51°F

Aaron Parecki

  • Articles
  • Notes
  • Photos
  • Aaron Parecki
    This is a good writeup on some sneaky vulnerabilities in OAuth implementations, but ultimately is just a simple access token injection attack: https://salt.security/blog/oh-auth-abusing-oauth-to-take-over-millions-of-accounts
    Portland, Oregon, USA • 42°F
    6 likes 8 reposts 2 replies 1 mention
    Thu, Oct 26, 2023 8:50am -07:00 #oauth
  • Aaron Parecki
    The deadline to submit drafts ahead of the IETF meeting in November just passed, and I submitted my last one with 30 minutes to spare! Here are all the docs I'll be discussing:

    https://www.ietf.org/archive/id/draft-ietf-oauth-browser-based-apps-15.html

    https://www.ietf.org/archive/id/draft-ietf-oauth-resource-metadata-01.html

    https://www.ietf.org/archive/id/draft-parecki-oauth-first-party-apps-00.html

    https://www.ietf.org/archive/id/draft-parecki-oauth-metadata-for-nested-flows-00.html
    Portland, Oregon, USA
    6 likes 3 reposts 1 reply 1 mention
    Mon, Oct 23, 2023 5:15pm -07:00 #oauth #ietf
  • OAuth WG

    OAuth for Browser-Based Apps Draft 15

    After a lot of discussion on the mailing list over the last few months, and after some excellent discussions at the OAuth Security Workshop, we've been working on revising the draft to provide clearer guidance and clearer discussion of the threats and consequences of the various architectural patterns in the draft.
    continue reading...
    1 mention
    Mon, Oct 23, 2023 9:12am -07:00 #oauth #ietf
  • Aaron Parecki
    Now that @1Password launched passkey support *and* it's integrated into iOS 17 with the 1Password app, I feel like I can finally actually take the plunge and set up passkeys everywhere!

    No more passwords! and the login UX is so much better too!
    Portland, Oregon, USA • 59°F
    32 likes 9 reposts 2 replies 1 mention
    Sat, Sep 23, 2023 6:48pm -07:00 #security #passkey #password
  • Aaron Parecki
    It is 2023 and I am still having to explain the dangers of the OAuth Implicit Flow because I am still finding current documentation suggesting otherwise. Time to make another video to follow up on the one from 4 years ago?
    Portland, Oregon, USA • 77°F
    9 likes 1 repost 2 replies
    Wed, Jun 7, 2023 3:09pm -07:00 #oauth
  • Aaron Parecki
    May the 4th be with you! Brand new OAuth shirts just launched: "I find your lack of security disturbing"

    Available in a variety of styles and also as a hacker hoodie!

    https://shop.oauth.net/listing/lack-of-security-disturbing?product=46
    Portland, Oregon, USA • 49°F
    12 likes 4 reposts 1 reply
    Thu, May 4, 2023 11:31am -07:00 #oauth #security
  • Aaron Parecki
    Tomorrow I’ll be speaking at the @OReillyMedia Security Superstream at 8AM PDT with host @ChloeMessdaghi

    Get up to speed on techniques & best practices related to OAuth and API security, the OWASP Top 10, & more! Register now: https://www.oreilly.com/live-events/security-superstream-application-security/0636920083707/0636920083706/

    https://infosec.exchange/@ChloeMessdaghi/110186693893045342
    Portland, Oregon, USA • 50°F
    5 likes 3 reposts
    Wed, Apr 12, 2023 5:28pm -07:00 #oreilly #oauth
  • Aaron Parecki
    we all know the real reason you install iOS updates πŸ‘€

    p.s. go update your devices
    Portland, Oregon, USA • 48°F
    28 likes 11 reposts 6 replies
    Fri, Apr 7, 2023 8:26pm -07:00 #security #emoji #ios
  • Aaron Parecki
    Yet another reason why Token Exchange is dangerous 🀯😱

    "Bing is allowed to issue Office tokens for any logged-on user"

    https://twitter.com/hillai/status/1641146523990753290
    η₯žε₯ˆε·ηœŒ, JPN
    13 likes 4 replies 1 mention
    Thu, Mar 30, 2023 9:54am +09:00 #security #oauth
  • Aaron Parecki
    First #ietf116 session of the day is #OAuth complete with custom SD-JWT t-shirts πŸ˜‚

    @kristinayasuda @dfett42
    θ₯ΏεŒΊ, η₯žε₯ˆε·ηœŒ, JPN • 48°F
    19 likes 6 reposts 4 mentions
    Tue, Mar 28, 2023 9:45am +09:00 #oauth #ietf116
  • OAuth Support in Bluesky and AT Protocol

