What the hell did Boeing think was going to happen?
What the hell did Boeing think was going to happen?
https://twitter.com/trevorsumner/status/1106934369158078470?...
I mean there are only two 737MAXes that have crashed in total, right? It's not like we have such a huge sample to work with for this to carry that much weight.
Not necessarily true. If that F-16 is flying over a populated area, it can kill numerous people on the ground when it crashes.
I think Boeing has handled the aftermath (and much of the lead up since the release of the plane) very, very poorly. I, as a layman to aviation, am not willing to bet that Boeing knew the true likelihood of a problem and didn't tell anyone or had a whistle blower over it.
However, if the issue with a non-redundant hydraulic value in the original 737 didn't teach us the lesson, this should: no matter the likelihood of failure, safety critical systems should always be redundant.
(Also, Boeing didn't handle that original issue very well either.)
1. https://aviation.stackexchange.com/questions/58798/why-doesn...
Pilot input works... then MCAS silently does it again with up to +2.5 degrees additional adjustment, until after enough times it's maxed out the full rotation of the tail flap. See: https://www.seattletimes.com/business/boeing-aerospace/faile...
That's east to say from an armchair but on an aircraft everything is "safety critical" to some extent and you have to choose what gets redundancy. Something where without it you can't fly the plane sure, that make sense. The argument for considering MCAS, a system which is not necessary to fly the plane safely, to be "safety critical" is much weaker. The Lion Air crash wouldn't have happened had the pilots disabled MCAS instead of fighting it into the drink.
The same thing can be said for literally tons of components on a plane. You can't have them all be redundant. At some point you have to pick and choose. A sensor for an obviously supplemental feature seems like a pretty obvious one to choose not to be redundant.
>I'm not sure what redundancy has to do with this,
I think the part in the GP comment where he/she state that "no matter the likelihood of failure, safety critical systems should always be redundant" has something to do with it.
Why not?
In any case, the actual regulations in play here would have required redundancy if the consequences of failure had been properly categorized:
> [I]n normal flight, an activation of MCAS to the maximum assumed authority of 0.6 degrees was classified as only a “major failure,” meaning that it could cause physical distress to people on the plane, but not death.
[..]
> He said virtually all equipment on any commercial airplane, including the various sensors, is reliable enough to meet the “major failure” requirement, which is that the probability of a failure must be less than one in 100,000. Such systems are therefore typically allowed to rely on a single input sensor.
> But when the consequences are assessed to be more severe, with a “hazardous failure” requirement demanding a more stringent probability of one in 10 million, then a system typically must have at least two separate input channels in case one goes wrong.
https://www.seattletimes.com/business/boeing-aerospace/faile...
From a certain perspective, the flaps give the plane redundant wings. One pair for low and slow, and another pair for high and fast.
"Cockpit displays and a warning light intended to flag problems with angle-of-attack sensors in flight were optional on the Lion Air jet that crashed, according to people familiar with the matter. The carrier, like some others, chose not to purchase the feature, people familiar with the matter said, so pilots didn’t receive any such alerts."
https://www.wsj.com/articles/maintenance-lapse-identified-as...
In flight entertainment, non-emergency lighting, food prep, &c aren't "safety critical" any more than the TVs in hospital rooms are.
As a layman, I'd've imagined that all avionics and control surface control was redundant. Don't most large planes have redundant hydraulic systems and even a deployable wind turbine to run avionics and hydraulic systems under total power loss scenarios? (And hasn't that turbine been used a few times?)
Yes, weight is always a factor, but that doesn't mean that there aren't already multiple redundant, heavy, systems on aircraft.
What puzzels me is that there are 2 angle of attack sensors, but they're only connected to one of the flight computers each, with the other flight computer being the redundant one. What's more Southwest ordered the optional disagree alert, so there is some way to tie and compare these sensors.
Edit:
> The argument for considering MCAS, a system which is not necessary to fly the plane safely, to be "safety critical" is much weaker.
It controls the control surfaces; I'm not sure how it wouldn't count.
It's still controlling control surfaces.
> Sure it can improve safety, so can lane keeping in a car. Neither are critical to operation. You can fly/drive perfectly safely without them so they need not be super hardened against failure because you can just switch them off.
I'm not quite sure where to begin. Just because the absence of something would make the plane flight worthy doesn't mean the addition of it keeps the plane flight worthy.
Take your lane following example. Sure, they can be turned off, but that didn't help the person whose Tesla ran straight into a jersey barrier because it got confused by it and where the lane was. (https://www.popularmechanics.com/technology/infrastructure/a...)
If a mechanisms can control the vehicle, it is safe critical. It needs to fail safe under all conditions. The requirement to fail safe is part of what makes it a safety critical system.
In the most extreme of examples, adding a lane following module to a car that randomly swerves into jersey barriers once at speed and if the barrier is close enough would be a clear example of a situation where the automatic controls can cause a situation that a human could not possibly react to; hence, the system itself needs to be held to much higher standards.
Nope, MCAS is required to meet the requirements set forth by the FAA. That's not a convenience thing. Various nannies may seem like convenience things in a well balanced car, but they become far more important in a powerful, poorly balanced car like a Porsche 911 or Dodge Viper — cars that have earned reputations as widowmakers.
