Normal view

Where to Drink in Paris this Week: 18 September 2024

18 September 2024 at 09:28

Welcome to the weekly guide on where to drink in Paris. Every Wednesday, I spotlight three bars including an old favorite worth revisiting, something new (bars, menus, etc) and something […]

The post Where to Drink in Paris this Week: 18 September 2024 appeared first on Paris • Cocktails • Bars.

The cautionary tale of Huy Fong’s hot sauce

16 September 2024 at 22:34
estimated reading time: < 1 min

Sweet and spicy with a sour tinge, sriracha sauce was an instant hit when David Tran, a Vietnamese refugee, brought it to America in the 1980s under the brand Huy Fong Foods. Asian eateries were the first to snap up Mr Tran’s hot sauce, but before long the green-nozzled bottle, with its distinctive rooster logo, had become a staple in restaurants and pantries alike. Within just a few years Mr Tran went from hawking his wares out of a Chevy van in Los Angeles to walking the floor of a 20,000-square-metre factory. By 2020 his business was worth $1bn.

The Devil in Miss Parton

13 September 2024 at 13:32

The Devil in Miss Jones (1973) is one of the classics of the ‘Golden Age’ of porn films. It was written, directed and produced by Gerard Damiano one year after the success of Deep Throat. The film takes inspiration both from Sartre’s No Exit – a play length exposition of the existentialist’s famous claim that ‘hell is other people’ – and from the Marquis de Sade’s Justine – whose titular character embodies the ideal feminine virtues of the 18th century, and is repeatedly punished for it; her innocence, piety, and honesty rewarded by a series of violations, as well as the torture, death, or betrayal of everyone she trusts (its sequel, Juliette, tells the story of Justine’s sister, who rejects both God and virtue, embraces corruption, and thrives).

The Devil in Miss Parton was released towards the end of a quiet period for angel film. After a glut of releases over the 1930s, 40s and 50s, barely anything was released between 1956 and 1968, when the genre gets going again with a series of films which deliberately play with its well-established cliches. If you’re familiar with angel films as a genre, it’s clear that The Devil in Miss Jones is written as a knowing parody of the standard tropes. The film’s protagonist Justine – having lived a perfectly virtuous life – dies by suicide, only to awaken into an afterlife where heaven is forbidden to her, yet she has not sinned enough to truly merit hell. The only solution, she is told by the angel Abaca assigned to judge her, is to go back to earth and earn her eternal damnation. She doesn’t seem enthused about the opportunity for theft, robbery or murder. What about lust, she asks?

Most of the rest of the film plays out as a series of explicit sex scenes, beginning with Justine’s encounter with ‘the teacher’ whose role is to cure her of her inhibitions, so as (he says) to make his work easier and hers more pleasurable. In each of the scenes – involving various other people, animals, and objects – the focus is on Justine. Both her pleasure and her voice are centred. At the end, she returns to Abaca, asks to be allowed to stay, only to be told that no such thing is possible, and to find herself, in the end, trapped in a small white room with a man (played by Damiano) raving about flies as she begs him to touch her.

Many of these narrative moves are easily recognisable from earlier angel films: a person awaking after death to find themselves with a lowly functionary responsible for overseeing their time in the space in between death and final judgement (Outward Bound (1930), Heaven Can Wait (1943), Here Comes Mr Jordan (1941); wishing to make up for the opportunities they had missed in life and hoping to do enough to be granted passage through judgment into everlasting life (Liliom (1934), remade as Carousel (1956), Angel on my Shoulder (1946); being tempted by the charms of the world they have temporarily been sent back to (The Bishop’s Wife (1947), The Horn Blows at Midnight (1945)). What’s striking about The Devil in Miss Jones is that it brings together these familiar tropes into a new format which seems, in turn, to become the template for two later angel films: 1990’s Almost an Angel, starring Paul Hogan/Crocodile Dundee and 1996’s Unlikely Angel, starring Dolly Parton. Both films share with The Devil in Miss Jones a very precise formula, here inverted: a protagonist whose entire life except for the manner of their death would seem to destine them for one of heaven and hell, and an opportunity to return to earth so as to make good on the promise of that very final moment, a moment of realisation about the kind of life they missed out on whilst alive, and then a final glimpse of their passage into their eternal destiny.

In Almost an Angel, Paul Hogan’s Terry Dean is a career criminal whose first move on getting out of prison is to try to rob another bank. As he does so, however, he spots a small girl about to be hit by a car and dies whilst saving her, only to find himself in a meeting with God (Charlton Heston), who describes himself as Dean’s probation officer, and tells him that while his entire life he never did anything but take, his final act of selflessness means that he’s earned a chance at heaven by dedicating his life to others; by giving instead of taking. While it takes him some time to unlearn his bad old habits, he manages to perform a series of selfless acts: befriending a terminally ill man named Steve and helping out the youth centre he runs with his sister Rose by clearing out some local drug dealers, convincing a tight-fisted evangelical that God is calling him to greater acts of charity, and comforting Steve as he dies. Whilst his attraction to Rose makes him regret the fact he cannot stay on earth, the film ends with a cross miraculously lighting up, Terry discovering that he cannot die, and a voiceover assuring Rose that Steve is with God now.

The sins of Dolly Parton’s Ruby Diamond are never quite as clear, but seem to be related to singing in bars, flirting with men, dating men who cheat on her, and never settling down to get married or have children. Driving home from a gig one night, she swerves to avoid hitting a death, and dies, only to find herself in a meeting with a man in a white suit who introduces himself as Peter and tells her that she’s lived an entirely selfish life, and that it’s only because at the very end she sacrificed herself for another living then that she will get a chance to make up for it. She’s then sent back to earth where she has to reconcile a family in the wake of their mother’s death by helping the father to recognise that his children need him and need a proper Christmas, helping the children to forgive their father, and pushing the father to marry his secretary, all while resisting her own desire to stay and take her place in the family home. As the film ends we see Dolly walking through the pearly gates, receiving her wings, and joining in the angelic chorus singing praise to God.

It’s interesting how precisely Almost an Angel and Unlikely Angel invert the plot of of The Devil in Miss Jones, itself a much looser parody of the angel film genre. While I can’t find any existing scholarship which connects the three the parallels are so precise – and The Devil in Miss Jones such a classic – that I’m convinced it must be a relatively direct influence on the two later films. The Devil in Miss Jones relates to Almost an Angel and Unlikely Angel like Justine to its sequel Juliette, mirrored narratives of virtue and vice, reward and punishment whose precise inversions reflect, however, a much more conventional moral universe than that of de Sade. It’s Unlikely Angel which more perfectly parallels The Devil in Miss Jones. Whereas Terry Dean ends by walking off out into the world, the promise of both further earthly adventures and of possible romantic consummation hanging in the air, both Justine and Ruby return in the end to their previous condition, albeit transformed by the lessons they have learned during their brief return to earth. Justine is only now able to fully appreciate the horror of the lonely, untouched life she already hated enough to want to kill herself; Ruby only now unable to sing in praise of God and in service of the middle class nuclear family rather than the dive bar circuit which she came from. Both films ultimately offer us a vision of the pleasures of sexual liberation once more safely enfolded into a narrative which sets desire against the care and self-sacrifice by which the white family is made and remade, in which sex can be recuperated as long as we do not acknowledge, as de Sade did, the pleasures of power, pain, and violence.

Where to Drink in Paris this Week: 13 September 2024

13 September 2024 at 11:37

Welcome to my weekly guide on where to drink in Paris! Every Wednesday, I’ll spotlight three ideas on where to drink in Paris this week. The trio will include an […]

The post Where to Drink in Paris this Week: 13 September 2024 appeared first on Paris • Cocktails • Bars.

Awk-ward!

10 September 2024 at 22:10

“Have you seen this?,” a friend recently messaged me. She was referring to this article on awkwardness, which hit some points familiar to readers of my 2010 book on the same topic. The author does cite me, and judging from a quick Google Books search, she does so even more in the full book, of which the article is a précis. And yet, one does feel “some kind of way,” as they say, especially since the title is identical (simply Awkwardness) and the subtitle is even in a very similar style (A Theory vs. my An Essay).

My friend felt defensive on my behalf, as did several other people with whom I shared the article. And yet my own mind wandered back to two awkward occasions, many years ago. One centered around a story published in the late lamented The Awl entitled “I Can Awkward.” Awkwardly, I cannot find it right now [though commenter Matthew Bertucci helpfully shares a Wayback Machine link], but the basic point was that maybe we should not be so scared of awkwardness because it could be empowering. Yikes! Sitting in my living room stewing, feeling that I had perhaps enjoyed fewer writing and career opportunities than I deserved, I talked myself into the idea that this article had somehow deprived me of something by not citing my work. I wrote to the editors, who were more gracious than they strictly had to be and who pointed out that academic and journalistic standards are different. There was no reason to believe the author had read and ripped off my book. There was also no reason to believe that it would have made any difference to my life if he had cited it. In the end, I just wound up making a fool of myself in front of a couple of the coolest people ever to internet.

And who woulda thought? It figures — a couple years later someone emailed me about Awkwardness (my book, not the more recent one). They were concerned that I may have ripped off the author of this 2007 book, whose existence I had indeed noted but which I did not read, because it appeared to be a memoir rather than a theory of awkwardness. Lo and behold, my ideas about awkwardness arguably echoed those of this author, a coincidence I could only explain by noting that sometimes when people address a similar topic, they come to similar conclusions. (I still have not read the book, because I have this bizarre sense that doing so would somehow represent a concession to my accuser.)

So for those keeping score, here are the three books under discussion:

  1. Awkward: A Detour (2007), by Mary Capello
  2. Awkwardness: An Essay (2010), by Adam Kotsko
  3. Awkwardness: A Theory (2024), by Alexandra Plakias

I note that I have not used the name of any other author before this listing, and the author of “I Can Awkward” remains unnamed even now. [UPDATE: Based on the Wayback Machine link above, it turns out his name is Matthew Wollin. I cannot find any evidence that his Awl piece catapulted him to the greatness that I should have enjoyed.] Similarly, I do not recall the name of the DePaul philosophy student who, in the course of a drunken conversation, stumbled upon the same joke connecting Heidegger to awkwardness that I had been honing for months — prompting me to stake my claim by finally putting together a book proposal.

It’s as though the idea is simply in the air, floating around, and all of us are always already too late to claim as our own. Writing a para-academic book, I didn’t feel I needed to do my due diligence of first reading everything potentially related to my idea — though of course I was also offended when someone treated me equally neglectfully. As for Plakias, it was doubtless strange to stumble across my oddball little text on ancient pop culture examples, and I’m glad she followed genre constraints nonetheless. Hopefully she will handle it gracefully when, some time in the next 5-15 years, someone else inevitably comes along and writes a book entitled Awkwardness with a two-word subtitle that puts forward the idea — perhaps not so creative after all — that awkwardness could be a positive thing if we attend to it in a certain way.

FreshRSS 1.24.3

6 September 2024 at 19:23

This is a quality-focussed release for the 1.24.x series meant to provide a good product to people blocked on PHP 7.4, while we will increase the requirements to PHP 8.1+ from the next release.

A few highlights ✨:

  • Last version supporting PHP 7.4 before requiring PHP 8.1+
  • Last version supporting PostgreSQL 9.5 before requiring PostgreSQL 10+
  • Last version supporting MariaDB 5.5 before requiring MariaDB 10.0.5+
  • Last version supporting MySQL 5.5.3 before requiring MySQL 8+
  • Many bug and regression fixes

This release has been made by @Alkarex, @math-GH and newcomer @pando85

Full changelog:

  • Bug fixing
    • Fix mark-as-read from user query #6738
    • Fix regression for shortcut to move between categories #6741
    • Fix feed title option #6771
    • Fix XPath for HTML documents with broken root (used by CSS selectors to fetch full content) #6774
    • Fix UI regression in Mapco/Ansum themes #6740
    • Fix minor style bug with some themes #6746
    • Fix export of OPML information for date format of JSON and HTML+XPath feeds #6779
  • Security
    • OpenID Connect better definition of session parameters #6730
  • Compatibility
    • Last version supporting PHP 7.4
  • Misc.
    • Use charset for JSON requests from the UI #6710
    • Use .html extension for the local cache of full content pages instead of .spc #6724
    • Update dev dependencies #6739, #6758,
      #6759, #6760

Faust in the Anthropocene: A Compilation and Coda

30 August 2024 at 09:00

For ease of reference, here are the links to the entire series:

Part 1: Faust the Innovative Throwback
Part 2: Faust and the Preemptive Crisis of the Professions
Part 3: Faust and the Tragedy of Misfired Modernity
Part 4: Faust and the Redemption of Modernity
Part 5: Faust Beyond Faust

I hope the unaccustomed pace of posting was okay, especially for my email subscribers. For my part, I was excited simply to have new material to post for a week straight! It felt like old times.

As I mentioned in the note to the first installment, this was my first attempt to write out some thoughts on Faust that have been percolating over many years as I have regularly taught a course on the Faust legend called “Deals With the Devil.” (You can see the most recent iteration of the syllabus here.) This means that I was trying to squeeze a lot of thoughts on Faust into a relatively short piece — a problem that was exacerbated by the unexpectedly short timeframe I had available to write it, due to severe disruptions in my travel back from New York.

