Boeing CEO Dennis Muilenburg Addresses the Ethiopian Airlines Flight 302 Report
boeing.mediaroom.com
boeing.mediaroom.com
He admits that MCAS "activated in response to erroneous angle of attack information" but doesn't admit that this alone directly resulted in the crashes. Rather, he implies that this sets off a chain of events which the pilots are unable to deal with ("pilots have told us, erroneous activation of the MCAS function can add to what is already a high workload environment") which puts undue blame on the pilots rather than the system.
If you'll excuse the analogy, it's as if they installed a new griddle in a restaurant kitchen which randomly gets ten times more hot than it ought to be, with no warning. The cook doesn't know it's too hot until the eggs start burning. Now the manager is saying that since the kitchen is so busy, the cook can't flip the eggs fast enough in response to these randomly fluctuating high temperature events. We're being told it's the cooks' fault.
I don't like being bullshitted and find this sort of dodgy language completely inappropriate when 300 people died.
That said, it's also true that Boeing is in a boatload of trouble. This is gonna get ugly. Likely not for the CEO. I'm pretty sure his signature is not on any of the relevant paperwork. But now that this report has been released, it might be prudent for people who do have their signatures on the relevant paperwork just to consult with some legal counsel. I suspect Boeing, as a company, wouldn't hesitate to throw them under the bus.
Sorry, but that's bull. Owning the mistake - and yes, that includes paying the families of the victims - and offering a serious apology combined with "that's what we will do to make sure it never happens again" would have been the best way to guarantee that Boeing as the current company will continue to exist. Right now they risk the 737 MAX being scrapped and governments around the work taking actions against the obvious regulatory shortcomings - the corruption that obviously happened, to have a plane being able to run itself into the ground based on one sensor system without any redundancies or other securities.
Now they need the US to protect them with further illegal subventions and government influence because they are too important for that country to fail. That's in no way the ideal way to follow "fiduciary obligations".
With all due respect, that's Bullshit, and anyone who cares to look into the provenance of the modern concept of a corporation can see that.
A corporation is a mechanism by which people pool resources and distribute risk such that endeavors unachievable by any individual of that collective group. This privileged collective vehicle, however, was based on the principle that the existence of the corporation was providing a service or good to the benefit of the society enabling the incorporation.
As a sibling poster mentioned, the Reagan/Thatcher years ushered in "the death of Society" and the birth of the "shareholder value" meme.
A corporation does not exist without the societal framework in which it is implemented. If corporations don't take this into account moving forward, the system that put them in a position to do what they are doing may find itself under attack from without by legislators, and within by an increasingly marginalized millennial demographic.
Point being, you can't sit here and say that the only obligation executives have is to their shareholders when the entire arrangement that makes that possible is dependent on the goodwill of everyone else who isn't a shareholder.
I acknowledge my arguments may not convince a hard core "shareholder value" believer, but I'm willing to put my money in the long run on the state of corporatism in America sidling up to a line after which there isn't going to be much they have to lean on once people start realizing that shareholder/not shareholder is becoming the new social division point. Either we're all countrymen, or we're not. If corporate America pounds the "not" drum hard enough, I have no delusions enough people won't get together to bring the entire house of cards to the ground.
Corporations and government have hands in each others' pockets. They are protected by court systems designed in their favor, weapons which could wipe out populations in an instant, and complete control of the technology we all use to communicate.
This is the "shareholder value" theory, modern economists successfully brainwashed the population with. It became popular during the 1980s, "greed is good" times. It's just an ideology disguised as a science. The purpose and structure of modern corporation hasn't changed in the last hundred years or so. In 1950s and 1960s the public good, among others, role of corporations was wildly accepted. What changed is the ideologues who became more vicious and took complete control of the narrative.
This is what people are referring to when they say "shareholder value" -- diving up the value of the stock.
https://duckduckgo.com/?q=money+stuff+matt+levine+%22everyth...
https://www.warren.senate.gov/newsroom/press-releases/warren...
Holy crap, should I be on the lookout for black helicopters?
For someone having the same problem: https://web.archive.org/web/20190402011933/https://www.warre...
As much as we would love to having Boeing stock plummet, it will impact most people even if they're not aware that they own it.
I don't expect him to kill himself, but honesty seems the least we should expect in its place. Dishonesty is what caused it, and dishonesty continues dragging it out.
He should be pelted with rotten fruit whenever he show his face in public until he comes clean.
Capitalism, baby!
I know what you are saying and fully agree but would like to put a finer point on it: the problem is with unfettered capitalism, especially after 100 years or more of the lawyers writing the laws for the wealthy, who own the vast majority of the corps.
What we need is a balance between the entrepreneurial spirit of capitalism and governments that enforce corporate responsibility to its human workers and our communal environment. The corps have very effectively massaged the legal systems of the world into removing almost all notions of corporate responsibility. And here we are.
Sure, but then I'd like for people to also realize that the problem is with authoritarian communism. Sadly, only capitalism seems to get a break.
But that's not how this whole show goes. CEOs are like robots that only act happy or serious. Go into a press conference and act all remorseful for the public, but don't ever offer a genuine apology or own up to the company's actions. Then when all the legal dust clears, the CEO can give a later update about how he is "shocked and appalled" that a verdict could possibly blame Boeing. What a joke.
https://scholarship.law.cornell.edu/cgi/viewcontent.cgi?arti...
I'd be very surprised if it did happen. "Lucky" for Boeing, it was mostly brown people in a third world country that died. Had it instead been two American planes that went down, Boeing and their executives would be in significantly deeper shit.
Back to the topic - I am not surprised by this kind of empty bullshit talks from CEO, what else to expect from massive PR team? Each word was carefully considered together with big team of lawyers too. For me the outcomes are clear:
- be very suspicious about anything coming from Boeing, their reputation is properly damaged (Airbus doesn't get a free pass, but their products didn't kill 300 people recently and they didn't try to shift blame everywhere else but themselves although things are crystal clear now)
- FAA lost any credibility, period. Globally no other national agency should trust its evaluations, since its obviously susceptible to external pressures and failed at its core mission, directly in the media spotlights, globally, just few weeks ago. Gaining back the trust would be a lengthy process of measurable changes that led to their failure to act, and monitoring the results of this for quite some time.
In the section "Questioning the Foundations of Traditional Safety Engineering":
Old Assumption
Most accidents are caused by operator error. Rewarding safe behaviour and punishing unsafe behaviours will eliminate or reduce accidents significantly.
New Assumption
Operator error is a product of the environment in which it occurs. To reduce operator "error" we must change the environment in which the operator works.
And: Old Assumption
Major accidents occur from the chance simultaneous occurrence of random events.
New Assumption
Systems will tend to migrate toward states of higher risk. Such migration is predictable and can be prevented by appropriate system design or detected during operations using leading indicators of increasing risk.
