52°F

Aaron Parecki

  • Articles
  • Notes
  • Photos
  • Isaac Rabinovitch https://mastodon.social/@isaac32767   •   Dec 2

    @aaronpk Sigh. The bit about the tracks depressed me. The Talgo trains Amtrak Cascades uses are designed to run just as fast as the Siemens trains Brightline uses. But track conditions don't allow it.

    I mean, all the amenities you describe are very nice, but having trains that fast would be life-changing for of lot of people in the PNW, even if you had to dine on stale crackers.

    Aaron Parecki
    I totally agree! The only reason I don't often take the train to Seattle is because it might be a 3 hour trip or it might be a 5 hour trip. If the passenger trains weren't at the mercy of the freight train schedule it would be a different story.
    Alaska Flight 301 MCO to PDX in Worland, Wyoming • 13°F
    1 like 1 reply
    Fri, Dec 1, 2023 9:25pm -07:00
  • Aaron Parecki https://aaronparecki.com/   •   Dec 1
    welp, managed to go a whole year without a major airline snafu until my last work trip of the year. Flight from Miami to Portland was cancelled, and all the other options from Miami were bad. So I'm taking the Brightline train to Orlando and getting on a direct flight to Portland tonight!
    Aaron Parecki
    well I made it to Orlando with plenty of time to spare! Full writeup of the high-speed train experience is coming shortly. Now I just have to cross my fingers that the next flight actually takes off.
    Orlando, Florida, USA • 77°F
    Fri, Dec 1, 2023 6:03pm -05:00
  • Brian Richards https://indieweb.social/@rzen   •   Dec 1

    @aaronpk hey, not too bad as far as travel snafus, go. Still annoying and inconvenient, but an impressive streak nevertheless!

    What's the delta between your final arrival time and the original? And did the airline cover the cost of the alternative arrangements?

    Aaron Parecki
    I will withhold judgment on that until I get home. Original flight was going to land at 2pm, now I get back at 10pm. They won't cover the train because that was my choice but I am more interested in a train and long flight than two shorter flights.
    Alaska Flight 337 FLL to PDX in Deerfield Beach, Florida • 83°F
    Fri, Dec 1, 2023 1:31pm -05:00
  • Matěj Cepl 🇪🇺 🇨🇿 https://floss.social/@mcepl   •   Nov 30

    @aaronpk I am certainly not the first one who noticed that the former champion of use-your-own-server and #Indieweb has as his three links only corporate monosilos, right?

    Aaron Parecki
    Not sure what you mean by "as his three links" since there are 4 links in my ActivityPub profile, the first of which is my blog. I'm probably going to remove Twitter soon since I haven't even posted there since June. I do run my own git server, but not for public stuff.
    Miami Beach, Florida, USA • 68°F
    1 reply
    Thu, Nov 30, 2023 7:28am -05:00
  • Aaron Parecki https://aaronparecki.com/   •   Dec 25

    Habanero Hot Sauce

    Aaron Parecki
    Made 116oz of hot sauce! First batch of hot sauce in the new place!

    The last batch was from April which was a pretty good run. We did run out a week or two ago and broke in to the backup Secret Aardvark stash but that's gone as of this morning.
    Portland, Oregon, USA • 37°F
    Mon, Nov 27, 2023 9:33pm -08:00 #habanero
  • Miraz https://micro.blog/Miraz   •   Nov 20

    @aaronpk Your unbelievably cute kitties?

    Aaron Parecki
    Yes! They settled right in to their new home as if they owned the place
    Portland, Oregon • 37°F
    Mon, Nov 20, 2023 6:54am -08:00
  • jeremycherfas https://micro.blog/jeremycherfas   •   Nov 13

    @aaronpk Super glad to hear this, although I think I will wait for the release.