Looking back over the whole thing over the course of the week, I feel that the effect was most pronounced in the ending, where I just kind of… stopped. Hence this follow-up post! The main thing that I would like to do is to flesh out the connection with the Anthropocene dilemma. I emphasize the Christian baggage in specific in our moralized way of thinking about climate change. One further step I would take in that direction is the attitude toward geoengineering, which feels like “cheating” to many. We should take the more painful and difficult method, not a quick fix! I once did a poll for my Twitter followers, a carefully curated group of mostly leftists and liberals, where I posited that there was a button they could push that would return atmospheric carbon to pre-industrial levels instantly with no adverse consequences. A surprising number said no! Presumably many of them were expressing their rejection of my absurd scenario, but at least some of the negative response is a Christian-esque moral masochism. The fact that — as a Bluesky follower whose post I cannot now find pointed out — geoengineering is sometimes referred to as a “Faustian bargain” also indicates a certain reluctance to make intentional interventions into the climate, as though we would illegitimately be “playing God.”

There’s another area where the Faustian situation sheds light on the dilemma of the Anthropocene, and that is the attempt to put new wine in old wineskins, discrediting both. The fact that capitalism is unable to deal with climate change and seems to relentlessly discover new ways to make it worse (tax credits for SUVs! a fake currency made of wasted carbon emissions! a bullshit machine that basically sets fire to a small village in order to generate an image of Garfield smoking pot!) discredits the system. Yet like Christianity, it hangs on through sheer inertia and we can only view solutions through its lens. We must somehow solve this urgent problem in a way that (a) guarantees continued capitalist profits, including for people who have invested in the very fuels that are causing the problem, and (b) maintains “fair” competition among the various nations into which we have divvied up the earth’s surface. Those conditions are literally impossible to meet! And compared to what’s at stake, making sure Exxon shareholders get their expected value or the EU remains “competitive” with China in battery production seems incredibly petty and stupid!

There’s a first as tragedy, then as farce dynamic here. At the dawn of modernity, scientific knowledge — with its claim for human empowerment and autonomy apart from divine revelation or ecclesiastical tutelage — appeared dangerous and demonic. At the twilight of modernity, it has become little more than an annoying wet blanket that no one wants to think about. Far from building a society on genuine knowledge that empowers us to master our world, we are letting archaic moral intuitions and discredited institutions permanetly ratchet down the life chances of future generations even though we know exactly what needs to be done and have the ability to do it. I remain haunted by an interview with Kim Stanley Robinson where he lays out the worst-case scenario (which is broadly what you’d think), but then also lays out a more optimistic scenario:

The best-case scenario is also completely possible from our current situation, despite the trajectory we are on. It would be a just, sustainable world in which the energy flows in the biosphere were in balance, such that the extinction rates would be normal, ecosystems everywhere restored to health, and 10 billion humans ― shrinking quite naturally in number as all the women in the world began living in complete gender equality ― were all living with adequate food, water, shelter, clothing, health care, education, and work.

This best-case scenario, the utopian turn, is physically possible if it were the goal of human civilization and became what we were all working toward together. The crucial technologies involved are not so much physical as they are social, which is to say, we have to have ecologically guided economics and politics. It is by its very nature a leftist vision, in that it foregrounds justice and welfare for all.

It is physically possible, and as Keynes — surely no socialist! — tells us, anything we can actually do, we can afford. But we won’t allow ourselves to do it because it would disrupt this system of claims and this weird zero-sum competition that we’ve set up among ourselves. In fact, many of our fellow humans regard the best-case scenario as the end of everything they value and are willing to fight to the death for their right to doom us all.

Here I am reminded of a version of Faust I don’t mention in the talk — Murnau’s amazing silent film (which you should all drop everything and watch if you haven’t already). There Faust uses his demonic power initially to try to cure a plague, but everyone turns on him once it becomes clear where his power is coming from. At that point, he embraces sheer nihilism and asks for Mephistopheles to give him youth — presumably so that he can relive a life he now believes to have been wasted. If the cure can’t be squared with Christianity — the same Christianity that will drive them to burn Gretchen alive at the end of the film — then they don’t want it. In the end, all Faust can strive for is some kind of personal satisfaction and personal connection, because any avenue to use his formidible knowledge in a meaningful way has been shut down. In a contemporary adaptation, what could Faust be but a climate scientist?

What Cheese to Pair with a Bramble Cocktail?

29 August 2024 at 22:18

August Cheese and cocktail pairing: Bramble Cocktail with Selles-sur-Cher In our cheese & cocktail pairing project, I combine my cocktail know-how with the encyclopedic cheese knowledge of Jennifer Greco of […]

The post What Cheese to Pair with a Bramble Cocktail? appeared first on Paris • Cocktails • Bars.

Faust in the Anthropocene, Part 5: Faust Beyond Faust

29 August 2024 at 14:20

[See Part 4 here, or go back and read the series from the beginning.]

I have compared Faust’s utopia to the American dream, although admittedly the notion of social solidarity in the face of disaster hits a sour note from that perspective. What makes it feel so American to me is that it is so profoundly capitalist. It presupposes that life demands constant labor and striving, that true freedom requires exposure to danger, that nature’s power is wasted unless it is conquered and redirected by human interests. This connection is far from hypothetical. Long passages of Part 2 revolve around Mephistopheles’s plot to introduce paper money into the German empire, and as Marshall Berman notes in All That is Solid Melts Into Air, Goethe himself was fascinated by vast world-shaping projects like the Panama Canal, which finally assert humanity’s mastery over nature.

In our current moment, it is ironically this very triumph of modern developmentalism that appears most naïve and even retrograde in Goethe’s Faust. Capitalist domination over nature has proven more profoundly world-shaping than Goethe ever could have anticipated—delivering potentially every nation on earth to the condition of Faust’s ocean-threatened utopia. If Goethe expected Faust’s project to evoke something like the Panama Canal, to me it seems anachronistically to evoke science fiction images like the half-flooded city of Kim Stanley Robinson’s New York 2140 or the vast flood walls around New York City in the dystopian future of The Expanse. From this perspective, it feels like no accident that the most recent major adaptation of Faust, Life and Trust, is precisely about the collapse of capitalism. Even more telling is the fact that in this immersive theater experience, the Great Crash does not open out onto the future of the New Deal and postwar economic miracle, but promises only a return to a lost past that is, if anything, even more riven by hierarchies of race, class, gender, and sexuality than the present.

Perhaps even more than the promise of freedom and abundance through capitalist development, Faust’s goal of seizing state power to build a better society for everyone is likely to strike the contemporary reader as sinister than redemptive. Of course, it doesn’t help that Goethe decided at the last minute to insert the story of the poor old couple whose humble abode is spoiling Faust’s perfect view. Even if Faust did not intend for them to die, his order to Mephistopheles to remove them is both callous and reckless—surely by now Faust must understand who he is dealing with.

I would suggest that Goethe may have added this unsavory episode precisely so that Faust would have something to be redeemed from. Certainly his seduction of Gretchen turned out to be destructive, but at that point he was as naïve about Mephistopheles’s motives as Gretchen was about Faust’s. All the most fatal moves (the poisoning of Gretchen’s mother, the stabbing of her brother, the escape to Walpurgis Night) were at Mephistopheles’s initiative rather than his. With the old couple, there is still a small sliver of plausible deniability insofar as he did not explicitly tell Mephistopheles to kill them—but his motives are also much more purely selfish, even petty. With Gretchen, he was a rejuvenated man in love for the very first time. One can imagine behaving irresponsibly in that situation. With the old couple, however, even if he did not directly wish them to die, he is still acting like a tyrant who values his own idle whims over the wellbeing of others.

I previously emphasized Goethe’s free adaptation of Christian materials in the conclusion. There I think he more or less succeeds in using those materials to craft his own idiosyncratic theology in a way that is not finally shaped or predetermined by Christianity. But if I am right about his motivation for inserting the death of the old couple, the denoeument of Part 2 is nonetheless profoundly determined by Christianity—specifically the Christian notion of the felix culpa, the happy fault. The phrase comes from the Easter Vigil liturgy: “O felix culpa quae talem et tantum meruit habere redemptorem” (“O happy fault that merited such and so great a Redeemer”). The notion here is that the sin of Adam and Eve, with all the vast suffering it unleashed, is nonetheless a net positive because it enabled the even greater event of redemption.

With this idea of the felix culpa in mind, we can see that the transition from Marlowe to Goethe is not, as it initially appeared, a transition from entrapment in the Christian framework to an escape from it. Rather, it is a shift from a more simplistic to a more sophisticated theology. In Marlowe, Faust’s sin is simply useless and meaningless within the Christian framework, petering out into pointless pranks. In Goethe, by contrast, Faust’s sin is a necessary step toward a greater redemption—not only for himself, but on a social, economic, and political level. This is not orthodox Christianity—insofar as Faust seems to fuse the first and second Adam, the sinner and the redeemer—but its moral economy does grow out of a profoundly Christian impulse.

Now, at last, it is time for me to justify my title. If we limit the “man” or anthropos of the Anthropocene to modern man in specific, and if I am right that Faust is in some sense the myth of modernity, that it supplies a stage on which modernity can enact its deepest tensions and contradictions, the connection between the Faust legend and the Anthropocene dilemma become much more profound than the kind of easy parallels I threw out and dismissed at the beginning of my lecture. The Anthropocene is the Faustocene—it is the dilemma of a modernity that remains profoundly shaped by Christianity at its foundations, and in particular in its moral instincts. Think, for instance, of the primary complaint about the term “Anthropocene,” namely that it attributes blame incorrectly, implicitly grouping in the largely innocent Global South nations with the real culprits. Better to call it the Capitalocene, blaming the specific system that caused the destruction rather than indulging in clichés about “human nature” in general. These observations are all correct as far as they go, but why is the most important priority to attribute blame? What will be changed by the sheer fact of knowing whose fault it is? One also thinks of the tendency to say that “we” are all to blame for environmental degradation and therefore “we” all deserve the punishment. Either case represents what we might call Marlowe’s Faustocene—a moral vision in which using the illicit powers unleashed by modernity leads to an inevitable punishment.

More profound and more insidious are the patterns of thought that we could characterize as Goethe’s Faustocene—the notion that environmental destruction is a felix culpa, a necessary step to development as such. Think of how often we hear that it is unfair that poorer nations should be deprived of the opportunity to destroy the environment themselves, as that is presumably the only path to prosperity. Think, too, of how often we on the left gesture toward the notion that the environmental crisis will finally force everyone to abandon capitalism as unsustainable and create a more holistic and communitarian way of life.

The Anthropocene is also the Faustocene in another sense, insofar as it represents a profound crisis of all the distinctively modern forms of authority. Science seems to betray its promise of ever-greater abundance and mastery, instead warning us that we must restrain ourself in the face of forces we can never fully control. Law—along with the liberal democratic institutions that generate and legitimize it—seems increasingly disconnected from reality, as even the most environmentally savvy nations are enacting what amounts to de facto climate change denial. The promise of the modern professions to guide and empower state instutitions with accredited knowledge is shattered—all the moreso in the wake of the pandemic, which has discredited the medical establishment and the entire enterprise of public health in the eyes of many (even if for mutually contradictory reasons depending on who you ask).

I will admit that it’s very unclear to me what we are supposed to do about this situation. It should be clear that I think the Faust legend probably has more resources for thinking about how we got where we are than how to move forward. But it may be worth pondering what it would look like if we reimagined a contemporary Faust who is trying to escape from the Faustian dilemma itself. And my first suggestion along these lines would be that such a Faust-beyond-Faust would give up the gestures of subversion, resistance, and even rebellion in favor of an affirmative creation.

[Continue on to the Coda.]

Faust in the Anthropocene, Part 4: Faust and the Redemption of Modernity

28 August 2024 at 13:44

[See Part 3 here.]

When Marlowe adapted the Faust story for the stage, it is only a slight exaggeration to say it was “ripped from the headlines”—the original German chapbook had been published only a few years prior, followed by an English translation. By the time Goethe took up the same material over two centuries later, Faust was an established legendary figure in a much more assertive and confident modern world. Far from being an edgy countercultural tale that had to be wrapped up in traditional piety for plausible deniability, the Faust legend in Goethe’s Germany was a story for children, commonly performed in puppet shows. (Indeed, Goethe himself seems not to have read Marlowe’s play until very late in his life, when he was already working on Part 2 of his massive drama.)

In many ways, as with our contemporary glut of adaptations of established cultural legends, Faust is an exercise in nostalgia—nostalgia for a lost naïve faith, nostalgia for the pure emotional receptivity of childhood and youth, even nostalgia for itself, given the fact that Goethe composed the play over the course of many years. The opening poem, skipped by many readers and only added at the very last stages of composition, connects the play to Goethe’s own lost youth, and Faust himself is preoccupied with childhood. When he is on the verge of suicide after his failed encounter with the Earth Spirit, Faust is saved by a children’s chorus that reminds him of his youthful faith and, even more, his immediate connection to nature in those days. His trip to town on Easter morning brings up painful memories of childhood, as the praise he receives for his role in his father’s medical practice reminds him only of the deadly effects of the dangerous poison they unwittingly distributed as medicine. And of course much of what attracts him to Gretchen is precisely her youth and naivety, which he believes will help him reconnect with that more authentic part of himself. (This is, incidentally, an aspect of the play that renders it somewhat difficult to teach to undergrads.)

As should be clear by now, Goethe freely reworks the material, most notably by revising Faust’s background (giving the former orphan a physician/alchemist father) and introducing a love interest. At times, he seems to be almost embarrassed to be adapting the Faust legend, introducing “meta” elements to highlight the silliness of previous versions. The clearest example is the scene at “Auerbach’s Tavern in Leipzig,” where Mephistopheles plays elaborate pranks on a group of drunks and Faust has only one line: a request to go home. This is a way of having his cake and eating it too—including the pranks that were such an integral part of the legend, while at the same time marking his distance from that vision of Faust. Indeed, by the end of Part 1, we seem to have forgotten the devil’s bargain altogether, as the story has become the tragedy of Gretchen more than that of Faust. In the unforgettable scene where Gretchen refuses to accept Faust’s offer of escape even knowing that she will be executed the next morning for the death of her baby, only an over-literal pedant could possibly be concerned with the dangling thread of Faust’s soul.

