I really expected VW to do better in handling this. Some business analysts are saying VW may be out of business within five years time. Based off this testimony I say good riddance.
I really expected VW to do better in handling this. Some business analysts are saying VW may be out of business within five years time. Based off this testimony I say good riddance.
I find this plausible...
(Particularly since these hearings seem designed to score political points rather than to find out what actually happened.)
His big thing was to be the largest car maker and he needed to juice US sales to get there. He had to have spent a lot of time on US strategy. The shitty part is that he succeeded--they became #1 (this year!) and he has a huge pension to retire on.
"Winterkorn’s professional career began in 1977 as a specialist assistant in the research division "Process Engineering" at Robert Bosch GmbH. From 1978 to 1981 he headed the refrigerant compressor development group "Substances and Processes" at Robert Bosch GmbH and Bosch-Siemens-Hausgeräte GmbH.
In 1981 Winterkorn joined AUDI AG as assistant to the Member of the Board for Quality Assurance. Two years later, he assumed responsibility for "Measuring Technology/Sampling and Test Laboratory" at Audi. At the beginning of 1988, he was made departmental head of "Central Quality Assurance", and in 1990 Head of Audi Quality Assurance.
In 1993 Winterkorn became Head of "Group Quality Assurance" at Volkswagen AG and was appointed General Representative of Volkswagen AG in March 1994."
These would be his formative years. It seems he focused on processes and quality rather than actual technology, IMO.
He was also known as a micromanger, I just don't see how he didn't somehow figure out that his entire clean diesel strategy was bullshit.
you can't get this running for 6 years without widespread cooperation, or at least willfully turning a blind eye.
those engines ran loads of miles on benches before being put into cars, and it's a large group running multiple cross tests on many parameters including fuel consumption and efficiency and operating temperature, which should give anyone within the sector a good rough idea of how an engine performs emission wise.
The company should have processes in place that can verify the claims it makes. Plausible deniability is really just a claim of neglect.
Edit: I'm being rate-limited, so I'll respond to the points below right here:
>What processes should be in place, exactly, to do what?
How about driving a vehicle in the manner most of their customer's do and examining the emissions?
>Quarterly polygraph tests performed by all engineering managers
How would that help exactly? Polygraph is demonstrably unreliable.
>to assure top management they haven't broken any laws?
It's mostly irrelevant how assured top management is about anything. What matters, in this case, is how far out of spec the vehicles Volkswagon produced are. That is what needed to be verified: specs vs. facts.
Let's assume the individial he is talking about is a manager of a group of hundreds of engineers working in this area. This means this guy's direct manager most likely would not be in a position to inspect the work of people 2-3 levels down for any irregularities.
What processes should be in place, exactly, to do what? Quarterly polygraph tests performed by all engineering managers to assure top management they haven't broken any laws?
All you need are strong whistleblowing protections and mandatory independent investigation of any claims made.
Do you really think of the dozens of people who had to be aware of it none of them would have thought "this is really dodgy" and wanted to push it up the chain?
Ignore whatever comes out of the VW USA guy. The investigations in Germany will most likely be more fruitful especially because police is involved.
It seems like the German government is more competent that the US at enforcing laws against corporations, even when those laws are USA laws...
*EDIT: This comment is poorly worded. What I mean to say is, Germany is doing a better job at holding PEOPLE AT THE TOP responsible, whereas the USA is predictably allowing CxOs to plead ignorance and hide behind the corporate veil. Meanwhile in Germany, http://www.wsj.com/articles/german-prosecutors-open-investig...
This all happened because of the work of the West Virginia lab, plus CARB and EPA's investigation, and the EPA's refusal to issue an emissions certification to 2016 diesel VW passenger cars which has led to likely tens of thousands of un-sellable cars sitting on US dealer lots.
The German government has been shown to have looked the other way repeatedly and to be complicit in fighting on behalf of the automakers instead of the environment.
The European emissions and mileage tests have been shown to be an utter and complete sham.
The story you're peddling is really the exact opposite of reality. Take a look around at the other stories that have been posted on HN on the matter.
The ICCT (an NGO) that appears to be based on Europe, commissioned the West Virginia study to try to figure out how more stringent US Diesel standards were being met, so they could encourage automakers to meet the same standards in Europe.
http://www.detroitnews.com/story/business/autos/foreign/2015...
