31 ms·
One shall not obsess with the game controller they use, I suppose, in their analysis, failing the controller wouldn't prevent the sub from resurfacing... It is
by major4x 3y ago
One shall not obsess with the game controller they use, I suppose, in their analysis, failing the controller wouldn't prevent the sub from resurfacing... It is symptomatic, however. The whole Silicon Valley is like that. You have the old guard, NASA, millions for fault analysis, rumors go the C code on some NASA rocket was certified at $1000 per line---human eyeballs reading it...
All those start-ups and unicorns, though. Just do it, when to be a hacker became an honorific, a title... Code your stuff, design your mechanics at Starbucks, who needs mathematics and physics when we can have s*t done instead. Who needs signing-off when we can have a carate-belt meeting standing on bouncing balls instead...
I don't want to be the dean of the faculty of prophecy but this is only the beginning. Wait until those autopilots starts using ChatGPT/Stack Overflow/copy/pasted code...
P.S. Hope they make it to the surface somehow...
- reikonomusha 3y agoToo bad even the "hacker" title has changed. One of the greatest "founding" hackers ever, Bill Gosper, is also a mathematical genius.
- toadi 3y agoHacking a social media site together and break stuff is fine. Move fast and kill people and iterate seems not so fine.
- truemotive 3y agoI'm really frustrated by anyone that poo-poos this specific issue. One shall absolutely fucking obsess, me for instance about the game controller they used. Look at this. https://i.imgur.com/FrdR7TP.png https://i.imgur.com/FrdR7TP.png So the F710 Logitech gamepad was something I wouldn't even trust as a teenager to let me play emulated retro games accurately. It has a hardware switch to toggle between DirectInput (an ancient input technology within Microsoft stack), and XInput which is a non-trivial third-party software to map controllers to do things on your computer. Complaints range from 'the input switch was finicky and I had to tape it down' to 'you had to insert the USB dongle into the computer carefully like trying to get a Nintendo cartridge to work'. In this case, it was the main navigation control on a submersible far exceeding its safety buffer by orders of magnitude. Sure, military applications have found use for XBox and other controllers as system inputs because generations of those serving are used to that interface. The differences are not subtle: 1. There had to be a certification process to use the controller, including risk analysis which would absolutely deny any attempt to use wireless controllers to operate any piece of equipment, no less anything that was weapon or safety critical. The military doesn't drive boats with XBox controllers. 2. XBox controllers are well designed and reliable, at an order of magnitude of this one. THEY ALSO COME IN A WIRED VERSION. 3. They decided to further mod the controller for no reason with longer sticks, maybe to make it look less like the toy it is which actually reduces the dead spot response of an analog joystick. Why? What the fuck. The reason for the photo above is to show what I've seen in every media piece where they talk about it: It is NEVER wired in any video or photo. In one video, which I can't dig up right now, the CEO actually tosses the controller carelessly on the ground and quips that "these things are designed for 16 year olds to throw them around". Edit: The bit mentioned above is at 0:37 in this video: https://youtu.be/ClkytJa0ghc?t=37 https://youtu.be/ClkytJa0ghc?t=37 - "we keep a couple of spares on board just in case", that's great but I'm wondering who in that sub knows how to pair an ancient Logitech gamepad and remap XInput like a kid playing Diablo. That is on video and a joke during the interview, forget for a second that they're using a controller from 2005-era for a moment; at that point on something like an airplane or a battleship, you just caused an incident that requires maintenance testing to make sure you didn't just disable the fucking vehicle by throwing the controls around for fun. No. Don't disregard this specific reckless decision even though it likely had nothing to do with whatever went wrong in this situation. The CEO of the company from the get-go abandoned any semblance of basic safety in engineering, and fired/sued the guy in charge of safety when he called it out. This controller is a metaphor for something that needs to immediately be regulated so that people like this can never get away with it again.
