> Imagine getting into your car and having it say “Oh! Hey. I’m faster now than I was yesterday. You’re welcome!” Because that’s what’s happening.
Yes, that is awesome.
But on the other hand, in the past I've had updates to my TiVo and my PS3 where I turned it on and it said "Oh! Hey. I'm shittier than I was yesterday. Suck it."
And someday, that could happen with Teslas, too. Updates are a mixed bag.
"This car will never speed in construction zones anymore"
"This car is now property of pWnz0r. Pay 20btc to {address} to reclaim your car"
"This car will only fill up at TSA approved electric stations"
"This car will not turn on for anyone with a recent DUI"
"This car will not turn on during the Snow Emergency"
Some of these are probably not risks given the current capabilities of Tesla's, but future cars might have enough cameras and sensors to enforce such updates.
Future generations will have all sorts of amazing technology and vehicles, but their experiences and freedoms will just never match what we have today...
to them we'll be bad-asses who lived danger ever minute of every day on our terms. The way we make movies about the future they'll make movies about our time. And the few of us still remaining we'll make up all sorts of stories to make it sound like everyone alive was an action star. They will be repulsed by what they have become.
that or...
to them we'll be wreckless and inefficient neanderthals. They'll be just happy to have their governments. Like having this monolithic antivirus installed on society, to keep everyone 'safe'.
same as you can have, just stand up and walk away from treadmill... oh wait, cash, security, not dying from appendicitis and whatnot is so comfortable, right? :)
You can walk away from the treadmill.......and still have cash, security, and not die from a healthcare issue. Live below your means, save, invest, and then move somewhere nice but with a lower cost of living (Costa Rica, Panama, and Uruguay are my short list).
This will not happen if you live somewhere paying $3K/month for a studio though ;)
>to them we'll be wreckless and inefficient neanderthals. They'll be just happy to have their governments. Like having this monolithic antivirus installed on society, to keep everyone 'safe'.
Does the current society view the people in the past as wreckless and inefficient neanderthals? On average, no. Sure, we view their lives as more dangerous, but we do not view them as wreckless or inefficient neanderthals.
When I was a kid in the 70's, nobody wore a bike helmet. If we saw a kid wearing a helmet riding a bike, we'd probably beat him up. Today, my wife won't let me ride without a helmet. I've either been civilized or emasculated. In retrospect, I don't think we were neanderthals. But we definitely should have been wearing helmets.
When I was a kid in the 70's, there were three kids in my town who died due to bike accidents. I'm betting that at least one of them would have not happened if the kid was wearing a helmet.
On the downside, there's less cost for being stupid which I think is probably bad for influencing cause-effect considerations, even though one effect is potentially death.
When I was a kid there was no nerf-padded society (late 70's into the 80's). If you made a stupid move on a bike, you bled on the ground and thought it over for a while. From that you got a very real sense of the implications of your actions and relied on your wits more, as not doing so would get you really screwed up.
Ask yourself honestly, are you using your wife as a convenient excuse? Or would you be wearing a helmet now anyway? :-) I'd go with civilized over emasculated.
I think the awareness campaigns of the 80's, as well as generally "growing up", in addition to quite a few near-deadly accidents, have changed my (in hindsight, ridiculously stupid) viewpoint on helmets.
In the last 12 months two friends have broken helmets, but survived. If they weren't wearing them, who knows...
In such a future, Demolition Man may actually have ended up being known as a scion of things to come, Marco Brambilla heralded in the Smithsonian for his foresight and ingenuity in taking on the project.
DJI just pushed an update that enforces no-fly-zones for their UAVs over parts of Washington. You have to assume similar types of things will be pushed to cars as they become more automated and connected.
Already happened, after the Tesla fires the cars quit dropping auto-lowering their suspension on the highways for a while. They eventually added it back as a feature you can turn on with a warning.
There's nothing stopping ICE car manufacturers from doing the same thing. ICEs are run by computers with lookup tables for fuel and ignition timings(etc.) which are often less than optimal and could be revised for both performance and reliability after a model has been in use by the general public.