"In 2013, his organization [the ICCT] commissioned a study of VW diesels by West Virginia University after questions were raised about European diesel emissions standards and whether European vehicles were emitting too much nitrogen oxides linked to smog. Testers looked at three diesel cars for the U.S. market: a 2012 VW Jetta, a 2013 VW Passat and a BMW X5. The group expected the cars they tested would perform better than those in Europe, because U.S. regulations are tougher. They were surprised the two Volkswagens had significantly higher-than-expected emissions, while the BMW performed well. They were so certain they had done something wrong that they tested the cars two more times with similar results."
http://www.ldra.com/en/software-quality-test-tools/group/by-...
The industry also has specific coding standard for every language that is used in embedded systems like MISRA-C https://en.wikipedia.org/wiki/MISRA_C
Today every thing you do with your car from using breaks to deploying air-bags is done through the computer, there's no way in hell that the motor industry would be releasing poor code "intentionally" because it would cost them billions in liabilities.
"Barr checked the [Toyota] source code against MISRA’s 2004 edition and found 81,514 violations."
http://www.safetyresearch.net/blog/articles/toyota-unintende...
It is inaccurate to claim Michael Barr determined the cause of Toyota's unintended acceleration: he proposed a possible failure mode that was persuasive to a lay jury. His proposed failure mode didn't leave a DTC, so there's no way to actually know if his proposed failure mode actually happened in this case (or in any other).
NASA found 7000 and change Barr found over 81,000, I'm not sure whats the size of the code that was reviewed but that's allot, even if you count the fact that half of them might be silly like naming convention violations that still leaves quite an odd number for actual violations especially when considering that the code for an embedded system can't be that huge.
And the 10,000 global variables thing, well 10,000 sounds like a huge number but there wasn't any mention if they were a) necessary, b) implemented correctly, and c) out of how many variables in total? if the code they've tested has say 1 million variables then well.... And how they described global variables is also weird, they claimed that every software within the system can access them to me this sounds that your stereo or the rain sensor for the wipers can override data for the breaks, but that might be true only if everything is running within a single application.
If the breaks run as an independent application well then only every function within the break software (depending on the language and how global variables are implemented) could potentially access those variables.
To me pretty much that entire explanation seem to be constructed to sound worse than what it is, which is why I think that expert witnesses should only be allowed to be appointed and called by the court it self (as in by the judge so they and the jury could understand the technical details better) and not by either the defense or the prosecution.
They were not. It is never necessary to have 10,000 global variables. If you have 10,000 global variables you are systematically Doing It Wrong. (That's not to say it's uncommon. From my experience I strongly suspect that it's a very common practice.) As one of the witnesses put it, quite correctly IMO:
"And in practice, five, ten, okay, fine. 10,000, no, we're done. It is not safe, and I don't need to see all 10,000 global variables to know that that is a problem,” Koopman testified.
Trying to justify this is like trying to justify not having a bug tracker. Which, BTW, they didn't.
> b) implemented correctly,
There's no way to check 10,000 global variables to see if they're implemented correctly, and that's the entire point.
> and c) out of how many variables in total?
That is completely irrelevant.
> they claimed that every software within the system can access them to me this sounds that your stereo or the rain sensor for the wipers can override data for the breaks,
This was the ECU, it only controls the engine, not the radio or the wipers. It has tasks for stuff like monitoring the engine and wheel speeds, the accelerator and brake pedal positions and controlling the fuel injection. And all of those tasks were only an extra header file and a typo away from stomping on one of the 10,000 global variables belonging to another task, but that isn't even the issue. The issue is that there is no way to trace the flow of data in the system because it's completely unstructured.
> but that might be true only if everything is running within a single application.
Welcome to the world of embedded RTOSs, where everything is running within a single application. It's not a PC. "Applications" aren't a thing. There's certainly no memory protection.
> Welcome to the world of embedded RTOSs, where
> everything is running within a single application.
> There's certainly no memory protection.
Generally, I agree, even though there have been quite a few chips already that have a primitive "Memory Protection Unit" that typically only distinguishes two processor states and you'd be able to protect the working data of e.g. the scheduler and your watchdog from the rest of the code running on your system. Which is much better than nothing!But in the end the important consequence is: Having everything in one address space encourages people to violate the concepts that memory protection between tasks on your PC typically enforces, e.g. tasks reading from, and writing to other tasks' data structures without proper synchronization; instead of using proper IPC mechanisms like queues. Which is probably what these 10'000 global variables were used for.
Dav3xor's Law -- Code Quality is Inversely Proportional to Risk.
Anecdotal evidence is anecdotal.
