Of course that's all speculation since we don't know much about this particular crash, but that's the main issue with them.
Totally backfired in that regard though.
I can imagine it looks good on the marketing material, 'no pilot retraining required!', but as far as I understand from all the analysis so far, it's actually not that hard to disable the new MCAS system and prevent a crash. As a pilot you only need to know it is there, and what happens if it somehow fails.
I would be surprised if they had sold even a single plane less if they advertised it as 'very minimal pilot retraining necessary'.
That might be enough for the plane to need a separate type certificate, meaning hundreds of millions of dollars expenses for Boeing to get it certified, and full new-type pilot training costs for every airline to fly the aircraft. (Plus, time, and ongoing crew management to juggle pilots certified on one but not the other.)
You don't even have to know it is there. All you need to know is "hey, auto trim is acting very funky today and I'm having to fight it. Better override.". And hit two switches.
> I would be surprised if they had sold even a single plane less if they advertised it as 'very minimal pilot retraining necessary'.
They were likely afraid that it would require a new type certificate.
Unless you believe your instruments (AoA reading high) and assume the plane is actually doing the correct thing.
It’s not yet known if this latest crash is in any way related to the first (although I have several outstanding wagers against this being the case).
Small typo: He says "forward and up" in the video.
If something else made the engine(s) catch fire and become inoperative, and the MCAS system enabled correctly due to low airspeed/stall conditions, but was fought by the panicked pilot(s) resulting in an unrecoverable stall, it's an entirely different story.
Yes, it may turn out that this incident bears no relation to the Lion Air one, but I think it's much too early to make any such assumption.
[1] https://www.nytimes.com/2002/06/23/weekinreview/ideas-trends...
[2] https://commons.erau.edu/cgi/viewcontent.cgi?article=1040&co...
https://www.youtube.com/watch?v=MQWYhsYfMxE (jump to 1 minute for an example, found in an earlier HN thread).
Picture being at the wheel of a self-driving car, with an obvious crash looming, and the car refusing to let you, the driver, take back control and steer the wheels or step on the brakes.
[0]: https://www.washingtonpost.com/podcasts/post-reports/questio...
If we speculate (e.g. before the facts are in) that this was similar in cause to Lion air incident, then I would be curious to know how often AoA sensor has malfunctioned and|or MCAS has otherwise gone haywire and pilots have needed to revert to manual control during the two years of service MAX8s have had.
I think most people don't realize just how much stuff can be broken on an airliner and it still deemed safe to fly. And it happens all the time.
Sure, airliners might fly all the time with a missing seat number or a broken overhead bin. They're big, complex machines. But if you're implying that it's routine to fly with broken sensors, then no. That's not true.
They didn't come up with a common sense solution, doing so would have costed many billions for a new airframe with longer legs for the landing gear. This is how I understand the problem, coming from a design compromise and organisational groupthink.
Clearly this is my armchair speculation however I suspect there will be lessons to be learned from this that run along the lines of the 'Vasa' rather than the 'Comet'.
https://en.wikipedia.org/wiki/Vasa_(ship)
The Vasa story crops up on HN from time to time, it was a top heavy Swedish ship that sank after launch in light winds many centuries ago. The spec had changed with more gun decks added and groupthink drove the 'pride of the fleet' project forward. The launch date happened and it sunk.
Jeez. How are pilots supposed to land that thing in heavy wind scenarios? One wind blow at the wrong moment and it will make ground contact.
The older versions of this aircraft have the same ground clearance and have had for decades.
The 737 MAX engine clearance from the ground isn't very unusual. E.g. the A320neo is below 56 cm[1].
1. https://aviation.stackexchange.com/questions/9350/is-the-gro...
Bascially MCAS is a hack to cover a problem raised by trying to save money by pretending it's the same as a 52-year old airframe. Instead of just saying "let's do this properly ” and certificating as a new design with appropriate design features.
Boeing's main argument is that the procedure for dealing with runaway trim is completely unchanged compared to other planes, so this shouldn't require any additional training.
I understand their reasoning, but it seems odd to not even inform that there was a change, so that this would be more on top of the pilots minds. It's even worse that the system engages as soon as flaps are retracted. Since 737's usually take off with at least some minimum flaps, and retract them soon after take-off once enough airspeed has been attained (but while the plane is still at low altitude), this is quite dangerous. Pilot workload is high at this stage and there is limited altitude to recover.
That said, since this issue is on top of everyone's minds, and US carriers have added the optional safety indicators, we are unlikely to see a crash any time soon. Pilots will be jumping to the override switches at any sign of trouble.
This is a good point. And very concerning!
Here's a good answer from Reddit:
https://www.reddit.com/r/aviation/comments/azzp0r/ethiopian_...
Based on what I read, the truth is a lot more complicated. The MCAS doesn't work the way most people seem to think it does. Maybe it is a factor in the crashes. We don't know that yet.
Maybe there is nothing in particular wrong with these planes, and they were just hit with two random accidents.
