64°F

Aaron Parecki

  • Articles
  • Notes
  • Photos
  • Brock Allen https://twitter.com/BrockLAllen   •   Feb 25
    Hey @aaronpk, can you explain this help article? It makes no sense to me. TIA

    https://support.okta.com/help/s/article/Browser-requests-to-the-token-endpoint-must-use-Proof-Key-for-Code-Exchange?language=en_US
    Aaron Parecki
    Oh yeah, I remember this one. I don't remember if this is still current behavior, but basically Okta is tying to prevent browsers from using anything other than the authorization code PKCE flow. It does that by detecting the Origin header which isn't sent by server apps.
    Portland, Oregon • 34°F
    1 like 11 replies
    Thu, Feb 24, 2022 6:50pm -08:00
  • Aaron Parecki https://aaronparecki.com/   •   Feb 23
    Do I know anyone involved with @LoginDotGov? I found a few (minor) issues with the OAuth/OpenID docs there https://developers.login.gov/oidc/
    Aaron Parecki
    I didn't realize before, but their docs are open source! I just sent them a PR to fix it!

    https://github.com/18F/identity-dev-docs/pull/235
    Portland, Oregon, USA • 29°F
    8 likes
    Wed, Feb 23, 2022 11:25am -08:00
  • DoctorMac https://micro.blog/DoctorMac   •   Feb 23

    @aaronpk you would use this mechanism: 18f.gsa.gov/vulnerabi...

    "We accept and discuss vulnerability reports on HackerOne, via email at tts-vulnerability-reports@gsa.gov, or through the form"

    HackerOne is the preferred reporting.

    Aaron Parecki
    Thanks, it's not a security issue, just some misleading wording in the docs. I sent them a PR to fix it!
    Portland, Oregon, USA • 29°F
    Wed, Feb 23, 2022 11:24am -08:00
  • Jason Garber https://twitter.com/jgarber   •   Feb 23
    18F manages the app. Main source repo is here: https://github.com/18F/identity-idp

    Not sure if the docs are generated from there, though.
    Aaron Parecki
    oh awesome, their docs are on there! I will just send them a PR then!

    https://github.com/18F/identity-dev-docs
    Portland, Oregon, USA • 29°F
    1 like 1 reply
    Wed, Feb 23, 2022 9:47am -08:00
  • Nils https://coolworld.cc/@n   •   Feb 20

    @aaronpk Lawyer up and hit em hard. False DMCA claims are no Kavaliersdelikt (there‘s one for your German lessons).

    Aaron Parecki
    Thankfully the place I licensed the songs from has a team of lawyers on it now!
    Portland, Oregon • 40°F
    Sun, Feb 20, 2022 7:42am -08:00
  • Raphael Lullis https://mastodon.communick.com/@raphael   •   Feb 20

    @aaronpk Aaron, so many popular youtubers dealing with bogus copyright claims now... what is missing on the open source video streaming platforms for them to make the
    switch? Is it "just" a matter of network effects?

    Aaron Parecki
    Yeah there's a lot more to it than just pushing out a video stream. Discovery and payments are the two big reasons to use YouTube/Twitch.

    If you stream on your own website, nobody will know unless you tell them thru some other network. If you also want to monetize that you have to sell your own ads.
    Portland, Oregon • 41°F
    Sun, Feb 20, 2022 6:16am -08:00
  • Vittorio https://twitter.com/vibronet   •   Feb 20
    Any day now
    Aaron Parecki
    Me picking out new kitchen appliances
    Portland, Oregon • 46°F
    1 like
    Sat, Feb 19, 2022 10:24pm -08:00
  • Sara Dietschy 🍑y https://twitter.com/saradietschy   •   Feb 20
    How do yal spend your Saturday night 🙃
    Aaron Parecki
    I mean, since you asked... https://twitter.com/aaronpk/status/1495218082461011969
    Portland, Oregon • 46°F
    Sat, Feb 19, 2022 8:15pm -08:00
  • Anandkar https://twitter.com/anandkar1987   •   Feb 20
    I want to buy this course. Is there any coupon code?
    Aaron Parecki
    Yeah! Udemy runs coupons on it pretty often! I don't know the exact schedule, but check back again every week or so and you'll probably find it discounted!
    Portland, Oregon • 46°F
    Sat, Feb 19, 2022 8:14pm -08:00
  • Aaron Parecki https://aaronparecki.com/   •   Feb 19
    anyway, if you want to hear me rant for an hour about what I'm dealing with trying to fight this obviously invalid (i'm being generous here) Content ID claim on some of my YouTube videos, join me tomorrow at 10am Pacific https://youtu.be/OLK2re0LfrQ
    Aaron Parecki
    oh no oh no it gets worse... I literally just got an email saying they rejected the dispute. They are obviously wrong about this and anyone at YouTube with half a brain can tell you this, but how am I supposed to get someone at YouTube to care??
    Portland, Oregon, USA • 46°F
    3 likes 4 replies
    Sat, Feb 19, 2022 8:02pm -08:00
  • Gary https://twitter.com/every_daydad   •   Feb 19
    Finally had to pull the safari bandage off.

