53°F

Aaron Parecki

  • Articles
  • Notes
  • Photos
  • Aaron Parecki
    Yet another example of why SMS is terrible for 2fa and account recovery.

    "the database — running on Amazon’s Elasticsearch — was configured with a Kibana front-end, making the data within easily readable"

    https://techcrunch.com/2018/11/15/millions-sms-text-messages-leaked-two-factor-codes/
    Chicago, Illinois, USA • 39°F
    Fri, Nov 16, 2018 3:23pm -06:00 #security #sms #2fa
    7 likes 9 reposts 2 replies
    • Jan Boddez
    • Debbie Goldsmith
    • Christopher Lemmer Webber
    • Mandar 📲
    • Tak Loufer
    • Felix Petzel
    • Thomas
    • Didier Raboud
    • Syam Kumar
    • J Λ H N Ξ R T Z
    • Nelson Pavlosky
    • Federated Republic of Sean
    • Debbie Goldsmith
    • Christopher Lemmer Webber
    • William Borix
    • sander micro.blog/sander

      @aaronpk had to make the case against sms 2fa this week but nowadays a simple websearch for the phrase returns mostly negative articles so it was easier than expected.

      Sat, Nov 17, 2018 9:36am +00:00
    • Christopher Lemmer Webber octodon.social/@cwebber

      @aaronpk You and I have had some conversation recently about the degree to when we do and don't want to use bearer token systems (I think we're both for them in some cases/ways and wary in others? but the division seems unclear), and the frequency of DB leaks may also be a good indicator in some places

      Fri, Nov 16, 2018 9:26pm +00:00
Posted in /notes using quill.p3k.io

Hi, I'm Aaron Parecki, Director of Identity Standards at Okta, and co-founder of IndieWebCamp. I maintain oauth.net, write and consult about OAuth, and participate in the OAuth Working Group at the IETF. I also help people learn about video production and livestreaming. (detailed bio)

I've been tracking my location since 2008 and I wrote 100 songs in 100 days. I've spoken at conferences around the world about owning your data, OAuth, quantified self, and explained why R is a vowel. Read more.

  • Director of Identity Standards at Okta
  • IndieWebCamp Founder
  • OAuth WG Editor
  • OpenID Board Member

  • 🎥 YouTube Tutorials and Reviews
  • 🏠 We're building a triplex!
  • ⭐️ Life Stack
  • ⚙️ Home Automation
  • All
  • Articles
  • Bookmarks
  • Notes
  • Photos
  • Replies
  • Reviews
  • Trips
  • Videos
  • Contact
© 1999-2025 by Aaron Parecki. Powered by p3k. This site supports Webmention.
Except where otherwise noted, text content on this site is licensed under a Creative Commons Attribution 3.0 License.
IndieWebCamp Microformats Webmention W3C HTML5 Creative Commons
WeChat ID
aaronpk_tv