How Did the FAA Allow the Boeing 737 Max to Fly?
newyorker.com
newyorker.com
This sounds insane. Is there a reasonable explanation?
This investigation seems to be turning against Boeing. They will survive, but it almost definitely will cost them far more than whatever they saved by cutting corners. There will also be changes to the certification process, and non-US authorities will take a hard look. Any new incident would become an existential risk for Boeing.
It's important to remember that a company like Boeing isn't a single person. People working on the certification process would usually have incentives that differ from the company as a whole: they do not individually reap the benefits of cutting corners, but bear the brunt of any mistakes, including moral responsibility, possible criminal charges, and an end to their careers.
Such schemes are employed in many industries. Usually, corporate structures and cultures prevent the sort of top-down pressure that people imagine being at play here. Threatening your safety engineers (fire marshals, data protection officers, etc) with job loss for doing their job would result in whistleblowers and lawsuits. It will be interesting to see how exactly this failed at Boeing.
So it is not a competency issue, so at best it was mostly capacity related: the FAA didn't have enough resources to certify at the speed Boeing needed. Of course, the fact that you are certifying yourself might also speed things up for other reasons than purely your willingness to allocate more resources.
[0]: https://www.seattletimes.com/business/boeing-aerospace/faile...
(edit): Podcast link if of interest - http://www.private-eye.co.uk/eyeplayer/play-350
Only in case of failure is the self-certification process checked for errors, usually by insurance investigators, because they have the most incentives to do so.
The visible examples of public failures investigated by public agencies are the exception, in my understanding.
I honestly don't think there's any other realistic way of doing it properly. The true experts are the ones doing the work.
https://www.seattletimes.com/business/boeing-aerospace/faa-e...
In this case I imagine someone at Boeing knew moving the elevator jack 2.5 degrees based on one sensor was unsafe hence them selling an optional upgrade that made the system safe. That seems kind of criminal.
But to me it currently looks like it's largely a problem of how the different systems interact and how it's communicated to the users aka pilots. That's something one should be able to spot from the flowcharts/blueprints or whatever they have to document system integration.
This was, in my opinion, one of the most disgusting aspects of this whole sordid story. They had to cut back after the Ethiopian crash, but blaming everybody else seems a big part of their DNA.
I read somewhere that the sensor was misreading by 20° and Lion should have noticed.
Should Boeing have shipped the system with a single point of failure by default? Probably not.
Should the FAA have raised questions about that? Probably.
Should Boeing have considered a test case where a pilot didn't know about MCAS? Probably. But we don't know that they didn't. Perhaps they did and their test pilots recovered the plane in time. That would make it a Lion Air training failure.
There's no single point of blame here, but thankfully the airline industry reacts as a whole to incidents like this and takes as many steps as possible to make sure it doesn't happen any more.
Well, how could they train for it, when Boieing conveniently hushed over such a significant change, because it was commercially expedient? Until the Lion Air crash the airlines and their pilots didn't even know that such a system is in place.
According to an AA pilot the entire training consisted of less than an hour presentation on an iPad, in which the new behavior wasn't mentioned at all.
Add to that that Boeing offered a paid upgrade which at least would make pilots aware that the system malfunctions.
This paid upgrade sounds a bit like "Nice plane you have here, would be a shame if it crashes"
No matter how you look at it: Boeing displayed despicable behavior in this whole sorry mess. Behavior which comes back now to bite them badly.
I don't disagree with your reasoning, for what it's worth. I just think there really should be a special place in hell for the Boeing executives who allowed this to happen. Especially after the first crash.
From what is reported about the Lion Air crash it sounds like the pilots may not have sorted out what the stabilizer trim was set to and what to do to correct it. Hopefully that is not the case as such a situation would be a glaring problem with pilot competence.
This case being "pilots untrained and unfamiliar with the MCAS system recovering from a catastrophic systems failure / error".
They are at fault no matter what though from straying from their long held principle that the pilot has the final say on control of the aircraft. Inputs from the yoke and throttle levers should always supercede the computer.
Nobody in either the article or this train of comments has suggested that it was unreasonable to assume pilot error after a single crash. The problem is the oversight process which allowed it to be certified in the first place.
The airline industry isn't responsibly reacting, they're reacting after trying for quite some time to ignore the problem because it's becoming increasingly obvious that they and the FAA have been horrendously negligent, and ignoring it isn't working anymore.
If you speak German, this piece in Süddeutsche Zeitung from 2015 is enlightening: https://www.sueddeutsche.de/wirtschaft/zertifizierung-von-au...
From the article:
> It turns out that the F.A.A., with congressional approval, has “over the years delegated increasing authority to Boeing to take on more of the work of certifying the safety of its own airplanes,”
This ran through Congress. Not that any of them or the bureaucrats at the FAA will face penalty.
There is a great deal of goal alignment between airplane designers, large air travel companies and safety regulators.
[0]https://arstechnica.com/information-technology/2019/03/boein...
[1]https://www.bnnbloomberg.ca/boeing-had-too-much-sway-checkin...
It is not realistic for the FAA to do all the work independently, but now it cannot even effectively audit the self-certification.
The cynic in me thinks that society needs to reward honesty and/or disincentivize dishonesty instead of relying on personal ethics for most matters though.
No redundancy on a system that can control flight. A system that is supposed to help avoid a stall scenario.
That alone is a crazy oversight, let alone differences between safety analysis and actual capabilities.
This stinks of truly awful management - the rules of the sky were written in boood. Ignoring them has shown serious consequences, because we already knew not to do this.
This article doesn't get the point right. From this article it sounds like some optional "helper" system for pilots to avoid stall. Another article got it right, the plane itself is unstable because of big engines if the MCAS is not there to stabilize it. So its not some optional system, that the pilots would switch off when manually controlling the plane, its there for the plane to fly at all.
> So its not some optional system, that the pilots would switch off when manually controlling the plane, its there for the plane to fly at all.
And that fact makes it utterly damning that there is absolutely no redundancy. A single sensor?
It's a critical component. No redundancy on a system that can control flight.
There's no instability whatsoever in level flight, at least relative to other planes. The issue is that the large surface area of the engine nacelles is far forward of the plane's CoM. The effect of this is that the control stick becomes 'lighter' as you approach high AoA. This is considered acceptable - though not ideal - in many aircraft, but would have changed the pilot rating requirements from the old 737s.
Some people seem to be suggesting that this is some sort of advanced stability system; the reality is that this is just an automated trim adjustment. Clearly it's very important, but the idea that the plane couldn't fly at all without it is absurd.
The 737 Max saga is certainly right in the HN wheelhouse, but it’s becoming difficult to pull signal from noise when so many articles with so little new information are rocketing to the front page daily.
[0]: https://www.seattletimes.com/business/boeing-aerospace/faile...
For a really striking example of regulatory capture, look no further than the FCC.
One way to make sure that regulatory capture does not happen, is to ensure that money is not part of lobbying. But that's another discussion.
In that case they won't be swayed so easily by special interests.
There are people willing to work for the good guys for half the money, but not for order of magnitude less.
FAA, FTC, US Treasury, US military all have lost credibility in recent years.
You can also measure indirect effects, like how many agencies rubber stamp standards and certifications by the agency in question.
The interesting question isn't if it's measurable but if somebody measured it and is sharing the data
> - Failed to account for how the system could reset itself each time a pilot responded, thereby missing the potential impact of the system repeatedly pushing the airplane’s nose downward.
This likely would not have been included in the simulator, right? So, even if pilots had be given more training, it would not have done much good. The system would still be acting different to the training.
https://en.wikipedia.org/wiki/X-Plane_(simulator)#Flight_mod...
back to your question, most full fidelity flight simulations use actual models that are validated against flight test data. and in most cases, they run the same software code as is used in the actual air vehicle.
which brings us back to the question..is a 737 MAX the same as other 737's? No.
