Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

As a general response not specific to this system failure: Train systems are designed to fail safe when not in state and significant safety engineering is done to ensure that if a rail system remains in a known good state over multiple decades almost every potential threat to human life caused by various equipment failure possibilities is quantified and reduced to a level of risk that’s acceptable. (Zero typically, for any known non-adversarial risks.) Many of the pathways in the fault tree involve shutting something down if it’s out of the correct state. So you will see train networks fail safe rather than run in a regressed state since these vehicles with up to a thousand human lives on board drive themselves to some degree in every modern system and we tend to hold them with a level for safety incompatible with easily winging it when something is wrong. This absolutely makes the system more brittle and less resilient, but for the most part it’s the tradeoff we accept in most modern rail engineering projects which are designed with the goal of reducing human loss of live to zero over the entire span of the system’s operational lifetime.

That said, train systems themselves usually maintain a ton of active operational procedures that remain part of staff training which would theoretically allow them to be more resilient and these procedures are kept current and you will often see them used in emergencies. I.E. on automated systems, trackway signaling often exists in the “not lit” off state and if the automated train control system failures, is often capable of lighting up for human controlled movement (usually required to be done at reduced speeds) of the trains during irregular operations like bringing stuck trains to the end of their lines and letting the people in them out at the next station. And any trains that still have a human conductor in a cab (or a cab for a human conductor at all) have procedures for that human to operate the train directly, even on segments of track where automated train control otherwise control all train movements.

We could try and run these systems in these degraded states under these emergency procedures, but most modern systems have safety analysis and engineering which focus on bringing the system to a safe halt state while fixing the underlying issue and returning to full operational state rather than messing around with rolling along in degraded states with unknown but assumed to be increased potential for catastrophic engineering failures with outcomes including loss of life.

(In the US it is generally illegal for a human being to operate a train unaided by some form of train control above 79mph. Most other systems have similar rules. We no longer trust humans themselves to operate these vehicles just because so many human lives can be at stake when they fail.)

Source: I did a stint working on system security and a little bit of electromagnetic compatibility safety engineering for rail systems. It was enlightening to see how the capital E engineers I was working alongside handle these concepts and design risk out of modern systems. The bulk of my work was in the US but the parts that weren’t were on systems that spanned multiple continents and/or train cars which were distributed worldwide. (To my knowledge none of my work has ever related to system discussed here.)



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: