RS: Hey there Brother Man (this apparently is a typical rock star salutation )Content with my mockery of someone more famous & rich, I slept well that night.
Me: Brother Man
RS: How do you like my bike?
Me: If it only had pink streamers, it'd be perfect.
When you don't have anything nice to say, well then perhaps its time consider a career as an analyst.
Monday, July 21, 2008
Brush with fame
A conversation between myself and a (Canadian) rock-star whose cottage happens to be near mine, as he biked by on his daughter's bike
Friday, July 18, 2008
IDDY 2008
The Liberty Alliance announced the winners of this years IDDY awards today.
Aetna – Aetna received a 2008 IDDY Deployment Award for an externally hosted online provider portal used for linking healthcare providers with health plans. Working with NaviMedix, the portal includes a variety of tools including transactions and content hosted by Aetna with interfaces to third-party Internet Application Service Providers and Content Service Providers. The deployment was launched in the US in December 2007 and is currently utilized by healthcare providers in all 50 states.Here is an ID quiz for you. By my copying huge swaths of the press release here, what well-known identity blogger am I channeling? Anyone? Anyone?
Citi – Citi’s Global Transaction Services received a 2008 IDDY Deployment Award for providing managed identity services that help institutional clients utilize digital credentials and signature technologies in a comprehensive and legally binding manner. Citi is both a Credential Service Provider and a Relying Party as defined in the Liberty Identity Assurance Framework (IAF). As a trusted financial services provider to the world’s top corporations and governments in more than 100 countries, Citi is addressing identity challenges in establishing trust in B2B and B2G identity-enabled transactions by coupling rigorous internal processes with proven identity management technologies.
Deutsche Telekom AG - Deutsche Telekom AG received a 2008 Multi-Protocol IDDY Award for its identity application designed to lower implementation barriers when it comes to the delivery of Online/IP-based services to consumers. Initially launched in 2002 and winner of the 2006 IDDY Award, the application has been steadily enhanced to offer multi-protocol capabilities for service provider interfaces as well as for authentication methods and automatic user identification. The application serves the requirements of the mass market for Online/IP-based consumer applications by providing fundamental functionalities such as Single Login, Automatic identification, Single Sign On and Single Logout.
UNINETT – UNINETT received a 2008 Emerging Application IDDY Award for SimpleSAMLphp, an open source lightweight implementation of several federation protocols written in PHP. Free to download and available in 15 languages, simpleSAMLphp is a platform for quick implementation of emerging standards or identity-enabled proof-of concept (POC) applications. The software implements Web SSO, and can be applied in any deployment where users need to be authenticated to a World Wide Web Service.
Getting from A to B
In 'The Discovers', Daniel J. Boorstin describes the process by which 14th & 15th century sailors of the North Sea and Baltic transitioned from their tried and true navigational method of depth sounding to the new-fangled magnetic compass.
Much of their sailing was in shallow waters where sailors had long since been finding their way by feeling their way along the bottom.... Their soundings traced the shape and character of the floor of the sea by "lead and line".... After the compass arrived, pilots off the north European coasts still felt more secure when they could combine the new device with their old reliable lead and line.Hmmm.
Tuesday, July 15, 2008
End of an Era
I am saddened to report that we have decided to end-of-life TrayTable. Changing market conditions forced us to re-evaluate our business plan (actually absence thereof). Bottom line, we were unable to compete against the multitude of low cost 'photo blogs of airline tray tables' coming out of China.
With the low wages they pay their employees and lack of concern for the environmental impact of their blogging, Chinese 'photo blogs of airline tray tables' were able to undercut TrayTable on every RFQ we bid on.
It was a good run.
I am happy to report that the last post features me reclining in one of Air Canada's new business class seats.
I am embarrased to report that the pic captured me wearing those socks from the free kit.
With the low wages they pay their employees and lack of concern for the environmental impact of their blogging, Chinese 'photo blogs of airline tray tables' were able to undercut TrayTable on every RFQ we bid on.
It was a good run.
I am happy to report that the last post features me reclining in one of Air Canada's new business class seats.
I am embarrased to report that the pic captured me wearing those socks from the free kit.
Monday, July 14, 2008
The Sheraton it ain't
Two things made last week's trip to Stockholm for Liberty Alliance meetings stand-out from a typical business trip.
