It seems that the ability to trivially roll back any update would be a better choice, at least for this. (But I'm sure there are downstream effects I haven't thought about if that were implemented.)
It seems that the ability to trivially roll back any update would be a better choice, at least for this. (But I'm sure there are downstream effects I haven't thought about if that were implemented.)
Giving user’s control over when the update runs allows them to be in a safe and secure setting when that update happens. Allowing them time, gives them and Jeep the ability to slow roll the update so they can halt it if initial feedback is negative.
I say this as a Mac user who does not allow auto updates for MacOS. I wait a week or so until the chatter validates it as non-breaking. They pushed an OS update several years ago that broke a few things I rely on. So I don’t trust them now, but these things just happen on OS’s with third party software. I expect it. But, I also don’t want to be forced to deal with the headaches immediately. I’d rather let the third parties run updates and advise how to deal, before I have to dive into fixing things. With car firmware, there’s really no excuse for this except poor engineering / processes.
FTFA:
> The buggy update doesn't appear to brick the car immediately. Instead, the failure appears to occur while driving — a far more serious problem
And from the GP upthread:
> There is no way to tell if you received the bad update.
> There is no way to tell if you received the 'fix' either.
Many security compliances require auto-updates to be on. It's thought of to be a lesser evil, because many (most) users never update their OS/browsers, which is worse.
If there are security related updates where the risk is severe then they may auto update.
This does not fix any QA process that is broken. And frankly you should not need to update any control unit firmware after it is sold. The fact that they're even doing this is broken.
Unless your Mac is somehow attached to 5000 pounds of metal going 65 on the highway, the same standards should probably not apply.
Oh you sweet summer child
The NASA space probes are constantly uploaded with new software that has greatly increased the scope of their mission.
If they didn't make "safety" right from the first time, why do you think they will do it better the second time, when the fixes are more expensive and the time pressure is enormous ?
...all of which is just an excuse to show this great picture of Margaret Hamilton [1] lead developer on the Apollo guidance system standing next to (and slightly shorter than) the printouts of the source code https://en.wikipedia.org/wiki/File:Margaret_Hamilton_-_resto...
[1] Who was admittedly quite short apparently
I've worked on some interesting software with lives on the line as well and the amount of test code absolutely dwarfed the functional part. I wonder whether at the time of the effort you linked that was already common practice and if it was what the fraction of that code was tests.
Assuming she's 1.65 meters tall and 66 lines per page (quite common back then), at 0.2 mm thickness per page that's 8K pages times 66 lines / page is ~550K lines. Pretty impressive!
The idea that one can create complex bug-free software is a fantasy. The correct mindset is to learn how to deal with failure. (This is how airliners are designed.)
As for cost, surely you can ask Ford's lawyers who worked there in the 70s to give you a good calculation on life vs recall costs.
That is why Samsung push update to disable note 7 even after recalling them.
In Germany we let the Kraftfahrtbundesamt handle this. You are required by law to keep your address updated with the authorities, and all vehicles have to be registered to get a license plate. When a recall for safety reasons happens, the Kraftfahrtbundesamt writes a notification letter, and if you do not respond in time with evidence of having the recall issue remediated by a qualified shop (or doing it yourself and getting a sign-off from a licensed inspector), eventually they write to your local DMV office that can ban your vehicle from the roads, and if you miss that the police shows up at your home and physically removes the license sticker from the table.
And heaven forbid you get actually caught driving the car after having gotten the notification letter from your local DMV. That's automatically felony territory. Our authorities really, really do not mess around.
[1] https://www.kba.de/DE/Themen/Marktueberwachung/Rueckrufe/rue...
No. You test it. And release it if and when it is fully tested. (you know, V-cycle). But we are Agile now and testing is expensive.
Let’s not let perfection obstruct progress.
Yup, my test is not perfect, but "Let’s not let perfection obstruct progress".
In all scenarios, tricky bugs will happen. Something inconceivable will go untested. But that’s not what happened here. This is basically functionality being lost that very obviously should have been tested.
In that sense, they could have made progress. Nobody is expecting perfection. You seem to be hung up on the distinction
I would bet most updates, especially from a company this bumbling, will be more along the lines of increasing telemetry or pointless UI changes than releasing actually useful features and bug fixes.
I certainly wouldn’t accept one while I was still driving the car!