Normal view

FreshRSS 1.24.3

6 September 2024 at 19:23

This is a quality-focussed release for the 1.24.x series meant to provide a good product to people blocked on PHP 7.4, while we will increase the requirements to PHP 8.1+ from the next release.

A few highlights ✨:

  • Last version supporting PHP 7.4 before requiring PHP 8.1+
  • Last version supporting PostgreSQL 9.5 before requiring PostgreSQL 10+
  • Last version supporting MariaDB 5.5 before requiring MariaDB 10.0.5+
  • Last version supporting MySQL 5.5.3 before requiring MySQL 8+
  • Many bug and regression fixes

This release has been made by @Alkarex, @math-GH and newcomer @pando85

Full changelog:

  • Bug fixing
    • Fix mark-as-read from user query #6738
    • Fix regression for shortcut to move between categories #6741
    • Fix feed title option #6771
    • Fix XPath for HTML documents with broken root (used by CSS selectors to fetch full content) #6774
    • Fix UI regression in Mapco/Ansum themes #6740
    • Fix minor style bug with some themes #6746
    • Fix export of OPML information for date format of JSON and HTML+XPath feeds #6779
  • Security
    • OpenID Connect better definition of session parameters #6730
  • Compatibility
    • Last version supporting PHP 7.4
  • Misc.
    • Use charset for JSON requests from the UI #6710
    • Use .html extension for the local cache of full content pages instead of .spc #6724
    • Update dev dependencies #6739, #6758,
      #6759, #6760

Faust in the Anthropocene: A Compilation and Coda

30 August 2024 at 09:00

For ease of reference, here are the links to the entire series:

Part 1: Faust the Innovative Throwback
Part 2: Faust and the Preemptive Crisis of the Professions
Part 3: Faust and the Tragedy of Misfired Modernity
Part 4: Faust and the Redemption of Modernity
Part 5: Faust Beyond Faust

I hope the unaccustomed pace of posting was okay, especially for my email subscribers. For my part, I was excited simply to have new material to post for a week straight! It felt like old times.

As I mentioned in the note to the first installment, this was my first attempt to write out some thoughts on Faust that have been percolating over many years as I have regularly taught a course on the Faust legend called “Deals With the Devil.” (You can see the most recent iteration of the syllabus here.) This means that I was trying to squeeze a lot of thoughts on Faust into a relatively short piece — a problem that was exacerbated by the unexpectedly short timeframe I had available to write it, due to severe disruptions in my travel back from New York.

Looking back over the whole thing over the course of the week, I feel that the effect was most pronounced in the ending, where I just kind of… stopped. Hence this follow-up post! The main thing that I would like to do is to flesh out the connection with the Anthropocene dilemma. I emphasize the Christian baggage in specific in our moralized way of thinking about climate change. One further step I would take in that direction is the attitude toward geoengineering, which feels like “cheating” to many. We should take the more painful and difficult method, not a quick fix! I once did a poll for my Twitter followers, a carefully curated group of mostly leftists and liberals, where I posited that there was a button they could push that would return atmospheric carbon to pre-industrial levels instantly with no adverse consequences. A surprising number said no! Presumably many of them were expressing their rejection of my absurd scenario, but at least some of the negative response is a Christian-esque moral masochism. The fact that — as a Bluesky follower whose post I cannot now find pointed out — geoengineering is sometimes referred to as a “Faustian bargain” also indicates a certain reluctance to make intentional interventions into the climate, as though we would illegitimately be “playing God.”

There’s another area where the Faustian situation sheds light on the dilemma of the Anthropocene, and that is the attempt to put new wine in old wineskins, discrediting both. The fact that capitalism is unable to deal with climate change and seems to relentlessly discover new ways to make it worse (tax credits for SUVs! a fake currency made of wasted carbon emissions! a bullshit machine that basically sets fire to a small village in order to generate an image of Garfield smoking pot!) discredits the system. Yet like Christianity, it hangs on through sheer inertia and we can only view solutions through its lens. We must somehow solve this urgent problem in a way that (a) guarantees continued capitalist profits, including for people who have invested in the very fuels that are causing the problem, and (b) maintains “fair” competition among the various nations into which we have divvied up the earth’s surface. Those conditions are literally impossible to meet! And compared to what’s at stake, making sure Exxon shareholders get their expected value or the EU remains “competitive” with China in battery production seems incredibly petty and stupid!

There’s a first as tragedy, then as farce dynamic here. At the dawn of modernity, scientific knowledge — with its claim for human empowerment and autonomy apart from divine revelation or ecclesiastical tutelage — appeared dangerous and demonic. At the twilight of modernity, it has become little more than an annoying wet blanket that no one wants to think about. Far from building a society on genuine knowledge that empowers us to master our world, we are letting archaic moral intuitions and discredited institutions permanetly ratchet down the life chances of future generations even though we know exactly what needs to be done and have the ability to do it. I remain haunted by an interview with Kim Stanley Robinson where he lays out the worst-case scenario (which is broadly what you’d think), but then also lays out a more optimistic scenario:

The best-case scenario is also completely possible from our current situation, despite the trajectory we are on. It would be a just, sustainable world in which the energy flows in the biosphere were in balance, such that the extinction rates would be normal, ecosystems everywhere restored to health, and 10 billion humans ― shrinking quite naturally in number as all the women in the world began living in complete gender equality ― were all living with adequate food, water, shelter, clothing, health care, education, and work.

This best-case scenario, the utopian turn, is physically possible if it were the goal of human civilization and became what we were all working toward together. The crucial technologies involved are not so much physical as they are social, which is to say, we have to have ecologically guided economics and politics. It is by its very nature a leftist vision, in that it foregrounds justice and welfare for all.

It is physically possible, and as Keynes — surely no socialist! — tells us, anything we can actually do, we can afford. But we won’t allow ourselves to do it because it would disrupt this system of claims and this weird zero-sum competition that we’ve set up among ourselves. In fact, many of our fellow humans regard the best-case scenario as the end of everything they value and are willing to fight to the death for their right to doom us all.

Here I am reminded of a version of Faust I don’t mention in the talk — Murnau’s amazing silent film (which you should all drop everything and watch if you haven’t already). There Faust uses his demonic power initially to try to cure a plague, but everyone turns on him once it becomes clear where his power is coming from. At that point, he embraces sheer nihilism and asks for Mephistopheles to give him youth — presumably so that he can relive a life he now believes to have been wasted. If the cure can’t be squared with Christianity — the same Christianity that will drive them to burn Gretchen alive at the end of the film — then they don’t want it. In the end, all Faust can strive for is some kind of personal satisfaction and personal connection, because any avenue to use his formidible knowledge in a meaningful way has been shut down. In a contemporary adaptation, what could Faust be but a climate scientist?

What Cheese to Pair with a Bramble Cocktail?

29 August 2024 at 22:18

August Cheese and cocktail pairing: Bramble Cocktail with Selles-sur-Cher In our cheese & cocktail pairing project, I combine my cocktail know-how with the encyclopedic cheese knowledge of Jennifer Greco of […]

The post What Cheese to Pair with a Bramble Cocktail? appeared first on Paris • Cocktails • Bars.

Faust in the Anthropocene, Part 5: Faust Beyond Faust

29 August 2024 at 14:20

[See Part 4 here, or go back and read the series from the beginning.]

I have compared Faust’s utopia to the American dream, although admittedly the notion of social solidarity in the face of disaster hits a sour note from that perspective. What makes it feel so American to me is that it is so profoundly capitalist. It presupposes that life demands constant labor and striving, that true freedom requires exposure to danger, that nature’s power is wasted unless it is conquered and redirected by human interests. This connection is far from hypothetical. Long passages of Part 2 revolve around Mephistopheles’s plot to introduce paper money into the German empire, and as Marshall Berman notes in All That is Solid Melts Into Air, Goethe himself was fascinated by vast world-shaping projects like the Panama Canal, which finally assert humanity’s mastery over nature.

In our current moment, it is ironically this very triumph of modern developmentalism that appears most naïve and even retrograde in Goethe’s Faust. Capitalist domination over nature has proven more profoundly world-shaping than Goethe ever could have anticipated—delivering potentially every nation on earth to the condition of Faust’s ocean-threatened utopia. If Goethe expected Faust’s project to evoke something like the Panama Canal, to me it seems anachronistically to evoke science fiction images like the half-flooded city of Kim Stanley Robinson’s New York 2140 or the vast flood walls around New York City in the dystopian future of The Expanse. From this perspective, it feels like no accident that the most recent major adaptation of Faust, Life and Trust, is precisely about the collapse of capitalism. Even more telling is the fact that in this immersive theater experience, the Great Crash does not open out onto the future of the New Deal and postwar economic miracle, but promises only a return to a lost past that is, if anything, even more riven by hierarchies of race, class, gender, and sexuality than the present.

Perhaps even more than the promise of freedom and abundance through capitalist development, Faust’s goal of seizing state power to build a better society for everyone is likely to strike the contemporary reader as sinister than redemptive. Of course, it doesn’t help that Goethe decided at the last minute to insert the story of the poor old couple whose humble abode is spoiling Faust’s perfect view. Even if Faust did not intend for them to die, his order to Mephistopheles to remove them is both callous and reckless—surely by now Faust must understand who he is dealing with.

I would suggest that Goethe may have added this unsavory episode precisely so that Faust would have something to be redeemed from. Certainly his seduction of Gretchen turned out to be destructive, but at that point he was as naïve about Mephistopheles’s motives as Gretchen was about Faust’s. All the most fatal moves (the poisoning of Gretchen’s mother, the stabbing of her brother, the escape to Walpurgis Night) were at Mephistopheles’s initiative rather than his. With the old couple, there is still a small sliver of plausible deniability insofar as he did not explicitly tell Mephistopheles to kill them—but his motives are also much more purely selfish, even petty. With Gretchen, he was a rejuvenated man in love for the very first time. One can imagine behaving irresponsibly in that situation. With the old couple, however, even if he did not directly wish them to die, he is still acting like a tyrant who values his own idle whims over the wellbeing of others.

I previously emphasized Goethe’s free adaptation of Christian materials in the conclusion. There I think he more or less succeeds in using those materials to craft his own idiosyncratic theology in a way that is not finally shaped or predetermined by Christianity. But if I am right about his motivation for inserting the death of the old couple, the denoeument of Part 2 is nonetheless profoundly determined by Christianity—specifically the Christian notion of the felix culpa, the happy fault. The phrase comes from the Easter Vigil liturgy: “O felix culpa quae talem et tantum meruit habere redemptorem” (“O happy fault that merited such and so great a Redeemer”). The notion here is that the sin of Adam and Eve, with all the vast suffering it unleashed, is nonetheless a net positive because it enabled the even greater event of redemption.

With this idea of the felix culpa in mind, we can see that the transition from Marlowe to Goethe is not, as it initially appeared, a transition from entrapment in the Christian framework to an escape from it. Rather, it is a shift from a more simplistic to a more sophisticated theology. In Marlowe, Faust’s sin is simply useless and meaningless within the Christian framework, petering out into pointless pranks. In Goethe, by contrast, Faust’s sin is a necessary step toward a greater redemption—not only for himself, but on a social, economic, and political level. This is not orthodox Christianity—insofar as Faust seems to fuse the first and second Adam, the sinner and the redeemer—but its moral economy does grow out of a profoundly Christian impulse.

Now, at last, it is time for me to justify my title. If we limit the “man” or anthropos of the Anthropocene to modern man in specific, and if I am right that Faust is in some sense the myth of modernity, that it supplies a stage on which modernity can enact its deepest tensions and contradictions, the connection between the Faust legend and the Anthropocene dilemma become much more profound than the kind of easy parallels I threw out and dismissed at the beginning of my lecture. The Anthropocene is the Faustocene—it is the dilemma of a modernity that remains profoundly shaped by Christianity at its foundations, and in particular in its moral instincts. Think, for instance, of the primary complaint about the term “Anthropocene,” namely that it attributes blame incorrectly, implicitly grouping in the largely innocent Global South nations with the real culprits. Better to call it the Capitalocene, blaming the specific system that caused the destruction rather than indulging in clichés about “human nature” in general. These observations are all correct as far as they go, but why is the most important priority to attribute blame? What will be changed by the sheer fact of knowing whose fault it is? One also thinks of the tendency to say that “we” are all to blame for environmental degradation and therefore “we” all deserve the punishment. Either case represents what we might call Marlowe’s Faustocene—a moral vision in which using the illicit powers unleashed by modernity leads to an inevitable punishment.

More profound and more insidious are the patterns of thought that we could characterize as Goethe’s Faustocene—the notion that environmental destruction is a felix culpa, a necessary step to development as such. Think of how often we hear that it is unfair that poorer nations should be deprived of the opportunity to destroy the environment themselves, as that is presumably the only path to prosperity. Think, too, of how often we on the left gesture toward the notion that the environmental crisis will finally force everyone to abandon capitalism as unsustainable and create a more holistic and communitarian way of life.

The Anthropocene is also the Faustocene in another sense, insofar as it represents a profound crisis of all the distinctively modern forms of authority. Science seems to betray its promise of ever-greater abundance and mastery, instead warning us that we must restrain ourself in the face of forces we can never fully control. Law—along with the liberal democratic institutions that generate and legitimize it—seems increasingly disconnected from reality, as even the most environmentally savvy nations are enacting what amounts to de facto climate change denial. The promise of the modern professions to guide and empower state instutitions with accredited knowledge is shattered—all the moreso in the wake of the pandemic, which has discredited the medical establishment and the entire enterprise of public health in the eyes of many (even if for mutually contradictory reasons depending on who you ask).

I will admit that it’s very unclear to me what we are supposed to do about this situation. It should be clear that I think the Faust legend probably has more resources for thinking about how we got where we are than how to move forward. But it may be worth pondering what it would look like if we reimagined a contemporary Faust who is trying to escape from the Faustian dilemma itself. And my first suggestion along these lines would be that such a Faust-beyond-Faust would give up the gestures of subversion, resistance, and even rebellion in favor of an affirmative creation.

[Continue on to the Coda.]

Faust in the Anthropocene, Part 4: Faust and the Redemption of Modernity

28 August 2024 at 13:44

[See Part 3 here.]

When Marlowe adapted the Faust story for the stage, it is only a slight exaggeration to say it was “ripped from the headlines”—the original German chapbook had been published only a few years prior, followed by an English translation. By the time Goethe took up the same material over two centuries later, Faust was an established legendary figure in a much more assertive and confident modern world. Far from being an edgy countercultural tale that had to be wrapped up in traditional piety for plausible deniability, the Faust legend in Goethe’s Germany was a story for children, commonly performed in puppet shows. (Indeed, Goethe himself seems not to have read Marlowe’s play until very late in his life, when he was already working on Part 2 of his massive drama.)

In many ways, as with our contemporary glut of adaptations of established cultural legends, Faust is an exercise in nostalgia—nostalgia for a lost naïve faith, nostalgia for the pure emotional receptivity of childhood and youth, even nostalgia for itself, given the fact that Goethe composed the play over the course of many years. The opening poem, skipped by many readers and only added at the very last stages of composition, connects the play to Goethe’s own lost youth, and Faust himself is preoccupied with childhood. When he is on the verge of suicide after his failed encounter with the Earth Spirit, Faust is saved by a children’s chorus that reminds him of his youthful faith and, even more, his immediate connection to nature in those days. His trip to town on Easter morning brings up painful memories of childhood, as the praise he receives for his role in his father’s medical practice reminds him only of the deadly effects of the dangerous poison they unwittingly distributed as medicine. And of course much of what attracts him to Gretchen is precisely her youth and naivety, which he believes will help him reconnect with that more authentic part of himself. (This is, incidentally, an aspect of the play that renders it somewhat difficult to teach to undergrads.)

As should be clear by now, Goethe freely reworks the material, most notably by revising Faust’s background (giving the former orphan a physician/alchemist father) and introducing a love interest. At times, he seems to be almost embarrassed to be adapting the Faust legend, introducing “meta” elements to highlight the silliness of previous versions. The clearest example is the scene at “Auerbach’s Tavern in Leipzig,” where Mephistopheles plays elaborate pranks on a group of drunks and Faust has only one line: a request to go home. This is a way of having his cake and eating it too—including the pranks that were such an integral part of the legend, while at the same time marking his distance from that vision of Faust. Indeed, by the end of Part 1, we seem to have forgotten the devil’s bargain altogether, as the story has become the tragedy of Gretchen more than that of Faust. In the unforgettable scene where Gretchen refuses to accept Faust’s offer of escape even knowing that she will be executed the next morning for the death of her baby, only an over-literal pedant could possibly be concerned with the dangling thread of Faust’s soul.

This displacement of the central element of the legend is surprising in light of the fact that Goethe’s own reworking of that theme is what gives his version such philosophical depth. As with his pranks in the tavern, Mephistopheles’s attempt to secure Faust’s soul represent an attempt to enact the script of the traditional legend, which this Faust continually derails. Scorning earthly pleasures, Faust seeks something more profound—a holistic grasp of the full range of human experience, of which he has been deprived in his life of scholarly isolation. In my favorite exchange, Faust declares (quoting David Luke’s excellent translation):

Poor devil! What can you offer to me?
A mind like yours, how can it comprehend
A human spirit’s high activity?
But have you food that leaves one still unsatisfied,
Quicksilver-gold that breaks up in
One’s very hands? Can you provide
A game that I can never win,
Procure a girl whose roving eye
Invites the next man even as I lie
In her embrace? A meteoric fame
That fades as quickly as it came?
Show me the fruit that rots before it’s plucked
And trees that change their foliage every day! (ll. 1671-1688)

Clearly something very strange is going on here, but Mephistopheles simply responds: “I shall perform as you instruct; / All these delights I can purvey” (ll. 1689-1690). Can you give me worthless, self-undermining pleasures? Yup, can do!

In place of the traditional devil’s bargain, Faust proposes a wager: if he ever ceases striving, if he ever allows himself to rest in full contentment, Mephistopheles can take him. Mephistopheles should presumably be more suspicious in this moment, because he has heard similar rhetoric before. In the “Prologue in Heaven,” Goethe had staged a dialogue between Mephistopheles and the Lord much like that found in the Book of Job—except this time, it is Faust whom God declares to be his servant. Mephistopheles is understandably puzzled, and God clarifies that it is precisely Faust’s implacable striving that he admires so greatly. When Mephistopheles again echoes the more traditional story by offering a wager, God responds with absolute confidence in Faust and even claims that Mephistopheles’s constant negativity will productively spur him from his stagnation and complacency.

Again, all of this is seemingly forgotten by the end of Part 1. Yet when Goethe returned to Faust late in his life, he apparently felt constrained not to leave this divine wager unresolved forever. In the end, Goethe famously—or infamously—engineers Faust’s redemption, in part through the intercession of the late Gretchen’s spirit. The path from Gretchen’s jail cell to this unexpected outcome is a long and winding one. Part 2 is much longer than Part 1, and much more allegorical in its storytelling. On the one hand, this approach allows Goethe to radically reimagine the Faust legend as an epic encompassing all of European modernity—including the rediscovery of Greek antiquity, as suggested by Faust’s famous encounter with Helen of Troy. On the other hand, the result is a self-indulgent slog that—if the two parts are taken as an integral work—retrospectively ruins the effect of the fragmentary but unforgettable original.

Be that as it may, for the sake of my goal of connecting Faust to our Anthropocene predicament, Part 2 is more relevant. The main plot—leaving aside various fanciful digressions and the entire interlude with Helen—reminds me of a scene from the classic HBO police procedural The Wire. After months of surveilling the cautious and methodical gang leader Stringer Bell (played by Idris Elba), an investigator has an epiphany: “He’s worse than a drug dealer, he’s a property developer.” The same could be said of the Faust of Part 2—he’s worse than a demon-summoner, he’s a property developer.

Act 1 opens with Faust quite recovered from the trauma of losing Gretchen and ready for new challenges. Contemplating a waterfall, he has an epiphany: the ocean is constantly churning, but it all amounts to nothing. Dismayed by the waste, he determines to conquer the sea and turn all that wasted energy toward human ends. Mephistopheles hatches an elaborate plot to fulfill this ambition: Faust will present himself as a powerful wizard who can help the emperor defeat his foes, in exchange for land rights that are currently located under water. Faust can then reclaim the land from the sea, creating a utopian kingdom on soil truly untouched by humanity.

