You can't press a button without understanding how it will affect the plane. How do you know the automation is at fault? Maybe there is mechanical damage and the only reason you're in the air is the automation? By the time you understand if the red button can be safely pressed, you understand what is generally causing the problem. So you can disable that specific automated system, which you can do today.
Also, automation is very very rarely at fault, it basically never happens. But accidents are often avoided, and many accidents would have been avoided, if pilots let go of the controls and let the automation and the inherent stability of the airframe return the flight to normal.
I can't think of a single time when that big red button is a good idea.
Boeing just recklessly didn't tell these pilots what to watch out for, what automated systems existed, and to save some money didn't include the basic safety equipment they needed.
I can't really contest that. The pressure to sell it as identical to previous models and skip certification and training steps seems to have played a part on this.
Contrary to what our instincts tell us, automated systems are potentially far saver than humans could ever be: You can take as much time as you need to think of the best reaction in every scenario; they will execute whatever best practice you come up with every single time without needing constant (re-)training, they don't drink, they don't suffer strokes, they don't get tired, etc.
The failures we have seen tend not to involve any errors in judgement by the automated system. Instead, they almost invariably result from faulty sensor input. For the 757 Max, the angle-of-attack sensor seems to have failed, and relying on input from just a single sensor seems catastrophically negligent.
Such failures cannot reliably be avoided by giving humans more control. With a sensor showing a large AOA and the "STALL! STALL!" alarm blaring, a pilot would take the same action MCAS took, at least initially.
For the two recent crashes, the pilots would probably have recovered. But they had the advantage of daylight and clear skies. At night, in bad weather, and even in the best conditions, hundreds of planes have crashed because the pilots suffered some sensory illusion. See, for but one example, https://en.wikipedia.org/wiki/Air_New_Zealand_Flight_901, which crashed into a mountain because the crew mistook it for an ice shelf. Air France 447 (https://en.wikipedia.org/wiki/Air_France_Flight_447#Accident) is even closer to the current crashes. It shows pilots taking manual control of the plane while fatally misjudging its attitude. There are many other examples where pilots get disoriented in, for example, clouds. The typical story is the plane coming out of the cloud inverted without anyone on board having noticed. Our sensory organs aren't equipped to measure complex movements in 3D: you can roll a plane without ever spilling the champagne glasses in first class.
That's why you trust what the instruments say. On both MAX crashes (and AF447) what happened is that the plane was doing things the crew didn't understand. If there were a clear indicator they had more than the usual amount of authority (say, chaining the cockpit lighting color to red) or a clear way to disengage the computer assistance and put the plane in an easy to reason about state, which, I assume, would be useful if the plane is doing something for a reason you don't know about. Like you said, the two MAXes would be saved. AF447 is less clear, but, still, if we find the machines so much more capable, then we should remove the humans altogether (that would probably safe AF447).
"I think it is unconscionable that a manufacturer, the FAA, and the airlines would have pilots flying an airplane without adequately training, or even providing available resources and sufficient documentation to understand the highly complex systems that differentiate this aircraft from prior models." [1]
Unless you're confident flying that specific model of that particular plane just turning off auto-pilot is really dangerous. Planes aren't all the same, so "knowing how to fly" doesn't really work, especially on take-off and landing where the margin of error is very, very small.
[1] https://www.politico.com/story/2019/03/12/pilots-boeing-737-...
My understanding is that there is a button on the stick to disable the autopilot if the pilot just wants to be maneuver. And a circuit breaker to really shut the thing down if there is something wrong, as it happened during the accident.
You don't want to disable everything at once, and put too much cognitive load on the pilot during the worst times. Especially not safety systems like MCAS is supposed to be.
But, I'm not sure if the concept of "full manual" is anymore relevant with modern passenger jets. Are they even flyable without any computer intervention or too unstable / have too complex flying charasteristics?
Commercial aircraft are not fighters. They don’t need to be unstable with computers making them flyable. An unstable airliner would be an uncomfortable airliner and hence a commercial disaster.
