News: 1653640210

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

When management went nuclear on an innocent software engineer

(2022/05/27)


On Call Sure, you might use words like "boom" and "explode" when it comes to errors with your system. But could a whoopsie have the potential to render a chunk of a country uninhabitable? Welcome to [1]On Call .

Our story comes from a reader Regomized as "Ellen" who spent the early part of the 1980s toiling away in the IT department of a company producing software responsible (in part) for running nuclear power stations.

A brand new system was in the process of being rolled out, which would keep track of which stations were online, how much power they could provide, and so on.

[2]

Commissioning was underway using a test rig connected to a new reactor under construction. "A team of Americans were in the building teaching the company's managers how to use their system," explained Ellen, "which was to sit on top of ours."

[3]

[4]

"They were providing the reactor control equipment that our system talked to."

It wasn't going well. Despite some lovely gear for the time (think a curved wooden desk with inset DEC Rainbow PCs in the control room and a bunch of VAX/VMS systems in a fail-safe cluster), there were problems getting the VAX to talk to the power station. The line was up, but there was no communication.

[5]

"Hair was being pulled out, time scales were collapsing, and I was getting white hair with stress," said Ellen, "not least because I was on a successful completion bonus."

As is so often the case, a seemingly inconsequential setting was changed and everything sprang to life. The equivalent of a ping was sent and the reactor responded: "Yes, I'm here."

"Strictly speaking, this was a reactor simulator ," Ellen added, "a fact that will become important later."

[6]

However, for now, things were online, the software was working, and while there were only three days to plow through 10 days' worth of tests, the team at least had a fighting chance. Tests were set to execute sequentially overnight.

The Rainbow PC in the comms room would run them and dump the results to the printer. Ellen and co explained the approach to the site manager at the end of day meeting, which the Americans also attended. Another important point.

Yet despite the money-no-object approach, bizarrely there was no lock fitted to the computer room door. While nobody was supposed to touch the equipment, Ellen's team took no chances and stuck a cardboard box over the PC with the words "System Under Test – DO NOT TOUCH" scrawled over it.

"It was now well around 10:30pm," she recalled, "so the team and I set off for our hotel, aiming to reconvene at the 8:30am Morning Meeting."

Sadly, The Call would come in a good few hours before that morning meeting. This being before the days of the ubiquitous mobile phone, Ellen had a pager which chirped urgently at 6am. She had to attend the site NOW!

When she arrived, the tension in the atmosphere was palpable. Something had gone terribly, terribly wrong. The manager of site was also in attendance, as was the biggest of all cheeses – the Director of Power Generation.

"A sort of deathly silence fell over the room," she recalled, "the sort just before a public hanging takes place."

"Yes, I was nervous."

"It seemed that our software had experienced some sort of problem and as a result the reactor had gone offline, the control rods had slammed in, and it was now no more than an oversized kettle."

At this point we must remind readers that this was a simulator, not the real thing.

Had this been a real reactor, it would have taken months to recover, at a cost of millions of pounds.

And Ellen and her software were clearly to blame.

"No one could tell me what exactly what had happened. Just that it was my fault," she said.

Seeking to delay her execution, Ellen asked if she could review the output of the line printer to get an idea of what might have happened. The bosses agreed and gave her an hour's reprieve as she scuttled off to the comms room.

Upon entering the room (the one without a lock), she and the team were greeted by a scene of utter devastation. The box with the "Do Not Touch" lettering had been discarded. The test PC was in bits and the disk was missing entirely. The line printer had stopped mid-line when the PC had been attacked.

Alarming, but not something that would cause a reactor scram, just a delay in testing.

"I asked one of my team to connect the printer back to the VAX and dump the application logs for me," recalled Ellen. "He was told to bring them to me even if I was in a meeting – especially if I was in what was going to be a stressful meeting, to say the least."

The investigation continued and got stranger still. The other Rainbow PCs were all up and running. They shouldn't have been – Ellen's team had yet to commission them, merely setting them up for cable routing purposes. And yet there they were, humming away.

Ellen returned to the meeting with her findings. One of the US team was in attendance, and confessed to switching on the PCs.