This plot obviously pushes the fantasies of settler colonialism to an extreme. Although it also seems to evoke the unique topography of one of the most successful colonial and mercantile states, namely the Netherlands, Faust’s vision of life in his new kingdom sounds more to me like the idealization of the American dream:

I see how
To give those millions a new living-space.
They’ll not be safe, but active, free at least.
I see green fields, so fertile: man and beast
At once shall settle that new pleasant earth,
Bastioned by great embankments that will rise
About them, by bold labor brought to birth.
Here there shall be an inland paradise:
Outside, the sea, as high as it can reach,
May rage and gnaw; and yet a common will,
Should it intrude, will act to close the breach.
Yes! to this vision I am wedded still,
And this as wisdom’s final word I teach:
Only that man earns freedom, merits life,
Who must reconquer both in constant daily strife.
In such a place, by danger still surrounded,
Youth, manhood, age, their brave new world have founded.
I long to see that multitude, and stand
With a free people on free land!
Then to the moment I might say:
Beautiful moment, do not pass away! (11559-11582)

The last phrase echoes Faust’s original wager. Even though it is a hypothetical statement about a future possibility, Mephistopheles seizes upon it, but, as I have said, his plans are ultimately foiled. And implicitly, this final labor, which actualizes Faust’s endless striving on the social, economic, and political plane, is part of the justification for Faust’s redemption. Regardless of its human costs—not only Gretchen and her baby, but also an elderly couple who are killed when Faust orders Mephistopheles to remove them from their land so he can have a better view of his kingdom—Goethe expects us to admire the grandeur of Faust’s project and to agree that he deserves the chance to continue striving eternally through the heavenly spheres.

Though this may initially seem like a reversion to the Christianity Faust dismisses early in the play, it is really a free reworking of Christian concepts and images (particularly Catholic ones, which do not reflect Goethe’s own religious background) to craft his own personal mythology of the “Eternal Feminine,” much as he had reworked Greek mythology to his own purposes in the Helen interlude. Finally, it seems, the Faustian modern man has triumphed so decisively over his Christian baggage that he doesn’t even need to reject it—instead, Goethe can treat it as indifferent material for his own goals, just as Faust treats nature itself. Where Marlowe had used Faust to dramatize the fraught transition to modernity, then, the Goethe of Part 2 recasts Faust as not only the embodiment but apotheosis of modern man.

[Continue on to Part 5…]

Faust in the Anthropocene, Part 3: Faust and the Tragedy of Misfired Modernity

27 August 2024 at 13:28

[See Part 2 here.]

This dynamic plays out almost literally in the opening monologue of Marlowe’s Tragical History of Doctor Faustus, which was written only a few years after the publication of the original Faust chapbook. When we meet Faustus, he is surveying the fields of human knowledge to determine which is of most value. He starts with Aristotelian logic, which claims foundational status and yet achieves no more than to help one “dispute well.” Faust is dissatisfied: “Is, to dispute well, logic’s chiefest end? / Affords this art no greater miracle? / Then read no more; thou hast attain’d that end” (1.1.8-10). Already we can see the mismatch—surely disputing well is not miraculous, but neither does it claim to be. He then moves on to medicine, again quoting and rejecting this field’s promised result: “The end of physic is our body’s health. / Why, Faustus, hast thou not attain’d that end?” (1.1.16-17). He then lays out an impressive résumé of his achievements as a physician but concludes: “Yet art thou still but Faustus, and a man. / Couldst thou make men to live eternally, / Or, being dead, raise them to life again, / Then this profession were to be esteem’d” (1.1.22-24). Again, Christian presuppositions are producing inappropriate expectations. Faustus then dismisses law as a matter of “paltry legacies” that “fits a mercenary drudge, / Who aims at nothing but external trash” (1.1.28 and 32-33). In place of an explicit comparison to Christian standards—the obvious source of his contempt for mere worldly possessions—Faustus then turns to the study of divinity itself. Apparently flipping through the Bible at random, he turns first to Romans 6:23, “for the wages of sin is death…” and then 1 John 1:8, “If we say that we have no sin, we deceive ourselves, and / there’s no truth in us” (1.1.38-42). In combination, these verses seem to Faustus to indicate that his situation is hopeless—he is constained to sin and therefore to die, a prospect that seems to render life meaningless.

One is tempted to say that the way out of the deadlock he points out can be found in the second half of the verse from Romans—“the gift of God is eternal life in Christ Jesus our Lord”—but surely we must give a theology PhD the benefit of the doubt that he knows the Bible. Rather than assuming he is simply making a mistake, I propose that he is lodging a deeper objection to Christianity when he claims that it amounts to a doctrine of “Che serà, serà” (1.1.46) The issue isn’t that there is no hope of salvation, but that the believer is rendered completely passive and powerless. By contrast, his books of magic seem to promise “a world of profit and delight, / Of power, of honour, of omnipotence” (1.1.52-53)—rather than relying on God’s arbitrary gift for his salvation, by becoming a magician Faustus can “gain a deity” of his own (1.1.61).

Yet when Faustus reaches the pinnacle of the magical art by allying himself with Mephistopheles, he spends his life squandering his supposedly divine power on a series of stupid pranks. The sense of pointless dissipation is echoed on the formal level by a plot that never seems to cohere into anything meaningful—defying Aristotle’s prescription of tragic unity in favor of a formless concatenation of episodes. On the level of plot and character as well, Marlowe’s Tragical History seems to defy Aristotle’s standards for tragic drama from the Poetics. There Aristotle defines tragedy as follows (quoting from the Joe Sachs translation):

Tragedy, then, is an imitation of an action of serious stature and complete, having magnitude, in language made pleasing in distinct forms in separate parts, imitating people acting and not using narration [by which he means that it is a play], accomplishing by means of pity and fear the cleansing of these states of feeling. (1449b)

As we have seen, far from being serious and complete, the play is a disjointed collection of mostly comic anecdotes. While Marlowe does hit the marks of using pleasing poetic language and literally writing a play rather than a prose narrative, it is not clear to me that we really experience pity and fear in relation to Faust’s fate. The apparent disconnect deepens when we consider Aristotle’s definitions of the tragic character and tragic action. For Aristotle, the tragic hero should be “the sort of person who is not surpassing in virtue and justice, but does not change into misfortune through bad character and vice, but on account of some missing of the mark,” and the action of a tragic play should depict “changing not into bad fortune from good but the opposite way, from good fortune to bad, not through badness of character but on account of a great missing of the mark” (1453a).

In Greek, the term for “missing of the mark” is the famous hamartia, which Christianized interpretations of Greek tragedy have construed as a “tragic flaw”—often pride. In reality, though, Aristotle means that the tragic hero should have made an understandable mistake. Oedipus doesn’t suffer because he’s a bad person—he’s a smart and capable guy who is trying his best to carry out his royal duties, but he got caught up in something really terrible through understandable ignorance. I don’t know how rigorously Marlowe read Aristotle or whether this distinction would have been available to him, but I do think it points toward two possible readings of the play—both of which turn on how we interpret Faustus’s objection to the doctrine of original sin. If we accept the Christianized notion of a “tragic flaw,” we would have to say that Faustus’s pride blinded him to the true nature of Christianity, leading him down his demonic path. If we think more in terms of Oedipus, who was attempting to do good things (e.g., avoiding murdering his father and marrying his mother, or looking out for his city) without realizing the trap he was in, the play becomes more interesting.

This second reading challenges us to look for what is admirable in Faustus, and when we do that we realize that it all hinges on his thirst for knowledge. Among the conditions of his devil’s bargain is the demand that Mephistopheles must answer all his questions—the only power that Faustus actually tests out before signing on the dotted line. We are also told that Mephistopheles takes Faustus to see both the heavenly spheres and a good chunk of the earthly sphere as well, though presumably Marlowe’s special effects budget was insufficient to show those actions directly. To the extent that Faustus seeks eartly power, it is as a servant to the king who helps enrich the kingdom—an ironic echo of the figures of Joseph or Daniel from the Bible, as well as an enactment of exactly the promise that the modern professions and academic disciplines made for themselves. Despite his initial dreams of domineering power from the opening monologue, he never commits irreversible violence and never seeks power for his own sake. Aside from petty amusements and some sexual satisfaction, the only thing he really desires is knowledge—which I personally find to be an admirable desire.

From this perspective, the tragedy of this Tragical History is not that Faustus has chosen damnation but that he was, like Oedipus, born under the wrong circumstances. His mistake is to seek out pure disinterested knowledge in a world where it can only appear as demonic and can only lead to damnation. Marlowe may not have succeeded in crafting a cohesive play, but if my reading does not miss the mark, he did intuitively, and profoundly, grasp the potential of the Faust legend. The original Faust chapbook amounted to a salacious gossip rag laundered with a superifical moral lesson (“don’t sell your soul to the devil, kids!”). In Marlowe’s hands, it becomes an existential meditation on the deadlocks of a world where Christianity appears as a legacy that is at once “paltry” and inescapable.

[Continue on to Part 4.]

Faust in the Anthropocene, Part 2: Faust and the Preemptive Crisis of the Professions

26 August 2024 at 13:38

[See Part 1 here.]

So far I have emphasized how Life and Trust embodies the unique combination of forward- and backward-looking elements that have made the Faust legend such a fertile ground for reflecting on the dilemmas of modernity. In terms of its narrative frame, this immersive theatrical experience’s portrayal of Faust as a disillusioned banker also draws on a more understated theme. Again and again, we see Faust (or the stand-in character) as a member of one of the professions. In the film The Devil’s Advocate, for instance, Keanu Reeve’s Faustian character is a high-powered lawyer. Goethe’s own version winds up making a transition that I’m sure many of us have considered, moving from professor to political fixer and property developer. And both Goethe and Marlowe, drawing on the earliest versions of the Faust legend, agree that their hero mastered all of the professions of his day and held doctorates from all four major faculties of the university: divinity, law, medicine, and philosophy.

From the very beginning, then, Faust embodies a uniquely modern form of authority, that of the credentialed professional. It is worth pausing to reflect on this association, which seems to prefigure the growing distrust of professionalism and professionals in our contemporary society. What is it about the traditional professions that could seem so suspect, so sinister? Perhaps one hint is another persistent association with Faust, aside from the obvious wickedness of seeking alliance with the devil. I am thinking of the view that Faust is a deceiver. Already in the original chapbook legend that compiled the stories that gathered around the historical Johann Georg Faust, we see Faust identified as a magician and alchemist. Later variations on the theme build on this association with charlatanism and deception. One of the most interesting examples is István Szabó’s film Mephisto portrays the Faust figure as an actor who, ironically, made his name by playing Mephistopheles in Goethe’s Faust. Not only is his profession intrinsically deceptive, but the Faustian character decides to pose as a committed Nazi in order to protect the theater from Hitler’s regime. Thomas Mann’s Doctor Faustus centers on the growing madness of Adrian Leverkühn, who is a master of the most seductive yet ungraspable of the arts—namely music. It does not seem like a stretch to say that both of these more modern Fausts are performing a kind of secularized magic, a disenchanted alchemy.

Going back to the most formative versions of the legend, both Marlowe and Goethe present these two sides of Faust—the credentialed professional and the magical manipulator—as intrinsically linked. In Marlowe’s play, Faust’s dissatisfaction with the power on offer from his four fields of study is what leads him to his magical and demonic pursuits, as though there is a continuity of aim between the professions and sorcery. Indeed, the Latin truisms that Marlowe’s Faust rattles off in the opening monologue seem almost like spells in themselves. Goethe characteristically pushes this Faustian theme even further, staging the assessment of the different fields of study as a dialogue between Mephistopheles (disguised as Faust) and a student who is trying to choose his course of study. In Mephistopheles’s cynical descriptions, the various professions are intrinsically false. Not only do they derive their power from obfuscation, but they license abuse—most notably when Mephistopheles suggests that the student choose medicine in order to have the opportunity to take advantage of his women patients. Even worse, earlier in the Goethe’s play Faust himself dismisses his father’s medical knowledge as worse than useless, claiming that his alchemy-derived drugs, far from curing victims of the plague, effectively euthanized them.

Life and Trust’s banker, driven to despair by the impending collapse of the fraudulent financial system he has presided over, is thus a natural extrapolation—Faust is, in essence, a credentialed expert who no longer finds himself credible. I use terms related to belief or faith advisedly here. If Faust is about a modern crisis of faith, it is also about a Christian crisis of faith. The trope of the deal with the devil contains a fatal paradox. In order to believe that such a deal is possible, that such an entity exists, one must accept the framework of Christian belief. But within that framework, such a deal can only lead to disaster and damnation! At the cusp of modernity, then, Faust simultaneously embodies a corrupted and self-undermining Christian faith and a corrupted and self-undermining professional authority. The most simplistic Whig narrative of modernity holds that medieval superstition was discredited and replaced by authentic modern rationality. In the Faust narrative, by contrast, the authority of Christianity has certainly seen better days, but its hold remains tenacious and insidious enough to damn Faust—and condemn the alternative modern forms of authority in advance. One is reminded of the classic Seinfeld episode where George claims God is cursing him. When Jerry reminds him that he doesn’t believe in God, George retorts: “I do for the bad stuff!”

So far I have spoken primarily of Faust as a professional and of the strangely preemptive collapse of professional authority in the legend. If we view the various professions through Mephistopheles’s cynical lens, there may seem to be no problem. Who cares if lawyers and bankers are consumed with self-doubt? Yet Goethe’s focus on Faust’s status as a medical doctor does point to a deeper problem. The credibility of modern professional credentials is not—or at least professes not to be—grounded solely in the empty self-assertion of a power-hungry clique. The modern credentialed profession claims to have a special knowledge that the professional guild exists to safeguard and expand. As the example of medicine shows, we all must hope that that knowledge is not purely invented or self-referential. We associate medicine more closely with scientific knowledge in the narrow sense, but ultimately all professions claim to have a knowledge that is scientific in the broader sense of the German Wissenschaft. Even if non-specialists are typically not in a position to assess the knowledge claimed by modern professionals, their knowledge is or should be rational, objective, and publicly verifiable. That association with science or Wissenschaft is why the university has always been the site of modern credentialization—and hence why Faust, as the professor who is fully credentialed in all fields, represents such a distinctively modern crisis of faith.

Here one may detect the influence of Hans Blumenberg’s monumental tome The Legitimacy of the Modern Age. As is well known, there Blumenberg forcefully rejects the claim of political theology that secular modernity is determined by its Christian roots. As a political theologian myself, I personally find his critique a bit beside the point, because he is not talking primarily about the political concepts and institutions that are political theology’s stock and trade, but about an institution that political theology mainly ignores: namely, modern science. For Blumenberg, modern scientific knowledge is at once genuinely new and genuinely authoritative—to use the German word for modernity, it is what is neu in the Neuzeit. Where the political theologian, in Blumenberg’s telling, is constantly seeking to undermine modernity as founded on the shifting sand of a disavowed legacy, Blumenberg insists that modern science is fully legitimate on its own terms.

This does not mean that modern science has nothing to do with Christianity, however. Science does not arise from Christianity, but it does arise in the midst of Christianity. And just as Christianity found that it had to provide some kind of answer to the questions raised by the most sophisticated and prestigious discourses of its time, namely Greek philosophy, so too does modern science have to respond in some way to the Christian milieu in which it happens to have arisen. In both cases, the attempt to answer the existential questions posed by the old regime is a case of putting new wine in old wineskins. In the extreme case, questions that were urgent in the context of the earlier paradigm become simply irrelevant in the new era—except that the handoff is never so neat and tidy. Even if those who inaugurate the new paradigm are able to cast aside the old values themselves, they must convince others who are still immersed in the old world.

One of Blumenberg’s clearest examples of this dynamic is the Christian theological conviction that the only knowledge worth having is knowledge about one’s relationship to God, or more abstractly, knowledge about the meaning and purpose of existence. As is well known, that is not the kind of knowledge modern science supplies—nor is it trying to. Yet the inertia of Christian expectations transforms that category error into a persistent disappointment, as though modern science is constantly trying and failing to supply a form of meaning that it in fact has no means or ambition to supply. And that disappointment always threatens to curdle into suspicion and hostility, because traditional Christianity—with its accustomed binary thinking—views knowledge that falls short of its standards not as indifferent or irrelevant, but as actively wicked.

[Continue on to Part 3.]

Faust in the Anthropocene, Part 1: Faust the Innovative Throwback

25 August 2024 at 17:05

[Editor’s note: I was invited to give a keynote address for this year’s Romancing the Gothic online conference. Given that the theme was “Devils and Justified Sinners,” I chose to discuss the Faust legend, which has been a big part of my teaching for many years but not something I have devoted any concentrated writing to. Since it is my first experiment in writing about Faust, it is closer to a blog post than a formal article in spirit, and so I will be posting the talk here in serialized format over the course of the week.]

It may initially seem strange that I am proposing to connect the two themes in my title. What could the story of a deal with the devil have to do with our contemporary ecological crisis? Here I could invoke any number of superficial parallels—we “made a deal with the devil” of capitalist growth and now the bill is coming due, etc., etc. That would doubtless be a satisfyingly clever way of saying the things we already know to be true about climate change, but it would not shed much fresh light on either the Faust legend or the Anthropocene.

Instead of jumping right into the comparison, then, I will largely take everyone’s knowledge of climate change for granted and focus initially on an analysis of the most fundamental themes of the Faust legend.  I observe first of all that the Faust legend has always provided a way to use the old to think through the new. In its demonological themes, the legend seems initially to be grounded in “medieval superstition.” Yet it is based on a historical individual—a fact that I can never quite believe—who lived at the very cusp of modernity, and its many later interpreters and appropriators have always used it to think through distinctively modern dilemmas. This is true even at the level of medium. The original Faust chapbook was one of the first runaway bestsellers of the print era, and Marlowe’s Doctor Faustus was among the most iconic showpieces of the Elizabethan era’s secular theater.

The Faustian fusion of innovation and old-timey-ness continues even to this day. This past weekend, I was fortunate enough to travel from Chicago to New York City to see the latest adaptation of the Faust legend, called Life and Trust. (In fact, I wrote a good portion of this talk in the hotel lobby after being stranded by a major storm that surely arose to punish me for so extravagantly indulging in my obsession with devils and demons.) Life and Trust belongs to an emergent but increasingly popular genre that we could call the immersive theatrical experience. The goal of this unique format is to break down the barrier between the audience and the players. Instead of watching events unfold on stage, the audience is thrown into the same space as the actors—a sprawling, even confusing space where everyone is free to wander. Even more radically, it shatters the unity of theatrical action by dispersing the actors and scenes throughout the space. Though many of the scenes play out in a kind of repeated loop, it is functionally impossible to see everything in one performance. And you have to work for what you do see, chasing after the incredibly athletic actors as they wind through a labyrinthine and stair-filled venue.

Life and Trust was developed by the producers of the best-known previous entry in the genre, the Macbeth adaptation Sleep No More, which recently completed a ten-year run. In the waiting area before the show, we talked to a young couple who had attended Sleep No More multiple times in the hope of seeing as much of its sprawling plot as possible. Some fans attended upward of a dozen times so that they could explore every nook and cranny of the elaborate set—audience members are allowed to dig through drawers, for example, which often include surprising background information or Easter eggs. Though Sleep No More had some limited dialogue, it was primarily a dance-based experience, something like a fragmentary narrative ballet. Life and Trust took that even further, all but dispensing with dialogue in favor of intense choreography.

In keeping with the tradition of Faust adaptations, this innovation was paired with a look backward—not to the early modernity of Faust, but to the Gilded Age and the Great Crash of 1929. For Americans, those events are a kind of pre-history, the threshold to the “American century” that began with Roosevelt’s New Deal, which profoundly transformed the American state and economy and laid the foundation for the postwar boom. But it is a past that continues to haunt the neoliberal era, where skyrocketing inequality and degraded state capacity threaten to return us to a new Gilded Age and recurrent economic crises inevitably raise the specter of a new Great Depression. The Faust avatar is a banker who is about to go bust in the Great Crash and sells his soul for the opportunity to relive his youth in the late 1800s. Once transported back to that era, the audience has the chance to follow any number of side characters from a variety of social backgrounds. One plot we were able to follow was that of a lesbian romance between a wealthy aristocrat and a servant girl, presided over by a demon who—as far as I was able to discern—was actually trying to get them to deny their love and conform to social norms, rather than egging on their supposed “sin.” This strikes me as a brilliant adaptation of the demonological theme for a world where the most serious sins are those against authenticity.