In the press release we see both the "operator error" and "random events" hand-waving. Regardless of the fiduciary duty of this man, this is just not good enough.[0] Open Access PDF: https://mitpress.mit.edu/books/engineering-safer-world
"Old Assumption
- Most accidents are caused by operator error. Rewarding safe behaviour and punishing unsafe behaviours will eliminate or reduce accidents significantly.
New Assumption
- Operator error is a product of the environment in which it occurs. To reduce operator "error" we must change the environment in which the operator works.
---
Old Assumption
- Major accidents occur from the chance simultaneous occurrence of random events.
New Assumption
- Systems will tend to migrate toward states of higher risk. Such migration is predictable and can be prevented by appropriate system design or detected during operations using leading indicators of increasing risk."
Just a day ago, user Gibbon1 also posted a link to a talk by the author of that book:
"Operator error is a symptom, not a cause."
Ms. Leveson's book "Engineering a Safer World" has a free PDF download at http://sunnyday.mit.edu/safer-world.pdf
They should do it anyway. After the Challenger and Columbia disasters, there were major public changes at NASA. If there are none at Boeing now, we have a huge problem (since the number of deaths is an order of magnitude larger!).
... reducing crew workload enough that the crew have a chance to figure out why the plane is trying to kill them? Nice move.
Am I irrational for not wanting to be on the first 1-2 years of flights on 737 MAX after it gets its software update?
The first accident was maybe understandable. We all know that shit happens. But Boeing has zero excuses for not immediately grounding the whole fleet after, and for putting out that useless recovery procedure which didn't work in this case. They let a deadly plane fly for 5 months after they were aware of it, and after the second crash they were phoning Trump to keep it in the air.
This is some Challenger O-ring type of shitshow. Accidents are one thing; incompetency or, worse yet, callous indifference is absolutely unacceptable.
That's just unrealistic. Unless you want plane and car rides to cost as much as a trip to space, after all, since everything would need to be engineered to that level of quality.
I said: "Accidents are one thing; incompetency or, worse yet, callous indifference is absolutely unacceptable."
Anybody may have a different judgement with respect to exactly where on the scale is appropriate, but we cannot just pretend that there's no trade-off to be made. Or that absolute safety is even a possibility.
It's sad, but most faults seem to be like this. First one is treated as an anomaly, second one is treated as the start of a trend. It happens so many times I'm glad I'm not working with human lives.
I wish this statement was held with as much as accountability as this comment implies. But have any of the major outlets been discussing potential prison sentences for Boeing or FAA employees / executives or potentially even board members? If you want accountability in today's age it seems the pressure needs to be applied at the point where financial decisions are held with more precedent than safety of life.
Boeing stock was up today on the glimmer of hope that the "software fix was working". Investors are assuming the stock is on sale and this only impacts Boeing for, what, a few weeks? I said something similar in another comment but I think Volkswagen is going to do more jail time and have more brand detriment than Boeing or the FAA will. Egregious doesn't begin to describe the misdirection of conversation. Why is the focus not yet on who will be sentenced for death over profits?
Reminds me of the Equifax breach. Stock tumbles then recovers. Overall, it validates that breaches are not a liability; therefore, additional resources to address future problems could be seen as a moot point.
Same with Boeing. If there is no impact to the company, then why change the business model?
If you don't have food in your belly and you steal you get jailed. You are not satisfied with your million dollar salary and your billion dollar company profit and don't care if people get killed, you get to have PR firm write how sorry and sincere you are. Justice seems truly blind so many times just not in the way the phrase was coined.
And they're totally going go get a fair trial and not some sort of kangaroo court to appease the locals?
But I do get your point.
I think it's worse.
The first crash can be compared to the Challenger shitshow. It was a (massive) engineering mistake, which lead to the Lion Air plane crashing. Looking at the history of the 737 in general and the 737-MAX specifically it was rekless, but I'm pretty certain not intentional or foreseen by Boeing.
That massively changed by the fact that they didn't immediately pull the plane after this crash and went into deep analysis mode to really evaluate the cause. Instead they smeared everybody but themselves, developed a completely useless checklist without really knowing or (apparently) caring if it's useful at all and let that deathtrap fly.
The second crash, in my opinion is corporate mass murder for profit. Maybe not legally, but morally most certainly.
There is always a trade off, your statement is too bold for a world of limited resources. We can use engineering to make the roads safer. Spent a trillion USD on road safety will save lives for sure. But maybe it is spend better on cancer R&D efforts?
The safest plane would be the most expensive and most uncompetitive since it needs unlimited resources and unlimited time for being designed.
It's not so much a matter of ressources than of specifically engineering excellence. There's plentiful examples of a much better product that was created with less ressources than the shitty existing competition (this must be commonplace for HN members).
I'm convinced the safest plane is not the most expensive, it's the one designed through sound and clear-sighted engineering.
Are you an engineer? Your argument sounds naive. Or to give a counter example: In the Soviet Union there were likely more accidents (normalized) compared to the west. Yet, they did not focus on maximizing profits.
A simpler yet effective design (may it be initial or rework) comes at a much lower cost than a flawed one, which inevitably aggregates irrelevant complexities.
Who decides this? This is not a trivial question.
The F-35 fighter is a good example. Trades many disadvantages (not fast, not good in dog-fighting, tremendous long maintenance time, low payload etc.) for one advantage. The F-35 may or may not be invisible to an able opponent. But this decision is a tremendous difficult one. Based on your argument, it would be better to stick with a simple design. This was worked for the Soviet Union in WW2 (don't build the best tank, build a decent one, build many).
You may like this story: https://en.wikipedia.org/wiki/Superiority_(short_story)
I'm not comparing simple vs. complex but rather sound vs. flawed, although often sound = simpler than flawed.
The 737 here is yet another example of this : - the MAX design is flawed : faulty risk assessment of MCAS, seemingly unstable airframe in some configurations - a likely sound design could be : airframe rework, thorough risk assessment, extra pilot training...
While the flawed design came at a lower initial cost, it will now overrun the cost of a likely sound one (further rework + retrofit + sales/reputation damage + legal), including the cost of a probable longer design phase in the latter.
(I concede that legal/sales costs are not directly technical debt costs).
Therefore, our medicine is not perfectly safe, our cars are not perfectly safe, our building are not perfectly safe, we don't / can't provide 100% health coverage to everyone, and so on... but in aggregate, they make the world a better place, so it's worth it.
I wonder if the European agency (don't remember the name) will stop trusting the FAA from now on and do their own tests. I'd thank them for that.
