53°F

Aaron Parecki

  • Articles
  • Notes
  • Photos
  • Aaron Parecki
    I'm a big fan of using more secure two-factor authentication methods like a security key or TouchID, but I will admit I never expected charging people to use SMS would be a viable strategy to get them off it πŸ˜… https://blog.twitter.com/en_us/topics/product/2023/an-update-on-two-factor-authentication-using-sms-on-twitter
    Portland, Oregon, USA • 43°F
    46 likes 6 reposts 12 replies
    Fri, Feb 17, 2023 9:26pm -08:00 #security #2fa #mfa #twitter
  • Aaron Parecki
    I've given many talks about how mobile apps can't be deployed with a secret, and using Twitter's 2013 "hacks" as an example. I'm just going to leave this completely unrelated string of random characters here for no particular reason

    GgDYlkSvaPxGxC4X8liwpUoqKwwr3lCADbz8A7ADU
    Portland, Oregon, USA • 43°F
    100 likes 52 reposts 10 replies
    Thu, Feb 2, 2023 8:12pm -08:00 #twitter #oauth #security
  • Aaron Parecki
    PSA: If you use Twitter to sign in to stuff, you should double check you have another way to get in to those accounts asap. With Twitter charging ??? for API access next week, you have no way of knowing whether the apps you use are going to pay that.
    Portland, Oregon, USA • 49°F
    140 likes 139 reposts 11 replies 5 mentions
    Thu, Feb 2, 2023 4:23pm -08:00 #oauth #twitter
  • Aaron Parecki
    It's been a while since I've set up an Amazon Echo device. Do I need to come over there and teach some Amazon folks about the OAuth Device Flow? There is a better way than making me type my password on this screen!
    Portland, Oregon, USA • 45°F
    44 likes 8 reposts 4 replies 1 mention
    Fri, Jan 27, 2023 9:20pm -08:00 #oauth
  • Aaron Parecki
    It's here! My new video course "Advanced OAuth Security" is now available on Udemy!

    In this course we break down the jargon in the high-security OAuth specs like PAR, JAR, JARM, DPoP, Mutual TLS, HTTP Signatures and more!

    https://oauth2simplified.com/advanced-oauth
    Portland, Oregon, USA • 43°F
    73 likes 16 reposts 7 replies 2 mentions
    Thu, Dec 29, 2022 11:28am -08:00 #oauth
  • Aaron Parecki
    I've got an ad spot opening up in the new year on https://oauth.net! This is *the* hub for everything about OAuth online. Text-only ads, and usually has a high clickthrough rate!

    Get in touch if you'd like to get your business in front of 150,000 people a month!
    Portland, Oregon, USA • 34°F
    6 likes 3 reposts 1 reply
    Wed, Dec 21, 2022 9:33am -08:00 #oauth
  • OAuth WG

    OAuth for Browser-Based Apps Draft 12

    I just published a revised version of OAuth for Browser-Based Apps based on the feedback and discussion at IETF 115 London!
    continue reading...
    Tue, Dec 6, 2022 4:20pm -08:00 #oauth #ietf
  • The Laws of OAuth

    The first law of OAuth states that the total number of authorized access tokens must remain constant in an isolated system.
    continue reading...
    2 replies
    Fri, Dec 2, 2022 3:00pm -08:00 #chatgpt #openai #oauth
  • Aaron Parecki
    By popular request, I just published a version of "The Little Book of OAuth 2.0 RFCs" as a free downloadable PDF!

    https://oauth.net/books/#little-book-of-rfcs
    Portland, Oregon, USA • 39°F
    122 likes 43 reposts 10 replies 4 mentions
    Thu, Dec 1, 2022 3:23pm -08:00 #oauth
  • Aaron Parecki
    Remember folks, "token exchange" does *not* mean "let me exchange a customer ID for a token"!

    Good thread on how remotely connected Honda, Nissan, Infiniti, and Acura cars were all able to be remotely controlled knowing only the VIN.

    https://twitter.com/samwcyo/status/1597792145691246593
    Portland, Oregon, USA • 38°F
    20 likes 10 reposts 3 replies 1 mention
    Thu, Dec 1, 2022 11:36am -08:00 #security
  • Aaron Parecki
    This is your scheduled periodic reminder, for no particular reason, that now is a good time to review the third party OAuth apps that have access to your Twitter account, and remove any that you don't recognize or haven't used in a while.