The audience in Life and Trust isn’t left completely rudderless. The drama is framed by two shared experiences, the opening scene that establishes the outline of the narrative and a dramatic conclusion. Even in those performances, it is impossible to take in everything at once from any particular standpoint within the theatrical space. But the basic outline of events is clear, especially in the final scene, where Faust’s side of the bargain inevitably comes due. As Faust pleads for his soul, dancers in demonic masks throw fake money down on the audience—and at times tear the bills to shreds, enacting the nearest secular equivalent to the death of God. Faust’s fate is also secularized. Instead of being pulled down into a literal hell, he is fitted with a strait jacket and consigned to an insane asylum, a potent image of being reduced to a non-person. For good measure, he is also drowned in a way reminiscent of magicians’ clones from the film The Prestige—an apparent reference to themes of uncanny doubles and echoes of The Picture of Dorian Gray that unfolded in parts of the theater I was unable to find. There is, in short, a lot going on.

[Continue on to Part 2….]

FreshRSS 1.24.2

23 September 2024 at 22:49

This is a quality-focussed release for the 1.24.x series meant to provide a good product to people blocked on PHP 7.4, while we will increase the requirements to PHP 8.1+ from the next 1.25.x series.

A few highlights ✨:

  • New global option to automatically add articles to favourites
  • New option to share articles from the article title line
  • Add core extensions, shipped by default: UserCSS and UserJS
  • Security: Force log out of users when they are disabled
  • Many bug and regression fixes

This release has been made by @Alkarex, @ColonelMoutarde, @den13501, @hkcomori, @math-GH
and newcomers @dservian, @crisukbot, @TomW1605

Full changelog:

  • Features
    • New global option to automatically add articles to favourites #6648
    • New possibility to share a user query in JSON GReader format #6655
    • New fields image and description for user query share #6541
    • Show article first words when an article title is empty #6240
    • New option to share articles from the article title line #6395
    • Improve JSON Dot Notation module to access more string-friendly types #6631
    • Improve detection of image types for enclosures not providing a type #6653
    • Add sharing to archive.is #6650
  • Security
    • Force log out of users when they are disabled #6612
    • Increase default values for OpenID Connect OIDCSessionMaxDuration and OIDCSessionInactivityTimeout #6642
    • Add default API CORS HTTP headers to shareable user queries #6659
  • Bug fixing
    • Fix parentheses for complex OR Boolean search expressions #6672
    • Fix keep max unread #6632
    • Fix regression in mark as read upon gone #6663
    • Fix regression on mark duplicate titles as read for modified articles #6664
    • Fix regression for Fever API, remove dependency to Exif extension #6624
    • Fix muted feeds for WebSub #6671
    • Fix performance / deadlock of PostgreSQL and MySQL / MariaDB during schema updates #6692
    • Fix HTTP cache of main page (regression since 1.18.0) #6719
    • Fix HTTP cache of shareable user queries #6718
    • Fix HTTP cache for feeds with modified Last-Modified when content is not modified #6723
  • Extensions
    • Add core extensions, shipped by default: UserCSS and UserJS #6267
      • Replaces CustomCSS and CustomCS extensions
    • Strong type array parameter helper #6661
  • CLI
    • Add quiet option to cli/db-backup.php #6593
  • Compatibility
  • Deployment
    • Docker default image (Debian 12 Bookworm) updated to PHP 8.2.20 and Apache 2.4.61
    • Docker alternative image updated to Alpine 3.20 with PHP 8.3.10 and Apache 2.4.62 #5383
    • Docker: Alpine dev image freshrss/freshrss:newest updated to PHP 8.4.0beta3 and Apache 2.4.62 #5764
  • UI
    • Default dark mode to auto #5582
    • New option to control action icons position in reading view #6297
    • Sticky buttons at the bottom of settings #6304
    • Various UI and style improvements #6446, #6485,
      #6651
  • I18n
    • Czech: use correct ISO 639-1 code cs (and not cz, which is the country) #6514
    • Improve Japanese #6564
    • Improve Spanish #6634
    • Improve Traditional Chinese #6691
  • Misc.

Seven Historic London Hotels for Cocktails

15 August 2024 at 20:16

The best historic London hotels seamlessly merge the city’s past with its present, leaving clients to contemplate a bygone era over modern day cocktails. Some have been hotels since their […]

The post Seven Historic London Hotels for Cocktails appeared first on Paris • Cocktails • Bars.

On drawing lines

13 August 2024 at 22:27

I’m gratified at the response yesterday’s post has received. It always makes one nervous to criticize what we used to call “political correctness,” because it can both open one up to unfair attacks and make one “sound like” bad political actors. The fact that I only really saw one response that appeared to conflate my critique of “political correctness” with a South Park-style advocacy of using offensive terms for their own sake was promising in this context. It seems like people really are tired of — quite literally exhausted by — this style of ostentatious self-righteous nitpicking. Nevertheless, for my own peace of mind I’d like to make it a little more explicit where I “draw the line” between the kind of common-sense courtesy and sensitivity we should all display and the kind of self-defeating signalling that we should try to avoid.

One clear case came out of a Facebook thread where one individual shared their gut-level offense at the term “moron” and their disappointment that I used that term as an example of PC overreach. In point of fact, I have eliminated “moron” from my everyday language, because I’m aware that those sensitivities exist. I believe they have been actively cultivated in a way that is ultimately counterproductive, but I can’t undo the fact that people have those sensitivities and there is no reason for me to offend them needlessly. I apologized for causing offense to that individual. By contrast, there was one time several years ago that I slipped up and used the word “moron” in a tweet, and a stranger — with no apparent connection to the disability community — direct-messaged me that such language could be offensive. When I shared my view that disability activists had actively cultivated those associations and created an occasion for offense where one needn’t exist, this person said they actually agreed with me.

To me, these two conversations are a teachable moment. One person was speaking on their own behalf, sharing that their experience and situation made a certain term hurtful to them. The other was speaking on behalf of a purely hypothetical other person who may potentially take offense. Basically, I think we should all respond with generosity and compassion to the former and we should stop doing the latter. We can perhaps think of other examples along these lines. For instance, it’s clear to me that all white people should treat the N-word as completely forbidden and taboo. There is no circumstance under which they should utter it, and they should call out their fellow white people if one of them breaks this taboo. By contrast, for a white person to correct a fellow white person who is still using the slightly outdated “African American” instead of the more current “Black” strikes me as not worth it.

Obviously in some sense the taboo against white people using the N-word is speaking on behalf of someone else — but it’s also speaking on behalf of oneself. We should all be offended by racism. It is a false and destructive pattern of belief and behavior that has no place in our shared life. We should not want to be racist and we should create conditions under which others do not feel comfortable being racist. It’s not only about not gravely offending Black people — though that is also urgently important. It’s also about what kind of person you want to be. Not keeping up with whether “Black” or “African American” is the preferred usage does not seem to have the same moral weight. (In fact, many older white people probably lived through a time when “Black” seemed vaguely insulting and “African American” was meant to signal greater respect.)

The case is clearer when some new coinage or practice is instituted. The odds that these innovations are responding to actual demands or even desires of the group in question are, in my experience, very very small. Even if members of thoses groups contributed to the proposed new norm, they likely represent an elite, unrepresentative strata of that community. A term like “Latinx,” for instance, clearly does not emerge organically out of the self-understanding of communities of Latin American descent. It is an ugly neologism that aims to “solve” the perceived problem that “Latino” does not appear sufficiently gender-inclusive from an Anglophone perspective. (I’ve also seen “Latin@,” which… a crucial aspect of words is that you have to be able to say them.)

Similarly, I’m not convinced that most land acknowledgments actually arise from genuine dialogue with the affect indigenous peoples — presumably many of them are based on internet searches for which tribes used to occupy a certain area, etc. If no one is asking for these acknowledgments and if no concrete change in practice results (is anyone doing land acknowledgments in the Chicago area actually reimbursing the Potawatomi People for the use of their unceded land, for example?), then I’m not sure what we’re trying to accomplish other than performing a certain “best practices” of righteousness. Of course, I can only assume that some land acknowledgments do result from such dialogue and engagement — but the awkwardly ritualistic nature of the practice leads me to believe that the vast majority of them represent a form of trend following.

I don’t presume to be the final arbiter on such matters. But that’s kind of my point — there can be no final decision of “where to draw the line.” We’re all just human beings and we need to negotiate a way to live together. The “politically correct” style of social justice denies that. It tries to set up in advance what the rules of engagement will be, often unilaterally on behalf of the very people it is supposedly empowering. But there is no system that is not gameable, no language that can’t be used to hurt. We all know people who have used politically correct categories to shame and silence others for individual gain or simply for the enjoyment of a power trip. We shouldn’t be afraid to call bullshit on that kind of behavior, and for too long we mostly have been.

To be sure, many people who reject political correctness (and especially those who deploy the term “woke”) are bad actors who simply resent that they aren’t allowed to make racist and sexist jokes anymore. But many are potentially reachable people who were turned off by the alienating neologisms and bad faith power plays — and when we can’t acknowledge that, especially when we conflate such excesses with “common sense” courtesy and respect, we are hurting the cause.

Again, to my mind the current messaging from the Democrats is well on “this side” of that line. They hold Trump, Vance, and their cronies up to ridicule for their blatant racism and sexism and homophobia. They presuppose that such attitudes and behaviors are unacceptable and expect their audience to agree — and the vast majority of Americans do agree. But more than that, rather than associating them with an inescapable all-pervading power, they present such attitudes and behaviors as ultimately pathetic. Look at these fools — why are they like that? Why would anyone want to be like that? In short, they respond like humans and invite their audience to respond like humans. That’s what makes it such a breath of fresh air compared to the kind of HR-inflected social justice jargon that has dominated such discussions for too long.

“Weird” conservatives and the end of whiny self-righteousness

12 August 2024 at 15:52

In the wake of Biden’s withdrawal from the race and Kamala Harris’s shockingly rapid and decisive ascension, I have begun feeling emotions that I haven’t allowed myself to feel in connection to politics in a long time: hope, excitement, even enjoyment. As many commentators have noted, there is a joyfulness, even a level of fun, to Harris’s campaign that is an almost shocking contrast to what came before. The fact that they are playing along with the JD Vance couch meme may be the clearest sign that they are in tune with contemporary culture, but the more general pattern of calling conservative leaders “weird” and “creepy” feels like a major turning point — not just in terms of political tactics, but in terms of liberal political culture. It marks the end of a certain fatalistic defensiveness on the one hand, and also of the joylessly self-righteous habits of policing and shaming allies on the left.

For all my life, conservatives have been the norm. Everybody (who matters) feels at best very uncomfortable about abortion and non-normative sexuality. Everybody (who matters) resents the burden of funding high-quality public service. Etc., etc., etc. Tactical observations from the early 90s hardened into inescapable truisms, even as they became less and less true. This produced a permanent defensive crouch, as Democrats seemed to believe that Republican rule was the norm and they could at best eke out a narrow win to take their turn — at passing a more nuanced and “smarter” version of Republican policies. Priority number one after each victory was to get bipartisan support, as though Democrats didn’t believe it was legitimate for them to legislate on their own. Attachment to the fillibuster rule among the older cohort of Democratic senators is the most destructive example of this built-in defeatism.

So the new confidence of the Harris campaign is refreshing, as is the contempt and puzzlement they express at conservatives’ increasingly unpopular and downright bizarre beliefs. More specifically, what is refreshing here is their willingness to be mean, to insult, to reduce their opponents to sputtering speechlessness. I cannot emphasize enough how much of a break this is with the joylessly self-righteous policing of language that has been the norm among liberals and leftists for my entire adult life. From that perspective, the parody responses write themselves — “we shouldn’t kink-shame JD Vance…” or “Republican leaders won’t read your post calling them weird, but your friends who could be viewed as weird for completely unrelated and totally harmless reasons will…” — and the fact that it’s so easy to come up with them shows how that mode of engagement has reduced itself to self-parody.

A key shift for me when I saw a white man worrying aloud about the tendency to refer to Vice President Harris as “Kamala” — there is of course a whole history of belittling people by refusing the respect of their last name, it’s especially fraught since she’s a Black woman, etc., etc. And I will be honest with you and say my first response was that this person should simply shut the fuck up. “Kamala” is a very distinctive name, whereas “Harris” is not. Her own social media team is called “Kamala HQ.” We do not need to get out ahead of the supposed “victim” herself.

More broadly, though, my strong gut reaction reflected my belief that we have just got to be done with this style of whiny preemptive strike against any hypothetical offense that may one day be perceived. Political correctness is a strategy that has failed. Aside from eliminating the grossest slurs and overtly bigoted jokes — which even conservatives themselves know not to share in mixed company — it has produced only irritation and insecurity.

People like to present it as simple common sense, but the euphemism treadmill and, more than that, the constant incentive to find ever more nuances of linguistic “oppression” ensure that the politically correct linguistic norms can never actually settle into a coherent common sense. It produces bristly defensiveness in those who can’t keep up and an unhealthy and counterproductive readiness to be offended among the avant-garde. My favorite example of the counterproductive nature of such language policing is the fact that disability activists are more or less singlehandedly keeping alive the etymological association of words like “moron” with disability. Linguistic usage moves on — take the win! But no, etymology is destiny when it gives you something to nitpick and alienate potential allies over.

Related here, I think, is the culture of constantly nitpicking headlines from the New York Times on social media. Again, the belief is that politics will take care of itself if everyone agrees to speak in just the right way. Obviously, the New York Times is a bad actor in many ways and the media establishment is artificially propping up Trump through the application of double standards. They are worthy of critique, but the obsessiveness and detail-orientation of the critique is what raises my hackles. It bespeaks a whiny wounded entitlement, as though we all believe that the New York Times should be a liberal actor or that a simple description of reality would automatically favor our politics.

In reality, to do politics, you have to do politics. The media is not an umpire, it is a terrain of struggle. The Harris campaign is engaging that struggle much more effectively than Joe Biden ever could because it does not embrace the false premise that the New York Times is or should be on her side by default. And she has received overwhelmingly favorable coverage! Not 100% — there is always something to whine about, of course. They don’t always put the word “falsely” in the headline, and sometimes they take too long describing Trump or Vance’s claims before debunking them. They achieved that not by whining about how unfair the Times has been, but by actively setting the agenda and setting the tone.

And that tone is mean. It is contemptuous. It aims to harm Trump and Vance and their reputations. It aims to make them personally angry and make people question their loyalty to such deeply flawed men. To achieve these goals, it is not overly concerned about petty details like whether JD Vance really engaged in an elaborate form of masturbation involving his furniture and described it at length in his memoir — much less whether other furniture-masturbation enthusiasts might be collateral damage of the joke. The joy and humor and fun of the Harris campaign, the way that it acknowledges the Republicans as enemies without setting them up as all-powerful, hopefully marks a decisive end to that kind of idiocy. From now on, entitlement and prickly defensiveness can remain in its more natural home — among the washed up losers who have coasted on white male privilege so long and spent so much time in the “safe space” of their ideological bubble that they don’t realize how pathetic they appear to anyone halfway normal — because eventually everyone complaining about unfair media coverage and moaning about how they aren’t being shown the proper respect will realize that… they sound like Trump.

The Coming Software Apocalypse

24 July 2024 at 09:33
estimated reading time: 49 min

There were six hours during the night of April 10, 2014, when the entire population of Washington State had no 911 service. People who called for help got a busy signal. One Seattle woman dialed 911 at least 37 times while a stranger was trying to break into her house. When he finally crawled into her living room through a window, she picked up a kitchen knife. The man fled.

To hear more feature stories, see our full list or get the Audm iPhone app.

The 911 outage, at the time the largest ever reported, was traced to software running on a server in Englewood, Colorado. Operated by a systems provider named Intrado, the server kept a running counter of how many calls it had routed to 911 dispatchers around the country. Intrado programmers had set a threshold for how high the counter could go. They picked a number in the millions.

Shortly before midnight on April 10, the counter exceeded that number, resulting in chaos. Because the counter was used to generate a unique identifier for each call, new calls were rejected. And because the programmers hadn’t anticipated the problem, they hadn’t created alarms to call attention to it. Nobody knew what was happening. Dispatch centers in Washington, California, Florida, the Carolinas, and Minnesota, serving 11 million Americans, struggled to make sense of reports that callers were getting busy signals. It took until morning to realize that Intrado’s software in Englewood was responsible, and that the fix was to change a single number.

Not long ago, emergency calls were handled locally. Outages were small and easily diagnosed and fixed. The rise of cellphones and the promise of new capabilities—what if you could text 911? or send videos to the dispatcher?—drove the development of a more complex system that relied on the internet. For the first time, there could be such a thing as a national 911 outage. There have now been four in as many years.

It’s been said that software is “eating the world.” More and more, critical systems that were once controlled mechanically, or by people, are coming to depend on code. This was perhaps never clearer than in the summer of 2015, when on a single day, United Airlines grounded its fleet because of a problem with its departure-management system; trading was suspended on the New York Stock Exchange after an upgrade; the front page of The Wall Street Journal’s website crashed; and Seattle’s 911 system went down again, this time because a different router failed. The simultaneous failure of so many software systems smelled at first of a coordinated cyberattack. Almost more frightening was the realization, late in the day, that it was just a coincidence.

“When we had electromechanical systems, we used to be able to test them exhaustively,” says Nancy Leveson, a professor of aeronautics and astronautics at the Massachusetts Institute of Technology who has been studying software safety for 35 years. She became known for her report on the Therac-25, a radiation-therapy machine that killed six patients because of a software error. “We used to be able to think through all the things it could do, all the states it could get into.” The electromechanical interlockings that controlled train movements at railroad crossings, for instance, only had so many configurations; a few sheets of paper could describe the whole system, and you could run physical trains against each configuration to see how it would behave. Once you’d built and tested it, you knew exactly what you were dealing with.

Software is different. Just by editing the text in a file somewhere, the same hunk of silicon can become an autopilot or an inventory-control system. This flexibility is software’s miracle, and its curse. Because it can be changed cheaply, software is constantly changed; and because it’s unmoored from anything physical—a program that is a thousand times more complex than another takes up the same actual space—it tends to grow without bound. “The problem,” Leveson wrote in a book, “is that we are attempting to build systems that are beyond our ability to intellectually manage.”

Our standard framework for thinking about engineering failures—reflected, for instance, in regulations for medical devices—was developed shortly after World War II, before the advent of software, for electromechanical systems. The idea was that you make something reliable by making its parts reliable (say, you build your engine to withstand 40,000 takeoff-and-landing cycles) and by planning for the breakdown of those parts (you have two engines). But software doesn’t break. Intrado’s faulty threshold is not like the faulty rivet that leads to the crash of an airliner. The software did exactly what it was told to do. In fact it did it perfectly. The reason it failed is that it was told to do the wrong thing. Software failures are failures of understanding, and of imagination. Intrado actually had a backup router, which, had it been switched to automatically, would have restored 911 service almost immediately. But, as described in a report to the FCC, “the situation occurred at a point in the application logic that was not designed to perform any automated corrective actions.”

This is the trouble with making things out of code, as opposed to something physical. “The complexity,” as Leveson puts it, “is invisible to the eye.”

The attempts now underway to change how we make software all seem to start with the same premise: Code is too hard to think about. Before trying to understand the attempts themselves, then, it’s worth understanding why this might be: what it is about code that makes it so foreign to the mind, and so unlike anything that came before it.

Technological progress used to change the way the world looked—you could watch the roads getting paved; you could see the skylines rise. Today you can hardly tell when something is remade, because so often it is remade by code. When you press your foot down on your car’s accelerator, for instance, you’re no longer controlling anything directly; there’s no mechanical link from the pedal to the throttle. Instead, you’re issuing a command to a piece of software that decides how much air to give the engine. The car is a computer you can sit inside of. The steering wheel and pedals might as well be keyboard keys.

Like everything else, the car has been computerized to enable new features. When a program is in charge of the throttle and brakes, it can slow you down when you’re too close to another car, or precisely control the fuel injection to help you save on gas. When it controls the steering, it can keep you in your lane as you start to drift, or guide you into a parking space. You couldn’t build these features without code. If you tried, a car might weigh 40,000 pounds, an immovable mass of clockwork.

Software has enabled us to make the most intricate machines that have ever existed. And yet we have hardly noticed, because all of that complexity is packed into tiny silicon chips as millions and millions of lines of code. But just because we can’t see the complexity doesn’t mean that it has gone away.

