The Verification Venue · a fear pointed at the wrong vehicle

The Trip That Flips the Fear

You grip the armrest at takeoff and let your guard down behind the wheel. For the same point-to-point trip, that is exactly backwards: the drive is the part that should scare you, not the flight.

Companion film · 3:00 · turn the sound on. Every click you hear is one micromort. The film sets a single exchange rate on screen, 2,000 miles per second, and after that each mode's click rate is nothing but its published death rate: the car at 14.56 a second, the plane at one click every 7.1 seconds, the motorcycle at 425 a second, which is fast enough to stop being a rhythm and become a pitch. Then it holds the hours still instead of the miles, and the plane's ticks multiply by 14.3 and cross the train's, because 2,000 miles is 57.1 hours in a car and 4.0 in a plane. The closing movement changes table to US roads in 2024 and sets two fractions side by side: the motorcyclist, whose 23.5× the average road user is a measurement because both halves are published, and the unbelted occupant, whose 2.0× to 24.9× the average occupant is a choice because the miles are measured by nobody. Those two are measured against different populations, which the film says on screen, so they sit beside each other and are never ranked. Pitch, timbre and the level balance are declared craft; the schedule is not, and film.html draws the same click arrays make-audio.mjs strikes. Every figure is gated by research/the-trip-that-flips-the-fear/film/film-facts.mjs (120 assertions), which also runs both verifiers so the tally on the sign-off cannot drift. Reproduce the film from a fresh checkout: research/the-trip-that-flips-the-fear/film/build.sh.

A micromort is a clean way to hold danger in your hand: one micromort is a one-in-a-million chance of sudden death (Ronald Howard, 1980; popularised by David Spiegelhalter). It turns "is flying safer than driving?" into arithmetic. Type in a trip below and watch the micromorts pile up for each way of making it — every number recomputed, live, from the raw 2023 death counts, not a quoted slogan.

Same distance for both — the fair, like-for-like question: per mile travelled per person, which is the gamble?

drive it 4.19 micromorts
fly it 0.04 micromorts

For this trip, driving carries 114× the death risk of flying.

The bars don't lie because the rates underneath them are taken from public counts, not vibes. The flight's risk is so much smaller that it nearly vanishes — and that's the point: cruising at 35,000 feet is one of the safest things a human can do per mile. The danger you feel is real danger, just attached to the wrong half of the journey.

But "per mile" is only one ruler

Every bar above measures danger per mile. That already sounds neutral — and it hides a decision. A mile of flying and a mile of walking are the same distance but wildly different amounts of your life: the plane covers its mile in seven seconds, the walk in twenty minutes. Ask the same death counts a different question — per hour of travel, or per whole trip — and the safest mode is not the one you'd expect. Add every mode and switch the ruler. Watch the order rearrange.

Risk per

Deaths per 100 million passenger-miles (Savage 2013, the one study that measures every US mode the same way). Bars are ranked safest at the top.

↔ logarithmic scale — each gridline is 10× the risk

The reorder is the whole point. Per mile, flying is untouchable — safer even than a bus, because a plane earns its safety by covering enormous distance. But that same speed is why the crown doesn't survive the switch to time: an hour aloft carries you five hundred miles, and it spends the plane's tiny per-mile risk over every one of them. Measured by the hour you actually sit there exposed, the humble bus wins, the train is next, and flying is merely ordinary — about as safe as the drive to the airport, not a hundred times safer. Nothing about the danger changed. Only the ruler did.

Whose average is it?

Everything above rests on one number for the road: 1.26 deaths per 100 million vehicle-miles. That is an average, and an average is a mixture. Poured into it: the motorcycle and the minivan, the county road at 3 a.m. and the Tuesday commute, the drunk driver and the sober one. Almost nobody is the average. So take the mixture apart, and find out whether the fear survives being aimed properly.

Conditioning a rate is one line of arithmetic, and the line repays staring at:

relative risk of a condition = its share of the deaths ÷ its share of the miles

That single line is the whole instrument, and it is lopsided in a way that risk writing almost never admits. The top is always knowable. The Fatality Analysis Reporting System records every death on a public U.S. road, along with the road class, the light, the vehicle body, the restraint, the measured blood alcohol. Splitting deaths is a matter of counting, and this page counts them, from the raw case files rather than from anyone's summary table. The bottom is usually not knowable. Somebody has to have measured how many miles were driven under that condition, and for most conditions nobody has.

