GNU is Not Unix

How the FSF Runs Using Nothing But Freedom-Respecting BIOS (fsf.org) 54

A senior systems administrator at the Free Software Foundation points out that they're running free software in two data centers and over a hundred virtual machine — each and every one with "a freedom-respecting BIOS."

But the "how" is surprisingly intricate: [E]arlier this week, we replaced "Columbia", the last of any FSF-run machines running a nonfree BIOS....

At FSF, our current standard is ASUS KGPE-D16 motherboards with AMD CPUs 6200 series CPUs released in 2012. For the BIOS, we install Libreboot, the easy-to-install, 100% free software replacement for proprietary BIOS/boot programs, or a version of Coreboot that is carefully built to avoid including any nonfree blobs. They are fast enough for our needs, and we expect this to be the case for many more years to come. They are also very affordable systems. We are also working toward supporting Raptor Computer Systems' newer and more powerful Talos II, as well as Blackbird motherboards that use IBM POWER9 CPUs. The POWER9 CPU architecture is called "PowerPC 64-bit little endian," abbreviated "ppc64el...." The Raptor motherboards come with entirely free firmware — and even have free hardware designs!

However, this type of migration has its challenges. For example, the first thing we needed to address before using these motherboards is that the main operating system we use, Trisquel GNU/Linux, didn't previously run on pp64el. So, earlier this year, we set up a Raptor POWER9 computer running Debian (without using any nonfree parts of Debian repositories) and loaned it to the maintainers of Trisquel for as long as needed. And now, we are proud to say that the upcoming Trisquel 11 release will support POWER9...!

Before I decommissioned Columbia, I ran a dmidecode, which told me that the BIOS program fit within a single megabyte of space. Often, very simplistic firmware becomes more complicated in later models, and that also usually means it has a growing significance for a user's software freedom. Some newer nonfree BIOSes have grown into operating systems in their own right, sometimes with large programs such as a full Web browser.

There is no fully-free BIOS available for x86 Intel and AMD CPUs released after about 2013. The key blocking factor is that those CPUs require certain firmware in the BIOS, like Intel Management Engine. Those CPUs will also refuse to run firmware that hasn't been cryptographically signed by private keys controlled by AMD and Intel, and AMD and Intel will only sign their own nonfree firmware. At the FSF, we refuse to run that nonfree firmware, and we applaud the many people who also avoid it. For those people who do run those Intel or AMD systems, running Coreboot or Osboot is still a step up the Freedom Ladder for the software freedom of your BIOS.

The road to freedom is a long road. We hope our dedication to achieve milestones like these can inspire the free software movement.

United States

Amazon's Prime Air Drones Will Soon Make Deliveries In Texas (engadget.com) 52

Amazon says it will start contacting customers in College Station, Texas, to gauge their interest in receiving orders via Prime Air. Engadget reports: Amazon says it was impressed by many elements of the city, including the research being conducted by Texas A&M University, such as work on drone technology. The US Census Bureau estimates the population of College Station was 120,000 as of last July, so while it isn't the biggest city around, it seems like a decent size for the initially rollout of Prime Air.

"Amazon's new facility presents a tremendous opportunity for College Station to be at the forefront of the development of drone delivery technology," Karl Mooney, the mayor of College Station, said. "We look forward to partnering with Amazon and Texas A&M and are confident that Amazon will be a productive, conscientious, and accountable participant in our community."

Privacy

A New Attack Can Unmask Anonymous Users On Any Major Browser (wired.com) 58

An anonymous reader quotes a report from Wired: [R]esearchers from the New Jersey Institute of Technology are warning this week about a novel technique attackers could use to de-anonymize website visitors and potentially connect the dots on many components of targets' digital lives. The findings (PDF), which NJIT researchers will present at the Usenix Security Symposium in Boston next month, show how an attacker who tricks someone into loading a malicious website can determine whether that visitor controls a particular public identifier, like an email address or social media account, thus linking the visitor to a piece of potentially personal data.

