Toyota Unintended Acceleration and the Big Bowl of “Spaghetti” Code (2013)
safetyresearch.net
safetyresearch.net
One company, the guy in charge of software was a CE, who would have been fine as long as the hardware was at the level of sophistication as what he was taught at school (He knew 8051 microcontrollers really well). He was really good at giant switch-case statements. Function pointers were a little newfangled and suspect.
Basically, he knew enough software engineering to get the hardware working.
That's one big problem that needs to be addressed -- there aren't a lot of people being trained in the software side of embedded systems. You have CS grads who for the most part aren't given much training on the low end of the abstraction spectrum, and the opposite for CE people, so there tends to be a very fuzzy area in the middle that causes arguments between the two camps.
The other company I worked for literally had crazy coding standards that basically dictated 20,000 line functions and a bizarre sort of anti-DRY mindset that I will never understand. You were encouraged to c-c c-v a block of code, change one line, move on!
https://www.youtube.com/watch?v=ouQFu1FDllw
To me it was an eye opener to learn about the different attitudes of tech professionals in countries such as South Korea and particularly Japan.
I highly recommend watching it some time.
I do also know a self taught free lancer who makes an absolute killing cleaning up problems in various companies. He does really short contracts (like 2-4 weeks) in Tokyo and Osaka. Then he comes back to Shizuoka and hangs out for a couple of weeks. So there is money to be made ;-)
Granted, even here in the USA programming used to be considered "women's work", mostly revolving around planning and organization. So they passed it off to secretaries. I just didn't think that was something that was still happening.
http://www.smithsonianmag.com/smart-news/computer-programmin...
Ask anyone who has lived in Japan for a sufficient period of time and they will laugh at this statement, especially as it relates to programming.
Or you could just hand print messages and send them by fax....
http://www.theatlantic.com/business/archive/2010/03/how-real...
Edit: I mean, -if it was this obvious we should have known it by now?
My recollection is: It was widely reported at the time.
Ultimately, Toyota was heavily penalized for fielding safety-critical software that it could not show was acceptably safe, which is a reasonable and desirable outcome, IMHO.
1) None of these cars are 700hp Supras that accelerate at drastic speeds. These were normal consumer cars that frankly aren't that fast even with the throttle fully depressed.
2) The brakes in all of these vehicles are many times more powerful than the engine. Pressing the brakes would have stopped the vehicles, even if the engine were attempting to accelerate full throttle.
In most cases I would never side with the corporation over average people. But this is one of those rare cases where lawyers were able to hire dishonest "experts" and snow over the judge and jury and get an unjust verdict.
I had a water bottle fall onto my right leg while turning, this caused a sudden but short lived acceleration (e.g. 10 MpH of unexpected acceleration for less than 1 second), this was enough to cause me to mount the curb, and do some decent property/car damage (thank god nobody was on the curb). The brakes worked perfectly, and stopped the car, but it does show how much damage even a tiny burst of unexpected acceleration can do (the entire incident was under 5-10 seconds).
It honestly boggles my mind that someone can dismiss any length of unexpected acceleration because "cars [aren't] 700 hp Supras." Consumer cars are plenty powerful enough to cause injury and death due to any length (even 1 second) of unexpected acceleration at the wrong moment. Sure, if you're going straight on the freeway then you aren't going to even notice, but in a car park, while turning, or stopped at a school crossing, the brake's ability to overcome the engine are largely irrelevant since you won't be expecting it.
Modern cars, even the modest ones, are fast enough that they can get out of control very quickly. While the brakes certainly can slow a vehicle with its throttle stuck open, the real question is what impact does that stuck throttle have on the average driver? When the brake doesn't work as expected, does the average driver continue to brake? Do they pump the brake pedal? Something else altogether? How long does it take them to regain composure and act sensibly (in this case, putting the car in neutral while continuing to brake aggressively)? If that slowed reaction is more than some fraction of a second, accidents will happen.
