On this Labor Day (as observed in the U. S.), let's consider how engineering has affected the way people work to earn a living, and how the way things have turned out may not necessarily be the best of all possible worlds, at least not for everyone.
Since its inception in the 1800s, modern engineering has assumed the characteristics or goals of the age which gave it birth: "individual achievement, efficiency, progress, faith in science, material comfort, equality, and freedom." This list was taken from a sociological study of families in modern society, but it applies equally well to the goals toward which much of modern engineering strives. Last Saturday I visited a place where these values are not ignored, exactly, but subordinated to a different set of values: "respect for human life, sexual restraint, patriarchy, devotion to family, and love of neighbor." This second list comes from the same source as the first, and despite some negative connotations that some of the terms such as patriarchy have acquired, I think they apply fairly to the place I visited, with some exceptions.
On a few hundred acres of land west of Waco, Texas, a Christian community called Heritage Ministries is trying an ongoing experiment in how to live out the Christian life in a way that puts people, relationships, and family ahead of efficiency, economics, politics, and productivity. That may sound easy, but it's not. The path these folks have chosen is similar to the way the Amish communities in Pennsylvania and elsewhere live, but without many of the rigidities and divisive religious infights that have characterized the Amish. I'm sure the Heritage folks have had their family arguments, but in my very limited exposure to them (a few visits and the reading of one publication), I haven't seen any. Instead, what I see is a way of life that both appeals to me and denies most of what I as an engineer live for.
Let me explain with an example or two. Unlike some Amish communities, the Heritage community welcomes visitors to their retail establishments where they sell samples of what they make: everything from handmade soap to five-thousand-dollar handcrafted rocking chairs. On the day we visited, a team of young men and their sons was squeezing sorghum cane in an old-fashioned mule-powered mill. The juice ran downhill through a pipe to a boiling vat tended by six or eight young ladies and a man who fed the wood fire under the boiler. He told me they had farmed about three acres of cane and expected to make several thousand pints of finished sorghum.
Now I don't know much about sugar cane processing, which is a somewhat different operation, but I'm sure that if you threw a few hundred thousand dollars' worth of capital at this situation, you could easily eliminate all but maybe a tenth of a worker by scaling up the operation to industrial size. A large, modern, efficient sugar processing plant could handle what the little Heritage crew took all day to process in about half a minute. As an engineer, I couldn't stop myself from thinking these ways-to-do-it-better thoughts as I watched the laborious process before me.
It's not that the Heritage people are ignorant, or arbitrarily rejecting every advance in technology made after 1850. They drive cars, use computers, and while I was walking the grounds I nearly tripped over some CAT5 computer cable left over from when they networked their cash registers during one of their semiannual fairs. But their strong belief in " a certain simplicity of lifestyle, a rootedness in the land, [and] an emphasis on family and intentional community" makes them eschew large modern capital investments whenever it tends to separate the worker from the thing worked, and from other workers.
As Heritage leader Blair Adams says in the booklet What We Believe, "a craft, as distinct from a manufacture, can express the inner person for the very reason that he becomes so directly involved in it. And as far as what constitutes 'a waste of time and effort,' money doesn't seem to us the best cirterion for establishing the worth of one's 'time and effort.' To us, meaning and fulfillment provide much better criteria."
In recent years, Heritage and similar communities have benefited from the increased popularity of organically grown foods, the urge to buy local produce, and renewed interest in crafts and other off-the-grid attempts to be less dependent on the global economy. These things are good as far as they go, but a simple analysis shows that they can only go so far. If everybody tried to buy local produce, thus reducing the distance food is shipped, historian James McWilliams has shown that the carbon footprint of food production would actually increase overall because of differences in climate, agricultural technology, and other factors, not to mention the market disruptions it would cause. So for that and many other reasons, it would not be practical for everyone, or even most of the world's urban population, to live the way the Heritage people live. But does that mean it's wrong?
I don't think so. The Heritage community views the way they live as a silent witness to the power of God in Christ Jesus—a way of preaching without words. But regardless of one's beliefs, they show that many of the things we as engineers regard as vitally necessary—labor-saving machinery, cost-effectiveness, and the latest technology—do not play a big role in a whole way of life that, from all outward appearances, is at least as satisfying and enjoyable as our modern, individualistic, grid-dependent one is. And that is a reminder worth bearing in mind.
Sources: The two sociological quotations are from p. 85 of Allan Carlson's From Cottage to Work Station (San Francisco: Ignatius Press, 1993), in which he cited the work of sociologist William D'Antonio. The quotations in the paragraph that mentions What We Believe are from the booklet of that title by Blair Adams (Elm Mott, Texas: Colloquium Press Trust, 2005). An article by James McWilliams describing the problems of being a "locavore" can be found in the online edition of Forbes Magazine at http://www.forbes.com/forbes/2009/0803/opinions-energy-locavores-on-my-mind.html.
Monday, September 07, 2009
Monday, August 31, 2009
The Cost of High-Tech Medical Imaging
As federal health-care reform bills make their tortuous way through Congress in September, one aspect of medical care that engineers should pay attention to concerns the cost of procedures that use expensive pieces of equipment such as CT-scan X-ray machines and MRI (magnetic resonance imaging) systems. A recent op-ed piece by a group of medical experts pointed out that one reason we have the most expensive health-care system in the world (by many measures), is that we spend a lot of money on high-tech tests that really don't make people healthier. A study of CT scans in Cedar Rapids, Iowa revealed that in the community of 300,000 people, about 52,000 CT scans were administered in only one year. And that's below the national average, which is even worse. One thing that makes it easy to spend that money is the fact that high-end medical equipment is very expensive, both in terms of initial installation and operating costs. Why is that?
From an engineering point of view, medical imaging combines several factors to make a kind of perfect storm of expense. In the case of a CT-scan machine, you are dealing with X-rays, which require precisely controlled high voltages to generate, and a large array of precision detectors. MRI machines don't use X-rays, but instead they need something even more exotic and hard to generate: precisely controlled magnetic fields of tremendous intensity, which can only be produced with superconducting magnets that use liquid helium. Liquid helium is a costly, exotic material that has to be renewed regularly and needs a whole infrastructure to obtain. So even before you have your data, you've spent a lot of money just generating it. Besides that, a lot of intensive computation is needed to produce the images, but with computer and software costs falling these days, the computational aspect is probably the only part of the system that's cheaper than it used to be. Not just anybody can operate a CT-scan or MRI machine: you require highly trained radiologists or technicians who are familiar with safety requirements and the details of how to acquire good images. These people don't come cheap. Finally, every engineer knows that any piece of equipment's price goes up significantly if it is to be used in medicine. There are special safety and other regulations that medical equipment must meet, and the medical-equipment market is a strange and narrow one compared to, for example, consumer electronics. For all these reasons and more, the typical CT scan device goes for between $150,000 and $300,000, while a whole-body MRI machine will set you back more than a megabuck. And that doesn't count maintenance and operating costs.
Considering all this, it doesn't sound like there's much chance to develop really cheap MRI or CT-scan machines operated by the consumer, which after all would be one way to fix the cost problem. The last consumer-operated X-ray machines were the shoe-store fluoroscopes, now banned because they were dangerous, and rightly so. But suppose Congress succeeds in changing the business model of health care, so that we move away from the present system in which each MRI or CT-scan machine is like a piece of factory equipment whose owners are obliged to operate at full capacity in order to recoup their investment. What if we break the connection between the number of procedures and tests done, and the money taken in, so that it is not so direct as it is today? What consequences might this have for the future of high-tech engineering in health care?
For some reason, I find myself thinking about the computers used by the U. S. Postal Service. That agency does use computers, though it was probably not a national leader in pioneering business applications of computers. My impression is that whoever makes the USPS's computers (I'm talking about the little systems the retail clerks use at local post offices) won that contract a long time ago and has jealously guarded it ever since. Innovation and competition is not a big feature of this deal, I suspect. I have no particular complaints about how the Postal Service uses computers, but they could probably do better.
I pick the Postal Service because their near-monopoly status (at least in terms of small-town facilities nationwide) means their revenue is not that sensitive to the amount of money they spend on innovative technologies. Most of us have seen billboards in big cities advertising the latest and greatest medical testing equipment that thus-and-so hospital system has. Those billboards are there for a reason. You don't see billboards advertising the latest computer system that the Postal Service just bought, because it wouldn't make them any more money.
I'm not saying we should leave the present medical system alone, because it's not perfect, and I agree that we probably waste a lot of money on needless procedures that help pay for too many expensive pieces of medical imaging equipment. But every kind of system has advantages and drawbacks. If health-care providers—private and public—can no longer directly recover capital expenses in a fee-for-service way, they will quit spending so much money on high-tech equipment. Maybe that's a good thing, to a degree. But I wouldn't want to go to the opposite extreme that would remind me of a doctor I once went to who prided himself on how long he could keep his semi-antique EKG machine going. The thing was at least thirty years old, and I had to wait an extra five minutes while the tubes warmed up. I felt like I was participating in a historic re-creation of the invention of electrocardiograms, and it did not impress me favorably.
The trick in this aspect of health-care reform is to negotiate the macro-ethics of finding a happy medium between overuse of expensive technology (which is probably where we are now) and underspending to the point that we fall behind the leading edge of technology, depriving some patients of newer procedures simply because we didn't spend the money on them. A thriving technology sector is a delicate thing, and while cost containment is good, we don't want to reduce spending so much that leading-edge medical imaging companies simply decide to leave the market. That would be a loss not only for us in the United States, but worldwide if such companies lead the global market too.
I'm glad I'm not having to make these decisions, but I hope the congressional staffers working on this decide carefully, and are willing to change course if things don't turn out the way they hoped. Any feedback loop that goes through the Congress and the President has a very long delay time, and so we better hope they get it right the first time, because fixing it might take quite a while.
Sources: The article "10 Steps to Better Health Care," in which the statistic on the Cedar Rapids CT scans appears, is from the online edition of the New York Times at http://www.nytimes.com/2009/08/13/opinion/13gawande.html.
From an engineering point of view, medical imaging combines several factors to make a kind of perfect storm of expense. In the case of a CT-scan machine, you are dealing with X-rays, which require precisely controlled high voltages to generate, and a large array of precision detectors. MRI machines don't use X-rays, but instead they need something even more exotic and hard to generate: precisely controlled magnetic fields of tremendous intensity, which can only be produced with superconducting magnets that use liquid helium. Liquid helium is a costly, exotic material that has to be renewed regularly and needs a whole infrastructure to obtain. So even before you have your data, you've spent a lot of money just generating it. Besides that, a lot of intensive computation is needed to produce the images, but with computer and software costs falling these days, the computational aspect is probably the only part of the system that's cheaper than it used to be. Not just anybody can operate a CT-scan or MRI machine: you require highly trained radiologists or technicians who are familiar with safety requirements and the details of how to acquire good images. These people don't come cheap. Finally, every engineer knows that any piece of equipment's price goes up significantly if it is to be used in medicine. There are special safety and other regulations that medical equipment must meet, and the medical-equipment market is a strange and narrow one compared to, for example, consumer electronics. For all these reasons and more, the typical CT scan device goes for between $150,000 and $300,000, while a whole-body MRI machine will set you back more than a megabuck. And that doesn't count maintenance and operating costs.
Considering all this, it doesn't sound like there's much chance to develop really cheap MRI or CT-scan machines operated by the consumer, which after all would be one way to fix the cost problem. The last consumer-operated X-ray machines were the shoe-store fluoroscopes, now banned because they were dangerous, and rightly so. But suppose Congress succeeds in changing the business model of health care, so that we move away from the present system in which each MRI or CT-scan machine is like a piece of factory equipment whose owners are obliged to operate at full capacity in order to recoup their investment. What if we break the connection between the number of procedures and tests done, and the money taken in, so that it is not so direct as it is today? What consequences might this have for the future of high-tech engineering in health care?
For some reason, I find myself thinking about the computers used by the U. S. Postal Service. That agency does use computers, though it was probably not a national leader in pioneering business applications of computers. My impression is that whoever makes the USPS's computers (I'm talking about the little systems the retail clerks use at local post offices) won that contract a long time ago and has jealously guarded it ever since. Innovation and competition is not a big feature of this deal, I suspect. I have no particular complaints about how the Postal Service uses computers, but they could probably do better.
I pick the Postal Service because their near-monopoly status (at least in terms of small-town facilities nationwide) means their revenue is not that sensitive to the amount of money they spend on innovative technologies. Most of us have seen billboards in big cities advertising the latest and greatest medical testing equipment that thus-and-so hospital system has. Those billboards are there for a reason. You don't see billboards advertising the latest computer system that the Postal Service just bought, because it wouldn't make them any more money.
I'm not saying we should leave the present medical system alone, because it's not perfect, and I agree that we probably waste a lot of money on needless procedures that help pay for too many expensive pieces of medical imaging equipment. But every kind of system has advantages and drawbacks. If health-care providers—private and public—can no longer directly recover capital expenses in a fee-for-service way, they will quit spending so much money on high-tech equipment. Maybe that's a good thing, to a degree. But I wouldn't want to go to the opposite extreme that would remind me of a doctor I once went to who prided himself on how long he could keep his semi-antique EKG machine going. The thing was at least thirty years old, and I had to wait an extra five minutes while the tubes warmed up. I felt like I was participating in a historic re-creation of the invention of electrocardiograms, and it did not impress me favorably.
The trick in this aspect of health-care reform is to negotiate the macro-ethics of finding a happy medium between overuse of expensive technology (which is probably where we are now) and underspending to the point that we fall behind the leading edge of technology, depriving some patients of newer procedures simply because we didn't spend the money on them. A thriving technology sector is a delicate thing, and while cost containment is good, we don't want to reduce spending so much that leading-edge medical imaging companies simply decide to leave the market. That would be a loss not only for us in the United States, but worldwide if such companies lead the global market too.
I'm glad I'm not having to make these decisions, but I hope the congressional staffers working on this decide carefully, and are willing to change course if things don't turn out the way they hoped. Any feedback loop that goes through the Congress and the President has a very long delay time, and so we better hope they get it right the first time, because fixing it might take quite a while.
Sources: The article "10 Steps to Better Health Care," in which the statistic on the Cedar Rapids CT scans appears, is from the online edition of the New York Times at http://www.nytimes.com/2009/08/13/opinion/13gawande.html.
Monday, August 24, 2009
Lessons from Russian Hydroelectric Plant Accident
Most of the time, hydroelectric plants are one of the safest ways to generate electricity. The technology has been well established for a century or more, there are few toxic substances or chemicals involved, pollution and other environmental problems are at a minimum, and all in all, hydropower is a pretty benign enterprise. But on Aug. 17, a week ago today, Russia's largest hydropower facility, the Sayano-Shushenskaya plant in Siberia, experienced a massive explosion and flood that at last report killed at least 69 people, knocked out the entire facility, and sent an oil slick down river for miles. What happened?
According to the Wikipedia website on the plant, there have been four major accidents including this one since construction was completed in 1978. The earlier mishaps in 1979, 1985, and 1988 were caused by spring floods that overwhelmed the dam's capacity. This does not give one a positive feeling about the overall balance of the system design. Again according to Wikipedia, the sequence of events last week apparently went like this.
The way a hydroelectric dam works is to direct water under high pressure to turbines. Of course, this means you have a lot of pipes, valves, and regulator mechanisms, and great quantities of water flowing at high speeds and pressures. Somehow a "water hammer" developed in the system. This is basically the same kind of thing you will sometimes hear in domestic plumbing when a toilet or washing-machine valve shuts off suddenly. Moving water has inertia, and when a column of water moving in a confined place suddenly has nowhere to go, the energy stored in the water's motion turns into a sudden pressure surge that makes the pounding noise. In homes, this is usually no more than an annoyance, but at a hydropower facility, the much larger volumes and energies involved can have serious consequences. Well-designed plants have surge absorbers of various kinds installed to prevent this sort of thing, but either the Sayano-Shushenskaya plant didn't have the right kind, they didn't work right, or perhaps an operator error caused a water hammer that exceeded the system's capacity to deal with it.
In any event, a severe water hammer ruptured a conduit leading to a turbine, immediately flooding the engine room and turbine room. This would have been bad enough, but apparently the flood caused a transformer to explode. Transformers used in power plants are filled with oil for insulation and cooling purposes. Ideally this oil is non-flammable, but the high cost of non-flammable oil sometimes means that flammable kinds are used. Whether or not a fire resulted, the explosion wrecked a large area of the turbine hall, apparently breaching outside walls, as some photographs show. As of Sunday, 69 bodies had been recovered from the wreckage, making this the worst hydropower accident in recent memory.
The worst regional consequences of this accident involve the oil slick previously mentioned, and the economic harm to Siberia's aluminum-smelting industry, which used 70% of the power-plant's output. These, while serious, are nothing like the global effects of the Chernobyl disaster, which also involved a power plant in the former Soviet Union. That 1986 accident was caused by operator error at the nuclear facility and emitted tons of highly radioactive material into the air. Nevertheless, I believe more people died in the hydropower incident than died immediately following the Chernobyl accident, so in that sense the hydropower disaster was worse.