    ➑ https://twitter.com/settings/connected_apps
    Portland, Oregon, USA • 43°F
    47 likes 20 reposts 5 replies
    Tue, Nov 15, 2022 6:36pm -08:00 #oauth #twitter #security
  • Aaron Parecki
    What could possibly go wrong? https://twitter.com/racheltobac/status/1588367452043235328
    Seattle, Washington, USA • 41°F
    26 likes 13 reposts 1 reply
    Thu, Nov 3, 2022 8:16pm -07:00 #twitter #security
  • Aaron Parecki
    October is cybersecurity awareness month.

    Okta is a cybersecurity company.

    ...coincidence...?
    Portland, Oregon, USA • 49°F
    20 likes 3 reposts 5 replies 1 mention
    Mon, Oct 24, 2022 7:55pm -07:00 #okta
  • Aaron Parecki
    In just 30 minutes, join me and @vibronet for another OAuth Happy Hour! We'll be catching up on all the latest progress in the world of OAuth and OpenID Connect! Bring your questions or just come to hear about what's new! https://youtu.be/Bg7cr9UTP9Q
    Portland, Oregon • 59°F
    2 likes 1 repost
    Tue, Oct 11, 2022 10:58am -07:00 #oauth
  • Aaron Parecki
    I'm working on a new video course, (tentatively) called "Advanced OAuth Security"!

    If you'd like to be the first to hear when it goes live, you can sign up for my email list here!

    https://oauth2simplified.com
    Portland, Oregon, USA • 68°F
    15 likes 5 replies
    Fri, Sep 16, 2022 2:13pm -07:00 #oauth
  • OAuth WG

    New Draft of OAuth for Browser-Based Apps (Draft -11)

    With the help of a few kind folks, we've made some updates to the OAuth 2.0 for Browser-Based Apps draft as discussed during the last IETF meeting in Philadelphia.
    continue reading...
    Thu, Sep 15, 2022 6:04pm -07:00 #oauth #oauth2
  • Aaron Parecki
    Just published a new version of OAuth 2.0 for Browser-Based Apps!

    https://www.ietf.org/archive/id/draft-ietf-oauth-browser-based-apps-11.html

    If you have feelings about tokens in browsers, please feel free to chime in on the discussion! You can comment on the mailing list or open issues on the GitHub repo linked from the doc!
    Portland, Oregon, USA • 67°F
    19 likes 3 reposts 1 reply
    Tue, Sep 13, 2022 11:26am -07:00 #oauth
  • Aaron Parecki
    Just landed in Seattle and realized even tho I fly thru here all the time I barely actually ever leave the airport!

    Super excited to be helping out with this event tomorrow tho! There's still space if you want to join!

    https://twitter.com/auth0/status/1560628964254679040
    Seattle, Washington, USA
    3 likes 1 reply
    Tue, Aug 23, 2022 1:30pm -07:00 #devday #auth0
  • Aaron Parecki
    Throwback to the OAuth WG dinner at #IETF114 in Philadelphia!

    Tag yourself if I missed you!

    @vibronet @timcappalli @__b_c @PieterKasselman @hpsin_ @selfissued @rifaat_sy and @kristinayasuda even tho she arrived just after this photo
    Portland, Oregon, USA • 73°F
    12 likes
    Fri, Aug 12, 2022 12:12pm -07:00 #ietf #oauth #ietf114
  • Aaron Parecki
    It was so great hanging out with my @OktaDev coworkers at @KC_DC this week! We fight for the users!

    @quorralyne @alisaduncan @briandemers @qedunham @melissatherms
    Portland, Oregon, USA • 71°F
    15 likes 2 reposts
    Fri, Aug 12, 2022 11:43am -07:00 #kcdc #oktadev
older
  • All
  • Articles
  • Bookmarks
  • Notes
  • Photos
  • Replies
  • Reviews
  • Trips
  • Videos
  • Contact
© 1999-2025 by Aaron Parecki. Powered by p3k. This site supports Webmention.
Except where otherwise noted, text content on this site is licensed under a Creative Commons Attribution 3.0 License.
IndieWebCamp Microformats Webmention W3C HTML5 Creative Commons
← πŸ•ΈπŸ’ β†’
WeChat ID
aaronpk_tv