Live data from Hacker News

Due to failure in the IT system, it is not possible to run any trains today

ns.nl

1–10 of 365 posts

Re: Due to failure in the IT system, it is not possible to run any trains today

#2
I do hope they have a more detailed RCA at some point, right now this is the only helpful paragraph in the article about what happened:

> The IT failure occurred at the end of the morning. It affected the system that generates up-to-date schedules for trains and staff. This system is important for safe and scheduled operations: if there is an incident somewhere, the system adjusts itself accordingly. This was not possible due to the failure.

Re: Due to failure in the IT system, it is not possible to run any trains today

#3
post #2

I do hope they have a more detailed RCA at some point, right now this is the only helpful paragraph in the article about what happened: > The IT failure occurred at the end of the morning. It affected the system that generates up-to-date schedules for trains and staff. This system is important for safe and scheduled operations: if there is an incident somewhere, the system adjusts itself accordingly. This was not pos…

I was expecting more as well. Not much information to glean from a barebones press release.

If I had to guess, it probably was an issue with scheduling/timetable software rather than anything to do with the trains, rails, etc. Nothing exceedingly seriously or difficult to correct.

Re: Due to failure in the IT system, it is not possible to run any trains today

#6
post #5
post #4

tl;dr : Restarting train schedule mid-day is too hard and unsafe. So we're sending them back to depot instead.

Why "unsafe"? Isn't safety supposed to be handled at a different abstraction level (in hardware)?

Defense in depth? With this safety feature inoperable, the margin of safety is reduced.

Other systems that might normally provide safety critical redundancy could be providing the sole measure of safety, with no other redundancy available in case one of those fails.

“Unsafe” is always defined based on context.

Re: Due to failure in the IT system, it is not possible to run any trains today

#7
post #5
post #4

tl;dr : Restarting train schedule mid-day is too hard and unsafe. So we're sending them back to depot instead.

Why "unsafe"? Isn't safety supposed to be handled at a different abstraction level (in hardware)?

I think that trains can travel in both directions on the same track and the schedule keeps them from hitting each other head-on.

Re: Due to failure in the IT system, it is not possible to run any trains today

#8
I was in the station for a different reason when I heard the announcement. The people entering and hearing the announcement were unsurprisingly very crestfallen, but it appears that twitter helped organize a lot of travel, with people posting where they were/going and picking up other travellers.

Also probably worth noting is that trains here are used fairly frequently, however unfortunately this isn't the first time trains are stopping - for example snow is a common reason for delayed/reduced service. (Snow isn't very common here in the NLs)

Re: Due to failure in the IT system, it is not possible to run any trains today

#9
post #6
post #5

Earlier quoted context omitted.

Why "unsafe"? Isn't safety supposed to be handled at a different abstraction level (in hardware)?

Defense in depth? With this safety feature inoperable, the margin of safety is reduced. Other systems that might normally provide safety critical redundancy could be providing the sole measure of safety, with no other redundancy available in case one of those fails. “Unsafe” is always defined based on context.

What's the point of having redundancy if you can't use it to avoid an impact to service?

Edit: and to be clear, we're not talking about holding down a resetable circuit breaker to avoid being late, we're talking about the rail network of an entire nation being inoperable for a day.

Re: Due to failure in the IT system, it is not possible to run any trains today

#10
post #6

Earlier quoted context omitted.

Defense in depth? With this safety feature inoperable, the margin of safety is reduced. Other systems that might normally provide safety critical redundancy could be providing the sole measure of safety, with no other redundancy available in case one of those fails. “Unsafe” is always defined based on context.

What's the point of having redundancy if you can't use it to avoid an impact to service? Edit: and to be clear, we're not talking about holding down a resetable circuit breaker to avoid being late, we're talking about the rail network of an entire nation being inoperable for a day.

The point is to still have it when you didn’t know you needed it. That’s the purpose of all redundant safety systems. The redundancy isn’t there to keep the service operating; it’s to keep people from dying.

You can never know if the primary safety system is functioning perfectly, so you need other systems to be there to step in when the primary fails unexpectedly.

If you detect the primary system has failed, isn’t it reasonable that you should stop operation as quickly and safely as possible, and be thankful nothing bad happened while you lacked redundancy? Any SPoF could be fatal for hundreds of people.

Post reply on HN