Am I irrational for not wanting to be on the first 1-2 years of flights on 737 MAX after it gets its software update?
Am I irrational for not wanting to be on the first 1-2 years of flights on 737 MAX after it gets its software update?
The first accident was maybe understandable. We all know that shit happens. But Boeing has zero excuses for not immediately grounding the whole fleet after, and for putting out that useless recovery procedure which didn't work in this case. They let a deadly plane fly for 5 months after they were aware of it, and after the second crash they were phoning Trump to keep it in the air.
This is some Challenger O-ring type of shitshow. Accidents are one thing; incompetency or, worse yet, callous indifference is absolutely unacceptable.
That's just unrealistic. Unless you want plane and car rides to cost as much as a trip to space, after all, since everything would need to be engineered to that level of quality.
I said: "Accidents are one thing; incompetency or, worse yet, callous indifference is absolutely unacceptable."
Anybody may have a different judgement with respect to exactly where on the scale is appropriate, but we cannot just pretend that there's no trade-off to be made. Or that absolute safety is even a possibility.
It's sad, but most faults seem to be like this. First one is treated as an anomaly, second one is treated as the start of a trend. It happens so many times I'm glad I'm not working with human lives.
I wish this statement was held with as much as accountability as this comment implies. But have any of the major outlets been discussing potential prison sentences for Boeing or FAA employees / executives or potentially even board members? If you want accountability in today's age it seems the pressure needs to be applied at the point where financial decisions are held with more precedent than safety of life.
Boeing stock was up today on the glimmer of hope that the "software fix was working". Investors are assuming the stock is on sale and this only impacts Boeing for, what, a few weeks? I said something similar in another comment but I think Volkswagen is going to do more jail time and have more brand detriment than Boeing or the FAA will. Egregious doesn't begin to describe the misdirection of conversation. Why is the focus not yet on who will be sentenced for death over profits?
Reminds me of the Equifax breach. Stock tumbles then recovers. Overall, it validates that breaches are not a liability; therefore, additional resources to address future problems could be seen as a moot point.
Same with Boeing. If there is no impact to the company, then why change the business model?
If you don't have food in your belly and you steal you get jailed. You are not satisfied with your million dollar salary and your billion dollar company profit and don't care if people get killed, you get to have PR firm write how sorry and sincere you are. Justice seems truly blind so many times just not in the way the phrase was coined.
And they're totally going go get a fair trial and not some sort of kangaroo court to appease the locals?
But I do get your point.
I think it's worse.
The first crash can be compared to the Challenger shitshow. It was a (massive) engineering mistake, which lead to the Lion Air plane crashing. Looking at the history of the 737 in general and the 737-MAX specifically it was rekless, but I'm pretty certain not intentional or foreseen by Boeing.
That massively changed by the fact that they didn't immediately pull the plane after this crash and went into deep analysis mode to really evaluate the cause. Instead they smeared everybody but themselves, developed a completely useless checklist without really knowing or (apparently) caring if it's useful at all and let that deathtrap fly.
The second crash, in my opinion is corporate mass murder for profit. Maybe not legally, but morally most certainly.
There is always a trade off, your statement is too bold for a world of limited resources. We can use engineering to make the roads safer. Spent a trillion USD on road safety will save lives for sure. But maybe it is spend better on cancer R&D efforts?
The safest plane would be the most expensive and most uncompetitive since it needs unlimited resources and unlimited time for being designed.
It's not so much a matter of ressources than of specifically engineering excellence. There's plentiful examples of a much better product that was created with less ressources than the shitty existing competition (this must be commonplace for HN members).
I'm convinced the safest plane is not the most expensive, it's the one designed through sound and clear-sighted engineering.
Are you an engineer? Your argument sounds naive. Or to give a counter example: In the Soviet Union there were likely more accidents (normalized) compared to the west. Yet, they did not focus on maximizing profits.
A simpler yet effective design (may it be initial or rework) comes at a much lower cost than a flawed one, which inevitably aggregates irrelevant complexities.
