4 ms·
It is possible to write safe and secure software. It's expensive, but it's possible. Digitizing the grid has enormous upside, to the tune of billions in saving
by throwawayjava 7y ago
It is possible to write safe and secure software. It's expensive, but it's possible.
Digitizing the grid has enormous upside, to the tune of billions in savings and improved resiliency/response to weather related outages. It we could do it safely and securely it'd be a no-brainer.
We're just trading a devil we know for a (preventable) devil we don't.
BTW: digitized grids aren't even necessarily more vulnerable. In a complex system, the increased latency and miscommunication opportunities introduced by human operators are also a potential attack vector...
- rrix2 7y agoDigitizing the grid also opens up efficiency gains which we sorely need. Smart water heaters which run when we have daytime solar surplus, etc.
- gamedori 7y agoWhy not send a price signal separate from the grid, or use AC frequency deviation as a price signal?
- cogman10 7y agoThe neat thing is that already basically exists in the form of voltage. If you've ever watched your voltage, you'd noticed that it isn't a perfect 110 or 220. It is often higher or lower. When it is higher, there is a local surplus, when it is lower, there is a high load. We could do this today. We might not have current pricing, but we do have load vs production information.
- cesarb 7y ago> When it is higher, there is a local surplus, when it is lower, there is a high load. Or perhaps the voltage got too low, and an on-load tap changer in one of the transformers increased the output voltage. Voltage does not necessarily follow the load. AFAIK, the thing generators themselves use as the main feedback signal is not voltage, but frequency; but it's not a useful signal for consumers, given that generators are much stronger at keeping the frequency at its nominal value.
- cogman10 7y agoFrequency doesn't change with load. Load causes the voltage to drop (that's what's happening when a "brown out" is triggered). Some loads cause the current to lead or lag the voltage wave (Inductive vs Capacitive loads, most are Inductive, particularly with heavy duty equipment). But that isn't changing the frequency but rather the phase of the current. This is all tied up with a number referred to the "Power factor" (see https://en.wikipedia.org/wiki/Power_factor https://en.wikipedia.org/wiki/Power_factor ). essentially, the farther shifted current is from voltage, the more work is done by the power plants essentially heating grid wires (rather than doing something useful) So, power grids will do 2 things. First, they'll work to keep the current and voltage phase in sync. They do this by adding extra capacitors/inductors. Second, they work to maintain the voltage of their tie in to to the grid. Generally speaking, the type of power plant matters as well. Base load plants will simply dump onto the grid at a constant rate (without really caring about what the voltage is) while peaker and load following plants will attempt to vary output relative to their voltage to try and keep the grid voltages stable. You are correct, the voltage variance can be misleading at the customer level if the transformer is actively adjusting it's voltage ratio. I didn't consider that.
- LIV2 7y agoThis is exactly how it's already done :) https://en.m.wikipedia.org/wiki/Zellweger_off-peak https://en.m.wikipedia.org/wiki/Zellweger_off-peak
- deleted 7y ago[deleted]
- a3n 7y ago> It is possible to write safe and secure software. It's expensive, but it's possible. And we've done it before (safe, anyway). Is our electric grid as critical as space shuttle software?
- MFLoon 7y agoNot to be a pessimist, but just because a software error never caused a catastrophic space shuttle accident doesn't necessarily mean that the software actually was safe and secure.
- bluejekyll 7y agoMaybe not the space shuttle, but: NASA’s Mars Climate Orbiter; crashed or is now inoperable and orbiting the sun due to a bad numerical conversion. ESA’s Ariane 5 Flight 501; manual self destruct triggered after a 64bit number being truncated into 16bits caused faults to be thrown. https://raygun.com/blog/costly-software-errors-history/# https://raygun.com/blog/costly-software-errors-history/# I don’t think we should go back to manual operation (as the default, but should be overridable). Instead we should be using stricter compilers, and better unit, integration tests, and fuzz testing to test as many edge conditions as possible.
- mattmar96 7y agoMatt Parker's book Humble Pi is full of math/programming errors like this.