in the activity.

I'd recently picked up in the backyard here a couple of disc golf baskets and some discs. And this year I plan to make a concerted effort because we have some amazing disc golf courses here in Colorado to go do some disc golf. So that's, that's on my agenda too, just to get some light walking in. And yeah, so that's, those are the kind of physical things I do other than just working out as well. I have a home gym at home.

I try to lift every once in a while, but yeah, so. Okay, well, let's go back to the other thing I kind of wrote down here because— and something that you were saying about blogging, YouTube, things like that. I mean, we, we have introverts here. Yeah, people that might be not coders, not writing, those kind of things. And one of the things that I always suggest is that, okay, maybe you're not that type, maybe you don't need to write a program, right?

But maybe, you know, contribute in the way of showing how a tool works, how, what the benefits are, because I think a lot of times what happens is that we show stuff that isn't that relevant. And, and what I mean by that is last night I was teaching Nmap, right? And we're going through Nmap, but it's like, you know, the most important part about Nmap is not running the tool. But the results of the tool. And can you demonstrate, how would you feel if they, instead of writing that, a new tool, a new module, anything like that, they just simply wrote, hey, I used Nmap and here's what I found, right?

Why I found it and then what we can do. Because that data feed is really what we want as hiring managers, as people in the field. It doesn't matter. I mean, anybody, we can teach someone how to run Nmap in what, 30 minutes, 20 minutes, something like that. Yeah.

But where the value is gonna come is afterwards. Yeah. I mean, it's a good observation. I think that there's a lot of, there's a lot of broken kind of training cycles that don't align to what job roles actually need, right? In the industry.

So one thing is that like any training that you take, Except for mine, of course. But any training that you take is, you know, it's probably already, you know, like the tools and techniques that you take in that training are probably already outdated by new open source tools that do something better by the time you take the training, right? So like you take your Nmap example, right? Like Nmap is not the fastest port scanner anymore, right? There are several others that are way faster.

There are several others that have different extensibility other than the Nmap scripting engine. And so, like, there's that side of it where you are expected to, you know, keep in the know about, like, the newest tooling. And then also, like you said, not a lot of people talk about, like, what you do after you do a port scan, right? Which, which is kind of this institutional knowledge that most people learn on the job. You know, so if you're a pen tester and you're doing Nmap scans, it's like you're, you're there with your team and let's say you're a junior and you just started and you just got into this, right?

Like, well, you've used Nmap before in CTFs and you've used Nmap at school maybe, and then you get into the job and they're like, cool, here's the Nmap output. And you've never seen an Nmap output for an enterprise network. And it's, first of all, it's huge. Second of all, there's services on there you've never heard of before. You know, like you don't really have any idea kind of what to do with it.

And that contextual, like what you do with the part you write is really important. Um, I think that's, uh, you know, I think that there's more than ever, there's, there's more options for training these days that where people are trying to pivot to that more about the institutional knowledge, giving that away than just the like, um, CTF style, because that's what most new people grow up on is, is challenges or CTFs or, you know, some lab on the internet. And what that does is like, uh, in the web world, I'm very active in the web hacking world, it's like What'll happen is you'll get a student who has finished all of the open source labs on the internet, and they've done a bunch of CTF work. But in all of those, they were basically shown exactly where the vulnerability is via the challenge, right? There isn't very much exploration to find the vulnerability.

It's just like, you get given a page, you know, there's a vulnerability here, and you have to exploit it. In the real world, the hard part is actually going to an enterprise-level website, breaking it down into components and understanding where the vulnerabilities will be, that's 60% of the job, right? It is not like you just land there and you're like, oh, this thing's going to be vulnerable. And it's the number one thing I hear from new web testers. They're like, oh, I started web testing and I had no idea where to start.

Like, I knew the vulnerability classes, I knew how to do injection, I knew all this stuff and I had done all these labs. But then I got onto an enterprise-level site And there's hundreds of parameters of traffic going across on the backend. This is something we try to address in our classes. We talk about heat mapping an application, breaking it down into components and understanding where vulnerabilities are most likely going to be. We do data analytics on where certain web vulnerabilities will be as far as their parameter names or path names.

