EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

10.12.10

Guest Article: Windows NT and the Deepwater Horizon

Posted in Microsoft, Windows at 2:48 am by Dr. Roy Schestowitz

Microsoft blue ribbon

Summary: An analysis of the causes that led to the Deepwater Horizon blowup (or what failed to prevent it), based on the long inquiry

THE previous post spoke about Stuxnet, which endangers many people whose company/authority/personal computer runs Microsoft Windows. Another recent disaster where Windows got some blame was the Deepwater Horizon blowup [1, 2, 3, 4]. An anonymous Techrights contributor wrote an update on the topic — one which we publish below.

“Here’s an update on the Deepwater Horizon story, “he writes, “New testimony spurred me to look up transcripts that had not been published at the time. There were several bombshells worth sharing and thinking about. For example, Windows NT is named and shamed by the expert witness. Windows was not mentioned in most press coverage but it seems to have played a more central roll than even I expected.”

Here is the report in question PDF and corresponding interpretation:


Windows NT and the Deepwater Horizon

A buggy control system left drillers and the rig blind and might even have damaged a critical safety system on the sea floor.

Microsoft Windows may have been directly responsible for Deepwater Horizon catastrophe. Previously, Techrights showed that Microsoft Windows played a crucial role. A 824 page transcript from the July 23 Deepwater Horizon investigation has been posted and we can see that things were as Techrights guessed. Mr. Williams describes Windows NT, “a very unstable platform” as the root cause of most problems. This buggy Windows based control system left drillers blind when it crashed daily was responsible for safety system bypasses and may have destroyed the annular seal. New testimony from Andrea Fleytas, who operated the alarm panels on the doomed bridge and jumped from the flaming deck with Mr. Williams, shows that the drilling team may have had time to escape if the alarms were not inhibited. This interpretation of her testimony, with some quotes, was published by the Times Picayune. The consequences of this disaster and ongoing cover up are well reported in the Florida Oil Spill Law blog.

Mr. Williams describes typical Windows problems in three identical, malfunctioning control systems, A Chair, B Chair and C Chair, on pages 42 and 101. There’s incompatibility, instability, harmful bugs and worries about viruses. On page 42, Mr. Williams talks about the systems, their importance and how broken they were.

The A-chair is located in the dog house. That is the main operating point for the driller to control all drilling functions. It controls everything from mud pumps to top drive, hydraulics. It controls everything.

For three to four months we’ve had problems with this computer simply locking up. [sometimes it was a blue screen, sometimes a frozen display] … We had ordered replacement hard drives from the manufacturer. We had actually ordered an entire new system, new computers, new servers, new everything to upgrade it from the very obsolete operating system that it was using. Those computers were actually using Windows NT, which is a very unstable platform to begin with.

Between the manufacturer and the rig, they could not get the bugs worked out of the new operating system. They couldn’t get the old software to run correctly on the new operating system. Our sister rig, the NAUTILUS, was going through those growing pains kind of for us. We had already ordered all the equipment. We were just waiting on them to figure it all out so that we could copy their learnings and make it work on our rig.

Meanwhile, we were limping along with what we had. We had ordered new hard drives. They came in. We replaced the images on the hard drives for the software imaging, got them back running, the chair would run for two, three days, and they would crash again. … I can’t tell you how many hours or days he [electrical supervisor, Tommy Daniels] spent focused entirely on getting these chairs resolved. … He was still working towards that up until the time of the explosion. It had not been resolved.

In the same discussion, Mr. Williams attributes the blowout to the failure of this system by referencing a previous incident.

[in another accident] It was internally discussed that the chair crashing caused the kick, because they lost all — They lost all communications to the drill package. They had no way to monitor anything for several seconds, and before they could get the B Chair up, they had taken a kick.

On pages 103 and 104, he also describes how a “blue screen of death” could lead to a “kick” while waiting for the backup system to boot and be informed by “servers”. Operators complained about this loss of control every day and it happened at all hours of the day and night.

It should be noted that the problem with the alarms was not the sensors but it could have been viruses. Mr. Williams describes how he made sure all of those were working properly on pages 66 and 68 to 70. On page 77, Williams says, “The chairs themselves were completely independent and isolated from the entire rig network, so there was no chance of infection, virus, hacking, there was no opportunity for that.” This tells us that the rest of the network had problems that might have been carried to the control system via physical media, like USB drives or floppies.