(According to what I read here, the European agency doesn't do exhaustive tests because they mostly trust whatever the FAA says; maybe that's false)
That's true. The FAA had a stellar record as a certification agency, which, it can be argued, they fucked in three days (sure, the hole history of this sad debacle is more complex. But by keeping the plane in the air longer than any other certification body in order to not hurt their buddies at Boeing they completely ruined their reputation, which was built in decades of good work).
I can't imagine that any responsible certification body anywhere trusts the FAA anymore without a complete and significant shakeup.
It's a sad story, really.
This is unlikely to change. It’s expected that some changes will occur at the FAA. Certifying an airliner is also a prohibitively expensive undertaking, which is part of the reason for this mess in the first place. It would take years even to train enough personnel to duplicate all those efforts.
EASA.
FWIW, the Brazilian regulator (whose name I don't remember...) did not rubber-stamp the FAA's type certification of the 737 MAX, and required some differences training for MCAS, IIRC.
And, yes, the Ethiopian Air pilots apparently did follow the procedures initially, flipping the Stab Trim Cutout switches, but did not manage to recenter the trim manually (via the trim wheel), so apparently re-enabled electric trim, and then let MCAS drive the trim even further down to their doom. :-/
"Those who don't remember history are doomed to repeat it"
It's been a couple of decades I think, maybe more, since an engineering screwup affected a passenger airliner like this. You could argue that the 787 LiIon battery thermal runaway thing was a red flag. That also resulted in an FAA grounding, but that was fairly easily remedied and nobody died.
From documents I've seen (which I cannot find the links to now), it appears that the FAA let Boeing themselves do some of the certification work and sign offs.
Putting the foxes in charge of the hen house, so to speak.
They become primarily concerned with the interests of the companies they're regulating, rather than the public interest they're in theory tasked with working for.
Unfortunately, that is just how a regulated society works.
So without regulations, there are fewer people to corrupt.
just because a regulatory agency did its job by protecting the pulic’s interest doesn’t mean it will always work that way. so your example doesn’t negate the existence of regulatory capture, which is an actual thing and not some political propaganda.
https://en.wikipedia.org/wiki/Regulatory_capture
https://en.wikipedia.org/wiki/Public_choice
Of course, my post above is sharpened and overgeneralized to fit in an online forum. There are more nuances.
A current example in the news is Facebook asking congress to be regulated. This makes little sense from a conventional perspective. From the Regulatory Capture perspective it's an obvious play. Government regulation will be very costly to comply with, and only FB and a few other giants will be able to afford it, thus cementing FBs monopoly position for the foreseeable future.
https://www.insidesources.com/facebooks-mark-zuckerberg-asks...
To be fair, Public Choice theory is certainly on the more controversial half of the subfields.
And of course you shouldn't blindly take some random post on this forum as complete proof of how the world works. That would be a foolish gullibility. Then again, completely rejecting it isn't the wisest thing either. At least that's my view :)
When has economics ever been a science?
But that's a small part of Economics, and the field in general is as hard as any science outside of physics, and had given us an enormous amount of insights we lacked 200 years ago, and contributed immensely to the relative peace and prosperity the world enjoys today.
Private enterprise has an analogue: principle-agent problem.
When CEO said "We're taking a comprehensive, disciplined approach, and taking the time, to get the software update right.", I wondered if they would characterize their initial design the same way.
It's shameful to even try to pin it on software. The fundamental problem is that they didn't want to do the right thing by admitting and teaching pilots that this plane has different flight characteristics and they need to train for flying a similar, but different plane.
As long as this MCAS software even exists on the plane, I'll never fly on one again. If they take MCAS out, certify, and train properly then I'll fly on them. Otherwise, no.
The problem is they can't take the MCAS out.
The MCAS is there to fix a design fault whereby the plane has a tendency to pitch up automatically (and hence have a chance of stalling) when accelerating, due to the oversize engines and their placement.
To me, it all comes down to to Boeing being able to self-certify their aircraft, and they knew they were sneaking the "fix" known as MCAS as a way to prevent loss of sales to A320. Super shady in my opinion.
The script required them to manually crank in the stabilizer, which wasn't possible. The script was manifestly not "working". That doesn't "remain to be seen" -- it's in the transcript of the cockpit
> At 05:41:46, the Captain asked the First-Officer if the trim is functional. The First-Officer has replied that the trim was not working and asked if he could try it manually. The Captain told him to try. At 05:41:54, the First-Officer replied that it is not working.
I guess the First-Officer must have been speculating...
Until someone sits down and calculates the torque needed to manually trim it's all just speculation.
They weren't
>the pilot is busy supplying maximum pull on the yoke,
Probably not true either
>and therefore likely unavailable to help crank a stiff trim wheel
Runaway trim should be a recoverable situation. If that's impossible then that means there is a distinct and major issue beyond MCAS.
> They weren't
They just took off, max height of the airplane was 1000 feet above the ground. That's a definely low altitude.
> Runaway trim should be a recoverable situation.
The trim pointed the nose down. The aerodynamic forces were so high on the elevator that the trim wheels could not be moved by a single person. This was confirmed in 737 simulator.
People thought that based on Flightaware data. But if you actually read the report you will see that it is incorrect and they reached about 7,000 feet.
>The trim pointed the nose down.
Incorrect. The plane was steadily gaining altitude until they re-enabled electric trim.
>I wouldn't feed the troll, but I don't want your misinformation to spread.
Try being right before throwing around personal insults.
which points clearly to MCAS applying maximum nose down, based on incorrect data from the left alpha sensor, both pilots pulling on their control sticks, and the aircraft failing to gain altitude even before final MCAS activation because the trim could not be manually reset by the F/O.
this report contradicts every element that you're pushing (plane reached altitude, pilots didn't pull on the column, the electric trim was not needed, MCAS did not intervene). did I missing anything ?
Screw Jack and effort force https://www.engineeringtoolbox.com/screw-jack-d_1308.html
Gearing: https://www.engineeringtoolbox.com/gears-d_1307.html
Here's some 737-800 dimensional analysis as a starting point.
https://holdingpoint.wordpress.com/2011/04/04/boeing-737-800...
Knock yourself out.
Or if you stick around long enough I may do it for gits and shiggles.
I'll need some schematic details of the actual manual trim wheel mechanism to figure out what the output forces on the jackscrew are... But hey, sounds like a fun mental exercise.
I'll see if I can find any details on it, but if anyone else just has it, reply to me, and let's see if we can get some delicious numbers going on here. Worst case scenario, I'll pull whatever design most makes sense to me out of my arse and theorycraft to get a feel for it.
737-800 has a 32.776m^2 horizontal stabilizer area. Let's double that to 65.556 to accomodate both airfoils.
