51°F

Aaron Parecki

  • Articles
  • Notes
  • Photos
  • Aaron Parecki https://aaronparecki.com/   •   Nov 22
    Shoulda brought my cargo bike. That's a long way to carry a TV box if this works
    Aaron Parecki
    I did it. I found a TV and survived the crowds and carried the TV back to the MAX station.
    Portland, Oregon, USA • 48°F
    1 reply
    Thu, Nov 22, 2018 6:56pm -08:00
  • Aaron Parecki https://aaronparecki.com/   •   Nov 22
    My TV broke just in time for the Black Friday deals. I'm on the train right now heading to the Best Buy by the airport, and with any luck will emerge with a new TV. Or I will find out how many people come down from Vancouver to shop at that Best Buy. Wish me luck.
    Aaron Parecki
    Shoulda brought my cargo bike. That's a long way to carry a TV box if this works
    Portland, Oregon, USA • 47°F
    1 reply
    Thu, Nov 22, 2018 5:06pm -08:00
  • UPS Customer Support https://twitter.com/UPSHelp   •   Nov 22
    Thank you for reaching out to us. Please, DM the details of your concern. Include your tracking and phone number. Please include your shipping address. ^LG
    Aaron Parecki
    sometimes people say nice things about you on twitter too
    Portland, Oregon, USA • 44°F
    1 like 1 reply
    Wed, Nov 21, 2018 4:57pm -08:00
  • Nov 19

    Has anyone here used Adobe Premiere Rush CC on the iPad? I started looking at it today and it looks like a great video editor for small projects. Curious if anyone has any experience with it for an entire project.

    Aaron Parecki
    That does look nice! I hadn't heard of it before. I just downloaded it and went through the tutorial, not bad! I'll try to use it for my next project.
    Portland, Oregon, USA • 45°F
    Wed, Nov 21, 2018 7:12am -08:00
  • https://www.ietf.org/mail-archive/web/oauth/current/msg18477.html
    OAUTH-WG
    Aaron Parecki
    On Wed, Nov 7, 2018 at 7:20 AM Joseph Heenan <joseph at authlete.com> wrote:

    > It may be worth slightly rewording 7.2 as it may encourage a growing misconception that all native apps must be public clients. With many devices now having embedded HSMs, we’ve seen increasing interest in mobile apps being dynamically (per-install) registered oauth2 private clients, and that model has a lot of advantages. (I’m not sure if we might see a similar model evolving for web apps.)

    That's a great point, thanks. I've removed the reference to native apps being public clients since it doesn't really add anything to this spec if I have to caveat the description.

    On Thu, Nov 15, 2018 at 12:58 PM Torsten Lodderstedt <torsten at lodderstedt.net> wrote:

    > > > First of all the AS decides whether it issues refresh tokens or not. Having the ability does not mean the AS must do it. If you feel it’s safer to not do it. Fine.
    > > Sure, and this should be mentioned then somewhere (either in the threats doc or in this proposed best practice doc). Not all end developers using these protocols fully understand the ramifications.
    > @Aaron: I suggest this goes to the SPA BCP since this is client specific.

    Thanks, I agree that this document should include some recommendations around refresh token handling. Looking at the discussion in this thread, it seems there are a few different strategies folks are taking. Since it seems like there isn't a strong consensus, it sounds like this would be better suited for the "Security Considerations" section, and to not make MUST/SHOULD recommendations, but rather just point out the issues. Any thoughts on that before I take a stab at writing something?