Toyota's unintended acceleration is notorious because of incidents where the car accelerated up to extremely high speeds, was driven down the highway in this state for an extended time, then finally crashed. At least one involved a panicked 911 call from the driver. This is a scenario drivers should be able to bring to a safe conclusion, because they have time to work things out.
Some drivers will panic in such a scenario and be unable to work on the problem. Those people should not be driving. That they are speaks to the woefully inadequate state of driver training in this country.
None of this absolves Toyota of blame, though. If an equipment malfunction due to a design defect results in death even if the human should have recovered, that's still the fault of the manufacturer, as well as the driver.
> Do they pump the brake pedal?
A comment below mentions this, and it's one factor that can be age-related without invoking ‘dumb old people pressed the accelerator by mistake’. People who learned to drive before ABS were taught to pump the brakes.I was thinking of my old race car days, where a low pedal (boiled fluid or worse) could be temporarily reversed by a few pedal pumps to bring up the line pressure.
The actual data paints a different picture: http://media.caranddriver.com/images/media/51/braking-result...
That said people don't do well with surprises so while the car mechanically would have no trouble at all stopping very nearly as fast due to a wide open throttle, the driver is probably freaking out instead of just slamming on the brakes.
Also people suck at actually slamming on the brakes, regardless of the situation. It's not something people want to ever do. They'll hit the brakes, they just won't go anywhere close to really pushing that pedal to the floor.
To what? That doesn't contradict what I said at all.
If we convert MPH to FPS we can look at the data as follows:
70 MPH: 102.667 fps 100 MPH: 146.667 fps
CAMRY, V6, 70-0: delta 16 feet, .15sec
CAMRY, V6, 100-0: delta 88 feet, .60sec
INFINITY 70-0: delta 9 feet, .08sec
INFINITY 100-0: delta 6 feet, .04sec
We're talking tenths or hundredths of a second of unintended acceleration. A cursory search tells me reaction time to visual stimuli is about ~250ms.[1][2]This means that in all but the Camry 100-0 case your reaction time is a larger factor in braking distance than the presence of wide open throttle.
[1]: http://www.humanbenchmark.com/tests/reactiontime/statistics
It's still the driver's fault for not reacting properly. You could have unexpected acceleration or deceleration (which is just as dangerous in some circumstances) due to a lot of different problems; throttle stuck open, O2 Sensor goes wonky and tells the ECU to adjust the fuel mixture in a way that makes your car run rich and stall out, tire blows out causing your car to swerve severely to the right. In all of these cases it is up to the driver to react properly.
NOW, if they had proven that there was a design/manufacturing defect in these cars that Toyota knew about and did nothing about (like in the GM faulty ignition switch case), that's a different story. That would mean the manufacturer put customers at risk deliberately and not only should they pay financial penalties for that, but there should be jail time involved.
However, in the Toyota unintended acceleration case, not only was it very few drivers, they were never even able to establish a cause for the unintended acceleration. The software "experts" that testified for the plaintiffs only said that basically the software is badly written. It was never demonstrated that a specific piece of code caused unintended acceleration.
Instead, what is the obvious answer is that panicking drivers hit the throttle when they meant to hit the brakes. Especially since at least one of the drivers testified that they hit the brakes and it was unable to stop the car, which is total baloney.
EDIT: Also let me just state as a disclaimer I do not work for Toyota, never have, don't know anybody who does, I don't own any Toyota cars and never have. I just can't deal with people spreading bullshit.
But in the scenario I gave the driver DID react properly. The break was applied and the car brought to a halt. It didn't stop damage being done or a dangerous situation from occurring.
Same thing with sudden acceleration. A driver can react appropriately and the condition can still be incredibly dangerous or even deadly.
> Instead, what is the obvious answer is that panicking drivers hit the throttle when they meant to hit the brakes.