This is just Tesla being their usual disruptive self. Patiently waiting for a Tesla I can afford.
That is called chip-tuning and being done since years.
The only think is, no OEM does this officially. It is only done by more or less shady third parties. Officially it is done eg. by Brabus for Mercedes, Alpine for BMW, …. But then not part of a retrofit but you have to buy the whole car from them. You can buy it as retrofit from some Russian or other alike.
It is also very common in the industry that the very same engine is used with different algorithms resulting in different PS. Like my Volvo S60 2001 Model uses an engine which was available with 140PS, 170PS and 210PS. The very same engine was used by Ford at that time in different Models with different PS.
Sure, but 1) cars come out of factory with sensible defaults. If you knew what you're doing, you could trade e.g. engine longevity or fuel consumption for extra HP but most people would be better off with factory defaults 2) visiting a dealership or doing update manually is not that much of a deal if it only needs to be done once or twice during the lifetime of the vehicle
For comparison, think about BIOS updates or camera firmware updates. Sure it would be kind of neat if these happened auto-magically. But would I see it as a big plus if my motherboard was able to fetch and install BIOS updates all by itself? Not really, I would in fact be concerned that it's fixing stuff that is not broken, and doing it behind my back.
> Sure, but 1) cars come out of factory with sensible defaults. If you knew what you're doing, you could trade e.g. engine longevity or fuel consumption for extra HP but most people would be better off with factory defaults 2) visiting a dealership or doing update manually is not that much of a deal if it only needs to be done once or twice during the lifetime of the vehicle
Just look at the CVT Ford Fiesta / Ford Fusion. In the 2012 model of the cars, the transmission would "slip" under certain conditions. I know because my friend Pete owns one. He went to the dealership. The mechanic there drove it with him in the passenger seat. Sure enough, this was a problem. They call Ford and they adamantly denied there was a problem of any sort. Fast forward about eight months and the dealership calls Pete. Apparently, there's been a software update. Pete went to the dealership. The transmission slips no longer happen.
I guess the point I am making is that it really sucks when Ford denies there being a problem when there is clearly a problem. I am not saying the software was the problem but they had a fix for it in software. I don't think Ford even publicly announced this software update. For sure, I understand that you should be able to decide when and which updates happen to your device. However, I see a positive change if they come up with a good change list with each update. Someone above noted that until recently Toyota didn't even have a bug tracking system for its software.
Traditional vendors are not willing to give the general public those kind of improvements not because they can't, but because they feel it will hurt their bottom line by not being able to sell more new car. Customer are left on their own - and so they resort to patch their car with parts that drop their warranty - sometimes for good reason, sometimes not.
For example some vendors are famous for selling the same engine at different price point, throttling the low end - a bit like what's done on some CPU/GPU in the computer world !
I put more stock in the idea that traditional vendors are terrified of any kind of pathway for frequent/easy access to the onboard engine computers. Just look at the kerflufle around stuck gas pedals; imagine what the public will do to the first vendor whose ECM is maliciously modified OTA, or who pushes an update with an unnoticed key regression or new bug (hardly an unusual thing in the world of frequent updates)
Actually, some other manufacturers do provide such free improvements, though they would require a visit to the dealership. McLaren provided performance improvements for the 12C, even after the model got discontinued.
Many manufacturers do actually sell you these upgrades. Mercedes has AMG chip tuning, Volvo calls their stuff Polestar (swedes and their funny english), BMW does it at least for the 1-series, etc etc. In most cases it includes not only ECU remapping but also cooling upgrades.
As for throttling the engine to sell at a different price point: in many countries this relates to government taxation on horsepowers. I don't see this as particularly nefarious by the car manufacturers.
"Traditional vendors" routinely update their cars to give better performance where it doesn't cost them anything and brings other benefits e.g. safety. Especially if the components are reused during multiple generations e.g. MY14/MY15.
I am buying a used LandRover now where I will get more than a 0.1s performance improvement when I take it into the dealership for a transmission software update.
