logoalt Hacker News

freeli • yesterday at 10:39 PM • 21 replies • view on HN

A certain nuclear power plant had a Windows NT 4.0 machine running as late as 2007. The reason is interesting.

The machine's purpose was to report status of the control rods that mitigate nuclear reactions. Basically, "are the rods inserted, and if so, how many / how far?". I want to emphasize that this was reporting only, NOT control.

The original software was written back in the 80's, when the plant was originally commissioned, for AmigaOS. Of course, it's hard to buy Amigas anymore, and the original one died long ago (nobody remembers when).

So in the mid '90s, the utility purchased an AmigaOS emulator that ran on Windows NT 4.0, which was current at the time. The emulator (IIRC) was developed by a firm in the UK. The firm went out of business sometime in the late '90s. The control rod monitoring software ran under this emulator on top of NT4.

Windows NT 4.0 was the last OS to allow the emulation software direct access to the physical hardware that produced the status signal. Later versions of Windows abstracted the hardware access away, and the monitoring software broke. Because the emulation company had gone belly up, there was no way to fix the incompatibility.

So the utility had a choice: get new hardware/software certified (by NRC?), or keep doing what they were doing with the software (and hardware) that they had. They chose the latter.

So this is how, in 2007, during a tour of the facility, I stumbled across a Pentium 1 system running an AmigaOS emulator on Windows NT 4.0 that was responsible for displaying the status of the control rods of a nuclear power plant.

Spare hardware for this setup was purchased off of eBay and stocked on an adjacent shelf.


Replies

justin66 • today at 1:03 PM

To me the funny part of this story is that they used to show you this warning as part of the EULA when installing Windows NT 4, which I remember joking about:

NOTE ON JAVA SUPPORT. THE PRODUCT MAY CONTAIN SUPPORT FOR PROGRAMS WRITTEN IN JAVA. JAVA TECHNOLOGY IS NOT FAULT TOLERANT AND IS NOT DESIGNED, MANUFACTURED, OR INTENDED FOR USE OR RESALE AS ONLINE CONTROL EQUIPMENT IN HAZARDOUS ENVIRONMENTS REQUIRING FAIL-SAFE PERFORMANCE, SUCH AS IN THE OPERATION OF NUCLEAR FACILITIES, AIRCRAFT NAVIGATION OR COMMUNICATION SYSTEMS, AIR TRAFFIC CONTROL, DIRECT LIFE SUPPORT MACHINES, OR WEAPONS SYSTEMS, IN WHICH THE FAILURE OF JAVA TECHNOLOGY COULD LEAD DIRECTLY TO DEATH, PERSONAL INJURY, OR SEVERE PHYSICAL OR ENVIRONMENTAL DAMAGE. Sun Microsystems, Inc. has contractually obligated Microsoft to make this disclaimer.

Also:

The machine's purpose was to report status of the control rods that mitigate nuclear reactions. Basically, "are the rods inserted, and if so, how many / how far?". I want to emphasize that this was reporting only, NOT control.

It would take a whole lot more context to make this somehow comforting. :D

➕ show 1 reply
throwaway2037 • today at 10:49 AM

This is a great post. How does someone write software that needs to run for ~50 years where the hardware will need to be replaced with non-equivalent, newer hardware? If I were facing this issue today, I might start with an OS that has excellent emulation. Example: Can I run 32-bit MS Windows 95 via emulation on a variety of current 64-bit OSes, like MS Windows, Linux, AIX, HP-UX, etc. If yes, then we can assume(?) this emulation will remain relatively stable even if we upgrade our hardware later. Maybe I am overthinking the whole problem: Can VMs do exactly what I want today? Will VMs running ancient OSes, such as 32-bit MS Windows 95, continue to be stable/viable in the future? I am unsure.

➕ show 9 replies
Froedlich • today at 12:33 AM

A friend works for an airline as a flight simulator tech. Their entire software stack, including the compiler and OS, is FAA-certified.

Then their ancient Honeywell(?) mainframes reached end-of-life they scouted for compatible hardware, of which there was none. The cost of certifying new software, plus the time involved, was astronomical. So, after consulting with the FAA, they paid a hardware company to clone the ancient mainframes in modern silicon. The FAA signed off on it, and they had all-new computers - much smaller than the originals - running the old stack.

➕ show 3 replies
CobaltFire • yesterday at 10:47 PM

Having worked on nuclear plants (as a reactor operator) around that time this doesn't surprise me in the least.

Thats far more advanced than the systems I worked with, one of which reported rod position via resistance measurement on a brushed cylinder (one for angular and one for depth).

Cleaning and calibrating those was a constant maintenance item every time the reactor was shut down.

vkazanov • today at 6:42 PM

I grew up in a little post soviet republic, in a small town with a big nuclear power plant.

Coincidently, that's where my father was working as a programmer until the shutdown of the plant.

