62°F

Aaron Parecki

  • Articles
  • Notes
  • Photos
  • Aaron Parecki
    Had some fun testing out the AVKANS Go they sent me during the livestream today! At around the same price as a GoPro, it's a clear winner vs the GoPro for livestreaming!
    Portland, Oregon, USA
    Sun, Feb 16, 2025 1:00pm -08:00 #365 #livestream #youtube
  • Anthony Sorace https://pdx.social/@a   •   Feb 16

    @aaronpk Hrm. Subsystem code per user? I don’t still have my Zelle setup email. Do your login codes start with 4? (If they’re always 4, I assume the crackers already know this.)

    Aaron Parecki
    yeah normally the direct ones are 4
    Portland, Oregon • 41°F
    Sun, Feb 16, 2025 8:32am -08:00
  • BrianKrebs https://infosec.exchange/@briankrebs   •   Feb 16

    Seeing as we're paving over federal websites left and right, maybe we can finally address the issue of open redirects on .gov websites? This isn't a new issue and it's not going away. But probably we shouldn't see dozens of pages of porn results all getting indexed by search engines by abusing redirects on the Centers for Disease Control (CDC) website, for example:

    https://www.google.com/search?q=site:cdc.gov&client=ubuntu-sn&hs=V5N&sca_esv=4986d38ff6c52357&channel=fs&source=lnt&tbs=qdr:d&sa=X&ved=2ahUKEwjU0c2NnciLAxV6STABHey_JpoQpwV6BAgDEAg&biw=1658&bih=863&dpr=1

    Aaron Parecki
    whoa, that appears to be a compromised azure app on that subdomain. If you fetch one of the URLs with curl, it straight up returns xxx HTML, it's not even redirecting first.
    Portland, Oregon • 41°F
    1 like
    Sun, Feb 16, 2025 7:21am -08:00
  • Michael Slade https://mastodon.cloud/@michaelslade   •   Feb 16

    @aaronpk They’re lonely and want to see if anyone notices.

    Aaron Parecki
    I wouldn't blame someone for hiding this kind of easter egg tbh
    Portland, Oregon • 40°F
    1 like
    Sun, Feb 16, 2025 5:57am -08:00
  • Anthony Sorace https://pdx.social/@a   •   Feb 16

    @aaronpk Maybe adding to the mystery: my login codes always start with a 4 (yeah, I’m okay making that effectively 7 digits now, whatever), but when they gave me one for signing up with Zelle it was 8 digits with a leading 2. Totally speculative, but I wonder if they assign a leading digit per subsystem.

    Aaron Parecki
    Oh fascinating, I just tested with Zelle and got similar results, the email code from Zelle started with 8, the SMS was 7
    Portland, Oregon • 40°F
    1 reply
    Sun, Feb 16, 2025 5:56am -08:00
  • Jak2k 🦀🐧🇪🇺 https://mastodontech.de/@jak2k   •   Feb 16

    @aaronpk Are they counting up?

    Aaron Parecki
    omg 🤣
    Portland, Oregon • 40°F
    Sun, Feb 16, 2025 5:55am -08:00
  • 9:15pm
    Asleep
    5:07am
    Awake
    7h 52m
    Slept
    16m
    Awake for
    Portland, Oregon, USA • 41°F
    Sun, Feb 16, 2025 5:07am -08:00
  • Aaron Parecki
    Contributions from: Austria, Canada, France, Germany, Ghana, Hungary, India, Kuwait, Russian Federation, Turkey, United Kingdom, United States
    Sun, Feb 16, 2025 12:23am -08:00
  • Aaron Parecki
    Contributions from: Austria, France, Germany, Ghana, Hungary, India, Kuwait, Russian Federation, Turkey, United Kingdom, United States
    Sat, Feb 15, 2025 9:08pm -08:00
  • Brandon Kraft ❤️‍🔥🧡 https://religious.social/@kraft   •   Feb 16

    @aaronpk what gets me is they ask for user name and password, then 2fa with the password again.

    Aaron Parecki
    gotta be extra secure. can't have that session integrity managed server side.
    Portland, Oregon • 40°F
    Sat, Feb 15, 2025 8:47pm -08:00
  • Jonathan Yu https://mastodon.social/@jawnsy   •   Feb 16

    @aaronpk Email codes always seem to start with 4, maybe it's something to do with the medium they sent it over?

    Aaron Parecki
    same with the SMS codes for me
    Portland, Oregon • 41°F
    1 like 1 reply
    Sat, Feb 15, 2025 6:17pm -08:00
  • Aaron Parecki
    Chase sends 8-digit 2fa SMS codes, which seems excessive compared to the 6 that most other places use, but even weirder is that the first digit of them has always been the same, effectively making it a 7 digit code. Anyone know what's up with that?
    Portland, Oregon, USA • 41°F
    4 likes 7 replies
    Sat, Feb 15, 2025 5:56pm -08:00 #security #sms #2fa
  • Hot Sauce Tasting
    Portland, Oregon • 41°F
    Sat, Feb 15, 2025 4:25pm -08:00
  • Beer
    Portland, Oregon, USA • 41°F
    Sat, Feb 15, 2025 4:14pm -08:00
  • Vegan Ramen
    Portland, Oregon, USA • 42°F
    Sat, Feb 15, 2025 3:41pm -08:00
  • Aaron Parecki
    at Kayo's Ramen Bar
    Portland, Oregon • Sat, February 15, 2025 3:35pm
    45.550467 -122.666516
    Portland, OR, United States • 42°F
    Checked in by anomalily
    17 Coins
    Sat, Feb 15, 2025 3:35pm -08:00 #365
  • 10:32pm
    Asleep
    6:07am
    Awake
    7h 35m
    Slept
    13m
    Awake for
    Portland, Oregon, USA • 34°F
    Sat, Feb 15, 2025 6:07am -08:00
  • Aaron Parecki
    Contributions from: Austria, France, Germany, Ghana, Hungary, India, Kuwait, Russian Federation, Turkey, United Kingdom, United States
    Fri, Feb 14, 2025 2:49pm -08:00
  • Paul Butler – Smuggling arbitrary data through an emoji (paulbutler.org)
    Fri, Feb 14, 2025 2:45pm -08:00 #emoji #steganography
  • Aaron Parecki
    Got even more snow overnight!
    Portland, Oregon, USA
    Fri, Feb 14, 2025 9:10am -08:00 #snow #365
older

Hi, I'm Aaron Parecki, Director of Identity Standards at Okta, and co-founder of IndieWebCamp. I maintain oauth.net, write and consult about OAuth, and participate in the OAuth Working Group at the IETF. I also help people learn about video production and livestreaming. (detailed bio)

I've been tracking my location since 2008 and I wrote 100 songs in 100 days. I've spoken at conferences around the world about owning your data, OAuth, quantified self, and explained why R is a vowel. Read more.

  • Director of Identity Standards at Okta
  • IndieWebCamp Founder
  • OAuth WG Editor
  • OpenID Board Member

  • 🎥 YouTube Tutorials and Reviews
  • 🏠 We're building a triplex!
  • ⭐️ Life Stack
  • ⚙️ Home Automation
  • All
  • Articles
  • Bookmarks
  • Notes
  • Photos
  • Replies
  • Reviews
  • Trips
  • Videos
  • Contact
© 1999-2025 by Aaron Parecki. Powered by p3k. This site supports Webmention.
Except where otherwise noted, text content on this site is licensed under a Creative Commons Attribution 3.0 License.
IndieWebCamp Microformats Webmention W3C HTML5 Creative Commons
WeChat ID
aaronpk_tv