That doesn't mean it's always going to be vulnerable, but it definitely gives you a place to be like, cool, I see this parameter name, I need to check it for XYZ because a lot of times this parameter is vulnerable to XYZ. So I think more and more people are getting to those things, but it is an underserved area, I would say. Well, okay, and I have to respectfully disagree with you only because when we are shown that vulnerability, I mean, I actually tell the students when they go through things like the TryHackMe or any type of job, Go ahead and go straight to the solutions, right? Especially if they've never done this before. Now, where the value is, though, is that they should be taking great notes, hopefully rewriting things again, and then they should do it a second time, right?

They should do it a second time, and this time hopefully off their notes, and then the third time, because we know that reputability, right, is going to build that knowledge and seeing what you can find. So Yeah. I think investing that time, making sure that you are doing it again and again and again. Right? Yeah.

I mean, I don't think, I don't think, I don't think we disagree, honestly. I think that, I think that all those online labs, the TryHackMes, the WebSec Academies, the, you know, HackTheBox, whatever, wherever you're learning, right? Like, these are valuable resources and you should be doing them. I don't agree, you know, there are some companies in this industry, training companies who have that try harder type mantra. I actually don't believe in that at all.

I am more on your side where, you know, like, this is a whole— even if you take that small domain, web hacking, right? There is so much to learn in web hacking when you're starting from zero. And I don't care if my students go, you know, I don't care which way they learn. I don't care if they learn via me talking, via watching video, or via doing it on their own. And then as a subcategory to doing it on your own, I don't care if you watch the solution first, and then learn how to do it through the solution guide and then repeat it.

I don't care. Everyone has a different learning style. I'm definitely not one of those try harder, bang your head against the wall type people. But yes, I don't think we disagree at all. I think that there's absolutely something we do in our classes is we'll have a lab, we'll have solutions to the lab linked.

If you want to go look at them, you can. But if you want to just— if you do like that try, harder kind of mentality, bang your head against the wall, you can do that as well. So I think everybody learns differently. So yeah, well, I think we have to do all of it, right? I mean, I don't think that, you know, again, Jason, I know you're an absolutely wonderful speaker.

I've watched many, many of your videos. Um, but I think you have to do listen, watch, and you absolutely have to do that hands-on 100%, and then go back to watching the video And possibly leading back to what we were talking about before, write up what you found, right? Yeah. I mean, that's, that's been a huge, huge part of my career is writing things down like you're talking about is, you know, some of, I mean, my most popular talks that then turned into one of my classes is called the Bug Hunter's Methodology. And it was basically me learning how to do bug bounty, which is a, a harder version of web testing because you're up against big production sites that have been assessed by pen testers already.

Um, and it was me cutting my teeth on doing that and just taking a bunch of notes and consolidating them into, you know, what then was a huge Notion database. And then I had my Notion database, and then I turned that into a conference talk about tooling and techniques that were modern for web testing. And that turned into my biggest talk that I ever did in my career. And I went back and updated every year. So the Bug Hunters Methodology is kind of one of the talks I'm known for.

And every year I update it and represent it as a new version. And it has been one of the biggest successes of my life. I've, you know, I still keep up to date. I managed to take notes still on my Notion database. And then I turned it into a course to teach other people like more than just what I could do in a couple hours at a talk or something like that.

So, um, I am a heavy believer in taking notes and then also after you take the raw notes, building a methodology for yourself, a mental model of how to approach things in a step-by-step order. Or a lookup table where you see a certain thing and you can go look it up and be like, cool, here's my steps to look, or the things to look for here, and here are the steps to do them. So I'm a big believer in that. Well, I think we, and we agree on that. I think the only thing I want to add in there for especially anyone that's learning, which by the way should be everybody in this career field, right?

Yeah. You never stop learning. What I say is choose a path, try to learn, and if it's wrong, accept the failure, accept that you didn't do it right, and learn from it and do it again. And I think that sometimes we have to set ourselves up to expect that failure. Yeah.

And know that, hey, we're not going to get it right the first time, we're not going to do it right. But what we can do is poke, prod, um, make a path forward, and then, and then turn around and say, okay, Now let's take that lessons learned, right? That famous phrase, lessons learned. Yeah. Try to feed that back into the cycle.

Yeah, I think it is also— that is also one of the things I look for is as a hiring manager now and previously at different— at other jobs hiring pentesters and that is like I said, you know, like blogging is, you know, important. Oh, excuse me. Sorry. Um, blogging is important and documenting your journey is important. And when I see someone who's talking about, you know, okay, you know, this week I'm doing HackTheBox whatever X, and, and they're blogging about it and they're like, at first I didn't understand this, I didn't get what's going on, I couldn't exploit the challenge, I failed, whatever.

