74°F

Aaron Parecki

  • Articles
  • Notes
  • Photos

#Security

  • Aaron Parecki
    Standing room only for my talk at #oktane19! πŸŽ‰ "OAuth: When Things Go Wrong" I had a blast, thanks everyone for coming to the session!
    The video will be posted to the @okta YouTube channel soon! .
    .
    .
    #okta #oktane #oauth #security #devrel #facebookfail #twitterfail #googlefail πŸ“· @quorralyne
    Moscone West Convention Center in San Francisco, California, USA • 49°F
    20 likes 1 repost 2 replies
    Wed, Apr 3, 2019 3:48pm -07:00 #oktane19 #okta #oktane #oauth #security #devrel #facebookfail #twitterfail #googlefail
  • How To Spoof PDF Signatures (web-in-security.blogspot.com)
    Wed, Mar 6, 2019 11:36am -08:00 #pdf #security
  • #202781 Chained Bugs to Leak Victim's Uber's FB Oauth Token (hackerone.com)
    Mon, Feb 25, 2019 9:06am -06:00 #oauth #security #hack #bug #uber
  • [Uber 8k Bug] Login CSRF + Open Redirect = Account Take Over – Ron Chan (ngailong.wordpress.com)
    Mon, Feb 25, 2019 9:05am -06:00 #oauth #security
  • Trusted Types help prevent Cross-Site Scripting  |  Web  |  Google Developers (developers.google.com)
    Sun, Feb 17, 2019 7:31am -08:00 #xss #web #security
  • Chaining Tricky OAuth Exploitation To Stored XSS – Rohan Aggarwal – Medium (medium.com)
    Sun, Jan 27, 2019 4:48pm -08:00 #oauth #security #xss
  • Aaron Parecki
    If you've ever needed a link to send someone to explain why OAuth secrets aren't safe in mobile apps, I made you a thing: https://developer.okta.com/blog/2019/01/22/oauth-api-keys-arent-safe-in-mobile-apps
    San Francisco, California, USA • 59°F
    13 likes 10 reposts 3 replies
    Tue, Jan 22, 2019 4:09pm -08:00 #oauth #oauth2 #api #security
  • Blue Iris - Video Security Software (blueirissoftware.com)
    Wed, Jan 16, 2019 10:26pm -08:00 #homeautomation #security #camera
  • willman duffy https://twitter.com/willmanduffy
    0 factor auth
    Portland, Oregon • 52°F
    Thu, Dec 13, 2018 3:45pm +00:00 (liked on Mon, Dec 17, 2018 2:59pm -08:00) #security #auth #mfa
  • NFC Card Emulation with ACR122u(PN532) (salmg.net)
    Sun, Dec 2, 2018 3:04pm -08:00 #nfc #security #oauth
  • Aaron Parecki
    Yet another example of why SMS is terrible for 2fa and account recovery.

    "the database β€” running on Amazon’s Elasticsearch β€” was configured with a Kibana front-end, making the data within easily readable"

    https://techcrunch.com/2018/11/15/millions-sms-text-messages-leaked-two-factor-codes/
    Chicago, Illinois, USA • 39°F
    7 likes 9 reposts 2 replies
    Fri, Nov 16, 2018 3:23pm -06:00 #security #sms #2fa
  • Shinobi - Simple CCTV and NVR Solution - Home (shinobi.video)
    Tue, Aug 7, 2018 8:01pm -07:00 #cctv #security
  • Securing Web Sites Made Them Less Accessible – Eric’s Archived Thoughts (meyerweb.com)
    Tue, Aug 7, 2018 4:01pm -07:00 #https #security #web
  • WireGuard: fast, modern, secure VPN tunnel (www.wireguard.com)
    Sun, Jul 29, 2018 8:03pm -07:00 #vpn #security
  • Gmail OAuth Phishing Goes Viral | Duo Security (duo.com)
    Tue, Jul 17, 2018 4:41pm -07:00 #oauth #security #google #gmail
  • Aaron Parecki
    Well this looks handy https://twitter.com/mraible/status/1017546900122361861
    Portland, Oregon, USA • 94°F
    3 likes
    Thu, Jul 12, 2018 4:28pm -07:00 #security #paseto
  • Troy Hunt: Pwned Passwords in Practice: Real World Examples of Blocking the Worst Passwords (www.troyhunt.com)
    Tue, May 29, 2018 9:54am -07:00 #okta #password #security
  • Aaron Parecki
    #tbt to when Facebook used to ask for your email password so that it could download your contact list lol omg πŸ˜±πŸ˜‚
    Portland, Oregon • 65°F
    5 likes 3 reposts 1 reply 2 mentions
    Thu, Apr 19, 2018 2:40pm -07:00 #oauth #security #facebook #tbt
  • Aaron Parecki
    I'm looking forward to #WebAuthn rolling out to more browsers and devices! πŸ” Here's a little taste of what's coming πŸ”œ https://developer.okta.com/blog/2018/04/17/webauthn-developers-guide-to-whats-on-the-horizon
    Portland, Oregon • 43°F
    13 likes 9 reposts
    Tue, Apr 17, 2018 7:45am -07:00 #webauthn #security
  • The dots do matter: how to scam a Gmail user (jameshfisher.com)
    Sat, Apr 7, 2018 12:55pm -07:00 #gmail #email #phishing #security
older

Hi, I'm Aaron Parecki, Director of Identity Standards at Okta, and co-founder of IndieWebCamp. I maintain oauth.net, write and consult about OAuth, and participate in the OAuth Working Group at the IETF. I also help people learn about video production and livestreaming. (detailed bio)

I've been tracking my location since 2008 and I wrote 100 songs in 100 days. I've spoken at conferences around the world about owning your data, OAuth, quantified self, and explained why R is a vowel. Read more.

  • Director of Identity Standards at Okta
  • IndieWebCamp Founder
  • OAuth WG Editor
  • OpenID Board Member

  • πŸŽ₯ YouTube Tutorials and Reviews
  • 🏠 We're building a triplex!
  • ⭐️ Life Stack
  • βš™οΈ Home Automation
  • All
  • Articles
  • Bookmarks
  • Notes
  • Photos
  • Replies
  • Reviews
  • Trips
  • Videos
  • Contact
© 1999-2025 by Aaron Parecki. Powered by p3k. This site supports Webmention.
Except where otherwise noted, text content on this site is licensed under a Creative Commons Attribution 3.0 License.
IndieWebCamp Microformats Webmention W3C HTML5 Creative Commons
WeChat ID
aaronpk_tv