When you visit a website, the page can capture your IP address, but this doesn't necessarily give the site owner enough information to individually identify you. Instead, the hack analyzes subtle features of a potential target's browser activity to determine whether they are logged into an account for an array of services, from YouTube and Dropbox to Twitter, Facebook, TikTok, and more. Plus the attacks work against every major browser, including the anonymity-focused Tor Browser. "If you're an average internet user, you may not think too much about your privacy when you visit a random website," says Reza Curtmola, one of the study authors and a computer science professor at NJIT. "But there are certain categories of internet users who may be more significantly impacted by this, like people who organize and participate in political protest, journalists, and people who network with fellow members of their minority group. And what makes these types of attacks dangerous is they're very stealthy. You just visit the website and you have no idea that you've been exposed."

How this de-anonymization attack works is difficult to explain but relatively easy to grasp once you have the gist. Someone carrying out the attack needs a few things to get started: a website they control, a list of accounts tied to people they want to identify as having visited that site, and content posted to the platforms of the accounts on their target list that either allows the targeted accounts to view that content or blocks them from viewing it -- the attack works both ways. Next, the attacker embeds the aforementioned content on the malicious website. Then they wait to see who clicks. If anyone on the targeted list visits the site, the attackers will know who they are by analyzing which users can (or cannot) view the embedded content. [...] Complicated as it may sound, the researchers warn that it would be simple to carry out once attackers have done the prep work. It would only take a couple of seconds to potentially unmask each visitor to the malicious site -- and it would be virtually impossible for an unsuspecting user to detect the hack. The researchers developed a browser extension that can thwart such attacks, and it is available for Chrome and Firefox. But they note that it may impact performance and isn't available for all browsers.

Social Networks

TikTok's Head of Cybersecurity Is Stepping Down Amid Rising Privacy Concerns (businessinsider.com) 10

TikTok's chief security officer is leaving the role in September amid renewed calls from members of the government to look into the social media app's ties to China. Insider reports: A TikTok spokesperson told the Wall Street Journal that the decision to replace Roland Cloutier as Chief Security Officer is unrelated to any data-privacy concerns. TikTok, which is currently the fastest growing social media company, has often faced scrutiny for being owned by the Chinese company ByteDance. Last month, Buzzfeed News reported that US user data had been repeatedly accessed by TikTok employees in China based on leaked audio from internal company meetings. [...]

CEO Shou Zi Chew sent a note to TikTok employees about Cloutier's exit as chief security officer, writing that "part of our evolving approach has been to minimize concerns about the security of user data in the U.S., including the creation of a new department to manage U.S. user data for TikTok. This is an important investment in our data protection practices, and it also changes the scope of the Global CSO role." Cloutier will officially step down from his role as Chief Security Officer in September and transition to an advisory role at TikTok.

Censorship

Tor Browser Now Bypasses Internet Censorship Automatically (bleepingcomputer.com) 18

An anonymous reader quotes a report from BleepingComputer: The Tor Project team has announced the release of Tor Browser 11.5, a major release that brings new features to help users fight censorship easier. [...] The updates in Tor Browser 11.5 focus on circumventing censorship, a process that started a year ago in version 10.5 with improving the Tor connection experience. In the new version, users no longer have to manually try out bridge configurations to unblock Tor.

Tor Browser version 11.5 comes with a new feature called "Connection Assist," which assigns automatically the bridge configuration known to work best for the user's location. "Connection Assist works by looking up and downloading an up-to-date list of country-specific options to try using your location (with your consent)," explains the release announcement. "It manages to do so without needing to connect to the Tor Network first by utilizing moat – the same domain-fronting tool that Tor Browser uses to request a bridge from torproject.org." Since Connection Assist is still in an early stage of development (v1.0), the Tor team welcomes user feedback and reports, which would help them iron out any kinks and improve on the system.

