62°F

Aaron Parecki

  • Articles
  • Notes
  • Photos
  • Photo “Wear the mask” Joseph https://twitter.com/photojoseph   •   Feb 12
    Anyone else got this mysterious app on their Mac? #5KPlayer which I donโ€™t remember installing, is NOT from Mac App Store, automatically became default video player, runs in background after quitting, but is actually an iOS app (and not on my iOS devices or in my iOS app history)?
    Aaron Parecki
    Yikes, found a reference to it in this article, definitely malware https://www.zdnet.com/google-amp/article/promethium-apt-attacks-surge-government-sponsorship-suspected/
    Portland, Oregon • 25°F
    1 like 1 reply
    Fri, Feb 12, 2021 9:21am -08:00
  • Blaine Cook https://twitter.com/blaine   •   Feb 12
    My company uses your company. I have one password, don't use a password manager, and can access every service I need to do my job, and I can do that extremely securely.
    Aaron Parecki
    That's exactly what I want, but across the whole internet, oh and maybe drop the password too ๐Ÿ˜…
    Portland, Oregon • 25°F
    9 replies
    Fri, Feb 12, 2021 7:12am -08:00
  • Blaine Cook https://twitter.com/blaine   •   Feb 11
    For sure - my complaint is that we wouldn't stand for the medical profession to say "abstinence is the only way to prevent unwanted childbirth"; I'm not saying no-one should use password managers. I'm trying to say that it's our (security folks) responsibility to build better.
    Aaron Parecki
    My problem with this whole thread is that yes, of course we need something better than passwords, but also, yes, there is a lot of improvement being made right now. It's not like someone can make something that "solves passwords" and suddenly everyone will be using it.
    Portland, Oregon • 25°F
    3 likes 1 reply
    Fri, Feb 12, 2021 7:06am -08:00
  • Sara ๐Ÿ‘y https://twitter.com/saradietschy   •   Feb 11
    gmail text prediction is gettin kinda spooky I can't wait to type one word and then just tab tab tab tab out my entire email
    Aaron Parecki
    There's a scifi book from 10 years ago about literally this, it's a trip ๐Ÿ˜‚ https://amzn.to/37oaMKb
    Portland, Oregon • 29°F
    1 like
    Thu, Feb 11, 2021 9:25pm -08:00
  • K. Mike Merrill https://twitter.com/kmikeym   •   Feb 12
    Fiber stays on if power dies? Is it dumb I didnโ€™t know that?
    Aaron Parecki
    Depends on what's powering the other end of the fiber line. I guess mine is on a different grid, but I'm also in a weird spot between two different power companies.
    Portland, Oregon • 29°F
    1 like
    Thu, Feb 11, 2021 8:57pm -08:00
  • Shannon Morse wears a mask responsibly https://twitter.com/Snubs   •   Feb 12
    One time me and @hak5darren sent a fake Microsoft tech support scammer goatse after keeping them on the phone for an hour.
    Aaron Parecki
    ๐Ÿ‘ that is some A plus countertrolling ๐Ÿ‘
    Portland, Oregon, USA • 30°F
    1 like
    Thu, Feb 11, 2021 4:23pm -08:00
  • M. Brandon Lee | THIS IS TECH TODAY https://twitter.com/thisistechtoday   •   Feb 12
    Should I play along? Iโ€™m curious now.
    Aaron Parecki
    I would if it were me! Just stay on high alert mode of course... don't download anything, don't connect any OAuth apps to anything, and click links only using an isolated computer. I'm always curious about these things!
    Portland, Oregon, USA • 30°F
    1 like 4 replies
    Thu, Feb 11, 2021 4:19pm -08:00
  • M. Brandon Lee | THIS IS TECH TODAY https://twitter.com/thisistechtoday   •   Feb 11
    Iโ€™d love to get @Snubs and @aaronpk on the scene ๐Ÿ‘€
    Aaron Parecki
    yeah I suspect you're right. I'm curious what the next play is. Maybe they send you a download link to the special "Spotify VIP" app?
    Portland, Oregon, USA • 30°F
    1 like 2 replies
    Thu, Feb 11, 2021 4:14pm -08:00
  • K. Mike Merrill https://twitter.com/kmikeym   •   Feb 11
    Whatโ€™s your current setup for backing up power? (Video idea!)
    Aaron Parecki
    Clearly I need to beef it up a bit, but right now I have a UPS on the network gear and also at my desk. It can keep things powered for about 30-40 minutes, and my internet is fiber so it stays online too
    Portland, Oregon • 31°F
    2 likes 4 replies
    Thu, Feb 11, 2021 2:53pm -08:00
  • Nick Fiacco https://twitter.com/FiaccoNick   •   Feb 11
    Is there a good way to verify the identity of a public app requesting an auth code?
    Aaron Parecki
    No not really, that's why the redirect URL is so important to get right. It's not a great situation, but it would require cooperation from the OS in order to have a more secure flow. That said, it's also a relatively unlikely attack vector so people mostly don't worry about it.
    Portland, Oregon • 33°F
    1 like
    Thu, Feb 11, 2021 12:51pm -08:00
  • Nick Fiacco https://twitter.com/FiaccoNick   •   Feb 11
    Chances are Iโ€™m missing somethingโ€” @aaronpk @leahculver does this make sense to either of you?
    Aaron Parecki
    Yes, you're right, but that doesn't mean PKCE is not secure. This is just an inherent limitation of public clients that can't use a client secret. PKCE does solve several attacks, but it doesn't provide authentication of the app itself.
    Portland, Oregon • 33°F
    2 likes
    Thu, Feb 11, 2021 9:58am -08:00
  • Jแตพlien Genestoux https://twitter.com/julien51   •   Feb 11
    Ideally though, an identity shouldn't have to be tied to a server, even if I own it?
    Aaron Parecki
    That's one opinion yes. There are good arguments on both sides.
    Portland, Oregon • 40°F
    1 like 6 replies
    Wed, Feb 10, 2021 7:22pm -08:00
  • Kevin Marks https://twitter.com/kevinmarks   •   Feb 11
    That's very true, and the Wordpress plugin makes the case as well.
    Aaron Parecki
    Yep although the WordPress plugin requires some active effort by the user. At least itโ€™s just installing a plugin and not dealing with markup though.
    Portland, Oregon • 40°F
    8 replies
    Wed, Feb 10, 2021 6:57pm -08:00
  • Kevin Marks https://twitter.com/kevinmarks   •   Feb 11
    That's part of it, though the RelMeAuth model can mitigate that to some extent. A lot of it is having a use case to authorise for. Micropub is one use case that can make sense to users
    Aaron Parecki
    Nah, donโ€™t forget that every micro.blog account is an IndieAuth account too. Users donโ€™t need to have any knowledge of anything under the hood for that to work. We need more service providers to implement it more than anything.
    Portland, Oregon • 40°F
    4 likes 1 repost 10 replies
    Wed, Feb 10, 2021 6:53pm -08:00
  • Blaine Cook https://twitter.com/blaine   •   Feb 9
    (fwiw, we're working on a really awesome auth flow for conde that is custom-built because all the vendors big enough to support us are busy selling horses)
    Aaron Parecki
    I would actually be very curious to learn more about this, cause we've got some fun stuff coming down the pipe too
    Portland, Oregon • 43°F
    2 likes 1 reply
    Mon, Feb 8, 2021 5:19pm -08:00
  • Blaine Cook https://twitter.com/blaine   •   Feb 9
    You *know* that's like Ford offering fast horses that will run alongside the car... ๐Ÿ˜œ
    Aaron Parecki
    sometimes you have to sell faster horses until people realize what they actually want is a car ๐Ÿ˜„
    Portland, Oregon • 43°F
    1 like 1 reply
    Mon, Feb 8, 2021 5:13pm -08:00
  • Blaine Cook https://twitter.com/blaine   •   Feb 9
    Security questions are never the right thing. Don't let the infosec bullies resort to ableist (good memory much?) tactics because they suck at UX. โค๏ธ
    Aaron Parecki
    Not to kick the can down the road, but we wouldn't even provide the option of a security question if people didn't ask for it ๐Ÿ˜ฆ
    Portland, Oregon • 43°F
    2 likes 8 replies
    Mon, Feb 8, 2021 5:00pm -08:00
  • muncman https://micro.blog/muncman   •   Feb 8