    Aaron Parecki
    No worries! I'm running it on a test phone until I'm confident that it's working as expected too.
    Portland, Oregon • 51°F
    Mon, Nov 13, 2023 1:04pm -08:00
  • Shauna GM https://social.coop/@shauna   •   Oct 31

    @JMMaok @dajb I am looking for:

    - ability to create recurring events (or at the very least, easily duplicate and edit events)
    - automated confirmation and reminder emails that can be customized with ie a zoom link
    - custom sign up forms

    Ideally also:

    - has a calendar integration or provides an .ics feed, so events automatically populate our public calendar
    - has a zoom or other videochat integration so I don't need to separately set that up

    Aaron Parecki
    This is a great list of features! Meetable https://github.com/aaronpk/Meetable supports some of these:

    - quickly clone an event
    - ics feed for the site as well as tags
    - schedule a zoom meeting when creating an event

    It's missing any actual signup or email stuff though, it's meant more as a discovery tool to push viewers to the actual ticketing website. I've been hesitant to expand it to include ticketing, but might be able to be talked into it.
    Portland, Oregon, USA • 59°F
    Tue, Oct 31, 2023 2:59pm -07:00
  • John Peart https://www.johnpe.art   •   Oct 31

    Making “Web mentions” look more conversational

    Aaron Parecki
    That's very cute!
    Portland, Oregon • 43°F
    Tue, Oct 31, 2023 8:38am -07:00
  • About sending pingbacks, webmentions and some thoughts on how to improve on them.

    Aaron Parecki
    The Webmention spec doesn't make any assumptions about the content of the page, and that was intentional. Interpreting the content of the page to decide what to do with the Webmention is typically done by parsing the Microformats on the page. There's more info here: https://indieweb.org/comments
    Portland, Oregon • 43°F
    1 mention
    Tue, Oct 31, 2023 7:25am -07:00
  • Aaron Ogle https://fosstodon.org/@geekgonecrazy   •   Oct 26

    @aaronpk is pkce used very often? When I was initially implementing pkce in a few cli tools I didn’t see a lot of people talking about it. Most people I talk to are familiar with oauth but you mention pkce and they don’t know it

    Aaron Parecki
    CLI tools are a bit of a special case, but if you're using the auth code flow with a CLI client, then you should also definitely use PKCE.
    Portland, Oregon • 43°F
    Thu, Oct 26, 2023 9:21am -07:00
  • Aaron Ogle https://fosstodon.org/@geekgonecrazy   •   Oct 26

    @aaronpk is pkce used very often? When I was initially implementing pkce in a few cli tools I didn’t see a lot of people talking about it. Most people I talk to are familiar with oauth but you mention pkce and they don’t know it

    Aaron Parecki
    It's used pretty often, but apparently not as often as it should. There's no excuse for not using it these days, that's why it's not called PKCE in OAuth 2.1, it's just built in to the authorization code flow.
    Portland, Oregon • 43°F
    Thu, Oct 26, 2023 9:08am -07:00
  • Aaron Parecki https://aaronparecki.com/   •   Oct 26
    This is a good writeup on some sneaky vulnerabilities in OAuth implementations, but ultimately is just a simple access token injection attack: https://salt.security/blog/oh-auth-abusing-oauth-to-take-over-millions-of-accounts
    Aaron Parecki
    tl;dr: Don't accept access tokens in your redirect URI (don't use the implicit flow)

    PKCE solves this attack and is enforced by the server rather than relying on client developers to "verify the access token" as described in the post
    Portland, Oregon, USA • 42°F
    4 likes 2 reposts 1 reply
    Thu, Oct 26, 2023 8:51am -07:00 #oauth
  • Paul Robert Lloyd https://paulrobertlloyd.com/   •   Oct 25

    A cohesive and unified identity for IndieWeb protocols

    Aaron Parecki
    These are really great! I like what you've done here!
    Portland, Oregon, USA • 46°F
    Wed, Oct 25, 2023 12:21pm -07:00
  • ocdtrekkie https://mastodon.social/@ocdtrekkie   •   Oct 23

    @aaronpk I mean, you never know when you'll need to be wired for ceiling mics.