Another important new feature in version 11.5 is making 'HTTPS-Only Mode' the default browsing mode, so that the connection is through a secure tunnel. This ensures that all data exchange between the user and the server hosting the website will be encrypted, to defend against man-in-the-middle (MitM) attacks and to protect users from SSL stripping on malicious exit relays. [...] The third significant improvement in Tor Browser 11.5 is a heavily revamped Network Settings menu, now called "Connection Settings," which should make it easier to find and understand specific settings. Most notably, bridge configuration and connection options have been redesigned to enable quick and easy review and management. Using emojis on the saved Bridges, the new interface offers visualization for the configuration for the first time, making it easy to identify the right bridge and select it when needed.
You can download the latest Tor Browser from the official download portal.
The Internet

FCC Chair Proposes Raising Broadband Standard To 100Mbps (engadget.com) 76

Chairwoman Jessica Rosenworcel has proposed raising the minimum definition of broadband to 100Mbps for downloads and 20Mbps for uploads. Engadget reports: The previous 25/3 benchmark is both outdated and hides just how many low-income and rural internet users are being "left behind and left offline," Rosenworcel said. The chair said multiple pieces of evidence supported the hike, including requirements for new network construction stemming from the Infrastructure Investment and Jobs Act. The FCC had already proposed upgrades to rural speeds through a special program, but this would affect the definition of broadband regardless of where users live in the country.

Rosenworcel also wanted the minimum speed to evolve over time. She proposed setting a much higher standard of 1Gbps down and 500Mbps up for some point in the future. The leader further suggested more criteria for determining the "reasonable and timely" rollout of broadband, including adoption rates, affordability, availability and equitable access.

Android

Google Play Hides App Permissions In Favor of Developer-Written Descriptions (arstechnica.com) 33

An anonymous reader quotes a report from Ars Technica: Google's developer deadline for the Play Store's new "Data Safety" section is next week (July 20), and we're starting to see what the future of Google Play privacy will look like. The actual Data Safety section started rolling out in April, but now that the developer deadline is approaching... Google is turning off the separate "app permissions" section? That doesn't sound like a great move for privacy at all.

The Play Store's new Data Safety section is Google's answer to a similar feature in iOS 14, which displays a list of developer-provided privacy considerations, like what data an app collects, how that data is stored, and who the data is shared with. At first blush, the Data Safety entries might seem pretty similar to the old list of app permissions. You get items like "location," and in some ways, it's better than a plain list of permissions since developers can explain how and why each bit of data is collected.

The difference is in how that data ends up in Google's system. The old list of app permissions was guaranteed to be factual because it was built by Google, automatically, by scanning the app. The Data Safety system, meanwhile, runs on the honor system. Here's Google's explanation to developers of how the new section works: "You alone are responsible for making complete and accurate declarations in your app's store listing on Google Play. Google Play reviews apps across all policy requirements; however, we cannot make determinations on behalf of the developers of how they handle user data. Only you possess all the information required to complete the Data safety form. When Google becomes aware of a discrepancy between your app behavior and your declaration, we may take appropriate action, including enforcement action."

United Kingdom

UK Lawmakers Tell Visa and Mastercard To Justify Fee Rises (reuters.com) 59

A committee in Britain's parliament has told payment firms Visa and Mastercard to justify recent rises in their card transaction fees after the country's payments regulator expressed concerns. From a report: The Payment Systems Regulator (PSR) told the Treasury Committee last week that the increases in card fees showed the market was "not working well", according to correspondence published by the committee on Thursday.
Technology

Working All Day in VR Does Not Increase Productivity, Comfort or Wellbeing, Study Says (inavateonthenet.net) 83

A new study from Germany has found that working in virtual reality does not increase productivity, comfort, or wellbeing, but does say the report will help identify opportunities for improving the experience of working in VR in the future. From a report: The project was headed by Dr Jens Grubert, a specialist in human-computer interaction at Coburg University, Germany. It involved 16 people who had to work for five days, eight hours a week (with 45 mins lunch break), in VR. The participants used Meta Quest 2 VR headsets combined with a Logitech K830 keyboard and Chrome Remote Desktop. The equipment was chosen specifically to create a realistic scenario of what users would be using in today's world.

