73°F

Aaron Parecki

  • Articles
  • Notes
  • Photos
  • 9:39pm
    Asleep
    5:59am
    Awake
    8h 20m
    Slept
    34m
    Awake for
    Portland, Oregon, USA • 34°F
    Sun, Mar 5, 2023 5:59am -08:00
  • Aaron Parecki
    Check out this fully decked out ATEM Mini Extreme rig!

    Featuring the PK1 stand with the new #coverlee custom printed acrylic cover. The aluminum bar has enough room for the 10.1" Lilliput monitor for the ATEM's multiview as well as an iPad Mini next to it to run MixEffect or LiveApp! Plus you can still bolt a wireless HDMI receiver like the Hollyland Mars 400S to the back of the stand!

    https://kit.co/aaronpk/pk1-atem-mini-extreme-rig
    Portland, Oregon, USA • 38°F
    Sat, Mar 4, 2023 8:40pm -08:00 #pk1 #youtube #video #coverlee
  • Aaron Parecki
    Contributions from: Australia, France, Germany, India, Kuwait, Russian Federation, Sweden, United Kingdom, United States
    Sat, Mar 4, 2023 4:05pm -08:00
  • Vegan Ramen
    Kayo's Ramen Bar
    Sat, Mar 4, 2023 1:53pm -08:00
  • Aaron Parecki
    Contributions from: Australia, France, Germany, India, Kuwait, Russian Federation, Sweden, United Kingdom, United States
    Sat, Mar 4, 2023 6:32am -08:00
  • 8:56pm
    Asleep
    6:09am
    Awake
    9h 13m
    Slept
    31m
    Awake for
    Portland, Oregon, USA • 39°F
    Sat, Mar 4, 2023 6:09am -08:00
  • Aaron Parecki
    Contributions from: Australia, France, Germany, India, Kuwait, Sweden, United Kingdom, United States
    Sat, Mar 4, 2023 2:58am -08:00
  • Barrett Shepherd 📦🚀 https://twitter.com/BarrettShepherd   •   Mar 4
    I use DoorDash too often probably and feel like I can spot a cloud kitchen from the name/image. I’ve never had a solid experience from a cloud kitchen. Glad they’re adding an indicator!
    Aaron Parecki
    I'm not a big customer of food delivery apps but I did order a burrito this week on DoorDash from a place that I assumed was a ghost kitchen by the name, but it turns out it was a food truck!
    Portland, Oregon • 40°F
    1 like
    Fri, Mar 3, 2023 8:50pm -08:00
  • Nabeel Qureshi https://twitter.com/nabeelqu
    In retrospect this was the best smartphone. High productivity, low addiction. No infinite scroll, no engagement hacking, just messaging with your friends and typing emails very fast with that clicky keyboard. Someone should do a new one.
    Portland, Oregon • 40°F
    Fri, Mar 3, 2023 9:08pm +00:00 (liked on Fri, Mar 3, 2023 8:29pm -08:00)
  • Jay Graber https://twitter.com/arcalinea
    Choice for users:

    If you start using the bluesky app, but decide you want to host your own server, or have a username that’s your personal website, you can switch over to doing that. Account portability will let users switch services without losing friends or data.
    Portland, Oregon • 40°F
    Fri, Mar 3, 2023 10:55pm +00:00 (liked on Fri, Mar 3, 2023 8:25pm -08:00)
  • Jay Graber https://twitter.com/arcalinea
    Here are the protocol features we're excited to finish:

    - Domain names as usernames & account portability
    - Algorithmic choice & custom feeds
    - Composable moderation & reputation systems
    Portland, Oregon • 40°F
    Fri, Mar 3, 2023 10:55pm +00:00 (liked on Fri, Mar 3, 2023 8:24pm -08:00)
  • Jay Graber https://twitter.com/arcalinea
    The app is a simple, straightforward microblogging client because our devs are currently focused on surfacing protocol features in the UX. The purpose of the app is to be a reference client for devs building on atproto, and to be a landing place for curious users.
    Portland, Oregon • 40°F
    Fri, Mar 3, 2023 10:55pm +00:00 (liked on Fri, Mar 3, 2023 8:24pm -08:00)
  • patrick. https://twitter.com/imPatrickT
    influencer marketing is broken. hear me out.

