@kentindell @OliverNoble @nuthatch @danluu
Part of safety is not pushing an update that breaks the system in the first place.
Plus when an update is performed >>NOT PUSHED<<, the system verifies that it received the update correctly, checks signatures, then runs the software.
If there is an error, it reverts to previous state >>WITHOUT USER INTERVENTION<<
A vehicle which fails to move because the Mfg pushed software is unsafe, not unreliable.
@johntimaeus @OliverNoble @nuthatch @danluu There’s way more to it than this.