65°F

Aaron Parecki

  • Articles
  • Notes
  • Photos
  • M. Brandon Lee | THIS IS TECH TODAY https://twitter.com/thisistechtoday   •   Feb 11
    I’d love to get @Snubs and @aaronpk on the scene 👀
    Aaron Parecki
    yeah I suspect you're right. I'm curious what the next play is. Maybe they send you a download link to the special "Spotify VIP" app?
    Portland, Oregon, USA • 30°F
    1 like 2 replies
    Thu, Feb 11, 2021 4:14pm -08:00
  • K. Mike Merrill https://twitter.com/kmikeym   •   Feb 11
    What’s your current setup for backing up power? (Video idea!)
    Aaron Parecki
    Clearly I need to beef it up a bit, but right now I have a UPS on the network gear and also at my desk. It can keep things powered for about 30-40 minutes, and my internet is fiber so it stays online too
    Portland, Oregon • 31°F
    2 likes 4 replies
    Thu, Feb 11, 2021 2:53pm -08:00
  • Nick Fiacco https://twitter.com/FiaccoNick   •   Feb 11
    Is there a good way to verify the identity of a public app requesting an auth code?
    Aaron Parecki
    No not really, that's why the redirect URL is so important to get right. It's not a great situation, but it would require cooperation from the OS in order to have a more secure flow. That said, it's also a relatively unlikely attack vector so people mostly don't worry about it.
    Portland, Oregon • 33°F
    1 like
    Thu, Feb 11, 2021 12:51pm -08:00
  • Nick Fiacco https://twitter.com/FiaccoNick   •   Feb 11
    Chances are I’m missing something— @aaronpk @leahculver does this make sense to either of you?
    Aaron Parecki
    Yes, you're right, but that doesn't mean PKCE is not secure. This is just an inherent limitation of public clients that can't use a client secret. PKCE does solve several attacks, but it doesn't provide authentication of the app itself.
    Portland, Oregon • 33°F
    2 likes
    Thu, Feb 11, 2021 9:58am -08:00
  • Jᵾlien Genestoux https://twitter.com/julien51   •   Feb 11
    Ideally though, an identity shouldn't have to be tied to a server, even if I own it?
    Aaron Parecki
    That's one opinion yes. There are good arguments on both sides.
    Portland, Oregon • 40°F
    1 like 6 replies
    Wed, Feb 10, 2021 7:22pm -08:00
  • Kevin Marks https://twitter.com/kevinmarks   •   Feb 11
    That's very true, and the Wordpress plugin makes the case as well.
    Aaron Parecki
    Yep although the WordPress plugin requires some active effort by the user. At least it’s just installing a plugin and not dealing with markup though.
    Portland, Oregon • 40°F
    8 replies
    Wed, Feb 10, 2021 6:57pm -08:00
  • Kevin Marks https://twitter.com/kevinmarks   •   Feb 11
    That's part of it, though the RelMeAuth model can mitigate that to some extent. A lot of it is having a use case to authorise for. Micropub is one use case that can make sense to users
    Aaron Parecki
    Nah, don’t forget that every micro.blog account is an IndieAuth account too. Users don’t need to have any knowledge of anything under the hood for that to work. We need more service providers to implement it more than anything.
    Portland, Oregon • 40°F
    4 likes 1 repost 10 replies
    Wed, Feb 10, 2021 6:53pm -08:00
  • Blaine Cook https://twitter.com/blaine   •   Feb 9
    (fwiw, we're working on a really awesome auth flow for conde that is custom-built because all the vendors big enough to support us are busy selling horses)
    Aaron Parecki
    I would actually be very curious to learn more about this, cause we've got some fun stuff coming down the pipe too
    Portland, Oregon • 43°F
    2 likes 1 reply
    Mon, Feb 8, 2021 5:19pm -08:00
  • Blaine Cook https://twitter.com/blaine   •   Feb 9
    You *know* that's like Ford offering fast horses that will run alongside the car... 😜
    Aaron Parecki
    sometimes you have to sell faster horses until people realize what they actually want is a car 😄
    Portland, Oregon • 43°F
    1 like 1 reply
    Mon, Feb 8, 2021 5:13pm -08:00
  • Blaine Cook https://twitter.com/blaine   •   Feb 9
    Security questions are never the right thing. Don't let the infosec bullies resort to ableist (good memory much?) tactics because they suck at UX. ❤️
    Aaron Parecki
    Not to kick the can down the road, but we wouldn't even provide the option of a security question if people didn't ask for it 😦
    Portland, Oregon • 43°F
    2 likes 8 replies
    Mon, Feb 8, 2021 5:00pm -08:00
  • muncman https://micro.blog/muncman   •   Feb 8

    @aaronpk Thanks — gonna try that myself. Even if it helps a little, it’ll be worth the effort.