You can't press a button without understanding how it will affect the plane. How do you know the automation is at fault? Maybe there is mechanical damage and the only reason you're in the air is the automation? By the time you understand if the red button can be safely pressed, you understand what is generally causing the problem. So you can disable that specific automated system, which you can do today.
Also, automation is very very rarely at fault, it basically never happens. But accidents are often avoided, and many accidents would have been avoided, if pilots let go of the controls and let the automation and the inherent stability of the airframe return the flight to normal.
I can't think of a single time when that big red button is a good idea.
Boeing just recklessly didn't tell these pilots what to watch out for, what automated systems existed, and to save some money didn't include the basic safety equipment they needed.
I can't really contest that. The pressure to sell it as identical to previous models and skip certification and training steps seems to have played a part on this.
Contrary to what our instincts tell us, automated systems are potentially far saver than humans could ever be: You can take as much time as you need to think of the best reaction in every scenario; they will execute whatever best practice you come up with every single time without needing constant (re-)training, they don't drink, they don't suffer strokes, they don't get tired, etc.
The failures we have seen tend not to involve any errors in judgement by the automated system. Instead, they almost invariably result from faulty sensor input. For the 757 Max, the angle-of-attack sensor seems to have failed, and relying on input from just a single sensor seems catastrophically negligent.
Such failures cannot reliably be avoided by giving humans more control. With a sensor showing a large AOA and the "STALL! STALL!" alarm blaring, a pilot would take the same action MCAS took, at least initially.
For the two recent crashes, the pilots would probably have recovered. But they had the advantage of daylight and clear skies. At night, in bad weather, and even in the best conditions, hundreds of planes have crashed because the pilots suffered some sensory illusion. See, for but one example, https://en.wikipedia.org/wiki/Air_New_Zealand_Flight_901, which crashed into a mountain because the crew mistook it for an ice shelf. Air France 447 (https://en.wikipedia.org/wiki/Air_France_Flight_447#Accident) is even closer to the current crashes. It shows pilots taking manual control of the plane while fatally misjudging its attitude. There are many other examples where pilots get disoriented in, for example, clouds. The typical story is the plane coming out of the cloud inverted without anyone on board having noticed. Our sensory organs aren't equipped to measure complex movements in 3D: you can roll a plane without ever spilling the champagne glasses in first class.
That's why you trust what the instruments say. On both MAX crashes (and AF447) what happened is that the plane was doing things the crew didn't understand. If there were a clear indicator they had more than the usual amount of authority (say, chaining the cockpit lighting color to red) or a clear way to disengage the computer assistance and put the plane in an easy to reason about state, which, I assume, would be useful if the plane is doing something for a reason you don't know about. Like you said, the two MAXes would be saved. AF447 is less clear, but, still, if we find the machines so much more capable, then we should remove the humans altogether (that would probably safe AF447).
"I think it is unconscionable that a manufacturer, the FAA, and the airlines would have pilots flying an airplane without adequately training, or even providing available resources and sufficient documentation to understand the highly complex systems that differentiate this aircraft from prior models." [1]
Unless you're confident flying that specific model of that particular plane just turning off auto-pilot is really dangerous. Planes aren't all the same, so "knowing how to fly" doesn't really work, especially on take-off and landing where the margin of error is very, very small.
[1] https://www.politico.com/story/2019/03/12/pilots-boeing-737-...
My understanding is that there is a button on the stick to disable the autopilot if the pilot just wants to be maneuver. And a circuit breaker to really shut the thing down if there is something wrong, as it happened during the accident.
You don't want to disable everything at once, and put too much cognitive load on the pilot during the worst times. Especially not safety systems like MCAS is supposed to be.
But, I'm not sure if the concept of "full manual" is anymore relevant with modern passenger jets. Are they even flyable without any computer intervention or too unstable / have too complex flying charasteristics?
In a non-fly by wire air craft though like the 737 max, a full manual mode is basically when you have auto pilot disengaged. There might be a mode you can enable to disable other functions like tail strike prevention/MCAS but I a haven't ever heard of it.
