“Durable Computronics”
github.com
github.com
They don't.
Computer engineers, electrical engineers, mechanical engineers, aerospace engineers, and probably more that I'm not specifically familiar with, design things like: cellular antennas, CPUs, rocket engines, spacecraft, EV charging stations, etc without these heavyweight certification structures. I tend to think we're better off without all that unnecessary red tape. There are better ways IMO to ensure that critical systems are engineered properly than to make engineers pay to take tests and pay license dues. I am also not generally a fan of saying that some body is in charge of all engineering standards for something.
> [Engineers] … design things like: cellular antennas, CPUs, rocket engines, spacecraft, EV charging stations, etc without these heavyweight certification structures.
Correct, this is the current reality, which I agree is very distinct from what I describe in this fantasy worldbuilding exercise.
Industries should play to their comparative advantages. A huge and mostly untapped comparative advantage of computers is that they reify formal systems, completely unlike a suspension bridge or an office building. If your vision of the future of computers doesn't take that into account, it's worth little.
If a system deviates from its design, the contractor becomes
liable for any such failure, whether related to the specific deviation
or not.
This seems a recipe for an eternal blame-game where the "engineer of record" aims to produce a plausible-but-impossible specification and manufacturers spend 99% of their time looking for loopholes.If your aim is to explain why your scifi setting has an entire planet covered with a kilometer-thick layer of used triplicate forms, this would be a great place to start. :P
If we are talking about electronics, then yes, the current reality is that EE stamps are generally not needed in the legal sense. This thing I wrote is a first step in imagining what sort of world would exist if electronics and software engineering had a legally-required PE level.
I expect that we will see quality management going the other way. Deriving new and more capable ways of dealing with the complexity of modern technology stacks. Then those methods backpropagate to how we manage other complex systems. As we saw with the 737 MAX, in many cases the "engineer signing off" is merely a figurehead/scapegoat. Could one person realistically know the details of every system (to a detailed engineering level) in a modern airliner? Even if they could, is that the best approach?
Our methods for durability are already overextended. Technology will be the area that makes us admit it, and provides the tools to manage it better.
In my opinion, the closest analogy is that of electrical power. In that world we have circuits and protection systems that have been standardized. The user interface at the end is an outlet of some form on a wall in a room. The circuit it is part of is protected against overload, and WILL NOT deliver more than the rated breaker output for more than a few cycles.
Any Operating system has to at minimum, provide such a way to run a program. Our current options, Linux (even SELinux), MacOS, Windows, etc. do not offer a way for the user to dynamically assign processing time and resources (such as files, network addresses, etc) to a program.
Actually it will, and it is required to do so. There are different classes of fuse and circuit breaker. The time to break the circuit depends on the class and the percentage overload, but think in terms of seconds to minutes, not cycles.
The rationale for this is:
A) With modern PVC insulation, the limit on continuous current is the continuous temperature. If it is too high, the wire core will slowly migrate through the PVC. Anything up to 90℃ is ok (British standards - and yes, I did check that!). Higher temperatures are ok for short periods because there will not be time for migration, but obviously you don't want to run it hot enough to cause fire ok allow fast migration.
B) Electrical motors can have high inrush current when they start, but only for short periods. It makes more sense to dimension the wiring for the steady state, and use a show blow fuse or circuit breaker to guard against stall conditions.
Still, the analogy is a good one. A few years ago I built a garage and had to have a Part P inspection done on the wiring, which included showing calculations which take account of the thermal environment (in free air, on wall, in tube with/without other cables etc.) and cable type to determine the maximum permitted current for that circuit. There was no "consenting adult" exception (although our legislation expressly permits non-professionals to do the job subject to Part P inspection).
The new arc protection breakers look interesting to me.
Of course, history didn't quite work that way, what with the proliferation of microcomputers - though sometimes I feel like the modern trend of web applications has managed to sloppily reinvent that idea.
How can this ever make sense? So if a bridge fails because the supplier of rebar messed up the heat treatment, the bridge designer is liable? What this means in practice is no systems larger than those that can be practically understood by a single person - possibly from atoms and first principles - and no systems that can't be audited by one person in time shorter than the project would become irrelevant.
Speaking about real world manufacturing: I'm ignorant of the details but I would assume there's some construct in law or regulation for liability to be assigned back "up the chain" if due diligence in statistically sound testing "down the chain" is demonstrated.
And yes, you’re probably right that systems would have to be much more legible. I’m interested in imagining what that tech landscape would look like.
> So if a bridge fails because the supplier of rebar messed up the heat treatment
Is a failure of a bridge necessarily a failure in a design? Or do we distinguish between a physical project which uses a design from the design itself? If the materials were bad, whether or not the construction team had some responsibility to re-test those materials prior to using them (is this common?), it doesn't seem like evidence that the _design_ failed.
If I'm reading the article right, "design" would encompass interaction boundaries as well as things like CPU/memory requirements, information storage, and security.
As someone who also does web development I know that this degree of liability is completely foreign to a big part of the software world, and IMO this is an part of the reason software still sucks big time in terms of efficiency, reliabilty, safety and security.
Because if you have to think about liability suddenly the simple rugged system starts to look lot more attractive.
At one point you learn to shrug it off and make notes to maybe revisit the code one day and fix the dangling bits. Alas, that time almost never comes because people get demotivated and leave the companies. Which is very normal.
1. Wordpress, being an example of thousands: https://cyraacs.com/privilege-escalation-by-exploiting-wordp...
That maybe used to be a good example of "durable computronics". It's increasingly not true. Seems to be for a variety of reasons though, not just one. Things like DRM, lower expectations of usable lifespan of a car, higher performance needs for complex safety systems, expectations around things like large displays, etc.