[7]Seriously, you do not want to make that cable your earth

[8]We can bend the laws of physics for your super-yacht, but we can't break them

[9]Thinnet cables are no match for director's morning workout

[10]Your software doesn't work when my PC is in 'O' mode

"When asked why," said Ellen, "he responded that because us amateur-hour Brits were so far behind schedule he wanted to get started training the control room staff, so he wanted all the PCs booted and ready."

So… how was this achieved? The media to boot up the PCs was locked up in Ellen's safe store ("the back of my car," she confessed).

No problem. The US tech had simply grabbed the disk from the PC running the testing and copied it to the other computers. "Obviously it worked because they are all up and running," he said.

Suddenly, everything became clear. Had Ellen a Poirot-style mustache, some serious twirling would have been called for.

The logs arrived and were handed over. Ellen pretended to study them, but already knew what the evidence was going to show.

Ellen: "So, you cloned the disk on to all the PCs..."

US Engineer (proudly): "Yes, and saved several days".

Ellen (looking at the log): "And you went to one PC and asked for a reactor status from the power station."

US Engineer: "Yes, but it didn't work – your software is so full of bugs, it's total crap."

Ellen: "And when you cloned the disks, you changed the DECNet address on each PC?"

She, of course, knew that he hadn't. The log said as much.

US Engineer: "Err, no, what's that? Is it important?"

It was indeed.

The protocol used for communication was designed to avoid hacking. "There were multiple control commands," explained Ellen, "to eliminate any false commands that could, quite literally, cause a bomb to go off."

In this instance, all the PCs now had the same address, meaning that when communication was attempted (for example, a simple status request from the reactor), all manner of nonsense would bounce around the network. The reactor (or, to be clear, the simulation) software decided that something weird was happening and correctly triggered its safeties. In this case, an immediate shutdown.

An extended recovery time (had this been a real reactor) was of no consequence compared to safety in the face of what might be an attack.

"After explaining all this to the now-silent room," Ellen said, "I finished with telling the Director of Power Generation that it was not our fault."

"It was someone, mentioning no names, who had disassembled our equipment and had misused our software and hardware, all before we had handed it over. The system did exactly what it was supposed to."

"And whilst simulating a reactor scram was not part of the tests, we now knew it worked."

The US contractor did the equivalent of falling on his sword. Puce-faced, he left the room, was apparently fired the same day and packed on the next plane home.

Again, this was not a real reactor and Ellen knew that the team could get back online in a matter of hours. However, "I shamelessly lied through my teeth, told the assembled team it would take me at least two weeks to reassemble the equipment, recommission all of our test and control equipment, and that I was declaring force majeure as per the contract, but I would not report the damage back to my head office."

The room was filled with apologies and gratitude that she would not be taking the issue further and that there had been no unpleasantness. The time extension? No problem – it was granted.

The team finished well ahead of time and bonuses were dispensed all round.

"And that," she said, "is how I was accused of nearly wiping [region redacted] off the map."

Ever had your bottom rescued by a fail-safe? Or been called out at an ungodly hour to deal with someone else's mistake? Of course you have, and you should share your story with an email to [11]On Call . ®

Get our [12]Tech Resources



[1] https://www.theregister.com/Tag/on-call

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YpChQ1PMnh3Jhw16F7On@AAAAA8&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YpChQ1PMnh3Jhw16F7On@AAAAA8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YpChQ1PMnh3Jhw16F7On@AAAAA8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YpChQ1PMnh3Jhw16F7On@AAAAA8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YpChQ1PMnh3Jhw16F7On@AAAAA8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2022/05/20/on_call/

[8] https://www.theregister.com/2022/05/13/on_call/

[9] https://www.theregister.com/2022/05/06/on_call/

[10] https://www.theregister.com/2022/04/29/on_call/

[11] mailto:oncall@theregister.com

[12] https://whitepapers.theregister.com/



Next time

BOFH in Training

More bigger explicit signs so even idiots know better then to think they know better.

Unfortunately Einstien did say "“Two things are infinite: the universe and human stupidity; and I'm not sure about the universe.” ..... so it may not be enough unless you have a few nasty guard dogs as well which will bite anyone who comes anywhere close.