This displacement of the central element of the legend is surprising in light of the fact that Goethe’s own reworking of that theme is what gives his version such philosophical depth. As with his pranks in the tavern, Mephistopheles’s attempt to secure Faust’s soul represent an attempt to enact the script of the traditional legend, which this Faust continually derails. Scorning earthly pleasures, Faust seeks something more profound—a holistic grasp of the full range of human experience, of which he has been deprived in his life of scholarly isolation. In my favorite exchange, Faust declares (quoting David Luke’s excellent translation):

Poor devil! What can you offer to me?
A mind like yours, how can it comprehend
A human spirit’s high activity?
But have you food that leaves one still unsatisfied,
Quicksilver-gold that breaks up in
One’s very hands? Can you provide
A game that I can never win,
Procure a girl whose roving eye
Invites the next man even as I lie
In her embrace? A meteoric fame
That fades as quickly as it came?
Show me the fruit that rots before it’s plucked
And trees that change their foliage every day! (ll. 1671-1688)

Clearly something very strange is going on here, but Mephistopheles simply responds: “I shall perform as you instruct; / All these delights I can purvey” (ll. 1689-1690). Can you give me worthless, self-undermining pleasures? Yup, can do!

In place of the traditional devil’s bargain, Faust proposes a wager: if he ever ceases striving, if he ever allows himself to rest in full contentment, Mephistopheles can take him. Mephistopheles should presumably be more suspicious in this moment, because he has heard similar rhetoric before. In the “Prologue in Heaven,” Goethe had staged a dialogue between Mephistopheles and the Lord much like that found in the Book of Job—except this time, it is Faust whom God declares to be his servant. Mephistopheles is understandably puzzled, and God clarifies that it is precisely Faust’s implacable striving that he admires so greatly. When Mephistopheles again echoes the more traditional story by offering a wager, God responds with absolute confidence in Faust and even claims that Mephistopheles’s constant negativity will productively spur him from his stagnation and complacency.

Again, all of this is seemingly forgotten by the end of Part 1. Yet when Goethe returned to Faust late in his life, he apparently felt constrained not to leave this divine wager unresolved forever. In the end, Goethe famously—or infamously—engineers Faust’s redemption, in part through the intercession of the late Gretchen’s spirit. The path from Gretchen’s jail cell to this unexpected outcome is a long and winding one. Part 2 is much longer than Part 1, and much more allegorical in its storytelling. On the one hand, this approach allows Goethe to radically reimagine the Faust legend as an epic encompassing all of European modernity—including the rediscovery of Greek antiquity, as suggested by Faust’s famous encounter with Helen of Troy. On the other hand, the result is a self-indulgent slog that—if the two parts are taken as an integral work—retrospectively ruins the effect of the fragmentary but unforgettable original.

Be that as it may, for the sake of my goal of connecting Faust to our Anthropocene predicament, Part 2 is more relevant. The main plot—leaving aside various fanciful digressions and the entire interlude with Helen—reminds me of a scene from the classic HBO police procedural The Wire. After months of surveilling the cautious and methodical gang leader Stringer Bell (played by Idris Elba), an investigator has an epiphany: “He’s worse than a drug dealer, he’s a property developer.” The same could be said of the Faust of Part 2—he’s worse than a demon-summoner, he’s a property developer.

Act 1 opens with Faust quite recovered from the trauma of losing Gretchen and ready for new challenges. Contemplating a waterfall, he has an epiphany: the ocean is constantly churning, but it all amounts to nothing. Dismayed by the waste, he determines to conquer the sea and turn all that wasted energy toward human ends. Mephistopheles hatches an elaborate plot to fulfill this ambition: Faust will present himself as a powerful wizard who can help the emperor defeat his foes, in exchange for land rights that are currently located under water. Faust can then reclaim the land from the sea, creating a utopian kingdom on soil truly untouched by humanity.

This plot obviously pushes the fantasies of settler colonialism to an extreme. Although it also seems to evoke the unique topography of one of the most successful colonial and mercantile states, namely the Netherlands, Faust’s vision of life in his new kingdom sounds more to me like the idealization of the American dream:

I see how
To give those millions a new living-space.
They’ll not be safe, but active, free at least.
I see green fields, so fertile: man and beast
At once shall settle that new pleasant earth,
Bastioned by great embankments that will rise
About them, by bold labor brought to birth.
Here there shall be an inland paradise:
Outside, the sea, as high as it can reach,
May rage and gnaw; and yet a common will,
Should it intrude, will act to close the breach.
Yes! to this vision I am wedded still,
And this as wisdom’s final word I teach:
Only that man earns freedom, merits life,
Who must reconquer both in constant daily strife.
In such a place, by danger still surrounded,
Youth, manhood, age, their brave new world have founded.
I long to see that multitude, and stand
With a free people on free land!
Then to the moment I might say:
Beautiful moment, do not pass away! (11559-11582)

The last phrase echoes Faust’s original wager. Even though it is a hypothetical statement about a future possibility, Mephistopheles seizes upon it, but, as I have said, his plans are ultimately foiled. And implicitly, this final labor, which actualizes Faust’s endless striving on the social, economic, and political plane, is part of the justification for Faust’s redemption. Regardless of its human costs—not only Gretchen and her baby, but also an elderly couple who are killed when Faust orders Mephistopheles to remove them from their land so he can have a better view of his kingdom—Goethe expects us to admire the grandeur of Faust’s project and to agree that he deserves the chance to continue striving eternally through the heavenly spheres.

Though this may initially seem like a reversion to the Christianity Faust dismisses early in the play, it is really a free reworking of Christian concepts and images (particularly Catholic ones, which do not reflect Goethe’s own religious background) to craft his own personal mythology of the “Eternal Feminine,” much as he had reworked Greek mythology to his own purposes in the Helen interlude. Finally, it seems, the Faustian modern man has triumphed so decisively over his Christian baggage that he doesn’t even need to reject it—instead, Goethe can treat it as indifferent material for his own goals, just as Faust treats nature itself. Where Marlowe had used Faust to dramatize the fraught transition to modernity, then, the Goethe of Part 2 recasts Faust as not only the embodiment but apotheosis of modern man.

[Continue on to Part 5…]

Faust in the Anthropocene, Part 3: Faust and the Tragedy of Misfired Modernity

27 August 2024 at 13:28

[See Part 2 here.]

This dynamic plays out almost literally in the opening monologue of Marlowe’s Tragical History of Doctor Faustus, which was written only a few years after the publication of the original Faust chapbook. When we meet Faustus, he is surveying the fields of human knowledge to determine which is of most value. He starts with Aristotelian logic, which claims foundational status and yet achieves no more than to help one “dispute well.” Faust is dissatisfied: “Is, to dispute well, logic’s chiefest end? / Affords this art no greater miracle? / Then read no more; thou hast attain’d that end” (1.1.8-10). Already we can see the mismatch—surely disputing well is not miraculous, but neither does it claim to be. He then moves on to medicine, again quoting and rejecting this field’s promised result: “The end of physic is our body’s health. / Why, Faustus, hast thou not attain’d that end?” (1.1.16-17). He then lays out an impressive résumé of his achievements as a physician but concludes: “Yet art thou still but Faustus, and a man. / Couldst thou make men to live eternally, / Or, being dead, raise them to life again, / Then this profession were to be esteem’d” (1.1.22-24). Again, Christian presuppositions are producing inappropriate expectations. Faustus then dismisses law as a matter of “paltry legacies” that “fits a mercenary drudge, / Who aims at nothing but external trash” (1.1.28 and 32-33). In place of an explicit comparison to Christian standards—the obvious source of his contempt for mere worldly possessions—Faustus then turns to the study of divinity itself. Apparently flipping through the Bible at random, he turns first to Romans 6:23, “for the wages of sin is death…” and then 1 John 1:8, “If we say that we have no sin, we deceive ourselves, and / there’s no truth in us” (1.1.38-42). In combination, these verses seem to Faustus to indicate that his situation is hopeless—he is constained to sin and therefore to die, a prospect that seems to render life meaningless.

One is tempted to say that the way out of the deadlock he points out can be found in the second half of the verse from Romans—“the gift of God is eternal life in Christ Jesus our Lord”—but surely we must give a theology PhD the benefit of the doubt that he knows the Bible. Rather than assuming he is simply making a mistake, I propose that he is lodging a deeper objection to Christianity when he claims that it amounts to a doctrine of “Che serà, serà” (1.1.46) The issue isn’t that there is no hope of salvation, but that the believer is rendered completely passive and powerless. By contrast, his books of magic seem to promise “a world of profit and delight, / Of power, of honour, of omnipotence” (1.1.52-53)—rather than relying on God’s arbitrary gift for his salvation, by becoming a magician Faustus can “gain a deity” of his own (1.1.61).

Yet when Faustus reaches the pinnacle of the magical art by allying himself with Mephistopheles, he spends his life squandering his supposedly divine power on a series of stupid pranks. The sense of pointless dissipation is echoed on the formal level by a plot that never seems to cohere into anything meaningful—defying Aristotle’s prescription of tragic unity in favor of a formless concatenation of episodes. On the level of plot and character as well, Marlowe’s Tragical History seems to defy Aristotle’s standards for tragic drama from the Poetics. There Aristotle defines tragedy as follows (quoting from the Joe Sachs translation):

Tragedy, then, is an imitation of an action of serious stature and complete, having magnitude, in language made pleasing in distinct forms in separate parts, imitating people acting and not using narration [by which he means that it is a play], accomplishing by means of pity and fear the cleansing of these states of feeling. (1449b)

As we have seen, far from being serious and complete, the play is a disjointed collection of mostly comic anecdotes. While Marlowe does hit the marks of using pleasing poetic language and literally writing a play rather than a prose narrative, it is not clear to me that we really experience pity and fear in relation to Faust’s fate. The apparent disconnect deepens when we consider Aristotle’s definitions of the tragic character and tragic action. For Aristotle, the tragic hero should be “the sort of person who is not surpassing in virtue and justice, but does not change into misfortune through bad character and vice, but on account of some missing of the mark,” and the action of a tragic play should depict “changing not into bad fortune from good but the opposite way, from good fortune to bad, not through badness of character but on account of a great missing of the mark” (1453a).

In Greek, the term for “missing of the mark” is the famous hamartia, which Christianized interpretations of Greek tragedy have construed as a “tragic flaw”—often pride. In reality, though, Aristotle means that the tragic hero should have made an understandable mistake. Oedipus doesn’t suffer because he’s a bad person—he’s a smart and capable guy who is trying his best to carry out his royal duties, but he got caught up in something really terrible through understandable ignorance. I don’t know how rigorously Marlowe read Aristotle or whether this distinction would have been available to him, but I do think it points toward two possible readings of the play—both of which turn on how we interpret Faustus’s objection to the doctrine of original sin. If we accept the Christianized notion of a “tragic flaw,” we would have to say that Faustus’s pride blinded him to the true nature of Christianity, leading him down his demonic path. If we think more in terms of Oedipus, who was attempting to do good things (e.g., avoiding murdering his father and marrying his mother, or looking out for his city) without realizing the trap he was in, the play becomes more interesting.

This second reading challenges us to look for what is admirable in Faustus, and when we do that we realize that it all hinges on his thirst for knowledge. Among the conditions of his devil’s bargain is the demand that Mephistopheles must answer all his questions—the only power that Faustus actually tests out before signing on the dotted line. We are also told that Mephistopheles takes Faustus to see both the heavenly spheres and a good chunk of the earthly sphere as well, though presumably Marlowe’s special effects budget was insufficient to show those actions directly. To the extent that Faustus seeks eartly power, it is as a servant to the king who helps enrich the kingdom—an ironic echo of the figures of Joseph or Daniel from the Bible, as well as an enactment of exactly the promise that the modern professions and academic disciplines made for themselves. Despite his initial dreams of domineering power from the opening monologue, he never commits irreversible violence and never seeks power for his own sake. Aside from petty amusements and some sexual satisfaction, the only thing he really desires is knowledge—which I personally find to be an admirable desire.

From this perspective, the tragedy of this Tragical History is not that Faustus has chosen damnation but that he was, like Oedipus, born under the wrong circumstances. His mistake is to seek out pure disinterested knowledge in a world where it can only appear as demonic and can only lead to damnation. Marlowe may not have succeeded in crafting a cohesive play, but if my reading does not miss the mark, he did intuitively, and profoundly, grasp the potential of the Faust legend. The original Faust chapbook amounted to a salacious gossip rag laundered with a superifical moral lesson (“don’t sell your soul to the devil, kids!”). In Marlowe’s hands, it becomes an existential meditation on the deadlocks of a world where Christianity appears as a legacy that is at once “paltry” and inescapable.

[Continue on to Part 4.]

Faust in the Anthropocene, Part 2: Faust and the Preemptive Crisis of the Professions

26 August 2024 at 13:38

[See Part 1 here.]