- raphman 3y agoIt seems your comment is missing a part: There's only one list item - which is truncated: > 1. There had to be a certification process to use the controller, including risk analysis which would absolutely deny any attempt to
- truemotive 3y agoFixed, thanks. I've had a lot of thoughts about this lately. Here's another fun fact: What's wrong with this picture taken while the submersible is out of operation? https://i.imgur.com/lBWlh3i.png https://i.imgur.com/lBWlh3i.png Answer: Look underneath the floor. The Altec Lansing ACS33 PowerCube 2.1 speaker system. $35 used on eBay and again from early 2000s era. -> https://i.imgur.com/fVdQ9Pc.png https://i.imgur.com/fVdQ9Pc.png Not safety critical, but so extremely indicative of how careless every element of this thing was handled before they started putting rich people in it and sending them 2.5mi underwater. It's as if they put it together by raiding my basement when I was in high school. Unbelievable.
- johnwalkr 3y agoWow that's bad. Every new detail looks like something out of an undergrad project. It works to hack something like that together as a first prototype, but even a masters student in a decent lab with decent mentors can make something much more professional. It's like they must have actively prevented anyone with any professional experience whatsoever from seeing it.
- heavyset_go 3y agoIt's likely that anyone with experience immediately walked away from the project when they saw what was going on. Who would want the reputation hit, the liabilities and the blood on their hands when things went wrong?
- rightbyte 3y agoI think they did sue some former employee that was publicly calling out some stress detail about some window. So experienced employees did not only walk away but sounded the alarm on the way out. It has to be hard for non-technical passagerare to judge these things, like the pre-tour disclaimer contract stating risks. I mean almost every house in CA tells you it will give you cancer.
- cscurmudgeon 3y ago> OceanGate Inc. is a privately held U.S. company operating out of Everett, Washington, that provides crewed submersibles for industry, research and exploration. The company was founded in 2009 by Stockton Rush.[1] Why do you blame Silicon Valley for that?
- sschueller 3y ago"Move fast, break things" is a SV mantra. That is ok for entertainment software or social networks but when you apply this to systems where people can die like healthcare, cars, spaceships and submersibles it's a problem,
- cscurmudgeon 3y agoYes, but no one in Silicon Valley forced this on these people.
- dehrmann 3y agoFor the most part (so no self-driving cars), startups are in a low-stakes game, so it makes sense to hack away, and it nas nothing to do with an "old guard." Google (or any other tech company) outages aren't particularly memorable unless you were an engineer involved in it. The space shuttle accidents were labeled "disasters."
- major4x 3y agoTheranos? All those cases of neglected security when data leaked and/or people killed themselves over scams?
- kumarvvr 3y agoTheranos is an outright fraud. Not the product of getting things done on fast track. They knew things could not be done and kept up the charade for long enough to profit off of it, and hopefully get away.
- ClumsyPilot 3y ago> Theranos is an outright fraud. Not the product of getting things done on fast track Theranos is product of the same culture. Company founder chases a goal they do not understand, and convinces investors its right around the corner. In actuality they have no clue. There is no foundamental difference between theranos diagnosis and tesla autopilot. The only reason we call theranos fraud is that we know conclusively that their goal is impossible. We have not yet accepted that autopilot is.
- throwbigdata 3y ago[flagged]
- ftrobro 3y ago> we know conclusively that their goal is impossible No we only know that their approach was wrong. Here is a preprint of a paper describing detection of 12 different types of cancer from a single drop of blood: https://www.researchsquare.com/article/rs-2025767/v1 https://www.researchsquare.com/article/rs-2025767/v1
- ikrenji 3y agoyou dont need the same coding standards for a crud web app vs a NASA space probe...
- moi2388 3y ago[flagged]
- thrashh 3y agoNothing has changed. The reason NASA did that is because the stakes were so high. They couldn’t send a firmware update in the middle of a journey and the reputation of America hinged on the success of NASA. If you are under that level of pressure, you make sure you dot your i’s and cross your t’s.
- radres 3y agoSure, because this does not happen in commercial aircrafts.
- alvah 3y agoThis is part of my ongoing campaign to resist the constant attempts to make "aircrafts" the plural of "aircraft". Thanks for your time!