Participants were also asked specific VR-related questions ('do you feel sick?' or 'are your eyes starting to hurt?'). The research team also monitored the worker's heartbeats and typing speed. The published paper, entitled 'Quantifying the Effects of Working in VR for One Week' found "concerning levels of simulator sickness, below average usability ratings and two participants dropped out on the first day using VR, due to migraine, nausea and anxiety." The study found that, as expected, VR results in significantly worse ratings across most measures. Each test subject scored their VR working experience versus working in a physical environment, many felt their task load had increased, on average by 35%. Frustration was by 42%, the 'negative affect' was up 11%, and anxiety rose by 19%. Mental wellbeing decreased by 20%., eye strain rose 48%, and VR ranked 36% lower on usability. Participants' self-rated workflow went down by 14% and their perceived productivity dropped by 16%.

Businesses

Cryptocurrency Flowing Into 'Mixers' Hits an All-Time High (arstechnica.com) 55

The amount of cryptocurrency flowing into privacy-enhancing mixer services has reached an all-time high this year as funds from wallets belonging to government-sanctioned groups and criminal activity almost doubled, researchers reported on Thursday. ArsTechnica: Mixers, also known as tumblers, obfuscate cryptocurrency transactions by creating a disconnect between the funds a user deposits and the funds the user withdraws. To do this, mixers pool funds deposited by large numbers of users and randomly mix them. Each user can withdraw the entire amount deposited, minus a cut for the mixer, but because the coins come from this jumbled pool, it's harder for blockchain investigators to track precisely where the money went. Some mixers provide additional obfuscation by allowing users to withdraw funds in differing amounts sent to different wallet addresses. Others try to conceal the mixing activity altogether by changing the fee on each transaction or varying the type of deposit address used. Mixer use isn't automatically illegal or unethical. [...].

"Mixers present a difficult question to regulators and members of the cryptocurrency community," researchers from cryptocurrency analysis firm Chainalysis wrote in a report that linked the surge to increased volumes deposited by sanctioned and criminal groups. "Virtually everyone would acknowledge that financial privacy is valuable, and that in a vacuum, there's no reason services like mixers shouldn't be able to provide it. However, the data shows that mixers currently pose a significant money laundering risk, with 25 percent of funds coming from illicit addresses, and that cybercriminals associated with hostile governments are taking advantage." Cryptocurrency received by these mixers fluctuates significantly from day to day, so researchers find it more useful to use longer-term measures. The 30-day moving average of funds received by mixers hit $51.8 million in mid-April, an all-time high, Chainalysis reported. The high-water mark represented almost double the incoming volumes at the same point last year. What's more, illicit wallet addresses accounted for 23 percent of funds sent to mixers this year, up from 12 percent in 2021.

Microsoft

Dissecting Microsoft's Proposed Policy To Ban Commercial Open-Source Apps (techcrunch.com) 51

Microsoft caused considerable consternation in the open source community over the past month, after unveiling a shake up to the way developers will be able to monetize open source software. From a report: There are many examples of open source software sold in Microsoft's app store as full-featured commercial applications, ranging from video editing software such as Shotcut, to FTP clients such as WinSCP. But given how easy it is for anyone to reappropriate and repackage open source software as a new standalone product, it appears that Microsoft is trying to put measures in place to prevent such "copycat" imitations from capitalizing on the hard work of the open source community.