Who decides this? This is not a trivial question.
The F-35 fighter is a good example. Trades many disadvantages (not fast, not good in dog-fighting, tremendous long maintenance time, low payload etc.) for one advantage. The F-35 may or may not be invisible to an able opponent. But this decision is a tremendous difficult one. Based on your argument, it would be better to stick with a simple design. This was worked for the Soviet Union in WW2 (don't build the best tank, build a decent one, build many).
You may like this story: https://en.wikipedia.org/wiki/Superiority_(short_story)
I'm not comparing simple vs. complex but rather sound vs. flawed, although often sound = simpler than flawed.
The 737 here is yet another example of this : - the MAX design is flawed : faulty risk assessment of MCAS, seemingly unstable airframe in some configurations - a likely sound design could be : airframe rework, thorough risk assessment, extra pilot training...
While the flawed design came at a lower initial cost, it will now overrun the cost of a likely sound one (further rework + retrofit + sales/reputation damage + legal), including the cost of a probable longer design phase in the latter.
(I concede that legal/sales costs are not directly technical debt costs).
Therefore, our medicine is not perfectly safe, our cars are not perfectly safe, our building are not perfectly safe, we don't / can't provide 100% health coverage to everyone, and so on... but in aggregate, they make the world a better place, so it's worth it.
I wonder if the European agency (don't remember the name) will stop trusting the FAA from now on and do their own tests. I'd thank them for that.
(According to what I read here, the European agency doesn't do exhaustive tests because they mostly trust whatever the FAA says; maybe that's false)
That's true. The FAA had a stellar record as a certification agency, which, it can be argued, they fucked in three days (sure, the hole history of this sad debacle is more complex. But by keeping the plane in the air longer than any other certification body in order to not hurt their buddies at Boeing they completely ruined their reputation, which was built in decades of good work).
I can't imagine that any responsible certification body anywhere trusts the FAA anymore without a complete and significant shakeup.
It's a sad story, really.
This is unlikely to change. It’s expected that some changes will occur at the FAA. Certifying an airliner is also a prohibitively expensive undertaking, which is part of the reason for this mess in the first place. It would take years even to train enough personnel to duplicate all those efforts.
EASA.
FWIW, the Brazilian regulator (whose name I don't remember...) did not rubber-stamp the FAA's type certification of the 737 MAX, and required some differences training for MCAS, IIRC.
And, yes, the Ethiopian Air pilots apparently did follow the procedures initially, flipping the Stab Trim Cutout switches, but did not manage to recenter the trim manually (via the trim wheel), so apparently re-enabled electric trim, and then let MCAS drive the trim even further down to their doom. :-/
"Those who don't remember history are doomed to repeat it"
It's been a couple of decades I think, maybe more, since an engineering screwup affected a passenger airliner like this. You could argue that the 787 LiIon battery thermal runaway thing was a red flag. That also resulted in an FAA grounding, but that was fairly easily remedied and nobody died.
From documents I've seen (which I cannot find the links to now), it appears that the FAA let Boeing themselves do some of the certification work and sign offs.
Putting the foxes in charge of the hen house, so to speak.
They become primarily concerned with the interests of the companies they're regulating, rather than the public interest they're in theory tasked with working for.
Unfortunately, that is just how a regulated society works.
So without regulations, there are fewer people to corrupt.
just because a regulatory agency did its job by protecting the pulic’s interest doesn’t mean it will always work that way. so your example doesn’t negate the existence of regulatory capture, which is an actual thing and not some political propaganda.
https://en.wikipedia.org/wiki/Regulatory_capture
https://en.wikipedia.org/wiki/Public_choice
Of course, my post above is sharpened and overgeneralized to fit in an online forum. There are more nuances.
A current example in the news is Facebook asking congress to be regulated. This makes little sense from a conventional perspective. From the Regulatory Capture perspective it's an obvious play. Government regulation will be very costly to comply with, and only FB and a few other giants will be able to afford it, thus cementing FBs monopoly position for the foreseeable future.
https://www.insidesources.com/facebooks-mark-zuckerberg-asks...
