83°F

Aaron Parecki

  • Articles
  • Notes
  • Photos
  • Aaron Parecki https://aaronparecki.com/   •   Oct 26
    This is a good writeup on some sneaky vulnerabilities in OAuth implementations, but ultimately is just a simple access token injection attack: https://salt.security/blog/oh-auth-abusing-oauth-to-take-over-millions-of-accounts
    Aaron Parecki
    tl;dr: Don't accept access tokens in your redirect URI (don't use the implicit flow)

    PKCE solves this attack and is enforced by the server rather than relying on client developers to "verify the access token" as described in the post
    Portland, Oregon, USA • 42°F
    4 likes 2 reposts 1 reply
    Thu, Oct 26, 2023 8:51am -07:00 #oauth
  • Paul Robert Lloyd https://paulrobertlloyd.com/   •   Oct 25

    A cohesive and unified identity for IndieWeb protocols

    Aaron Parecki
    These are really great! I like what you've done here!
    Portland, Oregon, USA • 46°F
    Wed, Oct 25, 2023 12:21pm -07:00
  • ocdtrekkie https://mastodon.social/@ocdtrekkie   •   Oct 23

    @aaronpk I mean, you never know when you'll need to be wired for ceiling mics.

    Aaron Parecki
    Easy to do now, almost impossible to do later, so why not!
    Portland, Oregon • 54°F
    Sun, Oct 22, 2023 9:31pm -07:00
  • rmdes https://micro.blog/rmdes   •   Oct 8

    @aaronpk my English isn't so good, and not my primary language.. so I always thought that it meant literally for the email to arrive in the inbox well (not in spam) , and not about the state, well-being of the receiving end ๐Ÿ˜…

    Aaron Parecki
    That's fantastic, from now on I am going to interpret this as such
    Portland, Oregon • 79°F
    Sun, Oct 8, 2023 4:18pm -07:00
  • Marty McGuire https://martymcgui.re/   •   Sep 23

    This map is made for you and me

    Aaron Parecki
    thanks a lot, that song has been stuck in my head all afternoon now
    Portland, Oregon • 57°F
    1 mention
    Sat, Sep 23, 2023 7:52pm -07:00
  • Emelia ๐Ÿ‘ธ๐Ÿป https://hachyderm.io/@thisismissem   •   Sep 19

    @aaronpk I've seen that, but haven't yet fully looked at it.. it always looked so... financial related?

    Aaron Parecki
    Yeah that is an artifact of its origins, but they took "Financial" out of the name and now it's just "FAPI". Think of it as just a high-security profile, one which would likely be useful for financial related industries and others with similar concerns.
    Dallas, Texas • 94°F
    1 like 1 reply
    Tue, Sep 19, 2023 4:19pm -05:00
  • Emelia ๐Ÿ‘ธ๐Ÿป https://hachyderm.io/@thisismissem   •   Sep 19

    @aaronpk that's perhaps fair, though I think OIDC smooths out a lot of OAuth 2.0's rough edges

    Aaron Parecki
    If you want to see a profile that *really* smoothes out the rough edges, check out the OpenID FAPI profile. The whole goal of that is high security and interoperability. OpenID core is still pretty loose.
    Dallas, Texas • 94°F
    1 like 1 reply
    Tue, Sep 19, 2023 4:10pm -05:00
  • Evan Prodromou https://cosocial.ca/@evan   •   Sep 17

    I started a FEP to define an #OAuth 2.0 profile for the #ActivityPub API (โ€œc2sโ€):

    https://codeberg.org/fediverse/fep/pulls/162

    Iโ€™d appreciate any feedback or support. Iโ€™ve begun implementing this profile, and I think itโ€™s testing out pretty well.

    Aaron Parecki
    I see the proposal has just been merged and now links out to a socialhub link? Where is the best place to continue discussing this? I have ... a lot of feedback as you might imagine.

    https://socialhub.activitypub.rocks/t/fep-d8c2-oauth-2-0-profile-for-the-activitypub-api/3575
    Dallas, Texas, USA • 93°F
    1 like 1 reply
    Tue, Sep 19, 2023 3:42pm -05:00
  • Emelia ๐Ÿ‘ธ๐Ÿป https://hachyderm.io/@thisismissem   •   Sep 17

    @evan no, I mean, I don't see why it'd make sense to define a custom profile of OAuth 2.0 when OIDC exists and we could just use it?

    What does defining a custom profile really give us? Our authentication needs can't be that unique, can they?

    Aaron Parecki
    there is no "just use" OIDC, it would still require defining a profile. Plus I don't think most ActivityPub implementations benefit from most of the features OIDC brings.
    Dallas, Texas, USA • 93°F
    1 reply
    Tue, Sep 19, 2023 3:40pm -05:00
  • Emelia ๐Ÿ‘ธ๐Ÿป https://hachyderm.io/@thisismissem   •   Sep 17

    @evan so currently all the different fediverse services that implement OAuth implement different bits of specs & don't support discovery of authorization server metadata; additionally, they rarely support PKCE. Dynamic Client Registration is supported, but OIDC Federation would likely be better.

    The scopes you define look like they could conflict with existing implementations, and are also not discoverable by the client.

    Aaron Parecki
    so, a few things. Despite "federation" in the name, OIDC Federation is really not the right thing for this. It's more for a closed ecosystem of independent servers, but is explicitly not made to be open for anyone to join a federation. That's why there are trust anchors and things.

    If current implementations don't support PKCE, they really should, because it's only a matter of time before someone takes advantage of the hole that not doing PKCE leaves open for public clients.
    Dallas, Texas, USA • 93°F
    1 like
    Tue, Sep 19, 2023 3:39pm -05:00
  • Michael Slade https://mastodon.cloud/@michaelslade   •   Sep 13

    @aaronpk So you donโ€™t need Spacial Video? How else will you justify a Vision Pro purchase?