Saying something is "obvious" when it is disputed just makes you sound arrogant and dismissive. Many experts don't agree with your "obvious" conclusions.
> Especially since at least one of the drivers testified that they hit the brakes and it was unable to stop the car, which is total baloney.
You're again contradicting the experts. They said that it is possible for the car to ignore brake input, but were unable to determine how corruption could have occurred to cause it.
I'm not saying I know for a fact that unintended acceleration occurred and that the brake was ignored, I do not, nobody does. But I think the way you're dismissing it and stomping all over a dozen or more experts is absurd. You cannot know it didn't occur any more or less than they know it did. You certainly don't have the expertise for your "obvious" conclusions to be meaningful.
> EDIT: Also let me just state as a disclaimer I do not work for Toyota, never have, don't know anybody who does, I don't own any Toyota cars and never have. I just can't deal with people spreading bullshit.
Right... And you essentially saying that the conclusions of experts in the field is wrong without any proof, cite, or good explanation definitely isn't "bullshit."
The fact you need a disclaimer saying "I am not a shill" (paraphrasing) means you yourself must know how absurd you're sounding here.
No one who is actually an expert in cars would say this because the cars in question did not have purely drive by wire brakes. There's literally no way the car could "ignore" brake input unless the hydraulic system failed, which the driver should have noticed the moment they got in the car.
The brakes in 2004 and newer models are controlled by the computer. It controls the hydraulic pressure to the brakes to maximize the amount of work the regenerative braking system can do. It uses a pump and accumulator to store hydraulic pressure, and solenoids to send it to the brakes as well as provide pedal feedback. The only time you directly control the brakes is if the main system loses all accumulated pressure. Until then, you're just sending pedal input to the computer and it does what it wants.
Some cars have a sensor to detect if you are overlapping the throttle and brakes and will cut the throttle if the brake pedal is detected as being pressed. This can frustrate people who attempt to match revs on downshifts in manual transmission cars.
No doubt there are accelerator-brake confusions in many of these cases, especially with older drivers. I'm really hesitant to say they all are in that category. Investigators need more "black box" info to see, for example, whether the accelerator and/or brake were being pressed in the seconds before an accident.
Not that many people are getting killed, so it's an acceptable tradeoff?
Thanks for posting.
I think part of the problem is that software development isn't considered an engineering discipline and code of engineering ethics goes out the window.
It IMHO shows a failure of the type approval process, maybe it didn't evolve enough with regard to the amount of software used in safety critical components. Inspiration from aircraft certification would likely be mùore than welcome in that regard...
Open source would be "nice", but it's just the training wheels, while safety and security baked into the process is the front tire. Might help it from not falling over but you're not going anywhere in the right direction without the right foundation.
In comparison, it took multiple deaths and a major lawsuit to create the same level of visibility into Toyota's codebase. And what reviewers found was code quality far worse than that of OpenSSL or bash.
Someone else said this in another HN thread, but I love it: imagine a world in which Consumer Reports car reviews include a code audit report. That would be far, far better for overall safety than the current situation.
I just think that going Open Source won't magically fix things. ShellShock and Heartbleed were out there for many years before someone reported on them, with (AFAIR) evidence of those holes being exploited by malicious actors. Trying to force a switch to Open Source won't improve situation very much, while requiring a serious overhaul of how the entire world does business. It doesn't seem to be worth it without introducing additional ways to fix the software creation and testing process.
Because it's open and findable. I think that was the point.
It looks like at least having the source available made it easier for the good guys to discover the bug.
Instead, what gets examined are the artifacts like requirements documents, the results of tests, specifications and such. This allows poor code quality to be hidden, and, to some extent, encourages sloppy development practices (especially when time is critical). Exposing the code to more people will have several effects, but the main two (from my perspective) are:
* Developers won't release as much bad code, either due to pride or insistence from their management.
