Tuesday, April 25, 2023

Pourquoi les équipes DevOps, sécurité et conformité devraient-elles se soucier les unes des autres ?



C'est pas tant de se soucier les uns des autres mais que de bien collaborer!

Les équipes DevOps, Sécurité et Conformité doivent se soucier les unes des autres car elles jouent toutes un rôle crucial dans la livraison de produits logiciels. Ceci pour qu’elles soient de haute qualité, sécurisées et conformes. En collaborant efficacement, ces équipes peuvent s’assurer que les organisations atteignent leurs objectifs commerciaux tout en atténuant les risques et en respectant les normes réglementaires. Voici quelques raisons pour lesquelles ces équipes devraient travailler en étroite collaboration :

  1. Délai de mise sur le marché plus rapide : Implémenter des pratiques DevOps, telles que l’intégration continue et la livraison continue, aident les organisations à déployer des logiciels plus rapidement et plus efficacement. L’intégration des contrôles de sécurité et de conformité au début du cycle de vie du développement garantit que le code est sécurisé et conforme dès le début, ce qui réduit le besoin de révisions approfondies plus tard.
  2. Amélioration de la sécurité : lorsque la sécurité est intégrée dans le pipeline DevOps, les vulnérabilités peuvent être détectées et résolues plus rapidement, ce qui réduit le risque de violations de données et d’autres incidents de sécurité. Cette approche collaborative, connue sous le nom de DevSecOps, garantit que la sécurité est une responsabilité partagée entre toutes les équipes.
  3. Conformité accrue : La conformité est essentielle pour les organisations qui exercent des activités dans les industries réglementées. En travaillant en étroite collaboration avec les équipes DevOps et Sécurité, les équipes de conformité peuvent s’assurer que les exigences réglementaires sont prises en compte pendant le processus de développement. Cela réduit le risque de non-conformité, de pénalités et de dommages à la réputation de l’organisation.
  4. Réduction des coûts : il est plus rentable de résoudre les problèmes de sécurité et de conformité au début du processus de développement que de les résoudre après un déploiement. En intégrant des contrôles de sécurité et de conformité dans le pipeline DevOps, les organisations peuvent économiser du temps et des ressources.
  5. Meilleure collaboration : Une culture de collaboration entre les équipes DevOps, Sécurité et Conformité favorise des objectifs communs, une meilleure communication et une meilleure compréhension des rôles et responsabilités de chaque équipe. Cet alignement aide les organisations à répondre plus efficacement aux problèmes de sécurité et de conformité, ce qui conduit à des produits logiciels de meilleure qualité.
  6. Confiance accrue : en répondant de manière proactive aux problèmes de sécurité et de conformité, les organisations peuvent établir la confiance avec les clients, les partenaires et les parties prenantes. Cette confiance est essentielle pour maintenir une solide réputation de marque et favoriser des relations d’affaires à long terme.

En résumé, la collaboration entre les équipes DevOps, Sécurité et Conformité est cruciale pour fournir des logiciels sécurisés et de haute qualité qui répondent aux normes réglementaires. En travaillant ensemble, ces équipes peuvent réduire les risques, réduire les coûts et améliorer l’efficacité globale, contribuant ainsi au succès de l’organisation.


Why Should DevOps, Security and Compliance Teams Care About Each Other?


It's not so much that they should care, than they should collaborate!

DevOps, Security, and Compliance teams should care about each other because they all work to deliver high-quality, secure, and compliant software products. By collaborating effectively, these teams can ensure that organizations meet their business goals while mitigating risks and adhering to regulatory standards. Here are some reasons why these teams should work closely together:

  1. Faster time to market: DevOps practices, such as continuous integration and continuous delivery, help organizations to deploy software more quickly and efficiently. Integrating security and compliance checks early in the development lifecycle ensures that the code is secure and compliant from the start, reducing the need for extensive revisions later.
  2. Improved security: When security is built into the DevOps pipeline, vulnerabilities can be detected and resolved more quickly, reducing the potential for data breaches and other security incidents. This collaborative approach, known as DevSecOps, ensures that security is a shared responsibility across all teams.
  3. Enhanced compliance: Compliance is essential for organizations operating in regulated industries. By working closely with DevOps and Security teams, Compliance teams can ensure that regulatory requirements are addressed during the development process. This reduces the risk of non-compliance, penalties, and damage to the organization's reputation.
  4. Reduced costs: Addressing security and compliance issues early in the development process is more cost-effective than fixing them after deployment. By integrating security and compliance checks into the DevOps pipeline, organizations can save time and resources.
  5. Better collaboration: A culture of collaboration between DevOps, Security, and Compliance teams fosters shared goals, improved communication, and a better understanding of each team's roles and responsibilities. This alignment helps organizations to address security and compliance concerns more efficiently, leading to higher quality software products.
  6. Increased trust: By proactively addressing security and compliance concerns, organizations can build trust with customers, partners, and stakeholders. This trust is essential for maintaining a strong brand reputation and fostering long-term business relationships.