The programmer, the renowned Dutch computer scientist Edsger Dijkstra wrote in 1988, “has to be able to think in terms of conceptual hierarchies that are much deeper than a single mind ever needed to face before.” Dijkstra meant this as a warning. As programmers eagerly poured software into critical systems, they became, more and more, the linchpins of the built world—and Dijkstra thought they had perhaps overestimated themselves.

What made programming so difficult was that it required you to think like a computer. The strangeness of it was in some sense more vivid in the early days of computing, when code took the form of literal ones and zeros. Anyone looking over a programmer’s shoulder as they pored over line after line like “100001010011” and “000010011110” would have seen just how alienated the programmer was from the actual problems they were trying to solve; it would have been impossible to tell whether they were trying to calculate artillery trajectories or simulate a game of tic-tac-toe. The introduction of programming languages like Fortran and C, which resemble English, and tools, known as “integrated development environments,” or IDEs, that help correct simple mistakes (like Microsoft Word’s grammar checker but for code), obscured, though did little to actually change, this basic alienation—the fact that the programmer didn’t work on a problem directly, but rather spent their days writing out instructions for a machine.

“The problem is that software engineers don’t understand the problem they’re trying to solve, and don’t care to,” says Leveson, the MIT software-safety expert. The reason is that they’re too wrapped up in getting their code to work. “Software engineers like to provide all kinds of tools and stuff for coding errors,” she says, referring to IDEs. “The serious problems that have happened with software have to do with requirements, not coding errors.” When you’re writing code that controls a car’s throttle, for instance, what’s important is the rules about when and how and by how much to open it. But these systems have become so complicated that hardly anyone can keep them straight in their head. “There’s 100 million lines of code in cars now,” Leveson says. “You just cannot anticipate all these things.”

In September 2007, Jean Bookout was driving on the highway with her best friend in a Toyota Camry when the accelerator seemed to get stuck. When she took her foot off the pedal, the car didn’t slow down. She tried the brakes but they seemed to have lost their power. As she swerved toward an off-ramp going 50 miles per hour, she pulled the emergency brake. The car left a skid mark 150 feet long before running into an embankment by the side of the road. The passenger was killed. Bookout woke up in a hospital a month later.

The incident was one of many in a nearly decade-long investigation into claims of so-called unintended acceleration in Toyota cars. Toyota blamed the incidents on poorly designed floor mats, “sticky” pedals, and driver error, but outsiders suspected that faulty software might be responsible. The National Highway Traffic Safety Administration enlisted software experts from NASA to perform an intensive review of Toyota’s code. After nearly 10 months, the NASA team hadn’t found evidence that software was the cause—but said they couldn’t prove it wasn’t.

It was during litigation of the Bookout accident that someone finally found a convincing connection. Michael Barr, an expert witness for the plaintiff, had a team of software experts spend 18 months with the Toyota code, picking up where NASA left off. Barr described what they found as “spaghetti code,” programmer lingo for software that has become a tangled mess. Code turns to spaghetti when it accretes over many years, with feature after feature piling on top of, and being woven around, what’s already there; eventually the code becomes impossible to follow, let alone to test exhaustively for flaws.

Using the same model as the Camry involved in the accident, Barr’s team demonstrated that there were more than 10 million ways for key tasks on the onboard computer to fail, potentially leading to unintended acceleration.* They showed that as little as a single bit flip—a one in the computer’s memory becoming a zero or vice versa—could make a car run out of control. The fail-safe code that Toyota had put in place wasn’t enough to stop it. “You have software watching the software,” Barr testified. “If the software malfunctions and the same program or same app that is crashed is supposed to save the day, it can’t save the day because it is not working.”

Barr’s testimony made the case for the plaintiff, resulting in $3 million in damages for Bookout and her friend’s family. According to The New York Times, it was the first of many similar cases against Toyota to bring to trial problems with the electronic throttle-control system, and the first time Toyota was found responsible by a jury for an accident involving unintended acceleration. The parties decided to settle the case before punitive damages could be awarded. In all, Toyota recalled more than 9 million cars, and paid nearly $3 billion in settlements and fines related to unintended acceleration.

There will be more bad days for software. It's important that we get better at making it, because if we don't, and as software becomes more sophisticated and connected—as it takes control of more critical functions—those days could get worse.

The problem is that programmers are having a hard time keeping up with their own creations. Since the 1980s, the way programmers work and the tools they use have changed remarkably little. There is a small but growing chorus that worries the status quo is unsustainable. “Even very good programmers are struggling to make sense of the systems that they are working with,” says Chris Granger, a software developer who worked as a lead at Microsoft on Visual Studio, an IDE that costs $1,199 a year and is used by nearly a third of all professional programmers. He told me that while he was at Microsoft, he arranged an end-to-end study of Visual Studio, the only one that had ever been done. For a month and a half, he watched behind a one-way mirror as people wrote code. “How do they use tools? How do they think?” he said. “How do they sit at the computer, do they touch the mouse, do they not touch the mouse? All these things that we have dogma around that we haven’t actually tested empirically.”

The findings surprised him. “Visual Studio is one of the single largest pieces of software in the world,” he said. “It’s over 55 million lines of code. And one of the things that I found out in this study is more than 98 percent of it is completely irrelevant. All this work had been put into this thing, but it missed the fundamental problems that people faced. And the biggest one that I took away from it was that basically people are playing computer inside their head.” Programmers were like chess players trying to play with a blindfold on—so much of their mental energy is spent just trying to picture where the pieces are that there’s hardly any left over to think about the game itself.

John Resig had been noticing the same thing among his students. Resig is a celebrated programmer of JavaScript—software he wrote powers over half of all websites—and a tech lead at the online-education site Khan Academy. In early 2012, he had been struggling with the site’s computer-science curriculum. Why was it so hard to learn to program? The essential problem seemed to be that code was so abstract. Writing software was not like making a bridge out of popsicle sticks, where you could see the sticks and touch the glue. To “make” a program, you typed words. When you wanted to change the behavior of the program, be it a game, or a website, or a simulation of physics, what you actually changed was text. So the students who did well—in fact the only ones who survived at all—were those who could step through that text one instruction at a time in their head, thinking the way a computer would, trying to keep track of every intermediate calculation. Resig, like Granger, started to wonder if it had to be that way. Computers had doubled in power every 18 months for the last 40 years. Why hadn’t programming changed?

The fact that the two of them were thinking about the same problem in the same terms, at the same time, was not a coincidence. They had both just seen the same remarkable talk, given to a group of software-engineering students in a Montreal hotel by a computer researcher named Bret Victor. The talk, which went viral when it was posted online in February 2012, seemed to be making two bold claims. The first was that the way we make software is fundamentally broken. The second was that Victor knew how to fix it.

Bret Victor does not like to write code. “It sounds weird,” he says. “When I want to make a thing, especially when I want to create something in software, there’s this initial layer of disgust that I have to push through, where I’m not manipulating the thing that I want to make, I’m writing a bunch of text into a text editor.”

“There’s a pretty strong conviction that that’s the wrong way of doing things.”

Victor has the mien of David Foster Wallace, with a lightning intelligence that lingers beneath a patina of aw-shucks shyness. He is 40 years old, with traces of gray and a thin, undeliberate beard. His voice is gentle, mournful almost, but he wants to share what’s in his head, and when he gets on a roll he’ll seem to skip syllables, as though outrunning his own vocal machinery.

Though he runs a lab that studies the future of computing, he seems less interested in technology per se than in the minds of the people who use it. Like any good toolmaker, he has a way of looking at the world that is equal parts technical and humane. He graduated top of his class at the California Institute of Technology for electrical engineering, and then went on, after grad school at the University of California, Berkeley, to work at a company that develops music synthesizers. It was a problem perfectly matched to his dual personality: He could spend as much time thinking about the way a performer makes music with a keyboard—the way it becomes an extension of their hands—as he could thinking about the mathematics of digital signal processing.

By the time he gave the talk that made his name, the one that Resig and Granger saw in early 2012, Victor had finally landed upon the principle that seemed to thread through all of his work. (He actually called the talk “Inventing on Principle.”) The principle was this: “Creators need an immediate connection to what they’re creating.” The problem with programming was that it violated the principle. That’s why software systems were so hard to think about, and so rife with bugs: The programmer, staring at a page of text, was abstracted from whatever it was they were actually making.

“Our current conception of what a computer program is,” he said, is “derived straight from Fortran and ALGOL in the late ’50s. Those languages were designed for punch cards.” That code now takes the form of letters on a screen in a language like C or Java (derivatives of Fortran and ALGOL), instead of a stack of cards with holes in it, doesn’t make it any less dead, any less indirect.

There is an analogy to word processing. It used to be that all you could see in a program for writing documents was the text itself, and to change the layout or font or margins, you had to write special “control codes,” or commands that would tell the computer that, for instance, “this part of the text should be in italics.” The trouble was that you couldn’t see the effect of those codes until you printed the document. It was hard to predict what you were going to get. You had to imagine how the codes were going to be interpreted by the computer—that is, you had to play computer in your head.

Then WYSIWYG (pronounced “wizzywig”) came along. It stood for “What You See Is What You Get.” When you marked a passage as being in italics, the letters tilted right there on the screen. If you wanted to change the margin, you could drag a ruler at the top of the screen—and see the effect of that change. The document thereby came to feel like something real, something you could poke and prod at. Just by looking you could tell if you’d done something wrong. Control of a sophisticated system—the document’s layout and formatting engine—was made accessible to anyone who could click around on a page.

Victor’s point was that programming itself should be like that. For him, the idea that people were doing important work, like designing adaptive cruise-control systems or trying to understand cancer, by staring at a text editor, was appalling. And it was the proper job of programmers to ensure that someday they wouldn’t have to.

There was precedent enough to suggest that this wasn’t a crazy idea. Photoshop, for instance, puts powerful image-processing algorithms in the hands of people who might not even know what an algorithm is. It’s a complicated piece of software, but complicated in the way a good synth is complicated, with knobs and buttons and sliders that the user learns to play like an instrument. Squarespace, a company that is perhaps best known for advertising aggressively on podcasts, makes a tool that lets users build websites by pointing and clicking, instead of by writing code in HTML and CSS. It is powerful enough to do work that once would have been done by a professional web designer.

But those were just a handful of examples. The overwhelming reality was that when someone wanted to do something interesting with a computer, they had to write code. Victor, who is something of an idealist, saw this not so much as an opportunity but as a moral failing of programmers at large. His talk was a call to arms.

At the heart of it was a series of demos that tried to show just how primitive the available tools were for various problems—circuit design, computer animation, debugging algorithms—and what better ones might look like. His demos were virtuosic. The one that captured everyone’s imagination was, ironically enough, the one that on its face was the most trivial. It showed a split screen with a game that looked like Mario on one side and the code that controlled it on the other. As Victor changed the code, things in the game world changed: He decreased one number, the strength of gravity, and the Mario character floated; he increased another, the player’s speed, and Mario raced across the screen.

Suppose you wanted to design a level where Mario, jumping and bouncing off of a turtle, would just make it into a small passageway. Game programmers were used to solving this kind of problem in two stages: First, you stared at your code—the code controlling how high Mario jumped, how fast he ran, how bouncy the turtle’s back was—and made some changes to it in your text editor, using your imagination to predict what effect they’d have. Then, you’d replay the game to see what actually happened.

Shadow Marios move on the left half of a screen as a mouse drags sliders on the right half.
CUSEC / Vimeo

Victor wanted something more immediate. “If you have a process in time,” he said, referring to Mario’s path through the level, “and you want to see changes immediately, you have to map time to space.” He hit a button that showed not just where Mario was right now, but where he would be at every moment in the future: a curve of shadow Marios stretching off into the far distance. What’s more, this projected path was reactive: When Victor changed the game’s parameters, now controlled by a quick drag of the mouse, the path’s shape changed. It was like having a god’s-eye view of the game. The whole problem had been reduced to playing with different parameters, as if adjusting levels on a stereo receiver, until you got Mario to thread the needle. With the right interface, it was almost as if you weren’t working with code at all; you were manipulating the game’s behavior directly.

When the audience first saw this in action, they literally gasped. They knew they weren’t looking at a kid’s game, but rather the future of their industry. Most software involved behavior that unfolded, in complex ways, over time, and Victor had shown that if you were imaginative enough, you could develop ways to see that behavior and change it, as if playing with it in your hands. One programmer who saw the talk wrote later: “Suddenly all of my tools feel obsolete.”

When John Resig saw the “Inventing on Principle” talk, he scrapped his plans for the Khan Academy programming curriculum. He wanted the site’s programming exercises to work just like Victor’s demos. On the left-hand side you’d have the code, and on the right, the running program: a picture or game or simulation. If you changed the code, it’d instantly change the picture. “In an environment that is truly responsive,” Resig wrote about the approach, “you can completely change the model of how a student learns ... [They] can now immediately see the result and intuit how underlying systems inherently work without ever following an explicit explanation.” Khan Academy has become perhaps the largest computer-programming class in the world, with a million students, on average, actively using the program each month.

Chris Granger, who had worked at Microsoft on Visual Studio, was likewise inspired. Within days of seeing a video of Victor’s talk, in January of 2012, he built a prototype of a new programming environment. Its key capability was that it would give you instant feedback on your program’s behavior. You’d see what your system was doing right next to the code that controlled it. It was like taking off a blindfold. Granger called the project “Light Table.”

In April of 2012, he sought funding for Light Table on Kickstarter. In programming circles, it was a sensation. Within a month, the project raised more than $200,000. The ideas spread. The notion of liveness, of being able to see data flowing through your program instantly, made its way into flagship programming tools offered by Google and Apple. The default language for making new iPhone and Mac apps, called Swift, was developed by Apple from the ground up to support an environment, called Playgrounds, that was directly inspired by Light Table.

But seeing the impact that his talk ended up having, Bret Victor was disillusioned. “A lot of those things seemed like misinterpretations of what I was saying,” he said later. He knew something was wrong when people began to invite him to conferences to talk about programming tools. “Everyone thought I was interested in programming environments,” he said. Really he was interested in how people see and understand systems—as he puts it, in the “visual representation of dynamic behavior.” Although code had increasingly become the tool of choice for creating dynamic behavior, it remained one of the worst tools for understanding it. The point of “Inventing on Principle” was to show that you could mitigate that problem by making the connection between a system’s behavior and its code immediate.

In a pair of later talks, “Stop Drawing Dead Fish” and “Drawing Dynamic Visualizations,” Victor went one further. He demoed two programs he’d built—the first for animators, the second for scientists trying to visualize their data—each of which took a process that used to involve writing lots of custom code and reduced it to playing around in a WYSIWYG interface. Victor suggested that the same trick could be pulled for nearly every problem where code was being written today. “I’m not sure that programming has to exist at all,” he told me. “Or at least software developers.” In his mind, a software developer’s proper role was to create tools that removed the need for software developers. Only then would people with the most urgent computational problems be able to grasp those problems directly, without the intermediate muck of code.

Of course, to do that, you’d have to get programmers themselves on board. In a recent essay, Victor implored professional software developers to stop pouring their talent into tools for building apps like Snapchat and Uber. “The inconveniences of daily life are not the significant problems,” he wrote. Instead, they should focus on scientists and engineers—as he put it to me, “these people that are doing work that actually matters, and critically matters, and using really, really bad tools.” Exciting work of this sort, in particular a class of tools for “model-based design,” was already underway, he wrote, and had been for years, but most programmers knew nothing about it.

“If you really look hard at all the industrial goods that you’ve got out there, that you’re using, that companies are using, the only non-industrial stuff that you have inside this is the code.” Eric Bantégnie is the founder of Esterel Technologies (now owned by ANSYS), a French company that makes tools for building safety-critical software. Like Victor, Bantégnie doesn’t think engineers should develop large systems by typing millions of lines of code into an IDE. “Nobody would build a car by hand,” he says. “Code is still, in many places, handicraft. When you’re crafting manually 10,000 lines of code, that’s okay. But you have systems that have 30 million lines of code, like an Airbus, or 100 million lines of code, like your Tesla or high-end cars—that’s becoming very, very complicated.”

Bantégnie’s company is one of the pioneers in the industrial use of model-based design, in which you no longer write code directly. Instead, you create a kind of flowchart that describes the rules your program should follow (the “model”), and the computer generates code for you based on those rules. If you were making the control system for an elevator, for instance, one rule might be that when the door is open, and someone presses the button for the lobby, you should close the door and start moving the car. In a model-based design tool, you’d represent this rule with a small diagram, as though drawing the logic out on a whiteboard, made of boxes that represent different states—like “door open,” “moving,” and “door closed”—and lines that define how you can get from one state to the other. The diagrams make the system’s rules obvious: Just by looking, you can see that the only way to get the elevator moving is to close the door, or that the only way to get the door open is to stop.

It’s not quite Photoshop. The beauty of Photoshop, of course, is that the picture you’re manipulating on the screen is the final product. In model-based design, by contrast, the picture on your screen is more like a blueprint. Still, making software this way is qualitatively different than traditional programming. In traditional programming, your task is to take complex rules and translate them into code; most of your energy is spent doing the translating, rather than thinking about the rules themselves. In the model-based approach, all you have is the rules. So that’s what you spend your time thinking about. It’s a way of focusing less on the machine and more on the problem you’re trying to get it to solve.

“Typically the main problem with software coding—and I’m a coder myself,” Bantégnie says, “is not the skills of the coders. The people know how to code. The problem is what to code. Because most of the requirements are kind of natural language, ambiguous, and a requirement is never extremely precise, it’s often understood differently by the guy who’s supposed to code.”

On this view, software becomes unruly because the media for describing what software should do—conversations, prose descriptions, drawings on a sheet of paper—are too different from the media describing what software does do, namely, code itself. Too much is lost going from one to the other. The idea behind model-based design is to close the gap. The very same model is used both by system designers to express what they want and by the computer to automatically generate code.

Of course, for this approach to succeed, much of the work has to be done well before the project even begins. Someone first has to build a tool for developing models that are natural for people—that feel just like the notes and drawings they’d make on their own—while still being unambiguous enough for a computer to understand. They have to make a program that turns these models into real code. And finally they have to prove that the generated code will always do what it’s supposed to. “We have benefited from fortunately 20 years of initial background work,” Bantégnie says.

Esterel Technologies, which was acquired by ANSYS in 2012, grew out of research begun in the 1980s by the French nuclear and aerospace industries, who worried that as safety-critical code ballooned in complexity, it was getting harder and harder to keep it free of bugs. “I started in 1988,” says Emmanuel Ledinot, the Head of Scientific Studies for Dassault Aviation, a French manufacturer of fighter jets and business aircraft. “At the time, I was working on military avionics systems. And the people in charge of integrating the systems, and debugging them, had noticed that the number of bugs was increasing.” The 80s had seen a surge in the number of onboard computers on planes. Instead of a single flight computer, there were now dozens, each responsible for highly specialized tasks related to control, navigation, and communications. Coordinating these systems to fly the plane as data poured in from sensors and as pilots entered commands required a symphony of perfectly timed reactions. “The handling of these hundreds of and even thousands of possible events in the right order, at the right time,” Ledinot says, “was diagnosed as the main cause of the bug inflation.”

Ledinot decided that writing such convoluted code by hand was no longer sustainable. It was too hard to understand what it was doing, and almost impossible to verify that it would work correctly. He went looking for something new. “You must understand that to change tools is extremely expensive in a process like this,” he said in a talk. “You don’t take this type of decision unless your back is against the wall.”

He began collaborating with Gerard Berry, a computer scientist at INRIA, the French computing-research center, on a tool called Esterel—a portmanteau of the French for “real-time.” The idea behind Esterel was that while traditional programming languages might be good for describing simple procedures that happened in a predetermined order—like a recipe—if you tried to use them in systems where lots of events could happen at nearly any time, in nearly any order—like in the cockpit of a plane—you inevitably got a mess. And a mess in control software was dangerous. In a paper, Berry went as far as to predict that “low-level programming techniques will not remain acceptable for large safety-critical programs, since they make behavior understanding and analysis almost impracticable.”

Esterel was designed to make the computer handle this complexity for you. That was the promise of the model-based approach: Instead of writing normal programming code, you created a model of the system’s behavior—in this case, a model focused on how individual events should be handled, how to prioritize events, which events depended on which others, and so on. The model becomes the detailed blueprint that the computer would use to do the actual programming.

