46°F

Aaron Parecki

  • Articles
  • Notes
  • Photos
  • Aaron Parecki
    :sigh: another day, another website that hardcodes their @oauth_2 client secret in JavaScript 🤦‍♂️
    Oregon City, Oregon, USA
    #oauth
    Thu, Aug 1, 2019 10:36am -07:00
    10 likes 4 replies
    • Chris Burnell
    • 𝕄𝕚𝕔𝕙𝕒𝕖𝕝
    • Jan Boddez
    • Josh Roppo
    • Alex Marcus
    • Amirsh
    • Amine Mouafik
    • Leonidas Tsementzis
    • repeat
    • Jason Gerecke
    • Not Fake Adam Kalsey twitter.com/akalsey
      I once had to respond to a security audit that included a code scan. The scanner red flagged any variable called password or secret, or various misspellings thereof.

      You could store the password, you just had to name the field “donottellanyone” or something.
      Thu, Aug 1, 2019 5:58pm +00:00 (via brid-gy.appspot.com)
    • Aaron Parecki twitter.com/aaronpk
      not even 😭 the variable is called "client_secret"

      and worse, it's a bank
      Thu, Aug 1, 2019 5:56pm +00:00 (via brid-gy.appspot.com)
    • Not Fake Adam Kalsey twitter.com/akalsey
      But they base64 encoded it, so that’s OK, right?
      Thu, Aug 1, 2019 5:55pm +00:00 (via brid-gy.appspot.com)
    • 🌮 Dave Millar 🌮 puz.fun/@dave

      @aaronpk did they also use a DHTML script to block right-clicking so nobody can view the source of the page?

      Thu, Aug 1, 2019 5:38pm +00:00
Posted in /notes using quill.p3k.io

Hi, I'm Aaron Parecki, co-founder of IndieWebCamp. I maintain oauth.net, write and consult about OAuth, and am the editor of several W3C specifications. I help people learn about video production and livestreaming and dabble in product design.

I've been tracking my location since 2008 and I wrote 100 songs in 100 days. I've spoken at conferences around the world about owning your data, OAuth, quantified self, and explained why R is a vowel. Read more.

  • Security Architect at Okta
  • IndieWebCamp Founder
  • OAuth WG Member

  • ⭐️ Life Stack
  • ⚙️ Home Automation
  • 🎥 YouTube
  • All
  • Articles
  • Bookmarks
  • Notes
  • Photos
  • Replies
  • Reviews
  • Sleep
  • Trips
  • Videos
  • Contact
© 1999-2022 by Aaron Parecki. Powered by p3k. This site supports Webmention.
Except where otherwise noted, text content on this site is licensed under a Creative Commons Attribution 3.0 License.
IndieWebCamp Microformats Webmention W3C HTML5 Creative Commons
WeChat ID
aaronpk_tv