Yeah. But ECUs in regular cars are designed to function in a broad variety of conditions. A car bought in Germany has to work when filling up top-quality BP Ultimate Diesel, but it also has to work if you drive it to Russia and fill up their horrible sulphuric Diesel. A petrol car has to work when filled up with 98 or even 100 octane petrol, but also when filled up with 91 octane petrol sold in some countries. Not to mention that the engine has to function normally in -30C but also 40C,both of which can be encountered within a single country.
Of course if you know that certain things are not going to be a problem(like you are not planning on driving to Russia or filling up at shady stations) then you can manually tweak the ECU for shorter timings or whatever, to get more performance out.
Parts in the engine can only take so much speed, heat, power, etc. before they fail. Sure you could push out a slightly higher performance tune but at some point you're going to need to get into the engine and upgrade moving parts like pistons, camshafts, fuel injectors, cooling system, etc.
Also transmissions can only take so much power before they have to be upgraded too. It wouldn't make any sense to ship an economy car with a sports car transmission because you might juice up the power with an update later.
Not to mention only upgrading power is no fun at all if you don't upgrade the brakes and suspension. All the power in the world does nothing if you can't put it down on the pavement or can't stop before hitting a wall.
Slightly higher performance tune ? ECU remaps and similar devices can add significant performance improvements typically around 30% more torque and power.
Car manufacturers generally aim for their cars to be mostly identical regardless of the country they are sold. Hence they are often targeting lowest common denominator country emissions levels.
And I've done ECU remaps before. You definitely do NOT need to upgrade brakes and suspension.
Those improvements aren't just possible they are what you get. Enthusiasts have been using these system for decades (?) with almost every type of car imaginable.
And your issues about reliability/emissions aren't necessarily true (spend time on any car forum and you will see better rebuttals to these issues). It isn't necessarily true for reliability since engines are often reused between models/manufacturers and so safe mappings are known.
And yes you may exceed emissions regulations but not necessarily. Again manufacturers aim to sell the same car in multiple countries and so depending on how relaxed your country is your car may still be legal with increased emissions.
Think about this. If these devices were so bad why do most insurance companies when you tell them about it either (a) don't increase premiums or (b) do so with a negligible increase. It's because they are never the cause for safety or reliability issues. Car companies use engine power as a key product differentiator.
Why would an insurance company care about the remaining lifetime of your engine?or reduced economy?
The off the shelf tunes are really only effective on turbocharged engines and are rooted in overboosting - that's a very cheap way to increase performance and it has longevity, emmissions and economy impact. It may if may not be significant but it is there. Manufacturers would be utterly foolish to experument like that in mass market cars.
Why would an insurance company care if you change the colour of your vehicle? They (t least, in England) do, and this is for a pure colour change, not for "colour change after an accident" or "colour change after vandalism" or "colour change to a colour that is riskier for accidents".
Point, but I suspect it's the same reason even so - they've found a measurable correlation between people changing their car colour and accident rates.
Isn't the kind of person that cares enough about their 0-60 to get their ECU remapped more likely to drive at speed, and therefor more likely to be involved in an accident?
I suppose I'm assuming a correlation between speed and crash-rate, which may not be a thing. But given that premiums ∝ engine power, you'd have thought that there might be.
By I'm sure that some overall improvement is possible, I meant some performance increase with no downside, not that the existing profiles were maxed out.
> This is just Tesla being their usual disruptive self.
Dealerships have been doing this for YEARS.
There are many dealerships who sell ECU remaps/devices that significantly increase performance of the car. And the biggest joke is that some manufacturers e.g. Mercedes actually turn a blind eye to it in many situations.
I wonder how the security on these over-the-air updates is. I'm a little scared of the idea that someone who's not even touching my car might be able to replace the piece of code that connect the brake pedal to the actual brakes.
While I have no knowledge of how Tesla does their OTA, my startup makes software for over-the-air updating, so I can make a few general comments on this.