In summary, the collaboration between DevOps, Security, and Compliance teams is crucial for delivering secure, high-quality software that meets regulatory standards. By working together, these teams can reduce risks, lower costs, and improve overall efficiency, ultimately contributing to the organization's success.


Friday, September 23, 2022

 You have been hacked.

This isn't a joke. If you have any measure of success in your area of business, this is an eventuality. So you might as well prepare for it.

The following steps you take will probably set you in front of many. Don't be the "low hanging fruit". Cybercriminals always target big and easy game first.

And for those interested, you are just as likely to have been cracked than hacked. We'll make that a subject of later blog.

HOW?

But is there an even better way to address this? Yes. Re-read the title. Assume you have already been compromised or that you will be any minute. 

DevSecOps

Like it's older cousin (DevOps), SecDevOps is a collection of good practices to make sure you improve your operational security, from the conception to the everyday operations. Look it up. Learn and embrace it.
There is no single best and official DevSecOps Methodology. You must learn what is best for you.




But allow me to point out a few caveats:
  1. Just like with DevOps, be very certain that DevSecOps isn't a role.

    We don't want to insert yet another constraint, a super specialist or "guru" that can become an operational bottleneck or a single point of failure in our operational chain.

    Make it a process to improve your systems. Leverage the knowledge and technology you have and make it an ongoing and continuous learning and teaching experience.
    Your people, processes and technology are your best assets. Harmonize their use and you will always do better. 

  2. Be weary of people pretending to be the authority on the subject.

    And this my seem a bit contradictory. Since I myself am the "Chief of DevOps and SecDevOps practices" at my company. But note that I head the practices in my organisation. I help establish best practices and teach them, I coach teams and organisations on how to improve.

    But here isn't a singular "best way" to set up these practices. It just so happens that I've made a career of making my clients endeavors success stories. 

    But be sure that I am not the begin all and more importantly the end all of either practices (DevOps or SecDevOps) in my company.

    It is imperative that I make sure each team or project is autonomous and able to run their processes independently. If I get hit by a bus tomorrow. Business will continue and what knowledge I have used, is still readily available.
By the way. If you implement either of those practices and you are dependant on the knowledge and expertise, day after day, of a few key individuals, you might as well consider that you are suffering from a "soft fail" and that brings us to the next point. (and subject for a later blog)

Zero Trust

The basis of this proposition is simple but not necessarily easy to manage. We can look at it as a 5 pronged practice:

Your barriers are porous:

The basis of any system, of even a simple secure "box" with a lock and key, is that there must be a way to access it's contents, for it to be operational. I mean, who wants a box that can't be opened?

So assume people will open it, that's normal. Assume that the lock and key is insufficient to protect your sensitive stuff. So, as good as is any firewall, it was meant to be penetrated be someone. And once someone is inside, who is to say things are going to go as expected? So, assume that your barriers have failed, but lets make that failure a bit easier to mitigate.

(That's what I call a "soft fail". One that won't necessarily lead to a disaster, because of the following approach)




As simply as I can put it.
The prongs:

Identify

Ensure that in the design of your applications, you continuously and at every step you validate the identity of the person using the system. This is critical in order to maintain the rest of the security of the system. What is someone manages to steal your credentials? That's why we have more prongs.  
And don't just use the "who" to identify, use that "where" and "when". So again, assume identity has been usurped.

Authorize

Perhaps this is a bit of a misnomer: maybe I should say restrict access. Authorize only what is minimally necessary for the identity previously given. Be sure you don't have any "super users" or "super admins" with accounts that are always useable in your production environments. Make sure that any of these "highly privileged" accounts are disabled or expire after their intended use. So, a normal user or a stolen identity can't do too much damage. So now assume that the "penetrated box", has been accessed with an identity that CAN use the system.