So far I have emphasized how Life and Trust embodies the unique combination of forward- and backward-looking elements that have made the Faust legend such a fertile ground for reflecting on the dilemmas of modernity. In terms of its narrative frame, this immersive theatrical experience’s portrayal of Faust as a disillusioned banker also draws on a more understated theme. Again and again, we see Faust (or the stand-in character) as a member of one of the professions. In the film The Devil’s Advocate, for instance, Keanu Reeve’s Faustian character is a high-powered lawyer. Goethe’s own version winds up making a transition that I’m sure many of us have considered, moving from professor to political fixer and property developer. And both Goethe and Marlowe, drawing on the earliest versions of the Faust legend, agree that their hero mastered all of the professions of his day and held doctorates from all four major faculties of the university: divinity, law, medicine, and philosophy.

From the very beginning, then, Faust embodies a uniquely modern form of authority, that of the credentialed professional. It is worth pausing to reflect on this association, which seems to prefigure the growing distrust of professionalism and professionals in our contemporary society. What is it about the traditional professions that could seem so suspect, so sinister? Perhaps one hint is another persistent association with Faust, aside from the obvious wickedness of seeking alliance with the devil. I am thinking of the view that Faust is a deceiver. Already in the original chapbook legend that compiled the stories that gathered around the historical Johann Georg Faust, we see Faust identified as a magician and alchemist. Later variations on the theme build on this association with charlatanism and deception. One of the most interesting examples is István Szabó’s film Mephisto portrays the Faust figure as an actor who, ironically, made his name by playing Mephistopheles in Goethe’s Faust. Not only is his profession intrinsically deceptive, but the Faustian character decides to pose as a committed Nazi in order to protect the theater from Hitler’s regime. Thomas Mann’s Doctor Faustus centers on the growing madness of Adrian Leverkühn, who is a master of the most seductive yet ungraspable of the arts—namely music. It does not seem like a stretch to say that both of these more modern Fausts are performing a kind of secularized magic, a disenchanted alchemy.

Going back to the most formative versions of the legend, both Marlowe and Goethe present these two sides of Faust—the credentialed professional and the magical manipulator—as intrinsically linked. In Marlowe’s play, Faust’s dissatisfaction with the power on offer from his four fields of study is what leads him to his magical and demonic pursuits, as though there is a continuity of aim between the professions and sorcery. Indeed, the Latin truisms that Marlowe’s Faust rattles off in the opening monologue seem almost like spells in themselves. Goethe characteristically pushes this Faustian theme even further, staging the assessment of the different fields of study as a dialogue between Mephistopheles (disguised as Faust) and a student who is trying to choose his course of study. In Mephistopheles’s cynical descriptions, the various professions are intrinsically false. Not only do they derive their power from obfuscation, but they license abuse—most notably when Mephistopheles suggests that the student choose medicine in order to have the opportunity to take advantage of his women patients. Even worse, earlier in the Goethe’s play Faust himself dismisses his father’s medical knowledge as worse than useless, claiming that his alchemy-derived drugs, far from curing victims of the plague, effectively euthanized them.

Life and Trust’s banker, driven to despair by the impending collapse of the fraudulent financial system he has presided over, is thus a natural extrapolation—Faust is, in essence, a credentialed expert who no longer finds himself credible. I use terms related to belief or faith advisedly here. If Faust is about a modern crisis of faith, it is also about a Christian crisis of faith. The trope of the deal with the devil contains a fatal paradox. In order to believe that such a deal is possible, that such an entity exists, one must accept the framework of Christian belief. But within that framework, such a deal can only lead to disaster and damnation! At the cusp of modernity, then, Faust simultaneously embodies a corrupted and self-undermining Christian faith and a corrupted and self-undermining professional authority. The most simplistic Whig narrative of modernity holds that medieval superstition was discredited and replaced by authentic modern rationality. In the Faust narrative, by contrast, the authority of Christianity has certainly seen better days, but its hold remains tenacious and insidious enough to damn Faust—and condemn the alternative modern forms of authority in advance. One is reminded of the classic Seinfeld episode where George claims God is cursing him. When Jerry reminds him that he doesn’t believe in God, George retorts: “I do for the bad stuff!”

So far I have spoken primarily of Faust as a professional and of the strangely preemptive collapse of professional authority in the legend. If we view the various professions through Mephistopheles’s cynical lens, there may seem to be no problem. Who cares if lawyers and bankers are consumed with self-doubt? Yet Goethe’s focus on Faust’s status as a medical doctor does point to a deeper problem. The credibility of modern professional credentials is not—or at least professes not to be—grounded solely in the empty self-assertion of a power-hungry clique. The modern credentialed profession claims to have a special knowledge that the professional guild exists to safeguard and expand. As the example of medicine shows, we all must hope that that knowledge is not purely invented or self-referential. We associate medicine more closely with scientific knowledge in the narrow sense, but ultimately all professions claim to have a knowledge that is scientific in the broader sense of the German Wissenschaft. Even if non-specialists are typically not in a position to assess the knowledge claimed by modern professionals, their knowledge is or should be rational, objective, and publicly verifiable. That association with science or Wissenschaft is why the university has always been the site of modern credentialization—and hence why Faust, as the professor who is fully credentialed in all fields, represents such a distinctively modern crisis of faith.

Here one may detect the influence of Hans Blumenberg’s monumental tome The Legitimacy of the Modern Age. As is well known, there Blumenberg forcefully rejects the claim of political theology that secular modernity is determined by its Christian roots. As a political theologian myself, I personally find his critique a bit beside the point, because he is not talking primarily about the political concepts and institutions that are political theology’s stock and trade, but about an institution that political theology mainly ignores: namely, modern science. For Blumenberg, modern scientific knowledge is at once genuinely new and genuinely authoritative—to use the German word for modernity, it is what is neu in the Neuzeit. Where the political theologian, in Blumenberg’s telling, is constantly seeking to undermine modernity as founded on the shifting sand of a disavowed legacy, Blumenberg insists that modern science is fully legitimate on its own terms.

This does not mean that modern science has nothing to do with Christianity, however. Science does not arise from Christianity, but it does arise in the midst of Christianity. And just as Christianity found that it had to provide some kind of answer to the questions raised by the most sophisticated and prestigious discourses of its time, namely Greek philosophy, so too does modern science have to respond in some way to the Christian milieu in which it happens to have arisen. In both cases, the attempt to answer the existential questions posed by the old regime is a case of putting new wine in old wineskins. In the extreme case, questions that were urgent in the context of the earlier paradigm become simply irrelevant in the new era—except that the handoff is never so neat and tidy. Even if those who inaugurate the new paradigm are able to cast aside the old values themselves, they must convince others who are still immersed in the old world.

One of Blumenberg’s clearest examples of this dynamic is the Christian theological conviction that the only knowledge worth having is knowledge about one’s relationship to God, or more abstractly, knowledge about the meaning and purpose of existence. As is well known, that is not the kind of knowledge modern science supplies—nor is it trying to. Yet the inertia of Christian expectations transforms that category error into a persistent disappointment, as though modern science is constantly trying and failing to supply a form of meaning that it in fact has no means or ambition to supply. And that disappointment always threatens to curdle into suspicion and hostility, because traditional Christianity—with its accustomed binary thinking—views knowledge that falls short of its standards not as indifferent or irrelevant, but as actively wicked.

[Continue on to Part 3.]

Faust in the Anthropocene, Part 1: Faust the Innovative Throwback

25 August 2024 at 17:05

[Editor’s note: I was invited to give a keynote address for this year’s Romancing the Gothic online conference. Given that the theme was “Devils and Justified Sinners,” I chose to discuss the Faust legend, which has been a big part of my teaching for many years but not something I have devoted any concentrated writing to. Since it is my first experiment in writing about Faust, it is closer to a blog post than a formal article in spirit, and so I will be posting the talk here in serialized format over the course of the week.]

It may initially seem strange that I am proposing to connect the two themes in my title. What could the story of a deal with the devil have to do with our contemporary ecological crisis? Here I could invoke any number of superficial parallels—we “made a deal with the devil” of capitalist growth and now the bill is coming due, etc., etc. That would doubtless be a satisfyingly clever way of saying the things we already know to be true about climate change, but it would not shed much fresh light on either the Faust legend or the Anthropocene.

Instead of jumping right into the comparison, then, I will largely take everyone’s knowledge of climate change for granted and focus initially on an analysis of the most fundamental themes of the Faust legend.  I observe first of all that the Faust legend has always provided a way to use the old to think through the new. In its demonological themes, the legend seems initially to be grounded in “medieval superstition.” Yet it is based on a historical individual—a fact that I can never quite believe—who lived at the very cusp of modernity, and its many later interpreters and appropriators have always used it to think through distinctively modern dilemmas. This is true even at the level of medium. The original Faust chapbook was one of the first runaway bestsellers of the print era, and Marlowe’s Doctor Faustus was among the most iconic showpieces of the Elizabethan era’s secular theater.

The Faustian fusion of innovation and old-timey-ness continues even to this day. This past weekend, I was fortunate enough to travel from Chicago to New York City to see the latest adaptation of the Faust legend, called Life and Trust. (In fact, I wrote a good portion of this talk in the hotel lobby after being stranded by a major storm that surely arose to punish me for so extravagantly indulging in my obsession with devils and demons.) Life and Trust belongs to an emergent but increasingly popular genre that we could call the immersive theatrical experience. The goal of this unique format is to break down the barrier between the audience and the players. Instead of watching events unfold on stage, the audience is thrown into the same space as the actors—a sprawling, even confusing space where everyone is free to wander. Even more radically, it shatters the unity of theatrical action by dispersing the actors and scenes throughout the space. Though many of the scenes play out in a kind of repeated loop, it is functionally impossible to see everything in one performance. And you have to work for what you do see, chasing after the incredibly athletic actors as they wind through a labyrinthine and stair-filled venue.

Life and Trust was developed by the producers of the best-known previous entry in the genre, the Macbeth adaptation Sleep No More, which recently completed a ten-year run. In the waiting area before the show, we talked to a young couple who had attended Sleep No More multiple times in the hope of seeing as much of its sprawling plot as possible. Some fans attended upward of a dozen times so that they could explore every nook and cranny of the elaborate set—audience members are allowed to dig through drawers, for example, which often include surprising background information or Easter eggs. Though Sleep No More had some limited dialogue, it was primarily a dance-based experience, something like a fragmentary narrative ballet. Life and Trust took that even further, all but dispensing with dialogue in favor of intense choreography.

In keeping with the tradition of Faust adaptations, this innovation was paired with a look backward—not to the early modernity of Faust, but to the Gilded Age and the Great Crash of 1929. For Americans, those events are a kind of pre-history, the threshold to the “American century” that began with Roosevelt’s New Deal, which profoundly transformed the American state and economy and laid the foundation for the postwar boom. But it is a past that continues to haunt the neoliberal era, where skyrocketing inequality and degraded state capacity threaten to return us to a new Gilded Age and recurrent economic crises inevitably raise the specter of a new Great Depression. The Faust avatar is a banker who is about to go bust in the Great Crash and sells his soul for the opportunity to relive his youth in the late 1800s. Once transported back to that era, the audience has the chance to follow any number of side characters from a variety of social backgrounds. One plot we were able to follow was that of a lesbian romance between a wealthy aristocrat and a servant girl, presided over by a demon who—as far as I was able to discern—was actually trying to get them to deny their love and conform to social norms, rather than egging on their supposed “sin.” This strikes me as a brilliant adaptation of the demonological theme for a world where the most serious sins are those against authenticity.

The audience in Life and Trust isn’t left completely rudderless. The drama is framed by two shared experiences, the opening scene that establishes the outline of the narrative and a dramatic conclusion. Even in those performances, it is impossible to take in everything at once from any particular standpoint within the theatrical space. But the basic outline of events is clear, especially in the final scene, where Faust’s side of the bargain inevitably comes due. As Faust pleads for his soul, dancers in demonic masks throw fake money down on the audience—and at times tear the bills to shreds, enacting the nearest secular equivalent to the death of God. Faust’s fate is also secularized. Instead of being pulled down into a literal hell, he is fitted with a strait jacket and consigned to an insane asylum, a potent image of being reduced to a non-person. For good measure, he is also drowned in a way reminiscent of magicians’ clones from the film The Prestige—an apparent reference to themes of uncanny doubles and echoes of The Picture of Dorian Gray that unfolded in parts of the theater I was unable to find. There is, in short, a lot going on.

[Continue on to Part 2….]

FreshRSS 1.24.2

23 September 2024 at 22:49

This is a quality-focussed release for the 1.24.x series meant to provide a good product to people blocked on PHP 7.4, while we will increase the requirements to PHP 8.1+ from the next 1.25.x series.