Firstly, Sampo and I were unable to synchronize our time/space continuua to meet at Kapellskar to go sailing. Consequently, I spent the first night of the trip in a lovely cabin at a nearby campground.
Quaint yes. But unreliable wireless connectivity. And I can't believe I'm the first person to ever ask for an extra mint from the turn-down service.
Secondly, Fulup, Joni, and I were later able to get out on Sampo's boat to spend an incredible day sailing in the Swedish Archipelago.
I am proud to add the Baltic to my 'Bodies of Water into which I've Peed' list.
Firstly, Sampo and I were unable to synchronize our time/space continuua to meet at Kapellskar to go sailing. Consequently, I spent the first night of the trip in a lovely cabin at a nearby campground.
Quaint yes. But unreliable wireless connectivity. And I can't believe I'm the first person to ever ask for an extra mint from the turn-down service.
Secondly, Fulup, Joni, and I were later able to get out on Sampo's boat to spend an incredible day sailing in the Swedish Archipelago.
I am proud to add the Baltic to my 'Bodies of Water into which I've Peed' list.
I spake as a child, I understood as a child ...
I have 3 children, ranging in age from 5 to 11.
With the youngest, I can sometimes get away with the 'Because I Said So' model of parenting.
Me: Clean up your room
5yr: Why?
Me: Because I said so.
Not so for the older ones. They constantly question my authority, and I have to justify my decisions to them.
Me: Clean up your room
11yr: Why?
Me: Because I can't find your little sister.
All this justifying of decisions is tiresome (it would be much simpler if they all just accepted my authority without question like my wife does).
As for tired parents, the 'Because I Say So' model for claimed authority is undeniably easier for an IDP than actually having to justify your decisions and actions. But most RPs, like all children, do grow up eventually.
With the youngest, I can sometimes get away with the 'Because I Said So' model of parenting.
Me: Clean up your room
5yr: Why?
Me: Because I said so.
Not so for the older ones. They constantly question my authority, and I have to justify my decisions to them.
Me: Clean up your room
11yr: Why?
Me: Because I can't find your little sister.
All this justifying of decisions is tiresome (it would be much simpler if they all just accepted my authority without question like my wife does).
As for tired parents, the 'Because I Say So' model for claimed authority is undeniably easier for an IDP than actually having to justify your decisions and actions. But most RPs, like all children, do grow up eventually.
Green identity
I'd like one of these for my identity.
Flip a single switch, and globally turn off identity sharing.
'Reduce, reuse, recycle' is actually a pretty good mantra for identity privacy.
Reduce corresponds nicely to minimal disclosure (i.e. reduce the amount of PII used in any transaction to only that necessary), reuse corresponds to controlled attribute sharing (i.e. reuse identity attributes stored in one network location at other locations/applications).
Not sure what it would mean to recycle identity ....
Flip a single switch, and globally turn off identity sharing.
'Reduce, reuse, recycle' is actually a pretty good mantra for identity privacy.
Reduce corresponds nicely to minimal disclosure (i.e. reduce the amount of PII used in any transaction to only that necessary), reuse corresponds to controlled attribute sharing (i.e. reuse identity attributes stored in one network location at other locations/applications).
Not sure what it would mean to recycle identity ....
SPML lives!
This rebate voucher from Air Canada rewards customers should a flight not support SPML.
Somebody at Air Canada must have been influenced by the powerful SPML lobby.
Somebody at Air Canada must have been influenced by the powerful SPML lobby.
Thursday, July 10, 2008
I resemble that comment
In an admirably succint post, Jeff mocks both OASIS's finances and Liberty Alliance's (seemingly profligate) travel model.
I can't speak to the OASIS barb and, as I'm currently in Stockholm (discussing the agenda for the upcoming Tokyo meeting), will have to defend against the ridiculous Liberty accusation at some later time.
I can't speak to the OASIS barb and, as I'm currently in Stockholm (discussing the agenda for the upcoming Tokyo meeting), will have to defend against the ridiculous Liberty accusation at some later time.
Tuesday, July 08, 2008
Physical metadata (or advertising language capabilities)
I don't disresemble the Swedes - my Danish ancestry (and a likely history of Viking raid-enabled intermarriage) at work. Consequently, it's not unreasonable for a Swede (e.g. a waitress, etc), on assessing my ability to speak their language when they first size me up, to err on the positive side.
