53°F

Aaron Parecki

  • Articles
  • Notes
  • Photos

#Security

  • Aaron Parecki
    Remember folks, "token exchange" does *not* mean "let me exchange a customer ID for a token"!

    Good thread on how remotely connected Honda, Nissan, Infiniti, and Acura cars were all able to be remotely controlled knowing only the VIN.

    https://twitter.com/samwcyo/status/1597792145691246593
    Portland, Oregon, USA • 38°F
    20 likes 10 reposts 3 replies 1 mention
    Thu, Dec 1, 2022 11:36am -08:00 #security
  • 1Password passkeys demo shows you the passwordless future (9to5mac.com)
    Thu, Nov 17, 2022 6:31pm -08:00 #passkeys #passwordless #security
  • Aaron Parecki
    This is your scheduled periodic reminder, for no particular reason, that now is a good time to review the third party OAuth apps that have access to your Twitter account, and remove any that you don't recognize or haven't used in a while.

    ➡ https://twitter.com/settings/connected_apps
    Portland, Oregon, USA • 43°F
    47 likes 20 reposts 5 replies
    Tue, Nov 15, 2022 6:36pm -08:00 #oauth #twitter #security
  • Aaron Parecki
    What could possibly go wrong? https://twitter.com/racheltobac/status/1588367452043235328
    Seattle, Washington, USA • 41°F
    26 likes 13 reposts 1 reply
    Thu, Nov 3, 2022 8:16pm -07:00 #twitter #security
  • A Yubico FAQ about passkeys - Yubico (www.yubico.com)
    Wed, Aug 17, 2022 2:30pm -07:00 #yubikey #authentication #security #fido #passkey
  • Let websites framebust out of native apps | Holovaty.com (www.holovaty.com)
    Sun, Aug 14, 2022 6:20am -07:00 #apps #security #oauth
  • Aaron Parecki
    Made a new illustration to use in my slide decks.

    I often talk about choosing where on the security vs usability dial you want your systems to be, so I figured it was time to have a visual for that.
    Houston, Texas, USA • 100°F
    20 likes 10 replies
    Tue, Jul 19, 2022 4:51pm -05:00 #security #oauth
  • Camplayer (www.rpi-camplayer.com)
    Tue, Jun 28, 2022 3:12pm -07:00 #raspi #raspberrypi #camera #security #video
  • Aaron Parecki
    Do I know anyone who knows the right malware analysis tools to determine whether an app accesses any files on the computer or what remote servers it connects to? I want to know more about what this particularly well targeted malware is trying to do.
    Portland, Oregon • 78°F
    13 likes 4 reposts 10 replies 1 mention
    Thu, Jun 2, 2022 5:45pm -07:00 #security #malware
  • Aaron Parecki
    After some great presentations and discussions at the OAuth Security Workshop and European Identity and Cloud Conference, I wrote up some of my thoughts on OAuth and native app impersonation #eic2022 #osw #oauth

    https://developer.okta.com/blog/2022/06/01/oauth-public-client-identity
    Portland, Oregon • 65°F
    22 likes 13 reposts 1 reply
    Wed, Jun 1, 2022 10:46am -07:00 #oauth #security #eic2022 #osw
  • Aaron Parecki
    Sad but true thread on the state of corporate security https://twitter.com/crdudeyoutube/status/1529994566115348485
    Portland, Oregon, USA • 54°F
    4 likes 2 reposts 1 reply
    Fri, May 27, 2022 6:05am -07:00 #security
  • Aaron Parecki
    There's nothing like being at #EIC2022, a conference all about identity and security, where phishing and hacking have been a major theme across all the talks, and then getting a "is this you?" push on my phone from an IP on a sketchy VPN followed by a password reset email
    Berlin, Berlin • 60°F
    24 likes 3 reposts 5 replies
    Thu, May 12, 2022 10:10am +02:00 #security #eic #mfa #eic2022
  • App Integrity Attestations for OAuth
    May
    6
    May 6, 2022 11:30am - 12:00pm (+0200)
    Scandic Nidelven
    Trondheim, Trøndelag, NOR
    OAuth Security Workshop
    View Slides
    permalink #oauth #security #osw #osw7
  • OAuth Security Workshop
    May
    4
    May
    5
    May
    6
    May 4-6, 2022
    3 days
    Scandic Nidelven
    Trondheim, Trøndelag, NOR
    permalink #oauth #okta #oktadev #security #osw
  • CVE-2022-21449: Psychic Signatures in Java – Neil Madden (neilmadden.blog)
    Wed, Apr 20, 2022 5:57am -07:00 #crypto #security #java
  • Aaron Parecki
    Dear @Linode, these are two very different things! Please don't combine them into the same notification! #security
    Wien, Wien
    16 likes 1 repost 2 replies
    Sun, Mar 27, 2022 12:00pm +02:00 #security #password
  • Record and archive video from IP cameras – LucaTNT's (lucatnt.com)
    Fri, Mar 4, 2022 2:07pm -08:00 #security #rtsp #video
  • Silkworm Encryption – The New Stack (thenewstack.io)
    Thu, Mar 3, 2022 9:07am -08:00 #encryption #security #random
  • OAuth 2.0 Device Posture Signals (tools.ietf.org)
    Mon, Jan 24, 2022 6:09pm -08:00 #oauth #ios #security
  • Establishing Your App’s Integrity | Apple Developer Documentation (developer.apple.com)
    Mon, Jan 24, 2022 5:40pm -08:00 #ios #security
older

Hi, I'm Aaron Parecki, Director of Identity Standards at Okta, and co-founder of IndieWebCamp. I maintain oauth.net, write and consult about OAuth, and participate in the OAuth Working Group at the IETF. I also help people learn about video production and livestreaming. (detailed bio)

I've been tracking my location since 2008 and I wrote 100 songs in 100 days. I've spoken at conferences around the world about owning your data, OAuth, quantified self, and explained why R is a vowel. Read more.

  • Director of Identity Standards at Okta
  • IndieWebCamp Founder
  • OAuth WG Editor
  • OpenID Board Member

  • 🎥 YouTube Tutorials and Reviews
  • 🏠 We're building a triplex!
  • ⭐️ Life Stack
  • ⚙️ Home Automation
  • All
  • Articles
  • Bookmarks
  • Notes
  • Photos
  • Replies
  • Reviews
  • Trips
  • Videos
  • Contact
© 1999-2025 by Aaron Parecki. Powered by p3k. This site supports Webmention.
Except where otherwise noted, text content on this site is licensed under a Creative Commons Attribution 3.0 License.
IndieWebCamp Microformats Webmention W3C HTML5 Creative Commons
WeChat ID
aaronpk_tv