4 ms·
> Immediately after the wreck at 9:14 p.m. on April 25, 2019, the crucial data detailing how it unfolded was automatically uploaded to the company’s servers and
by metaphor 1y ago
> Immediately after the wreck at 9:14 p.m. on April 25, 2019, the crucial data detailing how it unfolded was automatically uploaded to the company’s servers and stored in a vast central database, according to court documents. Tesla’s headquarters soon sent an automated message back to the car confirming that it had received the collision snapshot.
> Moments later, court records show, the data was just as automatically “unlinked” from the 2019 Tesla Model S at the scene, meaning the local copy was marked for deletion, a standard practice for Teslas in such incidents, according to court testimony.
Wow...just wow.
- A4ET8a8uTh0_v2 1y agoI am trying to imagine a scenario under which that is defensible and does not raise various questions including compliance, legal, retention. Not to mention, who were the people who put that code into production knowing it would do that. edit: My point is that it was not one lone actor, who would have made that change.
- colejohnson66 1y agoAssuming no malice, I'd guess it's for space saving on the car's internal memory. If the data was uploaded off of the car, there’s no point keeping it in the car.
- wat10000 1y agoSounds like a pretty standard telemetry upload. You transmit it, keep your copy until you get acknowledgement that it was received so you can retry if it went wrong, then delete it when it succeeds. It’s just worded to make this sound sketchy. I bet ten bucks “unlinked” just refers to the standard POSIX call for deleting a file.
- tobias3 1y agoSketchy is that then someone takes “affirmative action to delete” the data on the server as well. Also this is not like some process crash dump where the computer keeps running after one process crashed. This would be like an plane black box uploading its data to the manufacturer, then deleting itself after a plane crash.
- wat10000 1y agoI’ll bet another ten bucks that this is a generic implementation for all of their telemetry, not something special cased for crashes. Deleting the data on the server is totally sketchy, but that’s not what the quoted section is about.
- dylan604 1y agoHow handling an automobile crash not as a special case is the weird part. Even in the <$50 dashcams from Amazon there is a feature to mark a recording as locked so the auto delete logic does not touch the locked file. Some of them even have automatic collision detection which locks the file for you. How Tesla could say that detecting a collision and not locking all/any of the data is normal is just insane.
- immibis 1y agoThat one's easy: nobody at Tesla cares about having this feature
- pjob 1y agoThat might not be a good bet. https://news.ycombinator.com/item?id=45063380 https://news.ycombinator.com/item?id=45063380
- wat10000 1y agoI don't see anything in that comment that would apply to what I said.
- buran77 1y agoThe process of collecting and uploading the data probably confuses a lot of non-technical readers even if it worked as per standard industry practices. The real issue is that Tesla claimed the company doesn't have the data after every copy was deleted. There's no technical reason to dispose of data related to a crash when you hold so much data on all of the cars in general. Crash data in particular should be considered sacred, especially given the severity in this case. Ideally it should be kept both on the local black box and on the servers. But anything that leads to it being treated as instantly disposable everywhere, or even just claiming it was deleted, can only be malice.
- wat10000 1y ago> The real issue is that Tesla claimed the company doesn't have the data after every copy was deleted. Exactly. The issue is deleting the data on the servers, not a completely mundane upload-then-delete procedure for phoning home. This should have been one sentence, but instead they make it read like a heist.
- giancarlostoro 1y ago> The real issue is that Tesla claimed the company doesn't have the data after every copy was deleted. There's no technical reason to dispose of data related to a crash when you hold so much data on all of the cars in general. My money is on nobody built a tool to look up the data, so they have it, they just can't easily find it.
- deleted 1y ago[deleted]
- alistairSH 1y agoThat might be the case but the article seems to indicate the system knew the data was generated from an accident. So, removing to save space on the car should now be a secondary concern.
