Right, the mechanical brake linkage regularly failed at the same time as the brake sensor failed to no pedal and the accelerator sensor failed to full pedal.
You don't do much safety analysis, do you?
Let's see, assume a bad pointer goes in an corrupts the lookup table which identifies what input corresponds to which function. Now your pedals have reversed function. All the logging in the world isn't going to change the fact that the box is now looking at the wrong pin for its input.
Yes, there are certainly things that can be done to mitigate this risk, and some of them may have been implemented. However, the unfortunate truth is that there is no recognized/legislated functional safety standard for the development of automobile software in the US. Some international companies are trying to apply IEC61508 (developed for industrial automation), but compliance is strictly voluntary.
They may be right, but they don't provide sufficient data in TFA to say either way, in fact Toyota has come right out and said that their logger is a debugging tool, and to me that says it is not safety relevant software, and therefore not subject to additional quality controls.