    Aaron Parecki
    Oh gosh. I think I'm going to sit out this first generation of the goggles. I definitely don't *need* them, and I like to let things shake out a bit before jumping in
    Portland, Oregon • 67°F
    1 like 1 reply
    Tue, Sep 12, 2023 8:34pm -07:00
  • Mike https://mastodon.social/@mharleydev   •   Sep 9

    @aaronpk sounds expensive ๐Ÿ˜ฌ

    Do the new ones do any sort of energy reporting? What home automation platform have you landed on!

    Aaron Parecki
    yes, quite expensive. I don't think they have energy monitoring on them, but I'm installing a monitoring system at the circuit breaker panel so I will get usage on each circuit individually!

    I've been all in on Home Assistant for the last 5 years or so!
    Portland, Oregon • 85°F
    1 like 1 reply
    Sat, Sep 9, 2023 6:04pm -07:00
  • Mike https://mastodon.social/@mharleydev   •   Sep 9

    @aaronpk do you have a plan for light/wall switches yet? If I were building a house I think something like a Shelly relay would be my default go to to connect my lights. Could be a few switches where Iโ€™d use a special switch but I really like our Shellyโ€™s. Cost effective too, especially multigang switches.

    Aaron Parecki
    That's cool, I hadn't heard of that before, I'll have to try it out.

    Pretty sure I'm going with Lutron switches everywhere tho!
    Portland, Oregon • 55°F
    1 reply
    Sat, Sep 9, 2023 8:38am -07:00
  • Nils https://coolworld.cc/@n   •   Sep 8

    @aaronpk I can only think of a pneumatic tube system, although it's unlikely to be a last minute addition.

    Aaron Parecki
    we did briefly talk about doing that ๐Ÿ˜…

    more realistically we did talk about an in-house vacuum system but decided against it in the end
    Portland, Oregon • 72°F
    Fri, Sep 8, 2023 1:20pm -07:00
  • Brett Kosinski https://indieweb.social/@brettk   •   Sep 8

    @aaronpk Time capsule!

    Aaron Parecki
    haha yes! good plan
    Portland, Oregon • 72°F
    Fri, Sep 8, 2023 1:20pm -07:00
  • Dr. Fett https://social.cologne/@df   •   Sep 8

    @aaronpk A separate low-voltage DC net to power all those ESPs?

    Aaron Parecki
    That was kind of the idea behind running the doubled up ethernet everywhere, I can always send 5V or PoE over that if I need to.
    Portland, Oregon • 72°F
    2 likes 1 reply
    Fri, Sep 8, 2023 1:19pm -07:00
  • https://tech.lgbt/@nelson/111031001055817245
    Aaron Parecki
    absolutely on the list! It's going to be a full day project, I want to make sure I have some organization system for all the photos.
    Portland, Oregon • 68°F
    Fri, Sep 8, 2023 11:44am -07:00
  • Paul https://infosec.exchange/@planzi   •   Sep 8

    @aaronpk pretty much the wires for the contact sensors (doors, windows), the fire alarm wiring and the wires from the alarm box to the horn and the touchscreen panels themselves

    Aaron Parecki
    this is making me realize I have absolutely no idea what these kinds of modern security systems look like
    Portland, Oregon • 68°F
    Fri, Sep 8, 2023 11:35am -07:00
  • https://tech.lgbt/@dissolve/111030935162456963
    Aaron Parecki
    bahaha yes good plan
    Portland, Oregon • 65°F
    Fri, Sep 8, 2023 11:27am -07:00
  • Ashley Kolodziej ๐Ÿฐ https://fosstodon.org/@ashleykolodziej   •   Sep 8

    @aaronpk Some sort of metallic object at a consistent height that youโ€™ll remember for locating studs. It could be something as simple as a nail at doorknob height on all of them. Extra points if you can figure out some sort of way to note where your wires and pipes are, like maybe a magnet flipped so that it repels when you use a stud finding magnet. If I could make any upgrade to the walls of my house, that would be it by a mile.

    Aaron Parecki
    Interesting, I've always used a stud finder for finding the wood which works pretty well. I'm definitely worried about finding the pipes later, but I'm going to spend a full day photographing and cataloguing each wall before they get closed up.
    Portland, Oregon • 65°F
    1 like
    Fri, Sep 8, 2023 11:23am -07:00
older

Hi, I'm Aaron Parecki, Director of Identity Standards at Okta, and co-founder of IndieWebCamp. I maintain oauth.net, write and consult about OAuth, and participate in the OAuth Working Group at the IETF. I also help people learn about video production and livestreaming. (detailed bio)

I've been tracking my location since 2008 and I wrote 100 songs in 100 days. I've spoken at conferences around the world about owning your data, OAuth, quantified self, and explained why R is a vowel. Read more.

  • Director of Identity Standards at Okta
  • IndieWebCamp Founder
  • OAuth WG Editor
  • OpenID Board Member

  • ๐ŸŽฅ YouTube Tutorials and Reviews
  • ๐Ÿ  We're building a triplex!
  • โญ๏ธ Life Stack
  • โš™๏ธ Home Automation
  • All
  • Articles
  • Bookmarks
  • Notes
  • Photos
  • Replies
  • Reviews
  • Trips
  • Videos
  • Contact
© 1999-2025 by Aaron Parecki. Powered by p3k. This site supports Webmention.
Except where otherwise noted, text content on this site is licensed under a Creative Commons Attribution 3.0 License.
IndieWebCamp Microformats Webmention W3C HTML5 Creative Commons
WeChat ID
aaronpk_tv