    I've incorporated some of the other feedback here and published an updated version:

    https://tools.ietf.org/html/draft-parecki-oauth-browser-based-apps-01

    Thanks for the feedback so far.
    Portland, Oregon
    Mon, Nov 19, 2018 6:09pm -08:00 #oauth
  • Randall Degges https://twitter.com/rdegges   •   Nov 16
    Hohoho. About to give my new talk, 12 Factors of Pain and Suffering at #DOTIde in a few minutes! <3
    Aaron Parecki
    yesss i want to know how this goes
    Des Moines, Iowa • 43°F
    1 reply
    Thu, Nov 15, 2018 9:55pm -06:00
  • Aaron Parecki https://aaronparecki.com/   •   Nov 14
    whoa I've never been in a plane that's pulled out of the gate by making a u-turn and driving forwards before #tinyplane #travel
    Aaron Parecki
    Pulling out of the gate to the runway front first and taking off with no wait feels way more like riding in a car that can fly than an airplane
    Coal Valley, Illinois, USA
    Wed, Nov 14, 2018 6:47pm -06:00
  • yan https://twitter.com/bcrypt   •   Nov 14
    what was the first thing you ever did on the web? i think i was ~7 and i spent a few hours entering every URL i could think of into the browser to see what was there
    Aaron Parecki
    looked up MIDI versions of as many Beatles songs as I could find
    Milan, Illinois, USA
    1 like 1 reply
    Wed, Nov 14, 2018 5:00pm -06:00
  • https://micro.blog/manton/1041816
    Aaron Parecki
    Since Mastodon already supports OAuth 2, and all users already have a URL, adding IndieAuth to Mastodon would not be a huge leap.
    Portland, Oregon, USA • 44°F
    1 mention
    Tue, Nov 13, 2018 10:22am -08:00
  • Eddie Hinkle https://eddiehinkle.com/   •   Nov 11
    Oh wow!! Welcome to the iPhone X-life
    Aaron Parecki
    I'm pretty excited about the wireless charging! Not super thrilled about FaceID, since I thought TouchID was working just fine. I hear good things about the camera compared to the 6S too, so that should be fun!
    Portland, Oregon • 50°F
    1 like 1 reply
    Sun, Nov 11, 2018 7:53pm -08:00
  • https://micro.blog/boris/1022541
    Aaron Parecki
    I started working on a little proxy tool to do exactly that. It's just an API right now, but it lets you delegate all the activitypub stuff to an external service while still using your domain name as the identity. https://github.com/aaronpk/Nautilus
    Portland, Oregon, USA • 49°F
    1 reply
    Sat, Nov 10, 2018 2:20pm -08:00
  • https://www.ietf.org/mail-archive/web/oauth/current/msg18468.html
    OAUTH-WG
    Aaron Parecki
    Thanks Hannes,

    Since I wasn't able to give an intro during the meeting today, I'd like to share a little more context about this here as well.

    At the Internet Identity Workshop in Mountain View last week, I led a session to collect feedback on recommendations for OAuth for browser based apps. During the session, we came up with a list of several points based on the collective experience of the attendees. I then tried to address all those points in this draft.

    The goal of this is not to specify any new behavior, but rather to limit the possibilities that the existing OAuth specs provide, to ensure a secure implementation in browser based apps.

    Thanks in advance for your review and feedback!
    Portland, Oregon • 47°F
    Tue, Nov 6, 2018 11:13am +01:00 #oauth
  • https://indieweb.org/events/2018-10-31-homebrew-website-club
    Aaron Parecki
    Photo from HWC Berlin!
    Berlin, Berlin, DEU • 54°F
    1 like
    Fri, Nov 2, 2018 12:23pm +01:00
  • niklasjordan https://micro.blog/niklasjordan   •   Nov 1

    @aaronpk damn... I'm only in Berlin from Monday. Accessibility Club and BT conf. Are you attending one of this conferences?

    Aaron Parecki
    Yeah I'll be at Accessibility Club!
    Berlin, Berlin • 48°F
    Fri, Nov 2, 2018 1:02am +01:00
  • dietrich https://mastodon.social/@dietrich   •   Oct 31

    Prague sausage party. http://bit.ly/2yJxlHz

    Aaron Parecki
    TIL my last name means sausages in Slovak
    Berlin, Berlin
    1 like 1 repost 1 mention
    Thu, Nov 1, 2018 7:16am +01:00 #til
  • devilgate https://micro.blog/devilgate   •   Oct 31

    @aaronpk Good points. I think I was thinking in terms of, my users’ accounts are “my data” in some sense, so I should own it. But as you say, outsourcing is fine.