However, at the crux of the issue was the specific wording of Microsoft's new policy, with section 10.8.7 noting that developers must not: ...attempt to profit from open-source or other software that is otherwise generally available for free, nor be priced irrationally high relative to the features and functionality provided by your product. In its current form, the language is seemingly preventing anyone -- including the project owners and maintainers -- from charging for their work. Moreover, some have argued that it could hold implications for proprietary applications that include open source components with certain licenses, while others have noted that developers may be deterred from making their software available under an open source license.

The Military

DARPA Is Worried About How Well Open-Source Code Can Be Trusted (technologyreview.com) 85

An anonymous reader quotes a report from MIT Technology Review: "People are realizing now: wait a minute, literally everything we do is underpinned by Linux," says Dave Aitel, a cybersecurity researcher and former NSA computer security scientist. "This is a core technology to our society. Not understanding kernel security means we can't secure critical infrastructure." Now DARPA, the US military's research arm, wants to understand the collision of code and community that makes these open-source projects work, in order to better understand the risks they face. The goal is to be able to effectively recognize malicious actors and prevent them from disrupting or corrupting crucially important open-source code before it's too late. DARPA's "SocialCyber" program is an 18-month-long, multimillion-dollar project that will combine sociology with recent technological advances in artificial intelligence to map, understand, and protect these massive open-source communities and the code they create. It's different from most previous research because it combines automated analysis of both the code and the social dimensions of open-source software.

Here's how the SocialCyber program works. DARPA has contracted with multiple teams of what it calls "performers," including small, boutique cybersecurity research shops with deep technical chops. One such performer is New York -- based Margin Research, which has put together a team of well-respected researchers for the task. Margin Research is focused on the Linux kernel in part because it's so big and critical that succeeding here, at this scale, means you can make it anywhere else. The plan is to analyze both the code and the community in order to visualize and finally understand the whole ecosystem.

Margin's work maps out who is working on what specific parts of open-source projects. For example, Huawei is currently the biggest contributor to the Linux kernel. Another contributor works for Positive Technologies, a Russian cybersecurity firm that -- like Huawei -- has been sanctioned by the US government, says Aitel. Margin has also mapped code written by NSA employees, many of whom participate in different open-source projects. "This subject kills me," says d'Antoine of the quest to better understand the open-source movement, "because, honestly, even the most simple things seem so novel to so many important people. The government is only just realizing that our critical infrastructure is running code that could be literally being written by sanctioned entities. Right now." This kind of research also aims to find underinvestment -- that is critical software run entirely by one or two volunteers. It's more common than you might think -- so common that one common way software projects currently measure risk is the "bus factor": Does this whole project fall apart if just one person gets hit by a bus?
SocialCyber will also tackle other open-source projects too, such as Python which is "used in a huge number of artificial-intelligence and machine-learning projects," notes the report. "The hope is that greater understanding will make it easier to prevent a future disaster, whether it's caused by malicious activity or not."
United Kingdom

UK's Online Safety Bill On Pause Pending New PM (techcrunch.com) 24

An anonymous reader quotes a report from TechCrunch: A major populist but controversial piece of U.K. legislation to regulate internet content through a child safety-focused frame is on pause until the fall when the government expects to elect a new prime minister, following the resignation of Boris Johnson as Conservative Party leader last week. PoliticsHome reported yesterday that the Online Safety Bill would be dropped from House of Commons business next week with a view to being returned in the autumn. The Department for Digital, Culture, Media and Sport (DCMS) denied the legislation was being dropped altogether but the fate of the bill will clearly now rest with the new prime minister -- and their appetite for regulating online speech.

Reached for comment, DCMS confirmed that the bill's final day of report stage will be rescheduled to after the summer recess -- suggesting it had lost out to competing demands for remaining parliamentary time (without specifying to what). The department also made a point of reiterating that the legislation intends to deliver on the government's manifesto commitment to make the U.K. the safest place in the world to be online while defending freedom of speech. But critics of the bill continue to warn it vastly overreaches on content regulation while saddling the U.K.'s digital sector with crippling compliance costs.

