79°F

Aaron Parecki

  • Articles
  • Notes
  • Photos
  • 170.9lbs
    Weight
    22.8%
    Body Fat
    Portland, Oregon • 61°F
    Fri, Aug 12, 2022 5:27am -07:00
  • manton https://micro.blog/manton   •   Aug 11

    @aaronpk Enjoy Austin! ☕️ I'm in California this week... Hope the weather isn't too ridiculously hot in Texas while you're there.

    Aaron Parecki
    Thanks! It was okay in the morning but gosh does it get hot once the sun comes out!
    Portland, Oregon • 81°F
    Thu, Aug 11, 2022 8:03pm -07:00
  • Plane
    1843.80mi
    Distance
    219:43
    Duration
    6:18pm
    Start
    7:58pm
    End
    Portland, Oregon • 81°F
    Thu, Aug 11, 2022 7:58pm -07:00
  • George Fletcher https://twitter.com/gffletch   •   Aug 11
    And of course Twitter opens the link in an in-app browser:-)
    Aaron Parecki
    Oof yeah. At least they give you a button to pop out to the real browser easier.
    Alaska Flight 1254 AUS to PDX in Mitchell, Oregon • 82°F
    2 likes
    Thu, Aug 11, 2022 7:37pm -07:00
  • Fruit and Cheese Plate
    Alaska Flight 1254 AUS to PDX in Holly, Colorado • 90°F
    Thu, Aug 11, 2022 7:32pm -05:00
  • Austin (AUS) to Portland (PDX)
    August 11, 2022 from 5:35pm (-0500) to 7:45pm (-0700)
    Alaska Flight 1254
    Portland Intl in Portland
    permalink #okta #oktadev
  • Ricky Mondello https://twitter.com/rmondello
    Two-factor authentication doesn’t protect you in the way that many people think when the second factor is phishable.

    Passkeys are phishing-resistant.
    Austin, Texas • 99°F
    Thu, Aug 11, 2022 4:57pm +00:00 (liked on Thu, Aug 11, 2022 5:14pm -05:00)
  • Dan Moore https://twitter.com/mooreds   •   Aug 11
    So in your mind, no reason to ever use a webview/embedded browser?

    Or do I misunderstand?
    Aaron Parecki
    The only time you might be able to convince me that it's acceptable is if this account is only for one app and everything is all first party. If there's only ever one app then there's effectively no OAuth and everything (including the AS) is part of the app.
    Austin, Texas • 99°F
    1 like
    Thu, Aug 11, 2022 5:05pm -05:00
  • Dan Moore https://twitter.com/mooreds   •   Aug 11
    Agreed, as outlined here: https://datatracker.ietf.org/doc/html/rfc8252#section-8.12

    However, many folks, esp when first party all the way through, are willing to accept the downsides for better UX (popping out to the system browser being a pretty horrible UX).

    Hobson's browser is real:

    https://infrequently.org/2021/07/hobsons-browser/
    Aaron Parecki
    Frankly the "system browser is horrible UX" argument lost a long time ago once the OSs provided in-app browsers that share system cookies but aren't visible to the app.
    Austin, Texas • 99°F
    1 like 2 replies
    Thu, Aug 11, 2022 4:56pm -05:00
  • PhotoJoseph https://twitter.com/photojoseph   •   Aug 11
    The other side.
    Aaron Parecki
    So when are you getting a drone to take some shots from higher up 😇
    Austin, Texas • 99°F
    1 like 2 replies
    Thu, Aug 11, 2022 4:53pm -05:00
  • Faruk 🚀 ᴵᴾᴴᴼᴺᴱᴰᴼ https://twitter.com/iPhonedo   •   Aug 11
    same hahah!!!
    Aaron Parecki
    I still use it every day and add new venues and everything too! It's still the best source of up to date venue information anywhere, usually even beating Google!
    Austin, Texas • 99°F
    2 likes 1 reply
    Thu, Aug 11, 2022 4:52pm -05:00
  • Dan Moore https://twitter.com/mooreds   •   Aug 11
    Although if it is a first party oauth integration (where one company controls the mobile app, the APIs, and, through a legal contract the Authorization Server), this injection is less of an issue, right?
    Aaron Parecki
    This particular issue isn't really a problem if you control the app and AS, but there are other reasons not to embed the AS page in an in-app web view.
    Austin, Texas • 99°F
    1 like 4 replies
    Thu, Aug 11, 2022 4:44pm -05:00
  • Aaron Parecki
    at Gate 32
    Austin, Texas • Thu, August 11, 2022 4:42pm
    30.202175 -97.670839
    Austin, TX, United States • 99°F
    10 Coins
    Thu, Aug 11, 2022 4:42pm -05:00
  • Veggie Flatbread
    Departure Lounge
    Thu, Aug 11, 2022 3:03pm -05:00
  • Strawberry Margarita
    Departure Lounge
    Thu, Aug 11, 2022 2:51pm -05:00
  • Aaron Parecki
    at Departure Lounge
    Austin, Texas • Thu, August 11, 2022 2:46pm
    30.202081 -97.666818
    Austin, TX, United States • 98°F
    10 Coins
    Thu, Aug 11, 2022 2:46pm -05:00
  • Aaron Parecki
    at TSA Security Check Point
    Austin, Texas • Thu, August 11, 2022 2:24pm
    30.202327 -97.667446
    Austin, TX, United States
    22 Coins
    Thu, Aug 11, 2022 2:24pm -05:00
  • Aaron Parecki
    at Austin Bergstrom International Airport (AUS)
    Austin, Texas • Thu, August 11, 2022 2:20pm
    30.202242 -97.666831
    Austin, TX, United States
    1 Coin
    Thu, Aug 11, 2022 2:20pm -05:00
  • Taxi
    12.53mi
    Distance
    20:21
    Duration
    1:59pm
    Start
    2:20pm
    End
    Austin, Texas • 98°F
    Thu, Aug 11, 2022 2:20pm -05:00
  • Aaron Parecki
    at Army Software Factory
    Austin, Texas • Thu, August 11, 2022 1:57pm
    30.276491 -97.747354
    Austin, TX, United States • 97°F
    17 Coins
    Thu, Aug 11, 2022 1:57pm -05:00
older

Hi, I'm Aaron Parecki, Director of Identity Standards at Okta, and co-founder of IndieWebCamp. I maintain oauth.net, write and consult about OAuth, and participate in the OAuth Working Group at the IETF. I also help people learn about video production and livestreaming. (detailed bio)

I've been tracking my location since 2008 and I wrote 100 songs in 100 days. I've spoken at conferences around the world about owning your data, OAuth, quantified self, and explained why R is a vowel. Read more.

  • Director of Identity Standards at Okta
  • IndieWebCamp Founder
  • OAuth WG Editor
  • OpenID Board Member

  • 🎥 YouTube Tutorials and Reviews
  • 🏠 We're building a triplex!
  • ⭐️ Life Stack
  • ⚙️ Home Automation
  • All
  • Articles
  • Bookmarks
  • Notes
  • Photos
  • Replies
  • Reviews
  • Trips
  • Videos
  • Contact
© 1999-2025 by Aaron Parecki. Powered by p3k. This site supports Webmention.
Except where otherwise noted, text content on this site is licensed under a Creative Commons Attribution 3.0 License.
IndieWebCamp Microformats Webmention W3C HTML5 Creative Commons
WeChat ID
aaronpk_tv