Non free software left BP engineers in the field divided and helpless. On page 102, Mr. Williams tells us, “There was no fixing bad software. We could simply manage it, try to keep it running.” So, BP’s management was told that all they could do was as the vendor says. Money and resources were being spent to fix the problems but they were wasted. When the vendor’s software failed, BP was stuck begging for more from a system that had to be bypassed.

Mr. Williams describes the general alarm, its inhibition and consequences starting on page 30. The whole rig was blind to real danger.

.

You have four states of alarms. You have a normal operating condition, you have an inhibited condition, which simply means that the sensory is active, it is sensing, and it will alarm and it will give the information to the computer but the computer will not trigger an alarm for it. It will give you the indication, but it won’t trigger the actual alarm. [other states described] …

there are several toxic and combustible gas sensors located in key areas, mainly around the drilling package. … When you get two detectors to go into a high state in one zone, what is supposed to happen is the ESD for that zone should trip, which is your emergency shutdowns [designed to prevent explosions], and you should also sound the generator alarm.

The general alarm is set up to inform the entire rig of any of three conditions. … Each one of those conditions has a distinct tone and a distinct visual light. We have light columns throughout the rig. One red — Within the column there’s a red, a yellow, and a blue, with the red being fire, yellow being toxic, blue being combustible. So you get an audio tone and a visual tone with every general alarm. [none of these were used in the accident because the computer was set so general alarms had to be triggered manually. As we will see, they failed to do this.]

… When I discovered it was inhibited about a year ago, I inquired as to why it was inhibited, and the explanation I got was that they — from the OIM down, they did not want people woke up at 3:00 o’clock in the morning due to false alarms.

On pages 40 and 41 we see that Emergency Shut Downs had been set to bypass because the system shut panels down frequently over false alarms. This left everyone at risk of explosion.

On page 37, Mr. Williams drops another bombshell, that the same system may have destroyed the blow out preventer without human input. A reasonable system would inhibit motion, even human directed motion, that would destroy itself. What they had left them wondering about everything.

it took me a few days to understand or to formulate why we were getting chunks of [annular] rubber back. There was an incident prior to that where we were in testing mode and the annular was closed around the drill pipe. I got a call from the night-time toolpusher to come investigate whether or not there was an input to the stick to hoist the block while the annular was closed, and I inquired as to why he needed to know that. He said, “Well, the block moved about 15 or 20 feet. We need to know why. We need to know if it was inadvertent stick movement or if it went up by itself.” [an informal investigation] got into the chair log data and dissected the data. What we determined was one of the sticks was moved in the positive direction. What we could not definitively determine was which stick. The tag system inside the log was not accurate enough. It simply said, “Joystick A, Joystick B,” …

All the logs prove to me is that the computer thought someone pushed the joystick. The signal was erroneous and might also have been spurious.

The most dreadful immediate consequence of all of this was that eleven men died in an explosion and fire. New testimony shows a situation that a more reasonable system should have been able to react to and save the day. The blow out preventer should never have been damaged. Alarms should have sounded, so people could escape. Panels and generator should have been shut down to prevent an explosion. What actually happened? David Hammer of the Times Picayune tells us.

Andrea Fleytas said she felt the rig jolt that evening and saw more than 10 magenta lights flash on her screen notifying her that the highest level of combustible gas had entered the rig’s shaker house and drill shack, critical areas where the rig’s drilling team was at work. … she was trained to sound a general alarm any time more than one indicator light flashed, but didn’t do so immediately in this case because she had never been trained to deal with such an overwhelming number of warnings. … she eventually “went over and hit the alarms” after the first or two large explosions.

[before pushing the alarms] Fleytas received a telephone call from crew members on the drill floor who said they were fighting a kick of gas and oil in the well; she took another call from the engine control room asking what was happening and she told them they were having a well control problem; and she continued to hit buttons on her console acknowledging the multiple gas alarms popping up in various sectors of the rig. … A few seconds after she got off the telephone with the engine room, there was a blackout on the rig. A few seconds after that, the first explosion rang out, Fleytas testified. It was then that she sounded the general alarm.

Keplinger said in his own testimony that it was after the explosion when he first “noticed a lot of gas in there and called” the shaker house to try to get whoever may have been there out, but nobody answered the phone.

Fleytas said she knew of no protocols for activating the emergency shutdown and no one activated it. Gas likely ignited in the drilling area, killing everyone there, and also caused the two active engines to rev so high that all power on the rig was lost, preventing fire pumps from working and keeping the rig from moving away from the spewing well.

Microsoft failure did not end when the rig sank. Those trying to fix things were also burdened with second rate software.

Since then, people from Texas to Florida have been sickened and harmed by the spill. Toxic levels of dispersant have shown up in people’s private pools, the beaches are contaminated with about 200 ppm of oil, oysters, crabs and shrimp have even more. The oil made its way into people’s blood. If the big spill in Mexico is a guide, the spill will linger for decades [2].

Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

What Else is New


  1. Links 25/9/2018: Mesa 18.1.9, New Fedora Beta, and Oracle Solaris 11.4 SRU1

    Links for the day



  2. Technology Groups and Innovators Bemoan Attempts to Override the Courts to Promote Patent Maximalists' Agenda by USPTO Director Andrei Iancu

    The U.S. Patent and Trademark Office (USPTO) is not listening to the views of actual innovators; it seems to be serving just the patent and litigation 'industry' (i.e. those who profit from illegitimate patents and baseless lawsuits)



  3. Patent Trolls Roundup: Microsoft's Patent Troll Collapses, Samsung Fuels Patent Troll Sisvel, and Patent Troll VirnetX Wants Apple's Cash

    Microsoft's largest patent troll continues to experience a mass exodus (in addition to all the layoffs), Sisvel receives armament from Samsung, and VirnetX carries on pretending -- to shareholders at least -- that it will get a lot of money out of Apple (albeit an appeal will likely prevent that altogether)



  4. António Campinos Goes to UPC-Hostile Country, UPC Continues to Languish and Team UPC Carries on Pushing for Software Patents in Europe (Courts Also)

    The Unified Patent Court (UPC) fantasy has fizzled, but those striving to interject software patents agenda into Europe from the back door (e.g. labeling these "AI" or ignoring the stance of actual courts) aren't giving up just yet



  5. The Man Whose Actions Could Potentially Land Team Battistelli in Jail

    As new evidence and more material surfaces about Benalla, Battistelli tries hard to hide himself from French media, knowing that he might be criminally culpable



  6. Links 24/9/2018: Linux 4.19 RC5 From Greg Kroah-Hartman, OpenShot 2.4.3 Released

    Links for the day



  7. Reader's Article: Affaire Benalla Strongly Connected to EPO/OEB/EPA and Former President Benoît Battistelli

    A Macron scandal has led French media to finally (and years too late) exploring some of the much more explosive scandals at the EPO, revealing some interesting new details in the process



  8. Language Patent Lawyers Are Using to Warp the Debate and Decrease Public Understanding of Patents

    The patent microcosm, trying to get the public all baffled/confused about the patent system, continues (mis)using words to convey things in misleading ways



  9. USPTO FEES ACT Makes the US Patent Office a Money-Making Machine That Systematically Disregards Patent Quality

    The lingering issues with patent assessment at the US patent office, which unlike US courts isn't quite so impartial an actor (it benefits more from granting than from rejecting)



  10. Guest Post on Ronan Le Gleut and Benalla at the French Senate (in Light of Battistelli's Epic Abuses)

    Thoughts on the possibility that Battistelli will belatedly be held accountable for his abuses, knowing that a senator representing French Citizens residing Abroad comes from the EPO



  11. A Lot of US Patents Are Entirely Bogus, But Apple Was Willing to Pay for Them

    Apple's resistance to Qualcomm's patent aggression was preceded by very heavy ("thermonuclear" by Steve Jobs' description/words) patent wars against Android and even legitimisation of clearly bogus software patents from Amazon



  12. 'Owning' Nature, Thanks to Patent Insanity and People Who Profit From That

    Questionable patents on things that always existed and are merely being explained or reassembled; those sorts of patents typically serve to merely discredit the patent system and courts too increasingly reject such patents (e.g. SCOTUS on Mayo Collaborative Services and Myriad Genetics, Inc.)



  13. Patents Stranger Than Fiction and 'Protection' From Fictional Things

    Fictional things are being treated like "inventions" and insurance companies now look to exploit fear of fictional things (man-made concepts), such as ownership of mere ideas or words



  14. Benoît Battistelli Refuses to Talk to the Media About Bringing Firearms to the EPO

    Benoît Battistelli's highly aggressive approach has attracted the attention of French media; Battistelli has reportedly refused to comment on that matter, knowing that he lacks a defense (same thing happened after he had hauled millions of EPO euros to his other employer)



  15. Patent Law Firms Have Become More Like Marketing Departments With an Aptitude for Buzzwords

    What we're observing, without much reluctance anymore, is that a lot of patent lawyers still push abstract software patents, desperately looking for new trendy terms or adjectives by which to make these seem non-abstract



  16. Interlude: The Need to Counter Misinformation From the Patent and Litigation 'Industry'

    24,500 posts reached; so we pause and reflect, seeing that many sites/blogs of patent maximalists gradually ebb away



  17. Advocacy of the Unitary Patent System Has Become Almost Identical to the 'Leave' (Brexit) Campaign

    The charades of Team UPC carry on in Kluwer Patent Blog — a blog which for a very long time served no purpose other than Unified Patent Court (UPC) advocacy



  18. Open Invention Network is Rendered Obsolete in the Wake of Alice and It's Not Even Useful in Combating Microsoft's Patent Trolls

    Changes at the US Patent and Trademark Office (USPTO) and in US courts' outcomes may have already meant that patent trolls rather than software patents in general are a growing threat, including those that Microsoft is backing, funding and arming to put legal pressure on GNU/Linux (and compel people/companies to host GNU/Linux instances on Azure for patent 'protection' from these trolls)



  19. Bogus Patents Which Oughtn't Have Been Granted Make Products Deliberately Worse, Reducing Innovation and Worsening Customers' Experience

    How shallow patents — or patent applications that no patent office should be accepting — turn out to be at the core of multi-billion-dollar cases/lawsuits, with potentially a billion people impacted (their products made worse to work around such questionable patents)



  20. EPO is Like a Patent Litigation (Without Actual Trial) Office, Not a Patent Examination Office

    Examination of patent applications isn't taken seriously by an office whose entire existence was supposed to be about examination; bureaucracy at the top of this office has apparently decided that the sole goal is to create more demand (i.e. lawsuits) for the litigation 'industry'



  21. Philippe Cadre From the French National Institute of Industrial Property (INPI) Wants to Join António Campinos

    Yet another example of INPI's creeping influence if not 'entryism' at the EPO and this time too patent quality isn't a priority



  22. Links 22/9/2018: Mesa 18.2.1, CLIP OS, GPL Settlement in Artifex/First National Title Insurance Company

    Links for the day



  23. Links 21/9/2018: Cockpit 178, Purism 'Dongle'

    Links for the day



  24. Criticism of Unitary Patent (UPC) Agreement Doomed the UPC and Patent Trolls' Plan -- Along With the Litigation Lobby -- for Unified 'Extortion Vector'

    The Unitary Patent or Unified Patent Court (UPC) was the trolls' weapon against potentially millions of European businesses; but those businesses have woken up to the fact that it was against their interests and European member states such as Spain and Poland now oppose it while Germany halts ratification



  25. It Wasn't Judges With Weapons in Their Office, It Was Benoît Battistelli Who Brought Firearms to the European Patent Office (EPO)

    The EPO scandals deepen in light of a very major scandal which has occupied the French media for a couple of months



  26. Links 20/9/2018: 2018 Linux Audio Miniconference and Blackboard's Openwashing

    Links for the day



  27. Links 19/9/2018: Chromebooks Get More DEBs, LLVM 7.0.0 Released

    Links for the day



  28. Links 18/9/2018: Qt 5.12 Alpha , MAAS 2.5.0 Beta, PostgreSQL CoC

    Links for the day



  29. Today's European Patent Office (EPO) Works for Large, Foreign Pharmaceutical Companies in Pursuit of Patents on Nature, Life, and Essential/Basic Drugs

    The never-ending insanity which is patents on DNA/genome/genetics and all sorts of basic things that are put together like a recipe in a restaurant; patents are no longer covering actual machinery that accomplishes unique tasks in complicated ways, typically assembled from scratch by humans; some supposed 'inventions' are merely born into existence by the natural splitting of organisms or conception (e.g. pregnancy)



  30. The EPO Has Quit Pretending That It Cares About Patent Quality, All It Cares About is Quantity of Lawsuits

    A new interview with Roberta Romano-Götsch, as well as the EPO's promotion of software patents alongside CIPA (Team UPC), is an indication that the EPO has ceased caring about quality and hardly even pretends to care anymore


CoPilotCo

RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

CoPilotCo

Recent Posts