Windows

Microsoft Moves To New Windows Development Cycle (windowscentral.com) 122

Microsoft is shifting to a new engineering schedule for Windows which will see the company return to a more traditional three-year release cycle for major versions of the Windows client, while simultaneously increasing the output of new features shipping to the current version of Windows on the market. Zac Bowden writes via Windows Central: The news comes just a year after the company announced it was moving to a yearly release cadence for new versions of Windows. According to my sources, Microsoft now intends to ship "major" versions of the Windows client every three years, with the next release currently scheduled for 2024, three years after Windows 11 shipped in 2021. This means that the originally planned 2023 client release of Windows (codenamed Sun Valley 3) has been scrapped, but that's not the end of the story. I'm told that with the move to this new development schedule, Microsoft is also planning to increase the output of new features rolling out to users on the latest version of Windows.

Starting with Windows 11 version 22H2 (Sun Valley 2), Microsoft is kicking off a new "Moments" engineering effort which is designed to allow the company to rollout new features and experiences at key points throughout the year, outside of major OS releases. I hear the company intends to ship new features to the in-market version of Windows every few months, up to four times a year, starting in 2023. Microsoft has already tested this system with the rollout of the Taskbar weather button on Windows 11 earlier this year. That same approach will be used for these Moments, where the company will group together a handful of new features that have been in testing with Insiders and roll them out to everyone on top the latest shipping release of Windows. Many of the features that were planned for the now-scrapped Sun Valley 3 client release will ship as part of one of these Moments on top of Sun Valley 2, instead of in a dedicated new release of the Windows client in the fall of 2023.

EU

EU Lawmakers Slam 'Radical Proposal' To Let ISPs Demand New Fees From Websites (arstechnica.com) 42

An anonymous reader quotes a report from Ars Technica: Fifty-four members of the European Parliament (MEPs) are protesting what they call a "radical proposal" to require payments from online service providers to Internet service providers. Noting that Europe's 2015 "Open Internet Regulation ensures that citizens are free to use whichever apps and websites they wish," the MEPs said they have "deep concern about the European Commission's plans to change our net neutrality legislation in the upcoming Connectivity Infrastructure Act to be proposed in autumn, without having consulted the public, technology experts, academics, civil society, or expert regulatory agencies."

No specific proposal has been released, but "statements to the press indicate that a new provision would require payments from online service providers to broadband providers -- ostensibly to fund the rollout of 5G and fiber to the home," the MEPs wrote in the letter yesterday (PDF) to the European Commission. The letter cited a May 2 Reuters article that said, "Tech giants such as Google, Meta, and Netflix may have to bear some of the cost of Europe's telecoms network, Europe's digital chief Margrethe Vestager said on Monday, following EU telecoms operators' complaints." The MEPs' list of references also includes two Ars Technica articles from 2012 when a similar proposal was being discussed.

Vestager reportedly said at a news conference that "there are players who generate a lot of traffic that then enables their business but who have not been contributing actually to enable that traffic. They have not been contributing to enabling the investments in the rollout of connectivity... and we are in the process of getting a thorough understanding of how could that be enabled." [...] The MEPs' letter further argued that charging websites for access to broadband consumers would help ISPs abuse their monopolies: "Adopting a model that allows for or mandates access fees would be a disastrous return to the economic model for telephony, where telecommunications companies and countries leveraged their termination access monopolies to make communication expensive. Because phone companies had a monopoly over their customers, they could charge exorbitant prices to anyone seeking to call their customers. Broadband providers have the same monopoly over their customers. Allowing them to charge content providers for access could cause significant harm to the Internet economy." The MEPs also doubt such fees would improve broadband connectivity, saying that "factors such as permits or construction capacities can act as more severe barriers than lack of funding." They urged the European Commission to take its time and open an official consultation, saying, "There is no emergency that requires action in autumn 2022."