Re: Next time

ShadowSystems

Even better than a sign to warn folks away would be a quad of VDG towers, one at each corner, set to zap anyone that approaches without the proper safety measures. (Flicking the power switch on the far side of the room, hidden in a potted plant, disguised to look like a LawnGnome.)

Nothing says "Don't Touch!" like a ring of still smoking charred corpses surrounding something like a grisley moat.

On a COMPLETELY unrelated note, who is up for some bacon? =-D

Re: Next time

tinman

I'd have gone with using a metal box instead of cardboard and wired to the mains but yeah, something more robust than another sign

Also, long pig bacon, yes please. Breakfast of champions

Re: Next time

Mast1

New pair of glasses required here. I read it as "Breakfast of champignons"

Yup, I could do with some mushrooms with the bacon: dilutes the salt.

Re: Next time

Anonymous Custard

The inevitable TP quote here, from Thief of Time:

“Some humans would do anything to see if it was possible to do it. If you put a large switch in some cave somewhere, with a sign on it saying 'End-of-the-World Switch. PLEASE DO NOT TOUCH', the paint wouldn't even have time to dry.”

And of course, the thing should have been put in the cellar lavatory, without lights or stairs, in a locked filing cabinet and the signage reading "Beware of the Leopard.”

Best of British and a Friday pint to all...

GlenP

A long way from being the same scale of devastation but we had an MFD engineer who set up a new machine, checked it was connected to everything, then cloned the setup from an existing machine without checking/changing the IP address .

Cue shouts from the main office when they couldn't print as their "printer" just sat there saying, "Duplicate IP Address Detected".

Had me going

chivo243

I thought the gear had been stolen... the all the other shiny units were humming along nicely! Wait, this wasn't BOFH!! However, I get the feeling Ellen might hold her own for a while!

"but I would not report the damage back to my head office"

Pascal Monett

And that is definitely how you get Manglement appreciation - you screwed up, but I won't tell. Thank you ! Thank you !

Recovery from disaster results in ample time to finish the work properly. Well done.

Re: "but I would not report the damage back to my head office"

tinman

'Negotiating' the extra two weeks was just the chef's kiss. Montgomery Scott would have been proud of her

Dogs

Bertieboy

The mention of guard dogs reminds me of one of our colleagues who's idea (albeit 30 years ago) of the ultimate automated plant control system comprised the control system, a man and a big dog.

The man's job was to feed the dog;

The dog's job was to bite the man if he touched anything.

Einstein was right.

Sam not the Viking

We had a multi-million pound project where the machinery we supplied needed to be run in the correct sequence, according to a number of parameters. We saved the end-user a lot of money with a novel energy-efficient arrangement and avoiding a whole new building. In order to function properly, the control system needed to be robust with duplication and verification along the way. Costly, but necessary and it gave the consultants the impression they were contributing. When run in automatic control, it performed its function really well.

So the end-user ran it in hand control.

Don’t know about you

Mayday

But if I see a sign in a nuclear facility on ANYTHING saying “do not touch” then I’m not fucking touching.

nice story

Anonymous Coward

I couldn't fathom the answer before the end !

Cool.

Now, I feel nuclear power is really unsafe :( Maybe this is also what happened in RL to french EDF, with its fleet of nearly 32 out of 58 reactors out of the grid ...

Re: nice story

Potemkine!

Now, I feel nuclear power is really unsafe :( Maybe this is also what happened in RL to french EDF, with its fleet of nearly 32 out of 58 reactors out of the grid ...

Then you're wrong. Nuclear reactors are watched very carefully. If 32 out 58 EDF's reactors are out of the grid, this is because they are in planned maintenance.

The main problem is having relied for a long time on existing reactors without building new ones. The result is there: many reactors are ageing and require heavy maintenance, and no new ones were built to cover this, not even mentioning the need of covering new usages. There was so much anti-nuclear brainwashing by the so-called "Greens", so many newsfeed propagating the propaganda, so few educational efforts that now France has to reopen coal power stations which are an ecological disaster to compensate.

Prime example

JeffB

This is a prime example of a little bit of knowledge potentially being extremely dangerous

poisoned coffee, n.:
Grounds for divorce.