Model X Crash – Open Letters Between Driver and Tesla
teslarati.com
teslarati.com
This line of Tesla's letter back to the driver caught my eye;
The diagnostic data shows that the driver door was later
opened from the outside...
That is pretty impressive that diagnostics are not just logging that a door was open, but which handle was used to open it! I guess Tesla has had enough issues with their retracting outer handles to warrant some additional diagnostics in this area, but those logs sure do come in handy.In the Florida case they say 'who knows?'. How many seconds did the guy in Florida not have his hands on the wheel? How many alarms were sounded? What did the radar detect? What did the sonar say? Nothing.
If Tesla wants to be trusted they need to give out all the relevant information for all crashes, including timestamps, not pick and choose crafted statements that make their PR department happy.
[1] http://www.ntsb.gov/investigations/accidentreports/pages/acc...
Since the system didn't detect any danger, I think it's safe to assume that no alarms sounded. Hands on the wheel isn't relevant, since the problem wasn't one to be solved with steering.
Aside from timestamps (which don't seem particularly useful here), this seems to include just about everything interesting.
Has Tesla or NTSB actually said that? From ref. 1, published today, my emphasis:
Tesla *is considering* whether the radar and camera input
for the vehicle’s automatic emergency braking system
failed to detect the truck trailer or the automatic
braking system’s radar may have detected the trailer but
discounted this input…
[1] http://finance.yahoo.com/news/tesla-mulling-two-theories-exp...https://twitter.com/elonmusk/status/748625979271045121?ref_s...
I don't think it matters much. The main thing is that the system didn't detect the trailer. Exactly why it failed to detect the trailer is interesting, but doesn't change anything about fault or responsibility. And if Tesla is still considering the possibility, then apparently it's hard enough to figure out that just releasing logs wouldn't help us.
Has that information been made public? Unless it has, that statement would also appear to be speculative at this point.
> Exactly why it failed to detect the trailer is interesting, but doesn't change anything about fault or responsibility.
I would say that it is far too early to make that declaration, given that the investigation is ongoing.
"Neither Autopilot nor the driver noticed the white side of the tractor trailer against a brightly lit sky" - https://www.tesla.com/blog/tragic-loss
I have trouble imagining the underlying reasons for this being particularly interesting. I guess if the lighting was so bad that even the driver couldn't see the trailer then that would excuse him from fault, but I don't see how it changes Tesla's role in it.
I think there's a lot to be concerned about wrt. AutoPilot and I plan on thoroughly reading the completed investigation reports.
I don't see why they have to wait for an investigation to talk about what the car did, nor about what the driver did with the car. They have all that information. The purpose of the investigation is to contextualize that information and incorporate external information like the speed and position of the truck in the time leading up to the crash.
He could have had a medical complication. He could also have erred in thinking that the trailer would have cleared the path in time, or in thinking the car would have braked for him, or in perhaps his reaction time was insufficient. I have no idea. None of the items on my brainstormed list strike me was weird.
> I don't see why they have to wait for an investigation to talk about what the car did, nor about what the driver did with the car.
Tesla doesn't have to, but the skeptic in me observes that it is all too easy to spread misinformation (that would benefit them) through the technology press before the investigation is completed. I personally don't see an advantage for Tesla to speak at this stage since there are serious product liability issues in play, but I admittedly don't get Tesla in general.
Something to consider is that a "good" risk analysis takes into account the foreseeable use and misuse of a product based on the information available. Given that it is no secret that AutoPilot users have used the system contrary to directions, it is reasonable to demand that the risk analysis be updated to account for this reality (assuming it did not account for this) as part of the continuous PLM process.
To posit a deliberate conspiracy to obscure unflattering facts seems unnecessary when the company and Musk himself have faced up to unflattering facts before — largely in order to publicly spin them in a positive light, admittedly, but the facts weren't suppressed.
It does appear, so far, that these "log dumps" are being carefully sifted through and cherry picked for release.
From a code perspective, I know for a fact that it'd log which handle was used to open a door, just as reflex programming. The same way I'll log a user ID or any potentially useful value in scope for debugging.
Tesla also says that there was an "abrupt steering action" that preceded hitting the first post, and that the car was not auto-steering at all for the other 11 posts. There's some fuzziness in Tesla's description. The implication is that the driver hit the brakes immediately, but it's only an implication. No timestamps are provided, nor clarifying language beyond the broad implication.
I'm generally thinking Tesla's information is probably correct, BUT I'm really, really, really tired of hearing about how two seconds of no-hands is somehow unreasonable, when the car itself allows for much, much longer. If you want to say that someone has to keep a hand on the wheel, have it beep and prepare to disengage after two seconds of no-hands, not 15 minutes. If you allow for 15 minutes, don't be shocked when people use all 15 minutes.
As road conditions became increasingly uncertain, the vehicle
again alerted you to put your hands on the wheel. No steering
torque was then detected until Autosteer was disabled with an
abrupt steering action. Immediately following detection of the
first impact, adaptive cruise control was also disabled, the
vehicle began to slow, and you applied the brake pedal.