Music

New Windows Media Player App Travels Back in Time, Gains the Ability To Rip CDs (arstechnica.com) 65

In March, Microsoft enabled audio CD playback in the new version of Media Player, something that the old version had supported for pretty much as long as it had existed. And now, Microsoft is rolling out support for CD ripping in the new version of Media Player, presumably so that we can all convert our old Weezer and Matchbox 20 CDs into files we can copy over to our iPods and Zunes. From a report: By default, CDs can be ripped to AAC files at constant bitrates ranging between 96 and 320kbps. The WMA, FLAC, and ALAC formats are also supported. MP3 support and variable bitrate support, two features that are still included in the "Media Player Legacy" app, are notably absent.
Technology

Samsung Develops GDDR6 DRAM With 24Gbps Speed for Graphics Cards (zdnet.com) 20

Samsung said on Thursday that it has developed a new GDDR6 (graphics double data rate) DRAM with a data transfer rate of 24 gigabits per second (Gbps). From a report: A premium graphics card that packs the chips will support a data processing rate of up to 1.1 terabytes (TB), equivalent to processing 275 movies in Full HD resolution within a second, the South Korean tech giant said. Samsung said the DRAM was comprised of 16Gb chips using its third-generation 10nm process node, which also incorporates extreme ultraviolet (EUV) lithography during their production. The company also applied high-k metal gates, or the use of metals besides silicon dioxide to make the gate hold more charge, on the DRAM. Samsung said this allowed its latest DRAM to operate at a rate over 30% faster than its 18Gbps GGDR6 DRAM predecessor.
Your Rights Online

India Proposes Right To Repair Framework for Mobile Phones, Consumer Durables (techcrunch.com) 7

India has proposed to introduce a right to repair law, aiming to provide consumers the ability to have their devices repaired by third parties to fight the growing "culture of planned obsolescence" in a move that follows similar deliberations in the U.S. and the UK. From a report: The Indian Department of Consumer Affairs said Wednesday that it had set up a committee to develop a right to repair framework. The committee identified mobile phones, tablets, consumer durables, automobiles and farming as important sectors for the framework, the ministry said. "The pertinent issues highlighted during the meeting include companies avoiding the publication of manuals that can help users make repairs easily," the ministry said in a statement.
Technology

Stripe Cuts Internal Valuation by 28% To $74 Billion (wsj.com) 10

Payments giant Stripe, last valued by private investors at $95 billion, cut the internal value of its shares by 28%, WSJ reported Thursday, citing people familiar with the matter. From the report: Stripe told employees in an email Friday that the internal share price was about $29, compared with $40 in the most previous internal valuation, known as a 409A valuation, the people said. The move lowered the implied valuation of those shares to $74 billion, according to one of the people, which is calculated separately from the stock owned by major shareholders. Stripe said in the email that the board approved the lower share price effective June 30, the people said. The payments processor to startups and fast-growing internet companies didn't explain the decision to lower its internal valuation, the people said. The decision comes amid a prolonged market selloff that has slowed down the pace of private fundraising and pushed startups to slash costs and cut jobs.
Operating Systems

Google's Chrome OS Flex is Now Available for Old PCs and Macs (theverge.com) 60

Google is releasing Chrome OS Flex today, a new version of Chrome OS that's designed for businesses and schools to install and run on old PCs and Macs. From a report: Google first started testing Chrome OS Flex earlier this year in an early access preview, and the company has now resolved 600 bugs to roll out Flex to businesses and schools today. Chrome OS Flex is designed primarily for businesses running old Windows PCs, as Google has been testing and verifying devices from Acer, Asus, Dell, HP, Lenovo, LG, Toshiba, and many more OEMs. Flex will even run on some old Macs, including some 10-year-old MacBooks. The support of old hardware is the big selling point of Chrome OS Flex, as businesses don't have to ditch existing hardware to get the latest modern operating system. More than 400 devices are certified to work, and installation is as easy as using a USB drive to install Chrome OS Flex.

Slashdot Top Deals