    Aaron Parecki
    Easy to do now, almost impossible to do later, so why not!
    Portland, Oregon • 54°F
    Sun, Oct 22, 2023 9:31pm -07:00
  • rmdes https://micro.blog/rmdes   •   Oct 8

    @aaronpk my English isn't so good, and not my primary language.. so I always thought that it meant literally for the email to arrive in the inbox well (not in spam) , and not about the state, well-being of the receiving end 😅

    Aaron Parecki
    That's fantastic, from now on I am going to interpret this as such
    Portland, Oregon • 79°F
    Sun, Oct 8, 2023 4:18pm -07:00
  • Marty McGuire https://martymcgui.re/   •   Sep 23

    This map is made for you and me

    Aaron Parecki
    thanks a lot, that song has been stuck in my head all afternoon now
    Portland, Oregon • 57°F
    1 mention
    Sat, Sep 23, 2023 7:52pm -07:00
  • Emelia 👸🏻 https://hachyderm.io/@thisismissem   •   Sep 19

    @aaronpk I've seen that, but haven't yet fully looked at it.. it always looked so... financial related?

    Aaron Parecki
    Yeah that is an artifact of its origins, but they took "Financial" out of the name and now it's just "FAPI". Think of it as just a high-security profile, one which would likely be useful for financial related industries and others with similar concerns.
    Dallas, Texas • 94°F
    1 like 1 reply
    Tue, Sep 19, 2023 4:19pm -05:00
  • Emelia 👸🏻 https://hachyderm.io/@thisismissem   •   Sep 19

    @aaronpk that's perhaps fair, though I think OIDC smooths out a lot of OAuth 2.0's rough edges

    Aaron Parecki
    If you want to see a profile that *really* smoothes out the rough edges, check out the OpenID FAPI profile. The whole goal of that is high security and interoperability. OpenID core is still pretty loose.
    Dallas, Texas • 94°F
    1 like 1 reply
    Tue, Sep 19, 2023 4:10pm -05:00
  • Evan Prodromou https://cosocial.ca/@evan   •   Sep 17

    I started a FEP to define an #OAuth 2.0 profile for the #ActivityPub API (“c2s”):

    https://codeberg.org/fediverse/fep/pulls/162

    I’d appreciate any feedback or support. I’ve begun implementing this profile, and I think it’s testing out pretty well.

    Aaron Parecki
    I see the proposal has just been merged and now links out to a socialhub link? Where is the best place to continue discussing this? I have ... a lot of feedback as you might imagine.

    https://socialhub.activitypub.rocks/t/fep-d8c2-oauth-2-0-profile-for-the-activitypub-api/3575
    Dallas, Texas, USA • 93°F
    1 like 1 reply
    Tue, Sep 19, 2023 3:42pm -05:00
older

Hi, I'm Aaron Parecki, Director of Identity Standards at Okta, and co-founder of IndieWebCamp. I maintain oauth.net, write and consult about OAuth, and participate in the OAuth Working Group at the IETF. I also help people learn about video production and livestreaming. (detailed bio)

I've been tracking my location since 2008 and I wrote 100 songs in 100 days. I've spoken at conferences around the world about owning your data, OAuth, quantified self, and explained why R is a vowel. Read more.

  • Director of Identity Standards at Okta
  • IndieWebCamp Founder
  • OAuth WG Editor
  • OpenID Board Member

  • 🎥 YouTube Tutorials and Reviews
  • 🏠 We're building a triplex!
  • ⭐️ Life Stack
  • ⚙️ Home Automation
  • All
  • Articles
  • Bookmarks
  • Notes
  • Photos
  • Replies
  • Reviews
  • Trips
  • Videos
  • Contact
© 1999-2025 by Aaron Parecki. Powered by p3k. This site supports Webmention.
Except where otherwise noted, text content on this site is licensed under a Creative Commons Attribution 3.0 License.
IndieWebCamp Microformats Webmention W3C HTML5 Creative Commons
WeChat ID
aaronpk_tv