For example, if something goes wrong with the processor on your industrial robot arm, you just stop all the motors and activate all the brakes. No need to figure out which of the processors is right, have an engineer come out and fix the bug that caused the disagreement.
On the other hand, if something goes wrong with the processor during your space shuttle launch, it would not help to turn off all the rockets - better to have an election algorithm so things can keep working.
Is a self-driving car more like the first case or the second? Depends if the driver is ready to take the wheel :)
There are far too many situations where a switchover time of [user initial reaction time + initial response time] is high enough to be rather dangerous.
http://www.freescale.com/webapp/sps/site/application.jsp?cod...