So every row below wears a badge for its denominator, and the badge is the honest part: counted a national traffic-counting programme publishes the miles; surveyed only a household travel survey estimates them; none nobody produces a figure at all. Pick a row and the panel underneath opens it up.

FARS year

Both complete years are here on purpose. Every finding below survives the switch, which is the cheapest robustness check there is.

Condition Deaths Miles × average

Pick a condition above

The top of that table is the footnote made good. A motorcycle carries well under one percent of America's traffic and more than fifteen percent of its traffic deaths, which puts a rider more than twenty times above the average per mile. That is the order of magnitude, and it is a measurement: both halves of the fraction are published, by two agencies that were not trying to make this point. Inside the road network alone the spread is about four and a half to one, from an urban freeway at the safe end to a rural major collector at the other, which is a fair description of the difference between a highway engineer's road and a road that was a farm track once.

Now look at the bottom three rows, and at the column that will not fill in. Those are not obscure conditions. They are, almost exactly, the argument everyone makes for why the average does not apply to them: I do not drink and drive. I wear my belt. I do not drive at night. Every one of those is a claim about a rate. Not one of them has a denominator. You can count the deaths to the last person, and the miles are simply not there, so the relative risk becomes whatever you decide it is. Drag the slider and watch a widely repeated safety fact swing by more than a factor of ten without a single new observation.

This is worth being careful about in both directions. The missing denominator does not mean the claim is false. Impaired driving really is enormously more dangerous per mile, unbelted occupants really do die at a rate their numbers cannot justify, and no one should read this page as a licence for either. What is missing is the size: impaired driving multiplies your risk per mile by somewhere between about six and about a hundred and fifty, and on the evidence assembled above, the slider is the only thing choosing.

Correction, 2026-08-16. This paragraph used to end with a stronger sentence. It said that the width of that range “is not scientific caution about a hard measurement. It is the absence of any measurement at all.” That was wrong, and the rest of this page is now the retraction.

The missing miles are real. What does not follow is that nothing has been measured, and the reason it does not follow is sitting in the box at the top of this section. Share of the deaths over share of the miles is one estimator, not the field. Because the denominator is missing for exactly the conditions people care about, road-safety epidemiology went and built estimators that do not need one, and this page had confused a dead end in its own arithmetic for a hole in the world. Two of those estimators follow. One of them we ran ourselves, on the same case files this page already downloads.

The estimator that needs no denominator

Put the missing miles to one side and ask a narrower question. Not how much more dangerous is the unbelted population per mile, but what does the belt do. Two people are in one car when it leaves the road. One is wearing a belt and one is not. Nobody needs to know how far either of them drove that year to say which of them the tree treated worse.

That is double pair comparison, published by Leonard Evans in 1986 and NHTSA's standard belt method ever since. Take every vehicle in FARS carrying a subject and an other, where at least one of the two died. Inside a single crash the other occupant's deaths are a measure of how bad these crashes were: the speed, the angle, the tree, the vehicle, the road, and the disposition of whoever was driving. Form the ratio of subject deaths to other deaths separately for subjects who buckled and subjects who did not, then divide one ratio by the other. Everything the two people shared cancels, because they shared it. NHTSA's own statement of why this is worth doing: double pair comparison “implicitly ‘adjusts’ or ‘controls’ for the differences in the severity of crashes involving belted and unrestrained occupants.” No exposure data of any kind enters it. There is nothing to be missing.

Before it is pointed at anything, the estimator is checked against a case whose answer is already in print. NHTSA's 2017 evaluation works one all the way through on the page: four cells of centre-rear passengers and drivers, two separate estimates of 64.9% and 65.4%, and a combined 65.3%. Our implementation is handed those four cells first and has to return those three numbers, including NHTSA's own rounding of the intermediate ratios, or it exits without writing anything. It returns them.

Subject

FARS 2018 to 2024, every vehicle carrying both of these people with a recorded belt state, where at least one of them died. The other occupant is the control: their deaths say how bad the crash was.

computing

Read the spread before you read the answer. The four cells give two separate estimates, one using the unbelted control and one using the belted control, and they are measuring the same thing by different routes. NHTSA states the test they constitute: “effectiveness should be the same relative to any valid control group used for the comparisons – if it varies substantially, then at least one of those comparison groups is not a valid control group.” In the front seats the two routes land about two to six points apart, which is agreement. In the back seats they land twelve and twenty points apart, which is the estimator telling you it is running out of data and that you should not trust the third decimal of anything below it. That alarm is printed above whether it is quiet or loud.