I read that as:
> This is a company whose products are high-velocity 1500kg chunks of steel zooming around in public, not a company that sells an intangible virtual good/service
---
Yes, I know software is historically poor with car companies, but we should still expect better. Let's not just lower our standards because of cynicism :-)
When an engineer builds a bridge, she has to personally sign off on the bridge, saying it's safe, and is risking not only her professional career, but I think she can also be jailed and held criminally liable if the bridge kills people due to negligence.
It blows my mind, at least, that no such thing exists for software.
ISO, IEC, etc.
> There's no licensure body for software engineers who build software running your car, and therefore no accountability on a personal level.
MISRA, SCSC, etc.
- https://en.wikipedia.org/wiki/ISO_26262
There aren't any guarantees that they'll be useful, that they'll match the modern development processes in your language, that they'll fit your problem domain, etc.
Those standards are there primarily to make the publisher a buck--not to represent the codified wisdom of up-to-date practitioners in a field.
Until we've got a truly open-source standard for people to code against, we should stop wringing our hands about these things.
If you use software to build a bridge, bridge standards should apply. If you use software to build a car, car standards should apply.
If you use software to build a fart app, fart app standards should apply. (Which frankly, don't have to be very high.)
I'm not asking if you think such a thing would be possible or not - I'm asking if you would accept an alternate means of getting what I think we both want.
Then you don't know the motor industry very much as it has very strict coding standards like ISO 26262, the code has to be audited internally and by certified 3rd parties with every release to meet the development cycle requirements of the standards. http://www.ldra.com/en/software-quality-test-tools/group/by-.... The industry also has specific coding standard for every language that is used in embedded systems like MISRA-C https://en.wikipedia.org/wiki/MISRA_C
http://www.detroitnews.com/story/business/autos/foreign/2015...
Now it may very well be true that VW is lying and it was a corporate decision. But it's not completely implausible that this really was the decision of a few individual employees.
Other commenters here are expressing surprise that engineers could "slip through arbitrary code" to do this. But isn't that kind of the job of software engineers, to write code to do things? I would hope they have code review going on at VW, but code review doesn't always catch everything, or maybe several engineers who were working together would review each other's code.
Oh, I fully believe it was the decision of a few individual employees. I just don't believe those individuals were the actual coders. Coders will code to the spec they are given; problems are far more likely to lie in the spec layer.
It is possible it will turn out the coders should have known better. But it isn't even that hard for me to create plausible circumstances in which the coders didn't have any reason to believe they were doing anything wrong. Remember, we're only seeing the end-results, but it's not hard to imagine a combination of specifications where the programmers are assured each little step is legal and OK, and a combination of other optimizations combining together to produce this result, with no one person quite understanding the interactions.
And just to be clear, I work a lot in security, on the defense side. I'm familiar with taking the possibility that coders will be actively hostile seriously. But I'm also very familiar with seeing five intelligent people each acting according to their own best info and with their own best interests at heart interacting to produce blithering stupidity. It's not always as simple as it looks when you're just looking at the outcome.
> The German automaker has suspended 10 senior managers, including three top engineers, as part of its internal investigation.
So it could be a few engineers and their managers that colluded together on this.
As someone who has worked in a comparably highly regulated industry (pharma) I can state with full confidence that Mr Horn is a lying bastard.
Bingo! A lot of HN is acting like "it could slip through the processes we have at work so I can see how it could happen here" without realising that the processes, documentation, and independent review requirements are 100x more involved and thorough for critical car firmware than they are for a basic software shop.
The sort of shops where most every discussion is double top-secret: happens in-person, quietly, behind closed doors and the email trail is kept to strictly vague coordination details, at most, since it's subject to discovery. Oh and information is hoarded, because details create weaknesses.
I think it is cowardice to blame them.
The cars sold in the US have nothing in common with the European models but the name and engine.
The US models have different sizes, different engine selections, are fully assembled in the US, etc.
Some example images:
Interior: http://www.myturbodiesel.com/images/b7/tdi/2012-vw-passat-eu...
Exterior: http://www.myturbodiesel.com/images/b7/tdi/euro-passat-diffe...
Seats: http://www.myturbodiesel.com/images/b7/tdi/interior-differen...
And in this 2011 discussion there are already discussions about how VW is able to handle NOx without AdBlue in the US variation of the car: http://www.myturbodiesel.com/threads/differences-between-201...
But if they could just go out and get jobs, why would they fear for their jobs in the first place?
I really do feel this is analogous to some large pharmaceutical finally admitting that they cheated clinical testing on an important drug. You can't just pin that back to a couple of "rouge scientists".