    Aaron Parecki
    I've been getting 1-2 calls a day for the last few weeks from this, always a company assuming I have some role based on my title that I definitely don't have. I really hope this makes it stop.
    Portland, Oregon • 39°F
    Mon, Feb 8, 2021 12:04pm -08:00
  • Blaine Cook https://twitter.com/blaine   •   Feb 8
    Oh god. Was there an exec who moved from @united to @okta? @aaronpk what happened to make this a thing? 😭
    Aaron Parecki
    Ugh I know. The good news is the admin can disable security questions on the entire org if they want.
    Portland, Oregon • 39°F
    3 likes 21 replies
    Mon, Feb 8, 2021 10:49am -08:00
  • Víctor Suárez https://twitter.com/vicsuaba   •   Feb 8
    @aaronpk I'm going to do a livestream in someone's youtube channel. The live has been programmed and it's public, but doesn't appear in their channel, so people can't see it and add a reminder like in your channel. Am I missing something?
    Thanks!
    https://youtu.be/4RiB42EqhYo
    Aaron Parecki
    There's an option under "customize channel" to add a "featured section" that shows the next upcoming livestream. It takes a bit to find and youtube keeps rearranging stuff. Hope that helps!
    Portland, Oregon • 36°F
    1 like 1 reply
    Mon, Feb 8, 2021 6:42am -08:00
  • Carmelo Anthony’s Mute Button Operator https://twitter.com/VoiceOfUnreason   •   Feb 8
    Hm, weird, wonder if it updates at weird intervals or something.
    Aaron Parecki
    It was hovering around that number during the stream too, really weird. I'm sure it's just some weird bug
    Portland, Oregon • 45°F
    Sun, Feb 7, 2021 5:08pm -08:00
  • Carmelo Anthony’s Mute Button Operator https://twitter.com/VoiceOfUnreason   •   Feb 8
    @aaronpk Watching the recording of today’s livestream rn. I’ve seen reference to mystery low bitrates before from others. It’s certainly due to (nearly) static screens allowing the ATEM Mini’s encoder to reduce the bitrate dynamically without reducing perceptive quality, right?
    Aaron Parecki
    Normally yes, and I regularly see low bitrates on my countdown screen and when sharing my computer screen. But it was showing that low bitrate even when it was on my regular video feed so it was definitely not encoding at that bitrate or it would have looked like trash.
    Portland, Oregon • 45°F
    2 replies
    Sun, Feb 7, 2021 5:06pm -08:00
  • https://mxb.dev/blog/webmention-analytics/
    Aaron Parecki
    This is fantastic! Makes me want to add these kinds of graphs and analytics to https://webmention.io itself!
    Portland, Oregon, USA • 40°F
    Sun, Feb 7, 2021 7:11am -08:00
  • M. Brandon Lee | THIS IS TECH TODAY https://twitter.com/thisistechtoday   •   Feb 7
    Note to my fellow creators...don't release a video on the day of the Super Bowl unless it's about the Super Bowl. You'll regret it.
    Aaron Parecki
    they scheduled the superbowl on my livestream day, I'm gonna do it anyway
    Portland, Oregon • 45°F
    5 likes 1 reply
    Sat, Feb 6, 2021 9:34pm -08:00
  • https://justinmiller.io/microposts/2021/02/06/1/
    Aaron Parecki
    That's awesome! #OwnYourLikes
    Portland, Oregon • 45°F
    Sat, Feb 6, 2021 7:10pm -08:00 #ownyourlikes
  • poetalegre https://micro.blog/poetalegre   •   Feb 6

    @aaronpk All those greens are fantastic. It's like a fairy land.

    Aaron Parecki
    Thanks! It really is!
    Portland, Oregon • 45°F
    Sat, Feb 6, 2021 4:08pm -08:00
  • Ben Werdmüller https://werd.io/profile/benwerd   •   Feb 5
    How might I build a front end only Disqus-like comments section (i.e., add one line of JS, get comments on a page) with no centralized components, no blockchain, and no required authentication? Is there a decentralized key value store I'm missing?
    Aaron Parecki
    If you had enough visitors always on the page you could "store" them in webtorrents, so that all the visitors to your site would be participating in storing all the comments.
    Portland, Oregon • 51°F
    Fri, Feb 5, 2021 3:03pm -08:00
older

Hi, I'm Aaron Parecki, Director of Identity Standards at Okta, and co-founder of IndieWebCamp. I maintain oauth.net, write and consult about OAuth, and participate in the OAuth Working Group at the IETF. I also help people learn about video production and livestreaming. (detailed bio)

I've been tracking my location since 2008 and I wrote 100 songs in 100 days. I've spoken at conferences around the world about owning your data, OAuth, quantified self, and explained why R is a vowel. Read more.

  • Director of Identity Standards at Okta
  • IndieWebCamp Founder
  • OAuth WG Editor
  • OpenID Board Member

  • 🎥 YouTube Tutorials and Reviews
  • 🏠 We're building a triplex!
  • ⭐️ Life Stack
  • ⚙️ Home Automation
  • All
  • Articles
  • Bookmarks
  • Notes
  • Photos
  • Replies
  • Reviews
  • Trips
  • Videos
  • Contact
© 1999-2025 by Aaron Parecki. Powered by p3k. This site supports Webmention.
Except where otherwise noted, text content on this site is licensed under a Creative Commons Attribution 3.0 License.
IndieWebCamp Microformats Webmention W3C HTML5 Creative Commons
WeChat ID
aaronpk_tv