59°F

Aaron Parecki

  • Articles
  • Notes
  • Photos
  • Shannon Morse wears a mask responsibly https://twitter.com/Snubs
    One time me and @hak5darren sent a fake Microsoft tech support scammer goatse after keeping them on the phone for an hour.
    Portland, Oregon • 30°F
    Fri, Feb 12, 2021 12:22am +00:00 (liked on Thu, Feb 11, 2021 4:22pm -08:00)
  • M. Brandon Lee | THIS IS TECH TODAY https://twitter.com/thisistechtoday   •   Feb 12
    Should I play along? I’m curious now.
    Aaron Parecki
    I would if it were me! Just stay on high alert mode of course... don't download anything, don't connect any OAuth apps to anything, and click links only using an isolated computer. I'm always curious about these things!
    Portland, Oregon, USA • 30°F
    1 like 4 replies
    Thu, Feb 11, 2021 4:19pm -08:00
  • M. Brandon Lee | THIS IS TECH TODAY https://twitter.com/thisistechtoday   •   Feb 11
    I’d love to get @Snubs and @aaronpk on the scene 👀
    Aaron Parecki
    yeah I suspect you're right. I'm curious what the next play is. Maybe they send you a download link to the special "Spotify VIP" app?
    Portland, Oregon, USA • 30°F
    1 like 2 replies
    Thu, Feb 11, 2021 4:14pm -08:00
  • K. Mike Merrill https://twitter.com/kmikeym   •   Feb 11
    What’s your current setup for backing up power? (Video idea!)
    Aaron Parecki
    Clearly I need to beef it up a bit, but right now I have a UPS on the network gear and also at my desk. It can keep things powered for about 30-40 minutes, and my internet is fiber so it stays online too
    Portland, Oregon • 31°F
    2 likes 4 replies
    Thu, Feb 11, 2021 2:53pm -08:00
  • Aaron Parecki
    The power went out literally a minute after I finished hosting a workshop. Good timing I guess. Time to invest in some more batteries?
    Portland, Oregon, USA • 32°F
    10 likes 6 replies
    Thu, Feb 11, 2021 2:11pm -08:00
  • James Tucker https://twitter.com/tucker_dev
    Imagine gatekeeping an industry where one of the primary skills is Googling things.
    Portland, Oregon • 32°F
    Thu, Feb 11, 2021 12:37pm +00:00 (liked on Thu, Feb 11, 2021 2:08pm -08:00)
  • Nick Fiacco https://twitter.com/FiaccoNick   •   Feb 11
    Is there a good way to verify the identity of a public app requesting an auth code?
    Aaron Parecki
    No not really, that's why the redirect URL is so important to get right. It's not a great situation, but it would require cooperation from the OS in order to have a more secure flow. That said, it's also a relatively unlikely attack vector so people mostly don't worry about it.
    Portland, Oregon • 33°F
    1 like
    Thu, Feb 11, 2021 12:51pm -08:00
  • Nick Fiacco https://twitter.com/FiaccoNick   •   Feb 11
    Chances are I’m missing something— @aaronpk @leahculver does this make sense to either of you?
    Aaron Parecki
    Yes, you're right, but that doesn't mean PKCE is not secure. This is just an inherent limitation of public clients that can't use a client secret. PKCE does solve several attacks, but it doesn't provide authentication of the app itself.
    Portland, Oregon • 33°F
    2 likes
    Thu, Feb 11, 2021 9:58am -08:00
  • Shannon Morse wears a mask responsibly https://twitter.com/Snubs
    Two convos with completely different context, but both mentioned “YouTube isn’t a real job”.

