Edit: and to be clear, we're not talking about holding down a resetable circuit breaker to avoid being late, we're talking about the rail network of an entire nation being inoperable for a day.
Edit: and to be clear, we're not talking about holding down a resetable circuit breaker to avoid being late, we're talking about the rail network of an entire nation being inoperable for a day.
You can never know if the primary safety system is functioning perfectly, so you need other systems to be there to step in when the primary fails unexpectedly.
If you detect the primary system has failed, isn’t it reasonable that you should stop operation as quickly and safely as possible, and be thankful nothing bad happened while you lacked redundancy? Any SPoF could be fatal for hundreds of people.
This isn't some consumer appliance where you have to stupid proof every inch of it. These systems are bespoke and their architecture is mostly a matter of business decisions and not at all a matter of the internet peanut gallery trying to figure out how safe they can make it.
Calling me a ”clipboard warrior” isn’t furthering your argument, though.
This comment provides an excellent example along the lines I was talking about: https://news.ycombinator.com/item?id=30902016