And then they write about how they did research and they overcame the challenge and eventually they figured out the thing. Those are actually more More impactful, you know, blogs that I care about because it shows that they have problem-solving skills that, you know, they can execute things on their own and, you know, and figure it out. And so those blogs I actually enjoy the most, even if they're on the most simple of vulnerabilities, right? Your first cross-site scripting attacks, like, oh, well, I didn't really know how JavaScript worked here. I didn't really understand, like, when I put this text into the web page and it reflects, like, why does it do that?

You know, why is a popup important? And, you know, and then like some of them blog about, well, actually it isn't important. The popup isn't important at all. It's just a way for us to show it was there. But, you know, real JavaScript attacks I learned can do these kinds of things.

And so I love those types of articles. So if you're new and you're watching the, you know, the podcast, you know, like those, those go a real long way if you're documenting your journey like that and you're humble and, and you talk about your learning experience. Yeah. Well, that's where— and in my classes I always refer back to that. I guess it's technically a kids movie, but Meet the Robinsons, right?

Where— oh yeah, yeah, you have that thing. And boy, we're old, man.

We are, we are, absolutely. But, um, sorry, I tried to stop laughing about that. But there's a scene in there where the kid fails and everybody cheers, right? Yeah. And everybody's celebrating and he's down on his luck and he's like, oh, why are you cheering?

It's like, because you learn more from failure. And I have to say, I fully agree with that. Yeah, be proud of that failure. And the most important thing is let's learn from it. Yeah.

And don't give up. And that's where if you are that introvert, right, or you are in that hallway con, that is a perfect conversation to bring up with people, right? Yeah. I mean, I, I have to tell you that I've sat at DEF CON just by myself. I was trying to figure out something and I was becoming more and more frustrated.

I was doing that whole, you know, bang your head or try harder thing. 3 guys came up and were like, oh yeah, here's how you can fix it, right? Yeah, here's how we can do it. And that's where I think that the cybersecurity community is very, very giving, right? Yeah, there's a lot of people willing to help new people, I think, especially in this new wave, I think, of cybersecurity.

I feel like maybe when I was growing up, it was a little bit more adversarial. But, but yeah, I feel like nowadays there's a lot more places you can get mentorship and help. And, and yeah, those things, even mentorship and help, lead to, you know, networking and other ways to, you know, make friends in the community and you know, find a role somewhere. Yeah. And I think that's though the perfect reach out, right?

You know, one of the things that I don't like when people approach me at conferences, I mean, I'm a very open person. One of the things I don't like is when they walk up to me and the first thing they say is, are you hiring? Right? Yeah. Yeah.

And the second one, and I have to tell you my own pet peeve, which is absolutely infuriating to me, is take me under your wing. Yeah. Yeah. Mostly because I think that while the cybersecurity community is very giving, it's also very self-motivated. Right?

Yeah. Yeah. It's, it's interesting. My buddy Daniel Mesler, he wrote an article, I want to say a couple of years ago about ways to solicit mentorship. And those are 2 of the things that he said don't do, especially with like really known people who have put a lot of research already and are speaking at conferences and stuff like that.

You don't wanna just go up to them and be like, can I be your mentee? Right? Like, that's not gonna work. You know, like, that's not how friendship happens. I think Simon Sinek does a great, does a great talk on this too about mentorship.

And mentorship is more of a friendship actually. It's the willingness of 2 people to become friends, you know, exchange ideas. You know, some ideas, you know, are at first they flow one way very intensely, you know, but over time you become peers and, you know, so people don't, People don't really want a mentor. They don't want to like, they, you know, they probably want more of like a colleague or a friend or a partner or something like that. And so that's how mentorship relationships really, you know, when they do flourish, that's usually how they happen, right?

So most of my mentees, like I said, offered, you know, they're just around, offered to help when they could. They weren't overbearing about it, you know, and then I offered my mentorship to them when, you know, when I realized that they could use it or need it or whatever. And so You know, that's, that's something that you can, you can learn as you, as you kind of get into this. Yeah. Well, that's how I got into this, right?

Robb and Alex were asking for people to help out with the podcast. Yeah. And, you know, while I'm a pretty senior level, right? I mean, I still learn stuff from them, right? So, oh yeah.