Normally, hydroelectric plants do not need large numbers of personnel, especially in areas of the plant that could become hazardous if something went wrong. Small hydroplants can go for days or weeks under totally automatic operation with no personnel present at all, and while a huge facility like the Sayano-Shushenskaya plant would need some operators, it is at least odd that seventy or more people were in harm's way when the explosion occurred. Perhaps this is a legacy of the old Soviet Union days when facilities were often designed to maximize employment rather than efficiency or profit. If that is the case, I hope operators of similar plants realize that even hydroplants are dangerous places, and allowing large numbers of employees to congregate in places that could be flooded if something went wrong, is a bad policy.
If the operation records can be reconstructed, we can eventually discover the cause of the fatal water hammer—whether it was a design flaw, an operator mistake, or a combination. And while I am no hydroelectric-plant designer, floods are fairly easy to model, and if there was some way to keep transformers from exploding in the event of a flood, taking such measures would have at least mitigated the size of last week's accident.
Our sympathies are with those who lost loved ones and friends in the Sayano-Shushenskaya accident. If we can learn that even apparently safe facilities such as hydroelectric plants have their hazards, and prevent such accidents in the future, they will not have died in vain.
Sources: The Wikipedia article referred to is at http://en.wikipedia.org/wiki/Sayano–Shushenskaya_hydroelectric_power_station, and is being updated currently as more information emerges. I also referred to news articles on the disaster at http://news.yahoo.com/s/ap/20090818/ap_on_re_eu/eu_russia_power_plant and http://hosted.ap.org/dynamic/stories/E/EU_RUSSIA_POWER_PLANT?SITE=MOSTP&SECTION=HOME&TEMPLATE=DEFAULT.
According to the Wikipedia website on the plant, there have been four major accidents including this one since construction was completed in 1978. The earlier mishaps in 1979, 1985, and 1988 were caused by spring floods that overwhelmed the dam's capacity. This does not give one a positive feeling about the overall balance of the system design. Again according to Wikipedia, the sequence of events last week apparently went like this.
The way a hydroelectric dam works is to direct water under high pressure to turbines. Of course, this means you have a lot of pipes, valves, and regulator mechanisms, and great quantities of water flowing at high speeds and pressures. Somehow a "water hammer" developed in the system. This is basically the same kind of thing you will sometimes hear in domestic plumbing when a toilet or washing-machine valve shuts off suddenly. Moving water has inertia, and when a column of water moving in a confined place suddenly has nowhere to go, the energy stored in the water's motion turns into a sudden pressure surge that makes the pounding noise. In homes, this is usually no more than an annoyance, but at a hydropower facility, the much larger volumes and energies involved can have serious consequences. Well-designed plants have surge absorbers of various kinds installed to prevent this sort of thing, but either the Sayano-Shushenskaya plant didn't have the right kind, they didn't work right, or perhaps an operator error caused a water hammer that exceeded the system's capacity to deal with it.
In any event, a severe water hammer ruptured a conduit leading to a turbine, immediately flooding the engine room and turbine room. This would have been bad enough, but apparently the flood caused a transformer to explode. Transformers used in power plants are filled with oil for insulation and cooling purposes. Ideally this oil is non-flammable, but the high cost of non-flammable oil sometimes means that flammable kinds are used. Whether or not a fire resulted, the explosion wrecked a large area of the turbine hall, apparently breaching outside walls, as some photographs show. As of Sunday, 69 bodies had been recovered from the wreckage, making this the worst hydropower accident in recent memory.
The worst regional consequences of this accident involve the oil slick previously mentioned, and the economic harm to Siberia's aluminum-smelting industry, which used 70% of the power-plant's output. These, while serious, are nothing like the global effects of the Chernobyl disaster, which also involved a power plant in the former Soviet Union. That 1986 accident was caused by operator error at the nuclear facility and emitted tons of highly radioactive material into the air. Nevertheless, I believe more people died in the hydropower incident than died immediately following the Chernobyl accident, so in that sense the hydropower disaster was worse.
Normally, hydroelectric plants do not need large numbers of personnel, especially in areas of the plant that could become hazardous if something went wrong. Small hydroplants can go for days or weeks under totally automatic operation with no personnel present at all, and while a huge facility like the Sayano-Shushenskaya plant would need some operators, it is at least odd that seventy or more people were in harm's way when the explosion occurred. Perhaps this is a legacy of the old Soviet Union days when facilities were often designed to maximize employment rather than efficiency or profit. If that is the case, I hope operators of similar plants realize that even hydroplants are dangerous places, and allowing large numbers of employees to congregate in places that could be flooded if something went wrong, is a bad policy.
If the operation records can be reconstructed, we can eventually discover the cause of the fatal water hammer—whether it was a design flaw, an operator mistake, or a combination. And while I am no hydroelectric-plant designer, floods are fairly easy to model, and if there was some way to keep transformers from exploding in the event of a flood, taking such measures would have at least mitigated the size of last week's accident.
Our sympathies are with those who lost loved ones and friends in the Sayano-Shushenskaya accident. If we can learn that even apparently safe facilities such as hydroelectric plants have their hazards, and prevent such accidents in the future, they will not have died in vain.
Sources: The Wikipedia article referred to is at http://en.wikipedia.org/wiki/Sayano–Shushenskaya_hydroelectric_power_station, and is being updated currently as more information emerges. I also referred to news articles on the disaster at http://news.yahoo.com/s/ap/20090818/ap_on_re_eu/eu_russia_power_plant and http://hosted.ap.org/dynamic/stories/E/EU_RUSSIA_POWER_PLANT?SITE=MOSTP&SECTION=HOME&TEMPLATE=DEFAULT.
Sunday, August 16, 2009
Carbon Sequestration: Worth the Trouble?
In August of 1986, over 1700 villagers living as far away as 25 km from Cameroon's Lake Nyos died when a mysterious, invisible suffocating cloud enveloped them. They were victims of one of the two known limnic eruptions in recorded history. For years, the waters of Lake Nyos had absorbed carbon dioxide from underground sources, probably volcanic in origin. Because of temperature differences in the lake, the gas-saturated water remained at the bottom until something, possibly as insignificant as high winds, triggered a lake turnover. Once the eruption began, the lake began to boil like a soft-drink bottle you leave out in the sun and open by mistake. A giant cloud of carbon dioxide spilled out of the lake and smothered people and animals for miles around.
This is the same compound that, if numerous carbon sequestration projects now underway are successful, will be buried under tremendous pressure in dozens or hundreds of locations all over the world. The question is: will it stay there?
Ever since humans discovered fire, we have been adding to the amount of carbon dioxide in the atmosphere. Until the 1800s, the quantity of carbon dioxide humans put into the air was negligible compared to that contributed by natural causes such as forest fires and volcanic activity. The concern with rising levels of atmospheric carbon dioxide, of course, is that it tends to raise the Earth's temperature, other things being equal (which they never are). There is a general scientific consensus that (a) human activity has caused much if not most of the rise in carbon dioxide levels in the past two hundred years and (b) this will cause some increase in the Earth's average temperature, though how much and for how long is a matter of debate. Some theories even posit that a short temperature rise will trigger an instability that will wind us up in another Ice Age a few decades afterwards. Whatever actually happens, the political fact these days is that reducing one's carbon footprint has become a virtue, while emitting carbon, even for a good cause such as bringing the blessings of electric power to poor people, is a sin.
The business world has seen the politicians writing "cap-and-trade" on the wall, and so there is big private money to be made in developing systems that will capture the carbon dioxide generated when fossil fuels (most notably coal) are burned in power plants. A French firm called Alstom is currently building several pilot plants around the country, including one attached to a coal-fired power plant in New Haven, West Virginia.
The technology itself is rather clever. After cooling and washing the flue gas with cold water, they bubble it through a solution of ammonium bicarbonate (contains hydrogen) and ammonium carbonate (no hydrogen). Nearly all the carbon dioxide combines with the ammonium radicals. They pump the fizz-rich liquid under pressure to a heater where the carbon dioxide boils off and is compressed to send it underground. And there, in my opinion, the real trouble begins.
Never mind that the whole pile of machinery is doing something that engineers of an earlier era would have considered ludicrous: capturing the main gaseous combustion product and shooting it underground. The operation adds nothing to the efficiency of the plant, takes a fair amount of energy itself, and creates a long-term hazard compared to which nuclear waste is relatively harmless.
Look at it this way: would you rather live five miles from some well-shielded solid radioactive stuff whose emissions can't even be detected outside the plant boundaries, and which will just sit there and gradually cool off for the next few hundred years; or, would you like to live an equal distance from the wellhead of a giant underground reservoir which, if released, will suddenly spew out and make Lake Nyos look like a minor traffic accident? For my money, I'll take the nuclear stuff any day.
Presumably, geologists have been careful to select locations where the underground carbon dioxide is relatively safe and isolated. Okay, but our experience with large underground gas reservoirs of artificial origin is limited, to say the least. While natural gas has been stored underground for many years (often in depleted gas fields, not coincidentally), the two cases are significantly different. For one thing, natural gas storage is limited to transient market-related storage needs, and so the pressures and volumes required are relatively modest. By contrast, carbon sequestration will be "permanent"—the whole point is to send it down there and make it stay there indefinitely. If it escapes to the atmosphere we are back at Square One after spending billions of dollars for nothing, plus quite likely having numbers of dead citizens on our hands. The pressures and volumes eventually needed for carbon sequestration, if carried out on a large scale, will dwarf the current natural-gas underground storage facilities. While I am unaware of any major accidents that have happened with underground natural gas storage, there may have been some. Of course, carbon dioxide doesn't burn and natural gas does, but suffocation from a non-flammable gas makes you just as dead as if you had burned to death.
What makes a whole lot more sense from a technical point of view is to replace coal-fired power plants with nuclear plants as fast as we can. Nuclear energy generates zero carbon emissions, the nuclear waste problem is manageable even without the ill-fated Yucca Mountain disposal facility that the Obama Administration recently axed, and there are no particular concerns about running out of nuclear fuel any time soon. If we get low we can switch to the kind of reactor that makes more than it consumes.
That is the technical reality. But the political reality right now, which engineers as well as everyone else has to deal with, is that nuclear power is under the same emotion-laden mushroom cloud that has characterized it ever since nuclear weapons ended World War II, and has never freed itself from the almost superstitious fear that the word "nuclear" inspires in many people. Some of that fear has now been transferred to plain old carbon dioxide, a gas which each living human being emits every time we take a breath. When you end up being afraid of yourself, there's no place to hide.
It is still early in the carbon sequestration business, and there is time for the political winds to change before we all get burdened by carbon cap-and-trade taxes to pay for giant sequestration plants that send carbon dioxide into the ground, only to have some of it pop up one day in an unexpected place. Let's hope that cooler heads prevail and we reach a consensus that does sensible things about carbon emissions without burying a lot of unwelcome surprises for our descendants.
Sources: A good article originating at the Washington Post, describing the technology and politics of the carbon sequestration process pioneered by Alstom can be found at http://www.pittsburghlive.com/x/pittsburghtrib/business/s_638488.html. A description of the geology surrounding the Lake Nyos disaster can be found at http://www.cevl.msu.edu/~long/nyos.htm.
This is the same compound that, if numerous carbon sequestration projects now underway are successful, will be buried under tremendous pressure in dozens or hundreds of locations all over the world. The question is: will it stay there?
Ever since humans discovered fire, we have been adding to the amount of carbon dioxide in the atmosphere. Until the 1800s, the quantity of carbon dioxide humans put into the air was negligible compared to that contributed by natural causes such as forest fires and volcanic activity. The concern with rising levels of atmospheric carbon dioxide, of course, is that it tends to raise the Earth's temperature, other things being equal (which they never are). There is a general scientific consensus that (a) human activity has caused much if not most of the rise in carbon dioxide levels in the past two hundred years and (b) this will cause some increase in the Earth's average temperature, though how much and for how long is a matter of debate. Some theories even posit that a short temperature rise will trigger an instability that will wind us up in another Ice Age a few decades afterwards. Whatever actually happens, the political fact these days is that reducing one's carbon footprint has become a virtue, while emitting carbon, even for a good cause such as bringing the blessings of electric power to poor people, is a sin.
The business world has seen the politicians writing "cap-and-trade" on the wall, and so there is big private money to be made in developing systems that will capture the carbon dioxide generated when fossil fuels (most notably coal) are burned in power plants. A French firm called Alstom is currently building several pilot plants around the country, including one attached to a coal-fired power plant in New Haven, West Virginia.
The technology itself is rather clever. After cooling and washing the flue gas with cold water, they bubble it through a solution of ammonium bicarbonate (contains hydrogen) and ammonium carbonate (no hydrogen). Nearly all the carbon dioxide combines with the ammonium radicals. They pump the fizz-rich liquid under pressure to a heater where the carbon dioxide boils off and is compressed to send it underground. And there, in my opinion, the real trouble begins.
Never mind that the whole pile of machinery is doing something that engineers of an earlier era would have considered ludicrous: capturing the main gaseous combustion product and shooting it underground. The operation adds nothing to the efficiency of the plant, takes a fair amount of energy itself, and creates a long-term hazard compared to which nuclear waste is relatively harmless.
Look at it this way: would you rather live five miles from some well-shielded solid radioactive stuff whose emissions can't even be detected outside the plant boundaries, and which will just sit there and gradually cool off for the next few hundred years; or, would you like to live an equal distance from the wellhead of a giant underground reservoir which, if released, will suddenly spew out and make Lake Nyos look like a minor traffic accident? For my money, I'll take the nuclear stuff any day.
Presumably, geologists have been careful to select locations where the underground carbon dioxide is relatively safe and isolated. Okay, but our experience with large underground gas reservoirs of artificial origin is limited, to say the least. While natural gas has been stored underground for many years (often in depleted gas fields, not coincidentally), the two cases are significantly different. For one thing, natural gas storage is limited to transient market-related storage needs, and so the pressures and volumes required are relatively modest. By contrast, carbon sequestration will be "permanent"—the whole point is to send it down there and make it stay there indefinitely. If it escapes to the atmosphere we are back at Square One after spending billions of dollars for nothing, plus quite likely having numbers of dead citizens on our hands. The pressures and volumes eventually needed for carbon sequestration, if carried out on a large scale, will dwarf the current natural-gas underground storage facilities. While I am unaware of any major accidents that have happened with underground natural gas storage, there may have been some. Of course, carbon dioxide doesn't burn and natural gas does, but suffocation from a non-flammable gas makes you just as dead as if you had burned to death.
What makes a whole lot more sense from a technical point of view is to replace coal-fired power plants with nuclear plants as fast as we can. Nuclear energy generates zero carbon emissions, the nuclear waste problem is manageable even without the ill-fated Yucca Mountain disposal facility that the Obama Administration recently axed, and there are no particular concerns about running out of nuclear fuel any time soon. If we get low we can switch to the kind of reactor that makes more than it consumes.
That is the technical reality. But the political reality right now, which engineers as well as everyone else has to deal with, is that nuclear power is under the same emotion-laden mushroom cloud that has characterized it ever since nuclear weapons ended World War II, and has never freed itself from the almost superstitious fear that the word "nuclear" inspires in many people. Some of that fear has now been transferred to plain old carbon dioxide, a gas which each living human being emits every time we take a breath. When you end up being afraid of yourself, there's no place to hide.
It is still early in the carbon sequestration business, and there is time for the political winds to change before we all get burdened by carbon cap-and-trade taxes to pay for giant sequestration plants that send carbon dioxide into the ground, only to have some of it pop up one day in an unexpected place. Let's hope that cooler heads prevail and we reach a consensus that does sensible things about carbon emissions without burying a lot of unwelcome surprises for our descendants.
Sources: A good article originating at the Washington Post, describing the technology and politics of the carbon sequestration process pioneered by Alstom can be found at http://www.pittsburghlive.com/x/pittsburghtrib/business/s_638488.html. A description of the geology surrounding the Lake Nyos disaster can be found at http://www.cevl.msu.edu/~long/nyos.htm.
Monday, August 10, 2009
Twitter and Facebook Silenced by Russo-Georgian Cyberspat
You didn't quite see it here first (as usual, the New York Times seems to be the best source), but just last week we were writing about how cyberwars could cause serious collateral damage. Well, according to the Times, last Thursday millions of users of the social-media sites Twitter and LiveJournal had their service disrupted for the simple reason that a professor in the country of Georgia (formerly part of the old USSR) aroused the ire of some hackers whose malware-spawning abilities were way ahead of their good judgment. The 34-year-old economics professor was posting some nostalgic photos and recollections about the Russia-Georgia conflict of August 2008 when he noticed that the LiveJournal site he was using had gone bad. He tried switching to Facebook, which was also jammed, and then Twitter, which also flaked out for him. It took him a while to learn that he was the main reason that these sites were targeted by a distributed-denial-of-service attack that not only kept him from using them, but disconnected many millions of other users around the world as well. One expert said it was like bombing a TV station because you didn't like one of the newscasters.
Social media have taken on the roles formerly held exclusively by major news outlets with amazing speed. In Iran, during a June 20 election protest a young woman named Neda Agha Soltan was shot and killed. Cell-phone videos of the incident spread around the world to make her the iconic figure of the rebellion, and social media were crucial in this process.
So far, no one is relying on Twitter for much more than entertainment, unless you count a few businesses and advertisers. And so having it disappear for a few hours is nothing compared to finding a terrorist's bomb planted by a railroad line, for example. The argument I hear is that sooner or later, we will have life-critical systems that depend on the Internet in a way that hasn't happened yet, and that's when cyberwars will get serious.