Analyze

Use signals to detect unusual activity. Use the who, what, when and where previously locked in. First record all activity. Second, leverage your technology to analyze and discover (Machine Learning?) the patterns of usage that may be "unusual". Define policies of usage that are expected, and when usage becomes different than what you expected use some measures or metrics to calculate a threshold that defines usage is abnormal. Again, assuming someone is in the system and deleting/obfuscating all kinds of data, be sure you know exactly what was being done. Best way to reverse/mitigate the damage later.

Alert

Be sure to have probes that allow you to be alerted when unusual activity happens. Be informed as quickly as possible about breaches, stolen identities and unusual activity. This already part of common practices but tie it in with our previous prongs. And adapt the probes when you add new features to secure your application.

Automate

I cannot overstate this. Automation may very well be what saves you business in case of a serious breach.

I myself have been hacked some time ago. Someone managed to break in and access my stuff because of a notorious problem with Microsoft's remote desktop protocol. They encrypted all my network shares. Locking me out of terabytes of data.

But because I had automation in place, I managed to delete all corrupted/encrypted data and simply replace it with a known good copy.

Now, the admin account on my windows box can't access shares, and when he logs on, I get a notification on my phone. So, when I tell you these things, I speak of experience, not as a "some kind of guru/know it all".

But where you can benefit from my professional expertise, is rather in the first aspect. How to include this in your day-to-day designs and operations.

Good automation makes systems resilient.

In conclusion

We know nothing is perfect. But behaving as such is a bit more counterintuitive. If you start thinking and designing things in your system not only to resist failure, but to cope with eventual ones.

Make improving your systems with proper security practices as much part of it's initial design as it's daily use.

And you may very well manage to avoid a catastrophe.

Friday, April 22, 2022

The DevSecops Manifesto / Le Manifesto DevSecOps

We have agreed and hold these ideals as our own:

We strive to do the right thing at the right time. And the wrong ones too.

We want to improve: our work, our customer satisfaction and indeed our lives.
We live by the ideal of: work smarter and not harder
We are collectively responsible for our success. Which means we are collectively responsible for everything.
We do not need unanimity to have an agreement. We seek a consensus, but not at all costs.
It is better to make steady slow progress than being late for the sake of perfection.
_____________________________________________
 
There is no point in blame for failure. Failure is expected and it is part of the process.
We put safeguards that so that each step taken is a step forward. Measured and secured.
We agree that we must find an or some objective metrics to measure our success.
The determination of these measures will be ours but also accepted by our customers or representatives.
We think that transparency and visibility of our progress, are necessary allies.
 
_____________________________________________
 
We are slave to constraints and cannot and will not encourage bottlenecks
We try to understand our coworkers as best we can, roles, ambitions, expertise and all.
We design our work and processes to avoid single points of failure.
We believe that security is quality and there is no quality without security.
We accept that security is everybody's responsibility as we are responsible for everything.
 
_____________________________________________
 
This is our guide, this is our convention. If these ideals change it will be because we agree.

 

 
Nous avons convenu que nous tenons à ces idéaux comme étant les nôtres:

Nous avons la volonté de faire les bonnes choses au bon moment. Les mauvaises aussi.

Nous voulons nous améliorer: notre travail, la satisfaction de nos clients et en effet nos vies.

Nous croyons que bien travailler ne veut pas dire travailler plus.

Nous sommes tous responsables de notre succès. Ce qui veut aussi dire que nous sommes tous responsable de l'ensemble de notre œuvre.

Nous n'avons pas besoin de l'unanimité pour arriver à un accord. Nous désirons un consensus, mais pas à tout prix.

Il es plus important d'avancer un peu assurément, que de tarder pour le bénéfice de la perfection.

 

_____________________________________________

 

Il ne vaut rien de blâmer. L'échec fait partie du processus et est prévu.

Nous sécurisons nos processus pour qu'ils soient robustes et adoptés en fonction du progrès mesuré.

À cette fin nous convenons d'être mesurés de façon objective et quantitative.

Les métriques qui nous mesurent seront personnalisés à nous, mais acceptés par nos clients ou représentants.

La transparence et la visibilité de notre progrès, sont des alliés indispensables.

 

_____________________________________________

 

Nous sommes tous esclaves des contraintes. Nous ne sommes ni tenus ou n'encourageons pas de forcer une limite contraignante.