* Bugs may be more easily discovered and diagnosed if the code is available. As it is now, it's a black box. So if I find an issue I may be able to repeat it, but I can't examine the code to see why it's actually happening or to correct it.
If OpenSSL was closed-source my servers would probably still be vulnerable today.
Curiously the chief engineer I knew at a major car service center, also felt the same way.
And that's not even touching on the insanity of building computerized vehicle systems with always-on GSM data links to the Net. Ask Michael Hastings how that worked out for him.
Also I agree that critical systems software should be legally required to be open source.
Servo power steering is acceptable, though my present car (1993 Subaru stationwaggon) has direct steering, and I prefer that.
It's really hard to find cars with curtain airbags though without electronic accelerator and fake steering.
Because the way I see it power steering itself is just as mechanical as hydraulic brakes; and electronic steering is a far more recent development than throttle-by-wire.
If you're willing to accept power steering it's not too hard to find vehicles w/ side curtain airbags. Lots of '01 Toyotas had side curtain airbags, and it wasn't until '02 that they started putting drive-by-wire in the Lexus lineup (much later for the rest of their lineup, I believe it was phased in over '03-'05 for Toyotas.)
I adore my '01 Camry. The 5S-FE is a bit sluggish compared to modern powertrains, but its bulletproof, insanely easy to work on, and drives quite smoothly. It'll be a cold day in hell when I have to replace that car with a glorified playstation controller.
My steering works even with when the power assist fails, though it is much harder to turn at low speeds/standstill.
I'd hazard a guess that in a serious crash you're going to have a far better chance of survival in a modern car (crumple zones, airbags/side-cushions/curtains, ABS etc) vs a ~1980's or older car, and that the cause of said crash would be human error rather than a bug in the engine throttle code.
It'll come at a point when those cars will be unmaintainable, hard to aquire, expensive. I want to see if you'll still have the sae stance then. What if in 30 years it becomes illegal to drive your own car and can only use SDC's, will you still pine over the good old mechanica components then?
What I don't understand is how you can rationalize your preferences by thinking these old cars are safer because they don't have any software-defined points of failure. The chances of dying in a car accident because of driver error (by yourself, or by someone else) or mechanical failure (because of worn-out parts) are infinitely higher than by some kind of electronic failure. And if you end up in crash, your chance of survival will be much higher in a modern car, because of all the safety measures that have been added over the years. So IMO it doesn't make sense to stick with the things you've mentioned if safety is your primary concern.
The ECU however, was probably made ~10 years ago by a team of highly incompetent software developers trained as electronics engineers, with no access to any previous attempts by other companies and progressively getting worse over time (instead of being perfected). To make the ECU do something it wasn't made to do all it needs is a mere low voltage event just enough to flip a crucial bit, and many bits are crucial.
Not that I don't agree that it's silly to not drive cars with an ECU, but just saying that his point has merit.
Modern cars are vastly safer. Demonstrably so.
Computers in cars may make them more dangerous. But this is far outweighed by the greater overall safety in the cars that have them. You can't buy an otherwise modern car with no computer control, so your choice is either to buy a modern car with computers, or buy an old car without them. If you're avoiding computers then you're buying an old car, and the result is greatly decreased safety.
This is typical human risk management, of course. The mostly imaginary scenario where your ECU goes nuts and causes you to crash helplessly into a concrete barrier is assigned great importance, where the sadly common scenario of some drunk or texting (or drunk texting) idiot killing you in an accident that modern safety design would have allowed you to walk away from is assigned very little importance.
It's much like people who are afraid of flying but are happy to drive, because the thought of plummeting to their death from 30,000 feet is much more vivid than the thought of being randomly run over by a tractor trailer even though the latter is much more likely.
One was rushed to the hospital with a skull cracked like an eggshell. Almost fully recovered except he can't smell anything.
One had a tractor/trailer fall over while turning a corner, onto his car. He happened to lie in the gap between tractor and trailer, leaving a little uncrushed cell with him in it. No injury.