There are several possible ways this situation could go in the future.
One is that engineers who design life-critical systems, keenly aware of the less-than-perfect reliability and security of Internet-based communications, will continue to take precautions that no matter what happens on the Internet, nobody will die as a consequence. That is more or less the case now, at least judging by the absence of fatal outcomes from cyberwars so far.
A second possibility is that cyberattackers will get much more sophisticated and go after hardened systems such as banks and military networks. These are much harder to crack than sites that put a lower priority on security, but determined and disciplined attacks, perhaps using dedicated cyberwar server farms rather than the rather flaky botnets, might cause serious disruptions which would be economically equivalent to blowing up a large number of office buildings (minus the people). Say somebody got hold of a bank's network and messed it up so thoroughly with misinformation and garbage transactions that it would take weeks to straighten it out, and in the meantime no electronic transactions could take place through that bank. This could effectively ruin a financial institution, unless the government stepped in to help, and we're seeing what a mixed bag that can be. And like other terrorist acts, you don't have to shut down the entire system. There is probably a psychological trigger point for bank runs, and the terrorists would only have to reach that point. Mass panic—millions of people lining up at money machines to get cash all at once—would do the rest.
Nobody would get killed, unless maybe in the crush of people around the ATMs, but you would still have an outcome equivalent in economic terms to a physical bombing.
A third scenario is something that I suppose most computer experts believe can't happen: a total freeze-up of the Internet. This might not be as bad as you think. Back when international communications were restricted to submarine cables and radio, every now and then the Earth would be hit by a geomagnetic storm caused by solar flares. Big ones occasionally caused so much surge current in undersea cables as to render them useless, and the ionosphere would get so trashed that long-distance radio channels would go down as well. In really severe storms, domestic telegraph and telephone long-distance lines would see some trouble as well. For a day or two, we'd be back in the early 19th century when the fastest message from London to New York took about a week by sea. The world survived these incidents, nevertheless, and although international commerce was a smaller portion of each nation's economy back then, I think the consequences of a worldwide Internet freeze-up might not be as bad as you might think at first, as long as it didn't last too long.
But if it took more than 24 hours or so to restore service, or if it was a patchwork thing that took weeks to get everyone back to normal, then the consequences would be severe. Just as a lot of the damage from 9/11 was to economic interests in terms of lost airline revenue, depressed retail sales, and so on, the same sort of thing would happen during and after an Internet freeze-up. So it's worthwhile at least thinking about how to prevent such a thing, or how to survive it in case it ever happens.
In the meantime, let's hope that the worst cyberattacks are no worse than last week's Twitter and Facebook scares. Personally, while there are some people I might like to get back in touch with via Facebook, the prospect of hearing unexpectedly from certain others has led me to leave the whole thing alone for the time being, so I didn't miss them. But we'll see how long I can hide.
Sources: The New York Times article on the Georgian cyberattack is at http://www.nytimes.com/2009/08/08/technology/internet/08twitter.html?_r=2&hpw.
Social media have taken on the roles formerly held exclusively by major news outlets with amazing speed. In Iran, during a June 20 election protest a young woman named Neda Agha Soltan was shot and killed. Cell-phone videos of the incident spread around the world to make her the iconic figure of the rebellion, and social media were crucial in this process.
So far, no one is relying on Twitter for much more than entertainment, unless you count a few businesses and advertisers. And so having it disappear for a few hours is nothing compared to finding a terrorist's bomb planted by a railroad line, for example. The argument I hear is that sooner or later, we will have life-critical systems that depend on the Internet in a way that hasn't happened yet, and that's when cyberwars will get serious.
There are several possible ways this situation could go in the future.
One is that engineers who design life-critical systems, keenly aware of the less-than-perfect reliability and security of Internet-based communications, will continue to take precautions that no matter what happens on the Internet, nobody will die as a consequence. That is more or less the case now, at least judging by the absence of fatal outcomes from cyberwars so far.
A second possibility is that cyberattackers will get much more sophisticated and go after hardened systems such as banks and military networks. These are much harder to crack than sites that put a lower priority on security, but determined and disciplined attacks, perhaps using dedicated cyberwar server farms rather than the rather flaky botnets, might cause serious disruptions which would be economically equivalent to blowing up a large number of office buildings (minus the people). Say somebody got hold of a bank's network and messed it up so thoroughly with misinformation and garbage transactions that it would take weeks to straighten it out, and in the meantime no electronic transactions could take place through that bank. This could effectively ruin a financial institution, unless the government stepped in to help, and we're seeing what a mixed bag that can be. And like other terrorist acts, you don't have to shut down the entire system. There is probably a psychological trigger point for bank runs, and the terrorists would only have to reach that point. Mass panic—millions of people lining up at money machines to get cash all at once—would do the rest.
Nobody would get killed, unless maybe in the crush of people around the ATMs, but you would still have an outcome equivalent in economic terms to a physical bombing.
A third scenario is something that I suppose most computer experts believe can't happen: a total freeze-up of the Internet. This might not be as bad as you think. Back when international communications were restricted to submarine cables and radio, every now and then the Earth would be hit by a geomagnetic storm caused by solar flares. Big ones occasionally caused so much surge current in undersea cables as to render them useless, and the ionosphere would get so trashed that long-distance radio channels would go down as well. In really severe storms, domestic telegraph and telephone long-distance lines would see some trouble as well. For a day or two, we'd be back in the early 19th century when the fastest message from London to New York took about a week by sea. The world survived these incidents, nevertheless, and although international commerce was a smaller portion of each nation's economy back then, I think the consequences of a worldwide Internet freeze-up might not be as bad as you might think at first, as long as it didn't last too long.
But if it took more than 24 hours or so to restore service, or if it was a patchwork thing that took weeks to get everyone back to normal, then the consequences would be severe. Just as a lot of the damage from 9/11 was to economic interests in terms of lost airline revenue, depressed retail sales, and so on, the same sort of thing would happen during and after an Internet freeze-up. So it's worthwhile at least thinking about how to prevent such a thing, or how to survive it in case it ever happens.
In the meantime, let's hope that the worst cyberattacks are no worse than last week's Twitter and Facebook scares. Personally, while there are some people I might like to get back in touch with via Facebook, the prospect of hearing unexpectedly from certain others has led me to leave the whole thing alone for the time being, so I didn't miss them. But we'll see how long I can hide.
Sources: The New York Times article on the Georgian cyberattack is at http://www.nytimes.com/2009/08/08/technology/internet/08twitter.html?_r=2&hpw.
Monday, August 03, 2009
Cyberwars: From Plans to Reality
A report in the New York Times recently revealed that the U. S. military has already engaged to a limited degree in "cyberwar": attacks on an enemy's communications and computer networks. On two separate occasions, attempts were made to disrupt communications networks: one in Serbia in the late 1990s, and another during the early hours of the attack on Iraq in 2003. Both missions were at least partly successful, but both also caused collateral damage in the form of communications disruptions in nations that were not targeted for attack. The same report also described a much more ambitious plan to freeze Iraq's financial system electronically, but the Bush administration vetoed the idea over fears that it might cause a widespread financial panic. As was demonstrated last fall, inaction can just as easily cause widespread financial panic, but that is worlds away from deliberately fouling up a country's banking system. Nevertheless, the fact that we are already in a world where cyberwar is part of the armamentarium may be news to many people, including engineers.
As we mentioned in this space not long ago, the technology of cyberwar has outpaced the legal and moral traditions that govern, or at least address, the conduct of conventional warfare. Clearly, doing something to the Internet that would disrupt services to large numbers of people outside the territory under attack is not a good idea, which is one reason the Bush administration may have restrained themselves from putting Iraq's financial system in the deep freeze. But other issues related to cyberwar are less clear-cut than this.
Consider the principle that military forces should be clearly identifiable (wearing uniforms, etc.). This idea is routinely violated by terrorists, who like to fade into the background of ordinary citizenry, and also by cyberattackers, who are experts at hiding their true identity and whereabouts. I suppose you could leave return addresses in plain text in viruses designed to attack enemy networks, but I somehow doubt anyone is worrying about this.
A more serious consideration is the distinction between civilian and military populations. Until about 1900, it was not considered cricket to target civilian populations in warfare. This rule went by the board in a big way during World War II, when bombers on both sides began carpet-bombing attacks on cities without special regard for limiting their targets to sites of strategic significance. Since then, the principle of no attacks on civilians has received occasional lip service, but that's about all. It's very hard to imagine how a cyberattack could sort out only strategically important computers from those belonging to the average citizen, but maybe as the technology progresses, this sort of thing would be easier to do. The planned but never executed attack on Iraq's financial system would not have discriminated between a paycheck for a general and a payment for a bottle of milk, so clearly we have a ways to go in this regard.
The Obama Administration has said it is going to name a cyberwar czar who will try to centralize activities concerning cybersecurity and related matters. But so far no one has been nominated to the post, and we'll have to wait and see what happens once that person is in place. If history is any guide, this office will languish in obscurity until a major cyberattack causes serious damage to U. S. interests. Then there will be enough political steam generated to get something done, although the horse will have left the barn by then.
Fortunately, defending against cyberattacks is something that we have lots of experience with, since the field of computer science seems to have been born with a native proclivity to spawn hackers of all descriptions who like nothing better than to tear down what other programmers have spent months or years constructing. I don't know why this field is so hacker-prone, but the practical outcome is that we have lots of private-enterprise expertise already that knows how to defend against a variety of attacks, and these experts even work in a coordinated fashion most of the time. Let's hope that whatever the government does will not cripple this advantage, but instead will build upon it and encourage even better cooperation than we have already.
I wish the world was a place where computers and networks were used only for good and productive purposes. But anytime something of value comes into being, somebody is going to get jealous or greedy and want to use it as a pawn in conflicts and wars. The Internet and modern telecommunications systems are a part of our lives now, and so we need to think about how to defend them, and if need be, attack them along with other kinds of infrastructure that is the focus of war. So far, the worst consequences of cyberattacks have been financial losses and inconvenience. Let's hope that with wise planning and forethought, nothing worse will happen to us in this area.
Sources: The New York Times article " Halted ’03 Iraq Plan Illustrates U.S. Fear of Cyberwar Risk" appeared in the Aug. 1, 2009 online edition at http://www.nytimes.com/2009/08/02/us/politics/02cyber.html. Full disclosure: as I will mention every now and then, my wife works for About.com, a division of the New York Times Company.
As we mentioned in this space not long ago, the technology of cyberwar has outpaced the legal and moral traditions that govern, or at least address, the conduct of conventional warfare. Clearly, doing something to the Internet that would disrupt services to large numbers of people outside the territory under attack is not a good idea, which is one reason the Bush administration may have restrained themselves from putting Iraq's financial system in the deep freeze. But other issues related to cyberwar are less clear-cut than this.
Consider the principle that military forces should be clearly identifiable (wearing uniforms, etc.). This idea is routinely violated by terrorists, who like to fade into the background of ordinary citizenry, and also by cyberattackers, who are experts at hiding their true identity and whereabouts. I suppose you could leave return addresses in plain text in viruses designed to attack enemy networks, but I somehow doubt anyone is worrying about this.
A more serious consideration is the distinction between civilian and military populations. Until about 1900, it was not considered cricket to target civilian populations in warfare. This rule went by the board in a big way during World War II, when bombers on both sides began carpet-bombing attacks on cities without special regard for limiting their targets to sites of strategic significance. Since then, the principle of no attacks on civilians has received occasional lip service, but that's about all. It's very hard to imagine how a cyberattack could sort out only strategically important computers from those belonging to the average citizen, but maybe as the technology progresses, this sort of thing would be easier to do. The planned but never executed attack on Iraq's financial system would not have discriminated between a paycheck for a general and a payment for a bottle of milk, so clearly we have a ways to go in this regard.
The Obama Administration has said it is going to name a cyberwar czar who will try to centralize activities concerning cybersecurity and related matters. But so far no one has been nominated to the post, and we'll have to wait and see what happens once that person is in place. If history is any guide, this office will languish in obscurity until a major cyberattack causes serious damage to U. S. interests. Then there will be enough political steam generated to get something done, although the horse will have left the barn by then.
Fortunately, defending against cyberattacks is something that we have lots of experience with, since the field of computer science seems to have been born with a native proclivity to spawn hackers of all descriptions who like nothing better than to tear down what other programmers have spent months or years constructing. I don't know why this field is so hacker-prone, but the practical outcome is that we have lots of private-enterprise expertise already that knows how to defend against a variety of attacks, and these experts even work in a coordinated fashion most of the time. Let's hope that whatever the government does will not cripple this advantage, but instead will build upon it and encourage even better cooperation than we have already.
I wish the world was a place where computers and networks were used only for good and productive purposes. But anytime something of value comes into being, somebody is going to get jealous or greedy and want to use it as a pawn in conflicts and wars. The Internet and modern telecommunications systems are a part of our lives now, and so we need to think about how to defend them, and if need be, attack them along with other kinds of infrastructure that is the focus of war. So far, the worst consequences of cyberattacks have been financial losses and inconvenience. Let's hope that with wise planning and forethought, nothing worse will happen to us in this area.
Sources: The New York Times article " Halted ’03 Iraq Plan Illustrates U.S. Fear of Cyberwar Risk" appeared in the Aug. 1, 2009 online edition at http://www.nytimes.com/2009/08/02/us/politics/02cyber.html. Full disclosure: as I will mention every now and then, my wife works for About.com, a division of the New York Times Company.
Monday, July 27, 2009
Smashup at an Atom Smasher in Europe
Accidents at high-energy physics labs do not normally make the news. But when the lab is the European Union's crown jewel consortium CERN, and the accident puts their latest and greatest accelerator, the Large Hadron Collider, out of commission for up to a year, the incident is worthy of wider attention than it has gotten so far.
America used to dominate the field of experimental physics, as our first-out-of-the-gate development of nuclear weapons proved. But with the political collapse of the Superconducting Supercollider project, a Texas-based particle accelerator that was cancelled in 1993, the world leadership in high-energy experimental physics began to move to Europe, where last September the Large Hadron Collider was being put through its initial tests.
State-of-the-art particle accelerators are some of the most complex experimental systems ever built. The LHC resides in an underground tunnel 17 miles in circumference under the border between France and Switzerland. The basic idea is to shove atomic nuclei around a huge evacuated pipe with the aid of strong electromagnetic fields and the guidance of monstrous superconducting magnets that have to be submerged in tons of liquid helium. Such enterprises are of course very costly in comparison to more modest laboratory equipment, but a $5 billion expenditure these days when the U. S. Congress is cogitating about health-care programs costing 200 times that much doesn't seem like a lot of money. Nevertheless, you want to protect your investment even if it is only $5 billion, and that seems to be what got damaged the most in last fall's accident.
Superconducting magnets are used because once you get current running in them, no electrical power supply is needed for the magnet itself. To produce the tremendous magnetic fields needed with conventional magnets would require prohibitive amounts of power. But running a superconducting magnet is not a trivial task. The LHC's magnets have to be cooled down to about two degrees C above absolute zero, and only large amounts of liquid helium can do that. So CERN became the world's largest user of helium in its attempt to cool down all the magnets for their inaugural run of the LHC last September.
Nine days after the tests began, an electrical connection between two superconducting magnets apparently failed. In a normal magnet, this would not be that much of a big deal, since an open connection would just cause maybe a transient electrical discharge and then the whole thing would shut down. But with a superconducting magnet, a bad connection causes heat. Heat causes a superconductor to abandon its main desirable property, which is to be superconducting with no resistance. Once some resistance shows up, that generates more heat because the current cannot stop instantaneously in a large magnet. The heat boils off more helium, more of the magnet heats up and gets resistive, and you have a great big vicious circle called a "quench."
Being very large magnets, the LHC units quenched in a big way. The helium pressure was so high it blew all the way into the vacuum tunnel and spread insulation and trash everywhere. Since CERN policy is to clear the tunnel of personnel any time tests like this are going on, no one was injured. But successive press releases in the weeks and months after the accident cited longer and longer delays before the system could be up and running again. As of this writing (July 2009) repairs are still being made, and hopes now are that the LHC can go online again sometime this fall.
While the CERN managers are to be congratulated that this accident didn't hurt or kill anyone, having a multi-billion-dollar machine damage itself to the extent that it takes a year to fix is not exactly wise use of resources either. Any system as complex as the LHC will do unexpected things when first fired up, and CERN has decided to install fault detectors as part of the repair process that will give advance warning of a possible quench condition in the future. This is wise, prudent, and consistent with the highest engineering ethics principles. We just hope it will prevent such accidents in the future.
Which brings us to the larger question: what is all this billions of dollars of machinery and personnel good for? The holy grail of high-energy physics research right now is a thing called the Higgs boson, named after one of the six or seven theoretical physicists who thought of the concept in 1963 and 1964 (somebody had to be first, and it was Peter Higgs). According to the most widely accepted model of subatomic particles, called the Standard Model, the Higgs boson somehow gives mass to all elementary particles (such as electrons, I suppose) that have mass. No one knows how heavy this Higgs boson is, but guesses range from about the weight of a silver atom's nucleus on up. The problem with making really heavy particles like this in a particle accelerator like the LHC is, you need a lot of energy per particle. Current machines can get up to 120 billion electron-volts of energy (120 GeV) into a particle, and the LHC is supposed to reach values about ten times higher. When it finally works. So hopes are high that at long last the elusive Higgs boson will show its face, or tracks, or however they plan to catch one.
Fortunately, nobody has yet had to die for the chance to discover the Higgs boson. But a lot of people have put a lot of effort and money into looking for it, and now after the accident they're having to wait an extra year. Some may look at such work and criticize it on the basis that hey, people are starving in Rwanda and we're spending billions on chasing some pencil-pusher's pipe dream? But the fact that humankind can contemplate the universe and expend lots of energy searching for purely abstract products of the intellect such as the Higgs boson, is one of the things that distinguishes us from animals. I for one wish the CERN workers first safety, then success in their search. But being a Texan, I also wish we'd finished the Supercollider and made Higgs bosons first right here in Waxahachie.
Sources: Several news articles are available on the vicissitudes of the LHC accident. I used material from the U. S. LHC website http://blogs.uslhc.us/?p=393, an article in Discover Magazine online at http://blogs.discovermagazine.com/80beats/2009/02/10/until-next-fall-lhc-smashes-only-hopes-not-particles/, and one at the Big Science News blog at http://bigsciencenews.blogspot.com/2008/09/lhc-quench-stops-cern-re-start-delayed.html. For an instructive news video of what an unplanned superconducting-magnet quench looks like, see the YouTube version of a report on a hospital's MRI magnet that blew up at http://www.youtube.com/watch?v=1R7KsfosV-o.
America used to dominate the field of experimental physics, as our first-out-of-the-gate development of nuclear weapons proved. But with the political collapse of the Superconducting Supercollider project, a Texas-based particle accelerator that was cancelled in 1993, the world leadership in high-energy experimental physics began to move to Europe, where last September the Large Hadron Collider was being put through its initial tests.
State-of-the-art particle accelerators are some of the most complex experimental systems ever built. The LHC resides in an underground tunnel 17 miles in circumference under the border between France and Switzerland. The basic idea is to shove atomic nuclei around a huge evacuated pipe with the aid of strong electromagnetic fields and the guidance of monstrous superconducting magnets that have to be submerged in tons of liquid helium. Such enterprises are of course very costly in comparison to more modest laboratory equipment, but a $5 billion expenditure these days when the U. S. Congress is cogitating about health-care programs costing 200 times that much doesn't seem like a lot of money. Nevertheless, you want to protect your investment even if it is only $5 billion, and that seems to be what got damaged the most in last fall's accident.
Superconducting magnets are used because once you get current running in them, no electrical power supply is needed for the magnet itself. To produce the tremendous magnetic fields needed with conventional magnets would require prohibitive amounts of power. But running a superconducting magnet is not a trivial task. The LHC's magnets have to be cooled down to about two degrees C above absolute zero, and only large amounts of liquid helium can do that. So CERN became the world's largest user of helium in its attempt to cool down all the magnets for their inaugural run of the LHC last September.
Nine days after the tests began, an electrical connection between two superconducting magnets apparently failed. In a normal magnet, this would not be that much of a big deal, since an open connection would just cause maybe a transient electrical discharge and then the whole thing would shut down. But with a superconducting magnet, a bad connection causes heat. Heat causes a superconductor to abandon its main desirable property, which is to be superconducting with no resistance. Once some resistance shows up, that generates more heat because the current cannot stop instantaneously in a large magnet. The heat boils off more helium, more of the magnet heats up and gets resistive, and you have a great big vicious circle called a "quench."
Being very large magnets, the LHC units quenched in a big way. The helium pressure was so high it blew all the way into the vacuum tunnel and spread insulation and trash everywhere. Since CERN policy is to clear the tunnel of personnel any time tests like this are going on, no one was injured. But successive press releases in the weeks and months after the accident cited longer and longer delays before the system could be up and running again. As of this writing (July 2009) repairs are still being made, and hopes now are that the LHC can go online again sometime this fall.
While the CERN managers are to be congratulated that this accident didn't hurt or kill anyone, having a multi-billion-dollar machine damage itself to the extent that it takes a year to fix is not exactly wise use of resources either. Any system as complex as the LHC will do unexpected things when first fired up, and CERN has decided to install fault detectors as part of the repair process that will give advance warning of a possible quench condition in the future. This is wise, prudent, and consistent with the highest engineering ethics principles. We just hope it will prevent such accidents in the future.
Which brings us to the larger question: what is all this billions of dollars of machinery and personnel good for? The holy grail of high-energy physics research right now is a thing called the Higgs boson, named after one of the six or seven theoretical physicists who thought of the concept in 1963 and 1964 (somebody had to be first, and it was Peter Higgs). According to the most widely accepted model of subatomic particles, called the Standard Model, the Higgs boson somehow gives mass to all elementary particles (such as electrons, I suppose) that have mass. No one knows how heavy this Higgs boson is, but guesses range from about the weight of a silver atom's nucleus on up. The problem with making really heavy particles like this in a particle accelerator like the LHC is, you need a lot of energy per particle. Current machines can get up to 120 billion electron-volts of energy (120 GeV) into a particle, and the LHC is supposed to reach values about ten times higher. When it finally works. So hopes are high that at long last the elusive Higgs boson will show its face, or tracks, or however they plan to catch one.
Fortunately, nobody has yet had to die for the chance to discover the Higgs boson. But a lot of people have put a lot of effort and money into looking for it, and now after the accident they're having to wait an extra year. Some may look at such work and criticize it on the basis that hey, people are starving in Rwanda and we're spending billions on chasing some pencil-pusher's pipe dream? But the fact that humankind can contemplate the universe and expend lots of energy searching for purely abstract products of the intellect such as the Higgs boson, is one of the things that distinguishes us from animals. I for one wish the CERN workers first safety, then success in their search. But being a Texan, I also wish we'd finished the Supercollider and made Higgs bosons first right here in Waxahachie.
Sources: Several news articles are available on the vicissitudes of the LHC accident. I used material from the U. S. LHC website http://blogs.uslhc.us/?p=393, an article in Discover Magazine online at http://blogs.discovermagazine.com/80beats/2009/02/10/until-next-fall-lhc-smashes-only-hopes-not-particles/, and one at the Big Science News blog at http://bigsciencenews.blogspot.com/2008/09/lhc-quench-stops-cern-re-start-delayed.html. For an instructive news video of what an unplanned superconducting-magnet quench looks like, see the YouTube version of a report on a hospital's MRI magnet that blew up at http://www.youtube.com/watch?v=1R7KsfosV-o.
Monday, July 20, 2009
The Third Pole of the Health-Care Debate
In the current debate over how health care in the U. S. should be funded, no one seems to be talking in a first-principles way about the moral underpinnings of the system. As I've said before, technology and engineering are so heavily involved in modern health care that I think engineers are disingenuous if they say they don't have a dog in this fight.
Sometimes situations can be clarified by going to extremes. I will pick three extremes which I think represent the poles of what we could do about health-care funding, and then see what conclusions we can draw about the moral bases of each.
The first pole is the extreme-libertarian solution: get government totally out of health care and let people figure it out on their own. This would mean shutting down Medicare and Medicaid, selling off all government-run hospitals, and letting the chips (and the patients) fall where they might. I think even the most extreme libertarians might blanch at ending such long-established practices as the licensing of doctors, but maybe not. One of my cousins is a libertarian, and he hasn't blanched in years. Surprisingly, this solution might not make much difference to those who are employed at firms that provide good health benefits. But for retired people who have come to rely on government-paid health care, there would be big problems, as well as for many who can't afford private care or insurance for it. This solution maximizes individual freedom from government actions, but if you're poor or retired or both and can't afford medical care, you would be out of luck. This shows the radical individualism of libertarian philosophy, and why it is inferior as a total guide to life.
The second pole is the extreme-socialist solution as is done in Cuba, for example: free health care for everybody. Of course "free" means the government pays for it all, and Except for the sick folks that documentary filmmaker Michael Moore took along with him to Cuba as an example of how much better their health-care system is than ours, I'm not aware of a huge surge of people who travel to Cuba for their marvelous medical institutions or services. The fact is that any government, especially Cuba's, has finite resources, and when resources are allocated by bureaucrats rather than markets, the results are often less than optimal, even if there are enough resources to begin with, which in the case of Cuba is doubtful. This solution removes a person's economic status from the equation, at least in theory, but requires rationing, waiting lines, and a pretty low average level of quality. Besides which, it seems that government-run health care systems tend to encourage a psychological dependency on the state which some think is mentally unhealthy in the long run. As with most "free" offers, free medical care often comes with political enslavement.
Most debates about the subject seem to be focused on just where between these two poles we ought to land. But I think that leaves out a critical factor, which I will dignify with the designation of my third pole. It's not easy to think of a name for this pole that will not evoke negative connotations. Perhaps "charity" in the older sense of "love" would cover it. Many private and public hospitals provide services to indigent patients whose costs they absorb, which means that everybody else who uses the hospital helps pay for it. Historically, the idea of caring for the sick without consideration of cost was a founding principle of many medical institutions with religious backgrounds. Many hospitals were staffed by nuns who took vows of poverty. And I think when this motivation is present, it forms the best of all foundations for individual careers and institutional principles. Would you rather be treated by a doctor who went into the business because he wanted to help people, or because he could make a pile of money? Yes, skill is part of the equation, but skill is more than mere technical proficiency. Being a quality of character, charity does not fit easily into economic calculations or political structures. But the first two poles either discount it totally or regard it as an unreliable and suspect motivation that is best ignored in favor of government-run solutions to the problem.
Many religious leaders, up to and including Jesus, made healing a vital part of their ministries. I do not have all the answers to our health-care problems, but I think we should consider making more room for and encouraging those who provide care in the neighborhood of the third pole—people and institutions who help patients because it is the right thing to do, not just because they can make money at it or because the government compels them to. If the debate can center more around this idea, I think the outcome, whatever measures it takes from the other two poles, will be better than otherwise.
Sometimes situations can be clarified by going to extremes. I will pick three extremes which I think represent the poles of what we could do about health-care funding, and then see what conclusions we can draw about the moral bases of each.
The first pole is the extreme-libertarian solution: get government totally out of health care and let people figure it out on their own. This would mean shutting down Medicare and Medicaid, selling off all government-run hospitals, and letting the chips (and the patients) fall where they might. I think even the most extreme libertarians might blanch at ending such long-established practices as the licensing of doctors, but maybe not. One of my cousins is a libertarian, and he hasn't blanched in years. Surprisingly, this solution might not make much difference to those who are employed at firms that provide good health benefits. But for retired people who have come to rely on government-paid health care, there would be big problems, as well as for many who can't afford private care or insurance for it. This solution maximizes individual freedom from government actions, but if you're poor or retired or both and can't afford medical care, you would be out of luck. This shows the radical individualism of libertarian philosophy, and why it is inferior as a total guide to life.
The second pole is the extreme-socialist solution as is done in Cuba, for example: free health care for everybody. Of course "free" means the government pays for it all, and Except for the sick folks that documentary filmmaker Michael Moore took along with him to Cuba as an example of how much better their health-care system is than ours, I'm not aware of a huge surge of people who travel to Cuba for their marvelous medical institutions or services. The fact is that any government, especially Cuba's, has finite resources, and when resources are allocated by bureaucrats rather than markets, the results are often less than optimal, even if there are enough resources to begin with, which in the case of Cuba is doubtful. This solution removes a person's economic status from the equation, at least in theory, but requires rationing, waiting lines, and a pretty low average level of quality. Besides which, it seems that government-run health care systems tend to encourage a psychological dependency on the state which some think is mentally unhealthy in the long run. As with most "free" offers, free medical care often comes with political enslavement.
Most debates about the subject seem to be focused on just where between these two poles we ought to land. But I think that leaves out a critical factor, which I will dignify with the designation of my third pole. It's not easy to think of a name for this pole that will not evoke negative connotations. Perhaps "charity" in the older sense of "love" would cover it. Many private and public hospitals provide services to indigent patients whose costs they absorb, which means that everybody else who uses the hospital helps pay for it. Historically, the idea of caring for the sick without consideration of cost was a founding principle of many medical institutions with religious backgrounds. Many hospitals were staffed by nuns who took vows of poverty. And I think when this motivation is present, it forms the best of all foundations for individual careers and institutional principles. Would you rather be treated by a doctor who went into the business because he wanted to help people, or because he could make a pile of money? Yes, skill is part of the equation, but skill is more than mere technical proficiency. Being a quality of character, charity does not fit easily into economic calculations or political structures. But the first two poles either discount it totally or regard it as an unreliable and suspect motivation that is best ignored in favor of government-run solutions to the problem.
Many religious leaders, up to and including Jesus, made healing a vital part of their ministries. I do not have all the answers to our health-care problems, but I think we should consider making more room for and encouraging those who provide care in the neighborhood of the third pole—people and institutions who help patients because it is the right thing to do, not just because they can make money at it or because the government compels them to. If the debate can center more around this idea, I think the outcome, whatever measures it takes from the other two poles, will be better than otherwise.
Monday, July 13, 2009
Cyber-Security and North Korea: Worth Worrying About?
Beginning on July 4, numerous government and private websites in both South Korea and the U. S. succumbed temporarily to attacks by a shadowy entity suspected of connections with North Korea. Although the damage and disruption were temporary, this sort of thing may be a small wave of a big future for web-based warfare. But unlike conventional warfare, which has at least the restrictions of the Geneva Convention, cyber-warfare is so new that there are few international agreements about it, and even less agreement among those responsible in the U. S. as to what should be done to defend against it.
First, the attacks. According to the Wall Street Journal, they were "relatively unsophisticated," but that doesn't mean they weren't effective. The distributed denial-of-service attacks were carried out by large numbers of computers which harbored a virus that ordered them to flood the targeted websites with requests for service. It takes time for website operators to notice what's going on, get a fix on where it's coming from, computationally speaking, and devise work-arounds to restore service to legitimate users. In the case of these attacks, the time involved was as long as three to four days during which service was interrupted or degraded to some degree. Besides several government-operated websites in North Korea, U. S. websites operated by the Defense Department, the Federal Aviation Administration, and private entities such as the New York Stock Exchange and Amazon.com were attacked.
Although positive identification in these types of attacks is difficult, the timing and other characteristics of the attacks makes it likely that North Korea is responsible. North Korean dictator Kim Jong Il is in poor health and has not made public his plans for a transfer of power. That makes the normally volatile country even more unstable and likely to pull malicious pranks such as nuclear-weapons tests and missile firings, which have also occurred in recent months. But when should we quit calling these web attacks pranks and take them more seriously?
Cyber-warfare is the ultimate in modern conflicts. It resembles conventional terrorist actions such as suicide bombings in that its effects are large in proportion to the resources required, its perpetrators wear no uniforms and can blend into the civilian populace easily, and identifying even so broad a category as the country of origin for a cyber-attack is difficult, let alone finding the people responsible. As far as I know, no one has died as a direct consequence of a cyber-attack, although as more and more life-critical systems from medical care to power grids depend on the Internet, this may soon change. Websites accessible to the general public are the easiest targets, but the harm caused by disabling them is generally limited to loss of revenue or public access, which is inconvenient but not life-threatening.
We can expect that attackers will grow in sophistication and focus as time goes on. There is already some concern that critical infrastructure systems that use the Internet are more vulnerable to attack than they should be. But if history is any guide, we will coast along in blissful ignorance until someone wreaks real harm—death or destruction of large amounts of real property—before steps are taken to remedy these vulnerabilities.
Conventional wars were fought over physical objectives such as territory, natural resources, or lives. As much as many terrorists would like to, no one has yet figured out a way to kill you by means of your own computer, unless you count grabbing your laptop and lamming you over the head with it. There is a cautionary lesson here for those who would like to integrate their own bodies with the web by direct implants of nerve-stimulating devices in the brain and so on. If a computer does something I don't like, I can always walk away. But if it's wired permanently to my brain and some hacker gets his hands on it, I won't have that option. There's a sci-fi movie for you, but one I wouldn't want to watch.
President Obama, to his credit, appears to be the most web-savvy occupant of the White House so far. But his plans to name a cyber-czar in charge of government internet security have hung in limbo as he searches for a suitable candidate. It's not like the President has nothing else to do, but this may be one of those cases where we will wish he'd paid a little more attention to a low-profile matter at the expense of one more town-hall meeting on health care, for example.
All the same, I hope that such a czar will wear his or her authority lightly. One of the strengths of the Internet, and the cyberworld as a whole, is the way that highly distributed expertise works very effectively most of the time to remedy problems as they occur. It is an example of engineering ethics at work that is quiet, not flashy, but worthy of our attention nonetheless. The great majority of computer and networking experts have a vision of the way things ought to be that is both moral and efficient, and tend to work most of the time in cooperation with each other to keep things running well. But the strength of such distributed expertise is also its weakness, in that it takes only a few malicious people who grab the controls to mess things up. Let's hope that we can mount organized defenses against such attacks in time to thwart them before they cause the kind of headlines that 9/11 received.
Sources: I used information from the following articles on the recent cyber-attacks: a piece by Donald Kirk of the Christian Science Monitor at http://www.csmonitor.com/2009/0708/p06s24-woap.html, and an article in the online edition of the Wall Street Journal by Siobhan Gorman and Evan Ramstad at http://online.wsj.com/article/SB124701806176209691.html.
