57°F

Aaron Parecki

  • Articles
  • Notes
  • Photos
  • Aaron Parecki
    In case you missed it, our IPSIE webinar recording is now available! I had a great time chatting with Dean H. Saxe, George Fletcher, Gail Hodges, and Jeff Reich about what IPSIE is, why profiling existing specifications is so important, and the progress the working group has made so far! Thanks for the great conversation!

    IPSIE:
    Interoperability
    Profile for
    Secure
    Identity in the
    Enterprise

    https://www.brighttalk.com/webcast/18458/636068
    Portland, Oregon, USA • 56°F
    Wed, Mar 5, 2025 1:24pm -08:00 #ipsie #openid #okta
  • Aaron Parecki
    Chase sends 8-digit 2fa SMS codes, which seems excessive compared to the 6 that most other places use, but even weirder is that the first digit of them has always been the same, effectively making it a 7 digit code. Anyone know what's up with that?
    Portland, Oregon, USA • 41°F
    4 likes 7 replies
    Sat, Feb 15, 2025 5:56pm -08:00 #security #sms #2fa
  • Aaron Parecki
    At long last, the OAuth working group has finished the Best Current Practice for OAuth 2.0 Security and it was just published as RFC9700! This has been a long time in the works, and I'm very thankful to everyone who has helped out with it over the years!

    https://www.rfc-editor.org/rfc/rfc9700.html

    This is one of the major inputs to OAuth 2.1, so I'm also very excited to be able to move that forward this year as well!
    Portland, Oregon • 37°F
    65 likes 36 reposts 3 replies
    Tue, Feb 4, 2025 11:15am -08:00 #ietf #oauth #rfc #security
  • My IETF 121 Agenda

    Here's where you can find me at IETF 121 in Dublin!
    continue reading...
    1 like
    Mon, Nov 4, 2024 9:18am +00:00 #ietf #ietf121 #oauth
  • Aaron Parecki
    at Caesars Forum Conference Center
    Las Vegas, Nevada • Wed, October 16, 2024 7:58am
    36.118861 -115.168482
    #Oktane here we goooo
    Las Vegas, NV, United States • 69°F
    6 Coins
    Wed, Oct 16, 2024 7:58am -07:00 #oktane
  • Aaron Parecki
    Congrats to BlueSky for launching OAuth support for apps! πŸ™Œ https://docs.bsky.app/blog/oauth-atproto
    Portland, Oregon, USA • 60°F
    37 likes 8 reposts 6 replies
    Wed, Sep 25, 2024 6:47pm -07:00 #oauth
  • Aaron Parecki
    Love seeing more US banks adopting OAuth!
    Portland, Oregon, USA • 66°F
    5 likes 2 reposts
    Tue, Aug 13, 2024 9:05pm -07:00 #oauth
  • Aaron Parecki
    Someone broke through the chain link fence last week, in broad daylight, while I was home, and didn't notice at the time.

    I started thinking about what I could do about it, and it turns out the EA Unifi cameras have a new webhook feature. So now my cameras send a webhook to Home Assistant when someone crosses a virtual line, and it will trigger the siren. Since this is a line crossing event, not generic person detection, I can leave it armed 24/7, since nobody should be in that area at all.
    Portland, Oregon, USA • 91°F
    10 likes 2 replies
    Thu, Aug 8, 2024 7:03pm -07:00 #homeautomation #security #homeassistant #unifi
  • My IETF 120 Agenda

    The sessions I will be attending and presenting at during IETF 120 in Vancouver
    continue reading...
    Sun, Jul 21, 2024 12:54pm -07:00 #ietf #oauth #scim
  • Aaron Parecki
    So #Identiverse is using an AI tool to summarize all the conference talks and it works about as terribly as you'd imagine.

    Nowhere in my talk did I say "OAuth 3.0", nor did I say anything about global privacy regulation compliance. It straight up hallucinated quotes from me. πŸ€¦β€β™‚οΈ
    Las Vegas, Nevada, USA
    15 likes 6 reposts 3 replies
    Thu, May 30, 2024 11:09am -07:00 #identiverse #ai
  • FedCM for IndieAuth

    IndieWebCamp Düsseldorf took place this weekend, and I was inspired to work on a quick hack for demo day to show off a new feature I've been working on for IndieAuth.
    continue reading...
    13 likes 2 reposts 2 replies 1 mention
    Sun, May 12, 2024 7:39am -07:00 #fedcm #indieauth #oauth
  • Aaron Parecki
    OAuth for Browser-Based Apps has entered Working Group Last Call! Please share your comments in the next 2 weeks, even if it's just a general voice of support!

    https://aaronparecki.com/2024/05/02/5/oauth-browser-based-apps-last-call
    Portland, Oregon, USA • 60°F
    8 likes 8 reposts 1 reply
    Thu, May 2, 2024 3:22pm -07:00 #oauth #ietf
  • OAuth for Browser-Based Apps Working Group Last Call!

