58°F

Aaron Parecki

  • Articles
  • Notes
  • Photos
  • meddlin https://twitter.com/meddlin_dev   •   Jul 29
    How do we continue to push online services, subscription models, and near constant online connections to normal users without showing them they can trust anything to last 10 years?
    Aaron Parecki
    Um, you don't. It's a bad model. https://indieweb.org/site-deaths
    Alaska Flight 23 PHL to SEA in Bruno, Minnesota • 73°F
    7 replies
    Fri, Jul 29, 2022 7:58pm -05:00
  • Jared Hanson https://twitter.com/jaredhanson   •   Jul 29
    Yes, it was a random thought and Iโ€™m sure there are consequences. What if the browser itself required FaceID to unlock the cookie jar. That would mitigate many issues, and if you squint at it is not all that different than a credential store.
    Aaron Parecki
    The problem is FaceID is only tied to the device so it doesn't change the situation ๐Ÿ˜” I'm also not convinced syncing WebAuthn keys was a good idea either tho
    Philadelphia, Pennsylvania • 82°F
    1 reply
    Fri, Jul 29, 2022 6:19pm -04:00
  • TeamYouTube https://twitter.com/TeamYouTube   •   Jul 29
    sorry about this! as we donโ€™t tolerate creators who violate our policies on impersonation: https://goo.gle/3clE816, itโ€™s best to flag the acct for review โžก๏ธ https://goo.gle/3JhoUqj
    Aaron Parecki
    calling this account a "creator" is ... a bit of a stretch ๐Ÿ™„
    Philadelphia, Pennsylvania • 82°F
    1 like 1 reply
    Fri, Jul 29, 2022 5:43pm -04:00
  • Sam 0xEACD https://twitter.com/samuelgoto   •   Jul 29
    I'm pretty convinced there is something to be done here. Not cookies per se, has to be opt in (breaks backwards compatibility otherwise), but i agree there is something here.

    Interested in exploring this further with browser engineers?
    Aaron Parecki
    If you think this won't immediately be abused in ways you didn't intend, go read up on Britney's case where they had a copy of all her comms from a shadow iOS device signed in to her iCloud
    Philadelphia, Pennsylvania • 83°F
    1 like 3 replies
    Fri, Jul 29, 2022 5:40pm -04:00
  • Nicu Barbaros https://twitter.com/nicubarbaros   •   Jul 29
    gimme link to the course please
    Aaron Parecki
    Thank you for the glowing review! ๐Ÿ˜Š https://oauth2simplified.com/course
    Philadelphia, Pennsylvania, USA • 81°F
    2 likes 1 reply
    Fri, Jul 29, 2022 12:22pm -04:00
  • est https://twitter.com/emilyst   •   Jul 29
    It's the Vaonis Stellina (https://vaonis.com/stellina), which has a 80 mm aperture. photos taken from within Portland city limits.
    Aaron Parecki
    wow, I had no idea this was visible from within the city limits at all!
    Philadelphia, Pennsylvania • 73°F
    1 reply
    Fri, Jul 29, 2022 8:07am -04:00
  • Matt Haughey https://twitter.com/mathowie   •   Jul 28
    Itโ€™s kind of amazing how bad the downloads feature is on Plex. Every year or so I try it before a flight, and each time it fails to do what I thought. No overall progress meter or bar, if your iPad goes to sleep, downloads stop, if you switch to another app, downloads stop.
    Aaron Parecki
    The worst part is the old sync feature worked so well with a progress bar and everything! I don't understand why they think this one is better
    Philadelphia, Pennsylvania • 71°F
    1 like
    Fri, Jul 29, 2022 7:32am -04:00
  • tim cappalli | ๐Ÿ“Philly https://twitter.com/timcappalli   •   Jul 28
    revocation is really important.
    Aaron Parecki
    No it's not! You take that back!
    Philadelphia, Pennsylvania • 71°F
    4 likes
    Fri, Jul 29, 2022 7:12am -04:00
  • Gerald Undone https://twitter.com/GeraldUndone   •   Jul 25
    What if I just stopped reviewing cameras and started reviewing the mundane? ๐Ÿค”
    I'm envisioning absurdist reviews of bananas, my cat, or a piece of wood. I think that would entertain me. I'm not sure about anyone else though. ๐Ÿ˜œ
    Aaron Parecki
    Entertaining you is the most important, I say do it!
    Philadelphia, Pennsylvania, USA • 77°F
    1 like
    Tue, Jul 26, 2022 1:25pm -04:00
  • Virginia Roberts ๐Ÿณ๏ธ‍๐ŸŒˆ๐Ÿ˜ท๐Ÿซโ˜๏ธ๐Ÿ“–๐Ÿšฎ๐Ÿ”ฅโค๏ธ๐Ÿ’›๐ŸนโŒจ๏ธโœจ https://twitter.com/askvirginia   •   Jul 24
    How does one get on a tech consortium? (Bluetooth, Unicode, USB, etc) Serious question, as I imagine the real answer is sometimes different than the Google result, ya know?
    Aaron Parecki
    The IETF is one of the few standards orgs that's very open! Just join a group's mailing list and/or show up to an event!
    Philadelphia, Pennsylvania • 90°F
    2 likes
    Sun, Jul 24, 2022 8:04pm -04:00
  • Vittorio https://twitter.com/vibronet   •   Jul 24
    Other than shock collars for laggards, I see no viable strategy ๐Ÿ˜‚
    More seriously: I think there plan is simply to have ALL discussions and QA out of band, this will be only us updating the WG.
    Aaron Parecki
    Good thing we have nearly five hours of side meetings scheduled ๐Ÿ˜…
    Philadelphia, Pennsylvania • 96°F
    4 likes 1 reply
    Sun, Jul 24, 2022 4:49pm -04:00
  • Vittorio https://twitter.com/vibronet   •   Jul 24
    The #IETF114 #oauth WG meeting is going to be a tour de force.
    I think Iโ€™ll have to rap thru the deck to make it in 10 - perhaps I can convince @__b_c to beatbox ๐Ÿ˜›
    Aaron Parecki
    Bets on how well we'll stick to the timing? This is gonna be one of the more challenging ones for the chairs!
    Philadelphia, Pennsylvania • 97°F
    4 replies
    Sun, Jul 24, 2022 4:36pm -04:00
  • MadeinSpareTime https://micro.blog/MadeinSpareTime   •   Jul 24

    @aaronpk Awesome shot! Which drone are you using, if you don't mind me asking?