And I mean, Robb's awesome. So that's, that's, that's awesome. You know, the, the other thing too that I don't know if we explicitly mentioned, but all of these conferences we're talking about that happen Um, are opportunities for you to network, but they're also opportunities for you to volunteer, which is a type of networking. And so, um, you know, the best site I know of personally to monitor all of these cybersecurity conferences is this site called InfoSec Maps, infosec.maps. It's, um, it's run by a friend of mine, Martin, and, um, he has a whole team and all they do is monitor Twitter and the web to find out when the next BSides is, you know, and it's, you can basically put in your area code or you can put in your dates and it'll tell you all of the security conferences from small to large that are happening in that place.

And so that's an opportunity for people to like go volunteer some time, help run a village, help check people in or whatever, get to know people. And everybody at those conferences is a security person. So that's an opportunity to kind of get in there. And it can be a very structured way to do it, which helps with people who have social anxiety. Society because it's like, okay, today you're the, you know, today you're the speaker wrangler.

You're just gonna like make sure the speakers have everything they need, or today you're, you know, hallway monitor, or you're, you know, giving out tickets and badges, or, you know, any of the other million things which you know a lot about to run a conference, right? You need volunteers for those things. Yeah. Well, but so first off, is it infosec-maps.com?

That might be it. Yeah. Let me, let me look. All right. But because that way we can make sure we get it in the show notes.

It is, it is infosecmap.com. Okay. So no dash, no dash. Infosecmap.com. Yeah.

Okay. And then, you know, and I agree with you though, that I tell a lot, especially a lot of my students, is that you're actually going to get a lot more value out of a conference by volunteering than you are listening to the talks. Because let's be honest, some of our talks are going to be a little bit over their head, right? They may not get they may not have that base or that core knowledge. Yeah.

But being able to even go get a bottle of water for that speaker or making sure that, hey, I left my power cord or something along those lines. Yeah. I think that that will help build that relationship as well because most of the people, let's say 95-99% of the people that are going to these conferences are usually very helpful. Oh yeah. Probably either they're introverts or used to be introverts.

And they've been in that same position, so they understand what was like to try to get in. Yeah. Yeah. I, I think that you will find these days that there is a tremendous amount of people willing to help if you just, like I said, put yourself in the right places. And I, if you're part, if you're listening to this podcast, you got to go to SnowFROC.

So SnowFROC is one of the best OWASP conferences I've ever been to. And I've been to a lot. I've been to all the regionals. I've been to ones in California when I was in California. I've been to the DC ones, the New York ones, the Seattle ones.

And SnowFROC OWASP is an amazing, an amazing conference. So there's an opportunity for you to volunteer here with Frank who runs it and his stellar team. But there's also other conferences, many satellite in this area in Denver. There's many BSides. So BSides Denver is making a return this year.

BSides Boulder is a great one. It's small, but it's great. There's a whole bunch happening this year that you can get involved with. So absolutely, absolutely. Thank you for the shout out.

I appreciate it. I do want to make sure though that SnowFROC is not just me. We got Lily, we got Alex. Yes, the whole team is amazing. Yeah, we've got lots and lots of people out there.

I may be that kind of figurehead out there, but It would not be successful without the rest of those people there. Yeah. We are coming up to the end of our time. We've actually exceeded a little bit here. That's totally fine.

Yeah. I have until 1 hour time. So yeah. Okay. Well, Robb and Alex says I only have about an hour.

We're going to break that a little bit here. Okay. I always like to end with the same type of question though. And this is going to be a bit of a loaded question here. What is the greatest challenge for security today?

And how might you address it? We're not saying solve it. What we're gonna say is, how are you going to address it? Let's call it out right now.

Yeah, I mean, I think that, I think that just in general on multiple facets, cybersecurity is outnumbered.

In one facet, as part of an organization, there are usually anywhere between— in a very mature security organization, security-focused organization, the ratio is 5 developers to 1 security person, which is not a great ratio when you think about like the amount of auditing and code, you know, review we have to do and, you know, all kinds of stuff like that. And at a, at a non-security-focused organization, it can be 50 to 1 or 100 to 1 sometimes. Which just means that there's not enough people, which we talk a lot about this, like, you know, we need more people to help with, you know, a lot of the, you know, a lot of the work we do. But the problem is, is that security is often, you know, like a lower or middle served budgetary item for an organization, and they don't really want to do it until, until, you know, they really need it, right? Either for compliance reasons or because they've been subject to a breach or something like that.