Anyways, he was maintaining a bunch of systems related to collecting data from environment monitoring sensors around the plant. In mid 2000s or so he showed me some data collecting machines using what looked like DOS text UI that mentioned being written in Leningrad, 1989 or 1988.

The software was running in an emulator on Linux, which my father used to replace original x86-compatible machines runninh dos.

Pretty sure thr whole thing was running for quite a while since my family moved elsewhere.

kccqzy • yesterday at 10:54 PM

Did they not need NRC recertification when they moved from a physical machine running AmigaOS to an AmigaOS emulator?

➕ show 1 reply
the__alchemist • today at 1:23 PM

It is wild to me that you would use any GPOS for something like this instead of dedicated firmware for the task. This is evoking similar reactions to when I read articles about infrastructure being hacked remotely: Something must have taken a wrong turn with the architecture design for this to happen!

vincent-manis • today at 1:37 AM

This reminds me of the apocryphal story of the IBM System/360 running a 1410 emulator that ran an IBM 705 simulator that ran a business-critical application.

➕ show 2 replies
tombert • today at 4:29 AM

I find it deeply upsetting that anything important for a nuclear power plant is using an OS without protected memory.

➕ show 2 replies
ikidd • yesterday at 11:44 PM

NT4.0 in 2007? That wasn't even very late. I was replacing NT4 servers into the early 10s. Car dealerships were terrible for keeping that crap around.

gerdesj • yesterday at 11:07 PM

"Windows NT 4.0 machine running as late as 2007"

lol. I know a ... factory, that had a BBC model B (with a rather complicated wiring loom) still doing a job around that time.

The IT supplier at the same factory went to a museum in Cambs. around late '90s, early '00s to ask if they could buy an exhibit because something had failed locally. The museum gave them the part.

That was just aerospace and nothing fancy like your nuke plant!

dahart • today at 3:05 PM

> A certain nuclear power plant had a Windows NT 4.0 machine running as late as 2007.

To put this in perspective, NT 4 was released in 1996, 11 years before 2007. That’s roughly the same as someone running Windows 10 today, which a lot of people still do. The Pentium 1 was only 14 years old at most. These parts of the system shouldn’t be surprising.

The AmigaOS and software from the 80s are of course the older more interesting bits, but for critical infrastructure and safety, shouldn’t we expect and design for our hardware and software to last a long time, and not try to keep up with tech fads every decade? I feel like the main problem isn’t hardware or software that’s old, but that there wasn’t a longevity plan.

It’s always been an interesting question how to write software that will last a hundred years. Maybe with AI this is the first time in history that planning to port & upgrade to new hardware every 5-10 years seems totally reasonable.

➕ show 1 reply
rkagerer • today at 2:23 PM

Nothing wrong with this.

If it ain't broke, don't 'fix' it.

➕ show 1 reply
slicktux • today at 4:20 AM

Was this status indicator simple vertical bars that were black and white and displayed on an old CRT Monitor? Almost looks like black and white terminal vertical bars (like Alsamixer)?

icedchai • yesterday at 11:24 PM

I'm curious, how did the hardware present itself? It couldn't have been an Amiga Zorro card since it would've been impossible to get that into a PC. Did it connect over a serial or parallel port?

➕ show 1 reply
throwaway27448 • today at 3:17 PM

How on earth are these massive pieces of infrastructure relying on software they don't have the code to? i'm just utterly confused how these things happen.

ptek • today at 5:12 AM

If it's still running I wonder what they are going to do about the year 2038.

➕ show 1 reply
DoctorDabadedoo • today at 12:13 AM

I wonder if there is push in the public sector for open source software/hardware for cases like this.

I completely get the decisions over time here, but it's unsettling having a relevant piece of software (reports are important too!) working on with parts from ebay, in 50 years time they might be gone.

➕ show 1 reply
sajithdilshan • today at 9:05 AM

This is crazy. Why on earth wouldn’t the respective government spend money to modernize a critical infrastructure like a nuclear power plant?

This is how we would end up with nuclear disasters, not because the technology is bad, but purely because of mismanagement and human negligence.

➕ show 7 replies
TMWNN • yesterday at 11:37 PM

>So this is how, in 2007, during a tour of the facility, I stumbled across a Pentium 1 system running an AmigaOS emulator on Windows NT 4.0 that was responsible for displaying the status of the control rods of a nuclear power plant.

Vernor Vinge's A Deepness in the Sky depicts a human society thousands of years in the future, in which pretty much all software has already been written; it's just a matter of finding it. So programmer-archaeologists search archives and run code on emulators in emulators in emulators as far back as needed. <https://web.archive.org/web/20231114211656/http://www.gareth...>

(Heck, recently I migrated a VM to its third hypervisor. It began as a physical machine a quarter century ago.)

collingreen • today at 4:43 PM

That must have been a crazy moment for you when you first saw it and a big sigh moment for whomever had to explain it to you the first time. Thanks for sharing this; it made me smile!