57°F

Aaron Parecki

  • Articles
  • Notes
  • Photos

#security

  • Aaron Parecki
    This @jack situation is making me rethink my phone number strategy. I've been treating my SIM number as disposable and easily replaceable, where the number I use for 2FA is a google voice number. But now I'm thinking treating my SIM number as a password is a better plan.
    Portland, Oregon, USA
    6 likes 1 repost 2 replies
    Fri, Aug 30, 2019 2:23pm -07:00 #security
  • Aaron Parecki
    TIL even web developers aren't safe from side-channel attacks. Nice overview of CORB and why it's important. https://developer.okta.com/blog/2019/08/26/combat-side-channel-attacks-with-corb
    Portland, Oregon, USA
    4 likes
    Mon, Aug 26, 2019 9:08am -07:00 #security #corb #til
  • A Technical Analysis of the Capital One Hack - CloudSploit (blog.cloudsploit.com)
    Wed, Aug 7, 2019 12:03pm -07:00 #security #aws
  • apple_bleee/README.md at master · hexway/apple_bleee (github.com)
    Mon, Jul 29, 2019 7:42am -07:00 #bluetooth #apple #ios #security
  • UniFi Video & Nginx Reverse Proxy | Ubiquiti Community (community.ui.com)
    Sat, Jul 20, 2019 5:35pm -07:00 #unifi #video #camera #security #homeautomation
  • Heather Downing https://twitter.com/quorralyne
    Come to the @oktadev booth at #KCDC2019 to chat with fun and awesome people about #oauth #security and win stuff in it developer challenge! @briandemers @aaronpk @afitnerd @okta #Okta
    Kansas City, Missouri
    1 mention
    Wed, Jul 17, 2019 3:16pm +00:00 (liked on Wed, Jul 17, 2019 11:08am -05:00) #KCDC2019 #oauth #security #Okta
  • Aaron Parecki
    Good reminder to add "check whether the password field supports pasting from password managers" to my list of criteria when deciding where to open a bank account. https://twitter.com/KeyBank_Help/status/1148247347463446528
    Portland, Oregon, USA
    23 likes 2 reposts 4 replies
    Mon, Jul 8, 2019 8:20am -07:00 #security
  • Everybody is getting tragically sim swapped and you will too (www.tonysheng.com)
    Wed, Jun 19, 2019 11:54pm +01:00 #sim #security #hack
  • privacy/security concerns · Issue #68 · plaid/link (web.archive.org)
    Wed, Jun 19, 2019 11:32am +01:00 #bank #security #oauth
  • Better Default Security for IndieAuth Login Forms

    Last year, I posted a JavaScript snippet that I've started using in all my projects that have an IndieAuth login form, which will automatically add the http scheme if you type a plain domain. This is particularly a problem because the iOS keyboard doesn't include the : character in URL mode.
    continue reading...
    3 likes 1 reply
    Mon, May 13, 2019 12:49am +02:00 #indieweb #indieauth #security #https
  • Drummond Reed https://twitter.com/drummondreed
    Biggest laugh at #IIW so far: when @justin__richer in his session on β€œIs #selfsovereignidentity really possible” turned to Dave Crocker and said that we can all blame him for the Internet not having #security built in from the start.
    San Jose, California • 49°F
    Thu, May 2, 2019 6:03pm +00:00 (liked on Thu, May 2, 2019 4:18pm -07:00) #IIW #selfsovereignidentity #security
  • #110293 Insufficient OAuth callback validation which leads to Periscope account takeover (hackerone.com)
    Fri, Apr 12, 2019 11:37pm -07:00 #oauth #twitter #security
  • Security Considerations While Using ssh-agent. – Command Prompt, Inc. (www.commandprompt.com)
    Fri, Apr 12, 2019 10:29am +02:00 #ssh #security
  • Aaron Parecki https://aaronparecki.com/
    Standing room only for my talk at #oktane19! πŸŽ‰ "OAuth: When Things Go Wrong" I had a blast, thanks everyone for coming to the session!
    The video will be posted to the @okta YouTube channel soon! .
    .
    .
    #okta #oktane #oauth #security #devrel #facebookfail #twitterfail #googlefail πŸ“· @quorralyne
    San Francisco, California • 49°F
    Wed, Apr 3, 2019 3:48pm -07:00 (liked on Thu, Apr 4, 2019 7:35am -07:00) #oktane19 #okta #oktane #oauth #security #devrel #facebookfail #twitterfail #googlefail
  • Aaron Parecki
    Standing room only for my talk at #oktane19! πŸŽ‰ "OAuth: When Things Go Wrong" I had a blast, thanks everyone for coming to the session!
    The video will be posted to the @okta YouTube channel soon! .
    .
    .
    #okta #oktane #oauth #security #devrel #facebookfail #twitterfail #googlefail πŸ“· @quorralyne
    Moscone West Convention Center in San Francisco, California, USA • 49°F
    20 likes 1 repost 2 replies
    Wed, Apr 3, 2019 3:48pm -07:00 #oktane19 #okta #oktane #oauth #security #devrel #facebookfail #twitterfail #googlefail
  • How To Spoof PDF Signatures (web-in-security.blogspot.com)
    Wed, Mar 6, 2019 11:36am -08:00 #pdf #security
  • #202781 Chained Bugs to Leak Victim's Uber's FB Oauth Token (hackerone.com)
    Mon, Feb 25, 2019 9:06am -06:00 #oauth #security #hack #bug #uber
  • [Uber 8k Bug] Login CSRF + Open Redirect = Account Take Over – Ron Chan (ngailong.wordpress.com)
    Mon, Feb 25, 2019 9:05am -06:00 #oauth #security
  • Trusted Types help prevent Cross-Site Scripting  |  Web  |  Google Developers (developers.google.com)
    Sun, Feb 17, 2019 7:31am -08:00 #xss #web #security
  • Chaining Tricky OAuth Exploitation To Stored XSS – Rohan Aggarwal – Medium (medium.com)
    Sun, Jan 27, 2019 4:48pm -08:00 #oauth #security #xss
older

Hi, I'm Aaron Parecki, Director of Identity Standards at Okta, and co-founder of IndieWebCamp. I maintain oauth.net, write and consult about OAuth, and participate in the OAuth Working Group at the IETF. I also help people learn about video production and livestreaming. (detailed bio)

I've been tracking my location since 2008 and I wrote 100 songs in 100 days. I've spoken at conferences around the world about owning your data, OAuth, quantified self, and explained why R is a vowel. Read more.

  • Director of Identity Standards at Okta
  • IndieWebCamp Founder
  • OAuth WG Editor
  • OpenID Board Member

  • πŸŽ₯ YouTube Tutorials and Reviews
  • 🏠 We're building a triplex!
  • ⭐️ Life Stack
  • βš™οΈ Home Automation
  • All
  • Articles
  • Bookmarks
  • Notes
  • Photos
  • Replies
  • Reviews
  • Trips
  • Videos
  • Contact
© 1999-2025 by Aaron Parecki. Powered by p3k. This site supports Webmention.
Except where otherwise noted, text content on this site is licensed under a Creative Commons Attribution 3.0 License.
IndieWebCamp Microformats Webmention W3C HTML5 Creative Commons
WeChat ID
aaronpk_tv