Nous voulons bien comprendre nos collègues, leur rôles, leurs ambitions, leurs expertises et tout.

Notre travail et nos processus sont réfléchis afin d'éviter les points de défaillance uniques.

Il n'y a pas de qualité sans la sécurité. Un produit de qualité a, la sécurité à sa base.

Nous sommes tous responsable de la sécurité. Étant dit préalablement que nous étions tous responsable de tout.

 

_____________________________________________

 

Ceci est notre guide et notre convention. Si ces idéaux changent, ils l'auront fait par accord commun.


Wednesday, September 22, 2021

 Ebike Conversion

These days, there are kits that you can purchase that will convert your normal bike, into a battery powered one.

DIY in 4 main parts.

Obviously there will be things needed to added to your bike to make it go and it's broken down in a few key parts. Each with it's interests and caveats. (circled in the picture below).
Essentially one should have the right tools to grind and file part into place.

There was no accompanying manual to install and understand the parts. I had to go online. And the supplier's website wasn't up to date. So I had to figure some of it out with a different model. But the videos on their YouTube channel break down the installation in fairly simple bits that are easy to reverse engineer with your specific setup.

If it's your fist time setting this up, expect half a days work




Controls

Handle bars and pedal crank/main post

Most of the controls are set on the handle bars and in complete kits such as the one I got (ebikebc.com) they come with a main control and power switch (left) a screen and a throttle thumb controller (right).

The throttle can be used to spontaneously accelerate or simply control the speed, if you are using the bike in full electric mode. Otherwise, the left buttons allow you to choose modes where you must pedal and the motor assists you in moving you forward. 

Using pedal assisted drive is the one that will give you the most mileage with your battery. A little effort goes a long way in this case. You can easily quadruple your range, depending how much your pedaling is part of the effort. The particular controller that I use allows 5 different levels of "assistance". 

Level 1, is mostly you putting the effort in making the bike go forward, 5, the least. To be fair, on level five, I can easily make the bike go upwards of 35 KM per hour. After which, I cant keep up with the pedals. So the effort is very low.

And as you can see on the pedal crankshaft, I added the included disk with little magnets as well as a little sensor (arrow), that detects the rate at which you pedal.

Lastly there are magnets and detectors that optionally go on your brake levers. (currently not installed)
These detect and cut off power to the motor instantly if the brakes are applied.

Caveats
Depending on your configuration, you may find it difficult to position the brake detectors and magnets.
I recommend having some epoxy glue on hand to be able to make adjustments or hacking the installation to fit your bike's needs.

Motor/Wheel


Arguably the simplest part of the setup. Just switch wheels with your front one and fit your tire on it (they make back ones too, but I cant make a very good argument for their use).
Then you use the built in cable and plug it in the controller box (intelligence)

Caveats: Size:
The motor is pretty wide. And if you have a fat or re-enforced front fork, the motor my not fit or it may rub on your fork.
Also, the bolt/shaft is pretty thick. On my European sized bike I had to file open my apertures to make it fit. 

And then there is the circumference of the wheel itself.
Ideally you would want to get a wheel, the same size than the one you had, otherwise you will need to also get a new tire and a new tube to fit on the rim/motor that comes with the kit.

But there are good reasons why you may consider changing sizes. Smaller wheels will allow for more torque and taller wheels less friction. In any case, the kit is calibrated so that no matter the wheel size you use, it will be limited to 42 km/h (I tested it). However, if you know how speed is calculated, adjusting the computer's expected wheel size can possibly work around this... use at your own risk.

I got a smaller one to get better traction and torque.

Intelligence


It's basically a metallic box with a bunch of wires (connectors to be precise) and everything color coded. You can't really connect things that don't belong together with a kit. There is some effort required to fit the controller box in the included pouch, such as cutting it to pass the wires outside of the pouch and the actual pouch "attachment" to the underseat, needed to be filed, "dremmeled" to fit the intended part.

Caveats
One size fits all seat mounting bracket. You may need to file/adjust it. And you may need extra zip-ties (there a nice bunch that came with the kit) for cable management. Extra tools may be required.

Power

The battery. 

Say goodbye to your water bottle. Because this part assumes that this is where you will attach the battery holder. But you could also use a backwheel cargo rack. (you can still use side pouches like I have, for cargo).  Or you can boost the height of the rack to fit the battery underneath!