A few highlights ✨:

  • New global option to automatically add articles to favourites
  • New option to share articles from the article title line
  • Add core extensions, shipped by default: UserCSS and UserJS
  • Security: Force log out of users when they are disabled
  • Many bug and regression fixes

This release has been made by @Alkarex, @ColonelMoutarde, @den13501, @hkcomori, @math-GH
and newcomers @dservian, @crisukbot, @TomW1605

Full changelog:

  • Features
    • New global option to automatically add articles to favourites #6648
    • New possibility to share a user query in JSON GReader format #6655
    • New fields image and description for user query share #6541
    • Show article first words when an article title is empty #6240
    • New option to share articles from the article title line #6395
    • Improve JSON Dot Notation module to access more string-friendly types #6631
    • Improve detection of image types for enclosures not providing a type #6653
    • Add sharing to archive.is #6650
  • Security
    • Force log out of users when they are disabled #6612
    • Increase default values for OpenID Connect OIDCSessionMaxDuration and OIDCSessionInactivityTimeout #6642
    • Add default API CORS HTTP headers to shareable user queries #6659
  • Bug fixing
    • Fix parentheses for complex OR Boolean search expressions #6672
    • Fix keep max unread #6632
    • Fix regression in mark as read upon gone #6663
    • Fix regression on mark duplicate titles as read for modified articles #6664
    • Fix regression for Fever API, remove dependency to Exif extension #6624
    • Fix muted feeds for WebSub #6671
    • Fix performance / deadlock of PostgreSQL and MySQL / MariaDB during schema updates #6692
    • Fix HTTP cache of main page (regression since 1.18.0) #6719
    • Fix HTTP cache of shareable user queries #6718
    • Fix HTTP cache for feeds with modified Last-Modified when content is not modified #6723
  • Extensions
    • Add core extensions, shipped by default: UserCSS and UserJS #6267
      • Replaces CustomCSS and CustomCS extensions
    • Strong type array parameter helper #6661
  • CLI
    • Add quiet option to cli/db-backup.php #6593
  • Compatibility
  • Deployment
    • Docker default image (Debian 12 Bookworm) updated to PHP 8.2.20 and Apache 2.4.61
    • Docker alternative image updated to Alpine 3.20 with PHP 8.3.10 and Apache 2.4.62 #5383
    • Docker: Alpine dev image freshrss/freshrss:newest updated to PHP 8.4.0beta3 and Apache 2.4.62 #5764
  • UI
    • Default dark mode to auto #5582
    • New option to control action icons position in reading view #6297
    • Sticky buttons at the bottom of settings #6304
    • Various UI and style improvements #6446, #6485,
      #6651
  • I18n
    • Czech: use correct ISO 639-1 code cs (and not cz, which is the country) #6514
    • Improve Japanese #6564
    • Improve Spanish #6634
    • Improve Traditional Chinese #6691
  • Misc.

Seven Historic London Hotels for Cocktails

15 August 2024 at 20:16

The best historic London hotels seamlessly merge the city’s past with its present, leaving clients to contemplate a bygone era over modern day cocktails. Some have been hotels since their […]

The post Seven Historic London Hotels for Cocktails appeared first on Paris • Cocktails • Bars.

On drawing lines

13 August 2024 at 22:27

I’m gratified at the response yesterday’s post has received. It always makes one nervous to criticize what we used to call “political correctness,” because it can both open one up to unfair attacks and make one “sound like” bad political actors. The fact that I only really saw one response that appeared to conflate my critique of “political correctness” with a South Park-style advocacy of using offensive terms for their own sake was promising in this context. It seems like people really are tired of — quite literally exhausted by — this style of ostentatious self-righteous nitpicking. Nevertheless, for my own peace of mind I’d like to make it a little more explicit where I “draw the line” between the kind of common-sense courtesy and sensitivity we should all display and the kind of self-defeating signalling that we should try to avoid.

One clear case came out of a Facebook thread where one individual shared their gut-level offense at the term “moron” and their disappointment that I used that term as an example of PC overreach. In point of fact, I have eliminated “moron” from my everyday language, because I’m aware that those sensitivities exist. I believe they have been actively cultivated in a way that is ultimately counterproductive, but I can’t undo the fact that people have those sensitivities and there is no reason for me to offend them needlessly. I apologized for causing offense to that individual. By contrast, there was one time several years ago that I slipped up and used the word “moron” in a tweet, and a stranger — with no apparent connection to the disability community — direct-messaged me that such language could be offensive. When I shared my view that disability activists had actively cultivated those associations and created an occasion for offense where one needn’t exist, this person said they actually agreed with me.

To me, these two conversations are a teachable moment. One person was speaking on their own behalf, sharing that their experience and situation made a certain term hurtful to them. The other was speaking on behalf of a purely hypothetical other person who may potentially take offense. Basically, I think we should all respond with generosity and compassion to the former and we should stop doing the latter. We can perhaps think of other examples along these lines. For instance, it’s clear to me that all white people should treat the N-word as completely forbidden and taboo. There is no circumstance under which they should utter it, and they should call out their fellow white people if one of them breaks this taboo. By contrast, for a white person to correct a fellow white person who is still using the slightly outdated “African American” instead of the more current “Black” strikes me as not worth it.

Obviously in some sense the taboo against white people using the N-word is speaking on behalf of someone else — but it’s also speaking on behalf of oneself. We should all be offended by racism. It is a false and destructive pattern of belief and behavior that has no place in our shared life. We should not want to be racist and we should create conditions under which others do not feel comfortable being racist. It’s not only about not gravely offending Black people — though that is also urgently important. It’s also about what kind of person you want to be. Not keeping up with whether “Black” or “African American” is the preferred usage does not seem to have the same moral weight. (In fact, many older white people probably lived through a time when “Black” seemed vaguely insulting and “African American” was meant to signal greater respect.)

The case is clearer when some new coinage or practice is instituted. The odds that these innovations are responding to actual demands or even desires of the group in question are, in my experience, very very small. Even if members of thoses groups contributed to the proposed new norm, they likely represent an elite, unrepresentative strata of that community. A term like “Latinx,” for instance, clearly does not emerge organically out of the self-understanding of communities of Latin American descent. It is an ugly neologism that aims to “solve” the perceived problem that “Latino” does not appear sufficiently gender-inclusive from an Anglophone perspective. (I’ve also seen “Latin@,” which… a crucial aspect of words is that you have to be able to say them.)

Similarly, I’m not convinced that most land acknowledgments actually arise from genuine dialogue with the affect indigenous peoples — presumably many of them are based on internet searches for which tribes used to occupy a certain area, etc. If no one is asking for these acknowledgments and if no concrete change in practice results (is anyone doing land acknowledgments in the Chicago area actually reimbursing the Potawatomi People for the use of their unceded land, for example?), then I’m not sure what we’re trying to accomplish other than performing a certain “best practices” of righteousness. Of course, I can only assume that some land acknowledgments do result from such dialogue and engagement — but the awkwardly ritualistic nature of the practice leads me to believe that the vast majority of them represent a form of trend following.

I don’t presume to be the final arbiter on such matters. But that’s kind of my point — there can be no final decision of “where to draw the line.” We’re all just human beings and we need to negotiate a way to live together. The “politically correct” style of social justice denies that. It tries to set up in advance what the rules of engagement will be, often unilaterally on behalf of the very people it is supposedly empowering. But there is no system that is not gameable, no language that can’t be used to hurt. We all know people who have used politically correct categories to shame and silence others for individual gain or simply for the enjoyment of a power trip. We shouldn’t be afraid to call bullshit on that kind of behavior, and for too long we mostly have been.

To be sure, many people who reject political correctness (and especially those who deploy the term “woke”) are bad actors who simply resent that they aren’t allowed to make racist and sexist jokes anymore. But many are potentially reachable people who were turned off by the alienating neologisms and bad faith power plays — and when we can’t acknowledge that, especially when we conflate such excesses with “common sense” courtesy and respect, we are hurting the cause.

Again, to my mind the current messaging from the Democrats is well on “this side” of that line. They hold Trump, Vance, and their cronies up to ridicule for their blatant racism and sexism and homophobia. They presuppose that such attitudes and behaviors are unacceptable and expect their audience to agree — and the vast majority of Americans do agree. But more than that, rather than associating them with an inescapable all-pervading power, they present such attitudes and behaviors as ultimately pathetic. Look at these fools — why are they like that? Why would anyone want to be like that? In short, they respond like humans and invite their audience to respond like humans. That’s what makes it such a breath of fresh air compared to the kind of HR-inflected social justice jargon that has dominated such discussions for too long.

“Weird” conservatives and the end of whiny self-righteousness

12 August 2024 at 15:52

In the wake of Biden’s withdrawal from the race and Kamala Harris’s shockingly rapid and decisive ascension, I have begun feeling emotions that I haven’t allowed myself to feel in connection to politics in a long time: hope, excitement, even enjoyment. As many commentators have noted, there is a joyfulness, even a level of fun, to Harris’s campaign that is an almost shocking contrast to what came before. The fact that they are playing along with the JD Vance couch meme may be the clearest sign that they are in tune with contemporary culture, but the more general pattern of calling conservative leaders “weird” and “creepy” feels like a major turning point — not just in terms of political tactics, but in terms of liberal political culture. It marks the end of a certain fatalistic defensiveness on the one hand, and also of the joylessly self-righteous habits of policing and shaming allies on the left.

For all my life, conservatives have been the norm. Everybody (who matters) feels at best very uncomfortable about abortion and non-normative sexuality. Everybody (who matters) resents the burden of funding high-quality public service. Etc., etc., etc. Tactical observations from the early 90s hardened into inescapable truisms, even as they became less and less true. This produced a permanent defensive crouch, as Democrats seemed to believe that Republican rule was the norm and they could at best eke out a narrow win to take their turn — at passing a more nuanced and “smarter” version of Republican policies. Priority number one after each victory was to get bipartisan support, as though Democrats didn’t believe it was legitimate for them to legislate on their own. Attachment to the fillibuster rule among the older cohort of Democratic senators is the most destructive example of this built-in defeatism.

So the new confidence of the Harris campaign is refreshing, as is the contempt and puzzlement they express at conservatives’ increasingly unpopular and downright bizarre beliefs. More specifically, what is refreshing here is their willingness to be mean, to insult, to reduce their opponents to sputtering speechlessness. I cannot emphasize enough how much of a break this is with the joylessly self-righteous policing of language that has been the norm among liberals and leftists for my entire adult life. From that perspective, the parody responses write themselves — “we shouldn’t kink-shame JD Vance…” or “Republican leaders won’t read your post calling them weird, but your friends who could be viewed as weird for completely unrelated and totally harmless reasons will…” — and the fact that it’s so easy to come up with them shows how that mode of engagement has reduced itself to self-parody.

A key shift for me when I saw a white man worrying aloud about the tendency to refer to Vice President Harris as “Kamala” — there is of course a whole history of belittling people by refusing the respect of their last name, it’s especially fraught since she’s a Black woman, etc., etc. And I will be honest with you and say my first response was that this person should simply shut the fuck up. “Kamala” is a very distinctive name, whereas “Harris” is not. Her own social media team is called “Kamala HQ.” We do not need to get out ahead of the supposed “victim” herself.

More broadly, though, my strong gut reaction reflected my belief that we have just got to be done with this style of whiny preemptive strike against any hypothetical offense that may one day be perceived. Political correctness is a strategy that has failed. Aside from eliminating the grossest slurs and overtly bigoted jokes — which even conservatives themselves know not to share in mixed company — it has produced only irritation and insecurity.

People like to present it as simple common sense, but the euphemism treadmill and, more than that, the constant incentive to find ever more nuances of linguistic “oppression” ensure that the politically correct linguistic norms can never actually settle into a coherent common sense. It produces bristly defensiveness in those who can’t keep up and an unhealthy and counterproductive readiness to be offended among the avant-garde. My favorite example of the counterproductive nature of such language policing is the fact that disability activists are more or less singlehandedly keeping alive the etymological association of words like “moron” with disability. Linguistic usage moves on — take the win! But no, etymology is destiny when it gives you something to nitpick and alienate potential allies over.

Related here, I think, is the culture of constantly nitpicking headlines from the New York Times on social media. Again, the belief is that politics will take care of itself if everyone agrees to speak in just the right way. Obviously, the New York Times is a bad actor in many ways and the media establishment is artificially propping up Trump through the application of double standards. They are worthy of critique, but the obsessiveness and detail-orientation of the critique is what raises my hackles. It bespeaks a whiny wounded entitlement, as though we all believe that the New York Times should be a liberal actor or that a simple description of reality would automatically favor our politics.

In reality, to do politics, you have to do politics. The media is not an umpire, it is a terrain of struggle. The Harris campaign is engaging that struggle much more effectively than Joe Biden ever could because it does not embrace the false premise that the New York Times is or should be on her side by default. And she has received overwhelmingly favorable coverage! Not 100% — there is always something to whine about, of course. They don’t always put the word “falsely” in the headline, and sometimes they take too long describing Trump or Vance’s claims before debunking them. They achieved that not by whining about how unfair the Times has been, but by actively setting the agenda and setting the tone.

And that tone is mean. It is contemptuous. It aims to harm Trump and Vance and their reputations. It aims to make them personally angry and make people question their loyalty to such deeply flawed men. To achieve these goals, it is not overly concerned about petty details like whether JD Vance really engaged in an elaborate form of masturbation involving his furniture and described it at length in his memoir — much less whether other furniture-masturbation enthusiasts might be collateral damage of the joke. The joy and humor and fun of the Harris campaign, the way that it acknowledges the Republicans as enemies without setting them up as all-powerful, hopefully marks a decisive end to that kind of idiocy. From now on, entitlement and prickly defensiveness can remain in its more natural home — among the washed up losers who have coasted on white male privilege so long and spent so much time in the “safe space” of their ideological bubble that they don’t realize how pathetic they appear to anyone halfway normal — because eventually everyone complaining about unfair media coverage and moaning about how they aren’t being shown the proper respect will realize that… they sound like Trump.

The Coming Software Apocalypse

24 July 2024 at 09:33
estimated reading time: 49 min

There were six hours during the night of April 10, 2014, when the entire population of Washington State had no 911 service. People who called for help got a busy signal. One Seattle woman dialed 911 at least 37 times while a stranger was trying to break into her house. When he finally crawled into her living room through a window, she picked up a kitchen knife. The man fled.

To hear more feature stories, see our full list or get the Audm iPhone app.

The 911 outage, at the time the largest ever reported, was traced to software running on a server in Englewood, Colorado. Operated by a systems provider named Intrado, the server kept a running counter of how many calls it had routed to 911 dispatchers around the country. Intrado programmers had set a threshold for how high the counter could go. They picked a number in the millions.