It may help if you think of your car as just another server. Any connection between the server and client can be encrypted of course, using well-known tools. Besides that, the car can be made to not accept updates that are not signed by the manufacturer, so your only exposure is to the manufacturer.
Of course someone may have physical access to your car and be able to write new software locally, but then they may also be able to do mechanical sabotage, so it's not a new risk.
So you basically have to trade off one kind of security (the manufacturer can update my car remotely) with another (security bug announced in the software my car runs, I am now a sitting duck).
It definitely takes a shift in perspective, but in the brave new world where cars (and other things) run millions of lines of code, over-the-air updates are a necessity. (but of course I'd say that).
I don't know about Tesla specifically, but in general the security of embedded firmware is pretty catastrophic [1]. OTA updates are definitely a two-edged sword: on the one hand, they allow vulnerabilities to be fixed (without taking the car to a service center); on the other, the update process can itself be an attack target (e.g. man in the middle serves firmware image with malware included).
Anyone doing this in a serious fashion will have something similar to this kind of setup:
Device has a per-device key burned in at the factory and the private keys sit in a manufacturer HSM. Updates are signed by the manufacturer and also encrypted with the per-device key for each device. The device itself will have tamper-proof (well, as tamper resistant as they can be) chips and a secure boot-loader that will do all the dirty work.
Nothing is ever 100% secure, but you shouldn't believe it is something similar to a piece of software on your computer where it is just "hit this https URL for the executable and run it". Or maybe you should believe that and force manufacturers to come out and state otherwise :)
There are mechanical failure modes for these things, as well as multiple electronic ones.
I'm not saying your comment is ungrounded, I'm just saying that a process locking up or sending wrong information is not likely, or even possible, to net you 100% loss of use in your brakes.
Cars are the most highly regulated consumer product on earth. Brake systems nor Tesla fly under the radar here.
Cars are the most highly regulated consumer product on earth. Brake systems nor Tesla fly under the radar here.
I felt that way too, til I watched few of the talks from the people that were doing the testing of Toyota electronics after all of the unintended acceleration problems.[1]
Did you realize, for example, that while there are coding standards that one should adhere to while doing embedded systems-critical stuff (like MISRA guidelines), there are no requirements for automotive companies to adhere to any such software standardization, and that it's left up to the individual manufacturers to decide upon standards?
The US automotive industry is unique in that it doesn't have a rigor requirement for software. Planes and heavy equipment do have such requirements within the states.
Toyota didn't even use bug tracking or source management, and used their own software guidelines. That's scary given the complexity is so high that the entire system cannot be fully tested in a feasible way.
Atop the software issues, the hardware ECM was made in such a way so as to make the secondary 'cross-checking' processor basically useless. Both CPUs were checking the same I/O, if that was the fault then BOTH would read bad data, and the hardware was made in such a way as to make that impossible to work around.
An old Camry isn't anywhere near as complex as a modern electric car, and I personally have more faith in Tesla than I do Toyota, but it makes me want to push US legislation into requiring US auto manufacturers into following the strict software guidelines that are available to them.
Fun trivia: MISRA guidelines were originally pushed by the automotive industry in the early 90s/late 80s, and now they are one of the only critical systems groups to not follow them.
Those are pretty good points, and I didn't realize that auto manufacturers had the level of freedom in ECU software.
As far as Toyota is concerned, right now I'd trust them as much, of not more, than Tesla. Tesla has been doing great things and doesn't have much, if any, of a bad track record for failures. However, you have to realize that Toyota has also been making cars far longer than Tesla, produce more, and has one of the best reliability ratings in the industry.
I believe Tesla can achieve this or better. However, it's hard to compare when Tesla doesn't have the numbers that Toyota has.
I would have said the same thing about Apple, then they released an update that make the iPhone 6 unable to make calls. Mistakes happen, and your car could be bricked by one.
I hate the idea that Apple or Google are examples of good embedded coding and their defect ratio is the best humanity can get. I don't understand how people think this way. Embedded development has a very different culture and lower tolerance of faults than general development and ESPECIALLY mobile development which is a nightmarish show of amateur hour.