- joshcryer 1y agoThe problem with this is that it destroys any chain of evidence. Tesla "lost" this data, in fact. You would never want your "black box" in your car delete itself after uploading to some service because the service could go down, be hacked, or the provider could decide to withhold it, forcing you into a lengthy discovery / custody battle. This data is yours. You were going the speed limit when the accident happened and everyone else claims you were speeding. It would take forever to clear your name or worse you could be convicted if the data was lost. This is more of "you will own nothing" crap. And mainly so Tesla can cover its ass.
- aredox 1y agoIt is a car. A vehicule which can be involved in a fatal accident. It is not a website. There is no "oversight", nor is it "pretty standard" to do it like that: when you don't think about what your system is actually doing (and that is the most charitable explanation), YOU ARE STILL RESPONSIBLE AS IF YOU HAD DONE IT ON PURPOSE.
- wat10000 1y agoOne of Tesla’s things is that their software is built by software people rather than by car people. This has advantages and disadvantages. Maybe this is not appropriate for a car, but that doesn’t excuse the ridiculous breathless tone in the quoted text. It’s the worst purple prose making a boring system sound exciting and nefarious. They could have made your point without trying to make the unlink() call sound suspicious.
- buran77 1y ago> their software is built by software people rather than by car people The rogue engineer defense worked so well for VW and Dieselgate. The issue of missing crash data was raised repeatedly. Deleting or even just claiming it was deleted can only be a mistake the first time.
- wat10000 1y agoI really should know better than to think that I can criticize a small part of an article without a bunch of people thinking that I'm defending everything the article discusses.
- const_cast 1y agoThere are software people who know what they're doing - some write flight software or medical equipment software. They know how to critically think about the processes of their systems in detail. So either the problem is Tesla engineers are fucking stupid (doubtful) or this is a poor business/product design. My money is on the latter.
- 1y ago
- OutOfHere 1y agoThat's 100% wrong. In standard practice, collision files are to be "locked", prevented from local deletion.
- phkahler 1y ago>> That's 100% wrong. In standard practice, collision files are to be "locked", prevented from local deletion. I worked a year in airbag control, and they recorded a bit of information if the bags were deployed - seatbelt buckle status was one thing. But I was under the impression there was no legal requirement for that. I'm sure it helps in court when someone tries to sue because they were injured by an airbag. The argument becomes not just "the bags comply with the law" but also "you weren't wearing your seatbelt". Regardless, I'm sure Tesla has a lot more data than that and there is likely no legal requirement to keep it - especially if it's been transferred reliably to the server.
- giancarlostoro 1y agoI don't think its wrong, have you ever pushed code that was technically correct, only to find months later that you, your PM, their manager, their boss' boss, etc all missed one edge case? You're telling me no software developer has ever done this?
- buran77 1y agoYou discover it the day you a person dies and your relevant data is not there. Next time it's no longer a "missed edge case".
- giancarlostoro 1y agoIn a perfect world where developers are omnipresent and all knowing sure? This isn't a perfect world. Heck, how do you account for the developer who coded it leaving the company, and now that code has been untouched for half a decade if not more, because nothing is seemingly wrong with the code, what then? Who realizes it needs to be changed? Nobody. The number of obscure bugs I find in legacy code that stump even the most experienced maintainers never ends.
- giancarlostoro 1y agoI think your answer is the most logical to me as a developer, we often miss simple things, the PM overlooks it, and so it goes into production this way. I don't think its malicious. Sometimes bugs just don't become obvious until things break. We have all found an unintended consequence of our code that had nothing wrong with it technically sooner or later.
- const_cast 1y agoDude we're at the point where cars are practically gathering data on the size of your big toe. The performance ship sailed, like, 15 years ago. We're already storing about 10000000 more data than we need. And that's not even an exaggeration.
- ajross 1y agoIn point of fact eMMC wear failure was an actual bug in early Tesla MCUs. They were logging too much, so when the car reached (via routine use) a certain fill level the logging started running over the same storage again and again and the chips started failing. It's very easy to imagine a response to this being (beyond "don't log so much") an audit layer to start automatically removing redundant data. The externalities of the company are such that people want to ascribe malice, but this is a very routine kind of thing.
