74°F

Aaron Parecki

  • Articles
  • Notes
  • Photos
  • K. Mike Merrill https://twitter.com/kmikeym   •   Jan 22
    Like Netflix I also use my own private internal measurement that I only occasionally release for stats and yesterday I had 87,000,000,000 views on my website. https://buff.ly/30HVBXk
    Aaron Parecki
    the guy that runs your website must be really good
    Portland, Oregon • 45°F
    1 like
    Wed, Jan 22, 2020 7:10am -08:00
  • πŸ“· PhotoJoseph πŸŽ₯ https://twitter.com/photojoseph
    life goals… I showed my wife pieces of my latest video and she was actually impressed. 😯 https://youtu.be/UuCPuqcAH94
    Portland, Oregon • 46°F
    Wed, Jan 22, 2020 3:37am +00:00 (liked on Tue, Jan 21, 2020 10:11pm -08:00)
  • Lillian Karabaic https://twitter.com/anomalily
    I literally did this for my 30th birthday, only it was a $1000 budget because I'm cheap and was a multi-city spy-themed scavenger hunt on public transit. There was a rooftop message only readable from the aerial tram, and a secret karaoke bus. We had tacos.
    Portland, Oregon • 47°F
    Wed, Jan 22, 2020 4:29am +00:00 (liked on Tue, Jan 21, 2020 10:04pm -08:00)
  • Aaron Parecki
    at Lucky Labrador Tap Room
    Portland, Oregon • Tue, January 21, 2020 6:42pm
    45.56261 -122.685189
    #HomeAutomation meetup
    Portland, OR, United States • 46°F
    24 Coins
    Tue, Jan 21, 2020 6:42pm -08:00 #homeautomation
  • Dave Maze https://twitter.com/davemaze   •   Jan 21
    nice! i’m sure you learn stuff from work that you can utilize for your personal.
    Aaron Parecki
    so far it's been mostly the other way around, but mainly because I did a big push on my personal channel while on PTO in December πŸ˜„ which paid off cause I went from 200 to 1500 subscribers in like 7 weeks πŸŽ‰
    Portland, Oregon • 47°F
    Tue, Jan 21, 2020 4:02pm -08:00
  • Anders Pitman https://twitter.com/anderspitman   •   Jan 21
    What do you think would be fragile about my approach? Giving the client control over the random value?
    Aaron Parecki
    by "fragile" I mean things like vulnerable to popup blockers, popups are bad UX on mobile browsers, etc.
    Portland, Oregon • 47°F
    Tue, Jan 21, 2020 3:59pm -08:00
  • Anders Pitman https://twitter.com/anderspitman   •   Jan 21
    That's interesting. After a quick review, it does seem pretty similar. Why the timeout polling instead of long polling? Does the spec dictate what back-channel you send the user to?
    Aaron Parecki
    The spec has a way the AS can provide a URL that the user should visit to the app. So the app has to get the user to that URL somehow, doesn't matter how, and doesn't matter what that URL is.
    Portland, Oregon • 47°F
    1 reply
    Tue, Jan 21, 2020 3:58pm -08:00
  • Anders Pitman https://twitter.com/anderspitman   •   Jan 21
    Why not open a new tab for interacting with the auth server, while simultaneously opening a back channel request in the original session? Once the user has authenticated/authorized from the new tab, the back channel request would resolve. 2/
    Aaron Parecki
    There's also a new draft, Pushed Authorization Requests, which moves a bunch of the fragile bits out of the front channel. Similar but slightly different goal. https://tools.ietf.org/id/draft-lodderstedt-oauth-par-00.html
    Portland, Oregon, USA
    Tue, Jan 21, 2020 11:05am -08:00
  • Anders Pitman https://twitter.com/anderspitman   •   Jan 21
    Why not open a new tab for interacting with the auth server, while simultaneously opening a back channel request in the original session? Once the user has authenticated/authorized from the new tab, the back channel request would resolve. 2/
    Aaron Parecki
    That's basically what the Device Flow is, except manual. You certainly could do that. I suspect it would be fragile at best though, and wouldn't work well in mobile browsers.
    Portland, Oregon, USA
    4 replies
    Tue, Jan 21, 2020 11:04am -08:00
  • Dave Maze https://twitter.com/davemaze   •   Jan 21
    what kind of videos do you make? respond below
    Aaron Parecki
    Software/security education (work channel)
    Camera gear tutorials and reviews (personal channel)
    Portland, Oregon • 45°F
    4 likes 1 reply
    Tue, Jan 21, 2020 8:37am -08:00
  • Amanda J. Rush https://twitter.com/cswordpress
    Google finally realizes it created a trashfire. They should just support Microformats 2, much easier to construct and therefore use. https://twitter.com/googlewmc/status/1219565763759165441
    Portland, Oregon • 45°F
    Tue, Jan 21, 2020 4:35pm +00:00 (liked on Tue, Jan 21, 2020 8:36am -08:00)
  • Aaron Parecki
    Why do we even have OAuth at all? Take five minutes and find out! New video! πŸŽ₯πŸ‘‰ https://youtu.be/KT8ybowdyr0
    Portland, Oregon, USA • 44°F
    8 likes 3 reposts 2 replies 2 mentions
    Tue, Jan 21, 2020 7:52am -08:00 #oauth #okta
  • Chillian J. Yikes! https://twitter.com/jilliancyork
    Ha happened to me too, but Polish.
    Portland, Oregon • 43°F
    Tue, Jan 21, 2020 2:44pm +00:00 (liked on Tue, Jan 21, 2020 6:44am -08:00)
  • Chillian J. Yikes! https://twitter.com/jilliancyork   •   Jan 8
    A Thing That Annoys Me: When a website *has* English translation/text, but because I'm in Germany, I'm only offered the German version, with no chance to switch language. Fix this, engineers!
    Aaron Parecki
    I rode a Lime scooter in Prague once and for the next month all the emails I got from Lime were in Czech
    Portland, Oregon • 43°F
    1 like 1 reply
    Tue, Jan 21, 2020 6:43am -08:00
  • https://jgregorymcverry.com https://twitter.com/jgmac1106   •   Jan 21
    #IndieWeb more a philosophy for the web rather than a businesses. Though many companies (including mine) embrace these values.