First, the attacks. According to the Wall Street Journal, they were "relatively unsophisticated," but that doesn't mean they weren't effective. The distributed denial-of-service attacks were carried out by large numbers of computers which harbored a virus that ordered them to flood the targeted websites with requests for service. It takes time for website operators to notice what's going on, get a fix on where it's coming from, computationally speaking, and devise work-arounds to restore service to legitimate users. In the case of these attacks, the time involved was as long as three to four days during which service was interrupted or degraded to some degree. Besides several government-operated websites in North Korea, U. S. websites operated by the Defense Department, the Federal Aviation Administration, and private entities such as the New York Stock Exchange and Amazon.com were attacked.
Although positive identification in these types of attacks is difficult, the timing and other characteristics of the attacks makes it likely that North Korea is responsible. North Korean dictator Kim Jong Il is in poor health and has not made public his plans for a transfer of power. That makes the normally volatile country even more unstable and likely to pull malicious pranks such as nuclear-weapons tests and missile firings, which have also occurred in recent months. But when should we quit calling these web attacks pranks and take them more seriously?
Cyber-warfare is the ultimate in modern conflicts. It resembles conventional terrorist actions such as suicide bombings in that its effects are large in proportion to the resources required, its perpetrators wear no uniforms and can blend into the civilian populace easily, and identifying even so broad a category as the country of origin for a cyber-attack is difficult, let alone finding the people responsible. As far as I know, no one has died as a direct consequence of a cyber-attack, although as more and more life-critical systems from medical care to power grids depend on the Internet, this may soon change. Websites accessible to the general public are the easiest targets, but the harm caused by disabling them is generally limited to loss of revenue or public access, which is inconvenient but not life-threatening.
We can expect that attackers will grow in sophistication and focus as time goes on. There is already some concern that critical infrastructure systems that use the Internet are more vulnerable to attack than they should be. But if history is any guide, we will coast along in blissful ignorance until someone wreaks real harm—death or destruction of large amounts of real property—before steps are taken to remedy these vulnerabilities.
Conventional wars were fought over physical objectives such as territory, natural resources, or lives. As much as many terrorists would like to, no one has yet figured out a way to kill you by means of your own computer, unless you count grabbing your laptop and lamming you over the head with it. There is a cautionary lesson here for those who would like to integrate their own bodies with the web by direct implants of nerve-stimulating devices in the brain and so on. If a computer does something I don't like, I can always walk away. But if it's wired permanently to my brain and some hacker gets his hands on it, I won't have that option. There's a sci-fi movie for you, but one I wouldn't want to watch.
President Obama, to his credit, appears to be the most web-savvy occupant of the White House so far. But his plans to name a cyber-czar in charge of government internet security have hung in limbo as he searches for a suitable candidate. It's not like the President has nothing else to do, but this may be one of those cases where we will wish he'd paid a little more attention to a low-profile matter at the expense of one more town-hall meeting on health care, for example.
All the same, I hope that such a czar will wear his or her authority lightly. One of the strengths of the Internet, and the cyberworld as a whole, is the way that highly distributed expertise works very effectively most of the time to remedy problems as they occur. It is an example of engineering ethics at work that is quiet, not flashy, but worthy of our attention nonetheless. The great majority of computer and networking experts have a vision of the way things ought to be that is both moral and efficient, and tend to work most of the time in cooperation with each other to keep things running well. But the strength of such distributed expertise is also its weakness, in that it takes only a few malicious people who grab the controls to mess things up. Let's hope that we can mount organized defenses against such attacks in time to thwart them before they cause the kind of headlines that 9/11 received.
Sources: I used information from the following articles on the recent cyber-attacks: a piece by Donald Kirk of the Christian Science Monitor at http://www.csmonitor.com/2009/0708/p06s24-woap.html, and an article in the online edition of the Wall Street Journal by Siobhan Gorman and Evan Ramstad at http://online.wsj.com/article/SB124701806176209691.html.
Monday, July 06, 2009
Exclusive: Why the Austin Scaffolding Fell
On June 10 of this year, three construction workers died when a section of scaffolding collapsed at a construction site near the campus of the University of Texas at Austin. Because the accident resulted in deaths, personnel from the U. S. Occupational Safety and Health Administration began an investigation shortly thereafter. While it is the normal policy of OSHA not to divulge information on an investigation that is incomplete, leaks do occur. If you keep reading, you will be the beneficiary of one such leak. But first, some details about the accident.
Photographs published at the time showed that the scaffolding was a cantilevered box frame that extended several yards on either side of an elevator-type mechanism that allowed the whole thing to move up and down the side of the high-rise apartment complex under construction. Photos of units on the manufacturer's website show that the scaffolding can extend as far as 25 or 30 feet either side of the mast that supports it. The workers using the scaffolding walk along the frame to do whatever operations the construction job requires.
There's no particular mechanical-engineering magic to cantilevering. Like a branch of a tree that sticks out sideways, the box frame's unbalanced weight has to be supported by the central elevator. In particular, the bolts that keep the top of the box frame attached to the elevator unit are under tremendous tension, since the whole weight of the frame tends to pull the bolts away from the elevator. If these bolts aren't strong enough and fail, the scaffolding will fall away like a branch cracking off a dead tree. That is apparently what happened on June 10.
The following information is what the newspeople call an unconfirmed report from an anonymous source. But I believe it to be reliable. According to the source, the bolts used in the scaffolding that failed were not the required Grade 5 type. If you have ever bought bolts at a hardware store, you may have noticed little patterns of lines on the hexagonal bolt head. These are not just random forging marks. They indicate the quality of steel in the bolt, and in particular, the maximum stress the bolt can withstand. Grade 5 bolts have three embossed lines in a "Y" pattern on the bolt head, indicating that they can take up to 120,000 pounds per square inch of stress under certain defined conditions. Cheaper bolts with no head markings are available. For example, Grade 1 bolts have only about half the stress capacity of Grade 5.
Assuming my source is correct, how did the wrong bolts get there? To answer that question requires that we move from the realm of science to the realm of human behavior. The problem could lie anywhere from the manufacturer of the scaffolding, to the general contractor for the site, to the subcontractor who installed the scaffolding, to the subcontractor's employees who put it together, to someone else who might have lost the Grade 5 bolts and substituted others without knowing the danger it would cause. Presumably the OSHA investigators are also working on this angle of the problem, which will require extensive interviews and inquiries which may never reach a satisfactory conclusion. But this shows the vital importance of apparently minor details, such as three little lines on a bolt head, to the safety of construction workers who probably had nothing to do with the assembly of the scaffolding.
A subsequent news article in the Austin American-Statesman pointed out that Texas has one of the worst records in the U. S. for construction-related fatalities. Pay rates are low, some construction employers opt out of workers' compensation insurance, and since OSHA primarily investigates complaints lodged by workers, the workers have to be their own safety inspectors. Since many speak only Spanish and some are undocumented, their reluctance to undertake this role is understandable. Simply identifying the next of kin of the workers killed in this accident was a challenge to authorities, since their families lived in small towns in Mexico.
How can accidents like this be prevented in the future?
This incident shows how vital the "soft" technologies of training, inspection, and good management can be to safety improvements. Even if we give the benefit of the doubt to the contractor and subcontractors by assuming the use of the cheaper bolts was accidental, the accident reveals a grave deficiency in the way supplies are inventoried and assembly procedures are carried out. No human-operated process can be made 100% foolproof, but if certain bolts have to be Grade 5 in order for a scaffold to be assembled safely, there must be a way to make sure that only Grade 5 bolts go into the system. Simple things like matching spray-paint colors or other wordless guidelines can go far to prevent tragedies like this, especially where non-English speaking employees are involved.
Such measures come too late for the three workers who died when the less expensive bolts apparently failed. But I hope as more details emerge, the lessons of how to avoid this kind of accident won't be lost on those who are in a position to make sure their employees and subcontractors have a safe working environment.
Sources: My source for the bolt information is anonymous for the simple reason that I do not know his name. Published information on the scaffolding collapse can be found on the Austin American-Statesman website at http://www.statesman.com/search/content/news/stories/local/2009/06/17/0617construction.html. Information on the grades of bolts available can be found at http://www.engineershandbook.com/Tables/boltgrades.htm.
Photographs published at the time showed that the scaffolding was a cantilevered box frame that extended several yards on either side of an elevator-type mechanism that allowed the whole thing to move up and down the side of the high-rise apartment complex under construction. Photos of units on the manufacturer's website show that the scaffolding can extend as far as 25 or 30 feet either side of the mast that supports it. The workers using the scaffolding walk along the frame to do whatever operations the construction job requires.
There's no particular mechanical-engineering magic to cantilevering. Like a branch of a tree that sticks out sideways, the box frame's unbalanced weight has to be supported by the central elevator. In particular, the bolts that keep the top of the box frame attached to the elevator unit are under tremendous tension, since the whole weight of the frame tends to pull the bolts away from the elevator. If these bolts aren't strong enough and fail, the scaffolding will fall away like a branch cracking off a dead tree. That is apparently what happened on June 10.
The following information is what the newspeople call an unconfirmed report from an anonymous source. But I believe it to be reliable. According to the source, the bolts used in the scaffolding that failed were not the required Grade 5 type. If you have ever bought bolts at a hardware store, you may have noticed little patterns of lines on the hexagonal bolt head. These are not just random forging marks. They indicate the quality of steel in the bolt, and in particular, the maximum stress the bolt can withstand. Grade 5 bolts have three embossed lines in a "Y" pattern on the bolt head, indicating that they can take up to 120,000 pounds per square inch of stress under certain defined conditions. Cheaper bolts with no head markings are available. For example, Grade 1 bolts have only about half the stress capacity of Grade 5.
Assuming my source is correct, how did the wrong bolts get there? To answer that question requires that we move from the realm of science to the realm of human behavior. The problem could lie anywhere from the manufacturer of the scaffolding, to the general contractor for the site, to the subcontractor who installed the scaffolding, to the subcontractor's employees who put it together, to someone else who might have lost the Grade 5 bolts and substituted others without knowing the danger it would cause. Presumably the OSHA investigators are also working on this angle of the problem, which will require extensive interviews and inquiries which may never reach a satisfactory conclusion. But this shows the vital importance of apparently minor details, such as three little lines on a bolt head, to the safety of construction workers who probably had nothing to do with the assembly of the scaffolding.
A subsequent news article in the Austin American-Statesman pointed out that Texas has one of the worst records in the U. S. for construction-related fatalities. Pay rates are low, some construction employers opt out of workers' compensation insurance, and since OSHA primarily investigates complaints lodged by workers, the workers have to be their own safety inspectors. Since many speak only Spanish and some are undocumented, their reluctance to undertake this role is understandable. Simply identifying the next of kin of the workers killed in this accident was a challenge to authorities, since their families lived in small towns in Mexico.
How can accidents like this be prevented in the future?
This incident shows how vital the "soft" technologies of training, inspection, and good management can be to safety improvements. Even if we give the benefit of the doubt to the contractor and subcontractors by assuming the use of the cheaper bolts was accidental, the accident reveals a grave deficiency in the way supplies are inventoried and assembly procedures are carried out. No human-operated process can be made 100% foolproof, but if certain bolts have to be Grade 5 in order for a scaffold to be assembled safely, there must be a way to make sure that only Grade 5 bolts go into the system. Simple things like matching spray-paint colors or other wordless guidelines can go far to prevent tragedies like this, especially where non-English speaking employees are involved.
Such measures come too late for the three workers who died when the less expensive bolts apparently failed. But I hope as more details emerge, the lessons of how to avoid this kind of accident won't be lost on those who are in a position to make sure their employees and subcontractors have a safe working environment.
Sources: My source for the bolt information is anonymous for the simple reason that I do not know his name. Published information on the scaffolding collapse can be found on the Austin American-Statesman website at http://www.statesman.com/search/content/news/stories/local/2009/06/17/0617construction.html. Information on the grades of bolts available can be found at http://www.engineershandbook.com/Tables/boltgrades.htm.
Monday, June 29, 2009
If We Fixed Cars In the U. S. the Way We Fix People
You would typically get auto insurance (including insurance for major repairs) as an employment benefit, and you'd never see the money. If you lost your job, you'd either have to buy very expensive insurance on the open market, or just hope your car didn't break down before you got another job.
If you had insurance, all you'd have to pay at the repair shop would be a small copayment of twenty or thirty dollars. The insurance would cover the rest.
Many people with a car problem would first have to take their car to their primary care mechanic (PCM), no matter what was wrong. If it was the brakes, your PCM would have to write you a referral to a brake specialist before you could get your brakes fixed. Of course, you could just pay for the repair yourself, but that would cost many thousands of dollars.
You could do minor repairs yourself, but for something major like a new starter, you couldn't just walk into the parts store and buy a new one. You'd first have to get a handwritten note from your PCM. Then you'd take the note to a special parts store that has college-trained salespeople licensed to sell the higher grades of auto parts, and buy the part from one of them.
Every auto repair shop would have huge filing cabinets with multicolored file tabs sticking out of them, one file for each car. All the important records on your car would be written by hand.
Minor repairs would be made in small shops, but major repairs would take place in a few giant facilities in each metropolitan area, where hundreds of cars would be collected together for repairs. Getting an estimate for repairs at one of these mega-shops would be next to impossible. Instead, you just take your car in, wait till they fix it, and hope your insurance will pay for it.
Reading a repair bill would be an exercise in mystification. Even professional accountants couldn't explain why the repair shop would charge $674.92 for replacing a U-joint, the auto insurance would pay $407.17, and you would end up owing $103.37.
Mechanics would check for the most unlikely problems even when the issue was a simple one. You might take your car in because the wiper blades needed replacing, and the mechanic might do a stress test on the windshield and charge the insurance company $400.00 for it. But you could rest assured that your windshield wasn't about to shatter spontaneously, which happens maybe once in every 30 million passenger miles.
Auto mechanics would have to go to school for six to eight years after their BS degree and pay back hundreds of thousands of dollars in school loans before getting their license to fix cars. But they would earn almost as much as lawyers do, if they could keep ahead of their own soaring insurance premiums. If you didn't have a government-sanctioned auto repair license and you tried to fix anybody else's car, you could go to jail.
Gasoline additives would be a multi-billion-dollar business, funded with a combination of government support and private money. Universities would have special auto-repair branches and auto-repair research departments to develop new additives and repair techniques.
Mechanics could be hauled into court and made to pay millions for faulty repairs. Mechanical malpractice law would be a lucrative branch of the legal business.
Eventually, things would get so screwed up that the U. S. government would wade into the mess and take over large portions of it, promising to manage things better than the former private owners did. Of course, that's exactly what has happened with the U. S. auto industry already—so maybe it's time to wind up this little fantasy. . . .
Health care in the U. S. is a complex system that can be viewed as a technology. And it is fraught inside and out with ethical implications, so I think the current debate over what should be done about health care is fair game for an engineering ethics blog, broadly defined.
Of course, people aren't cars, and the analogy between car repair and health care breaks down if you examine it seriously. But sometimes casting a familiar situation in a new light will reveal problems in a way that more people can understand. For example, it is a fact that most people don't know they pay an average of $400 a month for health care—either as a deduction from their paycheck, or a contribution from their employer, or typically both. If you had to write a health-insurance check for $400 from your own pocket every month (as some self-employed people do), that single change would bring the reality of health-care costs home in a way that no number of TV ads will do. Most people do pay for their car repairs out of their own pocket. If we had the direct price information that would let us pay attention to the quality and price of health care in the same way we evaluate an auto mechanic's services, it would do a lot to reduce needless health-care expenses.
Eliminating the employer tax deduction for health-care costs, if done the right way, will be a step in this direction. But not if it is done just as a way to raise revenue and make a government-funded public insurance option more attractive.
As the debate develops, it seems to be coming down to a single question: Who can exert more effective discipline on the health-services sector: a set of government bureaucracies that will ration and regulate the system, or an enlightened public which is allowed to see the costs of health care directly and make their own judgments as to which insurance plan and caregiver is best for them? The latter option still has a role for government, possibly as the provider of last resort for insurance or services for those who can't afford them, and as a check on rampantly malicious behavior on the part of powerful institutions.
Either there will be major changes in the way health care is delivered in this country by later this fall, or there won't be. Sometimes no change is better than a bad change. After all, we could be worse off. Surveys indicate that most people are reasonably contented with their present state of health care. The trick will be to help the groups who are under-served without worsening the status of those who like what they have already—and not do something else awful like run the government into bankruptcy in the meantime.
If you had insurance, all you'd have to pay at the repair shop would be a small copayment of twenty or thirty dollars. The insurance would cover the rest.
Many people with a car problem would first have to take their car to their primary care mechanic (PCM), no matter what was wrong. If it was the brakes, your PCM would have to write you a referral to a brake specialist before you could get your brakes fixed. Of course, you could just pay for the repair yourself, but that would cost many thousands of dollars.
You could do minor repairs yourself, but for something major like a new starter, you couldn't just walk into the parts store and buy a new one. You'd first have to get a handwritten note from your PCM. Then you'd take the note to a special parts store that has college-trained salespeople licensed to sell the higher grades of auto parts, and buy the part from one of them.
Every auto repair shop would have huge filing cabinets with multicolored file tabs sticking out of them, one file for each car. All the important records on your car would be written by hand.