Shortly before midnight on April 10, the counter exceeded that number, resulting in chaos. Because the counter was used to generate a unique identifier for each call, new calls were rejected. And because the programmers hadn’t anticipated the problem, they hadn’t created alarms to call attention to it. Nobody knew what was happening. Dispatch centers in Washington, California, Florida, the Carolinas, and Minnesota, serving 11 million Americans, struggled to make sense of reports that callers were getting busy signals. It took until morning to realize that Intrado’s software in Englewood was responsible, and that the fix was to change a single number.

Not long ago, emergency calls were handled locally. Outages were small and easily diagnosed and fixed. The rise of cellphones and the promise of new capabilities—what if you could text 911? or send videos to the dispatcher?—drove the development of a more complex system that relied on the internet. For the first time, there could be such a thing as a national 911 outage. There have now been four in as many years.

It’s been said that software is “eating the world.” More and more, critical systems that were once controlled mechanically, or by people, are coming to depend on code. This was perhaps never clearer than in the summer of 2015, when on a single day, United Airlines grounded its fleet because of a problem with its departure-management system; trading was suspended on the New York Stock Exchange after an upgrade; the front page of The Wall Street Journal’s website crashed; and Seattle’s 911 system went down again, this time because a different router failed. The simultaneous failure of so many software systems smelled at first of a coordinated cyberattack. Almost more frightening was the realization, late in the day, that it was just a coincidence.

“When we had electromechanical systems, we used to be able to test them exhaustively,” says Nancy Leveson, a professor of aeronautics and astronautics at the Massachusetts Institute of Technology who has been studying software safety for 35 years. She became known for her report on the Therac-25, a radiation-therapy machine that killed six patients because of a software error. “We used to be able to think through all the things it could do, all the states it could get into.” The electromechanical interlockings that controlled train movements at railroad crossings, for instance, only had so many configurations; a few sheets of paper could describe the whole system, and you could run physical trains against each configuration to see how it would behave. Once you’d built and tested it, you knew exactly what you were dealing with.

Software is different. Just by editing the text in a file somewhere, the same hunk of silicon can become an autopilot or an inventory-control system. This flexibility is software’s miracle, and its curse. Because it can be changed cheaply, software is constantly changed; and because it’s unmoored from anything physical—a program that is a thousand times more complex than another takes up the same actual space—it tends to grow without bound. “The problem,” Leveson wrote in a book, “is that we are attempting to build systems that are beyond our ability to intellectually manage.”

Our standard framework for thinking about engineering failures—reflected, for instance, in regulations for medical devices—was developed shortly after World War II, before the advent of software, for electromechanical systems. The idea was that you make something reliable by making its parts reliable (say, you build your engine to withstand 40,000 takeoff-and-landing cycles) and by planning for the breakdown of those parts (you have two engines). But software doesn’t break. Intrado’s faulty threshold is not like the faulty rivet that leads to the crash of an airliner. The software did exactly what it was told to do. In fact it did it perfectly. The reason it failed is that it was told to do the wrong thing. Software failures are failures of understanding, and of imagination. Intrado actually had a backup router, which, had it been switched to automatically, would have restored 911 service almost immediately. But, as described in a report to the FCC, “the situation occurred at a point in the application logic that was not designed to perform any automated corrective actions.”

This is the trouble with making things out of code, as opposed to something physical. “The complexity,” as Leveson puts it, “is invisible to the eye.”

The attempts now underway to change how we make software all seem to start with the same premise: Code is too hard to think about. Before trying to understand the attempts themselves, then, it’s worth understanding why this might be: what it is about code that makes it so foreign to the mind, and so unlike anything that came before it.

Technological progress used to change the way the world looked—you could watch the roads getting paved; you could see the skylines rise. Today you can hardly tell when something is remade, because so often it is remade by code. When you press your foot down on your car’s accelerator, for instance, you’re no longer controlling anything directly; there’s no mechanical link from the pedal to the throttle. Instead, you’re issuing a command to a piece of software that decides how much air to give the engine. The car is a computer you can sit inside of. The steering wheel and pedals might as well be keyboard keys.

Like everything else, the car has been computerized to enable new features. When a program is in charge of the throttle and brakes, it can slow you down when you’re too close to another car, or precisely control the fuel injection to help you save on gas. When it controls the steering, it can keep you in your lane as you start to drift, or guide you into a parking space. You couldn’t build these features without code. If you tried, a car might weigh 40,000 pounds, an immovable mass of clockwork.

Software has enabled us to make the most intricate machines that have ever existed. And yet we have hardly noticed, because all of that complexity is packed into tiny silicon chips as millions and millions of lines of code. But just because we can’t see the complexity doesn’t mean that it has gone away.

The programmer, the renowned Dutch computer scientist Edsger Dijkstra wrote in 1988, “has to be able to think in terms of conceptual hierarchies that are much deeper than a single mind ever needed to face before.” Dijkstra meant this as a warning. As programmers eagerly poured software into critical systems, they became, more and more, the linchpins of the built world—and Dijkstra thought they had perhaps overestimated themselves.

What made programming so difficult was that it required you to think like a computer. The strangeness of it was in some sense more vivid in the early days of computing, when code took the form of literal ones and zeros. Anyone looking over a programmer’s shoulder as they pored over line after line like “100001010011” and “000010011110” would have seen just how alienated the programmer was from the actual problems they were trying to solve; it would have been impossible to tell whether they were trying to calculate artillery trajectories or simulate a game of tic-tac-toe. The introduction of programming languages like Fortran and C, which resemble English, and tools, known as “integrated development environments,” or IDEs, that help correct simple mistakes (like Microsoft Word’s grammar checker but for code), obscured, though did little to actually change, this basic alienation—the fact that the programmer didn’t work on a problem directly, but rather spent their days writing out instructions for a machine.

“The problem is that software engineers don’t understand the problem they’re trying to solve, and don’t care to,” says Leveson, the MIT software-safety expert. The reason is that they’re too wrapped up in getting their code to work. “Software engineers like to provide all kinds of tools and stuff for coding errors,” she says, referring to IDEs. “The serious problems that have happened with software have to do with requirements, not coding errors.” When you’re writing code that controls a car’s throttle, for instance, what’s important is the rules about when and how and by how much to open it. But these systems have become so complicated that hardly anyone can keep them straight in their head. “There’s 100 million lines of code in cars now,” Leveson says. “You just cannot anticipate all these things.”

In September 2007, Jean Bookout was driving on the highway with her best friend in a Toyota Camry when the accelerator seemed to get stuck. When she took her foot off the pedal, the car didn’t slow down. She tried the brakes but they seemed to have lost their power. As she swerved toward an off-ramp going 50 miles per hour, she pulled the emergency brake. The car left a skid mark 150 feet long before running into an embankment by the side of the road. The passenger was killed. Bookout woke up in a hospital a month later.

The incident was one of many in a nearly decade-long investigation into claims of so-called unintended acceleration in Toyota cars. Toyota blamed the incidents on poorly designed floor mats, “sticky” pedals, and driver error, but outsiders suspected that faulty software might be responsible. The National Highway Traffic Safety Administration enlisted software experts from NASA to perform an intensive review of Toyota’s code. After nearly 10 months, the NASA team hadn’t found evidence that software was the cause—but said they couldn’t prove it wasn’t.

It was during litigation of the Bookout accident that someone finally found a convincing connection. Michael Barr, an expert witness for the plaintiff, had a team of software experts spend 18 months with the Toyota code, picking up where NASA left off. Barr described what they found as “spaghetti code,” programmer lingo for software that has become a tangled mess. Code turns to spaghetti when it accretes over many years, with feature after feature piling on top of, and being woven around, what’s already there; eventually the code becomes impossible to follow, let alone to test exhaustively for flaws.

Using the same model as the Camry involved in the accident, Barr’s team demonstrated that there were more than 10 million ways for key tasks on the onboard computer to fail, potentially leading to unintended acceleration.* They showed that as little as a single bit flip—a one in the computer’s memory becoming a zero or vice versa—could make a car run out of control. The fail-safe code that Toyota had put in place wasn’t enough to stop it. “You have software watching the software,” Barr testified. “If the software malfunctions and the same program or same app that is crashed is supposed to save the day, it can’t save the day because it is not working.”

Barr’s testimony made the case for the plaintiff, resulting in $3 million in damages for Bookout and her friend’s family. According to The New York Times, it was the first of many similar cases against Toyota to bring to trial problems with the electronic throttle-control system, and the first time Toyota was found responsible by a jury for an accident involving unintended acceleration. The parties decided to settle the case before punitive damages could be awarded. In all, Toyota recalled more than 9 million cars, and paid nearly $3 billion in settlements and fines related to unintended acceleration.

There will be more bad days for software. It's important that we get better at making it, because if we don't, and as software becomes more sophisticated and connected—as it takes control of more critical functions—those days could get worse.

The problem is that programmers are having a hard time keeping up with their own creations. Since the 1980s, the way programmers work and the tools they use have changed remarkably little. There is a small but growing chorus that worries the status quo is unsustainable. “Even very good programmers are struggling to make sense of the systems that they are working with,” says Chris Granger, a software developer who worked as a lead at Microsoft on Visual Studio, an IDE that costs $1,199 a year and is used by nearly a third of all professional programmers. He told me that while he was at Microsoft, he arranged an end-to-end study of Visual Studio, the only one that had ever been done. For a month and a half, he watched behind a one-way mirror as people wrote code. “How do they use tools? How do they think?” he said. “How do they sit at the computer, do they touch the mouse, do they not touch the mouse? All these things that we have dogma around that we haven’t actually tested empirically.”

The findings surprised him. “Visual Studio is one of the single largest pieces of software in the world,” he said. “It’s over 55 million lines of code. And one of the things that I found out in this study is more than 98 percent of it is completely irrelevant. All this work had been put into this thing, but it missed the fundamental problems that people faced. And the biggest one that I took away from it was that basically people are playing computer inside their head.” Programmers were like chess players trying to play with a blindfold on—so much of their mental energy is spent just trying to picture where the pieces are that there’s hardly any left over to think about the game itself.

John Resig had been noticing the same thing among his students. Resig is a celebrated programmer of JavaScript—software he wrote powers over half of all websites—and a tech lead at the online-education site Khan Academy. In early 2012, he had been struggling with the site’s computer-science curriculum. Why was it so hard to learn to program? The essential problem seemed to be that code was so abstract. Writing software was not like making a bridge out of popsicle sticks, where you could see the sticks and touch the glue. To “make” a program, you typed words. When you wanted to change the behavior of the program, be it a game, or a website, or a simulation of physics, what you actually changed was text. So the students who did well—in fact the only ones who survived at all—were those who could step through that text one instruction at a time in their head, thinking the way a computer would, trying to keep track of every intermediate calculation. Resig, like Granger, started to wonder if it had to be that way. Computers had doubled in power every 18 months for the last 40 years. Why hadn’t programming changed?

The fact that the two of them were thinking about the same problem in the same terms, at the same time, was not a coincidence. They had both just seen the same remarkable talk, given to a group of software-engineering students in a Montreal hotel by a computer researcher named Bret Victor. The talk, which went viral when it was posted online in February 2012, seemed to be making two bold claims. The first was that the way we make software is fundamentally broken. The second was that Victor knew how to fix it.

Bret Victor does not like to write code. “It sounds weird,” he says. “When I want to make a thing, especially when I want to create something in software, there’s this initial layer of disgust that I have to push through, where I’m not manipulating the thing that I want to make, I’m writing a bunch of text into a text editor.”

“There’s a pretty strong conviction that that’s the wrong way of doing things.”

Victor has the mien of David Foster Wallace, with a lightning intelligence that lingers beneath a patina of aw-shucks shyness. He is 40 years old, with traces of gray and a thin, undeliberate beard. His voice is gentle, mournful almost, but he wants to share what’s in his head, and when he gets on a roll he’ll seem to skip syllables, as though outrunning his own vocal machinery.

Though he runs a lab that studies the future of computing, he seems less interested in technology per se than in the minds of the people who use it. Like any good toolmaker, he has a way of looking at the world that is equal parts technical and humane. He graduated top of his class at the California Institute of Technology for electrical engineering, and then went on, after grad school at the University of California, Berkeley, to work at a company that develops music synthesizers. It was a problem perfectly matched to his dual personality: He could spend as much time thinking about the way a performer makes music with a keyboard—the way it becomes an extension of their hands—as he could thinking about the mathematics of digital signal processing.

By the time he gave the talk that made his name, the one that Resig and Granger saw in early 2012, Victor had finally landed upon the principle that seemed to thread through all of his work. (He actually called the talk “Inventing on Principle.”) The principle was this: “Creators need an immediate connection to what they’re creating.” The problem with programming was that it violated the principle. That’s why software systems were so hard to think about, and so rife with bugs: The programmer, staring at a page of text, was abstracted from whatever it was they were actually making.

“Our current conception of what a computer program is,” he said, is “derived straight from Fortran and ALGOL in the late ’50s. Those languages were designed for punch cards.” That code now takes the form of letters on a screen in a language like C or Java (derivatives of Fortran and ALGOL), instead of a stack of cards with holes in it, doesn’t make it any less dead, any less indirect.

There is an analogy to word processing. It used to be that all you could see in a program for writing documents was the text itself, and to change the layout or font or margins, you had to write special “control codes,” or commands that would tell the computer that, for instance, “this part of the text should be in italics.” The trouble was that you couldn’t see the effect of those codes until you printed the document. It was hard to predict what you were going to get. You had to imagine how the codes were going to be interpreted by the computer—that is, you had to play computer in your head.

