78°F

Aaron Parecki

  • Articles
  • Notes
  • Photos

#Security

  • Philippe De Ryck https://twitter.com/PhilippeDeRyck
    API security touches upon various different topics. I am discussing a couple of common #API #security pitfalls at the @OWASPLondon meetup tonight. Here's an extended slide deck, with a ton of useful information. https://buff.ly/2N7ySAz

    Come say hi tonight, and share this info!
    Amsterdam, Noord-Holland • 61°F
    Thu, Sep 19, 2019 5:00pm +00:00 (liked on Thu, Sep 26, 2019 12:19pm +02:00) #API #security
  • Deconstructing an iPhone Spearphishing Attack (www.darkreading.com)
    Sun, Sep 22, 2019 7:05am +00:00 #iphone #security
  • Securing Your APIs with OAuth 2.0
    Sep
    19
    September 19, 2019 1:30pm - 2:00pm (+1000)
    API Days Melbourne
    API Days Melbourne
    View Slides
    Watch Video
    permalink #oauth #api #oktadev #security
  • e-sushi https://twitter.com/originalesushi
    Hey @facebook, demanding the secret password of the personal email accounts of your users for verification, or any other kind of use, is a HORRIBLE idea from an #infosec point of view. By going down that road, you're practically fishing for passwords you are not supposed to know!
    Sydney, New South Wales • 52°F
    Sun, Mar 31, 2019 11:27pm +00:00 (liked on Tue, Sep 17, 2019 12:04pm +10:00) #infosec #facebook #oauth #security
  • dekuNukem/daytripper: A Multifunctional Laser Tripwire (github.com)
    Mon, Sep 9, 2019 8:43pm -05:00 #electronics #security
  • Fraudsters deepfake CEO's voice to trick manager into transferring $243,000 (thenextweb.com)
    Mon, Sep 9, 2019 8:13am -05:00 #security
  • Aaron Parecki
    This @jack situation is making me rethink my phone number strategy. I've been treating my SIM number as disposable and easily replaceable, where the number I use for 2FA is a google voice number. But now I'm thinking treating my SIM number as a password is a better plan.
    Portland, Oregon, USA
    6 likes 1 repost 2 replies
    Fri, Aug 30, 2019 2:23pm -07:00 #security
  • Aaron Parecki
    TIL even web developers aren't safe from side-channel attacks. Nice overview of CORB and why it's important. https://developer.okta.com/blog/2019/08/26/combat-side-channel-attacks-with-corb
    Portland, Oregon, USA
    4 likes
    Mon, Aug 26, 2019 9:08am -07:00 #security #corb #til
  • A Technical Analysis of the Capital One Hack - CloudSploit (blog.cloudsploit.com)
    Wed, Aug 7, 2019 12:03pm -07:00 #security #aws
  • apple_bleee/README.md at master · hexway/apple_bleee (github.com)
    Mon, Jul 29, 2019 7:42am -07:00 #bluetooth #apple #ios #security
  • UniFi Video & Nginx Reverse Proxy | Ubiquiti Community (community.ui.com)
    Sat, Jul 20, 2019 5:35pm -07:00 #unifi #video #camera #security #homeautomation
  • Heather Downing https://twitter.com/quorralyne
    Come to the @oktadev booth at #KCDC2019 to chat with fun and awesome people about #oauth #security and win stuff in it developer challenge! @briandemers @aaronpk @afitnerd @okta #Okta
    Kansas City, Missouri
    1 mention
    Wed, Jul 17, 2019 3:16pm +00:00 (liked on Wed, Jul 17, 2019 11:08am -05:00) #KCDC2019 #oauth #security #Okta
  • Aaron Parecki
    Good reminder to add "check whether the password field supports pasting from password managers" to my list of criteria when deciding where to open a bank account. https://twitter.com/KeyBank_Help/status/1148247347463446528
    Portland, Oregon, USA
    23 likes 2 reposts 4 replies
    Mon, Jul 8, 2019 8:20am -07:00 #security
  • Everybody is getting tragically sim swapped and you will too (www.tonysheng.com)
    Wed, Jun 19, 2019 11:54pm +01:00 #sim #security #hack
  • privacy/security concerns · Issue #68 · plaid/link (web.archive.org)
    Wed, Jun 19, 2019 11:32am +01:00 #bank #security #oauth
  • Better Default Security for IndieAuth Login Forms

    Last year, I posted a JavaScript snippet that I've started using in all my projects that have an IndieAuth login form, which will automatically add the http scheme if you type a plain domain. This is particularly a problem because the iOS keyboard doesn't include the : character in URL mode.
    continue reading...
    3 likes 1 reply
    Mon, May 13, 2019 12:49am +02:00 #indieweb #indieauth #security #https
  • Drummond Reed https://twitter.com/drummondreed
    Biggest laugh at #IIW so far: when @justin__richer in his session on โ€œIs #selfsovereignidentity really possibleโ€ turned to Dave Crocker and said that we can all blame him for the Internet not having #security built in from the start.
    San Jose, California • 49°F
    Thu, May 2, 2019 6:03pm +00:00 (liked on Thu, May 2, 2019 4:18pm -07:00) #IIW #selfsovereignidentity #security
  • #110293 Insufficient OAuth callback validation which leads to Periscope account takeover (hackerone.com)
    Fri, Apr 12, 2019 11:37pm -07:00 #oauth #twitter #security
  • Security Considerations While Using ssh-agent. – Command Prompt, Inc. (www.commandprompt.com)
    Fri, Apr 12, 2019 10:29am +02:00 #ssh #security
  • Aaron Parecki https://aaronparecki.com/
    Standing room only for my talk at #oktane19! ๐ŸŽ‰ "OAuth: When Things Go Wrong" I had a blast, thanks everyone for coming to the session!
    The video will be posted to the @okta YouTube channel soon! .
    .
    .
    #okta #oktane #oauth #security #devrel #facebookfail #twitterfail #googlefail ๐Ÿ“ท @quorralyne
    San Francisco, California • 49°F
    Wed, Apr 3, 2019 3:48pm -07:00 (liked on Thu, Apr 4, 2019 7:35am -07:00) #oktane19 #okta #oktane #oauth #security #devrel #facebookfail #twitterfail #googlefail
older

Hi, I'm Aaron Parecki, Director of Identity Standards at Okta, and co-founder of IndieWebCamp. I maintain oauth.net, write and consult about OAuth, and participate in the OAuth Working Group at the IETF. I also help people learn about video production and livestreaming. (detailed bio)

I've been tracking my location since 2008 and I wrote 100 songs in 100 days. I've spoken at conferences around the world about owning your data, OAuth, quantified self, and explained why R is a vowel. Read more.

  • Director of Identity Standards at Okta
  • IndieWebCamp Founder
  • OAuth WG Editor
  • OpenID Board Member

  • ๐ŸŽฅ YouTube Tutorials and Reviews
  • ๐Ÿ  We're building a triplex!
  • โญ๏ธ Life Stack
  • โš™๏ธ Home Automation
  • All
  • Articles
  • Bookmarks
  • Notes
  • Photos
  • Replies
  • Reviews
  • Trips
  • Videos
  • Contact
© 1999-2025 by Aaron Parecki. Powered by p3k. This site supports Webmention.
Except where otherwise noted, text content on this site is licensed under a Creative Commons Attribution 3.0 License.
IndieWebCamp Microformats Webmention W3C HTML5 Creative Commons
WeChat ID
aaronpk_tv