    Fully using firefox on both windows and apple now.
    Aaron Parecki
    if there's nothing else that we've come to expect from you, it's drastically changing up your tech preferences every month or so
    Portland, Oregon • 47°F
    6 likes 2 replies
    Sat, Feb 19, 2022 7:03pm -08:00
  • Aaron Parecki https://aaronparecki.com/   •   Feb 19
    this system is inherently rigged to the advantage of copyright holders, except it's also extremely easy for a supposed copyright holder to be malicious, or at best just be wrong or make a mistake, and there's very little a content creator can do
    Aaron Parecki
    anyway, if you want to hear me rant for an hour about what I'm dealing with trying to fight this obviously invalid (i'm being generous here) Content ID claim on some of my YouTube videos, join me tomorrow at 10am Pacific https://youtu.be/OLK2re0LfrQ
    Portland, Oregon, USA • 47°F
    2 likes 1 reply
    Sat, Feb 19, 2022 6:23pm -08:00
  • Aaron Parecki https://aaronparecki.com/   •   Feb 19
    So I've been spending my Saturday night preparing for tomorrow's livestream by reading up on all the details of YouTube's Content ID system and reading the licenses of various royalty free music sites, and all it's doing is making me more and more angry about the whole system...
    Aaron Parecki
    this system is inherently rigged to the advantage of copyright holders, except it's also extremely easy for a supposed copyright holder to be malicious, or at best just be wrong or make a mistake, and there's very little a content creator can do
    Portland, Oregon, USA • 47°F
    5 likes 2 reposts 1 reply
    Sat, Feb 19, 2022 6:07pm -08:00
  • Anders Pitman https://twitter.com/anderspitman   •   Feb 18
    After a bit more research, looks like urn:ietf:wg:oauth:2.0:oob might be a more idiomatic (and probably more secure) approach?
    Aaron Parecki
    I'd recommend the device flow for it tbh, I've seen it used that way a bunch. The oob thing is more for installed apps that can monitor the address bar. With a command line app, especially over ssh, that doesn't really work.
    Portland, Oregon, USA • 43°F
    1 like 1 reply
    Fri, Feb 18, 2022 9:44am -08:00
  • Aaron Parecki https://aaronparecki.com/   •   Feb 17
    Update: Now I just got a copyright claim on a *year old* video for using this song!

    @travisisjoking get a grip on your copyright lawyers please!
    Aaron Parecki
    Looks like the folks I need to actually ping are @orchtweets

    I just realized the 2nd content ID claim was from a completely different comedy set, so it's their label that used this song in their outro for a couple different comedians and now YouTube is flagging older videos
    Portland, Oregon, USA • 42°F
    1 like
    Thu, Feb 17, 2022 7:04am -08:00
  • Aaron Parecki https://aaronparecki.com/   •   Feb 14
    I have every confidence @artlist_io will be able to sort this out, it's just so frustrating that the system works this way. I've been using this song for over a year, and now suddenly YouTube thinks this guy's comedy album published last week is the source of this song?
    Aaron Parecki
    Update: Now I just got a copyright claim on a *year old* video for using this song!

    @travisisjoking get a grip on your copyright lawyers please!
    Portland, Oregon, USA • 42°F
    4 likes 1 reply
    Thu, Feb 17, 2022 6:38am -08:00
  • Carter https://twitter.com/crtr0   •   Feb 16
    Hey, any freelancers or self-employed folks have an invoicing product they'd like to recommend?

    Don't need it to tie into bookkeeping, literally just need to send good looking invoices and collect payments online.

    /cc @eveporcello @marcysutton @MindsEyeCCF
    Aaron Parecki
    Stripe invoices are surprisingly effective. If you want something a little fancier then I've had good luck with Invoice Ninja, payments processed by Stripe of course
    Portland, Oregon • 46°F
    4 likes 1 reply
    Wed, Feb 16, 2022 10:43pm -08:00
  • Chris https://social.chrisburnell.com/@chris   •   Feb 16

    @aaronpk I love the transitioning checkin map on your homepage—it was a delight to discover!

    Aaron Parecki
    Thanks! I stole the idea from Flickr!
    Portland, Oregon • 43°F
    1 like
    Wed, Feb 16, 2022 9:35am -08:00
  • Luke Strickland https://twitter.com/clone1018   •   Feb 16
    Since launching http://WebSubHub.com 20 days ago, it's sent over 430,000 updates from 40k topics with a single tiny @DigitalOcean droplet. All using a couple hundred lines of @elixirlang and a single Oban job! #myelixirstatus

    Source on GitHub: https://github.com/clone1018/WebSubHub
    Aaron Parecki
    wow, this is great! Great job!
    Portland, Oregon, USA • 43°F
    1 like 1 reply
    Wed, Feb 16, 2022 9:15am -08:00
  • Emily Kager https://twitter.com/EmilyKager   •   Feb 14
    i like my men like i like my programming languages
    - takes care of dates
    - pretty to look at
    - has abs included
    - takes out the garbage for me
    Aaron Parecki
    emily
    Portland, Oregon • 42°F
    2 likes 1 reply
    Mon, Feb 14, 2022 11:07pm -08:00
older

Hi, I'm Aaron Parecki, Director of Identity Standards at Okta, and co-founder of IndieWebCamp. I maintain oauth.net, write and consult about OAuth, and participate in the OAuth Working Group at the IETF. I also help people learn about video production and livestreaming. (detailed bio)

I've been tracking my location since 2008 and I wrote 100 songs in 100 days. I've spoken at conferences around the world about owning your data, OAuth, quantified self, and explained why R is a vowel. Read more.

  • Director of Identity Standards at Okta
  • IndieWebCamp Founder
  • OAuth WG Editor
  • OpenID Board Member

  • 🎥 YouTube Tutorials and Reviews
  • 🏠 We're building a triplex!
  • ⭐️ Life Stack
  • ⚙️ Home Automation
  • All
  • Articles
  • Bookmarks
  • Notes
  • Photos
  • Replies
  • Reviews
  • Trips
  • Videos
  • Contact
© 1999-2025 by Aaron Parecki. Powered by p3k. This site supports Webmention.
Except where otherwise noted, text content on this site is licensed under a Creative Commons Attribution 3.0 License.
IndieWebCamp Microformats Webmention W3C HTML5 Creative Commons
WeChat ID
aaronpk_tv