And so you're outnumbered, you're under budget, you know, you're under budgeted for your, you know, the security program usually at most places. You're trying to make the best with what you have. So, so that's one of the hardest problems is like, how do we, how do we fix that? And then the other one is we're also outnumbered with just like the amount of iteration from, you know, real bad guys out there, right? Like, they move very fast.

Like, real threat actors, if you've ever been part of like a like a nation and like, you know, fought against a nation state trying to break into your network, which believe it or not, I have at a video game company, which is crazy. But you have to have like a very hard— or you have to have a very up-to-date skill set and very up-to-date staff and a forward-thinking security policy. And all those things like are very hard to upkeep. Like a lot of times you draft a security policy and you draft a security program and build your team and then it stays stagnant and you're not learning And, and so, yeah, I think those are 2 of the biggest problems. Now, how do we fix them?

I would love to say that we could scale our small teams really well with tools like AI or, you know, and I'm not talking about replacing people. What I'm talking about is augmenting them to help them scale, which is what I'm all about, right? First of all, anyone who tells you that AI is going to replace all our jobs is absolutely wrong. I am on the cutting edge of this technology right now. It's not replacing anyone.

It is definitely augmenting people. It is definitely making them faster, better, you know, able to research more quickly, giving them capabilities they didn't have before. So that's really cool. And I'm hoping that we get to that area. But the knowledge that we talked about earlier, you know, that's only in the heads of practitioners that have been doing this for so long and pass that down to other people.

And so, you know, a lot of AIs won't fix that. You know, then you look for automation too, like opportunities for automation or, you know, invisible security guardrails. And so one of my things is that I think that there's going to be a maturation really soon. It's already happening right now in Silicon Valley, but the role of security is no, you know, it's transitioning away from being this department that audits things and delivers output of reports and vulnerabilities to other people to fix to these days, especially in Silicon Valley, but now it's starting to transition everywhere, is you're going to have to be a developer too. You're going to have to know how to fix things yourself.

You're going to have to know, even if you can't fix things yourself and you're not a developer, you're going to have to be code literate, which when I started, that wasn't a requirement. You could know how to script, but you didn't know how to fix the application. Mostly you use your scripting to build tools to find vulnerabilities. And this is pivoting very quickly to, you know, when people hire, they look at your resume. And if they see the kind of same old thing as like, oh, this person's a pen tester, and yeah, they know how to do all the pen testy things.

And that's cool. That's great. That probably fulfills the role requirement if it's a pen tester job. But if it's, if it's a small company that, you know, is trying to get more for, you know, their hire, and they see that you have secure coding, you know, you've taken some secure coding courses, you know about certain languages and frameworks and protecting them using, you know, either architecture protections or library protections or custom code protections, you know, you've built security features before, you know, or at least helped build security features before at different companies, those people are infinitely more hireable than just your generic kind of audit and assessment people. These days.

And so I think that we're starting to pivot to that. I think it's a good thing actually, even though I'm at the tail end of it. I'm not a primary developer. If you put me on a development team, I wouldn't be able— wouldn't be much help, at least right now. But I am code literate.

I can read code, I understand what it's doing, and I understand the security patterns in code no matter what the language because I've been doing it for 20 years. That's not easy to displace. But those are the problems I see. I also see another one that's related to kind of what you and I do. And I know we're going over here, but I just want to talk about it is the number one question we get when we have a table like at a conference like SnowFROC is people who are entering the industry from a different industry or students, right?

From, you know, you know, MSU or whatever. And they'll come up to the table and they'll be like, oh, you're like, it looks like your company's cool. What do you do? And we'll tell them and they're like, and then we'll have a conversation, be like, what are you doing? And they're like, oh, I'm a student, I wanna do cyber.

Okay, cool. Like, what do you wanna do in cyber? And they're like, oh, I don't know. I'm like, how do you, what do you mean? Like, so what do you mean when you say you wanna do cyber?

And they're like, well, you know, we had like an OSINT class, we had like a, you know, a web application assessment class and a forensics class. And those are the 3 electives I took at my college for cyber. And like, I could do any of those, or I just think it's kind of cool. And then I'm like, did you know that there's like, you know, has anyone told you that there's like 50 distinct roles and, you know, maybe even more inside of cyber, right? Like, and they're like, no, I, you know, all I've ever done was like a little bit of forensics or a little bit of testing or a little bit of, you know, whatever.