- localplume 3y ago[dead]
- rob74 3y agoThe use of the controller is symptomatic of their attitude, but I agree that it's probably not as relevant as, say, using an untested (and apparently untestable) carbon fiber hull: > Lochridge’s concerns mainly focused on the company’s decision to rely on sensitive acoustic monitoring – cracking or popping sounds made by the hull under pressure – to detect flaws, rather than a scan of the hull. Lochridge said the company told him no equipment existed that could perform such a test on the 5in-thick (12.7cm-thick) carbon-fiber hull. “This was problematic because this type of acoustic analysis would only show when a component is about to fail – often milliseconds before an implosion – and would not detect any existing flaws prior to putting pressure on to the hull,” Lochridge’s counterclaim said. Source: https://www.theguardian.com/world/live/2023/jun/21/titanic-sub-live-updates-search-us-coast-guard-submarine-submersible?page=with:block-64929b868f088222c1ec77ae#block-64929b868f088222c1ec77ae https://www.theguardian.com/world/live/2023/jun/21/titanic-s...
- sn41 3y agoInteresting... This is similar to the concerns that Vince Weldon, the Boeing engineer had over the 787 Dreamliner hull made of composites: that flaws could not be found by a visual scan. https://en.wikipedia.org/wiki/Vince_Weldon https://en.wikipedia.org/wiki/Vince_Weldon
- twic 3y agoI have a carbon fibre fork on my bike. I had a low-speed accident a few years ago, and took the bike to a mechanic to get it checked out afterwards. He said he'd checked everything, and it was fine - except the fork, which he had no way of telling if was undamaged or about to fail. I think i'll get steel next time.
- hasmolo 3y agothis isn't true anymore. you can get carbon bikes scanned after and accident to find any internal damage. Ruckus in Portland, OR is where i've shipped to before with luck, but there's a lot more local options now depending on the scene
- taneq 3y ago> You have the old guard, NASA I thought the latest round of NASA missions were using commodity hardware and taking the fail-early-fail-often approach (at least compared to the old days)? And in doing so have delivered, all failures included, the most bang per buck of any NASA missions? Not saying I'd trust my life to a gamepad alone, but pragmatism is a virtue in engineering.
- whywhywhywhy 3y ago> Not saying I'd trust my life to a gamepad alone I’d trust it to an Xbox, PlayStation controller, they’re some of the most reliability tested input devices ever. Most people are freaking out because it’s some known glitchy budget gamepad.
- consp 3y agoMy playstation controller of less than a year old has stick drift so ymmv and you definately need backups. N=1 ofcourse but it's not that rare.
- whywhywhywhy 3y agoPS1 PS2 PS3 PS4 PS5 had two controllers each system, no drift or weirdness. Yeah someone must have it but we’re talking most of my life here no issues, I’d trust these controllers.
- taneq 3y agoFrom a functional safety perspective if you can't verify each step from the initial risk assessment to the final product, you can't prove the overall risk reduction and therefore don't know the overall residual hazard. From that perspective this sub would never have left dry dock (or possibly the CAD model). In practical terms if push came to shove, an Xbox or PS controller is probably more reliable than most equivalent devices. My stock phrase when comparing normal functions with Safety Instrumented Functions is "I'd trust this with my car, but not my life."
- _djo_ 3y ago
- eterevsky 3y ago> The whole Silicon Valley is like that. Well yes, and this enables making all the stuff that we have now like Google, YouTube or ChatGPT. If those things were developed with NASA approach to code quality, we might never have had them.
- danjac 3y agoIt's one thing if your favourite video host or chatbot crashes, quite another if it's a self-driven car, airplane control software or, in this case, a submarine.
- eterevsky 3y agoI'm not saying you should hack a sub from a scrap metal and just use it as is (which seems to have happened here). But you can rapidly iterate on your project to first make it functional and then gradually improve its reliability. What matters is not the process, but the result. For example, SpaceX are using iterative approach in their design and they now have the most reliable rocket in history.
- meigwilym 3y agoI'm not sure of your point here. You claim that SpaceX's process was an iterative one which lead to the 'most reliable rocket in history', but state that the process does not matter.
- eterevsky 3y agoAs I see it, there are two approaches: "NASA" approach and "SpaceX" or "Silicon valley" approach. In "NASA" approach you are building the system bottom-up ensuring the reliability on each level. In "SpaceX" approach you build a barely functional system as fast as you can and then iterate to improve reliability (and other characteristics). The top comment in this thread seems to imply that "NASA" approach is inherently better, especially for safety-critical applications. My view is that from the point of view of safety, the approach doesn't really matter and what matters is the results, i.e. reliability. At the same time from the point of view of development velocity iterative approach is clearly better. In case of the sunk submarine, it seems that the company followed iterative, "SpaceX" approach, but they didn't actually iterate enough to make their sub seaworthy.