[0] https://hackaday.com/2019/03/14/mcas-and-the-737-when-small-...
The 737 MAX is just not stable in every condition that the old 737 NG was. And it probably goes the other way, there are most likely flight conditions where the 737 MAX is stable but the 737 NG is not.
The difference is that pilots had been trained and have flown the old one for many years and trained to avoid the unstable conditions for the old 737.
*Flight conditions meaning: air speed, AOA, bank angle, total thrust, altitude.
I don't think that's the case. MCAS was added to satisfy a requirement in the airworthiness certifications that requires positive control forces to increase AoA. The lift generated by the engine nacelles caused this to not be the case at high AoA.
None of what has been revealed so far indicates that the pilots had issues related to the symptom, rather they had issues with MCAS. In a way the cure has been worse than the disease.
There is no red button as such (at least as far as Airbus is concerned). The computer decides that something has gone wrong and invokes an alternative law. You'd have to start pulling circuit breakers to manually trigger a reversion.
> Commercial airliners are stable when flying.
This is not necessarily true. All modern airliners have aggressively swept wings. This generally makes them susceptible to dutch roll in some phases of flight. They are fitted with yaw dampers to control this tendency.
The 737 MAX is not. That's why it has the MCAS system in the first place: the engines are too large for the airframe, making the aircraft fundamentally unstable, so they came up with MCAS to try to make it seem stable to the pilots, and then they didn't even bother telling the pilots that this MCAS system even existed.
Commercial aircraft are not fighters. They don’t need to be unstable with computers making them flyable. An unstable airliner would be an uncomfortable airliner and hence a commercial disaster.
What has changed is whether or not there is a manual connection between the yoke and the control surfaces. For reasons of cost, that connection has been going away.
If you hava a lot of computerized equipment to help you you depend on the things that work. You want only that malfunctioning part off. Here the problem was that before Lion Air crash nobody but Boeing even new that MCAS existed, let alone turning deadly with the malfunctioning non-redundant sensor.
The best was not even to enter that storm.
The "known" is the problem there. The pilots there were continuously misinformed about the plane speed due to that iced measurement devices. That is what plane "knew" and what the pilots "knew" in the storm.
The autopilot handed over control to human, but then human drove it too high (the "law" here means "mode of operation"):
"The pilot continued making nose-up inputs. The trimmable horizontal stabilizer (THS) moved from three to 13 degrees nose-up in about one minute, and remained in that latter position until the end of the flight."
"A second consequence of the reconfiguration into alternate law was that stall protection no longer operated. Whereas in normal law, the aircraft's flight management computers would have acted to prevent such a high angle of attack, in alternate law this did not happen. (Indeed, the switch into alternate law occurred precisely because the computers, denied reliable speed data, were no longer able to provide such protection—nor many of the other functions expected of normal law).[55] The wings lost lift and the aircraft stalled"
> one of them (the co-pilot, IIRC) didn't realize it
But the co-pilot definitely knew that the autopilot disengaged:
"The first officer, co-pilot in right seat, 32-year-old Pierre-Cédric Bonin"
"At 02:10:05 UTC the autopilot disengaged" ... "As pilot flying, Bonin took control of the aircraft via the side stick priority button and said, "I have the controls.""
So when we see capacity increases, fuel efficiency increases, reliability increases... I'd hazard to say that comes with increased complexity.
And at some point, it's more dangerous to let a pilot fly a highly engineered aircraft on full manual than it is to let a team with access to the technical specifications and time generate an approved, stepwise, degradation flowchart for pilots to work through.
In the same way the best solution to an engine timing issue isn't "Work the valve timing by hand" but rather "Degrade to a less efficient but more reliable profile" through to "Degrade to a static profile that keeps the engine operating after multiple failures."
You really don't want to be burdening pilots with more work.
The failure here seems to be in a poorly designed degradation route, not in the idea itself.
Anyway, I would not want to be the software engineer in charge of the Boeing 737 MAX 8 new update. Imagine what will happen if there is another accident after the software update? Do you think the proposed software solution is enough?