Wing load is 1/2p(v^2)A Where A=65.556m^2 (352.8 ft^2) v=180.556m/s (350 knots) And we'll guess our air density around .95ish kg/m^3 given our altitude of 2334m (7625 ft plus change) asl
Barring any flawed fundamental assumptions, that gives us a wind load of 1015087 N (228200.636 pounds-force (lbf)), and a dynamic pressure of 15485 N/m^2
I'll leave this out there to offend any actual aerospace engineers that might be reading so they'll tell us I'm doing it all wrong while I try to work out whether I can use the screw jack equations and what we've calculated thusfar in the hopes of figuring out something that even remotely makes sense.
I have a feeling I'm oversimplifying or misapplying the wind load equation. But hey, it's the internet. I'm allowed to be wrong.
Dropping in the previously calculated wind load of 1015087 N, we end up with an effort force of 3182 N, which through a 6 in pulley would be 485Nm (357 ft-lbs) of torque,
Note, we're in automobile engine levels of torque output to actuate this screw jack against the wind load on the horizontal stabilizer.
Give me a bit to come up with some estimates on the trim wheel and play around with some gear trains to see if I can come up with an arrangement that does the trick.
It should be doable, but with the gear ratios I'm thinking will be required to generate the requisite torque, the actual rate of actuation is going to be pretty slow.
Your responses have been incredibly selective about which parts of the report you take as gospel and which you handwave away as "speculation".
From where I'm sitting it appears you've started out by picking a contrarian conclusion you like ("the plane was safe once STAB CUTOUT was set cutout, and the crew could have maintained altitude indefinitely at that point, but fatally fucked up by re-engaging electronic trim to try to trim the stabilizer"), and to maintain that a priori conclusion you've consistently ignored the data and parts of the transcript that indicate that was very likely impossible.
Where is that data in the report?
> At 05:41:30, the Captain requested the First-Officer to pitch up with him and the First-Officer acknowledged.
> At 05:43:04, the Captain asked the First Officer to pitch up together and said that pitch is not enough.
Take a look at the chart of control column position deflections. They're jolting around like crazy at +10 to +15 aft starting immediately at the first big MCAS trim event through to the end of the recording. That's because the stabilizer mis-trim is exerting considerable force on the elevator. The captain wasn't calling for aid on the column for shits and giggles.
okay
https://www.satcom.guru/2019/04/stabilizer-trim-loads-and-ra...
05:41:30 - PIC requests SIC to pitch up with him
05:41:46, 05:41:54 manual trim not working, that is absolutely a trim wheel hand crank attempt; fairly clear (to me) but not stated is that both pilots were not simultaneously cranking on the trim wheel, there's plenty of anecdotal evidence that this exact configuration puts to much upward force on the jackscrew that it is difficult to impossible to turn.
05:43:04, PIC asks SIC to pitch up together says pitch is not enough
As for the noisiness of the control column position data, it could be partly the stick shaker, it could be light turbulence, the accel vert row at the bottom shows it's a bumpy flight, and pitch and roll attitude is also variable but less so than vertical accelerate. And accel vert gets noticably more perturbed as airspeed increases. I think it's light to moderate turbulence, but I'm not certain. A search for PIREPs and weather reports at the time could corroborate it.
Right, and my point is that until someone actually does that calculation we don't know how high that force was.
This isn't consistent with any coherent reading of the transcript:
> At 05:41:46, the Captain asked the First-Officer if the trim is functional. The First-Officer has replied that the trim was not working and asked if he could try it manually.
They've already hit the stab cutout at this point. Now maybe they're think this is like the older 737s and the cutout cut the autopilot and not the full electrical, BUT if you think the question he was asking was whether or not he could try the thumb switch, what exactly would he have been trying prior to that that "wasn't working"?
There is no other trim to try before the thumb switches such that you'd refer to the thumb switches as "trying it manually" when $OTHER_THING was not working. In the transcript, given what's being said, it's clearly the wheel crank that's meant. It doesn't even make sense otherwise.
From the report:
At 05:38:44, shortly after liftoff, the left and right recorded AOA values deviated. Left AOA decreased to 11.1° then increased to 35.7° while value of right AOA indicated 14.94°. Then after, the left AOA value reached 74.5° in ¾ seconds while the right AOA reached a maximum value of 15.3°. At this time, the left stick shaker activated and remained active until near the end of the recording. Also, the airspeed, altitude and flight director pitch bar values from the left side noted deviating from the corresponding right side values. The left side values were lower than the right side values until near the end of the recording.
...
At 05:39:06, the Captain advised the First-Officer to contact radar and First Officer reported SHALA 2A departure crossing 8400 ft and climbing FL 320.
...
At 05:39:42, Level Change mode was engaged. The selected altitude was 32000 ft. Shortly after the mode change, the selected airspeed was set to 238 kt.
At 05:39:45, Captain requested flaps up and First-Officer acknowledged. One second later, flap handle moved from 5 to 0 degrees and flaps retraction began.
Bear in mind stick shaker and divergent instrument readings all this time.
Why not just return and land, leave the flaps configuration alone (which would have inhibited MCAS), especially since this is exactly how the Lion Air flight started.
I know this is easy to critique from the comfort of my chair, and the pilots are not here to defend themselves, but some things in this narrative just don't make sense.
Experience sounds like a good thing on the face of it, but it also adds noise where all of these indications sound familiar enough, and yet nothing in particular stands out and tells you to leave flaps alone. That suggestion isn't even in the emergency airworthiness directive. And still at the time of this event there's no simulator that can be configured for MCAS upset so that pilots can experience it in various phases of flight.
Also, the priority in a flight control problem is to fly the plane, get it stabilized, understand the problem, and turning back to the airport is inconsistent with that. Fly runway heading is the proper thing to do, it's less complicated. A turn increases angle of attack, increases drag, it makes a high angle of attack situation worse, and if you're trying to climb it reduces your rate of climb.
But check Boeing's MCAS bulletin, which is the only official information pilots received about MCAS at the time of the flight.
http://www.b737.org.uk/images/aoa-bulletin.jpg
It makes zero mention of flaps. It doesn't recommend avoiding retracting them or trying to land as soon as possible.
Trying to land as fast as possible is typicality a bad idea. Planes which have just taken off are almost always over their maximum landing weight. Even if you ignore that, the extra stress of trying to land as soon as possible could cause the pilots to make more errors.
Procedures for issues on take off are typically focused on continuing to climb to gain as much altitude as possible to give the pilots time and space to assess the problem before dumping fuel and landing. The more altitude you have the more time you have to recover.
And unfortunately, climbing through 5000 feet requires retracting the flaps.
I don't know the most likely consequence of flying with flaps 5 above Vfe. Maybe flaps would (asynchronously) depart the airplane, or induce flutter at a much lower than usual airspeed. Either of those is an extremely high risk of losing the aircraft.
MCAS should be disabled at this time and this is confirmed further in the report.
> At 05:40:41, approximately five seconds after the end of the ANU stabilizer motion, a third instance of AND automatic trim command occurred without any corresponding motion of the stabilizer, which is consistent with the stabilizer trim cutout switches were in the ‘’cutout’’ position
the crash happens full three minutes later.
The other is that they make a convincing case that the problem is resolved. I don't know if that's possible given today's default hate for big corporations, we'll see. They've done it before with the 737 and the rudder problem it had in the 1990s or so. That problem led to a few fatal crashes, but I'm not sure it ever got the attention that this story is getting. The news cycle was different then.
I would absolutely fly on one once the problem is corrected.
What I would worry about is departure stalls, as MCAS doesn't seem to solve these. I wonder whether there isn't another 10E-5 to 10E-6 risk in there and people have just been lucky so far. Another MAX8 crash involving a stall would kill this plane I think, as it would prove much more that it's inherently unsafe.
That only holds if errors are statistically independent. See also Common Mode Failure [1].
[1] https://en.wikipedia.org/wiki/Common_cause_and_special_cause...
Now assuming 40.000 road deaths per year in the US and 300.000.000 citizens we have 0.000133 probability to suffer a road death a year. Assuming one 737MAX round trip per quarter we have 8 take-offs so .00008 probability to die in a 737MAX. Assuming commuter 40 trips a year we have a risk much higher than the average road death risk.
The problem is Boeing, not the MCAS system.
I don't think Boeing can be fixed.
I would rather there be guaranteed liability: have the execs set up a legal system to refund the entire order book and voluntarily plead guilty to federal charges in the event of another > 10 MAX deaths. But frankly, if Boeing is at fault for 340 deaths they should already be doing that.
That said, it seems likely that in the US Boeing is liable to their customers (airlines and aircraft owners) for fraud. In theory, the entire organization could be disbanded under RICO, but Boeing is a defense contractor, so more likely they pay to settle damages. I could see them getting away with paying for the costs of repairs, retraining and the lost revenue for planes already delivered in the US.
It also seems likely that Boeing is spending incredible amounts of money on PR to control the fallout. I expected the release of this report to be near the top of Reddit, but on reddit's /r/news the BBC report on this was sitting at only 21 net upvotes after 3 hours. (As of 8 hours ago.)
There has been the mention that the customization of planes in a certain way exposed this error - that's the bullshit part. Planes are complicated, the testing of them is complicated, allowing your marketing/sales team arbitrarily inject feature flags into your life or death machine to maximize profits is silly.
Make a thing and prove it is safe, if you wish to modify said thing, then prove the new version is just as safe - and don't allow corners to be cut with something as dangerous and expensive as a plane, these things aren't cheap and they don't need to rapidly iterate versions, they can move slowly and safely and be held to a standard of provable safety that I agree would be unreasonable for software like windows or instagram.
As an aside, I would offer more leeway to Cessna, given their focus on the individual consumer market and emphasis of customization, if someone ordered the plane equivalent of the small pizza with half sausage no cheese and no sauce[1], but not too much more leeway due to the danger these planes can have on others.
Like putting a very big engine in a small car: it’s a different car.
Isn’t that kind of the whole point?
Add in the facts that Boeing has been caught red-handed implementing a half-baked engineering solution as a regulatory dodge, and that this solution has to date crashed two aircraft and killed 346 (IIRC) people, and your view starts to look downright naive. You might call these tragedies "working out the kinks"; I call them wholly preventable, and evidence that human lives don't carry the proper weight in Boeing's financial calculus.
And speaking of the previous 737s, perhaps you should read: https://en.wikipedia.org/wiki/Boeing_737_rudder_issues
Which is to say, early defects in construction which were later resolved is not actually wholly uncommon to just this aircraft line, and planes of that model are still literally flying around today.
I'm also not sure why you'd reply to my comment when you clearly either haven't read it or have no interest in actually replying to the substance of it.
What would you suggest? Mothballing the MAX line for a wholly new aircraft? Arguably the MAX has significant flight testing time in production, to which one defect was found and is being remedied. A new aircraft would have less testing comparatively, and as noted, older aircraft really aren't inherently safer, as the 737's history shows.
My point was that the MAX will likely be the safest choice to fly in, and I don't think you offered up any logical argument saying otherwise.
I would suggest a fine-toothed audit of every single change made in the MAX aircraft, with particular attention paid to whether said changes were made solely in the interest of skirting regulations to sell more planes faster.
Because that is the point: Boeing's decision-making process is now highly suspect. It is pretty clear that the MCAS would not exist in anything like its current (flawed) form if Boeing hadn't been trying to avoid the pilot retraining requirement.
This is not a typical life-cycle for an engineering defect/flaw.
Hell no, I'll take Airbus or any other manufacturer over this crapware any day, even if I have to pay extra for the tickets. Boeing lost any trust in how they handled this, for very, very long time.
This topic is currently way beyond pure engineering issue, most human beings including me consider morality as quite an important aspect for example.
Unless I hear about some significant and measurable shift in the way company thinks and operates regarding to safety (nothing in the PR stuff discussed here), its a shady company with profits-above-safety mentality. No, thank you I can vote with my money
https://www.flightglobal.com/news/articles/boeing-wins-first...
Risk = probability x impact.
Even if probability has reduced (who knows by how much), impact is the near-certain death.
Avoid.
There's obviously a lot of concern and outrage. But I wonder if Boeing's share price would have been higher than last year if the two crashes were in first world countries specially US.
As with each aviation accident, it's not a single cause of failure - it's a swiss cheese model of failures, where it just happened that all the holes aligned - from the flight law dropping to alternate, to Bonin who didn't trust what the computers said, to the other pilots not understanding completely what Bonin did, to the pitot tubes freezing.
As opposed to Boeing's "lets pick one and hope to dear God that it's the correct one"?
How would you handle opposing input where any of the two pilots might give the incorrect input?
This stands out to me, and I have severely lost trust in Boeing and the FAA.
This plane should have not allowed to fly after the first crash, and Boeing knows this!
What a disaster - I will refuse to fly in any if these MAX planes going forward. I will not step my foot onboard.
Through WW2 and the proliferating age of defense contractors, the government (mostly defense department, but also civilian agencies) stood almost on equal footing with contractors in their ability to design, scope, and evaluate big projects.
You would see scientists and in-house advisers at these departments able to expertly evaluate proposals/designs by contractors with sufficient background knowledge and tools to do so. They even worked closely with contractors to lay out the requirements and designs for systems, or products.
But, through the decades, a couple factors eroded this equal footing of the government / regulatory experts:
-- Shrinking of government budgets for (or unwillingness of the public to stomach) the ranks of Washington "bureaucrats" who represented this expert class of people (what harm is there in cutting "fat" from public servants who don't seem to produce anything tangible?)