And so, you know, students come into this not knowing that there's so much more. You can be like a detection engineering person. You can be like, you know, obviously DFIR, you know, SOC analyst, you know, There's different level of SOC analysts, um, you know, there's threat intel, there's exposure management, there's, you know, cloud configuration and architecture, you know, there's, there's so many sub-components of security and students come in and they don't even know, um, and, uh, and so a little bit more education, you know, for peop— from people who are, you know, working with these students around like, you know, understanding the world of cybersecurity And how many different roles are they and what do they actually do day to day? Like when you sit down in the seat as a threat hunter, what are you doing when you go to work? It's like, okay, here's what you're doing.

You're probably using one of these 5 tools, open source or closed source. You're looking for X, Y, and Z patterns. You're reporting them, you know, when in your off time you're doing, you know, these types of things. And there needs to be more of that, I think, in the educational system. I feel like personally.

Well, yeah, absolutely. So, wow, we covered a lot with that. One of the things, though, that— because you mentioned this here about change and things like that, I'm going to give myself a shameless plug here. One of my research papers is reframing the Pyramid of Pain because I look at it the way it's traditionally taught with this— hackers are having a hard time doing this, this, and this. I don't believe that at all.

And honestly, I don't think that's that relevant. I think that what's more relevant to us is our pyramid of pain within corporate society, right? And in trying to get things changed, right? Like, okay, well, how do we change our own TTPs? How do we change, you know, how we do our detection engineering so that it becomes that value?

Because I do agree with parts of the pyramid of pain that, hey, IP addresses are easy to find. What do you do with it? Who cares, right? I mean, I can find one, who cares, right? What do you do with it, right?

So, um, but I do want to get back into a very loaded subject, and I know we're over time, but I know you have a little bit time here, so we're going to break the rules. Uh, Robb announced may yell at me later, but let's throw caution to the wind, or, you know, whatever we want to call it here. All right. And being code literate, right? You mentioned that piece in there because I am not a programmer, but I am code literate.

One of the things that I tell people is that, do you need to know coding to get into cybersecurity? No. Will it hurt you later? Yes. Would it give you an absolute advantage inside cybersecurity just reading the code, not necessarily writing it?

Yeah. What do you feel about that? Because, you know, one of the things I told them is I don't write a lot of code. I steal it off of other people, or, and by the way, that includes you, Jason. All right.

Yeah. So I 100% agree there. I mean, I mean, nowadays with the AI tools we have, I can write a lot more code than I used to, but at a very low level, at a very early level, you know, I started with bash scripting. And this was after I got the job. So I was one of these people that wasn't super code literate.

And then I, you know, bash scripting helped me do network pen testing in my early career. And then I moved into web testing, which I needed to instrument a lot more, like browser automation, stuff like that. So I had to learn a little bit of JavaScript. And when I talk— when I say a little bit, I'm, you know, go take the free Codecademy courses, right? Like, or, you know, there's a bunch of free, like, small JavaScript classes you can take on the internet for, like, you know, no money or whatever.

And so I took those just to get literate. Now, I'm never going to write production-level JavaScript. But now I understand, you know, how variables are declared and like how functions are managed and how a production pipeline works in web applications with JavaScript and, you know, minifying and all this stuff. And so that really helped me. As far as, you know, a scripting language that's more functional, Python is obviously very, very much used inside of the information security scene.

And I did it the wrong way. I did get some of that exposure, but then I kind of let it atrophy. But from doing so many web tests, I ended up by osmosis kind of learning bad patterns in code from just being exposed to it through assessing things all the time or just looking at code. And that was the wrong way to do it. I wish I would have taken more of a— like a little bit more of a structured path.

Now these days, I'll pass a blog to you in the chat right now, but I did a newsletter. I run a newsletter, but one of our newsletters was called The Big Bad Source Code Issue, and I talk about code literacy in here and how it's a superpower for everyone in cybersecurity. And there are, I think, let's see here, there are 10 different completely free secure coding resources here that are run by different companies. To get you started to understand the paradigms in secure code, at least for web stuff. It's not binaries or anything like that, it's mostly web stuff, but stuff like Snyk Academy, Secure Code Warrior, Code Bashing by Checkmarks, Hacksplaining, Contrast, Veracode, Contra, they all have these secure coding dojos that are absolutely free and they do this to give back to the community, but also You know, like, they're secure code companies, so they gain a little bit of press from having these types of things out there.

