January 13, 2023


No software updates for critical infrastructure should ever roll out to the entire user base simultaneously. Will have to treat users like lab rats- software updates go to a small random subsection of customers and wait to see how many rats die. This will catch some of the inadvertent mistakes, but not the bad actors who will leave a trojan horse in place until they are ready to bring down the fleet.

We need fail-soft systems. An escalator fails-soft into a stairway. An elevator fails-hard into a prison cell. A single emergency button to roll back into safe mode?