Minor repairs would be made in small shops, but major repairs would take place in a few giant facilities in each metropolitan area, where hundreds of cars would be collected together for repairs. Getting an estimate for repairs at one of these mega-shops would be next to impossible. Instead, you just take your car in, wait till they fix it, and hope your insurance will pay for it.
Reading a repair bill would be an exercise in mystification. Even professional accountants couldn't explain why the repair shop would charge $674.92 for replacing a U-joint, the auto insurance would pay $407.17, and you would end up owing $103.37.
Mechanics would check for the most unlikely problems even when the issue was a simple one. You might take your car in because the wiper blades needed replacing, and the mechanic might do a stress test on the windshield and charge the insurance company $400.00 for it. But you could rest assured that your windshield wasn't about to shatter spontaneously, which happens maybe once in every 30 million passenger miles.
Auto mechanics would have to go to school for six to eight years after their BS degree and pay back hundreds of thousands of dollars in school loans before getting their license to fix cars. But they would earn almost as much as lawyers do, if they could keep ahead of their own soaring insurance premiums. If you didn't have a government-sanctioned auto repair license and you tried to fix anybody else's car, you could go to jail.
Gasoline additives would be a multi-billion-dollar business, funded with a combination of government support and private money. Universities would have special auto-repair branches and auto-repair research departments to develop new additives and repair techniques.
Mechanics could be hauled into court and made to pay millions for faulty repairs. Mechanical malpractice law would be a lucrative branch of the legal business.
Eventually, things would get so screwed up that the U. S. government would wade into the mess and take over large portions of it, promising to manage things better than the former private owners did. Of course, that's exactly what has happened with the U. S. auto industry already—so maybe it's time to wind up this little fantasy. . . .
Health care in the U. S. is a complex system that can be viewed as a technology. And it is fraught inside and out with ethical implications, so I think the current debate over what should be done about health care is fair game for an engineering ethics blog, broadly defined.
Of course, people aren't cars, and the analogy between car repair and health care breaks down if you examine it seriously. But sometimes casting a familiar situation in a new light will reveal problems in a way that more people can understand. For example, it is a fact that most people don't know they pay an average of $400 a month for health care—either as a deduction from their paycheck, or a contribution from their employer, or typically both. If you had to write a health-insurance check for $400 from your own pocket every month (as some self-employed people do), that single change would bring the reality of health-care costs home in a way that no number of TV ads will do. Most people do pay for their car repairs out of their own pocket. If we had the direct price information that would let us pay attention to the quality and price of health care in the same way we evaluate an auto mechanic's services, it would do a lot to reduce needless health-care expenses.
Eliminating the employer tax deduction for health-care costs, if done the right way, will be a step in this direction. But not if it is done just as a way to raise revenue and make a government-funded public insurance option more attractive.
As the debate develops, it seems to be coming down to a single question: Who can exert more effective discipline on the health-services sector: a set of government bureaucracies that will ration and regulate the system, or an enlightened public which is allowed to see the costs of health care directly and make their own judgments as to which insurance plan and caregiver is best for them? The latter option still has a role for government, possibly as the provider of last resort for insurance or services for those who can't afford them, and as a check on rampantly malicious behavior on the part of powerful institutions.
Either there will be major changes in the way health care is delivered in this country by later this fall, or there won't be. Sometimes no change is better than a bad change. After all, we could be worse off. Surveys indicate that most people are reasonably contented with their present state of health care. The trick will be to help the groups who are under-served without worsening the status of those who like what they have already—and not do something else awful like run the government into bankruptcy in the meantime.
Monday, June 22, 2009
Should You Worry About Oil Sands?
Gasoline prices have been going up in recent weeks, and one reason they haven't gone up more is oil sands in Canada. As Michael Levi, writing in the current issue of Slate, points out, not too long ago Canada took over from Saudi Arabia as the country supplying the most imported oil to the U. S. And a big factor in Canada's oil exports is their production of oil sands.
It turns out that under a large chunk of northeastern Alberta, Canada, the Athabasca oil sands deposit harbors the oil-sands equivalent of the rest of the world's conventional oil reserves combined. What are oil sands? Sometimes referred to as "bitumen," the hydrocarbons in oil sands are tar-like substances that are too thick to flow out of the formations they are found in, as conventional petroleum does. Instead, you have to dig the stuff out with conventional open-pit mining techniques and then process it to make what is called synthetic crude oil. From that point on, the stuff can be treated more or less like regular petroleum.
Because of the added complexity of extraction, oil sands have only recently been exploited commercially on a large scale, and they still form only a fraction of Canada's total oil output. (Venezuela also has a large oil-sands deposit, but the government of Venezuela is not as favorably disposed toward the U. S. as the Canadian government is, to say the least.) Oil sands have received some black environmental marks, both for the relatively large amount of greenhouse gases that result from producing a barrel of oil-sands petroleum compared to a barrel of conventional oil, and for the problems that used water and mine tailings cause.
So what is the right thing to do about oil sands? Do the environmental issues dominate and make us swear off them altogether? Or should we just arrange some very long-term contracts with Canadian produces and quit worrying about the shrinking oil reserves in the rest of the world?
As Levi points out, neither of these extreme alternatives is wise. While the production end of oil-sands operations does make more carbon dioxide, you still end up burning oil at the consumption end, so economies or conservation elsewhere in the system can make up for the additional burden at the production end. Pollution of water and destruction of land due to poor open-pit mining practices are concerns, but if I know our Canadian friends, they are on top of those issues and have found ways of dealing with them.
All the same, it would be the height of complacency to say along with the rich fool in the New Testament parable, "Soul, you have oil sands saved up for many years. Drive, drink, and be merry." I have said before that for reasons of national security, the U. S. ought to devise a long-term plan to move gradually and even profitably toward increased energy independence. With the global oil market the way it is, namely much like a pickup basketball game with no referee, we are taking chances with our economy by relying too much on unstable parts of the world for our energy supplies. Although some weird things go on in Canada, as a whole its government is a lot more reliable than, say, Iran's, so on balance it's a good thing that we are getting more oil from Canada than we get from Saudi Arabia or other Middle Eastern countries. However, the best outcome would be to move, deliberately and without serious damage to the economy, toward a situation where fossil fuels are gradually phased out in preference to an electricity-based energy economy, perhaps powered largely by nuclear plants. But that's just my opinion.
Nuclear has the dual advantage of not emitting any greenhouse gases and of using fuel that is not primarily found in politically unstable parts of the world. Nuclear plants use uranium, and some types can even produce more fuel than they consume. And it turns out that more than half of all the uranium produced in the world is mined in two countries: Canada and Australia, both of which we get along with pretty well.
The difficulty, as always, is how to implement such a plan in a democracy where short-term considerations tend to dominate political discussions. Somehow we can always agree to keep troops here or there for another few years, but we can't agree on a plan to reduce our dependence on oil so much that we wouldn't need to play global policeman so much. The new administration has made efforts in this direction, but with so many other irons in the fire, energy independence is going to take a back seat (to mix a few metaphors).
In the meantime, we can be grateful to our Canadian friends for developing oil sands in an environmentally responsible way. For the next few years we will need to buy oil from somewhere outside the U. S., and Canada looks like a nice place to get it from.
Sources: Michael Levi's article "Living on Canada's Oil" can be found in Slate at http://www.slate.com/id/2220878/. I also used material from the Wikipedia articles on oil sands and uranium.
It turns out that under a large chunk of northeastern Alberta, Canada, the Athabasca oil sands deposit harbors the oil-sands equivalent of the rest of the world's conventional oil reserves combined. What are oil sands? Sometimes referred to as "bitumen," the hydrocarbons in oil sands are tar-like substances that are too thick to flow out of the formations they are found in, as conventional petroleum does. Instead, you have to dig the stuff out with conventional open-pit mining techniques and then process it to make what is called synthetic crude oil. From that point on, the stuff can be treated more or less like regular petroleum.
Because of the added complexity of extraction, oil sands have only recently been exploited commercially on a large scale, and they still form only a fraction of Canada's total oil output. (Venezuela also has a large oil-sands deposit, but the government of Venezuela is not as favorably disposed toward the U. S. as the Canadian government is, to say the least.) Oil sands have received some black environmental marks, both for the relatively large amount of greenhouse gases that result from producing a barrel of oil-sands petroleum compared to a barrel of conventional oil, and for the problems that used water and mine tailings cause.
So what is the right thing to do about oil sands? Do the environmental issues dominate and make us swear off them altogether? Or should we just arrange some very long-term contracts with Canadian produces and quit worrying about the shrinking oil reserves in the rest of the world?
As Levi points out, neither of these extreme alternatives is wise. While the production end of oil-sands operations does make more carbon dioxide, you still end up burning oil at the consumption end, so economies or conservation elsewhere in the system can make up for the additional burden at the production end. Pollution of water and destruction of land due to poor open-pit mining practices are concerns, but if I know our Canadian friends, they are on top of those issues and have found ways of dealing with them.
All the same, it would be the height of complacency to say along with the rich fool in the New Testament parable, "Soul, you have oil sands saved up for many years. Drive, drink, and be merry." I have said before that for reasons of national security, the U. S. ought to devise a long-term plan to move gradually and even profitably toward increased energy independence. With the global oil market the way it is, namely much like a pickup basketball game with no referee, we are taking chances with our economy by relying too much on unstable parts of the world for our energy supplies. Although some weird things go on in Canada, as a whole its government is a lot more reliable than, say, Iran's, so on balance it's a good thing that we are getting more oil from Canada than we get from Saudi Arabia or other Middle Eastern countries. However, the best outcome would be to move, deliberately and without serious damage to the economy, toward a situation where fossil fuels are gradually phased out in preference to an electricity-based energy economy, perhaps powered largely by nuclear plants. But that's just my opinion.
Nuclear has the dual advantage of not emitting any greenhouse gases and of using fuel that is not primarily found in politically unstable parts of the world. Nuclear plants use uranium, and some types can even produce more fuel than they consume. And it turns out that more than half of all the uranium produced in the world is mined in two countries: Canada and Australia, both of which we get along with pretty well.
The difficulty, as always, is how to implement such a plan in a democracy where short-term considerations tend to dominate political discussions. Somehow we can always agree to keep troops here or there for another few years, but we can't agree on a plan to reduce our dependence on oil so much that we wouldn't need to play global policeman so much. The new administration has made efforts in this direction, but with so many other irons in the fire, energy independence is going to take a back seat (to mix a few metaphors).
In the meantime, we can be grateful to our Canadian friends for developing oil sands in an environmentally responsible way. For the next few years we will need to buy oil from somewhere outside the U. S., and Canada looks like a nice place to get it from.
Sources: Michael Levi's article "Living on Canada's Oil" can be found in Slate at http://www.slate.com/id/2220878/. I also used material from the Wikipedia articles on oil sands and uranium.
Monday, June 15, 2009
Health Care as Systems Engineering
This summer promises a great debate over health care in the U. S. It is pretty sure to be great in the sense of historic or significant; what is not so clear is whether the outcome will be great either in the sense of good and positive, or in the ironic sense ("Great! That's just what I needed!"). One perspective that may help us judge the quality of the debate and the outcome is to view health care through the lens of systems engineering. But since health care deals with the most intimate aspects of human life, ethical considerations also show up at all levels, from individual decision-making to nationwide policy.
It is well known that the U. S. pays more per capita for health care than most other industrialized nations, but by many measures we are not that much more healthy than the other countries are. In other words, we're not getting what we're paying for, if we think that spending more health dollars per person will make everybody that much healthier. Viewed as a system with inputs (health care money and resources) and outputs (people treated by the system), our system does not work as efficiently as it could.
Over the last several weeks I have read of certain parts of the country where the health outcomes per Medicare dollar (which is an easy statistic to obtain) are much better than the national average (e. g. Green Bay, Wisconsin, where President Obama recently spoke on the issue), and other areas where they are much worse (e. g. McAllen, Texas, which a recent New Yorker article identified as in the second most expensive county in the country, measured in Medicare-dollar-per-patient terms). One reason for these identifications appears to be the idea that if we can just figure out what the good places are doing right, we can replicate these successes and do away with whatever bad or evil mischief is going on in the expensive places. How likely is that to succeed?
Atul Gawande, the author of the New Yorker piece, thinks the root problem in McAllen lies in the disconnected, revenue-driven nature of the medical culture there. He says many doctors view their practice as a way of making money, and if you want to practice medicine that way there are few barriers to stop you. By contrast, he cites places like the Mayo Clinic, where doctors on salary receive no incentives for ordering extra tests, and participate in meetings designed to improve patient care systematically by coordinating it to eliminate needless and duplicative tests, among other things. He admits, though, that discouraging the former behavior and encouraging the latter will be a long, tricky process.
I think a key element in the solution, if one can be found, lies in a careful study of incentives and disincentives. Although people can't always be relied upon to do the rational thing, most people will make choices they perceive to be in their own best interest. Of course, perception can be distorted through propaganda and so on, but especially where pocketbook matters are concerned, most people make fairly optimal decisions if given the opportunity to do so. One trouble with health care as it exists today is the same problem I have noticed with the college-textbook market: the people who pay for the goods or services (students or patients) are not the people making the decisions (professors or doctors). Although one doctor quoted by Gawande says allowing patients more of an economic stake in medical decision-making is like relying on "the sheep to negotiate with the wolves," it doesn't have to be that one-sided. If people were in economic control of their own health-care expenditures rather than having to rely on their employer (if they have a job in the first place), I think some way could be developed so that the Mayo-Clinic-type coordinated operations and their lower cost per patient could be packaged to be more appealing in an open market, compared to the multiple-stop-shopping of places like McAllen. The comparison is a little unfair, but think of shopping at Wal-Mart versus going to a third-world village market with its street of shoemakers and street of roasted-goat vendors. The streets full of private vendors are colorful and make for great vacation photos, but if all you want is a pair of shoes you'll go to Wal-Mart.
Of course, efficiency can be carried too far, and if we let even the Mayo Clinics coalesce into one giant monopolistic medical provider, the outcome is likely to be bad. But an appropriate level of market openness in which consumers could see economically efficient, good care for what it is, and choose it, would avoid the coercion and potential for debilitating bureaucracy that so many proposals involve.
Healing is a deeply ethical activity. The oldest known professional code of ethics—the Hippocratic Oath—deals with the ethics of medicine, and many religious leaders such as Jesus made healing an important part of their ministry. The problems Gawande and others have identified when healers start to put money over patient care merely demonstrate that the system, whatever form it takes, must have professionals in it whose philosophy or faith makes healing an end in itself, not primarily a means to wealth. Whatever happens to U. S. medical care after this summer's debate, I hope the designers do not lose sight of the fact that, like doctors themselves, they cannot fix the problem the way you would fix a balky lawnmower engine. All they can do is try to create an environment for people of good will to do even better than they are doing now.
Sources: Atul Gawande's article "The Cost Conundrum" appears in the June 1, 2009 issue of The New Yorker.
It is well known that the U. S. pays more per capita for health care than most other industrialized nations, but by many measures we are not that much more healthy than the other countries are. In other words, we're not getting what we're paying for, if we think that spending more health dollars per person will make everybody that much healthier. Viewed as a system with inputs (health care money and resources) and outputs (people treated by the system), our system does not work as efficiently as it could.
Over the last several weeks I have read of certain parts of the country where the health outcomes per Medicare dollar (which is an easy statistic to obtain) are much better than the national average (e. g. Green Bay, Wisconsin, where President Obama recently spoke on the issue), and other areas where they are much worse (e. g. McAllen, Texas, which a recent New Yorker article identified as in the second most expensive county in the country, measured in Medicare-dollar-per-patient terms). One reason for these identifications appears to be the idea that if we can just figure out what the good places are doing right, we can replicate these successes and do away with whatever bad or evil mischief is going on in the expensive places. How likely is that to succeed?
Atul Gawande, the author of the New Yorker piece, thinks the root problem in McAllen lies in the disconnected, revenue-driven nature of the medical culture there. He says many doctors view their practice as a way of making money, and if you want to practice medicine that way there are few barriers to stop you. By contrast, he cites places like the Mayo Clinic, where doctors on salary receive no incentives for ordering extra tests, and participate in meetings designed to improve patient care systematically by coordinating it to eliminate needless and duplicative tests, among other things. He admits, though, that discouraging the former behavior and encouraging the latter will be a long, tricky process.
I think a key element in the solution, if one can be found, lies in a careful study of incentives and disincentives. Although people can't always be relied upon to do the rational thing, most people will make choices they perceive to be in their own best interest. Of course, perception can be distorted through propaganda and so on, but especially where pocketbook matters are concerned, most people make fairly optimal decisions if given the opportunity to do so. One trouble with health care as it exists today is the same problem I have noticed with the college-textbook market: the people who pay for the goods or services (students or patients) are not the people making the decisions (professors or doctors). Although one doctor quoted by Gawande says allowing patients more of an economic stake in medical decision-making is like relying on "the sheep to negotiate with the wolves," it doesn't have to be that one-sided. If people were in economic control of their own health-care expenditures rather than having to rely on their employer (if they have a job in the first place), I think some way could be developed so that the Mayo-Clinic-type coordinated operations and their lower cost per patient could be packaged to be more appealing in an open market, compared to the multiple-stop-shopping of places like McAllen. The comparison is a little unfair, but think of shopping at Wal-Mart versus going to a third-world village market with its street of shoemakers and street of roasted-goat vendors. The streets full of private vendors are colorful and make for great vacation photos, but if all you want is a pair of shoes you'll go to Wal-Mart.