In Sweden my actual language abilities do not match my advertised abilities, as expressed by my physical metadata.
This is not the case in Japan. There, my appearance (facial and otherwise) advertises a probable inability to speak Nihongo - which (except for an a freakish skill at asking where Ibiya Street is), is correct.
In Japan, my actual language abilities match my advertised abilities, as expressed by my physical metadata.
In Sweden my actual language abilities do not match my advertised abilities, as expressed by my physical metadata.
This is not the case in Japan. There, my appearance (facial and otherwise) advertises a probable inability to speak Nihongo - which (except for an a freakish skill at asking where Ibiya Street is), is correct. In Japan, my actual language abilities match my advertised abilities, as expressed by my physical metadata.
Friday, July 04, 2008
Happy 4th to the Latitudinally Challenged
A US holiday for working Canadians can be surreal - you get this eerie silence from the lower provinces.
Thursday, July 03, 2008
Tabako no pasupōto
Taspo (tobacco passport) is a Japanese age verification card for the purchase of cigarettes.
As far as I can tell, the cards don't actually indicate the user's age - unless the information on the card passed to the readers doesn't match what is printed externally.
Taspo phones will surely follow.
Smokers without a Taspo card either buy their smokes in person or use a special machine equipped with face-recognition systems.
As far as I can tell, the cards don't actually indicate the user's age - unless the information on the card passed to the readers doesn't match what is printed externally.
Taspo phones will surely follow.
Smokers without a Taspo card either buy their smokes in person or use a special machine equipped with face-recognition systems.
Monday, June 30, 2008
Monkey See
I like how Chi.mp illustrates a 'privacy disclosure continuum'
A nit.
The chi.mp tagline implies to me that, were the user able to 'own' their identity, they'd be able to 'evolve' beyond the current chimp-like reality of Web identity.
Humans are not evolved chimpanzees. We are evolved from a common ancestor with the chimpanzees.
I do grant that 'lastcommonancestorbetweenhumansandachi.mp' is not optimal as a base URI for entering into the OpenID box.
Separately, if I get a chi.mp identity, I'm definitely going to be a Bonobo. - the other type is just so Common. And Bonobos have all the fun.
A nit.
The chi.mp tagline implies to me that, were the user able to 'own' their identity, they'd be able to 'evolve' beyond the current chimp-like reality of Web identity.
Humans are not evolved chimpanzees. We are evolved from a common ancestor with the chimpanzees.
I do grant that 'lastcommonancestorbetweenhumansandachi.mp' is not optimal as a base URI for entering into the OpenID box.
Separately, if I get a chi.mp identity, I'm definitely going to be a Bonobo. - the other type is just so Common. And Bonobos have all the fun.
Sunday, June 29, 2008
Superbad (use case)
Mike is excited (but in a mature age-appropriate way) about IDology's verified age cards.
IDology brags of the endorsement of Wine America.
I'm an underage drinker trying to work out how to get some booze for the weekend party (because I told this cute girl who might like me that I could get some). All my usual sources are dried up - my older brother is out of town, my parents liquor cabinet is locked, and the crazy bearded guy who hangs out at the beer store is in detox. My chances with the cute girl are looking slim.
Then it comes to me, I will buy wine for the party online. Wine has alcohol in it right? (I've seen my father do the Bird Dance countless times at weddings after drinking wine, there must be some). And it comes in different flavours and colours. And there is no way that the online wine store will know I'm underage. Sweet!
So the plan is as follows
1) I go to my chosen online wine retailer (a member of Wine America)
2) I learn that, in order to buy my Cabernet I must be able to prove my age. They provide a convenient link to IDology for the service
3) I create an account at IDology, claiming whatever age is necessary for me to be able to buy the wine
4) IDology asks me lots of tricky questions in order to verify my claimed age. Questions that only somebody of the right age would know - like ''Who was the ugly sister on the Brady Brunch?' (a trick, only Marsha wasn't ugly) and ''Janet Jackson's "wardrobe malfunction" displayed what part of her insecurities?'
5) With the aid of online search engines, I ace the test.
6) IDology gives me a card for the verified age.
7) I present the card to the wine retailer.
8) I place my order (30 bottles of a nice red from South Australia)
9) I wait for my order to arrive
10) 10-14 days later, I get my wine
11) the (disappointingly sober) party long ended, the cute girl ends up with the crazy bearded guy.