- somenameforme 3y agoLike the video [1] mentions, they were only improvising on things (including the controller) that would not pose a safety hazard if they failed. The critical components like the capsule were designed alongside NASA and others. People aren't just tossing safety to the wind, but trying to create a better balance. NASA does spend a extreme amount of money on compliance and safety - yet that doesn't prevent them from doing things like blowing up $600 million Mars probes because of a mismatch between Imperial and Metric units. [2] Basically you cannot, no matter how much money you spend, prevent every possible mistake, or even every "obvious" mistake, because "obvious" is often only obvious in hindsight. And going too far on the side of risk avoidance leaves you frozen in time, unable to progress, even as you continue to make mistakes - which drives you even further into extremes of risk avoidance. Of course on the other end being completely cavalier about safety leaves you making mistakes you both can and should have foreseen. So I suppose we'll just get to see which this was. If anything my prediction here would be that they started becoming so comfortable with these dives that they impacted the Titanic, going for that epic view, resulting in a cascade of system failures or even a breach, bearing in mind you're already going to be near critical pressure thresholds. Absolutely zero basis for my prediction, but I think it's much more probable than a controller failure. They had redundancies on the controllers, and could surface without them. But human hubris has no such constraints. [1] - https://youtu.be/29co_Hksk6o?t=213 https://youtu.be/29co_Hksk6o?t=213 [2] - https://en.wikipedia.org/wiki/Mars_Climate_Orbiter https://en.wikipedia.org/wiki/Mars_Climate_Orbiter
- weird-eye-issue 3y agoWhy is the capsule considered the only critical safety component? If everything else fails wouldn't it just fall to the bottom of the ocean? Even if it can survive that depth that only sounds good on paper. Nobody could get to you.
- Out_of_Characte 3y agoBecause an implosion is a single point of failure leading to instant death. Anything else can be salvaged by staying calm and using one of multiple ways to resurface.
- spacephysics 3y agoTo further your point, I hope with venture capital funding being far more expensive due to interest rate rise, that these kinds of practices are held back a bit due to money being harder to come by. Or because investor X wants real assurances that something like the current situation doesn’t occur. I think a good example of a balanced company in this space, is SpaceX. They’ve significantly reduced the cost of launching into space, have quite rapid development for their industry, yet they seem to take necessary precautions and safety measures when needed. They aren’t afraid to test things and have them fail, and been able to not let bad PR (because some conflate successful testing with a successful launch) take them down as a company. Maybe the “SpaceX” way to have done the sun dive would be to have a test where an automatic diver is used to send the sun down, or some first principles approach is done from the building phase. A Logitech gaming controller is surely a canary for other practices they’ve done
- wnkrshm 3y agoThey did the automated dive test, then kept diving without any idea how long the hull will last. They didn't automatically dive until failure.
- ojosilva 3y agoThe "whole Silicon Valley" thing is very old guard too. Larry Ellison's first Oracle database would lose customers records randomly and reliability was left for the "future". This submarine, Amazon's Blue Origin and so many others are no exception to this rule.
- phpisthebest 3y ago>> You have the old guard, NASA, millions for fault analysis, Like with most things, extremes in either direction is bad, I think there is a middle ground between using logitech controllers, and being sooo paralyzing on safety (or rather the bureaucracy of "Safety™") that not only do you never really get off the ground, but come full circle and a $0.50 o ring you failed to test in freezing conditions blows up your entire rocket even after you spent millions having human read your C code...
- relbeek2 3y agoJust a slight correction, the o-ring not being tested in freezing conditions wasn't an oversight that destroyed the challenger; the engineers knew that the o-ring hadn't been tested at that unusually low temperature and even suspected it could fail at those temperatures. Management at Morton Thiokol and NASA disregarded those concerns because they had already scrubbed the launch several times. Bureaucracy is forged from the furnace of past adversities.
- deleted 3y ago[deleted]