Of course, efficiency can be carried too far, and if we let even the Mayo Clinics coalesce into one giant monopolistic medical provider, the outcome is likely to be bad. But an appropriate level of market openness in which consumers could see economically efficient, good care for what it is, and choose it, would avoid the coercion and potential for debilitating bureaucracy that so many proposals involve.
Healing is a deeply ethical activity. The oldest known professional code of ethics—the Hippocratic Oath—deals with the ethics of medicine, and many religious leaders such as Jesus made healing an important part of their ministry. The problems Gawande and others have identified when healers start to put money over patient care merely demonstrate that the system, whatever form it takes, must have professionals in it whose philosophy or faith makes healing an end in itself, not primarily a means to wealth. Whatever happens to U. S. medical care after this summer's debate, I hope the designers do not lose sight of the fact that, like doctors themselves, they cannot fix the problem the way you would fix a balky lawnmower engine. All they can do is try to create an environment for people of good will to do even better than they are doing now.
Sources: Atul Gawande's article "The Cost Conundrum" appears in the June 1, 2009 issue of The New Yorker.
Monday, June 08, 2009
The Air France Crash: More Questions Than Answers
The crash of Air France flight 447 from Rio de Janeiro to Paris on the last day of May is bad news for a number of reasons. The deaths of all 228 people on board make it the worst air disaster since 2001. And while advancing technology has enabled investigators to recover a limited amount of flight data through a remote data link that was operating at the time of the crash, the deep waters where the plane went down may prevent the recovery of the "black box" containing voice and detailed data recordings.
What do we know today, eight days after the crash? There were thunderstorms in the area that night, and early speculation centered on the possibility of a lightning strike to the plane. Although lightning hits planes hundreds of times a year, relatively little damage usually occurs and most modern aircraft can be considered essentially (though not totally) lightning-proof. Evidently, there was a satellite or other radio-mediated data link which was continually feeding certain types of flight data to the ground. Examination of this data shows that the flight speeds during the last minute or so of the flight became "incoherent," followed by a loss of cabin pressure and failure of electrical systems. While this information will be helpful in deciphering what went wrong, it apparently lacks the detail that flight data recorders can preserve. One can imagine a day when such radio links will take the place of, or at least duplicate, the capabilities of flight data recorders so that mechanical recovery of the black box will no longer be so urgent. The black box is designed to emit a sonar signal for 30 days after the crash, so the underwater recovery crews gearing up to find it are operating under tremendous time pressure, not to mention the water pressure at depths exceeding 20,000 feet. The box may never be found.
Recent news reports have focused on the fact that the plane's Pitot tube, the device that measures airspeed, had not yet been replaced with a newer model as the plane's manufacturer Airbus recommended. A Pitot tube is a small tube that faces directly into the airstream. The difference in pressure between the air inside the tube (which is blocked off and registers what is called "stagnation pressure") and the ambient or "static" air pressure, is an indication of airspeed, which is the most important kind of speed to know about when you are trying to fly a plane. These days, when most parts of a flight except for landing and takeoff are under automatic control, the airspeed data from the Pitot tube forms part of an elaborate computer-controlled feedback loop that maintains constant speed, altitude, and other flight characteristics.
The old saw about computers regarding "garbage in, garbage out" goes double when a feedback loop is involved. If enough ice forms on a Pitot tube to plug up the entrance, the indicated airspeed goes way below what is actually the case, and either the automatic pilot guns the engines inappropriately or the real pilots may take incorrect action based on faulty airspeed data. This is exactly what happened to an Argentine DC-9 flight in 1999, which resulted in a spectacular crash, killing all aboard.
Although I have no independent information on this, I hope that modern aircraft such as the Air France A330 that crashed have more than one means of measuring speed: either a second Pitot tube (which of course would be just as likely to ice up as the first one), or other means such as radar altimeter and speed measurements or GPS-based airspeed indicators. But whether the autopilot takes all these other inputs into consideration, and whether the real pilots do too, I don't know. Clearly, if the Pitot tube was involved in this crash, the right thing to do in the circumstances wasn't done.
All flight-critical Pitot tubes have heaters to prevent icing, but evidently the one on Flight 447 was deficient or non-optimal in some way, or else Airbus wouldn't have recommended replacing it. Of course replacements can be recommended for all kinds of reasons, some of which have nothing to do with safety. All that will come out in the investigation report, which will take months or more to complete.
Despite this crash, the general trend in air safety has been a positive one. More people fly every year, and so the safety record per passenger mile is even better than the raw statistics on crashes would indicate. But this record can be maintained only through the painstaking work of investigators, engineers, regulators, inspectors, and the pilots and crews who actually do the work. Most of the time the system works well, and the silver lining in every accident is the fact that it carries with it potential answers to problems that need to be addressed to improve safety even further. I just hope they are able to recover the flight data recorders in order to develop a complete picture of what went wrong, and to teach us how similar situations can be avoided in the future.
We will revisit this accident when more information is available, and in the meantime, our sympathy is with the relatives and friends of those who lost loved ones in this tragedy.
Sources: I drew on reports from Fox News at http://www.foxnews.com/story/0,2933,525117,00.html and an Associated Press report obtained from Yahoo News at http://news.yahoo.com/s/ap/brazil_plane, as well as the Wikipedia article "Pitot tube."
What do we know today, eight days after the crash? There were thunderstorms in the area that night, and early speculation centered on the possibility of a lightning strike to the plane. Although lightning hits planes hundreds of times a year, relatively little damage usually occurs and most modern aircraft can be considered essentially (though not totally) lightning-proof. Evidently, there was a satellite or other radio-mediated data link which was continually feeding certain types of flight data to the ground. Examination of this data shows that the flight speeds during the last minute or so of the flight became "incoherent," followed by a loss of cabin pressure and failure of electrical systems. While this information will be helpful in deciphering what went wrong, it apparently lacks the detail that flight data recorders can preserve. One can imagine a day when such radio links will take the place of, or at least duplicate, the capabilities of flight data recorders so that mechanical recovery of the black box will no longer be so urgent. The black box is designed to emit a sonar signal for 30 days after the crash, so the underwater recovery crews gearing up to find it are operating under tremendous time pressure, not to mention the water pressure at depths exceeding 20,000 feet. The box may never be found.
Recent news reports have focused on the fact that the plane's Pitot tube, the device that measures airspeed, had not yet been replaced with a newer model as the plane's manufacturer Airbus recommended. A Pitot tube is a small tube that faces directly into the airstream. The difference in pressure between the air inside the tube (which is blocked off and registers what is called "stagnation pressure") and the ambient or "static" air pressure, is an indication of airspeed, which is the most important kind of speed to know about when you are trying to fly a plane. These days, when most parts of a flight except for landing and takeoff are under automatic control, the airspeed data from the Pitot tube forms part of an elaborate computer-controlled feedback loop that maintains constant speed, altitude, and other flight characteristics.
The old saw about computers regarding "garbage in, garbage out" goes double when a feedback loop is involved. If enough ice forms on a Pitot tube to plug up the entrance, the indicated airspeed goes way below what is actually the case, and either the automatic pilot guns the engines inappropriately or the real pilots may take incorrect action based on faulty airspeed data. This is exactly what happened to an Argentine DC-9 flight in 1999, which resulted in a spectacular crash, killing all aboard.
Although I have no independent information on this, I hope that modern aircraft such as the Air France A330 that crashed have more than one means of measuring speed: either a second Pitot tube (which of course would be just as likely to ice up as the first one), or other means such as radar altimeter and speed measurements or GPS-based airspeed indicators. But whether the autopilot takes all these other inputs into consideration, and whether the real pilots do too, I don't know. Clearly, if the Pitot tube was involved in this crash, the right thing to do in the circumstances wasn't done.
All flight-critical Pitot tubes have heaters to prevent icing, but evidently the one on Flight 447 was deficient or non-optimal in some way, or else Airbus wouldn't have recommended replacing it. Of course replacements can be recommended for all kinds of reasons, some of which have nothing to do with safety. All that will come out in the investigation report, which will take months or more to complete.
Despite this crash, the general trend in air safety has been a positive one. More people fly every year, and so the safety record per passenger mile is even better than the raw statistics on crashes would indicate. But this record can be maintained only through the painstaking work of investigators, engineers, regulators, inspectors, and the pilots and crews who actually do the work. Most of the time the system works well, and the silver lining in every accident is the fact that it carries with it potential answers to problems that need to be addressed to improve safety even further. I just hope they are able to recover the flight data recorders in order to develop a complete picture of what went wrong, and to teach us how similar situations can be avoided in the future.
We will revisit this accident when more information is available, and in the meantime, our sympathy is with the relatives and friends of those who lost loved ones in this tragedy.
Sources: I drew on reports from Fox News at http://www.foxnews.com/story/0,2933,525117,00.html and an Associated Press report obtained from Yahoo News at http://news.yahoo.com/s/ap/brazil_plane, as well as the Wikipedia article "Pitot tube."
Friday, May 29, 2009
Does the U. S. Need a Cyber Czar?
On Friday May 29, President Obama is scheduled to announce a plan to name a “cyber czar” whose responsibility will be to oversee computer security both in and outside the federal government. The term “czar” in Russian originally meant an emperor whose reign was maintained by the authority of God. Somehow I doubt that such overtones of meaning are intended by the PR people who put together these news releases and the members of the press who report them. But it is a good place to start asking whether the U. S. really needs such a czar for this increasingly important area of technology, and what the good and bad aspects of such an appointment might be.
From time to time we have discussed various cyberthreats in this blog, and so far, none of them have turned out to be the Armageddon of viruses or cyberattacks. The trend in recent years, however, is not reassuring. Back when email was a novelty engaged in by a few nerds and their friends, the worst motivation of those who wrote viruses or produced spamware was a kind of intellectual mischievousness: “Gee, can I really get away with this?” But eventually, people figured out there was serious money to be made, either quasi-legitimately via spamware advertising of kooky products, or illegally via shakedowns and blackmail threats (“If you don’t want your whole website to go down next Tuesday, leave $100,000 in unmarked bills in the trash can next to the entrance of the Kremlin tonight.”). And in the last year or two we’ve seen pretty definite evidence that nations are using cyberattacks as part of more conventional warfare, as when Russia evidently coordinated a cyberattack on Georgia’s government websites last August during its attack on contested territory between the two countries.
So the threats are real, no doubt about that. The question is, can we defend ourselves better against them if we have some centralized governmental authority taking some as-yet-undefined actions? That question has to be answered in the context of how things are done currently.
Like the Internet itself, the U. S. system (if you can call it that) of defense against cyberattacks consists of a not very organized, highly distributed network of specialty firms, companies who simply want to use the Internet legitimately without hindrance, and the various governmental entities who use computers, which is (I hope by now) all of them. Judging by various reports, the private firms seem to do a better job of security and upgrading, including defense against attacks, than the government does. But this may simply be an artifact of accessibility. Reporters can file requests under the Freedom of Information Act to obtain a wide variety of government records, but there is no such privilege with regard to the internal documents of private firms. So if (to take an example) Bank of America makes a big goof in purchasing vulnerable ATM machines that can be programmed to spurt out piles of twenty-dollar bills to a waiting kid on his tricycle, as long as they catch the problem and fix it before it hits the news wires, no one is the wiser. But let that happen in a government agency, and reporters can get all the documentation on it they want, usually.
That doesn’t mean the government is necessarily less competent in dealing with cyberattacks. One danger I can foresee is that of burdensome regulations in what is historically a very unregulated industry. If Microsoft had to prove to some government bureaucrat that its new software upgrade is bulletproof against cyberattacks before it could be released, we’d all still be running OS/2 on our PCs (except for those of us using Macs). But the advance reports indicate that the new cyber czar won’t have even the authority of a cabinet official, nor Presidential access of the highest level.
So if the new czar can’t do much, why should we bother? One aspect of the situation appears to pertain to public education. I suppose if the President talks about what you as an individual can do to improve computer security, a certain number of people will pay more attention, but it does seem like it might be a needless expenditure of political capital. On the other hand, if we are made aware of the cost of cyberattacks in terms of centrally analyzed statistics publicized by the government, that might motivate some changes.
This problem resembles environmental issues in that it is essentially a global, not strictly a national matter. The Internet knows no boundaries, and in fact many if not most cyberattacks on U. S. institutions come from abroad. That means a solution, or more likely a range of solutions, will have to have international aspects to it: international agreements, international coordination, and so on. And for this the federal government is probably the best choice.
In sum, let’s wait and see how czar-like the new czar acts. There is no need to worry that the designee will take over the universe, even the cyber-universe. And there is a lot of room for improvement both in the public and the private sector. But government can do only so much, and it will be interesting to see whether the person chosen makes a positive difference, or disappears after the next federal initiative grabs all the headlines.
Sources: An Associated Press article describing the results of a Presidential study of cyber security and related issues can be found on the Business Week website at http://www.businessweek.com/ap/financialnews/D98FEMQO1.htm. My blog “War Comes to the Internet” was posted on Sept. 8, 2008.
From time to time we have discussed various cyberthreats in this blog, and so far, none of them have turned out to be the Armageddon of viruses or cyberattacks. The trend in recent years, however, is not reassuring. Back when email was a novelty engaged in by a few nerds and their friends, the worst motivation of those who wrote viruses or produced spamware was a kind of intellectual mischievousness: “Gee, can I really get away with this?” But eventually, people figured out there was serious money to be made, either quasi-legitimately via spamware advertising of kooky products, or illegally via shakedowns and blackmail threats (“If you don’t want your whole website to go down next Tuesday, leave $100,000 in unmarked bills in the trash can next to the entrance of the Kremlin tonight.”). And in the last year or two we’ve seen pretty definite evidence that nations are using cyberattacks as part of more conventional warfare, as when Russia evidently coordinated a cyberattack on Georgia’s government websites last August during its attack on contested territory between the two countries.
So the threats are real, no doubt about that. The question is, can we defend ourselves better against them if we have some centralized governmental authority taking some as-yet-undefined actions? That question has to be answered in the context of how things are done currently.
Like the Internet itself, the U. S. system (if you can call it that) of defense against cyberattacks consists of a not very organized, highly distributed network of specialty firms, companies who simply want to use the Internet legitimately without hindrance, and the various governmental entities who use computers, which is (I hope by now) all of them. Judging by various reports, the private firms seem to do a better job of security and upgrading, including defense against attacks, than the government does. But this may simply be an artifact of accessibility. Reporters can file requests under the Freedom of Information Act to obtain a wide variety of government records, but there is no such privilege with regard to the internal documents of private firms. So if (to take an example) Bank of America makes a big goof in purchasing vulnerable ATM machines that can be programmed to spurt out piles of twenty-dollar bills to a waiting kid on his tricycle, as long as they catch the problem and fix it before it hits the news wires, no one is the wiser. But let that happen in a government agency, and reporters can get all the documentation on it they want, usually.
That doesn’t mean the government is necessarily less competent in dealing with cyberattacks. One danger I can foresee is that of burdensome regulations in what is historically a very unregulated industry. If Microsoft had to prove to some government bureaucrat that its new software upgrade is bulletproof against cyberattacks before it could be released, we’d all still be running OS/2 on our PCs (except for those of us using Macs). But the advance reports indicate that the new cyber czar won’t have even the authority of a cabinet official, nor Presidential access of the highest level.
So if the new czar can’t do much, why should we bother? One aspect of the situation appears to pertain to public education. I suppose if the President talks about what you as an individual can do to improve computer security, a certain number of people will pay more attention, but it does seem like it might be a needless expenditure of political capital. On the other hand, if we are made aware of the cost of cyberattacks in terms of centrally analyzed statistics publicized by the government, that might motivate some changes.
This problem resembles environmental issues in that it is essentially a global, not strictly a national matter. The Internet knows no boundaries, and in fact many if not most cyberattacks on U. S. institutions come from abroad. That means a solution, or more likely a range of solutions, will have to have international aspects to it: international agreements, international coordination, and so on. And for this the federal government is probably the best choice.
In sum, let’s wait and see how czar-like the new czar acts. There is no need to worry that the designee will take over the universe, even the cyber-universe. And there is a lot of room for improvement both in the public and the private sector. But government can do only so much, and it will be interesting to see whether the person chosen makes a positive difference, or disappears after the next federal initiative grabs all the headlines.
Sources: An Associated Press article describing the results of a Presidential study of cyber security and related issues can be found on the Business Week website at http://www.businessweek.com/ap/financialnews/D98FEMQO1.htm. My blog “War Comes to the Internet” was posted on Sept. 8, 2008.
Monday, May 25, 2009
Ethics Education: How Can You Tell?
One reason I started this blog was to use it in a short (four-week) engineering ethics segment of a freshman course for engineering and technology majors. When you teach something, you obviously expect the lessons to make some kind of positive change in your students. You hope that they will be able to do or understand something that they couldn’t do, or didn’t understand, before you went to work on them. With technical subjects such as circuit theory or computer programming, it’s fairly easy to tell whether the students learn what you want them to learn. That’s what exams are for. But how can you tell whether ethics instruction has achieved its goal, which is to turn students into ethical engineers?