And the method's own lie detector. Belt use in FARS is what somebody wrote down, not what anybody saw, and after the belt laws arrived survivors began reporting belts they had not worn. NHTSA measured the size of that: the same vehicles gave a 47.81% fatality reduction in 1977 to 1985 data and an apparent 61.89% in 1986 to 1999 data, so they defined a universal exaggeration factor, (100 − 47.81) / (100 − 61.89) = 1.369, and deflate every front-seat estimate by it. We do the same, and print both numbers, because which one you are looking at is the entire difference between 61% and 47%. NHTSA does not deflate rear-seat estimates, on the evidence that rear passengers under- report rather than over-report belt use, and neither do we.

Does it work? The point of running it here was never to improve on NHTSA. It was to find out whether a stranger with a laptop and no exposure data can get their number, because a method that only works inside the agency that owns the files is not a method a reader can check. Four of the six pairings land on the published figure, including the canonical one: for front-seat car occupants NHTSA has published 45% since 1984, and seven years of recent data run through this script gives 47.3%. Two pairings miss, both of them light trucks and vans, where our estimate runs high. We can name the likely reason and cannot close it: NHTSA restricts its analyses to vehicles it can VIN-decode and confirm were equipped with the belt in question, and we take the body-type code at face value. That is a real gap and it is printed in the panel above rather than left out of the count.

Two questions wearing one sentence

So the column fills in, but it does not fill in the row that was empty. It is worth being exact about what just happened, because the two quantities get spoken as though they were one:

what a belt DOES = P(death | crash) <- measured, above what NOT BUCKLING means = P(death | mile) <- still no denominator

Double pair comparison answers the first. It says an unbelted car driver is about 1.9 times as likely to die as a belted one in the same crash. It cannot answer the second, because the second folds in how often each group crashes at all, and that is where the miles were needed. And the two are not close, because the people who do not buckle are not a random sample of drivers who happen to have skipped a step. From the same seven years of case files, drivers in fatal crashes whose belt state was recorded:

The first row of that table is an effect of not buckling and belongs to the belt. The night row and the age row are things that were true of the driver before the crash, and belong to the second question, not the first. The alcohol rows are the honest mess: an unbelted driver in a fatal crash is nearly twice as likely to have been tested for alcohol at all, and the reason is that they are far more likely to be dead, and the dead get tested. So the last row compares two groups selected differently and cannot be read as a clean prevalence. It is here because leaving it out would be worse: it is the row a reader would most want, and it is the row the data is least able to give.

That gap, between about 1.9 and the slider's ten-fold swing, is not error. It is the difference between a belt and a person who wears one, and no amount of case-file arithmetic can turn one into the other.

The denominator somebody went and measured

The other row without a denominator was alcohol, and there the fix is less clever and more laborious: if nobody counts the miles, go and sample the traffic. NHTSA's Virginia Beach crash risk study ran for twenty months, twenty-four hours a day, seven days a week. Crash-involved drivers were recruited at the scene. Then, for each one, two control drivers were taken “from traffic passing the crash location, driving in the same direction of travel, on the same day of week and at the same time of day one week later.”

That control sample is the missing denominator, and it was measured. It is not measured in miles. It is measured in drivers who were on that road at that hour, which for this question is the better unit anyway, because it holds the road, the hour and the day of week fixed instead of averaging over them. It also quietly answers the third condition on the list: the controls were drawn at the same time of night as the crashes, so the whole risk curve is already conditioned on when you drive.

The result, from 3,353 crash drivers and 6,868 control drivers who gave breath samples: adjusted for age and gender, a driver at 0.05 is about 2 times as likely to crash as a driver at zero, at 0.08 about 4 times, at 0.10 about 5.5 times, at 0.15 about 12 times, and at 0.20 and above more than 23 times. Those are numbers with a denominator behind them.

One check worth doing by hand, because it shows what a bucket costs. The study's raw counts put 95 of 3,353 crash drivers above 0.08 against 26 of 6,868 controls, which is an odds ratio of (95/3258) / (26/6842) = 7.7. That is nearly twice the modelled figure at 0.08, and the difference is not a contradiction: above 0.08 is a bucket running up past 0.20, where the risk is more than twenty-fold, while at 0.08 is a single point on a curve that is still climbing steeply. A range and a point are different claims, and a great deal of alcohol statistics is the two being quoted as one.