Then WYSIWYG (pronounced “wizzywig”) came along. It stood for “What You See Is What You Get.” When you marked a passage as being in italics, the letters tilted right there on the screen. If you wanted to change the margin, you could drag a ruler at the top of the screen—and see the effect of that change. The document thereby came to feel like something real, something you could poke and prod at. Just by looking you could tell if you’d done something wrong. Control of a sophisticated system—the document’s layout and formatting engine—was made accessible to anyone who could click around on a page.

Victor’s point was that programming itself should be like that. For him, the idea that people were doing important work, like designing adaptive cruise-control systems or trying to understand cancer, by staring at a text editor, was appalling. And it was the proper job of programmers to ensure that someday they wouldn’t have to.

There was precedent enough to suggest that this wasn’t a crazy idea. Photoshop, for instance, puts powerful image-processing algorithms in the hands of people who might not even know what an algorithm is. It’s a complicated piece of software, but complicated in the way a good synth is complicated, with knobs and buttons and sliders that the user learns to play like an instrument. Squarespace, a company that is perhaps best known for advertising aggressively on podcasts, makes a tool that lets users build websites by pointing and clicking, instead of by writing code in HTML and CSS. It is powerful enough to do work that once would have been done by a professional web designer.

But those were just a handful of examples. The overwhelming reality was that when someone wanted to do something interesting with a computer, they had to write code. Victor, who is something of an idealist, saw this not so much as an opportunity but as a moral failing of programmers at large. His talk was a call to arms.

At the heart of it was a series of demos that tried to show just how primitive the available tools were for various problems—circuit design, computer animation, debugging algorithms—and what better ones might look like. His demos were virtuosic. The one that captured everyone’s imagination was, ironically enough, the one that on its face was the most trivial. It showed a split screen with a game that looked like Mario on one side and the code that controlled it on the other. As Victor changed the code, things in the game world changed: He decreased one number, the strength of gravity, and the Mario character floated; he increased another, the player’s speed, and Mario raced across the screen.

Suppose you wanted to design a level where Mario, jumping and bouncing off of a turtle, would just make it into a small passageway. Game programmers were used to solving this kind of problem in two stages: First, you stared at your code—the code controlling how high Mario jumped, how fast he ran, how bouncy the turtle’s back was—and made some changes to it in your text editor, using your imagination to predict what effect they’d have. Then, you’d replay the game to see what actually happened.

Shadow Marios move on the left half of a screen as a mouse drags sliders on the right half.
CUSEC / Vimeo

Victor wanted something more immediate. “If you have a process in time,” he said, referring to Mario’s path through the level, “and you want to see changes immediately, you have to map time to space.” He hit a button that showed not just where Mario was right now, but where he would be at every moment in the future: a curve of shadow Marios stretching off into the far distance. What’s more, this projected path was reactive: When Victor changed the game’s parameters, now controlled by a quick drag of the mouse, the path’s shape changed. It was like having a god’s-eye view of the game. The whole problem had been reduced to playing with different parameters, as if adjusting levels on a stereo receiver, until you got Mario to thread the needle. With the right interface, it was almost as if you weren’t working with code at all; you were manipulating the game’s behavior directly.

When the audience first saw this in action, they literally gasped. They knew they weren’t looking at a kid’s game, but rather the future of their industry. Most software involved behavior that unfolded, in complex ways, over time, and Victor had shown that if you were imaginative enough, you could develop ways to see that behavior and change it, as if playing with it in your hands. One programmer who saw the talk wrote later: “Suddenly all of my tools feel obsolete.”

When John Resig saw the “Inventing on Principle” talk, he scrapped his plans for the Khan Academy programming curriculum. He wanted the site’s programming exercises to work just like Victor’s demos. On the left-hand side you’d have the code, and on the right, the running program: a picture or game or simulation. If you changed the code, it’d instantly change the picture. “In an environment that is truly responsive,” Resig wrote about the approach, “you can completely change the model of how a student learns ... [They] can now immediately see the result and intuit how underlying systems inherently work without ever following an explicit explanation.” Khan Academy has become perhaps the largest computer-programming class in the world, with a million students, on average, actively using the program each month.

Chris Granger, who had worked at Microsoft on Visual Studio, was likewise inspired. Within days of seeing a video of Victor’s talk, in January of 2012, he built a prototype of a new programming environment. Its key capability was that it would give you instant feedback on your program’s behavior. You’d see what your system was doing right next to the code that controlled it. It was like taking off a blindfold. Granger called the project “Light Table.”

In April of 2012, he sought funding for Light Table on Kickstarter. In programming circles, it was a sensation. Within a month, the project raised more than $200,000. The ideas spread. The notion of liveness, of being able to see data flowing through your program instantly, made its way into flagship programming tools offered by Google and Apple. The default language for making new iPhone and Mac apps, called Swift, was developed by Apple from the ground up to support an environment, called Playgrounds, that was directly inspired by Light Table.

But seeing the impact that his talk ended up having, Bret Victor was disillusioned. “A lot of those things seemed like misinterpretations of what I was saying,” he said later. He knew something was wrong when people began to invite him to conferences to talk about programming tools. “Everyone thought I was interested in programming environments,” he said. Really he was interested in how people see and understand systems—as he puts it, in the “visual representation of dynamic behavior.” Although code had increasingly become the tool of choice for creating dynamic behavior, it remained one of the worst tools for understanding it. The point of “Inventing on Principle” was to show that you could mitigate that problem by making the connection between a system’s behavior and its code immediate.

In a pair of later talks, “Stop Drawing Dead Fish” and “Drawing Dynamic Visualizations,” Victor went one further. He demoed two programs he’d built—the first for animators, the second for scientists trying to visualize their data—each of which took a process that used to involve writing lots of custom code and reduced it to playing around in a WYSIWYG interface. Victor suggested that the same trick could be pulled for nearly every problem where code was being written today. “I’m not sure that programming has to exist at all,” he told me. “Or at least software developers.” In his mind, a software developer’s proper role was to create tools that removed the need for software developers. Only then would people with the most urgent computational problems be able to grasp those problems directly, without the intermediate muck of code.

Of course, to do that, you’d have to get programmers themselves on board. In a recent essay, Victor implored professional software developers to stop pouring their talent into tools for building apps like Snapchat and Uber. “The inconveniences of daily life are not the significant problems,” he wrote. Instead, they should focus on scientists and engineers—as he put it to me, “these people that are doing work that actually matters, and critically matters, and using really, really bad tools.” Exciting work of this sort, in particular a class of tools for “model-based design,” was already underway, he wrote, and had been for years, but most programmers knew nothing about it.

“If you really look hard at all the industrial goods that you’ve got out there, that you’re using, that companies are using, the only non-industrial stuff that you have inside this is the code.” Eric Bantégnie is the founder of Esterel Technologies (now owned by ANSYS), a French company that makes tools for building safety-critical software. Like Victor, Bantégnie doesn’t think engineers should develop large systems by typing millions of lines of code into an IDE. “Nobody would build a car by hand,” he says. “Code is still, in many places, handicraft. When you’re crafting manually 10,000 lines of code, that’s okay. But you have systems that have 30 million lines of code, like an Airbus, or 100 million lines of code, like your Tesla or high-end cars—that’s becoming very, very complicated.”

Bantégnie’s company is one of the pioneers in the industrial use of model-based design, in which you no longer write code directly. Instead, you create a kind of flowchart that describes the rules your program should follow (the “model”), and the computer generates code for you based on those rules. If you were making the control system for an elevator, for instance, one rule might be that when the door is open, and someone presses the button for the lobby, you should close the door and start moving the car. In a model-based design tool, you’d represent this rule with a small diagram, as though drawing the logic out on a whiteboard, made of boxes that represent different states—like “door open,” “moving,” and “door closed”—and lines that define how you can get from one state to the other. The diagrams make the system’s rules obvious: Just by looking, you can see that the only way to get the elevator moving is to close the door, or that the only way to get the door open is to stop.

It’s not quite Photoshop. The beauty of Photoshop, of course, is that the picture you’re manipulating on the screen is the final product. In model-based design, by contrast, the picture on your screen is more like a blueprint. Still, making software this way is qualitatively different than traditional programming. In traditional programming, your task is to take complex rules and translate them into code; most of your energy is spent doing the translating, rather than thinking about the rules themselves. In the model-based approach, all you have is the rules. So that’s what you spend your time thinking about. It’s a way of focusing less on the machine and more on the problem you’re trying to get it to solve.

“Typically the main problem with software coding—and I’m a coder myself,” Bantégnie says, “is not the skills of the coders. The people know how to code. The problem is what to code. Because most of the requirements are kind of natural language, ambiguous, and a requirement is never extremely precise, it’s often understood differently by the guy who’s supposed to code.”

On this view, software becomes unruly because the media for describing what software should do—conversations, prose descriptions, drawings on a sheet of paper—are too different from the media describing what software does do, namely, code itself. Too much is lost going from one to the other. The idea behind model-based design is to close the gap. The very same model is used both by system designers to express what they want and by the computer to automatically generate code.

Of course, for this approach to succeed, much of the work has to be done well before the project even begins. Someone first has to build a tool for developing models that are natural for people—that feel just like the notes and drawings they’d make on their own—while still being unambiguous enough for a computer to understand. They have to make a program that turns these models into real code. And finally they have to prove that the generated code will always do what it’s supposed to. “We have benefited from fortunately 20 years of initial background work,” Bantégnie says.

Esterel Technologies, which was acquired by ANSYS in 2012, grew out of research begun in the 1980s by the French nuclear and aerospace industries, who worried that as safety-critical code ballooned in complexity, it was getting harder and harder to keep it free of bugs. “I started in 1988,” says Emmanuel Ledinot, the Head of Scientific Studies for Dassault Aviation, a French manufacturer of fighter jets and business aircraft. “At the time, I was working on military avionics systems. And the people in charge of integrating the systems, and debugging them, had noticed that the number of bugs was increasing.” The 80s had seen a surge in the number of onboard computers on planes. Instead of a single flight computer, there were now dozens, each responsible for highly specialized tasks related to control, navigation, and communications. Coordinating these systems to fly the plane as data poured in from sensors and as pilots entered commands required a symphony of perfectly timed reactions. “The handling of these hundreds of and even thousands of possible events in the right order, at the right time,” Ledinot says, “was diagnosed as the main cause of the bug inflation.”

Ledinot decided that writing such convoluted code by hand was no longer sustainable. It was too hard to understand what it was doing, and almost impossible to verify that it would work correctly. He went looking for something new. “You must understand that to change tools is extremely expensive in a process like this,” he said in a talk. “You don’t take this type of decision unless your back is against the wall.”

He began collaborating with Gerard Berry, a computer scientist at INRIA, the French computing-research center, on a tool called Esterel—a portmanteau of the French for “real-time.” The idea behind Esterel was that while traditional programming languages might be good for describing simple procedures that happened in a predetermined order—like a recipe—if you tried to use them in systems where lots of events could happen at nearly any time, in nearly any order—like in the cockpit of a plane—you inevitably got a mess. And a mess in control software was dangerous. In a paper, Berry went as far as to predict that “low-level programming techniques will not remain acceptable for large safety-critical programs, since they make behavior understanding and analysis almost impracticable.”

Esterel was designed to make the computer handle this complexity for you. That was the promise of the model-based approach: Instead of writing normal programming code, you created a model of the system’s behavior—in this case, a model focused on how individual events should be handled, how to prioritize events, which events depended on which others, and so on. The model becomes the detailed blueprint that the computer would use to do the actual programming.

Ledinot and Berry worked for nearly 10 years to get Esterel to the point where it could be used in production. “It was in 2002 that we had the first operational software-modeling environment with automatic code generation,” Ledinot told me, “and the first embedded module in Rafale, the combat aircraft.” Today, the ANSYS SCADE product family (for “safety-critical application development environment”) is used to generate code by companies in the aerospace and defense industries, in nuclear power plants, transit systems, heavy industry, and medical devices. “My initial dream was to have SCADE-generated code in every plane in the world,” Bantégnie, the founder of Esterel Technologies, says, “and we’re not very far off from that objective.” Nearly all safety-critical code on the Airbus A380, including the system controlling the plane’s flight surfaces, was generated with ANSYS SCADE products.

Part of the draw for customers, especially in aviation, is that while it is possible to build highly reliable software by hand, it can be a Herculean effort. Ravi Shivappa, the VP of group software engineering at Meggitt PLC, an ANSYS customer which builds components for airplanes, like pneumatic fire detectors for engines, explains that traditional projects begin with a massive requirements document in English, which specifies everything the software should do. (A requirement might be something like, “When the pressure in this section rises above a threshold, open the safety valve, unless the manual-override switch is turned on.”) The problem with describing the requirements this way is that when you implement them in code, you have to painstakingly check that each one is satisfied. And when the customer changes the requirements, the code has to be changed, too, and tested extensively to make sure that nothing else was broken in the process.

The cost is compounded by exacting regulatory standards. The FAA is fanatical about software safety. The agency mandates that every requirement for a piece of safety-critical software be traceable to the lines of code that implement it, and vice versa. So every time a line of code changes, it must be retraced to the corresponding requirement in the design document, and you must be able to demonstrate that the code actually satisfies the requirement. The idea is that if something goes wrong, you’re able to figure out why; the practice brings order and accountability to large codebases. But, Shivappa says, “it’s a very labor-intensive process.” He estimates that before they used model-based design, on a two-year-long project only two to three months was spent writing code—the rest was spent working on the documentation.