But they're great to get started with this code literacy problem. I highly recommend. I'll give you the link. People go check some of these out. They're completely free, and you can work on them in your free time.

Yeah. Yeah. Well, I mean, we'll make sure we get that into the show notes, right? So that we don't have to, along with the infosecmap.com. Yeah.

Get into this. To the show notes and make sure that, of course, everyone knows about it. Any final thoughts though, Jason, before we close out? You know, I wish we had 3 hours to talk, honestly. There's so many topics I thought we were going to talk about in this podcast that we didn't even get to yet.

So, you know, this was more— I think this one's more structured around like getting into the industry, what the industry is like, and, you know, tips and tricks around all that kind of stuff and thoughts about training and Which is absolutely a wonderful topic to talk about. So maybe I'll just have to come back and we'll, you know, we'll do another episode on, you know, things like AI or offensive security or whatever. But, but yeah, I mean, I would— my wife would kill me if I didn't promote us a little bit. So we are Arcanum Information Security. We do a whole bunch of consulting services like AI pen tests.

We do AI automation assessments for organizations. We do regular pen tests, web, network. We do red team assessments and purple team assessments. Pretty much your standard consulting. We do all that.

And it's me and, you know, my ragtag team of former bug bounty hunters. We're really good at it. And then we also do trainings. So we have several live trainings and prerecorded trainings that we do on using AI to further your career, attacking AI-enabled systems, and then modern web application assessment through bug bounty hunting. So Check us out at arcanum.com or arcanum-sec.com is our website.

And yeah, and you can join any of those. So, well, I have to tell you that I have the deepest appreciation for Julia. Right. I think that she is absolutely wonderful. I introduced her to my wife, who, of course, I think is absolutely wonderful.

I do want to take a second, though, since we're on the subject here, to all the InfoSec professionals that are out there that are married. Turn to your significant other, your— whether that's a wife, a girlfriend, your family, and thank them a little bit for supporting you. I think that that is going to be very, very important, uh, because I have to tell you, after being married for over, you know, very multiple decades here, right, it cannot be easy to support somebody like us, right? Oh yeah, yeah. I mean, our ADHD, our our passion for the industry and the time we have to put in to make ourselves good at it.

It all does come from somewhere and that time comes from somewhere. And so your significant others and your partners, they end up supporting you a lot. Luckily, you and I have 2 great ones. So we're lucky. And Julia works with me at Arcanum.

She's the head of Chief Operations Officer. Yeah, it's, it's an amazing journey. And, you know, there's also some days where we get done with work and we're just like, okay, no more security talk, either of us, for, for like, you know, for at least a couple hours. Yeah, yeah, yeah, yeah. No, no, fully understand that one.

Or sometimes it's like, let's not even talk. Let's just go be introverts by ourselves. Yeah, yeah. I mean, my wife plays some games on her phone too, and we just, you know, we'll be in the same room. We still love each other, but, you know, we're doing our own thing and just decompressing.

So yeah, yeah. Well, again, thank you, Jason. Um, I— of course, the, the guest list is actually chosen by both, by Robb and Alex. However, I'm pretty sure that they're gonna have to want you back here because this has been, I think, an amazing, amazing podcast, and we'll have to do this again. Yeah, absolutely.

Yeah, I mean, whatever they say is cool, but, uh, but yeah, I would love to come back. So Awesome. Well, then, thank you, Jason. Again, my name is Frank. I am the Vice President of the Denver OWASP chapter.

Vince Pascal is actually the president. We can find out more about us at meetup.com/denver-owasp.

We also have the SnowFROC website. That's snowfroc.com website. That's our annual conference. Would love to come and meet you or have you come to our meetups. There's absolutely no fee and we do protect your information.

We do not share your data with anybody. So bonus, a lot of the meetings are at Dave Buster's. So fun place to hang out too when you're done with the OWASP meeting. Absolutely. In fact, actually, when we go to the meetups and we set these up, we have a 1-hour presentation, but we reserve the meetup for 3 hours.

So that you have 1 hour before and 1 hour after to just do that networking and gain and build those connections with people. You can build a lot of connections over skee-ball or, or some video games, you know? Absolutely. All right. Again, thank you for your time, Jason, and have a good one, sir.

Awesome. Thank you. Great trip out to RSA. Thanks, everybody. Learn more about the Colorado security scene at coloradosecurity.org.

Colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes