Doomed Jets Lacked 2 Safety Features That Boeing Sold as Extras
nytimes.com
nytimes.com
Well that's something that is not comforting to read. Charging extra for comfier seats, I can understand, but charging extra for features that might be the difference between life and death for 100+ persons, that's just sick and criminal in my mind.
Regardless, the safety requirements in planes are much more stringent than in road vehicles.
It’s like side air bags in cars. Some have them, some don’t, but if you want them you will pay an extra 2 grand as each airbag unit is easily a grand each, and must be replaced completely if it ever deploys. If you buy your teenager a car you can decide if you will pay extra for those safety features.
Auto manufacturers don't make an engine compartment firewall optional, or sell full-strength seatbelts as an upgrade.
I think the idea is that some safety features are so important they shouldn't be optimal.
Not arguing against safety, and this doesn't relate to aircraft at all, but your examples are interesting.
Pretty sure all three of those were optional when they were new things. The pattern of being optional on luxury vehicles, then standard on luxury models / optional on normal models, and finally, standard on all vehicles...is common.
In my view it should be criminal to withhold such safety features for profit.
How was MCAS rolled out and certified flight-ready when it did not rely on readings from both sensors? This breaks a cardinal law of airplane safety -- always have redundancy.
Then Boeing increased how much authority the system had to pass a different part of certification without telling the FAA.
> “The FAA believed the airplane was designed to the 0.6 limit, and that’s what the foreign regulatory authorities thought, too,” said an FAA engineer. “It makes a difference in your assessment of the hazard involved.”
[...]
> The discrepancy over this number is magnified by another element in the System Safety Analysis: The limit of the system’s authority to move the tail applies each time MCAS is triggered. And it can be triggered multiple times, as it was on the Lion Air flight.
I'd suggest reading the full article/context:
https://www.seattletimes.com/business/boeing-aerospace/faile...
If anything, it's MCAS that needs to be heeding the AoA readings disagreement. Instead it's more than happy to only rely on the reading of one of the sensors.
> Since MCAS was supposed to activate only in extreme circumstances far outside the normal flight envelope, Boeing decided that 737 pilots needed no extra training on the system — and indeed that they didn’t even need to know about it. It was not mentioned in their flight manuals.
> That stance allowed the new jet to earn a common “type rating” with existing 737 models, allowing airlines to minimize training of pilots moving to the MAX.
https://www.seattletimes.com/business/boeing-aerospace/faile...
It would seem that AoA disagreement would be the very first symptom of the failure that lead to these crashes. Since pilots are likely not to immediately notice this (hence the indicator), this feature may well have given them additional time to sort out a response. Depending on how this failure progressed, it may have even been discovered on previous flights or before take-off.
The AoA disagree could go off as soon as the nose is lifted, which still may give pilots just enough time to abort take-off or immediately request landing.
Airliners are committed to takeoff by the point of rotation. Typical ops manuals would abort for any warning before 80kts, at a speed known as V1 they are committed (even in case of engine failure) this typically occurs 10-20kts before rotation speed where the pilot initiates lifting the nose.
It's questionable if most pilots would abort a take off because of an AoA sensor discrepancy, especially if they didn't know it controls MCAS or that MCAS exists in the first place.
But yeah - good point about it potentially triggering further diagnostics prior to the flight altogether.
Reminds me so much of the car market though. Adding a $3 thermistor is "automatic temperature control" and requires a trim level that costs $1,400 more.
In software upgrades, the marginal cost is near zero.
An AOA difference indicator price is negligible compared to the total cost of an aircraft.
The designers generally don't care what happens to the rest of the car after deployment, so expect a broken windshield, various broken dashboard components, destroyed steering wheel components, HVAC system cracked (ducts, freon lines, vacuum lines, and water lines), broken wires of various kinds...
Even if the air conditioner evaporator coil wasn't cracked, for example, the sheer labor cost of having to disassemble and inspect the entire interior of the car is very expensive for labor. Technically yes you can replace an airbag in about an hour, then you discover there's no turn signals and at next inspection/registration you discover there's no working horn, etc etc it adds up.
You can have the latest, safest car money will buy and get plowed by a 30 years old land rover without any crumple zone and die because he couldn't stop in the snow/rain (bald tires, used break pads, &c.).
It's always a balance between regulations and ""freedom"".
In some US states you can drive anything as long as it has and engine and a plate. I lived in CA for a while, everyone drive with bald tire, I remember opening google maps on a rainy day, LA area was full of the red ! accident signs.
The world is a big kindergarden, you can't expect people/companies to do what's best for themselves/others so you have to enforce the rules through laws and regulations.
If companies were allowed to sell cars without safety features for a lower price people would buy them.
> When comparing old vs new cars the size difference is completely irrelevant.
impact force = mass * speed² / (2 * distance)
The crumple zone of modern car improves your _distance_ here, mass (size) still plays a huge role.
On the other hand it costs money to develop these systems. The people developing them deserve to get paid. The government needs to decide at what points it becomes mandatory to have these systems.
If companies can't charge for new safety features, the result will be every company getting out of the safety feature (non-)business.
If the newest safety features make cars unaffordable for most, people will complain also.
Airbags and, to a lesser degree, ABS definitely add substantial costs to cars. So it wasn't entirely unreasonable to ask customers for extra money. Yet subsequently, as they became cheaper and proved their potential to safe lives, they became mandatory. If I had been in a position to make decisions on this, I believe I would have argued for charging costs only for these features. Volvo's publicly announced decision not to enforce its patent on seat belts is example of a company with a mindset that goes beyond pure profit.
Judging Boeing's strategy here obviously requires a better idea of what they were charging and the actual costs of installing these features.
There may well be an argument that these systems are not comparable to airbags, but rather "pay us $X,XXX extra, and your car will not have a 10% chance of randomly blowing up".
"Nice plane you have here. Would be a shame if it crashes..."
I have seen this argument before, by a Nobel Memorial prize in economics, Milton Friedman. [1] https://www.youtube.com/watch?v=jltnBOrCB7I
Overall he said, that it is not possible, as a principle, to put 'infinite' economic value into individual life.
--
Perhaps the argument can be made, that in a different situation the 'other data' pilots were to use, would increase safety.
--
Either way, I think there is something wrong with Friedman's argument.
'Optionality' -- when related to safety features, should be treated very different, than optionality in, say, comfort features.
Passengers themselves should not be expected to make choices which optional safety features, on a car, a bus, or plane should be purchased by the drivers/operators.
Drivers, should not be expected to make these choices, either.
My thinking here, is that An optionality in safety device, should change the whole major (not minor) vehicle model number designation, for example.
This would drive different visible profiles: different training, cost, marketing and so on.
It's pretty much inexcusable when the safety features have near-zero marginal cost to implement.
Kinda like if you or I could rent an 18-wheeler truck with a promise that it "drives just like a car."
One wonders: Did outside air temperature or weight-and-balance issues figure in to these crashes? Hotter=less lift. Weight too far aft=nose up tendency.
Its an error of regulation to permit a ridiculously safety critical real world physical system to digitally emulate a historical virtual system to save training money. Its a perfectly good aircraft on its own; it just has intentionally hacked and modified controllers to fake being another plane, and those hacked and modified controls unfortunately kill hundreds of people.
Given the merger of government and aerospace its going to be a huge dysfunctional fight where neither side can back down and admit they need to change things. My guess is for purely political reasons both sides will admit guilt, although its obviously completely a government failure. On the other hand, as per the recent VW Diesel situation, if the government implements stupid regulations that are followed to the letter resulting in predictably dumb outcomes, the government accepted no blame and the company was attacked. There are strong indications going both directions which will make this interesting to watch.
That analogy implies that the pilots were trying to fly the plane in a way that it couldn't handle. A better analogy would be a safety mechanism on the SUV that prevents drivers from turning too sharply and rolling over. The crashes are caused by that system incorrectly measuring the turn rate, forcing the car to drive straight, and have it run off the road.
Really, there's nothing wrong with the MCAS system in theory. Plenty of planes require computer controlled inputs to fly safely. The problem is in the execution. The base model lacks redundancy and pilots weren't trained well enough to handle the system malfunctioning. And in the case of the Lion Air crash a poor safety culture.
Honestly, the problem is probably already solved at this point. Correcting the issue that caused the crashes is simply flipping a switch. The issue is identifying what's causing the control issues to know which switch to flip. Every pilot should be hyper aware of the potential issue and they'll be able to easily diagnose and fix in flight issues.
So, its more like an Volvo 18 wheeler which drives just like your Volvo hatchback except when you try to take really sharp turns under power.
I’m sure there are better examples that have a higher probability of improving safety, but for some fun examples, where are the massive, inflatable, roofmounted airfoils that inflate like big airbag parachutes in the event of an impending crash. What about 5 pt harnesses for all passenger? Where are the uniformed armed security squad on every flight to deter hostage situations? What about full situational awareness mesh network radar comms a la the F-35? What about no carryons allowed in the cabin to reduce flammability and airborne objects during crashes? Each of these things offers a potential, incrementally-increasing level of safety for passengers, that are not taken up by the market.
For an analogy, If my cabby didn’t buy curtain airbags from the Ford, and I get my head smashed in a wreck caused by a malfunctioning component elsewhere in the car, doesn’t the cab company still have some culpability for skimping in passenger safety? If not in that scenario, what about a poor level of maintenance (but still technically compliant) of the vehicle? At some point, for contracts of carriage, it’s up to the carrier to establish an expected, acceptable level of safety for its customers.
Again, it sounds like Boeing bears the lead blame, and it wasn’t clear the features as sold offered valuable data to the pilot in the event of an emergency, but I also expect my airline/carrier to provide as much safety is commercially reasonable. Just like when reviewing legal contracts or lines of code, if a line item is added with no obvious reason for existing, one must ask “why is this item here?”
That said, given the sensors are used directly as input having a disagree light is a reasonable thing to expect.
https://www.ainonline.com/aviation-news/general-aviation/201...
Since these are twin engine aircraft, you could make many arguments about blue line speeds and balanced runway lengths but I'll take your point.
It become a safety critical sensor as soon as flight inputs are directed as a result of its data. For example, bad data has now resulted in 346 deaths, if that isn't safety critical I don't know what the criterion would be.
It is quite likely that the pilots were overwhelmed with warnings (e.g. stick shaker activation) and conflicting data. It's not clear that presenting yet more conflicting data would have averted the disasters.
Limiting the authority of the MCAS system is likely to be the real fix.
But there has been on Lion Air, compelling ADS-B data for Ethiopian, and every regulatory agency in the world agrees they're similar enough to warrant grounding the entire fleet.
> Limiting the authority of the MCAS system is likely to be the real fix.
They're already changing it to take data from both sensors, and there's been talk of requiring a third for voting logic. So the "real fix" is treating a safety critical sensor as a safety critical sensor.
Not according to the press release.
https://boeing.mediaroom.com/news-releases-statements?item=1...
Interconnects like that are quite unusual. For example the autopilot is typically driven from either the same data source as pilot or the co-pilots system. There are some exceptions, for example in full auto-land mode both systems are engaged. But that really is an exception, only a fraction of the worlds runways have CATIII certification and they require special ground operations to support them.
There are procedures designed to ensure the systems agree on certain critical data, for example the 'pilot not flying' will usually call out 80 knots and cross check that the speed agrees between both sides.
Questionable conclusion, the press release doesn't go into details either way.
To quote this NYT article:
> Boeing is updating the software to require data from both sensors for the system to kick in, according to pilots at several major airlines and two lawmakers briefed on the matter.
https://www.nytimes.com/2019/03/15/business/boeing-ethiopian...
> Interconnects like that are quite unusual.
Not in aviation, for example the Airbus A330 has triple redundant Pitot tubes, the B737CL (Boeing 737 "classic") has four, the B737NG has three (737 Next Gen), etc.
So this "quite unusual" system appears on the very airplane we're discussing for the Pitot-Static System, a safety critical sensor.
I don't know much about the Airbus pitot system, except one ended up at the bottom of the Atlantic due, in part, to a frozen pitot tube.
You're mistaken. To quote Boeing themselves:
> The most modern systems today use an air data inertial reference unit (ADIRU), which incorporates the best information from three pitot and static sources and provides a single set of data to both pilots. An ADIRU receives information from air data modules, which are located close to the pressure sources.
This is used on, at least the Boeing 757, 737 and Airbus A319, A320, A321, A330, & A340.
For example read this report:
https://assets.publishing.service.gov.uk/media/578df0f5e5274...
> The Boeing 737 NG series are fitted with pitot probes mounted on the left and right of the fuselage just aft of the radome. The aircraft are also fitted with an auxiliary probe on the right side of the forward fuselage and two ‘elevator pitot probes’ on the fin.
The triple redundant system initiated a "IAS and ALT disagree master caution." Which is exactly what a safety critical sensor is meant to do.
As an aside I'm done conversing with you on this topic. You keep on saying incorrect things, link to bad citations that don't support your previous statements, and when that fails moving the goalposts to something else entirely. It isn't a good faith way to have a discussion.
Keep in mind half a dozen posts ago you claimed no aircraft used triple redundancy or voting logic (which the 737 does, as I've shown and your own citation shows). Now your argument has shifted to some kind of pedantic one about which exact systems consume what data or similar.
I pointed out that it would be highly unusual for them to cross connect the inputs as that's not normally the design of aviation systems.
You said:
> The most modern systems today use an air data inertial reference unit (ADIRU), which incorporates the best information from three pitot and static sources and provides a single set of data to both pilots.
The report said:
> The aircraft was on approach to London Gatwick when the crew was presented with erroneous airspeed and altitude information on one of the two cockpit display systems.
These statements are clearly at odds with one another. That isn't a pedantic argument. The systems have a clear A and B system and cross connects between them are minimised.
> Keep in mind half a dozen posts ago you claimed no aircraft used triple redundancy or voting logic
I didn't claim that. I said on the 737NG the 3 inputs (actually there are 4, the additional one drives an auxiliary set of flight instruments) aren't averaged voted upon or compared. The 3 instruments simply display data taken their inputs, even when they are potentially wrong.
Technically the pilot and co-pilot IAS is compared in that it can sound a master caution if they disagree. This is a long way from automatically choosing the best air data.
Additionally, the A330 which you introduced to the conversation, has 3 independent systems. However, they however functionally they don't drive the autopilot or the pilots display based on the 'best' data. They simply display their output, unless the input source is manually changed to the hot standby.
From the report on AF447 an Airbus A330. Again, much as I described.
https://www.seattletimes.com/business/boeing-aerospace/faile...
However, the point I started with is displaying the AoA in the cockpit is unlikely to have helped any of that. It's not really a safety feature except in quite specific scenarios (where the pilot is trying to extract maximum performance from an aircraft).
The other point I was making is that it's unlikely that they'll fit an extra sensor or cross connect the inputs. There are few systems which receive data from both pilots and co-pilots sources.
On the other hand, there is indicated airspeed, the traditional proxy for AofA. It, too, has its dependencies, but I think they are either measurable (e.g. flaps (, outside air temp.?)) or can be estimated from slowly changing values (e.g. weight from initial gross weight and fuel burn.)
They have TCAS warning and know the height of the ground at any point on earth. Yet they'll let you dial up a path on the autopilot that flies straight through a mountain. It's only relatively recently that light aircraft autopilots gained envelop protection, until then they'd happily fly an aircraft into a stall trying to maintain the set parameters.
In an emergency, too many warnings can be harmful. This can be a problem in hospitals, where every device beeps for all sorts of reasons. At Three Mile Island, the control panel became a 'christmas tree' of colored lights, when there was really only one problem: a stuck valve.
It is especially a problem when the significance of the alarm is not clear, as when a sensor is a control input to multiple systems with complex algorithms.
I would guess a warning light would be most useful in pre-flight checks, as a go/no-go indicator. It could also be an item in troubleshooting checklists (if the stick is shaking, yet the airspeed is good, is the AofA light on?)
> A related habit uses editor commands to signify corrections to previous text. This custom faded in email as more mailers got good editing capabilities, only to take on new life on IRCs and other line-based chat systems. [...] The s/Erik/Eric/ says “change Erik to Eric in the preceding”. This syntax is borrowed from the Unix editing tools ed and sed, but is widely recognized by non-Unix hackers as well.
The 737 is a classic story of undercompetition and underinvestment. The design goes back to the 1958 era 707, and it feels tiny on the outside even though it is big on the inside.
The Embraer 195 is much smaller than the 737 but it feels more like the 767 inside because it is designed with the human physique in mind.
Boeing was shocked by what it cost to develop the 787, but had it given the same treatment to the 737 it would have been able to recoup the costs more quickly because so many 737s get made. Also since the 737 is so common in the sky anyone who is concerned about climate change, noise, or any other environmental effects of air travel would see the 737 as a priority.
Ten years ago you could take a widebody from NYC to LAX. Today if you fly, you wind up on a 737 or an A320 which is basically the same thing. For me it is a reason to stay home, drive, or take the bus.