    Bluesky, a new social media platform and AT Protocol, is unsurprisingly running up against the same challenges and limitations that Flickr, Twitter and many other social media platforms faced in the 2000s: passwords!
    continue reading...
    12 likes 1 repost 10 replies 2 mentions
    Thu, Mar 9, 2023 5:09pm -08:00 #oauth #indieauth #bluesky #atproto #indieweb #indieauth
  • Aaron Parecki
    another day, another account takeover caused by an open redirector and the OAuth Implicit flow 🫠

    https://salt.security/blog/traveling-with-oauth-account-takeover-on-booking-com
    Portland, Oregon • 40°F
    14 likes 4 reposts 1 reply
    Thu, Mar 2, 2023 10:16am -08:00 #oauth #security
  • Aaron Parecki
    I'm a big fan of using more secure two-factor authentication methods like a security key or TouchID, but I will admit I never expected charging people to use SMS would be a viable strategy to get them off it πŸ˜… https://blog.twitter.com/en_us/topics/product/2023/an-update-on-two-factor-authentication-using-sms-on-twitter
    Portland, Oregon, USA • 43°F
    46 likes 6 reposts 12 replies
    Fri, Feb 17, 2023 9:26pm -08:00 #security #2fa #mfa #twitter
  • Aaron Parecki
    I've given many talks about how mobile apps can't be deployed with a secret, and using Twitter's 2013 "hacks" as an example. I'm just going to leave this completely unrelated string of random characters here for no particular reason

    GgDYlkSvaPxGxC4X8liwpUoqKwwr3lCADbz8A7ADU
    Portland, Oregon, USA • 43°F
    100 likes 52 reposts 10 replies
    Thu, Feb 2, 2023 8:12pm -08:00 #twitter #oauth #security
  • Aaron Parecki
    PSA: If you use Twitter to sign in to stuff, you should double check you have another way to get in to those accounts asap. With Twitter charging ??? for API access next week, you have no way of knowing whether the apps you use are going to pay that.
    Portland, Oregon, USA • 49°F
    140 likes 139 reposts 11 replies 5 mentions
    Thu, Feb 2, 2023 4:23pm -08:00 #oauth #twitter
  • Aaron Parecki
    It's been a while since I've set up an Amazon Echo device. Do I need to come over there and teach some Amazon folks about the OAuth Device Flow? There is a better way than making me type my password on this screen!
    Portland, Oregon, USA • 45°F
    44 likes 8 reposts 4 replies 1 mention
    Fri, Jan 27, 2023 9:20pm -08:00 #oauth
  • Aaron Parecki
    It's here! My new video course "Advanced OAuth Security" is now available on Udemy!

    In this course we break down the jargon in the high-security OAuth specs like PAR, JAR, JARM, DPoP, Mutual TLS, HTTP Signatures and more!

    https://oauth2simplified.com/advanced-oauth
    Portland, Oregon, USA • 43°F
    73 likes 16 reposts 7 replies 2 mentions
    Thu, Dec 29, 2022 11:28am -08:00 #oauth
  • Aaron Parecki
    I've got an ad spot opening up in the new year on https://oauth.net! This is *the* hub for everything about OAuth online. Text-only ads, and usually has a high clickthrough rate!

    Get in touch if you'd like to get your business in front of 150,000 people a month!
    Portland, Oregon, USA • 34°F
    6 likes 3 reposts 1 reply
    Wed, Dec 21, 2022 9:33am -08:00 #oauth
  • OAuth WG

    OAuth for Browser-Based Apps Draft 12

    I just published a revised version of OAuth for Browser-Based Apps based on the feedback and discussion at IETF 115 London!
    continue reading...
    Tue, Dec 6, 2022 4:20pm -08:00 #oauth #ietf
  • The Laws of OAuth

    The first law of OAuth states that the total number of authorized access tokens must remain constant in an isolated system.
    continue reading...
    2 replies
    Fri, Dec 2, 2022 3:00pm -08:00 #chatgpt #openai #oauth
older
  • All
  • Articles
  • Bookmarks
  • Notes
  • Photos
  • Replies
  • Reviews
  • Trips
  • Videos
  • Contact
© 1999-2025 by Aaron Parecki. Powered by p3k. This site supports Webmention.
Except where otherwise noted, text content on this site is licensed under a Creative Commons Attribution 3.0 License.
IndieWebCamp Microformats Webmention W3C HTML5 Creative Commons
← πŸ•ΈπŸ’ β†’
WeChat ID
aaronpk_tv