    Aaron Parecki
    Yep outsourcing is fine as long as you have a way to migrate to another provider! If we didn't hold that principle, it's a slippery slope to start saying everyone should host their site from a server in their house, and from there to having to build their own hardware. Gotta draw a line somewhere, and ours is identity and data portability.
    Berlin, Berlin • 47°F
    Wed, Oct 31, 2018 10:20pm +01:00
  • devilgate https://micro.blog/devilgate   •   Oct 30

    @aaronpk Sounds interesting. But doesn’t it mean that our account details will be stored on the Okta site, and not our own sites? Doesn’t that conflict with Indieweb principles, and also put Okta in a complex position regarding GDPR and other regulations?

    Or am I completely misunderstanding?

    Aaron Parecki
    Yes, that's the idea in fact. Re: GDPR, there's plenty about that you can read here https://www.okta.com/gdpr/

    But on the IndieWeb front, it's totally fine to outsource various parts of your website, as long as you own your online identity. That's why using a web host like micro.blog is still in line with IndieWeb principles as long as you point your domain to it.

    Using Okta to handle logging in to your own site is just outsourcing the internal user account management. There are some things I would rather have an expert do well for me rather than doing a poor job of it myself.
    Berlin, Berlin • 53°F
    1 reply
    Wed, Oct 31, 2018 4:44pm +01:00
  • Matthew McVickar https://mastodon.social/@matthewmcvickar   •   Oct 30

    I am very excited about Donut.js tonight because not only is it Donut.js, but it’s HALLOWEEN and I have lots of decorations and I love candy.

    Aaron Parecki
    halloweeneen anyway. Sorry to miss it!
    Seattle, Washington • 57°F
    1 like
    Tue, Oct 30, 2018 4:11pm -07:00
  • Philip Saa https://twitter.com/cowglow   •   Oct 30
    You coming to Germany for the IWC in Berlin??
    Aaron Parecki
    I sure am! Heading to the airport right now in fact!
    Portland, Oregon • 48°F
    1 like 1 reply
    Tue, Oct 30, 2018 10:06am -07:00
  • Melissa Santos https://weirder.earth/@ansate   •   Oct 30

    First day of new job, new routine. I'm starting as I mean to go - work from home. My big non-work goal is to leave the house today for at least a walk around the block.

    Aaron Parecki
    two birds with one stone: take conference calls outside on a walk!
    Portland, Oregon • 47°F
    Tue, Oct 30, 2018 8:27am -07:00
older

Hi, I'm Aaron Parecki, Director of Identity Standards at Okta, and co-founder of IndieWebCamp. I maintain oauth.net, write and consult about OAuth, and participate in the OAuth Working Group at the IETF. I also help people learn about video production and livestreaming. (detailed bio)

I've been tracking my location since 2008 and I wrote 100 songs in 100 days. I've spoken at conferences around the world about owning your data, OAuth, quantified self, and explained why R is a vowel. Read more.

  • Director of Identity Standards at Okta
  • IndieWebCamp Founder
  • OAuth WG Editor
  • OpenID Board Member

  • 🎥 YouTube Tutorials and Reviews
  • 🏠 We're building a triplex!
  • ⭐️ Life Stack
  • ⚙️ Home Automation
  • All
  • Articles
  • Bookmarks
  • Notes
  • Photos
  • Replies
  • Reviews
  • Trips
  • Videos
  • Contact
© 1999-2025 by Aaron Parecki. Powered by p3k. This site supports Webmention.
Except where otherwise noted, text content on this site is licensed under a Creative Commons Attribution 3.0 License.
IndieWebCamp Microformats Webmention W3C HTML5 Creative Commons
WeChat ID
aaronpk_tv