Ledinot and Berry worked for nearly 10 years to get Esterel to the point where it could be used in production. “It was in 2002 that we had the first operational software-modeling environment with automatic code generation,” Ledinot told me, “and the first embedded module in Rafale, the combat aircraft.” Today, the ANSYS SCADE product family (for “safety-critical application development environment”) is used to generate code by companies in the aerospace and defense industries, in nuclear power plants, transit systems, heavy industry, and medical devices. “My initial dream was to have SCADE-generated code in every plane in the world,” Bantégnie, the founder of Esterel Technologies, says, “and we’re not very far off from that objective.” Nearly all safety-critical code on the Airbus A380, including the system controlling the plane’s flight surfaces, was generated with ANSYS SCADE products.

Part of the draw for customers, especially in aviation, is that while it is possible to build highly reliable software by hand, it can be a Herculean effort. Ravi Shivappa, the VP of group software engineering at Meggitt PLC, an ANSYS customer which builds components for airplanes, like pneumatic fire detectors for engines, explains that traditional projects begin with a massive requirements document in English, which specifies everything the software should do. (A requirement might be something like, “When the pressure in this section rises above a threshold, open the safety valve, unless the manual-override switch is turned on.”) The problem with describing the requirements this way is that when you implement them in code, you have to painstakingly check that each one is satisfied. And when the customer changes the requirements, the code has to be changed, too, and tested extensively to make sure that nothing else was broken in the process.

The cost is compounded by exacting regulatory standards. The FAA is fanatical about software safety. The agency mandates that every requirement for a piece of safety-critical software be traceable to the lines of code that implement it, and vice versa. So every time a line of code changes, it must be retraced to the corresponding requirement in the design document, and you must be able to demonstrate that the code actually satisfies the requirement. The idea is that if something goes wrong, you’re able to figure out why; the practice brings order and accountability to large codebases. But, Shivappa says, “it’s a very labor-intensive process.” He estimates that before they used model-based design, on a two-year-long project only two to three months was spent writing code—the rest was spent working on the documentation.

As Bantégnie explains, the beauty of having a computer turn your requirements into code, rather than a human, is that you can be sure—in fact you can mathematically prove—that the generated code actually satisfies those requirements. Much of the benefit of the model-based approach comes from being able to add requirements on the fly while still ensuring that existing ones are met; with every change, the computer can verify that your program still works. You’re free to tweak your blueprint without fear of introducing new bugs. Your code is, in FAA parlance, “correct by construction.”

Still, most software, even in the safety-obsessed world of aviation, is made the old-fashioned way, with engineers writing their requirements in prose and programmers coding them up in a programming language like C. As Bret Victor made clear in his essay, model-based design is relatively unusual. “A lot of people in the FAA think code generation is magic, and hence call for greater scrutiny,” Shivappa told me.

Most programmers feel the same way. They like code. At least they understand it. Tools that write your code for you and verify its correctness using the mathematics of “finite-state machines” and “recurrent systems” sound esoteric and hard to use, if not just too good to be true.

It is a pattern that has played itself out before. Whenever programming has taken a step away from the writing of literal ones and zeros, the loudest objections have come from programmers. Margaret Hamilton, a celebrated software engineer on the Apollo missions—in fact the coiner of the phrase “software engineering”—told me that during her first year at the Draper lab at MIT, in 1964, she remembers a meeting where one faction was fighting the other about transitioning away from “some very low machine language,” as close to ones and zeros as you could get, to “assembly language.” “The people at the lowest level were fighting to keep it. And the arguments were so similar: ‘Well how do we know assembly language is going to do it right?’”

“Guys on one side, their faces got red, and they started screaming,” she said. She said she was “amazed how emotional they got.”

Emmanuel Ledinot, of Dassault Aviation, pointed out that when assembly language was itself phased out in favor of the programming languages still popular today, like C, it was the assembly programmers who were skeptical this time. No wonder, he said, that “people are not so easily transitioning to model-based software development: They perceive it as another opportunity to lose control, even more than they have already.”

The bias against model-based design, sometimes known as model-driven engineering, or MDE, is in fact so ingrained that according to a recent paper, “Some even argue that there is a stronger need to investigate people’s perception of MDE than to research new MDE technologies.”

Which sounds almost like a joke, but for proponents of the model-based approach, it’s an important point: We already know how to make complex software reliable, but in so many places, we’re choosing not to. Why?

In 2011, Chris Newcombe had been working at Amazon for almost seven years, and had risen to be a principal engineer. He had worked on some of the company’s most critical systems, including the retail-product catalog and the infrastructure that managed every Kindle device in the world. He was a leader on the highly prized Amazon Web Services team, which maintains cloud servers for some of the web’s biggest properties, like Netflix, Pinterest, and Reddit. Before Amazon, he’d helped build the backbone of Steam, the world’s largest online-gaming service. He is one of those engineers whose work quietly keeps the internet running. The products he’d worked on were considered massive successes. But all he could think about was that buried deep in the designs of those systems were disasters waiting to happen.

“Human intuition is poor at estimating the true probability of supposedly ‘extremely rare’ combinations of events in systems operating at a scale of millions of requests per second,” he wrote in a paper. “That human fallibility means that some of the more subtle, dangerous bugs turn out to be errors in design; the code faithfully implements the intended design, but the design fails to correctly handle a particular ‘rare’ scenario.”

Newcombe was convinced that the algorithms behind truly critical systems—systems storing a significant portion of the web’s data, for instance—ought to be not just good, but perfect. A single subtle bug could be catastrophic. But he knew how hard bugs were to find, especially as an algorithm grew more complex. You could do all the testing you wanted and you’d never find them all.

This is why he was so intrigued when, in the appendix of a paper he’d been reading, he came across a strange mixture of math and code—or what looked like code—that described an algorithm in something called “TLA+.” The surprising part was that this description was said to be mathematically precise: An algorithm written in TLA+ could in principle be proven correct. In practice, it allowed you to create a realistic model of your problem and test it not just thoroughly, but exhaustively. This was exactly what he’d been looking for: a language for writing perfect algorithms.

TLA+, which stands for “Temporal Logic of Actions,” is similar in spirit to model-based design: It’s a language for writing down the requirements—TLA+ calls them “specifications”—of computer programs. These specifications can then be completely verified by a computer. That is, before you write any code, you write a concise outline of your program’s logic, along with the constraints you need it to satisfy (say, if you were programming an ATM, a constraint might be that you can never withdraw the same money twice from your checking account). TLA+ then exhaustively checks that your logic does, in fact, satisfy those constraints. If not, it will show you exactly how they could be violated.

The language was invented by Leslie Lamport, a Turing Award–winning computer scientist. With a big white beard and scruffy white hair, and kind eyes behind large glasses, Lamport looks like he might be one of the friendlier professors at the American Hogwarts. Now at Microsoft Research, he is known as one of the pioneers of the theory of “distributed systems,” which describes any computer system made of multiple parts that communicate with each other. Lamport’s work laid the foundation for many of the systems that power the modern web.

For Lamport, a major reason today’s software is so full of bugs is that programmers jump straight into writing code. “Architects draw detailed plans before a brick is laid or a nail is hammered,” he wrote in an article. “But few programmers write even a rough sketch of what their programs will do before they start coding.” Programmers are drawn to the nitty-gritty of coding because code is what makes programs go; spending time on anything else can seem like a distraction. And there is a patient joy, a meditative kind of satisfaction, to be had from puzzling out the micro-mechanics of code. But code, Lamport argues, was never meant to be a medium for thought. “It really does constrain your ability to think when you’re thinking in terms of a programming language,” he says. Code makes you miss the forest for the trees: It draws your attention to the working of individual pieces, rather than to the bigger picture of how your program fits together, or what it’s supposed to do—and whether it actually does what you think. This is why Lamport created TLA+. As with model-based design, TLA+ draws your focus to the high-level structure of a system, its essential logic, rather than to the code that implements it.

Newcombe and his colleagues at Amazon would go on to use TLA+ to find subtle, critical bugs in major systems, including bugs in the core algorithms behind S3, regarded as perhaps the most reliable storage engine in the world. It is now used widely at the company. In the tiny universe of people who had ever used TLA+, their success was not so unusual. An intern at Microsoft used TLA+ to catch a bug that could have caused every Xbox in the world to crash after four hours of use. Engineers at the European Space Agency used it to rewrite, with 10 times less code, the operating system of a probe that was the first to ever land softly on a comet. Intel uses it regularly to verify its chips.

But TLA+ occupies just a small, far corner of the mainstream, if it can be said to take up any space there at all. Even to a seasoned engineer like Newcombe, the language read at first as bizarre and esoteric—a zoo of symbols. For Lamport, this is a failure of education. Though programming was born in mathematics, it has since largely been divorced from it. Most programmers aren’t very fluent in the kind of math—logic and set theory, mostly—that you need to work with TLA+. “Very few programmers—and including very few teachers of programming—understand the very basic concepts and how they’re applied in practice. And they seem to think that all they need is code,” Lamport says. “The idea that there’s some higher level than the code in which you need to be able to think precisely, and that mathematics actually allows you to think precisely about it, is just completely foreign. Because they never learned it.”

Lamport sees this failure to think mathematically about what they’re doing as the problem of modern software development in a nutshell: The stakes keep rising, but programmers aren’t stepping up—they haven’t developed the chops required to handle increasingly complex problems. “In the 15th century,” he said, “people used to build cathedrals without knowing calculus, and nowadays I don’t think you’d allow anyone to build a cathedral without knowing calculus. And I would hope that after some suitably long period of time, people won’t be allowed to write programs if they don’t understand these simple things.”

Newcombe isn’t so sure that it’s the programmer who is to blame. “I’ve heard from Leslie that he thinks programmers are afraid of math. I’ve found that programmers aren’t aware—or don’t believe—that math can help them handle complexity. Complexity is the biggest challenge for programmers.” The real problem in getting people to use TLA+, he said, was convincing them it wouldn’t be a waste of their time. Programmers, as a species, are relentlessly pragmatic. Tools like TLA+ reek of the ivory tower. When programmers encounter “formal methods” (so called because they involve mathematical, “formally” precise descriptions of programs), their deep-seated instinct is to recoil.

Most programmers who took computer science in college have briefly encountered formal methods. Usually they’re demonstrated on something trivial, like a program that counts up from zero; the student’s job is to mathematically prove that the program does, in fact, count up from zero.

“I needed to change people’s perceptions on what formal methods were,” Newcombe told me. Even Lamport himself didn’t seem to fully grasp this point: Formal methods had an image problem. And the way to fix it wasn’t to implore programmers to change—it was to change yourself. Newcombe realized that to bring tools like TLA+ to the programming mainstream, you had to start speaking their language.

For one thing, he said that when he was introducing colleagues at Amazon to TLA+ he would avoid telling them what it stood for, because he was afraid the name made it seem unnecessarily forbidding: “Temporal Logic of Actions” has exactly the kind of highfalutin ring to it that plays well in academia, but puts off most practicing programmers. He tried also not to use the terms “formal,” “verification,” or “proof,” which reminded programmers of tedious classroom exercises. Instead, he presented TLA+ as a new kind of “pseudocode,” a stepping-stone to real code that allowed you to exhaustively test your algorithms—and that got you thinking precisely early on in the design process. “Engineers think in terms of debugging rather than ‘verification,’” he wrote, so he titled his internal talk on the subject to fellow Amazon engineers “Debugging Designs.” Rather than bemoan the fact that programmers see the world in code, Newcombe embraced it. He knew he’d lose them otherwise. “I’ve had a bunch of people say, ‘Now I get it,’” Newcombe says.

He has since left Amazon for Oracle, where he’s been able to convince his new colleagues to give TLA+ a try. For him, using these tools is now a matter of responsibility. “We need to get better at this,” he said.

“I’m self-taught, been coding since I was nine, so my instincts were to start coding. That was my only—that was my way of thinking: You’d sketch something, try something, you’d organically evolve it.” In his view, this is what many programmers today still do. “They google, and they look on Stack Overflow” (a popular website where programmers answer each other’s technical questions) “and they get snippets of code to solve their tactical concern in this little function, and they glue it together, and iterate.”

“And that’s completely fine until you run smack into a real problem.”

In the summer of 2015, a pair of American security researchers, Charlie Miller and Chris Valasek, convinced that car manufacturers weren’t taking software flaws seriously enough, demonstrated that a 2014 Jeep Cherokee could be remotely controlled by hackers. They took advantage of the fact that the car’s entertainment system, which has a cellular connection (so that, for instance, you can start your car with your iPhone), was connected to more central systems, like the one that controls the windshield wipers, steering, acceleration, and brakes (so that, for instance, you can see guidelines on the rearview screen that respond as you turn the wheel). As proof of their attack, which they developed on nights and weekends, they hacked into Miller’s car while a journalist was driving it on the highway, and made it go haywire; the journalist, who knew what was coming, panicked when they cut the engines, forcing him to a slow crawl on a stretch of road with no shoulder to escape to.

Although they didn’t actually create one, they showed that it was possible to write a clever piece of software, a “vehicle worm,” that would use the onboard computer of a hacked Jeep Cherokee to scan for and hack others; had they wanted to, they could have had simultaneous access to a nationwide fleet of vulnerable cars and SUVs. (There were at least five Fiat Chrysler models affected, including the Jeep Cherokee.) One day they could have told them all to, say, suddenly veer left or cut the engines at high speed.

“We need to think about software differently,” Valasek told me. Car companies have long assembled their final product from parts made by hundreds of different suppliers. But where those parts were once purely mechanical, they now, as often as not, come with millions of lines of code. And while some of this code—for adaptive cruise control, for auto braking and lane assist—has indeed made cars safer (“The safety features on my Jeep have already saved me countless times,” says Miller), it has also created a level of complexity that is entirely new. And it has made possible a new kind of failure.

“There are lots of bugs in cars,” Gerard Berry, the French researcher behind Esterel, said in a talk. “It’s not like avionics—in avionics it’s taken very seriously. And it’s admitted that software is different from mechanics.” The automotive industry is perhaps among those that haven’t yet realized they are actually in the software business.

“We don’t in the automaker industry have a regulator for software safety that knows what it’s doing,” says Michael Barr, the software expert who testified in the Toyota case. NHTSA, he says, “has only limited software expertise. They’ve come at this from a mechanical history.” The same regulatory pressures that have made model-based design and code generation attractive to the aviation industry have been slower to come to car manufacturing. Emmanuel Ledinot, of Dassault Aviation, speculates that there might be economic reasons for the difference, too. Automakers simply can’t afford to increase the price of a component by even a few cents, since it is multiplied so many millionfold; the computers embedded in cars therefore have to be slimmed down to the bare minimum, with little room to run code that hasn’t been hand-tuned to be as lean as possible. “Introducing model-based software development was, I think, for the last decade, too costly for them.”

One suspects the incentives are changing. “I think the autonomous car might push them,” Ledinot told me—“ISO 26262 and the autonomous car might slowly push them to adopt this kind of approach on critical parts.” (ISO 26262 is a safety standard for cars published in 2011.) Barr said much the same thing: In the world of the self-driving car, software can’t be an afterthought. It can’t be built like today’s airline-reservation systems or 911 systems or stock-trading systems. Code will be put in charge of hundreds of millions of lives on the road and it has to work. That is no small task.

“Computing is fundamentally invisible,” Gerard Berry said in his talk. “When your tires are flat, you look at your tires, they are flat. When your software is broken, you look at your software, you see nothing.”

“So that’s a big problem.”


* This article originally stated that there were 10 million ways for the Toyota Camry to cause unintended acceleration. We regret the error.

About the Author

James Somers is a former contributing editor at The Atlantic.

The Lessons of ValuJet 592

estimated reading time: 57 min
Transaction

ON a muggy May afternoon in 1996 an emergency dispatcher in southern Florida got a call from a man on a cellular phone. The caller said, "Yes. I am fishing at Everglades Holiday Park, and a large jet aircraft has just crashed out here. Large. Like airliner-size."

The dispatcher said, "Wait a minute. Everglades Park?"

"Everglades Holiday Park, along canal L-sixty-seven. You need to get your choppers in the air. I'm a pilot. I have a GPS. I'll give you coordinates."

"Okay, sir. What kind of plane did you say? Is it a large plane?"

"A large aircraft similar to a seven-twenty-seven or a umm ... I can't think of it."

This lapse was unimportant. The caller was a born accident observer—a computer engineer and a private pilot with pride in his technical competence and a passion for detail. His name was Walton Little. When he first saw the airplane, it was banked steeply to the right and flying low, just above the swamp. Later he filed an official report, in which he stated,

There was no smoke, no strange engine noise, no debris in the air, no dangling materials or control surfaces, no apparent deformation of the airframe, and no areas that appeared to have missing panels or surfaces.... Sunlight was shining on the aircraft, and some surfaces were more reflective and some less reflective. I saw a difference in reflection of the wing skin in the area where I would expect the ailerons to be, as though they were not neutral. In particular, the lower (outboard) portion of the right wing appeared less reflective as though the aileron was deflected upward.

Nearby fishermen ducked into their boat for cover—but not Walton Little, who stood on his deck, facing "about 115 degrees," and watched the airplane hit the water. The shock wave passed through his body.

I was in disbelief that the crash had occurred. I stood there for just a moment to consider that it really did happen. I was already thinking that I needed to get my cellular phone out of the storage compartment and call 911, but I wanted to assure myself of what I was doing because it is against the law to make false calls to 911.

He called within a minute. After telling the dispatcher about the crash and reading off his latitude and longitude, he said, "I'm in a bass boat on the canal. I thought it was an aircraft from an air show or something, and..."

The dispatcher interrupted. "What did you ... Did you see flames and stuff come up, sir?"

"I heard the impact, and I saw dirt and mud fly in the air. The plane was sideways before it went out of my sight on the horizon about a mile from me."

"Yes, sir. Okay. You said it looked like a seven-twenty-seven that went down?"

"Uh, it's that type aircraft. It has twin engines in the rear. It is larger than an executive jet, like a Learjet."

"Yes, sir."

"It's much bigger than that. I won't tell you it's a seven-twenty-seven, but it's that type aircraft. No engines on the wing, two engines in the rear. I do not see any smoke, but I saw a tremendous cloud of mud and dirt go into the sky when it hit."

"Okay, sir."

"It was white with blue trim."

"White with blue trim, sir?"

"It will not be in one piece."

Walton Little was right. The airplane was a twin-engine DC-9 painted the colors of ValuJet, an aggressive young discount airline based in Atlanta. When it hit the Everglades, it was banked vertically to the right and pointed nearly straight down. The airplane did not sink mysteriously into the swamp, as reports later suggested, but shattered as it hit the surface with the furious force of a fast dive.

By the time Walton Little felt the shock wave, everyone aboard was dead—two pilots, three flight attendants, and 105 passengers. Their remains lay in a shallow, watery crater filled with liquid mud and grass. All that marked the surface was a fractured engine, a few dead fish, some jet fuel, and a scattering of personal papers, clothes, and twisted pieces of aluminum—the stuff of tragedy. During those first few days some officials worried aloud about the accident's effect on nature, but the swamp was not so fragile as that, and quickly resumed its usual life. The families of those who died have proved less resilient. Most will feel the poison forever.

For the rest of us, though, the accident should be finished business. The official investigation is over, a "cause" has been found, contributing factors have been acknowledged, and the Federal Aviation Administration has written new regulations. Editorialists have expressed their outrage, and individuals have been held responsible. After a long suspension ValuJet has returned to the air with a renewed commitment to safety. Other airlines, too, have promised to be more careful. And even the FAA has gone through a housecleaning. So by conventional standards the reaction to the tragedy has been admirable. And yes, we know anyway that flying is almost always safe. After years as a working pilot, I have a poetic idea of why: airplanes are fundamentally at home in the sky. Certainly my own experience is that Hopeless systemic complexitypassengers do not need to cower around the exit rows, or carry emergency "smoke hoods," or fear bad weather, or worry about some impending collapse of airline safety. Those are ideas promoted by aviation illiterates—overly cautious people who can always find an audience, and who would smother us in their fear of violent death. The public has the sense in the long run to ignore them. Nonetheless, the ValuJet accident continues to raise troubling questions—no longer about what happened but about why it happened, and what is to keep something similar from happening in the future. As these questions lead into the complicated and human core of flight safety, they become increasingly difficult to answer.