I have no idea how Tesla does this, but in most cases you're deal with deterministic software or real time OS's, massive testing suites, coding guidelines that guarantee positive outcomes, etc.
JPL published its guidelines. Do you think Google and Apple are this stringent with their mobile toys? Of course not. They have zero economic interest to do so. They just have to make things good enough that kids and housewives won't complain too much.
Hell, even if you like to believe mistakes only happen to some people- Musk clearly falls in the group of "has made mistakes". SpaceX is proof his ventures are not immune to error.
Which is fine, but I'm unnerved hearing the people who seem to consider Tesla infallible. 'They'll never make a mistake like that, they're Tesla!'
They made fewer mistakes than anyone else ever has when landing a reusable rocket from orbit that way. I'd be OK with driving a car made by someone with that track record.
I'll bite; why do you think SpaceX was a mistake? They've had some pretty impressive achievements, all while actually making profit. Unless you meant individual errors like this month's landing attempt.
> SpaceX is proof his ventures are not immune to error.
Errors probably means errors here. As in yeah, most recently trying to land a booster on a barge and missing.
Mistakes happen. The wrong number in a configuration somewhere and everyone's car suddenly has a vampire that sucks down the battery 50% faster, or causes a misreading of wheel speed for anti-lock braking, or etc.
So what if there was ? Everybody including myself (technical) would just install it regardless. We place faith in companies having proper testing procedures.
I'm assuming if you didn't have to accept immediately that you could push it off until you have time to do so. In addition just knowing that there is an update is a boon on it's own. If I know that the code has changed on my car and something starts acting funny, I'm a lot more likely to suspect the software and report issues properly than if it stealth changes it (I would assume mechanical wear and tear at that point).
I don't have an updatable car. But I have used Windows. And it's become my practice to hold off for a few days after updates come out, and check for horror stories. And I typically do a manual backup before updating.
I think they already doing the same: applying the update at the next "reboot" car start, and it's unlikely that the downloaded update is hot-swapping the running code.
This strikes me as quite a dangerous feature. Cars accelerating slowly is a great safety feature. Maybe they could relabel this feature the "Suge Knight" feature since it will make parking lots and other areas of surging cars a whole new theatre.
It's around as dangerous as any other performance car with an extremely powerful engine. You can still drive slowly; the difference is in what happens when you floor the pedal.
The notable thing here is that the updates are done "magically", as in, in the background over WiFi.
Software mappings for engine performance are often modified by hobbyists, performance tuners, etc., it just normally takes plugging in a tool or swapping a control chip.
Perhaps, put a tinfoil hat on your car's wifi or cellular radio? (I imagine it must use s cellular data connection for the backups given not everyone will log the car into wifi)
But with seriousness, it's a good question. I would be surprised if the purchase agreement for the car doesn't somewhere include a clause that you agree to allow the car to make updates.
In 2012 when the pushed the first big update, Wired indicated owners couldn't opt-out [1]. Looking at their legal website [2], I see that under Rights & Choices you can turn off the collection of Telemetric Data, which may disable periodic software and firmware updates.
But no, on a casual Googling, I don't see it outlined anywhere how they manage opting out of those updates.
I don't believe any of the Model S updates have ever been automatically applied. It will automatically tell you "hey, an update is available" but won't install it until you give the go-ahead.
But can you skip that update but install the next? Say update 2.1 is a speed increase and user doesn't want that. Update 2.2 is a safety feature that the user wants, would 2.2 include 2.1?
I was a bit confused initially as to how a mechanical problem can be solved by a software update, but then someone explained in one of the comments that it's about fuel-injection tables and stuff.
Incredible, but just a bit scary too.
I really hope they test that software to the hilt - I mean like NASA style, slow but steady kind of stuff. I wouldn't want to go 1 feet near the car if the quality is in the same quality vicinity as 99% other software (and that includes software that we generally consider "good quality").
Anyone knows what their software development process is to get that kind of confidence?