- A4ET8a8uTh0_v2 1y agoThis, I think, was the argument that seems most plausible to me ( without ascribing malice ). It brings its own set of issues, but even those issues make it more believable despite being problematic in their own right.
- jeffbee 1y agoThe artifact in question was a temporary archive created for upload. I can't think of a scenario in which you would not unlink it.
- JumpCrisscross 1y agoAnd then you delete the server copy?
- jeffbee 1y agoObviously no. The behavior of Tesla in discovery of this case is ridiculous. But treating this technical detail as an element of conspiracy is also ridiculous.
- actionfromafar 1y agoIf that was the only thing going wrong, yes. But when you have a pattern of conspiracy, deleting immediately on the client instead of having a ring buffer which ages out the oldest event, may be a malicious choice.
- jeffbee 1y agoI haven't seen anything in the (characteristically terrible and vague) coverage of this case that suggests the Tesla deleted the EDR.
- semiquaver 1y agoThey didn’t delete the server copy though. That’s what this article is about. > Tesla later said in court that it had the data on its own servers all along
- JumpCrisscross 1y agoWasn’t that after they’d been caught?
- ozim 1y agoWell if it would be EU for GDPR you can assume contract was terminated because of force majeure and you are not allowed to keep customer data past contract. /s
- raincole 1y agoThe 'wow' part is that they deleted data from server. The part you quoted sounds like nothing unusual to me.
- lexicality 1y agoYou don't think it's unusual that the software is designed to delete crash data from the crashed car?
- foobarian 1y agoThink of it as the scripts that run on CI/CD actions running unit tests. If a unit test fails, the test artifacts are uploaded to an artifact repository, and then, get this - the test runner instance is destroyed! But we don't think of that as unusual or nefarious.
- lexicality 1y agoThat's because typically the test runner hasn't just crashed into another test runner at full highway speed
- smallpipe 1y agoNo one dies when your unit test fails. Different stakes, different practices, what are all the Tesla apologists smoking here?
- Ambroisie 1y agoI don't think you can equate CI/CD unit tests and killing humans with 2 tons of metal.
- foobarian 1y agoAnd yet, that's what you get when your software org comes from that kind of devops culture. And here we are
- ndsipa_pomu 1y ago
- fny 1y agoYou left out the worse part: > someone at Tesla probably took “affirmative action to delete” the copy of the data on the company’s central database, too
- ryandvm 1y agoIt is wild to me that people put so much trust in this company. Even if Tesla hadn't squandered it's EV lead and was instead positioned to be a robotics and AI superpower, is this really the corporate behavior you would want? This is some fucking Aperture Science level corporate malfeasance.
- flatline 1y agoIt’s pretty typical of corporations, the cult surrounding its leader notwithstanding. Not even just US corporations - the VW emissions scandal was huge, and today they are doing as well as ever. That was a big shakeup; the kind of stuff we are seeing from Tesla feels like business as usual.
- estearum 1y agoNo, it's not typical, because you don't see huge numbers of people defending VW's emissions fraud.
- SoftTalker 1y agoI don't defend it but the specifics never bothered me. They cheated because their cars didn't meet new emissions standards. They were fine by the standards of the year before. So a bureaucracy just declared that a legal level of emissions was now illegal. In my mind it's like suddenly declaring that blue cars are illegal, and they made a color-shifting car that is blue except when the authorities are looking at it. It is wrong in the sense that it is normalizion of deviance, however. We live in a society and if we don't like a law or regulation the correct response is to get it legally changed, not to ignore it and cheat.
- estearum 1y agoI didn't say you are defending it. I'm saying that "companies do bad things sometimes" is not a full description of the Tesla phenomenon that people take issue with.
- 1y ago
- 1vuio0pswjnm7 1y agoThe top HN comment on the front page story about this crash on HN several weeks ago claimed the damages award was too high Maybe this thread will be different