    Aaron Parecki
    Thanks! It's the DJI Mini 2!
    Philadelphia, Pennsylvania • 94°F
    Sun, Jul 24, 2022 12:14pm -04:00
  • Ed Summers https://social.coop/@edsu   •   Jul 24

    @aaronpk what model drone are you using for that -- that photo is amazing

    Aaron Parecki
    Thanks! It's the DJI Mini 2! Reasonably cheap and very easy to use! I'm still too scared about crashing to fly a $2000 drone
    Philadelphia, Pennsylvania • 94°F
    1 like
    Sun, Jul 24, 2022 12:14pm -04:00
  • Danny Zollner https://twitter.com/zoll_nerd   •   Jul 23
    Heading out to Philadelphia for my first in-person #ietf session - #ietf114! Will be working on advancing the #SCIM 2.0 provisioning standard. Even if you can't attend in person, you can sign up and attend virtually! Come contribute to the future of the standard!
    Aaron Parecki
    See you there! ๐Ÿ‘‹
    Alaska Flight 32 SEA to PHL in Hodgenville, Kentucky • 93°F
    1 like
    Sat, Jul 23, 2022 3:54pm -04:00
  • Christos Karras https://twitter.com/ckarras   •   Jul 22
    - Having a SSO authentication form as a web page instead of a special OS window facilitates various phishing attempts
    Aaron Parecki
    hardware authenticators like Yubikey/FaceID/TouchID solve the phishing problem with OIDC at least, but I'm expecting we're going to see some interesting OS-facilitated login flows in the near future
    Portland, Oregon, USA • 63°F
    Fri, Jul 22, 2022 10:16am -07:00
  • Yann Crumeyrolle https://twitter.com/ycrumeyrolle   •   Jul 22
    Same protocol, same risk (sic). And moreover OAuth2 is not secure because it require TLS.

    Happy to have fought all this false assertions , but we still have SAML when connecting to old SaaS.
    Aaron Parecki
    that's...wrong and also just a weird thing to say. There's also FAPI which is a secure profile of OAuth and OpenID Connect.
    Portland, Oregon, USA • 63°F
    1 like 1 reply
    Fri, Jul 22, 2022 10:06am -07:00
  • Tobias Zuegel ๐Ÿ‡บ๐Ÿ‡ฆ | #AzureAD https://twitter.com/MrAzureAD   •   Jul 22
    Not talking about the protocol itself. Just how easy it is for a SaaS vendor to provide configuration information that can be followed by the IT department of the customer.
    Aaron Parecki
    I'm really curious about this, can you link me to some docs that you've seen that demonstrate this difference?
    Portland, Oregon, USA • 60°F
    1 like 1 reply
    Fri, Jul 22, 2022 7:41am -07:00
  • tim cappalli https://twitter.com/timcappalli   •   Jul 21
    Hey @onemedical, I do not consent to sharing my health records with Amazon. What guarantees do I have when I leave One Medical that this won't occur?
    Aaron Parecki
    you probably actually did when you agreed to the terms of service
    Portland, Oregon, USA • 73°F
    1 reply
    Thu, Jul 21, 2022 10:48am -07:00
  • BikePortland https://twitter.com/BikePortland   •   Jul 19
    Reader just sent us this pic.

    Someone is super mad that @PBOTinfo put concrete barricades and traffic signs on NE Sacramento because it... wait for it... ruins the view.

    #pdxtraffic
    Aaron Parecki
    Sounds like someone needs to get out and ride a bike more! โœจ๐Ÿšฒ
    American Flight 6306 IAH to PHX in Phoenix, Arizona • 107°F
    1 like
    Tue, Jul 19, 2022 6:56pm -07:00
older

Hi, I'm Aaron Parecki, Director of Identity Standards at Okta, and co-founder of IndieWebCamp. I maintain oauth.net, write and consult about OAuth, and participate in the OAuth Working Group at the IETF. I also help people learn about video production and livestreaming. (detailed bio)

I've been tracking my location since 2008 and I wrote 100 songs in 100 days. I've spoken at conferences around the world about owning your data, OAuth, quantified self, and explained why R is a vowel. Read more.

  • Director of Identity Standards at Okta
  • IndieWebCamp Founder
  • OAuth WG Editor
  • OpenID Board Member

  • ๐ŸŽฅ YouTube Tutorials and Reviews
  • ๐Ÿ  We're building a triplex!
  • โญ๏ธ Life Stack
  • โš™๏ธ Home Automation
  • All
  • Articles
  • Bookmarks
  • Notes
  • Photos
  • Replies
  • Reviews
  • Trips
  • Videos
  • Contact
© 1999-2025 by Aaron Parecki. Powered by p3k. This site supports Webmention.
Except where otherwise noted, text content on this site is licensed under a Creative Commons Attribution 3.0 License.
IndieWebCamp Microformats Webmention W3C HTML5 Creative Commons
WeChat ID
aaronpk_tv