Consider, for simplicity, that there are three kinds of airplane accidents. The most common ones might be called "procedural." They are those old-fashioned accidents that result from single obvious mistakes, that can immediately be understood in simple terms, and that have simple resolutions. To avoid such accidents pilots must not fly into violent thunderstorms, or take off with ice on their wings, or descend prematurely, or let fear or boredom gain the upper hand. Mechanics, ramp agents, and air-traffic controllers must observe equally simple rules. As practitioners, we have together learned many painful lessons.

The second kind of accident could be called "engineered." It consists of those surprising materials failures that should have been predicted by designers or discovered by test pilots but were not. Such failures at first defy understanding, but ultimately they yield to examination and result in tangible solutions. An American Eagle ATR turboprop dives into a frozen field in Roselawn, Indiana, because its de-icing boots did not protect its wings from freezing rain—and as a result new boots are designed, and the entire testing process undergoes review. A USAir Boeing 737 crashes near Pittsburgh because of a rare hard-over rudder movement—and as a result a redesigned rudder-control mechanism will be installed on the whole fleet. A TWA Boeing 747 blows apart off New York because, whatever the source of ignition, its nearly empty center tank contained an explosive mixture of fuel and air—and as a result explosive mixtures may in the future be avoided. Such tragic failures seem all too familiar, but in fact they are rare, and they will grow rarer still as aeronautical engineering improves. One can regret the lives lost and deplore the slowness with which officials respond, but in the long run there is reason to be optimistic. The Wright brothers were products of the Enlightenment. Our science will prevail.

The ValuJet accident is different. I would argue that it represents the third and most elusive kind of disaster, a "system accident," which may lie beyond the reach of conventional solution, and which a small group of thinkers, inspired by the Yale sociologist Charles Perrow, has been exploring elsewhere—for example, in power generation, chemical manufacturing, nuclear-weapons control, and space flight. Perrow has coined the more loaded term "normal accident" for such disasters, because he believes that they are normal for our time. His point is that these accidents are science's illegitimate children, bastards born of the confusion that lies within the complex organizations with which we manage our dangerous technologies. Perrow is not an expert on commercial flying, but his thinking applies to it nonetheless. In this case the organization includes not only ValuJet, the archetype of new-style airlines, but also the contractors that serve it and the government entities that, despite economic deregulation, are expected to oversee it. Taken as a whole, the airline system is complex indeed.

Keep in mind that it is also competitive, and that if one of its purposes is to make money, the other is to move the public through thin air cheaply and at high speed. Safety is never first, and it never will be, but for obvious reasons it is a necessary part of the venture. Risk is a part too, but on the everyday level of practical compromises and Planessmall decisions—the building blocks of this ambitious enterprise—the view of risk is usually obscured. The people involved do not consciously trade safety for money or convenience, but they inevitably make a lot of bad little choices. They get away with those choices because, as Perrow says, Murphy's Law is wrong—what can go wrong usually goes right. But then one day a few of the bad little choices come together, and circumstances take an airplane down. Who, then, is really to blame?

We can find fault among those directly involved—and we probably need to. But if our purpose is to attack the roots of such an accident, we may find them so entwined with the system that they are impossible to extract without toppling the whole structure. In the case of ValuJet the study of system accidents presents us with the possibility that we have come to depend on flight, that unless we are willing to end our affordable airline system as we know it, we cannot stop the occasional sacrifice. Beyond the questions of blame, it requires us to consider that our solutions, by adding to the complexity and obscurity of the airline business, may actually increase the risk of accidents. System-accident thinking does not demand that we accept our fate without a struggle, but it serves as an important caution.

"Smoke in the Cockpit"

THE distinction among procedural, engineered, and system accidents is of course not absolute. Most accidents are a bit of each. And even in the most extreme cases of system failure the post-crash investigation must work its way forward conventionally, usefully identifying those problems that can be fixed, before the remaining questions begin to force a still-deeper examination. That was certainly the way with ValuJet Flight 592.

It was headed from Miami to Atlanta, flown by Captain Candalyn Kubeck, age thirty-five, and her copilot Richard Hazen, age fifty-two. They represented a new kind of commercial pilot, experienced not only in the cockpit but in the rough-and-tumble of the deregulated airline industry, where both had held a number of low-paid flying jobs before settling on ValuJet. It would have been no shock to them that ValuJet pilots were non-unionized, or that the company required them to pay for their own training. With 9,000 flight hours behind her, more than 2,000 of them in a DC-9, Kubeck earned what the free market said she was worth—about $43,000 a year, plus bonuses. Hazen, formerly in the Air Force and with similar experience, earned a bit more than half as much.

Pilots were not the only low-paid employees at ValuJet—flight attendants, ramp agents, and mechanics made a lot less there than they would have at a more traditional airline. So much work was farmed out to temporary employees and independent contractors that ValuJet was sometimes called a "virtual airline." FAA regulators had begun to worry that the company was moving too fast, and not keeping up with its paperwork, but there was no evidence that the people involved were inadequate. Many of the pilots were refugees from the labor wars at the old Eastern Airlines, and they were generally as competent and experienced as their higher-paid friends at United, American, and Delta. ValuJet was helping the entire industry to understand just how far cost-cutting could be pushed. Its flights were cheap and full, and its stock was strong on Wall Street.

But six minutes out of Miami, while climbing northwest through 11,000 feet, Richard Hazen radioed, "Ah, five-ninety-two needs an immediate return to Miami." In the deliberate calm of pilot talk this was strong language. The time was thirty-one seconds after 2:10 P.M., and the sun was shining. Something had gone wrong with the airplane.

The radar controller at Miami Departure answered immediately. Using ValuJet's radio name "Critter" (for the company's cartoonish logo—a smiling airplane), he gave the flight clearance to turn initially toward the west, away from Miami and conflicting traffic flows, and to begin a descent to the airport. "Critter five-ninety-two, ah roger, turn left heading two-seven-zero, descend and maintain seven thousand."

Hazen said, "Two-seven-zero, seven thousand, five-ninety-two."

The controller was Jesse Fisher, age thirty-six, a seven-year veteran, who had twice handled the successful return of an airliner that had lost cabin pressurization. He had worked the night before, and had gone home, fed his cat, and slept well. He felt alert and rested. He said, "What kind of problem are you having?"

Hazen said, "Ah, smoke in the cockpit. Smoke in the cabin." His tone was urgent.

Fisher kept his own tone flat. He said, "Roger." Over his shoulder he called, "I need a supervisor here!"

The supervisor plugged in beside him. On Fisher's radar screen Flight 592 appeared as a little oval and an associated group of numbers, including a readout of its altitude. Fisher noticed that the airplane had not yet started to turn. He gave the pilots another heading, farther to the left, and cleared them down to 5,000 feet.

Aboard the airplane Hazen acknowledged the new heading but misheard the altitude assignment. It didn't matter. Flight 592 was burning, and the situation in the cockpit was rapidly getting out of hand. One minute into the emergency the pilots were still tracking away from Miami, and had not begun their return. Hazen said, "Critter five-ninety-two, we need the, ah, closest airport available."

The transmission was garbled or blocked, or Fisher was distracted by competing voices within the radar room. For whatever reason, he did not hear Hazen's request. When investigators later asked him if in retrospect he would have done anything differently, he admitted that he kept asking himself the same question. Even without hearing Hazen's request he might have suggested some slightly closer airport. But given that the flight's position was only twenty-five miles to the northwest, Miami still seemed like the best choice, because of the emergency equipment there. In any case "Miami" was the request he had heard, and he intended to deliver it.

To Hazen he said, "Critter five-ninety-two, they're gonna be standing, standing by for you." He meant the crash crews at Miami. "You can plan Runway One-two. When able, direct to Dolphin now."

Hazen said, "... need radar vectors." His transmission was garbled by loud background noises. Fisher thought he sounded "shaky."

Fisher answered, "Critter five-ninety-two, turn left heading one-four-zero."

Hazen said, "One-four-zero." It was his last coherent response.

The flight had only now begun to move through a gradual left turn. Fisher watched the target on his screen as it tracked through the heading changes: the turn tightened and then slowed again. With each sweep of the radar beam the altitude readouts showed a gradual descent—8,800, 8,500, 8,100. Two minutes into the crisis Fisher said, "Critter five-ninety-two, keep the turn around, heading ah one-two-zero."

Flight 592 may have tried to respond—someone keyed a microphone without talking.

Fisher said, "Critter five-ninety-two, contact Miami Approach on—correction, no, you just keep on my frequency."

Two and a half minutes had gone by. It was 2:13 P.M. The airplane was passing through 7,500 feet when suddenly it tightened the left turn and entered a steep dive. Fisher's radar showed the turn and an altitude readout of XXX—code for such a rapid altitude change that the computer cannot keep up. Investigators later calculated that the airplane rolled to a sixty-degree left bank and dove 6,400 feet in thirty-two seconds. During that loss of control Fisher radioed mechanically, "Critter five-ninety-two, you can, ah, turn left, heading one-zero-zero, and join the Runway One-two localizer at Miami." He also radioed, "Critter five-ninety-two, descend and maintain three thousand."

Then the incredible happened. The airplane rolled wings-level again and pulled sharply out of its dive. It is highly unlikely that the airplane would have done this on its own. It is possible that the autopilot kicked in, or that one of the pilots, having been incapacitated by smoke or defeated by melting control cables, somehow momentarily regained control. Fisher watched the radar target straighten toward the southeast, and again read out a nearly level altitude—now, however, merely a thousand feet. The airplane's speed was almost 500 miles an hour.

The frequency crackled with another unintelligible transmission. Shocked into the realization that the airplane would be unable to make Miami, Fisher said, "Critter five-ninety-two, Opa-Locka Airport's about ah twelve o'clock at fifteen miles."

Walton Little, in his bass boat, spotted the airplane then, as it rolled steeply to the right. The radar, too, noticed that last quick turn toward the south, just before the final nose-over. On the next sweep of the radar the flight's data block went into "coast" on Fisher's screen, indicating that contact had been lost. The supervisor marked the spot electronically and launched rescue procedures.

Fisher continued to work the other airplanes in his sector. Five minutes after the impact another low-paid pilot, this one for American Eagle, radioed, "Ah, how did Critter make out?" Fisher didn't answer.

Hopeless systemic complexity
The Recovery Operation

IT was known from the start that fire took the airplane down. The federal investigation began within hours, with the arrival that evening of a National Transportation Safety Board team from Washington. The investigators set up shop in an airport hotel, which they began to refer to as the "command post." The language is important. As we will see, similar forms of linguistic stiffness, specifically engineerspeak, ultimately proved to have been involved in the downing of Flight 592—and this is a factor that the NTSB investigators, because of their own verbal awkwardness, have been unable quite to recognize.

It is not reasonable to blame them for this, though. The NTSB is a technical agency, staffed by technicians, which occupies a central position in the stilted world of aviation. Its job is to examine important accidents and to issue nonbinding safety recommendations—opinions, really—to industry and government. Because the investigators have no regulatory authority and must rely on persuasion to influence events, it may at times be necessary for them to use official-sounding language. Even among its opponents, who often feel that its recommendations are impractical, the NTSB has a reputation for technical competence. The NTSB is a piece of engineering done right. In a world built on compromise, it manages to play the old-fashioned, unambiguous role of the public's defender.

The press plays a more difficult role, though one equally important to the public's safety. It has a classically symbiotic relationship with the NTSB, relying on the investigators for information while providing them with their only effective voice. Nonetheless, in the time of crisis immediately after an accident, a tension exists between the two. Working under pressure to get the story out, reporters resent the caution of the investigators and their reluctance to speculate anonymously. Working under pressure to get the story right, investigators, for their part, resent the reporters' incessant demands during the difficult first days of an accident probe—the recovery of human remains and airplane parts. By the time I got to Miami, nineteen hours after Flight 592 hit the swamp, the two camps had assumed their habitual positions and were passing each other warily in the hotel lobby.

Twenty miles to the northwest, deep in the Everglades, the recovery operation was already under way. The NTSB had set up a staging area—a "forward ops base," one official called it—beside the Tamiami Trail, a two-lane highway that traverses the watery grasslands of southern Florida. Within two days this staging area blossomed into a chaotic encampment of excited officials—local, state, and federal—with their tents and air-conditioned trailers, their helicopters, their cars and flashing lights. I quit counting the agencies. The NTSB had politely excluded most of them from the actual accident site, which lay seven miles north, along a narrow levee road.

The press was excluded even from the staging area, but was provided with two news conferences a day, during which investigators cautiously doled out tidbits of information. One NTSB official said to me, "We've got to feed them or we'll lose control." But the reporters were well behaved, and if anything a bit overcivilized. Near the staging area they settled into their own little town of television trucks, tents, and lawn chairs. The location gave them good Everglades backdrops and shots of alligators swimming by; the viewing public could not have guessed that they stood so far from the action. They acted impatient, but in truth this was not a bad assignment; at its peak their little town boasted pay phones and pizza delivery.

Maybe it was because of my obvious lack of deadline that the investigators made an exception in my case. They slipped me into the front seat of a Florida Game and Fish helicopter whose pilot, in a fraternal gesture, invited me to take the controls for the run out to the crash site. From the staging area we skimmed north across the swamped grasslands, loosely following the levee road, before swinging wide to circle over the impact zone—a new pond defined by a ring of turned mud and surrounded by a larger area of grass and water and accident debris. Searchers in white protective suits waded side by side through the muck, piling pieces of people and airplane into flat-bottomed boats. It was hot and unpleasant work performed in a contained little hell, a place that one investigator later described to me as reeking of fuel, earth, and rotting flesh—the special smell of an airplane accident. We descended onto the levee, about 300 yards away from the crash site, where an American flag and a few tents and trucks constituted the recovery base.

The mood there was quiet and purposeful, with no sign among the workers of the emotional trauma that officials had been worriedly predicting since the operation began. The workers on break sat in the shade of an awning, sipping cold drinks and chatting. Endangered flyingThey were policemen and firemen, not heroes but straightforward guys accustomed to confronting death. Not knowing who I was, they spoke to me frankly about the gruesome details of their work, and made indelicate jokes, but they seemed more worried about dehydration than about "taking the job home" or losing sleep. I relaxed in their company, relieved to have escaped for a while the expectation of grief.

It was, of course, a somber place to be. Human remains lay bagged in a refrigerated truck for later transport to the morgue. A decontamination crew washed down torn and twisted pieces of airplane, none longer than several feet. Investigators tagged the most promising wreckage, to be trucked immediately to a hangar at an outlying Miami airport, where specialists could study it. Farther down the levee I came upon a soiled photograph of a young woman with a small-town face and a head of teased hair. A white-suited crew arrived on an airboat and clambered up the embankment to be washed down. Another crew set off. A boatload of muddy wreckage arrived. The next day the families of the dead came on buses, and laid flowers and cried. Pieces of the airplane kept being hauled up for nearly another month.

Much was made of this recovery, which—prior to the offshore retrieval of TWA's Flight 800—the NTSB called the most challenging in its history. It is true that the swamp made the search slow and difficult, and that the violence of the impact meant that meticulous work was required to reconstruct the critical forward cargo hold. However, it is also true that the physical part of the investigation served to confirm what a look at a shipping ticket had already suggested—that ValuJet Flight 592 burned and crashed not because the airplane failed but, in large part, because the airline did.

To me as a pilot, the most impressive aspect of the investigation was the speed with which it worked through the false pursuit of an electrical fire—an explanation supported by my own experiences in flight, and all the more plausible here because the ValuJet DC-9 was old and had experienced a variety of electrical failures earlier the same day, including a tripped circuit breaker that had resisted the attentions of a mechanic in Atlanta, and then mysteriously had fixed itself. I was impressed also by the instincts of the reporters, who for all their technical ignorance seized on the news that Flight 592 had been loaded with a potentially dangerous cargo of chemical oxygen generators—more than a hundred little firebombs that could have caused this accident, and that indeed did.

Flight 592 crashed on a Saturday afternoon. By Sunday the recovery teams were pulling up scorched and soot-stained pieces. On Monday a searcher happened to step on the flight-data recorder, one of two required black boxes meant to help with accident investigations. The NTSB took the recorder to its Washington laboratory and found that a blip in the flight data six minutes after Flight 592's takeoff seemed to indicate a momentary rise in air pressure. Immediately afterward the recorder began to fail intermittently, apparently because of electrical-power interruptions. On Tuesday night, at a press conference at the hotel, Robert Francis, the vice-chairman of the NTSB and the senior official on the scene, announced in a monotone, "There could have been an explosion." A hazardous-materials team would be joining the investigation. The investigation was focusing on the airplane's forward cargo hold, which was located just below and behind the cockpit, and was unequipped with fire detection and extinguishing systems. Routine paperwork indicated that the Miami ground crew had loaded the hold with homeward-bound ValuJet "company material," a witch's brew of three tires—at least two of them mounted—and five cardboard boxes of old oxygen generators.

Inferno in the Air

OXYGEN generators are safety devices. They are small steel canisters mounted in airplane ceilings and seatbacks and linked to the flimsy oxygen masks that dangle in front of passengers when a cabin loses pressurization. To activate oxygen flow the passenger pulls a lanyard, which slides a retaining pin from a spring-loaded hammer, which falls on a minute explosive charge, which sparks a chemical reaction that liberates the oxygen within the sodium-chlorate core. This reaction produces heat, which may cause the surface temperature of the canister to rise to 500° Fahrenheit if the canister is mounted correctly in a ventilated bracket, and much higher if it is sealed in a box with other canisters, which may themselves be heating up. If there is a good source of fuel nearby, such as tires and cardboard boxes, the presence of pure oxygen will cause the canisters to burn ferociously. Was there an explosion on Flight 592? Perhaps. But in any event the airplane was blowtorched into the ground.

It is ironic that the airplane's own emergency-oxygen system was different—a set of simple oxygen tanks, similar to those used in hospitals, that do not emit heat during use. The oxygen generators in Flight 592's forward cargo hold came from three MD-80s, a more modern kind of twin jet, which ValuJet had recently bought and was having refurbished at a hangar across the airport in Miami. As was its practice for most maintenance, ValuJet had hired an outside company to do the job—in this case a large firm called SabreTech, owned by Sabreliner, of St. Louis, and licensed by the FAA to perform the often critical work. SabreTech, in turn, hired contract mechanics from other companies on an as-needed basis. It later turned out that three fourths of the people on the project were just such temporary outsiders. The vulnerability of American wageworkers could be sensed in their testimony after the accident. They inhabited a world of boss men and sudden firings, with few protections or guarantees for the future. As the ValuJet deadline approached, they worked in shifts, day and night, and sometimes through the weekend as well. It was their contribution to our cheap flying.

We will never know everyone at fault in this story. ValuJet gave the order to replace oxygen generators on the MD-80s, most of which had come to the end of their licensed lifetimes. It provided SabreTech with explicit removal procedures and general warnings about the dangers of fire. Over several weeks SabreTech workers extracted the generators and taped or cut off their lanyards before stacking most of them in five cardboard boxes that happened to be lying around the hangar. Apparently they believed that securing the lanyards would keep the generators from being fired inadvertently. What they did not do was place the required plastic safety caps over the firing pins—a precaution spelled out on the second line of ValuJet's written work order. The problem for SabreTech was that no one had such caps, or cared much about finding them. Ultimately the caps were forgotten or ignored. At the end of the job, in the rush to complete batches of paperwork on all three MD-80s, two mechanics routinely "pencil-whipped" the problem by signing off on the safety-cap line as well as on the others, certifying that the work had been done. SabreTech inspectors and supervisors signed off on the work too, apparently without giving the caps much thought.

The timing is not clear. For weeks the five boxes stood on a parts rack beside the airplanes. Eventually mechanics lugged them over to SabreTech's shipping-and-receiving department, where they sat on the floor in the area designated for ValuJet property. A few days before the accident a SabreTech manager told the shipping clerk to clean up the area and get all the boxes off the floor in preparation for an upcoming inspection by Continental Airlines, a potential customer. The boxes were unmarked, and the manager did not care what was in them.

The shipping clerk then did what shipping clerks do, and prepared to send the oxygen generators home to ValuJet headquarters, in Atlanta. He redistributed them equally among the five boxes, laying the canisters horizontally end to end, and packing bubble wrap on top. After sealing the boxes he applied address labels and ValuJet company-material stickers, and wrote "aircraft parts." As part of the load he included two large main tires and a smaller nose tire—at least two of which were mounted on wheels. The next day he asked a co-worker, the receiving clerk, to make out a shipping ticket, and to write "oxygen canisters—empty" on it. The receiving clerk wrote "Oxy Canisters" and then put "Empty" between quotation marks, as if he did not believe it. He also listed the tires.