It's actually not clear the order of events from Tesla's letter, but I read this to mean the abrupt steering action came after the first first impact.The car starts to alert you by beeping when it doesn't detect hands for a few minutes and displays a message on the dash to grab the wheel. It does this a few times (every ~10 seconds I think) after which if there are still no hands on the wheel, it starts to slow down and come to a complete stop.
In this case, it looks like the driver disabled Autosteer by abruptly tugging on the steering wheel after two alerts.
When I purchase a $100,000 vehicle, I want the vehicle to act under my control. Not under Tesla's control.
The sensor data belongs to Tesla, not to the customer. And Tesla uses the sensor data to serve their Public-Relation benefits instead of helping the individual customer.
> When I purchase a $100,000 vehicle, I want the vehicle to act under my control. Not under Tesla's control.
I feel the same way, and kind of find it intrusive that Tesla can seemingly obtain this data at will without my explicit permission.
It probably is - but that doesn't make it feel better. I want to explicitly allow log collection upon request, or disable it completely.
Where my car goes, how fast it was driving, which window I had open, whether or not I was listening to AM or FM radio - is frankly none of Tesla's business. As it is - these logs are seemingly only used to defend Tesla's PR - which as a simple customer, is not something I'm interested in.
why not publish the video from the car's Autopilot for say last 30 seconds?
Looking at the photos, the road seems straight and with proper lane markings well visible. Though, given that it was 2AM, may be Autopilot has issues at low-light - if say they use narrow lenses (for cost as well as depth of field reasons) then it would mean more sensitive sensor (more noise) or longer exposure (less FPS) and relationship of colors of objects are different when illuminated by headlights instead of Sun - all this making it harder to discern the objects. Yet it all would be just a technical reasons that should have been solved before product release.
that is really hard to believe. Given how useful dash cams are in cases of accidents, etc..
>and not enough storage in the camera module to save it there.
and how all these dash cams do it? Storing 8hrs or more. If Tesla didn't put an SD card there, it sounds really not smart.
To "mikeash" below: thanks for the link. It does seems like a small camera (thus one can expect low light issues). So Tesla uses 3rd party system - no miracles here, i hoped that they developed their own and thus hoped that they would improve it fast. That using of the 3rd party system explains while there are a lot of things missing that one would naturally expect in the sensing system of an "autopilot" functionality. It is also explains why they are so defensive instead of just going ahead and fixing issues.
What functionality is missing that you'd expect it to have? For the small number of sensors Tesla has (one camera, one radar, a dozen short-range ultrasonics), the system is amazing, and it's the best one commercially available right now (as verified by many independent tests, that's not just Tesla talking).
The system is from Mobileye, which is currently the best in the business. I don't see why this would hurt improvement (the system has improved dramatically through software updates) or why it would make Tesla defensive. It's not like they've tried to hide the fact that Mobileye provides the camera and image processing hardware.
(Note that Tesla has parted ways with Mobileye and the next generation of Autopilot is going to be a Tesla product. Not sure why, but it sounded like Mobileye delayed their next generation hardware too much for what Tesla wanted. But not really relevant to the current hardware.)
I think we have completely opposite understanding of things here.
>What functionality is missing that you'd expect it to have? For the small number of sensors Tesla has
exactly - small number of sensors. That is one of the main deficiencies.
>why it would make Tesla defensive.
because they can't improve it.
OK? I'm telling you how it actually is. The system works better at night, because there's better contrast. At night, the lane markers are lit up by your headlights, and the road is very dark. During the day, the difference in color is much less distinct, and as such the system doesn't perform as well. I've seen this in action with my own eyes during thousands of miles of Autopilot driving.
The small number of sensors has nothing to do with using Mobileye technology. Tesla easily could have incorporated multiple cameras or radars, they just didn't. And that's not missing functionality, that's missing hardware. You haven't given me any functionality you expect the system to have that it doesn't.
"they can't improve it"
Of course they can. Did you not read the part in the comment you're replying to where I said, "the system has improved dramatically through software updates"?
I don't mean to offend you with this question, but do you actually know anything about this stuff, or are you just guessing? It's getting tiresome to correct all of your incorrect statements.
http://skie.net/skynet/projects/tesla/view_post/7_Autopilot+...
I'm not entirely sure what the connector is, but I'd wager it's a standard CAN bus, which wouldn't be suitable for video data.
Dash cams do it by recording to a big SD card. I have a 32GB card in mine. Obviously Tesla could do something similar, they just don't.
If I'm reading this correct all the crashes against the post are supposedly with the drivers hand on the wheel? If thats the case then maybe the owner wasn't aware of the logging when he tried those claim.
I also depend on application log being correct but errors in logging is a scary thought in the sense that how hard it would be prove (or near impossible) that what you are saying the truth. And even beyond weird bug what happens when malicious actors change computer record and takes away all our proof of innocence (aka The Net). I wonder if there is really solid protection against such act possible. I want things more accessible but can you truly make accessible + safe work together (not necessarily now but long in the future). I do sure hope so.