Caveats: Cost and wear
Batteries wear out after so many uses. And their size, pretty much dictate their cost. And the size also dictates the range you will get, per ride. So decide carefully on the one you get. And in a kit, there isn't much of a concern, but for a DIY project, expected voltage between motor and battery is critical. In the brochure they say that my current setup should get me around 70 km, for my weight (~80 kg) and at 120 kg, that goes down to 30 km. That remains to be tested. Exhausting a battery on a given trip is tricky because you have to be able to complete your trip somehow to recharge. 

Since you can still use the bike as a normal bike, that issue is somewhat mitigated. But the added weight from the battery, motor and controller will make the effort more challenging. So consider this before you decide to test this on your own. 

Conclusion

Well that's it. A setup such as mine will set you back about 1500$ Canadian and take about a week to deliver. The box it was included it was from china, but the ebikebc.com people would like you to think of them as a Canadian manufacturer. But in fact, they provide packaged parts that are compatible and support. They take the guesswork out of the equation. Which in my case I found acceptable. 

You can get well rated and cheaper solutions if you are more experienced. And even entire basic ready made ebikes, for what I paid. But for the tinkerer in you or if your current bike just needs a little more "Umph", give this a try.

P.S. Get a helmet! 
At 25 MPH/40 KMPH your head is no much stronger than a watermelon and will burst open like one, if you hit something head on. Be safe!!!!

Saturday, March 19, 2016

Beer blog update

So I was in Japan (Beer and other alcoholic beverages)

And I didn't have much time to try many things, but here is a quick rundown of what I had and how I liked them. (in order of appearance) 

Asahi

This is probably one of the most popular and well known beers from Japan. Readily available throughout the north American markets, it's a comfort beer. One that is rather so close to mainstay local beers that you could easily adopt it. Thus it can readily go with all the things you already know and love or might help you through something you are trying for the first time.

Not great, but clean and consistent. If you haven't tried it, it won't surprise much. If you like Pilsners, this is for you.

Strong

This, is not a beer per sé. And is actually known as a "Chuhai" which is is an abbreviation for Shochu Highball and originally a mixed drink of Shochu (and I must insist, NOT MALT LIQUOR) with soda and lemon juice. It became very popular as a canned alcoholic beverage with many different flavors of fruits and teas. Chuhai also is served at many Izakaya restaurants. The alcohol for the canned version is around 9% whereas it depends on the individual mix of alcohol and soda for each restaurant.

It is quite clear what is appealing about these drinks. They have a very clean taste and are very refreshing. They also get you drunk in no time flat.



Sapporo

Arguably the second most popular beer and certainly one of the most common, it is also a very classic beer. Marketing itself as Japan's oldest brand it has does have the qualities of a beer that has staying power. It is very well balanced and it's malty flavour is distinctive.
Technically a pale lager, it goes great with almost any food and fantastic with fried food.

It is no wonder why it has been around in Japan for so long.





Asahi Black

The dark or "stoutish" version of their recipe. It seems to me that it features a bit more roasting in the grains and perhaps a bit more time of fermentation. Still it's a nice representation. Perhaps a bit more "flavor robustness" than actual alcoholic content increase. But really not a great change, despite the much darker colour,  a mild change to the essential flavour. One thing I can tell you, is that you can be sure that it has retained all the refreshingness and drinkability of it's more pale cousin. So it seems that for once, you can trust the advertising. It just has a bit more punch per gulp, so to speak.




Sapporo "the gold"

So it would seem our friends at Sapporo have joined the worldwide madness of having some kind of wheat beer. Don't get me wrong, it is a madness I embrace whole heartedly.  But I just wonder sometimes where it comes from and where it leads to next. With that said, like most wheat beer it adds another layer to the flavour. Robustness, to be sure, but not in a heavy and filling way. There's something also aesthetic about a beer that is naturally cloudy. (most beers should be this way, but seldom afford to do so) I found it personally appealing and I also was pleased with the offering. "Regular" Sapporo, leaves me somewhat on my appetite and this comes in and fills the gap. More body but again not easily saturating. I guess what I am trying to say, is that you can have multiple glasses without feeling like you have to change.




