85°F

Aaron Parecki

  • Articles
  • Notes
  • Photos
  • Blaine Cook https://twitter.com/blaine   •   Feb 8
    Oh god. Was there an exec who moved from @united to @okta? @aaronpk what happened to make this a thing? 😭
    Aaron Parecki
    Ugh I know. The good news is the admin can disable security questions on the entire org if they want.
    Portland, Oregon • 39°F
    Mon, Feb 8, 2021 10:49am -08:00
    3 likes 21 replies
    • Blaine Cook
    • Nick Gamb
    • Owen Blacker
    • Gus Andrews twitter.com/gusandrews
      Fails in what way?
      Wed, Feb 10, 2021 2:19pm +00:00 (via brid.gy)
    • Gus Andrews twitter.com/gusandrews
      @jpgoldberg wanna speak to this? 😈
      Wed, Feb 10, 2021 2:18pm +00:00 (via brid.gy)
    • Blaine Cook twitter.com/blaine
      Identify users.
      Tue, Feb 9, 2021 7:34pm +00:00 (via brid.gy)
    • Jeff Lindsay 💀 twitter.com/progrium
      for me: letting people login. after working with/for okta and having to use okta ... it seems like every time i had to login there were problems.
      Tue, Feb 9, 2021 7:29pm +00:00 (via brid.gy)
    • Joël Franusic twitter.com/jf
      Okta employee here. Genuinely curious, as there are lots of possible answers to this question: What is Okta's one job?
      Tue, Feb 9, 2021 7:02pm +00:00 (via brid.gy)
    • Blaine Cook twitter.com/blaine
      What lesson should we take from 15 years of admonishing users to "just use a password manager" but failing to get better than ~30-40% adoption, and patchy success even from "successful" adoption?
      Tue, Feb 9, 2021 6:41pm +00:00 (via brid.gy)
    • Blaine Cook twitter.com/blaine
      Put another way: User research is always painful, but I can only imagine how excruciating it would be to watch a 1password or Apple Keychain or Google passwords user research session.
      Tue, Feb 9, 2021 6:40pm +00:00 (via brid.gy)
    • Blaine Cook twitter.com/blaine
      I haven't done a detailed analysis, but I'd estimate that Google's "suggest a secure password" doesn't work on 10% of sites, and is effectively hidden on 30-40% (i.e., I have to look for it, which an average user wouldn't do).
      Tue, Feb 9, 2021 6:37pm +00:00 (via brid.gy)
    • Blaine Cook twitter.com/blaine
      I despise 1password - I've tried, it fails way too often. I've taken to using Google's cloud password system, which is OK, but fails reasonably often - often enough that *I* end up futzing around with password resets for longer than is reasonable. Average users have no hope.
      Tue, Feb 9, 2021 6:36pm +00:00 (via brid.gy)
    • Gus Andrews twitter.com/gusandrews
      mental model problems are real tho frsure
      Tue, Feb 9, 2021 6:02pm +00:00 (via brid.gy)
    • Gus Andrews twitter.com/gusandrews
      uhhhhhhhhh so did you just reveal you don't use password managers? because I've been using one for years now with a setup not unlike that and I find it quite reliable ;)
      Tue, Feb 9, 2021 6:02pm +00:00 (via brid.gy)
    • Blaine Cook twitter.com/blaine
      (sorry, this rant brought to you by "don't apologise to Okta they literally have ONE JOB and a market cap of $36B and choose to do their job by shaming users" 😂)
      Tue, Feb 9, 2021 5:27pm +00:00 (via brid.gy)
    • Blaine Cook twitter.com/blaine
      If we start with that *instead of* starting with passwords, there are a bunch of solutions and approaches that make byzantine quests like "remember this random inconsequential thing so that we can trust you enough to reset this other random thing" seem *actively hostile*
      Tue, Feb 9, 2021 5:26pm +00:00 (via brid.gy)
    • Blaine Cook twitter.com/blaine
      We have this fundamentally distorted view that authentication is "username and password", but what we're trying to achieve is to answer two questions: 1. Who are you? 2. Prove that you are who you say you are.
      Tue, Feb 9, 2021 5:24pm +00:00 (via brid.gy)
    • Blaine Cook twitter.com/blaine
      ... not to mention unreliable or buggy auth systems (which are *extremely* common), or the struggle to form a mental model of how accounts work. So the real "question" is "I don't know my password (and it's not my fault), so please just let me in another way."
      Tue, Feb 9, 2021 5:22pm +00:00 (via brid.gy)
    • Blaine Cook twitter.com/blaine
      Password managers are deeply unreliable. Use Chrome on a Mac? LOL. Good luck. Use a service on both a phone and a desktop computer? Share an account with another person? Yeah, no chance.
      Tue, Feb 9, 2021 5:21pm +00:00 (via brid.gy)
    • Blaine Cook twitter.com/blaine
      100%. The big thing here is that we assume that people just forgot their password. But we also say they need to use unique, complicated, unmemorable passwords across literally hundreds of sites. So how the hell are they supposed to remember?
      Tue, Feb 9, 2021 5:19pm +00:00 (via brid.gy)
    • Jon Gilbert (한) twitter.com/jong
      Instead of "Forgot your password?", maybe sites should start asking, "Are you taking your password with you to your grave?" or "Have your mystical unlocking runes been lost to the ages?"
      Tue, Feb 9, 2021 5:18pm +00:00 (via brid.gy)
    • Gus Andrews twitter.com/gusandrews
      "forbidden password question" has much more allure 🙃
      Tue, Feb 9, 2021 4:46pm +00:00 (via brid.gy)
    • Gus Andrews twitter.com/gusandrews
      "forgotten password question" is kind of an awkward phrase in and of itself
      Tue, Feb 9, 2021 4:35pm +00:00 (via brid.gy)
    • Yoz Grahame twitter.com/yoz
      honestly, I wasn't being very fair to you folks with this one, hence this follow-up twitter.com/yoz/status/135…
      Tue, Feb 9, 2021 12:41am +00:00 (via brid.gy)
Posted in /replies using quill.p3k.io

Hi, I'm Aaron Parecki, Director of Identity Standards at Okta, and co-founder of IndieWebCamp. I maintain oauth.net, write and consult about OAuth, and participate in the OAuth Working Group at the IETF. I also help people learn about video production and livestreaming. (detailed bio)

I've been tracking my location since 2008 and I wrote 100 songs in 100 days. I've spoken at conferences around the world about owning your data, OAuth, quantified self, and explained why R is a vowel. Read more.

  • Director of Identity Standards at Okta
  • IndieWebCamp Founder
  • OAuth WG Editor
  • OpenID Board Member

  • 🎥 YouTube Tutorials and Reviews
  • 🏠 We're building a triplex!
  • ⭐️ Life Stack
  • ⚙️ Home Automation
  • All
  • Articles
  • Bookmarks
  • Notes
  • Photos
  • Replies
  • Reviews
  • Trips
  • Videos
  • Contact
© 1999-2025 by Aaron Parecki. Powered by p3k. This site supports Webmention.
Except where otherwise noted, text content on this site is licensed under a Creative Commons Attribution 3.0 License.
IndieWebCamp Microformats Webmention W3C HTML5 Creative Commons
WeChat ID
aaronpk_tv