As Bantégnie explains, the beauty of having a computer turn your requirements into code, rather than a human, is that you can be sure—in fact you can mathematically prove—that the generated code actually satisfies those requirements. Much of the benefit of the model-based approach comes from being able to add requirements on the fly while still ensuring that existing ones are met; with every change, the computer can verify that your program still works. You’re free to tweak your blueprint without fear of introducing new bugs. Your code is, in FAA parlance, “correct by construction.”

Still, most software, even in the safety-obsessed world of aviation, is made the old-fashioned way, with engineers writing their requirements in prose and programmers coding them up in a programming language like C. As Bret Victor made clear in his essay, model-based design is relatively unusual. “A lot of people in the FAA think code generation is magic, and hence call for greater scrutiny,” Shivappa told me.

Most programmers feel the same way. They like code. At least they understand it. Tools that write your code for you and verify its correctness using the mathematics of “finite-state machines” and “recurrent systems” sound esoteric and hard to use, if not just too good to be true.

It is a pattern that has played itself out before. Whenever programming has taken a step away from the writing of literal ones and zeros, the loudest objections have come from programmers. Margaret Hamilton, a celebrated software engineer on the Apollo missions—in fact the coiner of the phrase “software engineering”—told me that during her first year at the Draper lab at MIT, in 1964, she remembers a meeting where one faction was fighting the other about transitioning away from “some very low machine language,” as close to ones and zeros as you could get, to “assembly language.” “The people at the lowest level were fighting to keep it. And the arguments were so similar: ‘Well how do we know assembly language is going to do it right?’”

“Guys on one side, their faces got red, and they started screaming,” she said. She said she was “amazed how emotional they got.”

Emmanuel Ledinot, of Dassault Aviation, pointed out that when assembly language was itself phased out in favor of the programming languages still popular today, like C, it was the assembly programmers who were skeptical this time. No wonder, he said, that “people are not so easily transitioning to model-based software development: They perceive it as another opportunity to lose control, even more than they have already.”

The bias against model-based design, sometimes known as model-driven engineering, or MDE, is in fact so ingrained that according to a recent paper, “Some even argue that there is a stronger need to investigate people’s perception of MDE than to research new MDE technologies.”

Which sounds almost like a joke, but for proponents of the model-based approach, it’s an important point: We already know how to make complex software reliable, but in so many places, we’re choosing not to. Why?

In 2011, Chris Newcombe had been working at Amazon for almost seven years, and had risen to be a principal engineer. He had worked on some of the company’s most critical systems, including the retail-product catalog and the infrastructure that managed every Kindle device in the world. He was a leader on the highly prized Amazon Web Services team, which maintains cloud servers for some of the web’s biggest properties, like Netflix, Pinterest, and Reddit. Before Amazon, he’d helped build the backbone of Steam, the world’s largest online-gaming service. He is one of those engineers whose work quietly keeps the internet running. The products he’d worked on were considered massive successes. But all he could think about was that buried deep in the designs of those systems were disasters waiting to happen.

“Human intuition is poor at estimating the true probability of supposedly ‘extremely rare’ combinations of events in systems operating at a scale of millions of requests per second,” he wrote in a paper. “That human fallibility means that some of the more subtle, dangerous bugs turn out to be errors in design; the code faithfully implements the intended design, but the design fails to correctly handle a particular ‘rare’ scenario.”

Newcombe was convinced that the algorithms behind truly critical systems—systems storing a significant portion of the web’s data, for instance—ought to be not just good, but perfect. A single subtle bug could be catastrophic. But he knew how hard bugs were to find, especially as an algorithm grew more complex. You could do all the testing you wanted and you’d never find them all.

This is why he was so intrigued when, in the appendix of a paper he’d been reading, he came across a strange mixture of math and code—or what looked like code—that described an algorithm in something called “TLA+.” The surprising part was that this description was said to be mathematically precise: An algorithm written in TLA+ could in principle be proven correct. In practice, it allowed you to create a realistic model of your problem and test it not just thoroughly, but exhaustively. This was exactly what he’d been looking for: a language for writing perfect algorithms.

TLA+, which stands for “Temporal Logic of Actions,” is similar in spirit to model-based design: It’s a language for writing down the requirements—TLA+ calls them “specifications”—of computer programs. These specifications can then be completely verified by a computer. That is, before you write any code, you write a concise outline of your program’s logic, along with the constraints you need it to satisfy (say, if you were programming an ATM, a constraint might be that you can never withdraw the same money twice from your checking account). TLA+ then exhaustively checks that your logic does, in fact, satisfy those constraints. If not, it will show you exactly how they could be violated.

The language was invented by Leslie Lamport, a Turing Award–winning computer scientist. With a big white beard and scruffy white hair, and kind eyes behind large glasses, Lamport looks like he might be one of the friendlier professors at the American Hogwarts. Now at Microsoft Research, he is known as one of the pioneers of the theory of “distributed systems,” which describes any computer system made of multiple parts that communicate with each other. Lamport’s work laid the foundation for many of the systems that power the modern web.

For Lamport, a major reason today’s software is so full of bugs is that programmers jump straight into writing code. “Architects draw detailed plans before a brick is laid or a nail is hammered,” he wrote in an article. “But few programmers write even a rough sketch of what their programs will do before they start coding.” Programmers are drawn to the nitty-gritty of coding because code is what makes programs go; spending time on anything else can seem like a distraction. And there is a patient joy, a meditative kind of satisfaction, to be had from puzzling out the micro-mechanics of code. But code, Lamport argues, was never meant to be a medium for thought. “It really does constrain your ability to think when you’re thinking in terms of a programming language,” he says. Code makes you miss the forest for the trees: It draws your attention to the working of individual pieces, rather than to the bigger picture of how your program fits together, or what it’s supposed to do—and whether it actually does what you think. This is why Lamport created TLA+. As with model-based design, TLA+ draws your focus to the high-level structure of a system, its essential logic, rather than to the code that implements it.

Newcombe and his colleagues at Amazon would go on to use TLA+ to find subtle, critical bugs in major systems, including bugs in the core algorithms behind S3, regarded as perhaps the most reliable storage engine in the world. It is now used widely at the company. In the tiny universe of people who had ever used TLA+, their success was not so unusual. An intern at Microsoft used TLA+ to catch a bug that could have caused every Xbox in the world to crash after four hours of use. Engineers at the European Space Agency used it to rewrite, with 10 times less code, the operating system of a probe that was the first to ever land softly on a comet. Intel uses it regularly to verify its chips.

But TLA+ occupies just a small, far corner of the mainstream, if it can be said to take up any space there at all. Even to a seasoned engineer like Newcombe, the language read at first as bizarre and esoteric—a zoo of symbols. For Lamport, this is a failure of education. Though programming was born in mathematics, it has since largely been divorced from it. Most programmers aren’t very fluent in the kind of math—logic and set theory, mostly—that you need to work with TLA+. “Very few programmers—and including very few teachers of programming—understand the very basic concepts and how they’re applied in practice. And they seem to think that all they need is code,” Lamport says. “The idea that there’s some higher level than the code in which you need to be able to think precisely, and that mathematics actually allows you to think precisely about it, is just completely foreign. Because they never learned it.”

Lamport sees this failure to think mathematically about what they’re doing as the problem of modern software development in a nutshell: The stakes keep rising, but programmers aren’t stepping up—they haven’t developed the chops required to handle increasingly complex problems. “In the 15th century,” he said, “people used to build cathedrals without knowing calculus, and nowadays I don’t think you’d allow anyone to build a cathedral without knowing calculus. And I would hope that after some suitably long period of time, people won’t be allowed to write programs if they don’t understand these simple things.”

Newcombe isn’t so sure that it’s the programmer who is to blame. “I’ve heard from Leslie that he thinks programmers are afraid of math. I’ve found that programmers aren’t aware—or don’t believe—that math can help them handle complexity. Complexity is the biggest challenge for programmers.” The real problem in getting people to use TLA+, he said, was convincing them it wouldn’t be a waste of their time. Programmers, as a species, are relentlessly pragmatic. Tools like TLA+ reek of the ivory tower. When programmers encounter “formal methods” (so called because they involve mathematical, “formally” precise descriptions of programs), their deep-seated instinct is to recoil.

Most programmers who took computer science in college have briefly encountered formal methods. Usually they’re demonstrated on something trivial, like a program that counts up from zero; the student’s job is to mathematically prove that the program does, in fact, count up from zero.

“I needed to change people’s perceptions on what formal methods were,” Newcombe told me. Even Lamport himself didn’t seem to fully grasp this point: Formal methods had an image problem. And the way to fix it wasn’t to implore programmers to change—it was to change yourself. Newcombe realized that to bring tools like TLA+ to the programming mainstream, you had to start speaking their language.

For one thing, he said that when he was introducing colleagues at Amazon to TLA+ he would avoid telling them what it stood for, because he was afraid the name made it seem unnecessarily forbidding: “Temporal Logic of Actions” has exactly the kind of highfalutin ring to it that plays well in academia, but puts off most practicing programmers. He tried also not to use the terms “formal,” “verification,” or “proof,” which reminded programmers of tedious classroom exercises. Instead, he presented TLA+ as a new kind of “pseudocode,” a stepping-stone to real code that allowed you to exhaustively test your algorithms—and that got you thinking precisely early on in the design process. “Engineers think in terms of debugging rather than ‘verification,’” he wrote, so he titled his internal talk on the subject to fellow Amazon engineers “Debugging Designs.” Rather than bemoan the fact that programmers see the world in code, Newcombe embraced it. He knew he’d lose them otherwise. “I’ve had a bunch of people say, ‘Now I get it,’” Newcombe says.

He has since left Amazon for Oracle, where he’s been able to convince his new colleagues to give TLA+ a try. For him, using these tools is now a matter of responsibility. “We need to get better at this,” he said.

“I’m self-taught, been coding since I was nine, so my instincts were to start coding. That was my only—that was my way of thinking: You’d sketch something, try something, you’d organically evolve it.” In his view, this is what many programmers today still do. “They google, and they look on Stack Overflow” (a popular website where programmers answer each other’s technical questions) “and they get snippets of code to solve their tactical concern in this little function, and they glue it together, and iterate.”

“And that’s completely fine until you run smack into a real problem.”

In the summer of 2015, a pair of American security researchers, Charlie Miller and Chris Valasek, convinced that car manufacturers weren’t taking software flaws seriously enough, demonstrated that a 2014 Jeep Cherokee could be remotely controlled by hackers. They took advantage of the fact that the car’s entertainment system, which has a cellular connection (so that, for instance, you can start your car with your iPhone), was connected to more central systems, like the one that controls the windshield wipers, steering, acceleration, and brakes (so that, for instance, you can see guidelines on the rearview screen that respond as you turn the wheel). As proof of their attack, which they developed on nights and weekends, they hacked into Miller’s car while a journalist was driving it on the highway, and made it go haywire; the journalist, who knew what was coming, panicked when they cut the engines, forcing him to a slow crawl on a stretch of road with no shoulder to escape to.

Although they didn’t actually create one, they showed that it was possible to write a clever piece of software, a “vehicle worm,” that would use the onboard computer of a hacked Jeep Cherokee to scan for and hack others; had they wanted to, they could have had simultaneous access to a nationwide fleet of vulnerable cars and SUVs. (There were at least five Fiat Chrysler models affected, including the Jeep Cherokee.) One day they could have told them all to, say, suddenly veer left or cut the engines at high speed.

“We need to think about software differently,” Valasek told me. Car companies have long assembled their final product from parts made by hundreds of different suppliers. But where those parts were once purely mechanical, they now, as often as not, come with millions of lines of code. And while some of this code—for adaptive cruise control, for auto braking and lane assist—has indeed made cars safer (“The safety features on my Jeep have already saved me countless times,” says Miller), it has also created a level of complexity that is entirely new. And it has made possible a new kind of failure.

“There are lots of bugs in cars,” Gerard Berry, the French researcher behind Esterel, said in a talk. “It’s not like avionics—in avionics it’s taken very seriously. And it’s admitted that software is different from mechanics.” The automotive industry is perhaps among those that haven’t yet realized they are actually in the software business.

“We don’t in the automaker industry have a regulator for software safety that knows what it’s doing,” says Michael Barr, the software expert who testified in the Toyota case. NHTSA, he says, “has only limited software expertise. They’ve come at this from a mechanical history.” The same regulatory pressures that have made model-based design and code generation attractive to the aviation industry have been slower to come to car manufacturing. Emmanuel Ledinot, of Dassault Aviation, speculates that there might be economic reasons for the difference, too. Automakers simply can’t afford to increase the price of a component by even a few cents, since it is multiplied so many millionfold; the computers embedded in cars therefore have to be slimmed down to the bare minimum, with little room to run code that hasn’t been hand-tuned to be as lean as possible. “Introducing model-based software development was, I think, for the last decade, too costly for them.”

One suspects the incentives are changing. “I think the autonomous car might push them,” Ledinot told me—“ISO 26262 and the autonomous car might slowly push them to adopt this kind of approach on critical parts.” (ISO 26262 is a safety standard for cars published in 2011.) Barr said much the same thing: In the world of the self-driving car, software can’t be an afterthought. It can’t be built like today’s airline-reservation systems or 911 systems or stock-trading systems. Code will be put in charge of hundreds of millions of lives on the road and it has to work. That is no small task.

“Computing is fundamentally invisible,” Gerard Berry said in his talk. “When your tires are flat, you look at your tires, they are flat. When your software is broken, you look at your software, you see nothing.”

“So that’s a big problem.”


* This article originally stated that there were 10 million ways for the Toyota Camry to cause unintended acceleration. We regret the error.

About the Author

James Somers is a former contributing editor at The Atlantic.
❌