There is a write up about the development of the STS-software[1]. If memory serves, the key is specifying everything extremely rigorously. It seems to me though, that writing such specification (if sensor A detects such-and-such value and sensor B...) would share most of the problems writing actual software does.
Another look at how to get "NASA like" confidence is provided by Richard Feynman[2] and Diane Vaughan[3].
It isn't insane. It's been happening for many years.
And the software development process is pretty standard waterfall. And yes they absolutely test that software to the hilt. Generally though the software is architecturally quite basic i.e. they don't do anything too fancy.
> Anyone knows what their software development process is to get that kind of confidence?
If it's NASA confidence, waterfall every time :)
Having worked in that sort of environment (everything about the system has been analysed on paper before a text editor is launched), don't knock it until you've tried it. This wasn't rocket science either, it was export refund batch jobs. In the 21st century.
Awaits the first person to claim that open source car software is much better and that that next year will be the year of open source driving software - just as soon as the whole dashboard UI/UX is made a little better and the update process for your engine doesn't require you going to the command line because the drivers for the windscreen wipers are broken for no reason after the last upgrade.
As a motor control guy I'd really like to have a look inside Teslas control algorithm. Most people - even experts - leave something on the table. This improvement is no surprise to me.
I wonder if they typically launch with very conservative defaults and over time can learn more about the system and what tweaks can be done without causing too many issues. In ICE there's this whole "chip tuning" culture that does this as well. With a trivial updating process and all the data each Tesla sends, it seems like "chip tuning" is built into the Tesla culture as well.
>> I wonder if they typically launch with very conservative defaults and over time can learn more about the system and what tweaks can be done without causing too many issues.
Good point. Slamming full torque as fast as possible on a Tesla might physically break things and should only be pushed out as an update after appropriate testing. I'm assuming they were not even getting the highest possible torque out of it though. Electric motors are a fairly interesting problem and most of the work goes into dealing with limiting cases. Most of the literature doesn't even deal with some of the fundamental problems and most people just avoid them by leaving a little performance on the table.
Until you've completed not inconsiderable testing that might take months you wont push a component to its limits or within 99% of its limits. Same with normal cars. e.g. Diesel components are very heavy and can deliver much more power than the engines they live in have by default.
An extra gear would not give more performance, the reason cars with internal combustion engines have gears is because they do not produce their full power at low engine speeds, whereas electric motors do, hence why the Tesla does not have nor would benefit from a gearbox.
You can see why a gearbox is a disadvantage in this video here:
Tesla's original cars had a 2-speed gearbox, because they had problems with the motor at high revs and they couldn't get their desired top speed without a gear change. The gearbox was a huge problem, because the shift ratio was so big that the jolt on gear change damaged the gearbox, and gearbox life was maybe a year. So they went to a motor with a larger speed range and better cooling, and a one-speed gearbox. Tesla retrofit most of their early cars with the new powertrain.
Some earlier electric cars had multi-speed gearboxes, but that was back when electric cars had brush-type DC motors. Once high-power semiconductors got really good, electric cars went to polyphase AC motors with variable-frequency drive. That technology is now in everything from better R/C drones to electric locomotives. AC motors can be made to synchronize, which allows the Tesla 2-motor car to have all-wheel drive with no front/back differential. One motor per wheel is probably next.
The big win for this technology turns out to be Diesel-electric locomotives. All the wheels on all the locomotives can be synched up, eliminating wheel slip. The locomotives can even be distributed through the train. Here's a 3.5 mile long train run as a test by Union Pacific in 2010.
https://www.youtube.com/watch?v=jdIzRFOaTCY
There have been longer trains, but mostly in flat areas. This was from LA to Texas at speeds to 70mph.
And saying a Tesla would have no benefit of a gearbox is a bit strong. There are reasons to believe [1] it would increase efficiency at the cost of more complexity.
Yes, that is awesome.
But on the other hand, in the past I've had updates to my TiVo and my PS3 where I turned it on and it said "Oh! Hey. I'm shittier than I was yesterday. Suck it."
And someday, that could happen with Teslas, too. Updates are a mixed bag.