    Bitch I bought a house and my car is paid off, YouTube is a real job.
    Portland, Oregon • 33°F
    Thu, Feb 11, 2021 6:32am +00:00 (liked on Thu, Feb 11, 2021 6:59am -08:00)
  • TikTok Habit https://twitter.com/tiktokhabit
    I’m not a cat. https://vm.tiktok.com/ZMeRUgvkw/
    Portland, Oregon • 39°F
    Wed, Feb 10, 2021 10:43pm +00:00 (liked on Wed, Feb 10, 2021 9:46pm -08:00)
  • Jᵾlien Genestoux https://twitter.com/julien51   •   Feb 11
    Ideally though, an identity shouldn't have to be tied to a server, even if I own it?
    Aaron Parecki
    That's one opinion yes. There are good arguments on both sides.
    Portland, Oregon • 40°F
    1 like 6 replies
    Wed, Feb 10, 2021 7:22pm -08:00
  • Kevin Marks https://twitter.com/kevinmarks   •   Feb 11
    That's very true, and the Wordpress plugin makes the case as well.
    Aaron Parecki
    Yep although the WordPress plugin requires some active effort by the user. At least it’s just installing a plugin and not dealing with markup though.
    Portland, Oregon • 40°F
    8 replies
    Wed, Feb 10, 2021 6:57pm -08:00
  • Sara 🍑y https://twitter.com/saradietschy
    I think Sony makes more cameras than I make YouTube videos
    Portland, Oregon • 40°F
    Thu, Feb 11, 2021 2:39am +00:00 (liked on Wed, Feb 10, 2021 6:53pm -08:00)
  • Kevin Marks https://twitter.com/kevinmarks   •   Feb 11
    That's part of it, though the RelMeAuth model can mitigate that to some extent. A lot of it is having a use case to authorise for. Micropub is one use case that can make sense to users
    Aaron Parecki
    Nah, don’t forget that every micro.blog account is an IndieAuth account too. Users don’t need to have any knowledge of anything under the hood for that to work. We need more service providers to implement it more than anything.
    Portland, Oregon • 40°F
    4 likes 1 repost 10 replies
    Wed, Feb 10, 2021 6:53pm -08:00
  • Nick Gamb https://twitter.com/NickCGamb
    But while the industry still clings to things like AD, and product teams throughout tech still demand support for password, we have to support it while offering a path to the future.
    Portland, Oregon • 36°F
    Wed, Feb 10, 2021 5:03pm +00:00 (liked on Wed, Feb 10, 2021 9:50am -08:00)
  • Nick Gamb https://twitter.com/NickCGamb
    Yes, we all are fully aware that the password is the problem. Thats why the best identity platforms will support many different factors and will strive to be fully passwordless and platform agnostic (supporting new factors as they are created via standards)
    Portland, Oregon • 36°F
    Wed, Feb 10, 2021 5:03pm +00:00 (liked on Wed, Feb 10, 2021 9:50am -08:00)
  • Nick Gamb https://twitter.com/NickCGamb
    I'm still struggling to understand how a person with such a reasonably impressive background can think that they are offering profound insight when they are just rambling on about the obvious and getting hung up on the wrong part of the tech.
    Portland, Oregon • 36°F
    Wed, Feb 10, 2021 5:03pm +00:00 (liked on Wed, Feb 10, 2021 9:50am -08:00)
  • patrick. https://twitter.com/imPatrickT
    YouTube should prompt users with a “You haven’t finished watching this video yet are you sure you want to comment?” message so they don’t waste their time asking questions you already answered - or cherry pick something you follow up & expand on. Would also support watch time.
    Portland, Oregon • 33°F
    Wed, Feb 10, 2021 2:23pm +00:00 (liked on Wed, Feb 10, 2021 6:55am -08:00)
  • Simon Willison https://twitter.com/simonw
    Last year I finally gave myself permission to ignore the entire modern JavaScript ecosystem and go back to writing front-end code by typing library-free JavaScript into a <script> block... and it works great!

    Don't even need jQuery any more, native JS absorbed its best features
    Portland, Oregon • 33°F
    Wed, Feb 10, 2021 12:56pm +00:00 (liked on Wed, Feb 10, 2021 6:20am -08:00)
  • What's New in YoloBox Version 3.4: Livestream chat, side by side view, PDFs, and more! (Feb 2021)

    The latest update to the YoloBox adds some incredible new features! This makes it super competitive with some of the far more expensive and bulkier switchers! In this video I give you the rundown of the latest features in the YoloBox version 3.4 update!
    continue reading...
    Wed, Feb 10, 2021 5:30am -08:00
older

Hi, I'm Aaron Parecki, Director of Identity Standards at Okta, and co-founder of IndieWebCamp. I maintain oauth.net, write and consult about OAuth, and participate in the OAuth Working Group at the IETF. I also help people learn about video production and livestreaming. (detailed bio)

I've been tracking my location since 2008 and I wrote 100 songs in 100 days. I've spoken at conferences around the world about owning your data, OAuth, quantified self, and explained why R is a vowel. Read more.

  • Director of Identity Standards at Okta
  • IndieWebCamp Founder
  • OAuth WG Editor
  • OpenID Board Member

  • 🎥 YouTube Tutorials and Reviews
  • 🏠 We're building a triplex!
  • ⭐️ Life Stack
  • ⚙️ Home Automation
  • All
  • Articles
  • Bookmarks
  • Notes
  • Photos
  • Replies
  • Reviews
  • Trips
  • Videos
  • Contact
© 1999-2025 by Aaron Parecki. Powered by p3k. This site supports Webmention.
Except where otherwise noted, text content on this site is licensed under a Creative Commons Attribution 3.0 License.
IndieWebCamp Microformats Webmention W3C HTML5 Creative Commons
WeChat ID
aaronpk_tv