The cargo stood for another day or two, until May 11, when the SabreTech driver had time to deliver the boxes across the airport to Flight 592. There the ValuJet ramp agent accepted the material, though federal regulations forbade him to, even if the generators were empty, since canisters that have been discharged contain a toxic residue, and ValuJet was not licensed to carry any such officially designated hazardous materials. He discussed the cargo's weight with the copilot, Richard Hazen, who also should have known better. Together they decided to place the load in the forward hold, where ValuJet workers laid one of the big main tires flat, placed the nose tire at the center of it, and stacked the five boxes on top of it around the outer edge, in a loose ring. They leaned the other main tire against a bulkhead. It was an unstable arrangement. No one knows exactly what happened then, but it seems likely that the first oxygen generator ignited during the loading or during taxiing or on takeoff, as the airplane climbed skyward.

Two weeks later and halfway through the recovery of the scorched and shattered parts a worker finally found the airplane's cockpit voice recorder, the second black box sought by the investigators. It had recorded normal sounds and conversation up to the moment—six minutes after takeoff—when the flight-data recorder indicated a pulse of high pressure. The pulse may have been one of the tires exploding. In the cockpit it sounded like a chirp and a simultaneous beep on the public-address system. The captain, Candalyn Kubeck, asked, "What was that?"

Hazen said, "I don't know."

They scanned the airplane's instruments and found sudden indications of electrical failure. It was not the cause but a symptom of the inferno in the hold—the wires and electrical panels were probably melting and burning along with other, more crucial parts of the airplane—but the pilots' first thought was that the airplane was merely up to its circuit-breaking tricks again. The recording here is garbled. Kubeck seems to have asked, "About to lose a bus?" Then, more clearly, she said, "We've got some electrical problem."

Hazen said, "Yeah. That battery charger's kickin' in. Oooh, we gotta ..."

"We're losing everything," Kubeck said. "We need, we need to go back to Miami."

Twenty seconds had passed since the strange chirp in the cockpit. A total electrical failure, though serious, was not in those sunny conditions a life-threatening emergency. But suddenly there was incoherent shouting from the passenger cabin, and women and men screaming, "Fire!" The shouting continued for thirteen seconds and then subsided.

Kubeck said, "To Miami," and Hazen put in the call to Jesse Fisher, the air-traffic controller. When Fisher asked, "What kind of problem are you having?" Kubeck answered, off-radio, "Fire," and Hazen transmitted his urgent "Smoke in the cockpit. Smoke in the cabin."

Investigators now presume that the smoke was black and thick, and perhaps poisonous. The recorder picked up the sound of the cockpit door opening, and the voice of the chief flight attendant, who said, "Okay, we need oxygen. We can't get oxygen back there." Did she mean that the airplane's cabin masks had not dropped, or that they had dropped but were not working? If the smoke was poisonous, the masks might not have helped much, since by design they mix cabin air into the oxygen flow. The pilots were equipped with better, isolating-type masks and with goggles, but may not have had time to put them on. Only a minute had passed since the first strange chirp. Now the voice recorder captured the sound of renewed shouting from the cabin. In the cockpit the flight attendant said, "Completely on fire."

The recording was of little use to the NTSB's technical investigation, but because it showed that the passengers had died in agony, it added emotional weight to a political reaction that was already spreading beyond the details of the accident and that had begun to call the entire airline industry into question. The public, it seemed, would not be placated this time by standard reassurances and the discovery of a culprit or two. The press and the NTSB had put aside their on-site antagonism and had joined forces in a natural coalition with Congress. The questioning was motivated not by an immediate fear of unsafe skies (despite the warnings of Mary Schiavo, a federal whistle-blower who claimed special insight) but rather by a more nuanced suspicion that competition in the open sky had gone too far, and that the FAA, the agency charged with protecting the flying public, had fallen into the hands of industry insiders.

Fire
The Hunt for Blame

THE FAA's administrator then was a onetime airline boss named David Hinson—the sort of glib and self-assured executive who does well in closed circles of like-minded men. Now, however, he would have to address a diverse and skeptical audience. The day after the ValuJet accident he had flown to Miami and made the incredible assertion that ValuJet was a safe airline—when for 110 people lying dead in a nearby swamp it very obviously was not. He also said, "I would fly on it," as if he believed that he had to reassure a nation of children. It was an insulting performance, and it was taken as evidence of the FAA's isolation and of its betrayal of the public's trust.

After a good night's sleep Hinson might have tried to repair the damage. Instead he appeared two days later at a Senate hearing in Washington sounding like an unrepentant Prussian: "We have a very professional, highly dedicated, organized, and efficient inspector work force that do their job day in and day out. And when we say an airline is safe to fly, it is safe to fly. There is no gray area."

His colleagues must have winced. Aviation safety is nothing but a gray area, and the regulation of it is an indirect process of negotiation and maneuver. Consider the size of the airline business, the scale of the sky, and the loneliness of an airplane in flight. The FAA can affect safety by establishing standards and enforcing them through inspections and paperwork, but it cannot throw the switches or turn the wrenches, or in this case supervise the disposal of old oxygen generators. Safety is ultimately in the hands of the operators, the mechanics and pilots and their managers, because it involves a blizzard of small judgments. Hinson might have admitted this reality to the American public, which is certainly capable of understanding such subtleties, but instead, inexplicably, he chose to link the FAA's reputation to that of ValuJet. This placed the agency in an impossible position. Whether for incompetence or for cronyism, the FAA would now inevitably be blamed.

Within days it came out that certain inspectors at the FAA had been worried about ValuJet for some time and had described their concerns in their reports. Their consensus was that the airline was expanding too fast (from two to fifty-two airplanes over its two-and-a-half-year life) and that it had neither the procedures nor the people in place to maintain standards of safety. The FAA tried to keep pace, but because of its other commitments—including countering the threat of terrorism—it could assign only three inspectors to the airline. At the time of the accident they had run 1,471 routine checks on the operation and made two additional eleven-day inspections, in 1994 and 1995. This level of scrutiny was about normal. But by early 1996 concern had grown within the FAA about the disproportionate number of infractions committed by ValuJet and the string of small bang-ups it had had. The agency began to move more aggressively. An aircraft-maintenance group found such serious problems in both the FAA's surveillance and the airline's operations that it wrote an internal report recommending that ValuJet be "recertified" immediately—meaning that it be grounded and started all over again. The report was apparently sent to Washington, where for reasons that remain unexplained it lay buried until after the accident. Meanwhile, on February 22, 1996, headquarters launched a 120-day "special emphasis" inspection, a preliminary report on which was issued after the first week. This suggested a wide range of problems. The special-emphasis inspection was ongoing when, on May 11, Flight 592 went down.

As this record of official concern emerged, the question changed from why Hinson had insisted on calling ValuJet "safe" after the accident to why he had not shut down the airline before the accident. Trapped by his own simplistic formulations, he could provide no convincing answer. The press and Congress were sharply critical. The FAA launched an exhaustive thirty-day review of ValuJet, perhaps the most concentrated airline inspection in history, assigning sixty inspectors to perform in one month the equivalent of four years' work. Lewis Jordan, a founder and the president of ValuJet, complained that Hinson was, in effect, conducting a witch hunt that no airline could withstand. Jordan had been trying shamelessly to shift the blame for the deaths onto his own contractor, SabreTech, and he received little sympathy now. No one was surprised when ValuJet was grounded indefinitely five weeks after the accident.

Here now was proof that the FAA had earlier neglected its duties. The agency's chief regulator, Anthony Broderick, was the first to lose his job. Broderick was an expert technocrat, disliked by safety crusaders because of his conservative approach to instituting and applying regulations, and respected by aviation insiders for the same reason. Hinson let him take the fall: Broderick was a man of integrity and would accept responsibility for the FAA's poor performance. But if Hinson thought that he himself could escape with this sacrifice, he was wrong. Broderick's airline friends now joined the critics in disgust. Hinson announced his upcoming resignation.

In a sense, the system worked. The tragedy did have some positive consequences—primarily because the NTSB did an even better job than usual, not only pinpointing the source and history of the fire but also recognizing some of its larger implications. With a well-timed series of press feedings and public hearings the accident team kept the difficult organizational issues alive and managed to stretch the soul-searching through the end of the year and beyond. By shaking up the FAA, the team reminded the agency of its mandate to oversee the safety of the airlines—perhaps prodding the FAA into a renewed commitment to inspections and a resolution to hold airlines responsible for their actions and for the performance of outside shops.

For the airlines, the investigation served as a necessary reminder of the possible consequences of cost-cutting and complacency. Among airline executives smart enough to notice, it may also have served as a warning about the public's growing distrust of their motives and about widespread anger with the whole industry—anger that may have as much to do with the way passengers are handled as with their fears of dying. However one wants to read it, the ValuJet turmoil marked the limits of the public's tolerance. The airlines were cowed, and they submitted eagerly to the banning of oxygen generators as cargo on passenger flights. They then rushed ahead of the FAA with a $400 million promise (not yet fulfilled) to install fire detectors and extinguishers in all cargo holds. The desire to find hidden hazards runs up against the practical difficulties of inspecting cargo. Nonetheless, ground crews can be counted on for a while to watch what they load into airplanes and what they take out and throw away.

And the guilty companies? They lost money and were sued, of course. After firing the two mechanics who had falsely signed the work orders, SabreTech tried to put its house in order. Nonetheless, its customers fled and did not return. The Miami operation shrank from 650 to 135 employees, and in January of last year was forced to close its doors. Soon afterward, as the result of a two-month FAA investigation, SabreTech's new Orlando facility was forced to close as well. ValuJet survived its grounding, and under intense FAA scrutiny returned to the sky later in 1996, with a reduced and standardized fleet of DC-9s; it ultimately changed its name to AirTran. For a while it was probably the safest airline in the country. What, then, explains the feeling, particular to this case, that so little has in reality been achieved?

A "Normal Accident"

PILOTS are safety practitioners, steeped in a can-do attitude toward survival and confident in their own skills. We tend to think that man-made accidents must lie within human control. This idea has been encouraged to some extent by the work of a group of Berkeley professors—notably the political scientist Todd La Porte—who study "high-reliability organizations," meaning those with good track records at handling apparently hazardous technologies: aircraft carriers, air-traffic-control centers, Flyingcertain power companies. They believe that organizations can learn from past mistakes and can tailor themselves to achieve new objectives, and that if the right, albeit difficult, steps are taken, many accidents can be avoided.

Charles Perrow's thinking is more difficult for pilots like me to accept. Perrow came unintentionally to his theory about normal accidents after studying the failings of large organizations. His point is not that some technologies are riskier than others, which is obvious, but that the control and operation of some of the riskiest technologies require organizations so complex that serious failures are virtually guaranteed to occur. Those failures will occasionally combine in unforeseeable ways, and if they induce further failures in an operating environment of tightly interrelated processes, the failures will spin out of control, defeating all interventions. The resulting accidents are inevitable, Perrow asserts, because they emerge from the venture itself. You cannot eliminate one without killing the other.

Perrow's seminal book Normal Accidents: Living With High-Risk Technologies (1984) is an unusual work—a hodgepodge of storytelling and exhortation, out of which this new way of thinking has risen. His central device is an organizational chart on which to plot the likelihood of serious system accidents. He does not append numerical values to the chart but uses a set of general risk indicators. In one quadrant stand the processes—like those of most manufacturing—that are simple, slow, linear, and visible, and in which the operators experience failures as isolated and containable events. In the opposite one stand the opaque and tangled processes characterized by a combination of what Perrow calls "interactive complexity" and "tight coupling." By "interactive complexity" he means not simply that there are many elements involved but that those elements are linked in multiple and often unpredictable ways. The failure of one part—whether material, psychological, or organizational—may coincide with the failure of an entirely different part, and this unforeseeable combination will cause the failure of other parts, and so on. If the system is large, the possible combinations of failures are practically infinite. Such unravelings seem to have an intelligence of their own: they expose hidden connections, neutralize redundancies, bypass "firewalls," and exploit chance circumstances that no engineer could have planned for. When the operating system is inherently quick and inflexible (like a chemical process, an automated response to missile attack, or a jet airliner in flight), the cascading failures can accelerate out of control, confounding the human operators and denying them a chance to jury-rig a recovery. That lack of slack is Perrow's tight coupling. Then the only difference between a harmless accident and a human tragedy may be a question, as in chemical plants, of which way the wind blows.

I ran across this thinking by chance, a year before the ValuJet crash, when I picked up a copy of Scott D. Sagan's book The Limits of Safety: Organizations, Accidents, and Nuclear Weapons (1993). Sagan, a Stanford political scientist who is a generation younger than Perrow, is the most persuasive of Perrow's interpreters, and with The Limits of Safety he has solidified system-accident thinking, focusing it more clearly than Perrow was able to. The Limits of Safety starts by placing high-reliability and normal-accident theories in opposition and then tests them against a laboriously researched and previously secret history of failures within U.S. nuclear-weapons programs. The test is a transparent artifice, but it serves to define the two theories. Sagan's obvious bias does not diminish his work.

Strategic nuclear weapons pose an especially difficult problem for system-accident thinking, for two reasons: first, there has never been an accidental nuclear detonation, let alone an accidental nuclear war; and second, if a real possibility of such an apocalyptic failure exists, it threatens the very logic of nuclear deterrence—the expectation of rational behavior on which we continue to base our arsenals. Once again the pursuit of system accidents leads to uncomfortable ends. Sagan is not a man to advocate disarmament, and he shies away from doing so in his book, observing realistically that nuclear weapons are here to stay. Nonetheless, once he has defined "accidents" as less than nuclear explosions (as false warnings, near launches, and other unanticipated breakdowns in this ultimate "high-reliability" system), Sagan discovers a pattern of accidents, some of which were contained only by chance. The reader is hardly surprised when Sagan concludes that such accidents are inevitable.

The book interested me not because of the accidents themselves but because of their pattern, which seemed strangely familiar. Though the pattern represented possibilities that I as a pilot had categorically rejected, this new perspective required me to face the unpredictable side of my own experience with the sky. I had to admit that some of my friends had died in crazy and unlucky ways, that some flights had gone uncontrollably wrong, and that perhaps not even the pilots were to blame. What is more, I had to admit that no matter how carefully I checked my own airplanes, and how cautiously I flew them, the same could happen to me.

That is where we stand now as a society with ValuJet Flight 592, and it may explain our continuing discomfort with the accident. The ValuJet case represents a nearly perfect system accident. It arose from a process that fits most of Perrow's technical requirements of unpredictability and interactive complexity and some of those of tight coupling. More important, it fits the most basic definitions of an accident caused by the very functioning of the system or industry within which it occurred. Flight 592 burned because of its cargo of oxygen generators, yes, but more fundamentally because of a tangle of confusions that will take some entirely different form next time. It is frustrating to fight such a thing, and wrongdoing is difficult to assign.

ValuJet's Pretend Reality

TAKE, for example, the case of the two SabreTech mechanics who helped to remove the oxygen canisters from the ValuJet MD-80s, ignored the written work orders to install safety caps, stacked the dangerous canisters improperly in cardboard boxes, and finished by falsely signing off on the job. They will probably suffer for the rest of their lives for their negligence, as perhaps they should. But here is what really happened: Nearly 600 people logged time working on the three ValuJet airplanes in SabreTech's Miami hangar, and of them seventy-two logged 910 hours over several weeks for replacing oxygen generators, in most cases because they had "expired"—reached the end of their approved lives. According to ValuJet work card No. 0069, which was supplied to investigators, the second step of the seven-step removal process was If generator has not been expended, install shipping cap on firing pin.

This required a gang of hard-pressed mechanics to draw a verbal distinction between canisters that were "expired," meaning most of the ones they were removing, and canisters that were not "expended," meaning many of the same ones, loaded and ready to fire, on which they were expected to put nonexistent caps. Also involved were canisters that were expired and expended, and others that were not expired but were expended. And then, of course, there was the set of new replacement canisters, which were both unexpended and unexpired. If this seems confusing, do not waste your time trying to figure it out—the SabreTech mechanics did not, nor should they have been expected to. The NTSB suggested that one problem at SabreTech's Miami facility may have been the presence of Spanish-speaking immigrants on the work force, but quite obviously the language problem lay on the other side—with ValuJet and the English-speaking engineers, literalists, who wrote the orders and technical manuals as if they were writing to themselves. The real problem, in other words, was engineerspeak.

Before the accident the worry was not about old parts but about new ones—the safe refurbishing of the MD-80s in time to meet the ValuJet deadline. The mechanics quickly removed the oxygen canisters from their brackets and wired green tags to most of them. The green tags meant "repairable," which these canisters were not. It is not clear how many of the seventy-two workers were aware that these canisters couldn't be used again, since the replacement of oxygen generators is a rare operation, though of the people questioned after the accident most claimed to have known at least why the canisters had to be removed. But here, too, there is evidence of confusion. After the accident two tagged canisters were found still lying in the SabreTech hangar. On one of the tags, under "Reason for Removal," someone had written, "out of date." On the other tag someone had written, "generators have been expired fired."

Yes, a mechanic might have found his way past the ValuJet work card and into the huge MD-80 maintenance manual, to chapter 35-22-01, within which line "h" would have instructed him to "store or dispose of oxygen generator." By diligently pursuing his options, the mechanic could have found his way to a different part of the manual and learned that "all serviceable and unserviceable (unexpended) oxygen generators (canisters) are to be stored in an area that ensures that each unit is not exposed to high temperatures or possible damage." By pondering the implications of the parentheses he might have deduced that the "unexpended" canisters were also "unserviceable"canisters and that because he had no shipping cap, he should perhaps take such canisters to a safe area and "initiate" them, according to the procedures described in section 2.D. To initiate an oxygen generator is of course to fire it off, triggering the chemical reaction that produces oxygen and leaves a mildly toxic residue within the canister, which is then classified as hazardous waste. Section 2.D contains the admonition "An expended oxygen generator (canister) contains both barium oxide and asbestos fibers and must be disposed of in accordance with local regulatory compliances and using authorized procedures." No wonder the mechanics stuck the old generators in boxes.

The supervisors and inspectors failed miserably here, though after the accident they proved clever at ducking responsibility. At the least they should have supplied the required safety caps and verified that those caps were being used. If they had—despite all the other errors that were made—Flight 592 would not have burned. For larger reasons, too, their failure is an essential part of this story. It represents not the avarice of profit takers but rather something more insidious—the sort of collective relaxation of technical standards that the Boston College sociologist Diane Vaughan has called "the normalization of deviance," and that she believes existed at NASA in the years leading up to the 1986 explosion of the space shuttle Challenger. The leaking O-rings that caused the catastrophic blow-by of rocket fuel were a well-known design weakness, and had been the subject of worried memos and conferences up to the eve of the launch. Vaughan's book The Challenger Launch Decision (1996) is a 575-page exercise in system-accident thinking. After a long immersion in NASA's technical culture, Vaughan concludes that the O-ring worries were put aside in part because the agency had gotten away with launching the O-rings before. As Perrow has argued, what can go wrong usually goes right—and then people draw the wrong conclusions. In a general way this is what happened at SabreTech. Some mechanics now claim to have expressed their concerns about the safety caps, but if they did, they were not heard. The operation had grown used to taking shortcuts.

But let us be honest—mechanics who are too careful will never get the job done. The airline system as it stands today requires people, in flight or on the ground, to compromise, to make choices, and sometimes even to gamble. The SabreTech crews went astray—but not far astray—by allowing themselves quite naturally not to worry about discarded parts. A fire hazard? Sure. The mechanics taped off the lanyards and may have shoved the canisters a little farther away from the airplanes they were working on. The canisters had no warnings about heat on them and none of the standard hazardous-materials placards. It probably would not have mattered anyway, because the work area was crowded with placards and officially designated hazardous materials, and people had learned not to take them too seriously. Out of curiosity a few of the mechanics fired off some canisters and listened to the oxygen come out—it went pssst. No one seems to have considered the possibility that the canisters might accidentally be shipped. The mechanics did finally carry the five cardboard boxes over to the shipping department, but only because that was where ValuJet property was stored—an arrangement that itself made sense.