-- More attractive pay, career potential, prestige, etc. of working in the private sector
-- Political distaste for being seen as working too closely with contractors
So what happened is that gradually but surely, government lost the tools to do these things themselves, and by sheer need to still have things approved, shifted the work onto industry.
What can you do when industry comes to you with new complicated designs for things, and you have no one who can assess (and no budget to pay for assessments of) whether those designs are safe? You ask the person proposing to critique themselves, and in many cases, they seem to know more than you anyway.
Of course, what in part probably led to our current situation.
As I said in the beginning, the pros and cons of operating a system in this way should be looked at.
As a society, my question is, how do we make it possible to choose to do these things in the way that produces the right outcome? For a start, I think we need to stop asking everyone to make uninformed votes about certain detailed things we don't understand, yet rely on every day. That definitely produces bad consequences for many issues.
https://www.npr.org/2019/04/04/709431845/faa-is-not-alone-in...
Claims aren't evidence. But testimony is evidence. How compelling that is depends on their credibility, qualifications, and whether there's corroborating evidence.
Meaning, was there ever a case where the nose went up so much, because of the bigger motors and their different location on the wings, that the activation of MCAS prevented a stall? I'm surprised no one seems to talk about this.
It's also surprising the MCAS was implemented at all, instead of an alarm. Yes, the point of MCAS is to make appear the MAX is the same plane as earlier models (when in fact it's not), but if pilots need to learn how to deal with MCAS malfunction, isn't it the same as learning to deal with unexpected stalling during take-off? The whole reasoning sounds kind of circular.
Essentially it was an emulation layer to make what is effectively a new plane behave like an old plane. And now 300+ people are dead.
They are liable for the deaths. The real question now is what is a human life worth to a corporation? (i.e. payout).
Next Steps: + BA should be heavily fined. +scrutinize ties and lobbying with FAA. + Fire head of FAA, and teams involved in approving MCAS.
Quite the feat, Boeing.
The plane is not airworthy.
Let’s not forget MCAS only exists to protect Boeing’s profits by avoiding a new type certification.
Let's say Boeing ships a new airliner, where in 1/1,000 flights, the wings fall off for no reason.
Would you be asking the question of: "But did the wings save lives in other circumstances?"
Of bloody course, they did. Doesn't mean that they should have ever shipped an aircraft, where the wings fall off for no reason!
MCAS was a hack around a redesign of the plane. If the plane would have crashed at an even higher rate, without that hack, then the conclusion is not: "WOW, MCAS saves lives."
The conclusion is: "That airplane should never have been shipped, because it is a deathtrap."
If it would have crashed at a lower rate, without MCAS, then no, MCAS was not a net life-saver.
Boeing chose to redesign the place, making it more dangerous to operate. To mitigate the danger, they added MCAS, which was also dangerous to operate. It doesn't matter whether or not a MAX with MCAS, or a MAX without MCAS is more dangerous. What matters is that a MAX with MCAS is dangerous. Nobody put a gun to their head, and made them redesign their plane.
The execs at Boeing probably felt the A320 was a gun to their head. The A320 was set to eat their lunch, and they made a decision that ultimately has resulted in 300+ deaths. Was it a malicious decision? I give them enough credit to say that they honestly believed they solved the problem with MCAS. Was it a malicious decision to lie about pilots not needing to re-train? I'm leaning towards yes.
Reading the other comments it seems the answer is yes.
That said, it's unclear that a Max with MCAS is dangerous: the danger comes from pilots not being aware of it / trained for it. Which, again, doesn't disculp Boeing in any way.
Regulations are that "(1) The stick force vs. g curve must have a positive slope at any speed up to and including VFC/MFC; and......(a lot of other text)......During the approach to the stall, the longitudinal control pull force should increase continuously as speed is reduced from the trimmed speed to the onset of stall warning."
The Max's aerodynamics are such that as you approach a stall angle, at a certain point the force inverts and the aircraft "pitches nose up" reducing force against the stick close to the stall angle.
An alarm thus fails to meet the stick force requirement. The intention behind the MCAS is to push force against the stick throughout the approach to the stall angle to meet the requirement.
(Which obviously created a whole host of failure modes that everyone seems to have entirely missed).
Which anybody who claims that MAX is safe without MCAS is ignoring: without properly working MCAS the plane effectively starts to misbehave exactly when it shouldn't (when it's harder to save it).
Unfortunately, with improperly working MCAS, the way it was designed (non redundant single sensor which is blindly trusted by MCAS and which is in effect stronger than the pilots fighting against it) there were already two crashes.
MCAS is there to prevent stalls at high thrust and AoA. It's also disabled when flaps are down. Meaning that it's turned off for take offs and landings where you'd most expect high thrust and AoA as well as the worst times to stall. It's hard to square that with MCAS being necessary for safe operation.
Simply put, commercial imperatives overtook solid engineering practices.
"The Boeing 737-300 was on approach to Bournemouth Airport following a routine passenger flight from Faro, Portugal. Early in the ILS approach the auto-throttle disengaged with the thrust levers in the idle thrust position. The disengagement was neither commanded nor recognised by the crew and the thrust levers remained at idle throughout the approach. Because the aircraft was fully configured for landing, the air speed decayed rapidly to a value below that appropriate for the approach. The commander took control and initiated a go-around. During the go-around the aircraft pitched up excessively; flight crew attempts to reduce the aircraft’s pitch were largely ineffective. The aircraft reached a maximum pitch of 44º nose-up and the indicated airspeed reduced to 82 kt. The flight crew, however, were able to recover control of the aircraft and complete a subsequent approach and landing at Bournemouth without further incident."
https://www.gov.uk/aaib-reports/aar-3-2009-boeing-737-3q8-g-...
If that had happened in a Max, without MCAS, would it have ended badly? We'll never know, but it seems possible.
Very possible. The question is, should you use a plane with an unstable design in civilian air transport? AFAIK, a stealth bomber can't fly without the help of a computer to keep in in the air. But for a civilian aircraft this should be a very conscious decision and nothing that is hidden under band aid.
It's a bandaid fix for an airframe issue. So yeah it probably saved lives, but ones which shouldn't have been at risk in the first place.
The whole thing wasn't kosher - re-using an old airframe to save costs even though its not really compatible with new engines to rush something to market with reduced certification requirements. The bandaid coming off shouldn't be where the focus should be
Culturally move fast & break things shouldn't be how aircraft go to market
https://www.avm-mag.com/faa-issues-emergency-ad-for-boeing-7...
"An erroneous AOA input can cause some or all of the following indications and effects:"
"IAS DISAGREE alert."