In an ideal world of infinite educational-evaluation resources, you would do a longitudinal study of two groups of students: one group who took engineering ethics, and a second matched cohort of students who took the same courses as the test group except for the engineering ethics parts. You would then follow every student, doing in-depth interviews and gathering third-party information about the ethical aspects of their work over their entire careers. And at the end of this process (which would take thirty-five years or so), you could write a paper saying we know for sure that X number of students who took Y ethics module thirty-five years ago were Z per cent more ethical than the control group of students who didn’t. Only, of course, Z might turn out to be negative. All it takes is one determined crook in your test sample to throw everything off.
And that ties in to something I learned last week. It’s not only universities that try to improve their students’ ethics with educational modules; companies and governments try it too. In particular, every employee of the state of Illinois has to take a brief online ethics module periodically, up to and including (I presume) the governor. You may have heard the name Rod Blagojevich in the news over the last six months or so. He is the (now ex-) governor of Illinois who was impeached for trying to sell the Senate seat vacated by now-President Obama. This was hardly ethical behavior under any standard, yet Blagojevich was following a tradition honored by numerous Illinois governors, of engaging in indictable behavior. If anyone was trying to evaluate the ethics education of Illinois employees and included the governor in their sample, they are going to have a lot of trouble showing that it helps.
But wait. Should one or two spectacularly bad apples spoil the barrel? That is, you are always going to have what are called “outliers.” If you are familiar with a Gaussian distribution, often called a “bell curve,” you know that it looks like a hill with gently sloping sides. If one of these distributions represents some measure of “ethicalness” (an ugly word, but I can’t think of a better one), then the peak of the hill represents the bulk of students who have what you might call typical or average ethics. Mother Teresa would be in the right-hand tail of the distribution, way off to one end, and the ex-governor would be somewhere in the left-hand tail.
You can make the argument that even though ethics education doesn’t prevent the occasional Blagojevich, if it moves the whole distribution to the right it makes the average person more ethical, which is worth something. But then you get into the utilitarian bind of evaluating the worth of ethics to society in general. Is it better that most people in a profession are a little more ethical even though some are still news-worthily unethical, or would it be better if somehow we could prevent only the worst ethical lapses and leave the rest alone? And all this assumes that there is some fail-safe way to evaluate ethics education other than the impossibly expensive and lengthy longitudinal study I described above, which is by no means clear.
All education involves some degree of faith, which is the certain knowledge of things we don’t see yet. Even if my students pass exams on digital logic or electromagnetics, I can’t say for sure what they’re going to do with those pieces of knowledge and ability. I can only trust that they will remember them and use them somehow in a good way. Experience has shown that the vast majority of our students do just that, although I can’t instantly pull up tons of documentation to prove it.
In the last several years, whenever the National Science Foundation funds programs to augment and encourage engineering ethics education, it insists that the outcomes of these programs be evaluated by some independent means. Their argument is that taxpayer money is being used for these programs, and the agency has to go back to Congress and show that the money did some good. Although the motive is laudable, I have questions about the method. The same person who told me about the online ethics course in Illinois is an expert in evaluating ethics education, which he admits is not a perfect process either. The preferred way is to administer a survey in which students answer questions about hypothetical ethical situations. As I say, it’s better than nothing. But it seems to me that the process of evaluating ethics education mainly to generate some paperwork to send back to Washington is motivated by the same spirit that causes the government of the state of Illinois to insist that all its employees take the online ethics module. In both cases, the ostensible motive seems to differ from the real motive.
Ostensibly, one is doing something that will genuinely improve (or measure) the ethics of the target population. But in reality, both the online ethics module and the ethics evaluation process serve mainly to shift responsibility for any possible bad outcomes. If another Rod Blagojevich shows up, Illinois government administrators can say, “Well, we did all we could—we made him take that ethics module.” And if despite all efforts, the next couple of decades turn up a few engineers who, despite taking NSF-evaluated engineering ethics education, go ahead and do something unethical anyway, the National Science Foundation can turn to Congress and say, “Well, we did all we could—we evaluated those programs with the best available evaluation instruments.”
Am I saying we should chuck all attempts at evaluation, or even ethics education? By no means. But let’s be realistic about what we’re trying to do, and not pretend that it’s capable of more than it can really do, which is simply to give us some reason to hope, but not to be certain, that we are making people more ethical.
Sources: Michael Loui, professor at the University of Illinois Urbana-Champaign, told me about these matters. I would point you to some information about Rod Blagojevich, but I think he’s already had more attention than he deserves. And my definition of faith is taken from the New Testament book of Hebrews, 11:1.
In an ideal world of infinite educational-evaluation resources, you would do a longitudinal study of two groups of students: one group who took engineering ethics, and a second matched cohort of students who took the same courses as the test group except for the engineering ethics parts. You would then follow every student, doing in-depth interviews and gathering third-party information about the ethical aspects of their work over their entire careers. And at the end of this process (which would take thirty-five years or so), you could write a paper saying we know for sure that X number of students who took Y ethics module thirty-five years ago were Z per cent more ethical than the control group of students who didn’t. Only, of course, Z might turn out to be negative. All it takes is one determined crook in your test sample to throw everything off.
And that ties in to something I learned last week. It’s not only universities that try to improve their students’ ethics with educational modules; companies and governments try it too. In particular, every employee of the state of Illinois has to take a brief online ethics module periodically, up to and including (I presume) the governor. You may have heard the name Rod Blagojevich in the news over the last six months or so. He is the (now ex-) governor of Illinois who was impeached for trying to sell the Senate seat vacated by now-President Obama. This was hardly ethical behavior under any standard, yet Blagojevich was following a tradition honored by numerous Illinois governors, of engaging in indictable behavior. If anyone was trying to evaluate the ethics education of Illinois employees and included the governor in their sample, they are going to have a lot of trouble showing that it helps.
But wait. Should one or two spectacularly bad apples spoil the barrel? That is, you are always going to have what are called “outliers.” If you are familiar with a Gaussian distribution, often called a “bell curve,” you know that it looks like a hill with gently sloping sides. If one of these distributions represents some measure of “ethicalness” (an ugly word, but I can’t think of a better one), then the peak of the hill represents the bulk of students who have what you might call typical or average ethics. Mother Teresa would be in the right-hand tail of the distribution, way off to one end, and the ex-governor would be somewhere in the left-hand tail.
You can make the argument that even though ethics education doesn’t prevent the occasional Blagojevich, if it moves the whole distribution to the right it makes the average person more ethical, which is worth something. But then you get into the utilitarian bind of evaluating the worth of ethics to society in general. Is it better that most people in a profession are a little more ethical even though some are still news-worthily unethical, or would it be better if somehow we could prevent only the worst ethical lapses and leave the rest alone? And all this assumes that there is some fail-safe way to evaluate ethics education other than the impossibly expensive and lengthy longitudinal study I described above, which is by no means clear.
All education involves some degree of faith, which is the certain knowledge of things we don’t see yet. Even if my students pass exams on digital logic or electromagnetics, I can’t say for sure what they’re going to do with those pieces of knowledge and ability. I can only trust that they will remember them and use them somehow in a good way. Experience has shown that the vast majority of our students do just that, although I can’t instantly pull up tons of documentation to prove it.
In the last several years, whenever the National Science Foundation funds programs to augment and encourage engineering ethics education, it insists that the outcomes of these programs be evaluated by some independent means. Their argument is that taxpayer money is being used for these programs, and the agency has to go back to Congress and show that the money did some good. Although the motive is laudable, I have questions about the method. The same person who told me about the online ethics course in Illinois is an expert in evaluating ethics education, which he admits is not a perfect process either. The preferred way is to administer a survey in which students answer questions about hypothetical ethical situations. As I say, it’s better than nothing. But it seems to me that the process of evaluating ethics education mainly to generate some paperwork to send back to Washington is motivated by the same spirit that causes the government of the state of Illinois to insist that all its employees take the online ethics module. In both cases, the ostensible motive seems to differ from the real motive.
Ostensibly, one is doing something that will genuinely improve (or measure) the ethics of the target population. But in reality, both the online ethics module and the ethics evaluation process serve mainly to shift responsibility for any possible bad outcomes. If another Rod Blagojevich shows up, Illinois government administrators can say, “Well, we did all we could—we made him take that ethics module.” And if despite all efforts, the next couple of decades turn up a few engineers who, despite taking NSF-evaluated engineering ethics education, go ahead and do something unethical anyway, the National Science Foundation can turn to Congress and say, “Well, we did all we could—we evaluated those programs with the best available evaluation instruments.”
Am I saying we should chuck all attempts at evaluation, or even ethics education? By no means. But let’s be realistic about what we’re trying to do, and not pretend that it’s capable of more than it can really do, which is simply to give us some reason to hope, but not to be certain, that we are making people more ethical.
Sources: Michael Loui, professor at the University of Illinois Urbana-Champaign, told me about these matters. I would point you to some information about Rod Blagojevich, but I think he’s already had more attention than he deserves. And my definition of faith is taken from the New Testament book of Hebrews, 11:1.
Monday, May 18, 2009
Crash of Flight 3407: The Human Factor
Last February 12, a Continental Airlines regional flight 3407, operated by Colgan Air, crashed short of the Buffalo, New York runway it was headed for, killing all 49 aboard and one person on the ground. At the time I wrote about it shortly afterward, speculation centered on how well the deicing systems were working, since icy conditions had been reported in the area. But after a three-day hearing on the crash held by the National Transportation Safety Board last week, it looks like human error may be the root cause of the crash.
Working with voice-recorder transcripts and flight data from the "black boxes" recovered from the crash, NTSB investigators painted a picture of the last minute or so of the flight which did not show pilot Marvin Renslow and his 24-year-old copilot Rebecca Shaw in a good light. During their final approach, when FAA regulations prohibit nonessential communications in the cockpit, the pair are heard chatting about careers and the co-pilot's lack of experience flying in icing conditions. Renslow himself had only three months of experience flying the particular Dash-8 involved in the crash, and had failed several flight simulator tests in the last few years. Besides these factors, fatigue may have further dulled the crew's responses. Shaw had joined the flight after commuting all night from her home in Seattle, where she lived with her parents. Her raising the plane's flaps without a command from the captain compounded the already critical situation the pilot found himself in when the plane lost airspeed and began to stall. Under these conditions an automatic system activates a "stick-shaker" intended to alert the pilot to the danger. The proper response is to move the stick forward to regain airspeed, but records indicate Renslow pulled it back. After stalling, the plane rolled and crashed.
The impressive and improving safety record of U. S. air travel says that on balance, nearly all pilots do the right thing in critical moments nearly all the time. But the fact that the safety record for smaller regional carriers such as Colgan is not as good as for the major carriers flying larger aircraft says there may be something about the difference in working conditions between long-range and regional carriers that bears watching, to say the least. A lot of the news coverage of the NTSB hearing centered on co-pilot Shaw's meager annual salary, which was less than $17,000 (not counting extra flying time). Deregulation of the airline industry plus the recent recession has brought intense competitive pressure to regional operators, who may be cutting corners and hiring inexperienced pilots with less-than-stellar records simply because they're cheaper. The Federal Aviation Administration has regulations about minimum standards for pilot training, performance, work hours, and rest breaks, but these things are human rules, and rules can be bent or broken without automatic penalties coming into play. At least, until something bad happens.
The loss of any life in an engineered system is a tragedy. But if the publicity surrounding the accident and its investigation result in corrective action, we can look forward to further improvements in safety procedures and their enforcement.
At last week's hearing, a NASA expert in cockpit communications acknowledged that more could be done to give pilots even earlier warning of potential stall conditions than the stick-shaker provides. This is a problem in what is called human-factors engineering: how to effectively interface a machine to a person so that the person has the right information at the right time in order to take the right action. By the time the stick-shaker went off, the pilot's options were very limited. If an earlier warning had been provided, the crew might have snapped out of their inattentive mood sooner and realized their difficulties in time to avert the accident. We will never know about this particular case, but if the investigation results in improved cockpit instrumentation that saves other inattentive crews from getting into the same fix, something good will have come from this crash.
The current federal administration seems to be more interested in regulation than deregulation, and there may be areas where such a change is appropriate. One reason that co-pilot Shaw's low pay got so much attention was that it is such a contrast to the typical popular perception of airline pilots: distinguished-looking former military flyers with some dignified gray around their temples (nearly always men), good pay, and years of flying experience. Stereotypes are made to be broken, and my hat is off to any young woman who goes through the arduous process of becoming a commercial pilot, but in the bad old days of high airfares and closely regulated airlines, the companies could afford to hire the very best pilots available, and generally did. The case of Shaw may indicate that inexperienced crews are being pushed too fast into positions of great responsibility without adequate training, or even sleep.
As sad as this accident was, we are starting to see the feedback system of engineering work. I don't mean the stick-shaker; I mean the corrective process that learns from mistakes, errors, and tragedies, and does things to make them less likely in the future. This kind of work takes place out of the spotlight, in quiet offices and labs around the world, but it is the reason that air travel is as safe and reliable as it generally is. And as long as we pay attention to the rare cases when something goes wrong, and have the courage to fix problems—whether mechanical or human—it will keep on getting even safer.
Sources: Two good reports on last week's NTSB hearings may be found at http://www.chicagotribune.com/news/politics/sns-ap-us-plane-into-home,0,5946950.story and http://www.cbsnews.com/stories/2009/05/13/national/main5010745.shtml. My article "The Crash of Flight 3407: Better Deicing Needed?" appeared on Feb. 16, 2009.
Working with voice-recorder transcripts and flight data from the "black boxes" recovered from the crash, NTSB investigators painted a picture of the last minute or so of the flight which did not show pilot Marvin Renslow and his 24-year-old copilot Rebecca Shaw in a good light. During their final approach, when FAA regulations prohibit nonessential communications in the cockpit, the pair are heard chatting about careers and the co-pilot's lack of experience flying in icing conditions. Renslow himself had only three months of experience flying the particular Dash-8 involved in the crash, and had failed several flight simulator tests in the last few years. Besides these factors, fatigue may have further dulled the crew's responses. Shaw had joined the flight after commuting all night from her home in Seattle, where she lived with her parents. Her raising the plane's flaps without a command from the captain compounded the already critical situation the pilot found himself in when the plane lost airspeed and began to stall. Under these conditions an automatic system activates a "stick-shaker" intended to alert the pilot to the danger. The proper response is to move the stick forward to regain airspeed, but records indicate Renslow pulled it back. After stalling, the plane rolled and crashed.
The impressive and improving safety record of U. S. air travel says that on balance, nearly all pilots do the right thing in critical moments nearly all the time. But the fact that the safety record for smaller regional carriers such as Colgan is not as good as for the major carriers flying larger aircraft says there may be something about the difference in working conditions between long-range and regional carriers that bears watching, to say the least. A lot of the news coverage of the NTSB hearing centered on co-pilot Shaw's meager annual salary, which was less than $17,000 (not counting extra flying time). Deregulation of the airline industry plus the recent recession has brought intense competitive pressure to regional operators, who may be cutting corners and hiring inexperienced pilots with less-than-stellar records simply because they're cheaper. The Federal Aviation Administration has regulations about minimum standards for pilot training, performance, work hours, and rest breaks, but these things are human rules, and rules can be bent or broken without automatic penalties coming into play. At least, until something bad happens.
The loss of any life in an engineered system is a tragedy. But if the publicity surrounding the accident and its investigation result in corrective action, we can look forward to further improvements in safety procedures and their enforcement.
At last week's hearing, a NASA expert in cockpit communications acknowledged that more could be done to give pilots even earlier warning of potential stall conditions than the stick-shaker provides. This is a problem in what is called human-factors engineering: how to effectively interface a machine to a person so that the person has the right information at the right time in order to take the right action. By the time the stick-shaker went off, the pilot's options were very limited. If an earlier warning had been provided, the crew might have snapped out of their inattentive mood sooner and realized their difficulties in time to avert the accident. We will never know about this particular case, but if the investigation results in improved cockpit instrumentation that saves other inattentive crews from getting into the same fix, something good will have come from this crash.
The current federal administration seems to be more interested in regulation than deregulation, and there may be areas where such a change is appropriate. One reason that co-pilot Shaw's low pay got so much attention was that it is such a contrast to the typical popular perception of airline pilots: distinguished-looking former military flyers with some dignified gray around their temples (nearly always men), good pay, and years of flying experience. Stereotypes are made to be broken, and my hat is off to any young woman who goes through the arduous process of becoming a commercial pilot, but in the bad old days of high airfares and closely regulated airlines, the companies could afford to hire the very best pilots available, and generally did. The case of Shaw may indicate that inexperienced crews are being pushed too fast into positions of great responsibility without adequate training, or even sleep.
As sad as this accident was, we are starting to see the feedback system of engineering work. I don't mean the stick-shaker; I mean the corrective process that learns from mistakes, errors, and tragedies, and does things to make them less likely in the future. This kind of work takes place out of the spotlight, in quiet offices and labs around the world, but it is the reason that air travel is as safe and reliable as it generally is. And as long as we pay attention to the rare cases when something goes wrong, and have the courage to fix problems—whether mechanical or human—it will keep on getting even safer.
Sources: Two good reports on last week's NTSB hearings may be found at http://www.chicagotribune.com/news/politics/sns-ap-us-plane-into-home,0,5946950.story and http://www.cbsnews.com/stories/2009/05/13/national/main5010745.shtml. My article "The Crash of Flight 3407: Better Deicing Needed?" appeared on Feb. 16, 2009.
Subscribe to:
Posts (Atom)