Notes:
1) I believe there are lots of real online use cases where verified age is important - but stopping underage drinking isn't one (until such time that bandwidth expands to allow immediate product delivery and thereby creates a channel of interest to teenagers).
2) I have no idea how IDology actually verifies age. I presume they do not use 'general cultural knowledge quizes' (it was always lack of baseball trivia that caught out the prisoner-of-war camp stooges in World War II movies).
3) I expect that somewhere in the IDology card is a claim URI that includes the string 'age:verified'. As I see it, this approach conflates the claim with the 'metaclaim', i.e. as AuthnContext does for SAML, and PAPE does for OpenID - the justification for why an IDP is making a claim should not be part of the claim itself.
IDology brags of the endorsement of Wine America.
“IDology’s age verification solution gives wineries an important, effective and efficient way to instantly confirm someone’s age when making remote wine sales”Let me get this straight.
Bill Nelson, President, WineAmerica
I'm an underage drinker trying to work out how to get some booze for the weekend party (because I told this cute girl who might like me that I could get some). All my usual sources are dried up - my older brother is out of town, my parents liquor cabinet is locked, and the crazy bearded guy who hangs out at the beer store is in detox. My chances with the cute girl are looking slim.
Then it comes to me, I will buy wine for the party online. Wine has alcohol in it right? (I've seen my father do the Bird Dance countless times at weddings after drinking wine, there must be some). And it comes in different flavours and colours. And there is no way that the online wine store will know I'm underage. Sweet!
So the plan is as follows
1) I go to my chosen online wine retailer (a member of Wine America)
2) I learn that, in order to buy my Cabernet I must be able to prove my age. They provide a convenient link to IDology for the service
3) I create an account at IDology, claiming whatever age is necessary for me to be able to buy the wine
4) IDology asks me lots of tricky questions in order to verify my claimed age. Questions that only somebody of the right age would know - like ''Who was the ugly sister on the Brady Brunch?' (a trick, only Marsha wasn't ugly) and ''Janet Jackson's "wardrobe malfunction" displayed what part of her insecurities?'
5) With the aid of online search engines, I ace the test.
6) IDology gives me a card for the verified age.
7) I present the card to the wine retailer.
8) I place my order (30 bottles of a nice red from South Australia)
9) I wait for my order to arrive
10) 10-14 days later, I get my wine
11) the (disappointingly sober) party long ended, the cute girl ends up with the crazy bearded guy.
Notes:
1) I believe there are lots of real online use cases where verified age is important - but stopping underage drinking isn't one (until such time that bandwidth expands to allow immediate product delivery and thereby creates a channel of interest to teenagers).
2) I have no idea how IDology actually verifies age. I presume they do not use 'general cultural knowledge quizes' (it was always lack of baseball trivia that caught out the prisoner-of-war camp stooges in World War II movies).
3) I expect that somewhere in the IDology card is a claim URI that includes the string 'age:verified'. As I see it, this approach conflates the claim with the 'metaclaim', i.e. as AuthnContext does for SAML, and PAPE does for OpenID - the justification for why an IDP is making a claim should not be part of the claim itself.
Saturday, June 28, 2008
So you think you can assert?
I'm pitching an idea for a new reality show to the networks. Working title is 'So you think you can Assert?'.
The idea is that we have a big name RP (TBD, I'm in conversations with some strong candidates but negotiations are still underway) looking for suitable OPs. We do an initial interview where the RP complains about how hard it is to find good OPs, how it's not their specialty to assess security processes, and how they really just want the whole decision made for them, etc (we'll do the interview in a boardroom). We'll have lots of shots of our charming and attractive host making sympathetic faces in close-up, head-nodding etc.
If the RP doesn't feel up to the job of choosing OPs, let's let "The People' TM decide!
For each episode we'll bring in 3 new candidate OPs, who will all pitch why they should be that week's winner. Maybe one uses 2-factor, another a snazzy picture grid, the other has a large user base, etc.
Lots of candid interviews with each OP tearing apart the other 2, e.g. 'Yeah, I know thats how many users they say they have but ask me how many women I've slept with and I might exaggerate too' and 'Well he supports 3-factor if you count his fat ass as two of them '. Juicy stuff.
I see the charming & attractive host asking probing and insightful questions like 'So how about mobile?' and 'Users really want this?' etc. The drama will be great.
