52°F

Aaron Parecki

  • Articles
  • Notes
  • Photos
  • Aaron Parecki
    at Caesars Forum Conference Center
    Las Vegas, Nevada • Wed, October 16, 2024 7:58am
    36.118861 -115.168482
    #Oktane here we goooo
    Las Vegas, NV, United States • 69°F
    6 Coins
    Wed, Oct 16, 2024 7:58am -07:00 #oktane
  • Aaron Parecki
    Congrats to BlueSky for launching OAuth support for apps! πŸ™Œ https://docs.bsky.app/blog/oauth-atproto
    Portland, Oregon, USA • 60°F
    37 likes 8 reposts 6 replies
    Wed, Sep 25, 2024 6:47pm -07:00 #oauth
  • Aaron Parecki
    Love seeing more US banks adopting OAuth!
    Portland, Oregon, USA • 66°F
    5 likes 2 reposts
    Tue, Aug 13, 2024 9:05pm -07:00 #oauth
  • Aaron Parecki
    Someone broke through the chain link fence last week, in broad daylight, while I was home, and didn't notice at the time.

    I started thinking about what I could do about it, and it turns out the EA Unifi cameras have a new webhook feature. So now my cameras send a webhook to Home Assistant when someone crosses a virtual line, and it will trigger the siren. Since this is a line crossing event, not generic person detection, I can leave it armed 24/7, since nobody should be in that area at all.
    Portland, Oregon, USA • 91°F
    10 likes 2 replies
    Thu, Aug 8, 2024 7:03pm -07:00 #homeautomation #security #homeassistant #unifi
  • My IETF 120 Agenda

    The sessions I will be attending and presenting at during IETF 120 in Vancouver
    continue reading...
    Sun, Jul 21, 2024 12:54pm -07:00 #ietf #oauth #scim
  • Aaron Parecki
    So #Identiverse is using an AI tool to summarize all the conference talks and it works about as terribly as you'd imagine.

    Nowhere in my talk did I say "OAuth 3.0", nor did I say anything about global privacy regulation compliance. It straight up hallucinated quotes from me. πŸ€¦β€β™‚οΈ
    Las Vegas, Nevada, USA
    15 likes 6 reposts 3 replies
    Thu, May 30, 2024 11:09am -07:00 #identiverse #ai
  • FedCM for IndieAuth

    IndieWebCamp Düsseldorf took place this weekend, and I was inspired to work on a quick hack for demo day to show off a new feature I've been working on for IndieAuth.
    continue reading...
    13 likes 2 reposts 2 replies 1 mention
    Sun, May 12, 2024 7:39am -07:00 #fedcm #indieauth #oauth
  • Aaron Parecki
    OAuth for Browser-Based Apps has entered Working Group Last Call! Please share your comments in the next 2 weeks, even if it's just a general voice of support!

    https://aaronparecki.com/2024/05/02/5/oauth-browser-based-apps-last-call
    Portland, Oregon, USA • 60°F
    8 likes 8 reposts 1 reply
    Thu, May 2, 2024 3:22pm -07:00 #oauth #ietf
  • OAuth for Browser-Based Apps Working Group Last Call!

    The draft specification OAuth for Browser-Based Applications has just entered Working Group Last Call!
    continue reading...
    3 likes 1 mention
    Thu, May 2, 2024 3:06pm -07:00 #oauth #ietf
  • OAuth: "grant" vs "flow" vs "grant type"

    Is it called an OAuth "grant" or a "flow"? What about "grant type"?
    continue reading...
    1 like 5 reposts
    Fri, Mar 29, 2024 8:15am -07:00 #oauth #terminology
  • Aaron Parecki
    This is a good writeup on some sneaky vulnerabilities in OAuth implementations, but ultimately is just a simple access token injection attack: https://salt.security/blog/oh-auth-abusing-oauth-to-take-over-millions-of-accounts
    Portland, Oregon, USA • 42°F
    6 likes 8 reposts 2 replies 1 mention
    Thu, Oct 26, 2023 8:50am -07:00 #oauth
  • Aaron Parecki
    The deadline to submit drafts ahead of the IETF meeting in November just passed, and I submitted my last one with 30 minutes to spare! Here are all the docs I'll be discussing:

    https://www.ietf.org/archive/id/draft-ietf-oauth-browser-based-apps-15.html

    https://www.ietf.org/archive/id/draft-ietf-oauth-resource-metadata-01.html

    https://www.ietf.org/archive/id/draft-parecki-oauth-first-party-apps-00.html

    https://www.ietf.org/archive/id/draft-parecki-oauth-metadata-for-nested-flows-00.html
    Portland, Oregon, USA
    6 likes 3 reposts 1 reply 1 mention
    Mon, Oct 23, 2023 5:15pm -07:00 #oauth #ietf
  • OAuth WG