To be fair, Public Choice theory is certainly on the more controversial half of the subfields.
And of course you shouldn't blindly take some random post on this forum as complete proof of how the world works. That would be a foolish gullibility. Then again, completely rejecting it isn't the wisest thing either. At least that's my view :)
When has economics ever been a science?
But that's a small part of Economics, and the field in general is as hard as any science outside of physics, and had given us an enormous amount of insights we lacked 200 years ago, and contributed immensely to the relative peace and prosperity the world enjoys today.
Private enterprise has an analogue: principle-agent problem.
To me, it all comes down to to Boeing being able to self-certify their aircraft, and they knew they were sneaking the "fix" known as MCAS as a way to prevent loss of sales to A320. Super shady in my opinion.
The script required them to manually crank in the stabilizer, which wasn't possible. The script was manifestly not "working". That doesn't "remain to be seen" -- it's in the transcript of the cockpit
> At 05:41:46, the Captain asked the First-Officer if the trim is functional. The First-Officer has replied that the trim was not working and asked if he could try it manually. The Captain told him to try. At 05:41:54, the First-Officer replied that it is not working.
I guess the First-Officer must have been speculating...
Until someone sits down and calculates the torque needed to manually trim it's all just speculation.
They weren't
>the pilot is busy supplying maximum pull on the yoke,
Probably not true either
>and therefore likely unavailable to help crank a stiff trim wheel
Runaway trim should be a recoverable situation. If that's impossible then that means there is a distinct and major issue beyond MCAS.
> They weren't
They just took off, max height of the airplane was 1000 feet above the ground. That's a definely low altitude.
> Runaway trim should be a recoverable situation.
The trim pointed the nose down. The aerodynamic forces were so high on the elevator that the trim wheels could not be moved by a single person. This was confirmed in 737 simulator.
People thought that based on Flightaware data. But if you actually read the report you will see that it is incorrect and they reached about 7,000 feet.
>The trim pointed the nose down.
Incorrect. The plane was steadily gaining altitude until they re-enabled electric trim.
>I wouldn't feed the troll, but I don't want your misinformation to spread.
Try being right before throwing around personal insults.
which points clearly to MCAS applying maximum nose down, based on incorrect data from the left alpha sensor, both pilots pulling on their control sticks, and the aircraft failing to gain altitude even before final MCAS activation because the trim could not be manually reset by the F/O.
this report contradicts every element that you're pushing (plane reached altitude, pilots didn't pull on the column, the electric trim was not needed, MCAS did not intervene). did I missing anything ?
Screw Jack and effort force https://www.engineeringtoolbox.com/screw-jack-d_1308.html
Gearing: https://www.engineeringtoolbox.com/gears-d_1307.html
Here's some 737-800 dimensional analysis as a starting point.
https://holdingpoint.wordpress.com/2011/04/04/boeing-737-800...
Knock yourself out.
Or if you stick around long enough I may do it for gits and shiggles.
I'll need some schematic details of the actual manual trim wheel mechanism to figure out what the output forces on the jackscrew are... But hey, sounds like a fun mental exercise.
I'll see if I can find any details on it, but if anyone else just has it, reply to me, and let's see if we can get some delicious numbers going on here. Worst case scenario, I'll pull whatever design most makes sense to me out of my arse and theorycraft to get a feel for it.
737-800 has a 32.776m^2 horizontal stabilizer area. Let's double that to 65.556 to accomodate both airfoils.
Wing load is 1/2p(v^2)A Where A=65.556m^2 (352.8 ft^2) v=180.556m/s (350 knots) And we'll guess our air density around .95ish kg/m^3 given our altitude of 2334m (7625 ft plus change) asl
Barring any flawed fundamental assumptions, that gives us a wind load of 1015087 N (228200.636 pounds-force (lbf)), and a dynamic pressure of 15485 N/m^2
I'll leave this out there to offend any actual aerospace engineers that might be reading so they'll tell us I'm doing it all wrong while I try to work out whether I can use the screw jack equations and what we've calculated thusfar in the hopes of figuring out something that even remotely makes sense.