    the space needs disrupting. think:
    - display ads
    - promoting posts on social media
    - billboards
    - product placement in tv/movies
    - pre-roll
    - brand accessible analytics
    - actionable KPI’s

    who’s building this?
    Portland, Oregon • 40°F
    Fri, Mar 3, 2023 4:08pm +00:00 (liked on Fri, Mar 3, 2023 5:02pm -08:00)
  • The Fediverse is Already Dead | Nora Codes (nora.codes)
    Fri, Mar 3, 2023 9:23am -08:00 #mastodon #fediverse
  • Aaron Parecki
    Contributions from: Australia, France, Germany, India, Kuwait, Sweden, United Kingdom, United States
    Fri, Mar 3, 2023 8:58am -08:00
  • 9:35pm
    Asleep
    5:37am
    Awake
    8h 02m
    Slept
    28m
    Awake for
    Portland, Oregon, USA • 37°F
    Fri, Mar 3, 2023 5:37am -08:00
  • Brandon Trebitowski https://brandontreb.com   •   Mar 3

    True, but it would be tricky.

    Wouldn’t the attacker have find a way to extract the code_verifier from local storage and pass it along with the hijacked redirect?

    They would have to somehow have the ability to write custom js code on the path they are redirecting to. I guess this is possible on sites that don’t sanitize user inputs.

    Aaron Parecki
    I was thinking the attacker makes up their *own* `code_verifier` and injects that into the first open redirect
    Portland, Oregon • 42°F
    1 reply
    Thu, Mar 2, 2023 4:16pm -08:00
  • Brandon Trebitowski https://brandontreb.com   •   Mar 2

    Could using PKCE fix this issue?

    Aaron Parecki
    Yep! This is exactly the kind of thing PKCE prevents! With PKCE, even if the open redirect were in place, the attacker wouldn't have been able to do anything with the stolen authorization code.

    Although now I'm thinking this through and if the open redirects are really open enough, you could probably still pull something off even while using PKCE.
    Portland, Oregon • 42°F
    1 reply
    Thu, Mar 2, 2023 4:03pm -08:00
  • Aaron Parecki
    another day, another account takeover caused by an open redirector and the OAuth Implicit flow 🫠

    https://salt.security/blog/traveling-with-oauth-account-takeover-on-booking-com
    Portland, Oregon • 40°F
    14 likes 4 reposts 1 reply
    Thu, Mar 2, 2023 10:16am -08:00 #oauth #security
  • Charlotte Brandhorst-Satzkorn https://inuh.net/@catzkorn   •   Mar 2

    Ever wanted to use your own choice of OIDC IdP with @tailscale? I'm looking for private alpha testers - new and existing users welcome. DM me!

    Aaron Parecki
    I would love to check this out actually, I'm working on some documentation to help companies like Tailscale adopt features exactly like this!

    I don't have a way to DM you on mastodon but you can email me! https://aaronparecki.com/contact/
    Portland, Oregon • 39°F
    Thu, Mar 2, 2023 9:40am -08:00
older

Hi, I'm Aaron Parecki, Director of Identity Standards at Okta, and co-founder of IndieWebCamp. I maintain oauth.net, write and consult about OAuth, and participate in the OAuth Working Group at the IETF. I also help people learn about video production and livestreaming. (detailed bio)

I've been tracking my location since 2008 and I wrote 100 songs in 100 days. I've spoken at conferences around the world about owning your data, OAuth, quantified self, and explained why R is a vowel. Read more.

  • Director of Identity Standards at Okta
  • IndieWebCamp Founder
  • OAuth WG Editor
  • OpenID Board Member

  • 🎥 YouTube Tutorials and Reviews
  • 🏠 We're building a triplex!
  • ⭐️ Life Stack
  • ⚙️ Home Automation
  • All
  • Articles
  • Bookmarks
  • Notes
  • Photos
  • Replies
  • Reviews
  • Trips
  • Videos
  • Contact
© 1999-2025 by Aaron Parecki. Powered by p3k. This site supports Webmention.
Except where otherwise noted, text content on this site is licensed under a Creative Commons Attribution 3.0 License.
IndieWebCamp Microformats Webmention W3C HTML5 Creative Commons
WeChat ID
aaronpk_tv