    OAuth for Browser-Based Apps Draft 15

    After a lot of discussion on the mailing list over the last few months, and after some excellent discussions at the OAuth Security Workshop, we've been working on revising the draft to provide clearer guidance and clearer discussion of the threats and consequences of the various architectural patterns in the draft.
    continue reading...
    1 mention
    Mon, Oct 23, 2023 9:12am -07:00 #oauth #ietf
  • Aaron Parecki
    Now that @1Password launched passkey support *and* it's integrated into iOS 17 with the 1Password app, I feel like I can finally actually take the plunge and set up passkeys everywhere!

    No more passwords! and the login UX is so much better too!
    Portland, Oregon, USA • 59°F
    32 likes 9 reposts 2 replies 1 mention
    Sat, Sep 23, 2023 6:48pm -07:00 #security #passkey #password
  • Aaron Parecki
    It is 2023 and I am still having to explain the dangers of the OAuth Implicit Flow because I am still finding current documentation suggesting otherwise. Time to make another video to follow up on the one from 4 years ago?
    Portland, Oregon, USA • 77°F
    9 likes 1 repost 2 replies
    Wed, Jun 7, 2023 3:09pm -07:00 #oauth
  • Aaron Parecki
    May the 4th be with you! Brand new OAuth shirts just launched: "I find your lack of security disturbing"

    Available in a variety of styles and also as a hacker hoodie!

    https://shop.oauth.net/listing/lack-of-security-disturbing?product=46
    Portland, Oregon, USA • 49°F
    12 likes 4 reposts 1 reply
    Thu, May 4, 2023 11:31am -07:00 #oauth #security
  • Aaron Parecki
    Tomorrow I’ll be speaking at the @OReillyMedia Security Superstream at 8AM PDT with host @ChloeMessdaghi

    Get up to speed on techniques & best practices related to OAuth and API security, the OWASP Top 10, & more! Register now: https://www.oreilly.com/live-events/security-superstream-application-security/0636920083707/0636920083706/

    https://infosec.exchange/@ChloeMessdaghi/110186693893045342
    Portland, Oregon, USA • 50°F
    5 likes 3 reposts
    Wed, Apr 12, 2023 5:28pm -07:00 #oreilly #oauth
  • Aaron Parecki
    we all know the real reason you install iOS updates πŸ‘€

    p.s. go update your devices
    Portland, Oregon, USA • 48°F
    28 likes 11 reposts 6 replies
    Fri, Apr 7, 2023 8:26pm -07:00 #security #emoji #ios
  • Aaron Parecki
    Yet another reason why Token Exchange is dangerous 🀯😱

    "Bing is allowed to issue Office tokens for any logged-on user"

    https://twitter.com/hillai/status/1641146523990753290
    η₯žε₯ˆε·ηœŒ, JPN
    13 likes 4 replies 1 mention
    Thu, Mar 30, 2023 9:54am +09:00 #security #oauth
  • Aaron Parecki
    First #ietf116 session of the day is #OAuth complete with custom SD-JWT t-shirts πŸ˜‚

    @kristinayasuda @dfett42
    θ₯ΏεŒΊ, η₯žε₯ˆε·ηœŒ, JPN • 48°F
    19 likes 6 reposts 4 mentions
    Tue, Mar 28, 2023 9:45am +09:00 #oauth #ietf116
older
  • All
  • Articles
  • Bookmarks
  • Notes
  • Photos
  • Replies
  • Reviews
  • Trips
  • Videos
  • Contact
© 1999-2025 by Aaron Parecki. Powered by p3k. This site supports Webmention.
Except where otherwise noted, text content on this site is licensed under a Creative Commons Attribution 3.0 License.
IndieWebCamp Microformats Webmention W3C HTML5 Creative Commons
← πŸ•ΈπŸ’ β†’
WeChat ID
aaronpk_tv