69°F

Aaron Parecki

  • Articles
  • Notes
  • Photos
  • alexlindsay https://twitter.com/alexlindsay
    I have spoken at nearly every major conference in our industry…

    My presentation from my house in Office Hours is 10x more effective. I have a media cockpit, the tools to manage the conversation, and an incredible online community to join me.

    I’m never speaking in person again.
    Portland, Oregon • 44°F
    Sat, Feb 26, 2022 10:42pm +00:00 (liked on Sat, Feb 26, 2022 4:41pm -08:00)
  • Cabel https://twitter.com/cabel
    ps: I’ve been kinda harsh on 1P lately so I should note I still use it every day! it’s good! i just see the future of the path they are on and it worries me is all
    Portland, Oregon • 46°F
    Fri, Feb 25, 2022 3:47pm +00:00 (liked on Sat, Feb 26, 2022 1:27pm -08:00)
  • Luria Petrucci https://twitter.com/LuriaPetrucci   •   Feb 26
    Hosting any live streams this weekend? Drop your link in the comments 🤗
    Aaron Parecki
    Live every Sunday! This time talking about copyright claims on YouTube! https://youtu.be/FzX0lmV8rRA
    Portland, Oregon • 35°F
    1 like
    Sat, Feb 26, 2022 8:17am -08:00
  • Jake Sloan https://twitter.com/jakesloaninak   •   Feb 26
    With the amount of traveling I have been doing in the last year, I think the single best thing I did was buy an @AlaskaAir lounge pass. Coffee, food, great wifi and a quiet place to relax between flights. I’ve even live-streamed from one in Seattle!
    Aaron Parecki
    ooh this is relevant to my interests. They didn't mind you live-streaming from there? Did you go find a private booth or just set up in the corner somewhere? I have some trips coming up...
    Portland, Oregon • 33°F
    1 like 1 reply
    Sat, Feb 26, 2022 6:27am -08:00
  • INUX3D_AU https://twitter.com/INUX3D_AU
    Let the tapping begin

    Sing to “Bottles of beer”

    🎶
    120 M5 holes to tap,
    120 M5 holes
    Put the drill down, spin it around, 119 M5 holes…
    🎶

    #pk1stand #prostreamer
    #yolobox #yoloboxpro #yoloboxcage @Inux3D @aaronpk @YoloLivTech
    https://pk1.tv
    Portland, Oregon • 33°F
    Sat, Feb 26, 2022 7:39am +00:00 (liked on Sat, Feb 26, 2022 6:24am -08:00) #pk1stand #prostreamer #yolobox #yoloboxpro #yoloboxcage
  • The ATEM Mini keeps ruining my video recordings 😠

    I keep losing my video recordings because of this bug with the ATEM Mini! I hope Blackmagic can fix it soon!
    continue reading...
    Fri, Feb 25, 2022 9:21pm -08:00
  • Andrew Kan https://twitter.com/AndrewKanFilm
    Idea for #YouTube let us set a Superchat/Sticker/Thanks goal on our channel, so our audience can know what we plan to do with the content. This could help us be transaprent and also help our audience be apart of the progress towards goals. What do you think about this?
    Portland, Oregon • 41°F
    Fri, Feb 25, 2022 7:22pm +00:00 (liked on Fri, Feb 25, 2022 5:59pm -08:00) #YouTube
  • Vittorio https://twitter.com/vibronet   •   Feb 25
    Yesterday I was attending a 350ppl Zoom meeting while driving.
    The car in front of me made me miss a green light🚦, & I let out a scream of pure, unadulterated rage😡 .
    The presenter suddenly stopped and everyone in chat wondered what made Vittorio so upset. I was unmuted 😅 oops
    Aaron Parecki
    It was frankly an unforgettable moment 😅
    Portland, Oregon • 43°F
    4 likes
    Fri, Feb 25, 2022 5:33pm -08:00
  • Vittorio https://twitter.com/vibronet
    Yesterday I was attending a 350ppl Zoom meeting while driving.
    The car in front of me made me miss a green light🚦, & I let out a scream of pure, unadulterated rage😡 .
    The presenter suddenly stopped and everyone in chat wondered what made Vittorio so upset. I was unmuted 😅 oops
    Portland, Oregon • 44°F
    Fri, Feb 25, 2022 9:19pm +00:00 (liked on Fri, Feb 25, 2022 5:33pm -08:00)
  • WTF OAuth https://twitter.com/wtf_oauth
    I still can't believe my bank uses OAuth for authentication. I mean, they are the bank. They should be able to trust me.
    Portland, Oregon • 44°F
    Fri, Feb 25, 2022 11:24pm +00:00 (liked on Fri, Feb 25, 2022 5:32pm -08:00)
  • PhotoJoseph https://twitter.com/photojoseph
    Why do brands reach out with “sponsorship” offers then later say “we can only sponsor with a free ($100) product”. That is not a sponsorship.
    Portland, Oregon • 30°F
    Fri, Feb 25, 2022 2:13am +00:00 (liked on Thu, Feb 24, 2022 9:10pm -08:00)
  • Mary Louise Kelly https://twitter.com/NPRKelly
    For those asking, @npr goes with Ukrainian spelling & pronunciation (not Russian) wherever possible when reporting on Ukraine.

