73°F

Aaron Parecki

  • Articles
  • Notes
  • Photos
  • Anna βœ¨πŸ™…‍β™€οΈβœ¨ https://twitter.com/anna_hax
    There's some sound #indieWeb advice from @LauraKalbag here at #naconf

    πŸ‘‰ Self host where possible
    πŸ‘‰ Post to your own site first, then publish to third party apps
    πŸ‘‰ Your site will be better than Medium anyway πŸ˜…
    Portland, Oregon • 51°F
    Thu, Jan 23, 2020 3:07pm +00:00 (liked on Thu, Jan 23, 2020 7:11am -08:00) #indieWeb #naconf
  • Aaron Parecki
    Contributions from: Japan, Netherlands, Singapore, United Kingdom, United States
    Thu, Jan 23, 2020 6:47am -08:00
  • 9:53pm
    Asleep
    5:49am
    Awake
    7h 56m
    Slept
    16m
    Awake for
    Portland, Oregon, USA
    Thu, Jan 23, 2020 5:49am -08:00
  • Aaron Parecki
    Contributions from: Japan, Netherlands, Singapore, United Kingdom, United States
    Wed, Jan 22, 2020 11:51pm -08:00
  • Keiran Flanigan https://twitter.com/aeliox
    Reminds me of the quote from Teller (of Penn & Teller) – "Sometimes magic is just someone spending more time on something than anyone else might reasonably expect."
    Portland, Oregon • 49°F
    Fri, Jan 17, 2020 6:03pm +00:00 (liked on Wed, Jan 22, 2020 8:07pm -08:00)
  • Pelle Wessman https://twitter.com/voxpelli
    The decision of something being a good technical fit and something being a sound investment is often not done by the same person, so it would be a complex obstacle.

    I would much prefer support to be a progressive enhancement that can be dealt with in parallel to shipping stuff.
    Portland, Oregon • 49°F
    Wed, Jan 22, 2020 10:57pm +00:00 (liked on Wed, Jan 22, 2020 8:05pm -08:00)
  • Dave Maze https://twitter.com/davemaze   •   Jan 23
    what’s your favorite? i’ve been just doing old fashions
    Aaron Parecki
    My summer go-to is a Negroni (gin, campari, vermouth, bitters), winter is Boulevardier season (bourbon, campari, vermouth, bitters). Can you tell I like Campari?
    Portland, Oregon • 49°F
    1 like
    Wed, Jan 22, 2020 7:59pm -08:00
  • Dave Maze https://twitter.com/davemaze   •   Jan 23
    got an ice ball maker. cocktail game level up.
    Aaron Parecki
    now you're speaking my language!
    Portland, Oregon • 49°F
    2 likes 2 replies
    Wed, Jan 22, 2020 7:51pm -08:00
  • Johannes Ernst https://twitter.com/Johannes_Ernst   •   Jan 23
    And to this day, nobody knows how to label uSD cards.
    Aaron Parecki
    to be fair I don't label any of mine anyway
    Portland, Oregon • 49°F
    Wed, Jan 22, 2020 6:29pm -08:00
  • Ben Werdmuller https://twitter.com/benwerd   •   Jan 23
    I will provide feedback once it arrives!
    Aaron Parecki
    😍
    Portland, Oregon • 49°F
    3 replies
    Wed, Jan 22, 2020 6:13pm -08:00
  • Ben Werdmuller https://twitter.com/benwerd   •   Jan 23
    I just ordered a Post-It printer, and I have no regrets about it.
    Aaron Parecki
    Wait what's a post-it printer? Is it smol and cute if so I must have one
    Portland, Oregon • 49°F
    Wed, Jan 22, 2020 6:05pm -08:00
  • Lisa Phillips https://twitter.com/lisaphillips
    I'm "I just made a <Blink> Tag joke and they didn't get it" years old.
    Portland, Oregon • 49°F
    Wed, Jan 22, 2020 11:12pm +00:00 (liked on Wed, Jan 22, 2020 6:04pm -08:00)
  • Anders Pitman https://twitter.com/anderspitman   •   Jan 23
    I'm imagining a world where email servers handle identity, and authorization servers handle delegation, after confirmation ownership over the email identity.
    Aaron Parecki
    β€ͺWhile that sounds nice in theory, the real world is more complicated. Apple's OAuth server is a great example. User IDs are scoped to the app to prevent cross correlation, and the app gets a proxy email instead of the user's real email. Users don't always want to be identified.‬
    Portland, Oregon • 48°F
    Wed, Jan 22, 2020 4:33pm -08:00
  • Anders Pitman https://twitter.com/anderspitman   •   Jan 23
    Don't get me wrong, I think URLs for client IDs is a great idea, which I intend to use. I'm just less sold on URLs for user IDs. Everyone already has email addresses, and they also come with a relatively reliable protocol for contacting the owner.
    Aaron Parecki
    I was trying to say feel free to pick and choose and use just the client ID part. I think that'd be a huge benefit for OAuth as a whole for the exact kind of use case you're talking about.
    Portland, Oregon • 48°F
    1 like
    Wed, Jan 22, 2020 4:29pm -08:00
  • Anders Pitman https://twitter.com/anderspitman   •   Jan 23
    Ahhh that's what IndieAuth is. I was reading up on it, but didn't see any information about the spec on the website. I think my main hesitance towards it is the use of domains. I just don't see the average user buying their own domain. Emails seems more realistic for unique IDs.
    Aaron Parecki
    β€ͺDoesn't have to be a top level domain, just a URL. Both users and apps are identified by URLs. ‬