The whole "what to do" is then:
"Initially, higher control forces may be needed to overcome any stabilizer nose down trim already applied. Electric stabilizer trim can be used to neutralize control column pitch forces before moving the STAB TRIM CUTOUT switches to CUTOUT. Manual stabilizer trim can be used before and after the STAB TRIM CUTOUT switches are moved to CUTOUT."
We know now that the pilots performed what was there laconically written, and that even these actions couldn't save the plane.
Which means either:
- Boeing never actually tested how to really handle the situation described then or
- Boeing indeed tested that and knew that IAS DISAGREE procedures would also be followed and which would guarantee to make the plane uncontrollable (for details see here: https://leehamnews.com/2019/04/03/et302-used-the-cut-out-swi... how one pilot recently reconstructed that and made a video about it, which was later withdrawn on the demand of the pilot's company -- note a single pilot here did what Boeing, which is supposed to sell hundreds of billions USD worth of these planes didn't want to do), but bet on "it won't happen soon enough, we can get away with it."
I can't find that anybody can excuse either of these.
So what approach did they use the first time around?
He just finished several paragraphs about how the plane and it's software was not safe ("erroneous activation of the MCAS function"), and then arrives at this conclusion?
If my car erroneously responds to the pressure on the gas pedal it's not safe.
I don't believe share price is at the front of his mind, nor any of the engineers working at Boeing. I, for one, work for much more than a paycheck; I think it's reasonable to think they do too.
You could argue that it was at the front of their minds before these accidents, but IMO that conclusion only stands in confirmation of some bias against large corporations (which apparently is pretty common!)
I'm cynical because of Occam's razor, not because I want to be. I'd very much prefer not to be cynical, to tell you the truth.
It's also a training issue, especially with the first flight pilots not being informed about this system.
Maybe it can be worked around via software changes and human training. But the software appears to have done what it was supposed to.
Two isn't good for much, if they give different readings you don't know which to believe. Either that kills you like in real life, or it kills you because of the stall problem it was invented to fix.
Edit: And yes, you could do something more sensible than what they did, but that doesn't "fix" the issue, it merely mitigates it to some extent.
I'm not saying they should avoid using a third sensor. It sounds like a good idea. But I'm not sure it's required for airworthiness, after you move from one to two.
Yes, it seems the plane is probably mostly flyable if you kill the MCAS system (which is the only reasonable step to take in a two sensor system when they disagree). But
- The plane no longer handles the same, you definitely need to be alerting the pilots, and put this change into manuals and training. This isn't just a thing you should silently do in software and expect not to kill people.
- The plane no longer meets the FAA rules for the class under these conditions. Maybe that's acceptable because it is an error state, but I think that meets the definition of a "workaround" and not a "fix".
- At least one of these planes took off when one of the sensors was known to be bad from the previous flight (as I understand it). I can only assume that they don't do that when something critical to the handling of the plane is broken. This is another process bug that needs to be fixed before a software workaround might be acceptable.
I don't see any way to interpret this other than "the hardware didn't work as we thought it did", which leads me to say "hardware bug", even if you can maybe work around it with process, training, and software changes.
If only you had done that the first time.
>> This update, along with the associated training and additional educational materials that pilots want in the wake of these accidents, will eliminate the possibility of unintended MCAS activation and prevent an MCAS-related accident from ever happening again.
From what we've read, your company thought that cost too much the first time around. Maybe it's time to reconsider the costs of NOT doing the work up front. Boeing used to be better at this.
Assurances alone are going to mean a very rocky road back for this plane.
https://www.airlineratings.com/news/boeing-ceo-muilenburg-ab...
Also, Ethiopian airways is quite old and had a good safety record.
I am fairly confident that by the time we are done with this, a system called MCAS never flies again. Even if it means the entire MAX is shelved.
They can reuse the engines. If the airframe can’t fly safely without MCAS (it’s getting a new type rating anyway at this point, right?) then I think perhaps it shouldn’t fly.
Do you really think this?
Anyways, we'll see how the stock price looks in a year, I sincerely have no idea, but I think airlines outside US will try to prefer Airbus for new contracts in the next year.
Like, Fly-by-wire is not new, airbus has been flying this way for 30 years, and had some bad early accidents because of it. The name of the system doesnt matter very much, so I fail to understand how the name would ground the airplane forever
Versus Airbus which moderates pilot input to keep within the flight envelope, but I don’t think it steers without inputs when autopilot is off?
It’s clear FAA lacks the expertise to regulate this kind safety issues. It’s not easy for them to have it either since the innovators are always a step ahead but it’s clear they need to shape up.
I don’t have any knowledge of the process for verification of new airplane models, but one thought as software developer would perhaps be for FAA to become more digital in their efforts. Require from manufacturers (At least for bigger models) a digital virtual model of the entire airplane that will be used for simulated tests. You could for instance test faulty signaling sensors but also the whole subseqqunt chain of events taking into account pilot actions (or lack of).
It should be a routine to replay a simulation with data from previous crashes. In this particular instance perhaps FAA would have understood the reasons of the first crash and been able to stopped the second crash from ever happening.
You could even develop methods that can generate data to be able to predict hidden issues with an existing design without a real crash ever happening.
Boeing fucked up. FAA fucked up. Boeing management fucked up after Lion. Boeing mgmt fucked up after EA. They should resign in disgrace, not issue self-serving press releases.
Shame!
If they've been working tirelessly, then they should have understood the risks and grounded the fleet.
Either they understood the risks, but neglected to ground the fleet, or they didn't understand the risks and hence we can't trust the fix.
I also find it sort of nauseating that the CEO implicitly gets the message through that the fix already has been worked on for a long time, has thus matured, can now be fully trusted, and we are just weeks away from flying with a safe plane.
I don't buy any of it. Let's analyse this critically.
The MCAS still needs to augment the flight characteristics. There is nothing that can be fundamentally changed regarding this fact. We can only change the conditions under which MCAS activates and the conditions under which it is deactivated.
It still has to have the same authority for a nose-down and recovering from an erroneous high-magnitude nose-down will still be mechanically hard or require additional pilot knowledge and actions. The latter should be impossible without recertification.
The operational characteristics of the airplane are not matched with the operational controls offered to the pilots, by design constraint. The plane is thus unsafe and will forever be unsafe, without redesign and recertification, because with the constraints in place, they can only add additional information on displays, add more reliability by having the MCAS utilise input from more sensors, add more conditions under which the the MCAS deactivates, etc, but none of this attacks the fundamental impedance mismatch between characteristics and controls, as well as the lack of education for it. Deactivation also simply exchanges the risk of stalls for nose downs.
All-in-all, the MAX is simply an airplane with a worse flight envelope as far as safety is concerned, and nothing can be done about it.