What this section did not close. Driving at night, taken on its own and separately from alcohol, still has no per-mile denominator here. The case-control design absorbs the hour rather than measuring it, which is exactly what makes the alcohol curve trustworthy and exactly why it cannot be turned round to price the night. The honest state of the three rows is now: the belt is measured by a design that needs no exposure, alcohol is measured against a sampled exposure, and the night is still a slider.

Can you drive your way to airline safety?

This is the question the conditioning was really for. If the average driver is roughly a hundred times worse per mile than the average airline passenger, and you are demonstrably not the average driver, how much of that hundred can you claw back by being careful? Stack the conditionings that have counted denominators, each one in your favour, and watch where the ladder actually stops.

Per mile, deaths per 100 million miles

↔ logarithmic, four decades across the bar, because the plane sits three below the road

computing

The check — every number recomputed in front of you

1. The U.S. road rate, from the raw 2023 counts (NHTSA FARS deaths ÷ FHWA vehicle-miles). Watch "miles per death" fall out of the division — no slogan needed:

1a. The count itself moved. When this page was built it said 40,901, which was the number NHTSA had published. FARS ships each year twice: an Annual Report File about a year after the crashes, then a Final File about a year after that, at the same address. In April 2026 the 2023 Final File replaced the 2023 Annual Report File and the total went up by 124 people. NHTSA states the change in its own words: "The final fatality count in motor vehicle traffic crashes for 2023 was 41,025, updated from 40,901 in the 2023 ARF." The reason is prosaic and worth knowing, because it is the same reason the alcohol figures below are modelled: some fields depend on records from outside the police report, and those arrive late or not at all.

2023, first published40,901
2023, final file41,025
difference+124
rate, both ways1.26

The honest footnote to our own alarm: 124 out of 41,025 is three ten-thousandths, and the published rate per 100 million miles rounds to 1.26 either way. The bedrock moved, and it moved a little. Both of those are worth saying.

2. The fair per-person comparison uses deaths per 100 million passenger-miles (NSC / USAFacts, 2023), so a car seat and a plane seat are measured the same way:

modedeaths /100M pax-miµmort / milemiles per µmort

3. Your trip, plugged through with the slider value above:

4. Changing the ruler — every US mode on one consistent basis (Savage 2013, per 100M passenger-miles, 2000–2009), then converted to per-hour by multiplying by a named representative speed. The two orderings differ, and that difference is the argument:

modeper 100M pax-miµmort/mile× speedµmort/hour

5. The alcohol figure, taken apart. Roughly half of all fatal-crash drivers are never tested, so NHTSA does not publish a measured count. It publishes a modelled one: ten blood-alcohol values are drawn for every missing result and shipped inside FARS itself, and the headline number is their mean. We recompute it from those files rather than quoting it, and put it beside what the measurements alone support:

Hitting NHTSA's published figure to the rounding is the check that our reading of the files is right. The gap between the two rows is not error and not spin. It is the size of what the tests did not measure.

5a. The belt effect, and the estimator checked before it was used. Double pair comparison is run against NHTSA's own published worked example first, and only then against the case files. The control is what makes the second run worth reading:

NHTSA worked example, control = unbelted64.9%
ours64.9%
theirs, control = belted65.4%
ours65.4%
theirs, combined65.3%
ours65.3%

6. Every conditioned rate above comes out of three committed artifacts that anyone can regenerate from the government's own downloads, with no key and no account:

node research/the-trip-that-flips-the-fear/fars-extract.mjs # numerators, from the FARS case files node research/the-trip-that-flips-the-fear/vmt-extract.mjs # denominators, from FHWA VM-1 and VM-2
node research/the-trip-that-flips-the-fear/double-pair.mjs # the estimator that needs neither

The verifier recomputes all of this — the 1.26-per-100M rate, the ~79-mile-per-micromort figure, the ~177× per-mile safety ratio, the drive-beats-fly verdict for every preset trip, and every conditioned rate in the panel above, and checks they agree with what this page displays, in a real browser. Run it: node verify-the-trip-that-flips-the-fear.mjs

What's idealised here, and what's exactly true

Two denominators, two stories — both shown. The headline road rate (1.26 per 100M) is per vehicle-mile: every road death (drivers, passengers, motorcyclists, pedestrians, cyclists) over all miles driven. That gives ~79 miles per micromort. The drive-vs-fly bars instead use per passenger-mile occupant rates, the only fair way to compare a car seat with a plane seat — there car driving is ~189 miles per micromort. They are different questions, and the choice is itself the lesson.