What has changed is whether or not there is a manual connection between the yoke and the control surfaces. For reasons of cost, that connection has been going away.
In a non-fly by wire air craft though like the 737 max, a full manual mode is basically when you have auto pilot disengaged. There might be a mode you can enable to disable other functions like tail strike prevention/MCAS but I a haven't ever heard of it.
[0] https://hackaday.com/2019/03/14/mcas-and-the-737-when-small-...
The 737 MAX is just not stable in every condition that the old 737 NG was. And it probably goes the other way, there are most likely flight conditions where the 737 MAX is stable but the 737 NG is not.
The difference is that pilots had been trained and have flown the old one for many years and trained to avoid the unstable conditions for the old 737.
*Flight conditions meaning: air speed, AOA, bank angle, total thrust, altitude.
I don't think that's the case. MCAS was added to satisfy a requirement in the airworthiness certifications that requires positive control forces to increase AoA. The lift generated by the engine nacelles caused this to not be the case at high AoA.
None of what has been revealed so far indicates that the pilots had issues related to the symptom, rather they had issues with MCAS. In a way the cure has been worse than the disease.
There is no red button as such (at least as far as Airbus is concerned). The computer decides that something has gone wrong and invokes an alternative law. You'd have to start pulling circuit breakers to manually trigger a reversion.
> Commercial airliners are stable when flying.
This is not necessarily true. All modern airliners have aggressively swept wings. This generally makes them susceptible to dutch roll in some phases of flight. They are fitted with yaw dampers to control this tendency.
The 737 MAX is not. That's why it has the MCAS system in the first place: the engines are too large for the airframe, making the aircraft fundamentally unstable, so they came up with MCAS to try to make it seem stable to the pilots, and then they didn't even bother telling the pilots that this MCAS system even existed.
If you hava a lot of computerized equipment to help you you depend on the things that work. You want only that malfunctioning part off. Here the problem was that before Lion Air crash nobody but Boeing even new that MCAS existed, let alone turning deadly with the malfunctioning non-redundant sensor.
The best was not even to enter that storm.
The "known" is the problem there. The pilots there were continuously misinformed about the plane speed due to that iced measurement devices. That is what plane "knew" and what the pilots "knew" in the storm.
The autopilot handed over control to human, but then human drove it too high (the "law" here means "mode of operation"):
"The pilot continued making nose-up inputs. The trimmable horizontal stabilizer (THS) moved from three to 13 degrees nose-up in about one minute, and remained in that latter position until the end of the flight."
"A second consequence of the reconfiguration into alternate law was that stall protection no longer operated. Whereas in normal law, the aircraft's flight management computers would have acted to prevent such a high angle of attack, in alternate law this did not happen. (Indeed, the switch into alternate law occurred precisely because the computers, denied reliable speed data, were no longer able to provide such protection—nor many of the other functions expected of normal law).[55] The wings lost lift and the aircraft stalled"
> one of them (the co-pilot, IIRC) didn't realize it
But the co-pilot definitely knew that the autopilot disengaged:
"The first officer, co-pilot in right seat, 32-year-old Pierre-Cédric Bonin"
"At 02:10:05 UTC the autopilot disengaged" ... "As pilot flying, Bonin took control of the aircraft via the side stick priority button and said, "I have the controls.""
So when we see capacity increases, fuel efficiency increases, reliability increases... I'd hazard to say that comes with increased complexity.
And at some point, it's more dangerous to let a pilot fly a highly engineered aircraft on full manual than it is to let a team with access to the technical specifications and time generate an approved, stepwise, degradation flowchart for pilots to work through.
In the same way the best solution to an engine timing issue isn't "Work the valve timing by hand" but rather "Degrade to a less efficient but more reliable profile" through to "Degrade to a static profile that keeps the engine operating after multiple failures."
You really don't want to be burdening pilots with more work.
The failure here seems to be in a poorly designed degradation route, not in the idea itself.