Even if we suppose that is true and a fair comparison (which I wouldn't), the way failure modes are handled is key. If there is uncertainty about the sensors that control the feature which controls the avionics the system needs to halt. This is like keeping the lane control active when the computer vision algorithm used to detect the lanes is uncertain about where the lane is. Chances are it'll steer you into the next available tree and kill you.
> [Boeing self-assessed] a failure of the [MCAS] system as one level below “catastrophic.” But even that “hazardous” danger level should have precluded activation of the system based on input from a single sensor — and yet that’s how it was designed.
-- https://www.seattletimes.com/business/boeing-aerospace/faile...
Even at Boeing's understated safety risk, redundancy is required. And the system actually has much more risk than they stated, since it will eventually totally deflect the stabilizer -- as happened to both fatal flights, with the jackscrews found in their farthest position in the wrecks.
I don't think any aviation expert would agree that the case for requiring redundancy in the MCAS system is weak.
But the normal way of stopping it (the yoke) doesn't necessarily work, and the pilots wouldn't necessarily think to physically stop the wheel with their hands.
I don't get why the plane doesn't just say what it's doing, and why it's doing it, and have a big red button to put the plane into a safe-mode alternate law. 737s already say warnings like "BANK ANGLE", couldn't it just say "DANGEROUS CLIMB DETECTED, TRIMMING NOSE DOWN. PRESS RED BUTTON TO CANCEL."
https://theaircurrent.com/aviation-safety/southwest-airlines...
A detailed explanation should not be required since they should know what the different warning lights mean and what can cause them to be lit.
I personally would like to see a list of the airlines that bought the more expensive 737 max that included the additional safety features.
Even the current training does not tell pilots to know that an AoA disagree light is an emergency because it can cause the plane to enter an uncommanded nosedive via MCAS. I really don't think it's reasonable to expect the pilots to know things that Boeing is not even trying to tell them.
The crew monitor the central EICAS display for fault indications, not random locations around the cockpit.
If you start bolting-on additional check locations you increase crew workload, particularly if it's not a 'dark cockpit' like an Airbus type.
It probably wouldn’t have mattered. Lion Air couldn’t even maintain their planes properly; assuming an extra indicator would help would be charitable at best.
Well, no. Pulling on the yoke traditionally moves the elevator. MCAS adjusts the horizontal stabilizer. You can adjust the stabilizer with switches on the yoke or with the trim wheels by your knee. MCAS will pause for five seconds if the pilot hits one of the switches on the yoke (and the Lion Air pilots did this until that stopped working).
They were saying you cannot counteract MCAS's control inputs with the elevator alone. Which is a somewhat unconventional design, in a lot of aircraft the elevator can overpower the horizontal stabilizer, whereas with a bad sensor MCAS will continue to move the stabilizer until you cannot overcome it.
To use a bad analogy, in a car the break is stronger than the accelerator, so if the peddle sticks you can still stop. In other aircraft the elevator is more powerful than the horizontal stabilizer.
Pulling on the yoke is not how you counteract a runaway stabilizer on the 737. I've pasted the relevant part of the QRH in a few previous comments. Yes, the stabilizer ultimately has more pitch authority under some circumstances. That may be what happened here, but if I'm interpreting the graphs on the preliminary report correctly I wonder about mechanical failure of some sort.
This gets a bit more complex with the 737 because moving the yoke WILL actually stop one of the stabilizer trim algorithms, but not MCAS.
It is how pilots learn to counteract nose down day one of pilot training. In many aircraft hard elevation will overpower even a faulty horizontal stabilizer. If the QRH was a panacea we would have 348 fewer loses today.
> That may be what happened here, but if I'm interpreting the graphs on the preliminary report correctly I wonder about mechanical failure of some sort.
There was a mechanical failure, the AoA sensor. I'm skeptical there needs to be more going on than MCAS due to the "repeated correction" unauthorized change Boeing made.
> “The FAA believed the airplane was designed to the 0.6 limit, and that’s what the foreign regulatory authorities thought, too,” said an FAA engineer. “It makes a difference in your assessment of the hazard involved.”
In the 737 you can get into situations where the elevator has insufficient authority to overcome a stabilizer. Excessive pitch up (leading to a potential stall) that you can't counter by pushing on the yoke is exactly what MCAS is designed to prevent.
There was a mechanical failure, the AoA sensor.
A fixed offset from reality is an interesting failure mode, especially in two separate sensors (Lion Air replaced the alpha vane before flight 610), and even more interesting as it's the same alpha vane used in the 737 NG. The left alpha vane was being interpreted as almost exactly twenty degrees higher than the right.
Is that because the plane was in a banking maneuver at the time maybe? I dont know anything about planes but I heard that when you're turning the two sensors will disagree by some amount
The difference in angle of attack was consistent throughout the entire flight (well up until the crash where the values began to converge). The threshold for the optional 'angle-of-attack disagree' warning is, I think, ten degrees. It seems very unlikely that the plane had a twenty degree bank angle for two entire flights.