    β€ͺI do think there's value in just client IDs being URLs in some cases, demonstrated by the fact that Home Assistant picked out just that part of the spec for their OAuth API.‬
    Portland, Oregon • 48°F
    5 replies
    Wed, Jan 22, 2020 4:21pm -08:00
  • Aaron Parecki
    I like to think of myself as a somewhat organized person.

    But all these SD cards have photos and videos from different trips and projects and cameras, in no particular order, and I really need to sort out what has already been backed up and what exists only on the cards.
    Portland, Oregon, USA • 48°F
    4 likes 6 replies
    Wed, Jan 22, 2020 3:34pm -08:00
  • Anders Pitman https://twitter.com/anderspitman   •   Jan 22
    have their own custom domain for their instance, hosting an auth server. If someone wants to develop an app to talk to my service, they would have to register it with the instance of every user, which is impossible. Am I missing something? 2/2
    Aaron Parecki
    You're not wrong.

    You may want to give this a read, which addresses that exact problem: https://aaronparecki.com/2018/07/07/7/oauth-for-the-open-web

    We use this a lot for the case you're talking about, where app developers have no relationship with the OAuth service the app is talking to.
    Portland, Oregon, USA
    1 like 1 reply
    Wed, Jan 22, 2020 3:18pm -08:00
  • Fiona W. https://www.instagram.com/aliasxahna/
    Better late than never. :p | 2020 will be a year of change and action. πŸ’ͺ🏼πŸ’ͺ🏼πŸ’ͺ🏼 Personally trying for a more minimalistic life, spending more time with friends and family, be open to new ideas/ learn a few new things/skill, saying yes to trying (new) things out of my comfort zone, and to just do it... more quickly. πŸ€­πŸ˜… P/s top row first two drawings (left and middle) inspired by Pottering Cat.
    Portland, Oregon • 48°F
    Sat, Jan 18, 2020 5:32pm +00:00 (liked on Wed, Jan 22, 2020 2:35pm -08:00)
  • Aaron Parecki
    Contributions from: Japan, Netherlands, Singapore, United States
    Wed, Jan 22, 2020 9:30am -08:00
  • nystudio107 https://twitter.com/nystudio107   •   Jan 22
    Ironically, I have no microformat code on the site. It's pulling that from the JSON-LD "sameAs" URLs, I presume.
    Aaron Parecki
    Microformats != Microdata

    https://microformats.io

    tbh I also can't stand the itemprop= itemscope= stuff, it's so messy. That's why I like the Microformats approach instead.
    Portland, Oregon • 46°F
    Wed, Jan 22, 2020 9:17am -08:00
older

Hi, I'm Aaron Parecki, Director of Identity Standards at Okta, and co-founder of IndieWebCamp. I maintain oauth.net, write and consult about OAuth, and participate in the OAuth Working Group at the IETF. I also help people learn about video production and livestreaming. (detailed bio)

I've been tracking my location since 2008 and I wrote 100 songs in 100 days. I've spoken at conferences around the world about owning your data, OAuth, quantified self, and explained why R is a vowel. Read more.

  • Director of Identity Standards at Okta
  • IndieWebCamp Founder
  • OAuth WG Editor
  • OpenID Board Member

  • πŸŽ₯ YouTube Tutorials and Reviews
  • 🏠 We're building a triplex!
  • ⭐️ Life Stack
  • βš™οΈ Home Automation
  • All
  • Articles
  • Bookmarks
  • Notes
  • Photos
  • Replies
  • Reviews
  • Trips
  • Videos
  • Contact
© 1999-2025 by Aaron Parecki. Powered by p3k. This site supports Webmention.
Except where otherwise noted, text content on this site is licensed under a Creative Commons Attribution 3.0 License.
IndieWebCamp Microformats Webmention W3C HTML5 Creative Commons
WeChat ID
aaronpk_tv