71°F

Aaron Parecki

  • Articles
  • Notes
  • Photos

#security

  • Aaron Parecki
    Good reminder to add "check whether the password field supports pasting from password managers" to my list of criteria when deciding where to open a bank account. https://twitter.com/KeyBank_Help/status/1148247347463446528
    Portland, Oregon, USA
    23 likes 2 reposts 4 replies
    Mon, Jul 8, 2019 8:20am -07:00 #security
  • Everybody is getting tragically sim swapped and you will too (www.tonysheng.com)
    Wed, Jun 19, 2019 11:54pm +01:00 #sim #security #hack
  • privacy/security concerns · Issue #68 · plaid/link (web.archive.org)
    Wed, Jun 19, 2019 11:32am +01:00 #bank #security #oauth
  • Better Default Security for IndieAuth Login Forms

    Last year, I posted a JavaScript snippet that I've started using in all my projects that have an IndieAuth login form, which will automatically add the http scheme if you type a plain domain. This is particularly a problem because the iOS keyboard doesn't include the : character in URL mode.
    continue reading...
    3 likes 1 reply
    Mon, May 13, 2019 12:49am +02:00 #indieweb #indieauth #security #https
  • Drummond Reed https://twitter.com/drummondreed
    Biggest laugh at #IIW so far: when @justin__richer in his session on β€œIs #selfsovereignidentity really possible” turned to Dave Crocker and said that we can all blame him for the Internet not having #security built in from the start.
    San Jose, California • 49°F
    Thu, May 2, 2019 6:03pm +00:00 (liked on Thu, May 2, 2019 4:18pm -07:00) #IIW #selfsovereignidentity #security
  • #110293 Insufficient OAuth callback validation which leads to Periscope account takeover (hackerone.com)
    Fri, Apr 12, 2019 11:37pm -07:00 #oauth #twitter #security
  • Security Considerations While Using ssh-agent. – Command Prompt, Inc. (www.commandprompt.com)
    Fri, Apr 12, 2019 10:29am +02:00 #ssh #security
  • Aaron Parecki https://aaronparecki.com/
    Standing room only for my talk at #oktane19! πŸŽ‰ "OAuth: When Things Go Wrong" I had a blast, thanks everyone for coming to the session!
    The video will be posted to the @okta YouTube channel soon! .
    .
    .
    #okta #oktane #oauth #security #devrel #facebookfail #twitterfail #googlefail πŸ“· @quorralyne
    San Francisco, California • 49°F
    Wed, Apr 3, 2019 3:48pm -07:00 (liked on Thu, Apr 4, 2019 7:35am -07:00) #oktane19 #okta #oktane #oauth #security #devrel #facebookfail #twitterfail #googlefail
  • Aaron Parecki
    Standing room only for my talk at #oktane19! πŸŽ‰ "OAuth: When Things Go Wrong" I had a blast, thanks everyone for coming to the session!
    The video will be posted to the @okta YouTube channel soon! .
    .
    .
    #okta #oktane #oauth #security #devrel #facebookfail #twitterfail #googlefail πŸ“· @quorralyne
    Moscone West Convention Center in San Francisco, California, USA • 49°F
    20 likes 1 repost 2 replies
    Wed, Apr 3, 2019 3:48pm -07:00 #oktane19 #okta #oktane #oauth #security #devrel #facebookfail #twitterfail #googlefail
  • How To Spoof PDF Signatures (web-in-security.blogspot.com)
    Wed, Mar 6, 2019 11:36am -08:00 #pdf #security
  • #202781 Chained Bugs to Leak Victim's Uber's FB Oauth Token (hackerone.com)
    Mon, Feb 25, 2019 9:06am -06:00 #oauth #security #hack #bug #uber
  • [Uber 8k Bug] Login CSRF + Open Redirect = Account Take Over – Ron Chan (ngailong.wordpress.com)
    Mon, Feb 25, 2019 9:05am -06:00 #oauth #security
  • Trusted Types help prevent Cross-Site Scripting  |  Web  |  Google Developers (developers.google.com)
    Sun, Feb 17, 2019 7:31am -08:00 #xss #web #security
  • Chaining Tricky OAuth Exploitation To Stored XSS – Rohan Aggarwal – Medium (medium.com)
    Sun, Jan 27, 2019 4:48pm -08:00 #oauth #security #xss
  • Aaron Parecki
    If you've ever needed a link to send someone to explain why OAuth secrets aren't safe in mobile apps, I made you a thing: https://developer.okta.com/blog/2019/01/22/oauth-api-keys-arent-safe-in-mobile-apps
    San Francisco, California, USA • 59°F
    13 likes 10 reposts 3 replies
    Tue, Jan 22, 2019 4:09pm -08:00 #oauth #oauth2 #api #security
  • Blue Iris - Video Security Software (blueirissoftware.com)
    Wed, Jan 16, 2019 10:26pm -08:00 #homeautomation #security #camera
  • willman duffy https://twitter.com/willmanduffy
    0 factor auth
    Portland, Oregon • 52°F
    Thu, Dec 13, 2018 3:45pm +00:00 (liked on Mon, Dec 17, 2018 2:59pm -08:00) #security #auth #mfa
  • NFC Card Emulation with ACR122u(PN532) (salmg.net)
    Sun, Dec 2, 2018 3:04pm -08:00 #nfc #security #oauth
  • Aaron Parecki
    Yet another example of why SMS is terrible for 2fa and account recovery.

    "the database β€” running on Amazon’s Elasticsearch β€” was configured with a Kibana front-end, making the data within easily readable"

    https://techcrunch.com/2018/11/15/millions-sms-text-messages-leaked-two-factor-codes/
    Chicago, Illinois, USA • 39°F
    7 likes 9 reposts 2 replies
    Fri, Nov 16, 2018 3:23pm -06:00 #security #sms #2fa
  • Shinobi - Simple CCTV and NVR Solution - Home (shinobi.video)
    Tue, Aug 7, 2018 8:01pm -07:00 #cctv #security
older

Hi, I'm Aaron Parecki, Director of Identity Standards at Okta, and co-founder of IndieWebCamp. I maintain oauth.net, write and consult about OAuth, and participate in the OAuth Working Group at the IETF. I also help people learn about video production and livestreaming. (detailed bio)

I've been tracking my location since 2008 and I wrote 100 songs in 100 days. I've spoken at conferences around the world about owning your data, OAuth, quantified self, and explained why R is a vowel. Read more.

  • Director of Identity Standards at Okta
  • IndieWebCamp Founder
  • OAuth WG Editor
  • OpenID Board Member

  • πŸŽ₯ YouTube Tutorials and Reviews
  • 🏠 We're building a triplex!
  • ⭐️ Life Stack
  • βš™οΈ Home Automation
  • All
  • Articles
  • Bookmarks
  • Notes
  • Photos
  • Replies
  • Reviews
  • Trips
  • Videos
  • Contact
© 1999-2025 by Aaron Parecki. Powered by p3k. This site supports Webmention.
Except where otherwise noted, text content on this site is licensed under a Creative Commons Attribution 3.0 License.
IndieWebCamp Microformats Webmention W3C HTML5 Creative Commons
WeChat ID
aaronpk_tv