In fact it seems quite prudent for a regulator to do this.
It can be, though.
There is a risk inherent to air travel. The safest thing to do would be to ground all flights of all aircraft permanently.
That wouldn't be prudent, though, because we can mitigate the risk until the benefit of air travel outweighs the risk of dying during air travel.
The prudent thing to do is to carefully evaluate the risks, and make a determination when the risks become too great.
If a company releases a new version of their software and it crashes twice in similar ways (much more frequently than the previous version), that is also enough reason to rollback the release and investigate, especially if the software has any critical use cases.
Obviously commercial aviation has much higher standards than software vendors generally do. Airline tickets don’t generally come with 5,000 word EULAs with all-caps provisions like “THIS SOFTWARE IS NOT FIT FOR PURPOSE AND SHOULD NOT BE USED FOR ANY REASON AND YOU ASSUME ALL RESPONSIBILITY FOR ANY NEGATIVE OUTCOMES OF ANY KIND” etc.
Two crashes in close succession seems like an obvious abnormality. But because standards are so high, to commercial aviation providers and regulators, every single crash is treated as a significant abnormality. So the question is, why don’t they ground all models of a certain plane after a single crash? Once you understand that, the same logic applies to two crashes.
Clearly, a chance for a bug losing you 300$ is much less of a problem than a chance for a bug killing 300 people.
The second thing is that a software update may render previous knowledge useless.
Just because the old software ran successfully on 100k nodes, it might still be the case that 2 out of 1000 new versions fail, so then you have 0.2% failure rate. That doesn't mean you should take out all 100k nodes but it means you might want to stop the 1k nodes in accordance with the principles laid out above.
Finally, I am not even sure why this is a yes/no question. How about: You're allowed to use the plane but you cannot rely on a defense of "the FAA said it was ok" if something happens, so talk to your insurance before.
So this is both statistically suspicious, and points at a possible common cause for the crash, making it even more worrying that there's something seriously broken in this design.
Imagine the story would go like this: a girl heard the story about the boy who cried wolf. Uppon seeing a pack of wolves the girl doesn’t cry wolf because she wasn’t 100% sure that it wasn’t in fact a pack of stray dogs. Villagers die.
The original story teaches kids not to lie to gain attention, because nobody will believe you when you for once have a serious risk at hand. It has nothing to do with how we should treat real risks, where we have real indicators of increased risk.
Climate change is the ultimate example of such a risk. Better safe than sorry, because beeing sorry can easily become the end of the species here. Some airplane failing is arguably a tiny thing in comparison — but once you have been warned about a risk you can mitigate and you do nothing, you own it. Living is dangerous and everything has a remaining risk that stays dangerous even after any reasonable risk has been mitigated.
But this isn’t about totally ruling out all remaining risks, it is about ruling out risks that are easy to rule out.
If somebody told you the brakes of your bicycle are both broken, you would probably not lend it to someone until you convinced yourself of the condition of your brakes. You will do this despite the fact that cyling can be dangerous with a fully functional bicycle too.
Literally every one would have been grounded had the FAA grounded the type after 2 accidents.
The first crash of the 777 occurred 15 years after it was launched with 1500 aircraft delivered, and even in that crash foul play is suspected.
The first crash (ignoring hijacking) of the 767 occurred almost a decade after it was launched, and the second was almost two decades after launch, and it's still not clear if it was suicide.
2008 British Airways Flight 38: 47 injured https://en.wikipedia.org/wiki/British_Airways_Flight_38
2013 Asiana Airlines Flight 214: 3 fatalities, 187 injuries https://en.wikipedia.org/wiki/Asiana_Airlines_Flight_214
2014 Malaysia Airlines Flight 370: disappeared https://en.wikipedia.org/wiki/Malaysia_Airlines_Flight_370
2014 Malaysia Airlines Flight 17: hit by anti aircraft missile https://en.wikipedia.org/wiki/Malaysia_Airlines_Flight_370
Overall, I'm pretty happy with what I saw out of the FAA. It just seems like the FAA may have gotten the data last. Canada got it before we did. The EU got the blackbox first, so once they looked at the data, they banned the plane. China's response may have been preemptive, since there's no way they could have looked through the data at that speed.
Perhaps we should be pissed off at getting the data-last. But that's hardly the FAA's fault (maybe a State-department thing). In the future, Boeing needs to at least appear more neutral and less like a lobbyist when these events occur. There's significant distrust in our system these days, our regulators need to understand what it looks like when they're talking with the companies who make the plane before getting the black box...
Nope, the FAA had the data before the Canadians.