When the shipping clerk got to work the next morning, he found the boxes without explanation on the floor of the ValuJet area. The boxes were innocent-looking, and he left them alone until he was told to tidy up. Sending them to Atlanta seemed like the best way to do that. He had shipped off "company material" before without ValuJet's specific approval, and he had heard no complaints. He knew he was dealing with oxygen canisters, but apparently did not understand the difference between oxygen storage tanks and generators designed to fire off. When he prepared the boxes for shipping, he noticed the green "repairable" tags mistakenly placed on the canisters by the mechanics, and misunderstood them to signify "unserviceable" or "out of service," as he variably said after the accident. He also drew the unpredictable conclusion that the canisters were therefore empty. He asked the receiving clerk to fill out a shipping ticket. The receiving clerk did as he was asked, listing the tires and canisters, and put quotation marks around the word "Empty." Later, when asked why, he replied, "No reason. I always put like, when I put my check, I put 'Carlos' in quotations. No reason I put that." The reason was that it was his habit. On the shipping ticket he also put "5 boxes" between quotation marks.

But a day or so later, over by Flight 592, the ValuJet ramp agent who signed for the cargo didn't care about such subtleties. ValuJet was not authorized to carry hazardous cargoes of any sort, and it seems obvious now that a shipping ticket listing tires on wheel assemblies and oxygen canisters (whether or not they were empty) should have aroused the ramp agent's suspicions. No one would have complained had he opened the boxes, or summarily rejected the load. There was no hazardous-materials paperwork associated with it, but he had been formally trained in the recognition of unmarked hazards. His ValuJet station-operations manual specifically warned, "Cargo may be declared under a general description that may have hazards which are not apparent, that the shipper may not be aware of this. You must be conscious of the fact that these items have caused serious incidents, and in fact, endangered the safety of the aircraft and personnel involved." It also said,

Your responsibility in recognizing hazardous materials is dependent on your ability to: 1. Be Alert! 2. Take the time to ask questions! 3. Look for labels! ... Ramp agents should be alert whenever handling luggage or boxes. Any item that might be considered hazardous should be brought to the attention of your supervisor or pilot, and brought to the immediate attention of Flight Control and, if required, the FAA. REMEMBER: SAFETY OF PASSENGERS AND FELLOW EMPLOYEES DEPENDS ON YOU!

It is possible that the ramp agent was lulled by the company-material labels. Would the SabreTech workers ship hazardous cargo without letting him know? His conversation with the copilot, Richard Hazen, about the weight of the load may have lulled him as well. Hazen, too, had been formally trained to spot hazardous materials, and he would have understood better than the ramp agent the dangerous nature of oxygen canisters, but he said nothing. It was a routine moment in a routine day. The morning's pesky electrical problems had perhaps been resolved. The crew was calmly and rationally preparing the airplane for the next flight, a procedure that had always worked for them before. As a result the passengers' last line of defense folded. They were unlucky, and the system killed them.

Disaster
Giving Up on a Zero-Accident Future

WHAT are we to make of this tangle of circumstance and error? One suspicion is that its causes may lie in the market forces of a deregulated airline industry, and that in order to keep such catastrophes from happening in the future we might need to consider the possibility of re-regulation—a return to the old system of limited competition, union work forces, higher salaries, and expensive tickets. There are calls now for just that. The improvement in safety would come from slowing things down, and allowing a few anointed airlines the leisure to discover their mistakes and act on them. The effects on society, however, would be costly and anti-egalitarian—a return to a constricted system that many fewer people could afford to use. Moreover, technical trends would argue against it. Despite the obvious chaos of the business and the apparent frequency of airline accidents, air travel has become safer under deregulation. Reductions in "procedural" and "engineered" accidents have more than compensated for any increase in system accidents—which in any case must have occurred in the past as well.

The other way to regulate the airline industry is not economic but operational—detailed governmental oversight of all the technical aspects of flight. This is an approach we have taken since the birth of the airlines, in the 1920s, and it is what we expect of the FAA today. Strictly applied standards are all the more important in a free market, in which unchecked competition would eventually require airlines to cut costs to the point of operating unsafely, until accidents forced them out of business one by one. A company should not overload its airplanes or fly them with worn-out parts, but it also cannot compete effectively against other companies that do. Day to day, airline executives may resent the intrusion of government, but in their more reflective moments they must also realize that they need this regulation in order to survive. The friendship that has grown up between the two sides—between the regulators and the regulated—is an expression of this fact, which no amount of self-reform at the FAA can change. When after the ValuJet crash David Hinson, of the FAA, reacted to accusations of cronyism by going to Congress and humbly requesting that his agency's "dual mandate" be eliminated, so that it would no longer be required by law to promote the airlines, he and Congress (which did as he requested) were engaged in a particularly hollow form of political theater.

The FAA's critics had real points to make. The agency had become too worried about the reactions of its allies in the airline industry, and it needed to try harder to enforce existing regulations. Perhaps it needed even to write some new regulations. Like NASA before the Challenger accident, the FAAneeded to listen to the opinions and worries of its own lower-level employees. But there are limits to all this, too. When, at a post-crash press conference in Miami, a reporter asked Robert Francis, of the NTSB, "Shouldn't the government protect us against this kind of thing?" the best answer would have been "It cannot, and never will."

The truth helps, because in our frustration with such system accidents we may be tempted to invent solutions that, by adding to the obscurity and complexity of the system, may aggravate just those characteristics that led to the accidents in the first place. This argument for a theoretical point of diminishing safety is a central part of Perrow's thinking, and it seems to be borne out in practice. In his exploration of the North American early-warning system Sagan found that the failures of safety devices and backup systems gave the most dangerous false indications of missile attack—the kind that could have triggered a response. The radiation accidents at Chernobyl and Three Mile Island were both induced by failures in the safety systems. Remember also that the ValuJet oxygen generators were safety devices, that they were backup systems, and that they were removed from the MD-80s because of regulations limiting their useful lives. This is not an argument against such devices but a reminder that elaboration comes at a price.

Human reactions add to the problem. Administrators can think up impressive chains of command and control, and impose complex double checks and procedures on an operating system, and they can load the structure with redundancies, but on the receiving end there comes a point—in the privacy of a hangar or a cockpit—beyond which people rebel. These rebellions are now common throughout the airline business—and, indeed, throughout society. They result in unpredictable and arbitrary actions, all the more so because in the modern, insecure workplace they remain undeclared. The one thing that always gets done is the required paperwork.

Paperwork is a necessary and inevitable part of the system, but it, too, introduces dangers. The problem is not just the burden that it places on practical operations but also the deception that it breeds. The two unfortunate mechanics who signed off on the nonexistent safety caps just happened to be the slowest to slip away when the supervisors needed signatures. The other mechanics almost certainly would have signed too, as did the inspectors. Their good old-fashioned pencil-whipping is perhaps the most widespread form of Vaughan's "normalization of deviance." The falsification they committed was part of a larger deception—the creation of an entire pretend reality that includes unworkable chains of command, unlearnable training programs, unreadable manuals, and the fiction of regulations, checks, and controls. Such pretend realities extend even into the most self-consciously progressive large organizations, with their attempts to formalize informality, to deregulate the workplace, to share profits and responsibilities, to respect the integrity and initiative of the individual. The systems work in principle, and usually in practice as well, but the two may have little to do with each other. Paperwork floats free of the ground and obscures the murky workplaces where, in the confusion of real life, system accidents are born.

It would be wrong to conclude that we should join the alarmists in their prophesies of doom. Flying will remain safe, and for conventional reasons, including the admirable reaction we have seen to the ValuJet crash. But it should also be clear that there are structural limits to flight safety, and that any dream of a zero-accident future is probably about as realistic as the old ValuJet promise to put safety first. If that is true, we had better get used to it. Conventional accidents—those I call procedural or engineered—will submit to our solutions, but as air travel continues to expand, we can expect capricious system accidents to blossom. Understanding why might keep us from making the system even more complex, and therefore perhaps more dangerous, too.

About the Author

William Langewiesche, a former national correspondent for The Atlantic and a professional pilot, has written about subjects including aviation, national security, and North Africa.

The Three Best Bars for Martinis in London

When it comes to the best bars for martinis in London, you’re completely spoiled for choice. There are so many places I can order up my favorite classic and they’ll […]

The post The Three Best Bars for Martinis in London appeared first on Paris • Cocktails • Bars.

Two Ways to Enjoy Cocktails at Paris’ Historic Hotel Lutetia

Last time I wrote about drinking at Hotel Lutetia, it was for cocktails at their beautiful Bar Josephine not long after the extensive remodel. At the time, there was a […]

The post Two Ways to Enjoy Cocktails at Paris’ Historic Hotel Lutetia appeared first on Paris • Cocktails • Bars.

10 Things I Learned Losing 10 Million Dollars

3 July 2024 at 14:51
estimated reading time: 14 min

In January 2021, I was a crypto outsider day-trading a few thousand dollars of DOGE on my phone.

By January 2022, my crypto net-worth had ballooned to over $10 million dollars.

Then almost all of it disappeared.

If you want the full story, you should read Crypto Confidential. It takes you through exactly what happened in a fun fast-paced thriller of an adventure that you don’t need to know anything about crypto to enjoy.

Order Crypto Confidential!

But what I want to share today are some important lessons around money, happiness, and sanity that crystalized as I reflected on the events of the book.

When you hold an asset, whether it’s crypto, stock, real estate, gold, Pokemon cards, whatever, you can always check to see what that asset is worth.

You can look at your stock trading app to see what people are buying and selling the stock for, or you can troll eBay to see what a mint-condition Dark Charizard last sold for.

Based on that data, you can add up the value of all your assets and calculate what your net worth is.

But here’s the problem: your net worth is more or less imaginary based on how easily you can actually sell your assets at their supposed value.

The NFT market has been plagued by this problem ever since it crashed in 2022. At the peak of the market in 2022, the cheapest NFT in the “Gutter Cat Gang” collection was 8.5 ETH, about $27,000.

Now the cheapest is 0.25 ETH, about $850. Ouch.

But it gets worse. Imagine you were extremely bullish on Gutter Cats and you bought 100 of them when they were 0.07 ETH. Well then you’re still up 18 ETH, right?

Probably not. There are only 120 Gutter Cats currently for sale, and only 64 sold in the last month. So if you try to list all of yours for sale, a few things will happen:

  • If you list them all, you’d be doubling the supply of Cats for sale.

  • Doubling the supply would bring the value of the a Cat down significantly.

  • Then other people might see the market tanking and rush in to list their Cats, undercutting you and driving the price down further, which could lead to a death spiral in the price.

  • On top of all that, you might have to wait weeks or months for your Cats to sell.

And if you sold them off slowly to exit it over time and not tank the market, it might take months to fully exit your position for who knows how much along the way.

Even at the peak of the market, there were only 12 sales on the day it hit 8.5. So there’s no way you could have exited for 850 ETH,

But you’re not thinking about that when you see the number on your net worth spreadsheet. You’re thinking “I have almost 1,000 ETH!” But that number only exists in your mind.

The same mistake can happen in real estate, where you see houses around you selling for crazy numbers and start to believe your house is also worth that much. Plenty of people (including me) fell victim to this in 2022.

And it can happen in companies too, where the founder of a company thinks they’re actually worth what all their shares are worth on paper, not realizing how quickly their fortune can turn. That’s what happened to the Bird founder who leveraged his shares to buy a mansion in Miami, only to have to sell it for an $11 million dollar loss when the value of Bird collapsed.

If you’re holding a highly traded stock in your Robinhood account and you don’t have too much of it, that part of your net worth is almost 100% real. You could almost instantly convert your 100 shares of GME to $2,500 or whatever it’s worth when you read this.

But if you dabble in crypto gambling, buy speculative assets, start a company, do anything where there might be some degree of liquidity concerns, you have to remember your wealth is partially imaginary.

Obviously this becomes a big problem for me in the book. But I won’t spoil too much…

There’s a point in time during the story where I’m making tens of thousands of dollars a day. I’m not pulling it out into my bank account of course (because I’m an idiot) but I’m seeing that number in my crypto wallet.

So, what do I do? I convince myself that buying a Rolex Submariner is a perfectly reasonable thing to do. Watches hold value, it cost less than I was making a day, and I just wanted one. Besides, the money was never going to stop coming in. Right?

My watch guy (yes, I briefly had a watch guy, that’s how bad I got), texted me that he had one in, and I went out and bought it that day. I didn’t think twice about spending the ~$15,000 on it.

That absolutely was not me a year or two earlier. And if you had asked me the year before what I would do if I had seen that kind of money coming in, I would have told you that I’d be saving and investing all of it. Not buying watches and doubling down.

But once things started taking off, all I could think about was how much higher it was going to go. I didn’t feel like I was being indulgent by buying a watch or going to the Gucci store. It was a drop in the bucket compared to the paper net worth and how much money I was going to make. I still felt like I was being responsible. You gotta enjoy your money a little, right?

It’s almost impossible to imagine how much your psychology around money will change once you start seeing those kinds of numbers. And no matter how much of a minimalist, smart saver and investor you think you are, you might be surprised by how quickly your attitude can change.

One of the worst mistakes you can make in a mania is buying things for the long-term when everyone else is playing a short-term game.

The big, core assets like Bitcoin and Ethereum are definitely long-term plays. You can buy and hold them and not look at them and feel pretty good about them still being relevant in 10-20 years.

But if you try to take that approach with whatever new fad pops up during the mania, you’re going to be the one left holding the bag.

The “Diamond Hands” meme was one of the most harmful ideologies you could have adopted during the last crypto cycle. When everyone is trying to get rich as quickly as possible, the best way to make sure no one else sells before you do is to convince them that everyone is going to hold onto this asset forever. They’re going to ride it to the moon.

But the reality is that in a speculative mania, you’re playing a giant game of chicken to see how long you can ride it before it collapses. You have to recognize this is true, even if the project behind the token is a fundamentally good one.

Unfortunately, not having diamond hands can lead to some really nasty consequences too, which I also discuss in the book.

This is not just a crypto lesson, it applies to all areas of making money.

The faster the value of something, or the revenue from it, goes up, the faster it can go down too.

The shitcoin that goes up 1,000% overnight might drop 90% the next night.

The website that shoots to the front page of Google overnight might disappear next week.

The Amazon dropshipping opportunity you find and make a ton of money on can be quickly cannibalized by another entrepreneur.

Even the faster you try to learn a language the faster you’ll forget it.

Value and income have a certain invisible “durability” measure.

Buying land and building a parking lot in the middle of Austin is slow, expensive, competitive, but once you have it and it’s making money, it will probably perform for a very long time. It’s durable.

Hacking your way into Twitter followers with engagement bait and algorithm optimizations could build you an audience very quickly, but they’ll jump to the next engagement hacker without thinking twice about it. It’s highly fragile.

Almost everyone who falls for the “passive income” trap eventually realizes this. Yes you can quickly build a business and yes you can make money from it, but that money will go away SHOCKINGLY fast, especially once you stop working on it.

And then you’ll be back to square one and wish you had worked on something more durable in the first place.

You’ll be shocked at how quickly some of the stories in the book turned south. Projects that had hundreds of millions, even billions of dollars in them, could disappear almost overnight. If you tried to put money into them with a long-term investor mindset, you would have gotten cooked.

No matter how smart and rational you think you are, if you start seeing huge dollar amounts attached to something you speculated on, you will get very stupid very fast.

You can’t hope that you’ll make the right decision in that moment. You have to have already made the right decision earlier, before the wave of euphoric success has crashed over you.

Whatever bad impulsive behavior you’re trying to avoid, whether it’s holding a shitcoin too long or not eating desert, the more you can prevent yourself from being able to act impulsively, the better.

One modest version of this is “automatic escalation,” where you can automatically increase the amount that’s deducted from your salary and put into your 401k each year, or with each raise. You won’t notice the small biweekly hit to your income, but over twenty or thirty years it will turn into a significant chunk of change.

There was one way I chose to automate my decision making around selling crypto in the book, and it ended up having a bigger impact than almost anything else I did. If I hadn’t made that one seemingly small choice, I would have been much stupider with my money.

You’re probably thinking “Yeah, duh,” but you’d be surprised by how quickly you forget this fact once you’re in the maelstrom.

And this doesn’t just apply to crypto. Looking at your Stripe dashboard won’t make your business grow. Looking at the scale won’t make you lose weight. You need to check these things occasionally to make sure you’re on the right track, but if you find yourself constantly looking at some metric, it usually means:

  1. Too much is riding on that chart’s short-term performance

  2. You haven’t sufficiently automated your decision making

Sometimes you’re constantly looking at a chart because you’ve over-invested in a speculative asset. In fact this is probably the best sign you’re over-invested. If it suddenly dropping 10-20% is going to stress you out because you need this one to work, you’re taking on way too much risk.

In the same vein, if you need your business to double its revenue overnight, you’re probably taking too much risk with it and don’t have a sufficiently long-term view.

Other times you’re constantly looking at the chart because you’re trying to decide what to do. If that’s the case, then you haven’t sufficiently automated your decision making, and you need to create better rules for yourself. You should never be looking at a price to decide what to do. You should already have your decisions made about what you will do at different prices.

Remember that when you find yourself constantly checking some metric, it means there’s a deeper problem you need to address. I wish I had known that earlier, because constant chart-checking definitely led to some of the worst consequences in the story.

As I mentioned before, there were some periods of insane income during the events of the book.

And during that time, I felt like I was rich. Money felt like it was falling from the sky.

But when the market crashed and the crypto income stopped, I was terrified. I felt awful not having that income anymore.

It was keeping me up at night, making me neurotic, there were periods where I thought I should give up on this writing goal and go find a job.

Here’s the insane thing though: my net worth was actually higher once the income stopped, and over the last two years while I was feeling that terror, my net worth hasn’t changed much.

I felt the poorest when I was actually the wealthiest, purely because I didn’t see new money coming in.

That is INCREDIBLY STRANGE. But it explains why people have such a hard time enjoying the fruits of their hard work and living off their savings and investments. Having wealth does not feel as good or secure as seeing more money come in.

I feel okay about it now, but it’s taken nearly two years to deprogram that relationship. And it was surprisingly brutal to work through it. So it’s another thing to be wary of if you chase making enough money for early retirement or even just being able to take some time off work.

Even if you have enough money to not need to be worried in the short term, you still will be if you don’t see cash coming in.

My friend Khe Hy talks about this extensively. And he should know, he walked away from a $2 million a year salary on Wall Street.

It’s easy to make a spreadsheet where you look at what you currently spend, figure out how much you need to have saved and invested (The Number) to deduct that amount every year until you die, and then try to save up that much so you can quit your job and live off of it.

But it very, very rarely works out like that.

You might get close to The Number, then decide you actually want a better lifestyle and keep grinding (the money is “too damn good”).

You might get close to The Number, then find your lifestyle has gotten more expensive along the way and you need to increase it.

You also might run into unforeseen obstacles along the way and never get close to it!

I had one goal when the story in the book started, and once I hit it, I immediately increased the goal. Then I increased it again when I hit the next goal.

It wasn’t until something very unexpected happened that I realized I’d completely abandoned the original reasonable goal for a completely unreasonable one.

One of the realizations that helped me step out of crypto world and get back to writing was that I was getting good at the wrong thing.

I imagined five, ten, twenty years in the future, and asked myself how I would feel if I never became an extremely successful crypto investor or programmer.

And the truth was, I wouldn’t care. That skillset was near meaningless to me, it was just a means to an end.

But when I imagined not being a successful author that far in the future, I realized I would be filled with regret.

This is how success can become a curse. If you get really good at the wrong thing and you’re making a bunch of money from it, people are telling you how smart and capable and accomplished you are, you might start to think that it is the thing. And then you wake up one day and realize you were duped.

Obviously you probably need to get good at something you’re less thrilled about to put food on the table and get your career started. But don’t forget that it’s merely a tool for the work you really want to do later. Deprioritize it as soon as you can.

We have a very limited time on earth to go after our dream work. And while you should absolutely make sure you can afford to chase it before you do, once you can chase it you’re robbing yourself of future joy by not getting after it.

This is why the inflation of The Number or getting Too Good at the Wrong Thing is so sad. If you’re already 30 and have, say, 60 years left, another year spent chasing The Number is 1.6% of your life. If you’re 50, it’s 2.5% of your life.

If you want to commit to a career which requires a long time to get rolling, like writing or music or building a business, waiting isn’t going to shorten the startup time.

You’re going to have to spend those 2, 5, 10 years getting it going eventually. Start before it’s too late.

Before you go, don’t forget to order Crypto Confidential if you haven’t yet! If you’ve ever enjoyed a piece of my writing, I know you’re going to absolutely love the book.

Order Crypto Confidential!

❌