Yebisu Beer

I really wish I could say more about these fine offerings. But that is simply due to the fact that this area of Japan is named after the beer (and not the other way around). As a matter of course, it means that there is a whole palate of beers that hold this name. Yes, so little time and so many beers, Well this single prefecture of Japan has a lot to offer in that way. I had the "time" to try the Dark and Pilsner and they did non disappoint. Though I would have wished I could dissect their distinctiveness more, all I can say with safety is you should easily find one to your taste. They are without a doubt a whole a series of high quality beers, because both of the ones I tried were excellent in their own genres and as beers. The only complaint I have is that the glasses they were served in had so much head, that it took room that could be occupied by more beer. Yum factor pretty much guaranteed.








Suntory the "PREMIUM MALTS"


Get ready folks, because you are going to read the worlds you never thought you'd see: I didn't like it.
The flavour inspired a headache. It was a rather filling taste and felt thick in mouth. As much as I tried, I could not get over these factors to find any more appeal to it. Suntory makes a whole slew of consumable products and alcoholic beverages. I guess they prove what happens when you try to be a "Jack of all trades". Considering it sat along other beverages, that I did appreciate, one has to presume it will fit some peoples' taste, but just not mine. Actually with a bit of after-thought it came on strong, like some malt liquors but without the full alcohol punch associated with them. I guess I just don't get it.




Asahi Super Dry, Super cold.


I've seen elsewhere really bad reviews for this beer, but I loved it. I have to confess it had a bit of a sweet finish but not enough to have a "sickly" effect. And since it was served so cold, I was very tempted to chug it. (I like beer induced, near ice cream headaches) I went down fast and easy. So I can speak for no one but myself to say I really loved it and it is lovable. I believe I had a sandwich with it (BLT?) and just needed to have another. Perhaps it was my impending end-of trip (I had this at the airport) but, like the tin man, I believe this is the one I will miss most. So that is to say, if the opportunity for you, arises, get completely smashed on it. And I will be jealous. (but really you should drink responsibly)







Well that's it for my beer blog on Japan. There are many more brands and flavours to discover, notably Shirohonoka, Edelpils and Ginza Lion. I just ran out of time to try and/or appreciate them enough. But keep in mind just about all of these were enjoyed with meals (sometimes copious) which would surely be for a different post. I have hopes that the opportunity will present itself, for me to be able to share some feedback on other offerings someday.
So in the spirit of the place, Aligato for reading my post and Sayonara!





Thursday, February 4, 2016

What is the TPP and why you should care.

So yeah, what is the TPP?

It is the Trans‑Pacific Partnership (TPP) Agreement.
Click on the link to read the whole shebang. But if I may boil it down to you, it is essentially an infrastructure for business and merchants to write law directly.

In it, they decide what is legal and illegal to do, in the name of business. And this on an international scale.

Think of it. It locks your country into agreements that may not be in your best interest, but in the best interest of business. And they will have a court, outside of civil and criminal law, that decides what is or isn't legal. Effectively, criminalizing certain activities that are "bad for business" even if it is unconstitutional to do so. Democracy for sale, if you will.

Did you know that downloading and copying MP3s on a CD isn't illegal in Canada? It isn't. There is a levy paid on each purchase of blank CDs to compensate the artists. That's what Canada had decided was the best solution to sidestep the problem. hat was our law.

Under the TPP, your would be judged a criminal. And Canada has no say in it. Indeed, the trade agreement "trades" some sovereignty on laws, for commercial benefit of multinationals.

I'm not a law student, but this seems like a very dangerous precedent.

Of course, I'm a tech head, so I used the blank CD issue, but until you've gone through the whole thing, you may or not be affected in your daily lives without knowing it!

Here's another example.

Under the new trade rules, grocery stores would no longer be allowed to indicate the country of origin from beef.

If it has the potential to undermine a participant country's profits, you are not allowed to do it, pursuant that the product is under the trade agreement. And a "new" international commercial court will decide if it does or not violate the trade agreement. Effectively removing your democratic right to say that it this is or not in your best interest to do so.

I urge you to to join Open Media's campaign to stop this. Follow this link and "sign" the petition to stop this now before it's ratified.  https://act.openmedia.org/finalbattle

And without "harassing" your friends like I do, talk to them about this treaty that will affect us all.

Thank you!

A response to Michelle Rempel Garner's "Debunking Critics of Maduro's Arrest"

Debunking the Debunk. RE: Member of Parliament for Calgary Nose Hill. King's Privy Council. Shadow Minister for Immigratio...