Here's the magic. At the end of each episode, we let the viewers decide which OP the RP will add to their whitelist.
Lots of shots of the screaming, happy winner OP, the bitter losers shaking their heads, the RP smiling idiotically, etc
Series ends with the RP being sued for multiple privacy breaches. Shot of RP CEO running after cameraman, etc.
Sure winner. You in or out?
Cat, call me, let's do lunch. The hosting role is perfect for you. So what if you know nothing about security & privacy - it's the viewers that need to understand that stuff.
The idea is that we have a big name RP (TBD, I'm in conversations with some strong candidates but negotiations are still underway) looking for suitable OPs. We do an initial interview where the RP complains about how hard it is to find good OPs, how it's not their specialty to assess security processes, and how they really just want the whole decision made for them, etc (we'll do the interview in a boardroom). We'll have lots of shots of our charming and attractive host making sympathetic faces in close-up, head-nodding etc.
If the RP doesn't feel up to the job of choosing OPs, let's let "The People' TM decide!
For each episode we'll bring in 3 new candidate OPs, who will all pitch why they should be that week's winner. Maybe one uses 2-factor, another a snazzy picture grid, the other has a large user base, etc.
Lots of candid interviews with each OP tearing apart the other 2, e.g. 'Yeah, I know thats how many users they say they have but ask me how many women I've slept with and I might exaggerate too' and 'Well he supports 3-factor if you count his fat ass as two of them '. Juicy stuff.
I see the charming & attractive host asking probing and insightful questions like 'So how about mobile?' and 'Users really want this?' etc. The drama will be great.
Here's the magic. At the end of each episode, we let the viewers decide which OP the RP will add to their whitelist.
If you want RP to accept identity assertions from OP1, text 'OP1'
Lots of shots of the screaming, happy winner OP, the bitter losers shaking their heads, the RP smiling idiotically, etc
Series ends with the RP being sued for multiple privacy breaches. Shot of RP CEO running after cameraman, etc.
Sure winner. You in or out?
Cat, call me, let's do lunch. The hosting role is perfect for you. So what if you know nothing about security & privacy - it's the viewers that need to understand that stuff.
Passive phish prevention policy
Clients have an important role to play in preventing the FPA (federated phish attack), as I discovered.
Separate from any role the client might play for authentication to the OP (and thereby actively prevent a phish), it has a role in passively spotting mismatches between the 'where I think I am going' and the 'where I am actually going'.
But this sort of functionality is invisible to the OP (and has nothing to do with the authentication of the user) so it can't be factored into PAPE (nor easily into SAML AuthnContext).
Were clients to advertise this functionality through some header (a la SAML PAOS advertisement), then the OP could include it in PAPE (with a new URI to distinguish this from the active sort of phish prevention).
Separate from any role the client might play for authentication to the OP (and thereby actively prevent a phish), it has a role in passively spotting mismatches between the 'where I think I am going' and the 'where I am actually going'.
But this sort of functionality is invisible to the OP (and has nothing to do with the authentication of the user) so it can't be factored into PAPE (nor easily into SAML AuthnContext).
Were clients to advertise this functionality through some header (a la SAML PAOS advertisement), then the OP could include it in PAPE (with a new URI to distinguish this from the active sort of phish prevention).
Thursday, June 26, 2008
Click-in?
In the press surrounding the formation of the Infocard Foundation, and on the ICF site itself, the new & improved authentication experience is described as
Two comments:
1) Click-in? is this going to be trademarked for Infocards only? I already 'click in' using Sxipper.
And you know, I never actually presented a 'log' or 'signed' anything before to authenticate. Do we need a new descriptor?
2) all the talk of 'without the need to type in a user name and password' ignores the possibility of the user needing to present a) a PIN to the selector to open the card or b) authenticate to the IDP.
Isn't the real difference 'without the need to give to the RP a user name and password'?
When you go to a website that accepts Information Cards or "I-Cards" you can "click-in" without the need to type in a user name and password.
Two comments:
1) Click-in? is this going to be trademarked for Infocards only? I already 'click in' using Sxipper.
And you know, I never actually presented a 'log' or 'signed' anything before to authenticate. Do we need a new descriptor?
2) all the talk of 'without the need to type in a user name and password' ignores the possibility of the user needing to present a) a PIN to the selector to open the card or b) authenticate to the IDP.