(I don't believe Tesla has ever tampered with or lied about what the logs say; this would merely address folks who have such doubts).
It's wouldn't be possible to say for sure whether the driver or the log is correct unless the sensors are physically recovered and tests.
Well, which way did the driver steer? Away from the barrier to avoid more damage, like he claims, or into it causing the accident in the first place? This statement is ambiguous and I get the feeling from reading the whole PR response that Tesla is either omitting or cherry-picking information to obfuscate the truth.
Mr. Pang states that:
> the car suddenly veered right
And later that he: > managed to step on the break, turn the car left and
> stopped the car
So, that's __two__ steering motions (one to veer right and another to turn left and stop.)Tesla only says:
> No steering torque was then detected until Autosteer
> was disabled with an abrupt steering action.
> Immediately following detection of the first impact,
> adaptive cruise control was also disabled, the
> vehicle began to slow, and you applied the brake
> pedal.
That's one steering motion -- no indication of direction or magnitude. Also, Tesla's language deliberately avoids ordering the events. Since the "steering action" appears first in the paragraph, it seems as though this happened before the impact. That information is not actually encoded in the article, but a reader would naturally assume this is the case (I know I did).Short of a publicly released log file or an investigation by a third-party, I don't think we'll ever know the truth of what happened.
For Model S/X, you need a proprietary device to connect to the car's ethernet port (it may be possible to build your own -- not sure if they are encrypted), or you need Tesla to download them and hand them over. Tesla has told me that they will only release logs when ordered to do so by a court, but that they will download and hold them locally upon an owner's request, so that if you think you will have a legal need for them you have time to make that request before they get pruned/deleted by the car.
[1] https://upload.teslamotors.com/
edit: Differentiated between Roadster and Model S/X policies.
They might not be doing that, but until and unless they make all data available every time they make any data available, it's a matter of faith.
Police say "oh, you were doing 75mph in a 50? ticket!"... insurance rate hike, etc... how much liability would they be picking up if they exposed all of that, and how quickly would people be throwing a fit about privacy?
I know multiple people (in multiple states) who have been ticketed based on their youtube videos... im sure police would try to use the logs just the same...
And now here we are. I'm not sure why you're jumping to liability questions about logs of speeding and bringing up privacy (amusing, that one, when it comes to Tesla's public descriptions of events in their cars). I think the point is clear. Tesla, either provide evidence for your claims, or stop making claims. Simple.
For example, a few months ago someone drove a Tesla into a wall by flooring the accelerator while parked. They said they had their foot on the brake. I saw a ton of people criticizing the driver for lying. But it's almost certain that the driver mixed up the pedals and really did think they were on the brake. They're not lying, they're just wrong.
I think you meant to say they believe they are telling the truth.
If the car does not detect any steering input, even though it has been given (due to bad software or hardware), or logs a warning being sounded, even though none manifested in the real world, what do we do? How do we know?
Bugs are by definition human assertions of computer failure, the computers can't lie (yet), but they can be wrong.
Are inward-facing dash-cams going to be required so that we have evidience of compliance with the terms of service of our vehicles?
I think it is rather unlikely that a false steering input detection, a false warning log, and a false door-opening log all happpend at once...perhpas not in thic case, but subtle, cascading bugs can and do happen.
Well, until there is a free tool to dump the logs from all of the Tesla cars, and Tesla the company starts releasing the raw data for the public to verify, the more appropriate question is:
Do we trust the man or the company?
Telsa has a _lot_ to lose, so the temptation to cherry pick data points that tell their desired narrative is fairly strong.
It would be easy to correlate one sensor failure and one part of the crash (detected hands on the wheels, kept it going int autopilot - because the sensor failure would lead to the crash)
But to say that sensors failed, then warning sounds failed, then failsafes failed, becomes rather unbelievable.
Also the high drama content of the customer's letter (there is no 50 foot drop off, i just checked on streetview for that entire section of route 2). There is a railroad, then a river, but not a steep drop. Even then, railroads pretty much stop cars dead trying to cross them (dont ask how i know, lets just say a 1986 ford tempo can go from about 45mph to a dead stop real fast)
But since we don't have the logs themselves, every conclusion we come to is pure conjecture and obscured by cloudy language.
2. The driver claims that the warning sound never came on. If the indicator was buggy, logs would not necessarily show that if the car thought it had played the sound but the speaker malfunctioned.
3. The logs haven't been released AFAICT and since Tesla motors isn't under any oath not to lie, there's no proof that they're telling the ttuth here either.
I'm guessing this functionality is because the risk of hard braking at the wrong time outweighs the risk of hard braking at the right time, and so it's better to tell drivers the car will not hard brake, and it's up to them. There must be some trade-off, because certainly the car is capable of hard-braking itself, it's just a matter of ensuring the software only does it at just the right times.