I also question the lack of clear communication between the two pilots. Examples such as the captain asking the first officer if the aircraft could be manually trimmed and the first officer replying in the negative, with no verification on the part of the captain and no checklist use make me wonder. Maybe they were doing those things. I'd be interested in seeing a transcript. It's understandable why Muilenburg doesn't seem particularly remorseful.
The plane _is_ balanced; it's not like Boeing built an aircraft that falls out of the sky if you slightly nudge the yoke wrong. (Which wouldn't even be unusual; plenty of modern aircraft are completely uncontrollable without computer assistance.) Yes, the problem could've been solved with a re-design of the aircraft- lengthening the landing gear struts, modifying the wings, etc. - but that would negate the point of using an existing and well-tested design.
There's A LOT of guilt to go around in this story, but no one can actually be casting doubt on the abilities of Boeing engineers in the fundamentals of aircraft design.
As a developer, I can say the same about writing software. Yet, my software is not likely to kill people and comes with no warranties whatsoever.
In this scenario, we should make sure the test engineers are even more competent than design engineers. We can't rely on designers to thoroughly test what they build.
Then you either have to put up and do it or you'll be strategically moved elsewhere or be managed out of the job.
Through WW2 and the proliferating age of defense contractors, the government (mostly defense department, but also civilian agencies) stood almost on equal footing with contractors in their ability to design, scope, and evaluate big projects.
You would see scientists and in-house advisers at these departments able to expertly evaluate proposals/designs by contractors with sufficient background knowledge and tools to do so. They even worked closely with contractors to lay out the requirements and designs for systems, or products.
But, through the decades, a couple factors eroded this equal footing of the government / regulatory experts:
-- Shrinking of government budgets for (or unwillingness of the public to stomach) the ranks of Washington "bureaucrats" who represented this expert class of people (what harm is there in cutting "fat" from public servants who don't seem to produce anything tangible?)
-- More attractive pay, career potential, prestige, etc. of working in the private sector
-- Political distaste for being seen as working too closely with contractors
So what happened is that gradually but surely, government lost the tools to do these things themselves, and by sheer need to still have things approved, shifted the work onto industry.
What can you do when industry comes to you with new complicated designs for things, and you have no one who can assess (and no budget to pay for assessments of) whether those designs are safe? You ask the person proposing to critique themselves, and in many cases, they seem to know more than you anyway.
Of course, what in part probably led to our current situation.
As a society, my question is, how do we make it possible to choose to do these things in the way that produces the right outcome? For a start, I think we need to stop asking everyone to make uninformed votes about things we don't understand, yet rely on every day.
Absent a politically impossible change to the way the government handles employment, trimming the ranks is the only way to get rid of the harmful parasites that infest the typical government agency.
Allowing the company to produce a plane, equipped with a non-redundant system with control over the vertical attitude of the plane, and doing so in a way that intentionally minimizes the perceived impact and required training to operate a plane with this system is the true mistake here.
This is a failure of the both the FAA, Boeing, and pretty much every player along the chain.
I was just trying to read up a little about sings of sociopath. It seems to me that a big chunk of major corporate big brash could be considered extreme versions of sociopath.
It's clear why this type of system selects for leaders who do not value ethics, respect the law, or value the individual. I'm not sure what to call these leaders, but sociopath doesn't seem too far off.
Let’s say we wanted to get really punitive... who do we blame? The engineers that worked on it? The Boeing CEO for not personally verifying every piece of software on all of their aircraft?
Do we throw someone in jail? How does that help improve safety culture exactly?
Boeing & Airbus are largely responsible for the massive improvements in flight safety over the last 40 years. It’s incredible that flying is as safe as it. Yes the deaths are a tragedy, but every time I get in a plane I accept the fact that the physics of flying could ultimately kill me, and I trade that off against the convenience of getting somewhere quickly.
This was a business decision to remove re-certification/re-training for some 60B sales. So yes the CEO is responsible. If you can float on money for the success you can spend the lifetime in jail for the deaths too.
But that might be a little extreme. So here's a better one for after Lion Air crash there is no reason to believe that Boeing including the CEO didn't go over this, didn't realize they made a risky plan and even then they didn't go through with their temporary mitigation with a fine tooth comb. So yes it seems the CEO and some big shots and maybe some down the line should go to jail.
No one is sent to jail for complicated to reason or never before seen problem that they didn't know about or didn't think about and it happened. This wasn't an accident, they implemented absolutely critical safety feature by design without triple redundancy as well understood to be required then they lied about it (if I understood the max change from earlier to later version), tried to downplay it and when a crash happened due to this didn't own up to it. So for sure this helps safely culture. If you hide safety problem knowingly for greed/money, because your boss asked and you didn't care you shouldn't be working in safety critical system.
> Boeing & Airbus are largely responsible for the massive improvements in flight safety over the last 40 years. It’s incredible that flying is as safe as it. Yes the deaths are a tragedy, but every time I get in a plane I accept the fact that the physics of flying could ultimately kill me, and I trade that off against the convenience of getting somewhere quickly.
I don't even know what to say to this. So I drove safely for 40 years and today I decided to see if I can safely drunk drive if I play the music really loud and killed a family of four.
This was not physics, this was not a complicated software bug (at the core) but it was cutting corners for profit.
How can he claim this? They'd have to remove MCAS for this to be true.
Boeing wants to get as far away from this as possible.
furthermore, this is summed up by just "we'll fix it in software". hurray, everything we touch including cars and airplanes are now subscribing to the "we'll fix it in software" approach. failed a safety brake test? fix it with software. kill a few hundred people by an automatic system crashing a plane? fix it with software.
i really hope society wakes up and SLOWS DOWN. we're trying to move so fast, with hardly any reason at all, and in doing so, we are throwing away all ability to properly design, build, and god forbid, think about things. i don't know what it's going to take, but it feels out of control. everywhere you look is people hurrying and hurrying to release, to productize, to ship it, etc. whenever i ask "why?" to schedules, there has NEVER been a clear answer. it always boils down to basically "just because".
in addition, we simply have too much laziness and greed taking place, which is what added to boeing's misstep here. they tried pulling a fast one on buyers (and basically accomplished it) to make a few bucks towards that everlasting capitalist dream.
> Chairman, President & CEO
Aren’t these suppose to be different people to keep the board independent?
Is it absolutely necessary for the computer to be adjusting the angle of attack?
https://www.smh.com.au/lifestyle/the-untold-story-of-qf72-wh...
https://www.atsb.gov.au/publications/investigation_reports/2...
*edited to cite sources
"The occurrence was the only known example where this design limitation led to a pitch-down command in over 28 million flight hours on A330/A340 aircraft"
The common-platform A330/40 had been in service for 15 years before this event. It really was a freak failure of one computer unit which went haywire and which led to a design change to mitigate it. That was 11 years ago.
It is deceptive to claim it's anything like the 737 Max issue.