54°F

Aaron Parecki

  • Articles
  • Notes
  • Photos
  • Aaron Parecki
    This is a good writeup on some sneaky vulnerabilities in OAuth implementations, but ultimately is just a simple access token injection attack: https://salt.security/blog/oh-auth-abusing-oauth-to-take-over-millions-of-accounts
    Portland, Oregon, USA • 42°F
    Thu, Oct 26, 2023 8:50am -07:00 #oauth
    6 likes 8 reposts 2 replies 1 mention
    • Jérôme Scheer
    • Ben Scheirman
    • Torstein Krause Johansen
    • Mike VanDelinder
    • Royce Williams
    • 🎄Festive Dog🎄
    • Stevarino
    • Ben Scheirman
    • Axel Nennker
    • Simon Forman
    • Aaron Ogle :linux: :manjaro:
    • carpetbomberz
    • Scary Mary Branscombe
    • Ste Roughley
    • Scary Mary Branscombe bsky.app/profile/marypcbuk.bsky.social
      Is this why I’ve been sobbing about not getting token binding for years?
      Thu, Oct 26, 2023 4:38pm +00:00 (via brid.gy)
    • Aaron Parecki aaronparecki.com
      tl;dr: Don't accept access tokens in your redirect URI (don't use the implicit flow)

      PKCE solves this attack and is enforced by the server rather than relying on client developers to "verify the access token" as described in the post
      Thu, Oct 26, 2023 8:51am -07:00

    Other Mentions

    • aaronpk micro.blog/aaronpk
      This is a good writeup on some sneaky vulnerabilities in OAuth implementations, but ultimately is just a simple access token injection attack: https://salt.security/blog/oh-auth-abusing-oauth-to-take-over-millions-of-accounts
      Thu, Oct 26, 2023 8:50am -07:00 (via micro.blog)
Posted in /notes using quill.p3k.io

Hi, I'm Aaron Parecki, Director of Identity Standards at Okta, and co-founder of IndieWebCamp. I maintain oauth.net, write and consult about OAuth, and participate in the OAuth Working Group at the IETF. I also help people learn about video production and livestreaming. (detailed bio)

I've been tracking my location since 2008 and I wrote 100 songs in 100 days. I've spoken at conferences around the world about owning your data, OAuth, quantified self, and explained why R is a vowel. Read more.

  • Director of Identity Standards at Okta
  • IndieWebCamp Founder
  • OAuth WG Editor
  • OpenID Board Member

  • 🎥 YouTube Tutorials and Reviews
  • 🏠 We're building a triplex!
  • ⭐️ Life Stack
  • ⚙️ Home Automation
  • All
  • Articles
  • Bookmarks
  • Notes
  • Photos
  • Replies
  • Reviews
  • Trips
  • Videos
  • Contact
© 1999-2025 by Aaron Parecki. Powered by p3k. This site supports Webmention.
Except where otherwise noted, text content on this site is licensed under a Creative Commons Attribution 3.0 License.
IndieWebCamp Microformats Webmention W3C HTML5 Creative Commons
WeChat ID
aaronpk_tv