Isn't the real difference 'without the need to give to the RP a user name and password'?
In which I clarify
Often times, in trying to be clever and sarcastic, I dive too deep into the 'satire pool'. The urge to be witty and contrarian surpasses the urge to be clear. Consequently, the 'point' I am trying to make can, on occasion, be buried underneath surface frivolity and snideness.
As happened with my recent post on HealthVault's chosen model for OP acceptance.
With that post, I have confused Kim, and for that I here apologize.
I was responding to a post of Simon Willison, in which he defended HealthVault's right to choose OPs selectively - and not be compelled to accept any ol' OP coming in off the street presenting an identity claim.
My post might have given some the impression that I disagreed with Simon. For instance, I wrote
Admittedly, this set a tone.
But the rest of the post was meant to point out that, while I do think the user has the right to pressure RPs like HealthVault to accept assertions from particular OPs - the appropriate mechanism for this pressure, as for many other interactions between customers and service providers (e.g. buying an OS), is through market forces. If enough users choose an OP because it is secure and privacy-respecting, or because it offers 2-factor authentication, or because it has a snazzy flash UI, the RPs will find it (if they are interested in serving their customer base).
When the RPs do find these candidate OPs (or IDPs, the issue is of course not unique to OpenID) they will themselves do their own checking and assessment before they start accepting assertions. And of course, each RP has to ask the question 'Is this OP appropriate for the resources I protect/manage?'. If the resources are neither privacy sensitive nor valuable, the list of OPs that are appropriate will be longer than for medical or financial information.
HealthVault (actually probably some other audit & risk management group in Microsoft) performed this assessment and, at least initially, came up with 2 OPs that they felt were right for them. More power to 'em. Partner selection is tough and fraught with risk - they are right to be careful.
I smile (more a smirk really) when I hear some in the user-centric world place the sole right and responsibility of choosing an OP on the user's shoulders. User's can't even remember their passwords, and you want them to assess the security infrastructure of an OP?
Surgeon: So, are we ready for your operation tomorrow?
Patient: Hi Doc, yes. But I was just reading about this new surgical instrument for the procedure. I really want you to try it out on me.
Surgeon: Hmmm, I don't know much about it ...
Patient: Oh, you'll work it out as you go
So yes Kim, I agree. Resources, and gall bladders, do have rights.
As happened with my recent post on HealthVault's chosen model for OP acceptance.
With that post, I have confused Kim, and for that I here apologize.
I was responding to a post of Simon Willison, in which he defended HealthVault's right to choose OPs selectively - and not be compelled to accept any ol' OP coming in off the street presenting an identity claim.
My post might have given some the impression that I disagreed with Simon. For instance, I wrote
I disagree
Admittedly, this set a tone.
But the rest of the post was meant to point out that, while I do think the user has the right to pressure RPs like HealthVault to accept assertions from particular OPs - the appropriate mechanism for this pressure, as for many other interactions between customers and service providers (e.g. buying an OS), is through market forces. If enough users choose an OP because it is secure and privacy-respecting, or because it offers 2-factor authentication, or because it has a snazzy flash UI, the RPs will find it (if they are interested in serving their customer base).
When the RPs do find these candidate OPs (or IDPs, the issue is of course not unique to OpenID) they will themselves do their own checking and assessment before they start accepting assertions. And of course, each RP has to ask the question 'Is this OP appropriate for the resources I protect/manage?'. If the resources are neither privacy sensitive nor valuable, the list of OPs that are appropriate will be longer than for medical or financial information.
HealthVault (actually probably some other audit & risk management group in Microsoft) performed this assessment and, at least initially, came up with 2 OPs that they felt were right for them. More power to 'em. Partner selection is tough and fraught with risk - they are right to be careful.
I smile (more a smirk really) when I hear some in the user-centric world place the sole right and responsibility of choosing an OP on the user's shoulders. User's can't even remember their passwords, and you want them to assess the security infrastructure of an OP?
Surgeon: So, are we ready for your operation tomorrow?
Patient: Hi Doc, yes. But I was just reading about this new surgical instrument for the procedure. I really want you to try it out on me.
Surgeon: Hmmm, I don't know much about it ...
Patient: Oh, you'll work it out as you go
So yes Kim, I agree. Resources, and gall bladders, do have rights.
Subscribe to:
Posts (Atom)