    Kyiv not Kiev. KEE-eve not KEE-yev.

    Hat tip: @michelekelemen @wexler_m
    #Kyiv #Ukraine
    Portland, Oregon • 30°F
    Mon, Jan 24, 2022 3:46pm +00:00 (liked on Thu, Feb 24, 2022 9:00pm -08:00) #Kyiv #Ukraine
  • Aaron Parecki
    Well that's quite the sentence:

    "Facebook has built its empire on the ability to acquire intimate details about user behavior across the internet"

    https://9to5mac.com/2022/02/24/app-tracking-transparency-harmful-says-facebook/
    Portland, Oregon, USA • 30°F
    1 repost 2 replies
    Thu, Feb 24, 2022 8:58pm -08:00 #facebook
  • Faruk 🚀 ᴵᴾᴴᴼᴺᴱᴰᴼ https://twitter.com/iPhonedo
    I wonder how stupid we look from space.
    Portland, Oregon • 32°F
    Thu, Feb 24, 2022 6:23pm +00:00 (liked on Thu, Feb 24, 2022 7:39pm -08:00)
  • WTF OAuth https://twitter.com/wtf_oauth
    I still remember the first time I used OAuth 2.0. It was so easy and fast that I thought it was a joke.
    Portland, Oregon • 32°F
    Thu, Feb 24, 2022 10:24pm +00:00 (liked on Thu, Feb 24, 2022 7:37pm -08:00)
  • Brock Allen https://twitter.com/BrockLAllen   •   Feb 25
    Arguably, tho, PKCE and putting a client secret into a SPA are orthogonal. It's conflating two things that work differently. Poor devs can't understand those differences.

    The error should be "we see you sent a client secret and an Origin header. is your client a SPA?"
    Aaron Parecki
    I totally agree, this error message makes no sense. I'm going to file a ticket tomorrow internally to fix it.
    Portland, Oregon, USA • 33°F
    Thu, Feb 24, 2022 7:18pm -08:00
  • Hirsch Singhal https://twitter.com/hpsin_   •   Feb 25
    Helps prevent devs from putting their client secrets in a web page to perform the client creds flow, yep. When AAD enabled this, we definitely got a couple support calls on that. This was how we ratcheted forward PKCE use from suggested to required as well.
    Aaron Parecki
    yep you guessed it! misleading error message but that's exactly what was going on.
    Portland, Oregon, USA • 33°F
    2 replies
    Thu, Feb 24, 2022 7:07pm -08:00
  • Brock Allen https://twitter.com/BrockLAllen   •   Feb 25
    Ah, good question -- I didn't notice that. I bet their client config is misconfigured then.
    Aaron Parecki
    Yep, I confirmed my suspicion. Misleading error message. Will post details on the github thread.
    Portland, Oregon, USA • 33°F
    1 like
    Thu, Feb 24, 2022 7:03pm -08:00
  • Brock Allen https://twitter.com/BrockLAllen   •   Feb 25
    People are asking, when using standards compliant OIDC client libraries:

    https://github.com/authts/oidc-client-ts/issues/395#issue-1149525542
    Aaron Parecki
    why does that example have the browser sending a client secret in the request? That seems odd. Happy to continue this over on the github thread.
    Portland, Oregon, USA • 34°F
    2 replies
    Thu, Feb 24, 2022 6:58pm -08:00
  • Brock Allen https://twitter.com/BrockLAllen   •   Feb 25
    It's confusing as hell, and I'm confused by the implementation -- on the token endpoint if Origin is present, you require that the authz used PKCE? That's about the only valid approach to that I can imagine.
    Aaron Parecki
    Yeah that's right. I agree it's super confusing and has caused some tricky issues before. It may be different in the new platform but I'd have to double check
    Portland, Oregon • 34°F
    4 replies
    Thu, Feb 24, 2022 6:53pm -08:00
older

Hi, I'm Aaron Parecki, Director of Identity Standards at Okta, and co-founder of IndieWebCamp. I maintain oauth.net, write and consult about OAuth, and participate in the OAuth Working Group at the IETF. I also help people learn about video production and livestreaming. (detailed bio)

I've been tracking my location since 2008 and I wrote 100 songs in 100 days. I've spoken at conferences around the world about owning your data, OAuth, quantified self, and explained why R is a vowel. Read more.

  • Director of Identity Standards at Okta
  • IndieWebCamp Founder
  • OAuth WG Editor
  • OpenID Board Member

  • 🎥 YouTube Tutorials and Reviews
  • 🏠 We're building a triplex!
  • ⭐️ Life Stack
  • ⚙️ Home Automation
  • All
  • Articles
  • Bookmarks
  • Notes
  • Photos
  • Replies
  • Reviews
  • Trips
  • Videos
  • Contact
© 1999-2025 by Aaron Parecki. Powered by p3k. This site supports Webmention.
Except where otherwise noted, text content on this site is licensed under a Creative Commons Attribution 3.0 License.
IndieWebCamp Microformats Webmention W3C HTML5 Creative Commons
WeChat ID
aaronpk_tv