    phrase you want is "small business"

    Also like @bryce idea of "real business"

    Let revenue define roadway. (https://quickthoughts.jgregorymcverry.com/s/1sO8h8)
    Aaron Parecki
    I've heard "zebras" to counter the idea of "unicorns" https://zebrasunite.mn.co/
    Portland, Oregon • 43°F
    1 repost
    Tue, Jan 21, 2020 6:06am -08:00
  • Boris Mann https://twitter.com/bmann   •   Jan 20
    no apology necessary, we’re all in this together!

    I’m digging into this stuff so that others don’t have to.

    Ideally we can add an endpoint to something like IndieKit which is easily self hostable. Everything is a little piecemeal right now.
    Aaron Parecki
    For sure, I'd love to see that.

    I'm actually gonna be in Vancouver a couple times in the near future, it'd be great to meet up and chat more about this in person!

    https://aaronparecki.com/trips
    Portland, Oregon • 45°F
    Mon, Jan 20, 2020 9:50am -08:00
  • Boris Mann https://twitter.com/bmann   •   Jan 20
    more thinking about what to include in the template. I can update to IndieLogin, so at least people can link Twitter and Github to different sites.

    Single-file selfauth looks interesting https://indieweb.org/selfauth -- hmm, but not a token endpoint
    Aaron Parecki
    I apologize for the horrible confusion due to how I named these, but indielogin.com is not a replacement for indieauth.com from a user's point of view, only from the PoV of a website trying to authenticate users.
    Portland, Oregon • 45°F
    1 reply
    Mon, Jan 20, 2020 9:45am -08:00
  • Boris Mann https://twitter.com/bmann   •   Jan 20
    @aaronpk is Github the only "external" IndieAuth supported provider right now? Other than email / pgp?

    I temporarily edit my Github profile link for different sites right now, which is not ideal.
    Aaron Parecki
    If you don't need Micropub support then your best bet is to remove the authorization_endpoint link so that the wiki will let you use any of its own supported options including Twitter.

    If you do need Micropub support, then you're stuck with the current situation.
    Portland, Oregon • 44°F
    2 replies
    Mon, Jan 20, 2020 9:25am -08:00
  • Boris Mann https://twitter.com/bmann   •   Jan 20
    @aaronpk is Github the only "external" IndieAuth supported provider right now? Other than email / pgp?

    I temporarily edit my Github profile link for different sites right now, which is not ideal.
    Aaron Parecki
    The wiki actually uses https://indielogin.com when you log in, which supports GitHub as well as Twitter and some other options.

    If your site says to use indieauth.com then yes, GitHub is the only external authentication provider supported by indieauth.com.
    Portland, Oregon • 44°F
    Mon, Jan 20, 2020 9:23am -08:00
  • Boris Mann https://twitter.com/bmann   •   Jan 20
    Yeah, theoretically @patdryburgh & I ran some "official" events a couple of times, but going to keep it casual for now.

    More about writing & info management than tools although I will demo my Jekyll + IndieKit template https://github.com/bmann/so-simple-indieweb
    Aaron Parecki
    Doesn't need to be an "official" event to post there at all! As long as it's vaguely IndieWeb adjacent, that's a great place to post it so more people can find it!
    Portland, Oregon • 43°F
    2 likes 1 reply
    Mon, Jan 20, 2020 9:09am -08:00
older

Hi, I'm Aaron Parecki, Director of Identity Standards at Okta, and co-founder of IndieWebCamp. I maintain oauth.net, write and consult about OAuth, and participate in the OAuth Working Group at the IETF. I also help people learn about video production and livestreaming. (detailed bio)

I've been tracking my location since 2008 and I wrote 100 songs in 100 days. I've spoken at conferences around the world about owning your data, OAuth, quantified self, and explained why R is a vowel. Read more.

  • Director of Identity Standards at Okta
  • IndieWebCamp Founder
  • OAuth WG Editor
  • OpenID Board Member

  • πŸŽ₯ YouTube Tutorials and Reviews
  • 🏠 We're building a triplex!
  • ⭐️ Life Stack
  • βš™οΈ Home Automation
  • All
  • Articles
  • Bookmarks
  • Notes
  • Photos
  • Replies
  • Reviews
  • Trips
  • Videos
  • Contact
© 1999-2026 by Aaron Parecki. Powered by p3k. This site supports Webmention.
Except where otherwise noted, text content on this site is licensed under a Creative Commons Attribution 3.0 License.
IndieWebCamp Microformats Webmention W3C HTML5 Creative Commons
WeChat ID
aaronpk_tv