The "240 miles per micromort" slogan is a kinder, older number. The figure you'll see quoted everywhere (~240–250 miles) implies a death only every ~240 million miles — a rate near 0.42 per 100M, about a third of the 2023 all-road rate. It reflects safer years and/or occupant-only counts. We don't repeat it as today's fact; we audit it against the raw number it disagrees with.

Per mile is one frame, not the only one. Per-mile, flying wins enormously. Per trip or per hour the gap narrows, because a flight covers vastly more miles per hour — and a fair door-to-door comparison should add the drive to and from the airport (which is, ironically, the riskiest leg of flying). The first calculator deliberately fixes distance and asks the per-mile question; it does not model the airport drive.

The per-hour numbers depend on an assumed speed — and it's shown. Per-hour risk is per-mile risk × a representative speed (mph). Savage reports per-mile and notes that "engineers might argue for … passenger-hours … to account for … the average speed of travel"; the per-hour reframing here is that transparent multiplication. The speeds (car ~35, bus ~30, train ~45, motorcycle ~35, air ~500 mph) are round representative values — the car figure is the softest (real trip speeds run ~25–70 depending on road), and the per-hour car number scales with it. But the conclusions don't: the air/ground speed gap is roughly 14×, so flying's per-mile lead over driving (~104×) must shrink to single digits per hour (~7×), and the slow, safe bus wins per hour for any speed between a city crawl and an intercity cruise.

Two eras, one ordering. The ruler table uses Savage's uniform 2000–2009 US rates because that is the one study measuring every mode the same way (onboard passengers only, one method). The car and air rates there (0.73 and 0.007 per 100M pax-mi) are a touch higher than the 2023 figures the first calculator uses (0.53 and 0.003) — both roads and skies got safer over two decades — but the ranking and the ruler-flip are unchanged. Modern transit totals quoted elsewhere (train ~0.19, bus ~0.09) look worse than Savage's onboard figures because they fold in trespassers, grade-crossing and platform deaths — people who were never riding. The honest denominator for "how risky is it to ride?" is the onboard-passenger rate, and that is what these bars use.

Why walking and cycling aren't on the bars. Savage leaves them out on purpose, and so do we: there is no reliable count of passenger-miles walked or cycled in the US — the denominator is a survey estimate, not a measurement, so any per-mile rate for them is built on sand. The best published US figures (Buehler & Pucher, Transport Reviews 2021: pedestrian ≈18, cyclist ≈10 deaths per 100M passenger-miles) are real but range-bearing, and — crucially — that acute crash rate ignores the large net health benefit of the exercise, which studies consistently find outweighs the crash risk in all-cause mortality. Put those two facts together and a bar labelled "walking" would mislead twice. The honest move is to name the gap rather than paper a false number over it.

The per-flight floor is a transparent free choice. Almost all aviation risk sits in take-off, climb, approach and landing, not cruise, so we add a representative 0.013 micromort fixed cost per flight. It barely moves a long trip, but it means that below roughly 2.5 miles the (absurd) flight would out-risk the drive — an honest boundary, not a hidden one.

The average hides enormous spread, and this page used to only say so. Until 2026-07-26 that sentence ended here, asserting an order of magnitude and checking none of it. It is now the section Whose average is it?, built from the raw FARS case files and FHWA's travel tables, where the order of magnitude turns out to be real (a motorcycle rider, more than twenty times the average per mile, both halves of the fraction published) and where the conditionings people actually invoke about themselves turn out to have no denominator at all. Commercial aviation's per-mile rate is separately dominated by rare catastrophic events, so single years are noisy. The ordering (drive >> fly per mile) survives every conditioning we can honestly apply, and the conditioning panel carries both complete FARS years so you can watch it survive the switch.

Three different ways of not knowing, and the page keeps them apart. A counted denominator is FHWA's traffic-counting programme, which is an estimate with real error but a measurement programme behind it; FHWA itself notes that travel on local roads and rural minor collectors "is estimated by the States based on a model or other means", so those cells are the softest of the counted ones. A surveyed denominator counts people rather than miles, under conditions chosen by the survey. None means nobody produces a figure. Separately, the alcohol numerator is itself modelled: NHTSA draws ten imputed blood-alcohol values for every driver never tested, and the published total is their mean. Our own count of deaths in crashes with a measured reading at 0.08 or above is far lower, because in 2024 roughly half of all road deaths were in crashes where no driver had a measured reading at all. Both figures are honest. They are not the same kind of thing, and the panel says which is which.