    @aaronpk Thanks โ€” gonna try that myself. Even if it helps a little, itโ€™ll be worth the effort.

    Aaron Parecki
    I've been getting 1-2 calls a day for the last few weeks from this, always a company assuming I have some role based on my title that I definitely don't have. I really hope this makes it stop.
    Portland, Oregon • 39°F
    Mon, Feb 8, 2021 12:04pm -08:00
  • Blaine Cook https://twitter.com/blaine   •   Feb 8
    Oh god. Was there an exec who moved from @united to @okta? @aaronpk what happened to make this a thing? ๐Ÿ˜ญ
    Aaron Parecki
    Ugh I know. The good news is the admin can disable security questions on the entire org if they want.
    Portland, Oregon • 39°F
    3 likes 21 replies
    Mon, Feb 8, 2021 10:49am -08:00
  • Víctor Suárez https://twitter.com/vicsuaba   •   Feb 8
    @aaronpk I'm going to do a livestream in someone's youtube channel. The live has been programmed and it's public, but doesn't appear in their channel, so people can't see it and add a reminder like in your channel. Am I missing something?
    Thanks!
    https://youtu.be/4RiB42EqhYo
    Aaron Parecki
    There's an option under "customize channel" to add a "featured section" that shows the next upcoming livestream. It takes a bit to find and youtube keeps rearranging stuff. Hope that helps!
    Portland, Oregon • 36°F
    1 like 1 reply
    Mon, Feb 8, 2021 6:42am -08:00
older

Hi, I'm Aaron Parecki, Director of Identity Standards at Okta, and co-founder of IndieWebCamp. I maintain oauth.net, write and consult about OAuth, and participate in the OAuth Working Group at the IETF. I also help people learn about video production and livestreaming. (detailed bio)

I've been tracking my location since 2008 and I wrote 100 songs in 100 days. I've spoken at conferences around the world about owning your data, OAuth, quantified self, and explained why R is a vowel. Read more.

  • Director of Identity Standards at Okta
  • IndieWebCamp Founder
  • OAuth WG Editor
  • OpenID Board Member

  • ๐ŸŽฅ YouTube Tutorials and Reviews
  • ๐Ÿ  We're building a triplex!
  • โญ๏ธ Life Stack
  • โš™๏ธ Home Automation
  • All
  • Articles
  • Bookmarks
  • Notes
  • Photos
  • Replies
  • Reviews
  • Trips
  • Videos
  • Contact
© 1999-2025 by Aaron Parecki. Powered by p3k. This site supports Webmention.
Except where otherwise noted, text content on this site is licensed under a Creative Commons Attribution 3.0 License.
IndieWebCamp Microformats Webmention W3C HTML5 Creative Commons
WeChat ID
aaronpk_tv