One was slowing to turn right on a highway; sleepy tractor driver ran fullspeed into the back of his old American car, crushing it utterly up to the back of the front seat. Unhurt. So old American cars have something going for them?
Your second story is pretty amazing! Sometimes it's all about luck.
Analog toaster and refrigerator technology has been working quite well for us for almost a century.
In the olden times, the throttle was controlled by a mechanical device and tensioned springs. The failure characteristics were studied for 150+ years, and the state of the mechanical components could be assessed by visual or physical inspection. The failure scenarios for open throttle are also non-obvious things to workaround. What do you do? Pump the brake? Take the car out of gear? Depress the accelerator to reset? Turn the key? It's a complex decision matrix with life-and-death consequences, and the correct answer will vary by car configuration and vendor.
The ridiculous positions taken by posters here are indicative of how engineering fail like this happens.
The number of incidents related to speeding Toyota's is pretty insignificant to that number.
Yes it has an ECU, but EFI is not the problem in my opinion, and the computer by itself doesn't frighten me. EFI was a fantastic invention as far as I'm concerned. Also despite it being a "black box" I find it much more pleasurable to tune and maintain EFI systems over fickle carburetors.
The real problem was making the ECU an _active control system_ which directly controls the engine, throttle, brakes, etc. in response to your inputs; as opposed to a passive one which merely _reacts in response to changes in its environment_ (e.g: more air moving through the intake, wheels locked up, losing traction on one side.)
So yes, my '01 Toyota has a black box, but it's simple enough that it could be replaced by a handful of aftermarket controllers, many of which have their source freely available, or available for a modest licensing fee.
---
Also I'd like to disagree that reacting to WOT is a "complex decision matrix." -- My instinctual reaction would be as follows.
First you open the clutch and/or put the car in neutral. Disconnecting the motor from the wheels is the most reasonable solution to this problem. When I was taught to drive stick the very first thing I was told, before I ever moved the car an inch, was: "when you need to stop, clutch and brake."
(Of course if it's an automatic transmission: "going into neutral" is just controlled by another black box. Sucks to be you if you hit deadly bugs in two separate powertrain management controllers.)
(As an aside I do personally know people that commute every day in the US, and they don't even know what a transmission does. Why are we licensing these people as skilled motorists?)
If I somehow found myself without even the most basic control of my transmission then you just press the brakes as hard as you can and you stop in ~300 feet.[1]
If that didn't work, or if I had stopped but hadn't regained control of the vehicle, I would then kill the ignition. (To be fair: I'm told this is not quite so simple in modern cars! Apparently someone thought "pushing and holding a button for 3 seconds" was a better idea than "turn a key." -- However I also wouldn't agree to drive a car if I didn't know something as basic as how to kill the ignition under duress. I'm the sort of guy that reads the manual cover to cover for fun.)
If killing the ignition doesn't work[2] and your transmission is somehow stuck engaged then today is really not your day.
I don't see how any of this requires any more skill than driving does normally. To me this is not some complex decision tree, it's reflex at this point.
(Also there is a good reason I would brake before killing the ignition. Brakes and steering are mechanically assisted by the engine. It would be extremely irresponsible to cut the ignition in a vehicle w/ power steering and power brakes on a public motorway in my opinion. -- Again I don't think this is some complex decision, I believe it should be requisite knowledge for being licensed to operate a motor vehicle under such conditions.)
tl;dr: the complexity in this matrix is inherent in the task itself. If this is "too complex" then maybe we should work to improve our driver training and licensing programs; or better yet consider having more people take public transit, instead of handing out licenses like candy.
[1]: http://media.caranddriver.com/images/media/51/braking-result... [2]: https://www.youtube.com/watch?v=3NRaqgab0_w
You know, that's not completely insane: https://en.wikipedia.org/wiki/General_Motors_ignition_switch...