[1] To a reasonable extent, of course, nothing can ever be proven 100% safe.
https://en.wikipedia.org/wiki/Malaysia_Airlines_Flight_17
https://en.wikipedia.org/wiki/Malaysia_Airlines_Flight_370
2 Boeing 777-200ERs down within three months of each other (one was shot down by Russia and the other is speculation)
I don't think you could say Malaysia Airlines was at fault for MH17, but it's hardly a good example of a null hypothesis. Since e.g. if BA was operating the same flight at the time it wouldn't have been anywhere near Ukraine.
The hardware, software, and human systems are so intertwined that it likely involves all 3, even if the route cause can be isolated to one.
That being said, there hasn't been much specific information about the cause released yet, that I've heard.
"You don't have to do anything, the plane will fly itself. Unless there's a catastrophic emergency. Then you better remember everything you haven't practiced from 18 months ago" seems like a failed implementation.
There's a checklist procedure for almost any scenario they will run into (of course not every). This exact issue was seen by other airlines and the pilots followed the checklist procedures to safely regain control of the plane as expected.
In theory, these checklists are optimized to resolve these issues and regain control as quickly as possible while ruling out other causes. It is very rare the correct course of action for the pilot differs from the checklist procedure.
There is 0 expectation that the pilot should remember everything. Pilots are trained specifically to communicate with each other to go through these checklists as quickly as possible.
That being said, there is a major concern that this issue will popup while taking off and being too low to the ground to properly follow procedure in time to recover control of the aircraft.
(Air Traffic increased ten-fold since 1970, while fatalities went from 3,500 pa to a few hundred)
Reviewing the video below - it appears to still line up with this. He doesn't mention the actual memory items changing. His explanation is the pilots starting using the wrong memory items because of information overload.
Example - They could have been going through the stall memory items instead of the runaway vertical stabilizer memory items.
Apparently, the plane thought all was well, just needed to point the nose of the plane down a wee bit.
When a typical civilian passenger plane throws everything up and yields control to its pilot, the pilot gets 10+ minutes to fix it, helped by a copilot, mountains of checklists and a direct audio line to air traffic control.
Nothing to do with the 5s you maybe get when your Tesla yields.
The general idea is that there is an auto-trim system meant to stop the plane from stalling. But when it gets bad data from a faulty sensor it tries to crash the aircraft (short version). Pilots, all pilots, are trained to recognize this and override the system, but this aircraft requires them to do some things slightly differently. Specifically, they have to shut down the system rather than manually work against it. Difficulties arise where there is a disconnect between what the pilots think is happening, what the systems think and tell them is happening, and what the aircraft is actually experiencing. So this is an interaction between an automated system (software) a potentially faulty sensor (hardware) and pilot training. It is a complex problem that will take a while to fully understand and solve.
These crashes happened because Boeing tried to market the plane as not requiring retraining in order to boost sales to airlines.
Lol. Thanks for the downvote all below. Thanks for proving my point about the change of behavior.
"What the hell is happening?"
"MCAS ACTIVE"
"Flip the cutouts!"
Why that wasn't mandated by the FAA I have no idea. Instead the pilots are expected to systematically analyse the options whilst trying to stay airborne.
We don't know it had anything to do with pilot training until the investigation is actually finished. To say it's pilot training is pushing Boeing's narrative.
https://boeing.mediaroom.com/news-releases-statements?item=1...
It's also not the first plane to crash because of software reading bad data from bad sensors. Or the last.
> Following the Lion Air crash, US aviation authorities issued an emergency directive to carriers to update flight manuals with information on what to do when the aircraft’s anti-stall system is triggered by erroneous data from what’s called an “angle-of-attack” sensor. The flight system can react to that data by pointing the plane’s nose sharply downward. Boeing, meanwhile, directed airlines to a checklist in manuals for stabilizing the aircraft. Pilots said the crash and the directives that followed were the first time that they were made aware of these changes to the flight system.
That way, if you have one faulty sensor, it gets outvoted.
The MCAS system in the new 737-MAX's only have 2 AoA sensors, which means a single faulty sensor can cause bad things to happen.
That's pretty damning if true.
The reddit thread linked from elsewhere says the same thing.
The preliminary report on the Lion air crash (http://knkt.dephub.go.id/knkt/ntsc_aviation/baru/pre/2018/20...) says they replaced and tested the AoA sensor 2 days prior.
They repeatedly refer to the AoA sensor using only singular nouns everywhere.
Given the report says it was giving faulty data and that was used, the only way this can occur is either:
1. Their are multiple sensors and the software is broken
2. There is a single sensor
Given all other data, i'm going with #2 :)
Nobody has been enterprising enough to publish the MAX8 troubleshooting/etc manuals online, if they did, you could easily verify this.
If true than that's preposterous.
https://s3media.freemalaysiatoday.com/wp-content/uploads/201... https://static.businessinsider.com/image/5be287c7b73c2846bb4...
That way, if you have one faulty sensor, it gets outvoted.
That would make sense, but unfortunately it's not the way they're actually implemented. Several incidents with Airbus aircraft were due to one AoA sensor's faulty input being allowed to trigger uncommanded pitch down events, instead of the one faulty sensor being outvoted by the other two.
I agree having only two sensors is even worse.
Do you have anything real to add here other than "I am Very Smart and everyone else is not"?
For example, whether it is a fly by wire system or not does not change anything about what i said about the sensors.