    The draft specification OAuth for Browser-Based Applications has just entered Working Group Last Call!
    continue reading...
    3 likes 1 mention
    Thu, May 2, 2024 3:06pm -07:00 #oauth #ietf
  • OAuth: "grant" vs "flow" vs "grant type"

    Is it called an OAuth "grant" or a "flow"? What about "grant type"?
    continue reading...
    1 like 5 reposts
    Fri, Mar 29, 2024 8:15am -07:00 #oauth #terminology
  • Aaron Parecki
    This is a good writeup on some sneaky vulnerabilities in OAuth implementations, but ultimately is just a simple access token injection attack: https://salt.security/blog/oh-auth-abusing-oauth-to-take-over-millions-of-accounts
    Portland, Oregon, USA • 42°F
    6 likes 8 reposts 2 replies 1 mention
    Thu, Oct 26, 2023 8:50am -07:00 #oauth
  • Aaron Parecki
    The deadline to submit drafts ahead of the IETF meeting in November just passed, and I submitted my last one with 30 minutes to spare! Here are all the docs I'll be discussing:

    https://www.ietf.org/archive/id/draft-ietf-oauth-browser-based-apps-15.html

    https://www.ietf.org/archive/id/draft-ietf-oauth-resource-metadata-01.html

    https://www.ietf.org/archive/id/draft-parecki-oauth-first-party-apps-00.html

    https://www.ietf.org/archive/id/draft-parecki-oauth-metadata-for-nested-flows-00.html
    Portland, Oregon, USA
    6 likes 3 reposts 1 reply 1 mention
    Mon, Oct 23, 2023 5:15pm -07:00 #oauth #ietf
  • OAuth WG

    OAuth for Browser-Based Apps Draft 15

    After a lot of discussion on the mailing list over the last few months, and after some excellent discussions at the OAuth Security Workshop, we've been working on revising the draft to provide clearer guidance and clearer discussion of the threats and consequences of the various architectural patterns in the draft.
    continue reading...
    1 mention
    Mon, Oct 23, 2023 9:12am -07:00 #oauth #ietf
  • Aaron Parecki
    Now that @1Password launched passkey support *and* it's integrated into iOS 17 with the 1Password app, I feel like I can finally actually take the plunge and set up passkeys everywhere!

    No more passwords! and the login UX is so much better too!
    Portland, Oregon, USA • 59°F
    32 likes 9 reposts 2 replies 1 mention
    Sat, Sep 23, 2023 6:48pm -07:00 #security #passkey #password
  • Aaron Parecki
    It is 2023 and I am still having to explain the dangers of the OAuth Implicit Flow because I am still finding current documentation suggesting otherwise. Time to make another video to follow up on the one from 4 years ago?
    Portland, Oregon, USA • 77°F
    9 likes 1 repost 2 replies
    Wed, Jun 7, 2023 3:09pm -07:00 #oauth
  • Aaron Parecki
    May the 4th be with you! Brand new OAuth shirts just launched: "I find your lack of security disturbing"

    Available in a variety of styles and also as a hacker hoodie!

    https://shop.oauth.net/listing/lack-of-security-disturbing?product=46
    Portland, Oregon, USA • 49°F
    12 likes 4 reposts 1 reply
    Thu, May 4, 2023 11:31am -07:00 #oauth #security
older
  • All
  • Articles
  • Bookmarks
  • Notes
  • Photos
  • Replies
  • Reviews
  • Trips
  • Videos
  • Contact
© 1999-2025 by Aaron Parecki. Powered by p3k. This site supports Webmention.
Except where otherwise noted, text content on this site is licensed under a Creative Commons Attribution 3.0 License.
IndieWebCamp Microformats Webmention W3C HTML5 Creative Commons
← πŸ•ΈπŸ’ β†’
WeChat ID
aaronpk_tv