Although, wow, that's an awful article, skimming it there's only this hint of the root cause: "After being asked by Missouri Senator Claire McCaskill whether a GM engineer had apparently lied under oath, [GM CEO] Barra confirmed that this had indeed happened (or at least seemed to)." The problem, besides GM having a procurement system that assumed people in it wouldn't lie through their teeth about lethal problems, was a single engineer who selected an out of spec switch, and then, for example, slipstreamed a better one into the system without a part number change.
(Otherwise we're in total agreement.)
Thing is, if attackers that advanced are out to get you, you're pretty much screwed regardless.
Had Hastings been driving a classic car, I'm sure he would have suffered a tragic drug overdose or something instead.
Besides, even if your car isn't computerized, there's plenty of others on the road with you that are.
On top of that: pilots of any caliber undergo far more rigorous training than what is required of a licensed driver in the US. They routinely have to train for the autopilot systems they use, etc. -- I trust a pilot to react appropriately when the fly-by-wire system goes haywire moreso than the average driver.
The automotive industry has quite a ways to go before I'll consider their safety critical engineering to be anywhere near the level of robustness present on even the oldest commercial airliners in service.
Actually, for the division I used to work for, a lot of the people programming ECU's for cars came from aerospace. They built radars for planes, now they build radars for cars.
Also, the safety of the systems tends to improve with time, as technology matures.
Also, another interesting anecdote, the Flexray communication protocol used more and more in cars these days was first used in planes.
i.e. brakes on cars are not designed the stop the engine but to absorb the vehicle's momentum.
This will have the effect of reducing the power assist, which is already reduced due to high revs / low vacuum.
Preventing the wheels from locking up under hard braking is crucial to stopping when you have little traction. To provide traction on any surface _wheels must keep rolling._
When wheels are static their contact patch is effectively the size of a hockey puck, that little bit of rubber is not very good at stopping a car going 80MPH. Not compared to disc brakes w/ ceramic pads bleeding off all that energy, at any rate.
While I'm on the subject, I'll take this time to drop a PSA: on ice, where ABS is most helpful, the rubber of your all season tires is about the consistency of a hockey puck. -- Please invest in actual winter tires if you get regular snowfall.
(Also if you live in Texas: invest in a set of winter tires anyways and go have a blast when the streets are deserted.)
If your car starts accelerating in an unintended fashion, you should push the brakes to the floor and keep them there, then if you have time shift into neutral and turn off the ignition (this shouldn't be necessary, but will help).
Many drivers won't actually do this in the heat of the moment, though, thus many deadly crashes.
While you're at it, read the FDA list of food and medical recalls too, so much risk!
People are still buying and driving Toyotas.
When the VW emissions thing started making its way through the news cycle, I read comments postulating that this might be the end of VW. Hah - people are going to forget about VW just like they forget about everything else.
It wasn't the end of Toyota, and it won't be the end of VW; but it was the end of Toyota's goal to be the Biggest Car Company in the World[1][2], and it may be the end of VW's goal to be the Biggest Car Company in the the World.
Being #1 volume vehicle manufacturer is a curse!
1. https://hbr.org/2007/07/lessons-from-toyotas-long-drive - Interestingly, in this article Mr Watanabe claims that Toyota never had the goal to be the biggest car company.
2. http://www.economist.com/node/15576506 - James Womack, one of the authors of “The Machine that Changed the World”, a book about Toyota's innovations in manufacturing, dates the origin of its present woes to 2002, when it set itself the goal of raising its global market share from 11% to 15%. Mr Womack says that the 15% target was “totally irrelevant to any customer” and was “just driven by ego”. According to Mr Womack, the requirement to expand its supply chain rapidly “meant working with a lot of unfamiliar suppliers who didn't have a deep understanding of Toyota culture.”
Disclosure - I work for GM, these opinions are my own, etc.
It's like the worst internal shit code you see in the in house tools at many companies where the moment it ran it was considered done enough.
Oh my.