I have a feeling I'm oversimplifying or misapplying the wind load equation. But hey, it's the internet. I'm allowed to be wrong.
Dropping in the previously calculated wind load of 1015087 N, we end up with an effort force of 3182 N, which through a 6 in pulley would be 485Nm (357 ft-lbs) of torque,
Note, we're in automobile engine levels of torque output to actuate this screw jack against the wind load on the horizontal stabilizer.
Give me a bit to come up with some estimates on the trim wheel and play around with some gear trains to see if I can come up with an arrangement that does the trick.
It should be doable, but with the gear ratios I'm thinking will be required to generate the requisite torque, the actual rate of actuation is going to be pretty slow.
Your responses have been incredibly selective about which parts of the report you take as gospel and which you handwave away as "speculation".
From where I'm sitting it appears you've started out by picking a contrarian conclusion you like ("the plane was safe once STAB CUTOUT was set cutout, and the crew could have maintained altitude indefinitely at that point, but fatally fucked up by re-engaging electronic trim to try to trim the stabilizer"), and to maintain that a priori conclusion you've consistently ignored the data and parts of the transcript that indicate that was very likely impossible.
Where is that data in the report?
> At 05:41:30, the Captain requested the First-Officer to pitch up with him and the First-Officer acknowledged.
> At 05:43:04, the Captain asked the First Officer to pitch up together and said that pitch is not enough.
Take a look at the chart of control column position deflections. They're jolting around like crazy at +10 to +15 aft starting immediately at the first big MCAS trim event through to the end of the recording. That's because the stabilizer mis-trim is exerting considerable force on the elevator. The captain wasn't calling for aid on the column for shits and giggles.
okay
https://www.satcom.guru/2019/04/stabilizer-trim-loads-and-ra...
05:41:30 - PIC requests SIC to pitch up with him
05:41:46, 05:41:54 manual trim not working, that is absolutely a trim wheel hand crank attempt; fairly clear (to me) but not stated is that both pilots were not simultaneously cranking on the trim wheel, there's plenty of anecdotal evidence that this exact configuration puts to much upward force on the jackscrew that it is difficult to impossible to turn.
05:43:04, PIC asks SIC to pitch up together says pitch is not enough
As for the noisiness of the control column position data, it could be partly the stick shaker, it could be light turbulence, the accel vert row at the bottom shows it's a bumpy flight, and pitch and roll attitude is also variable but less so than vertical accelerate. And accel vert gets noticably more perturbed as airspeed increases. I think it's light to moderate turbulence, but I'm not certain. A search for PIREPs and weather reports at the time could corroborate it.
Right, and my point is that until someone actually does that calculation we don't know how high that force was.
This isn't consistent with any coherent reading of the transcript:
> At 05:41:46, the Captain asked the First-Officer if the trim is functional. The First-Officer has replied that the trim was not working and asked if he could try it manually.
They've already hit the stab cutout at this point. Now maybe they're think this is like the older 737s and the cutout cut the autopilot and not the full electrical, BUT if you think the question he was asking was whether or not he could try the thumb switch, what exactly would he have been trying prior to that that "wasn't working"?
There is no other trim to try before the thumb switches such that you'd refer to the thumb switches as "trying it manually" when $OTHER_THING was not working. In the transcript, given what's being said, it's clearly the wheel crank that's meant. It doesn't even make sense otherwise.
From the report:
At 05:38:44, shortly after liftoff, the left and right recorded AOA values deviated. Left AOA decreased to 11.1° then increased to 35.7° while value of right AOA indicated 14.94°. Then after, the left AOA value reached 74.5° in ¾ seconds while the right AOA reached a maximum value of 15.3°. At this time, the left stick shaker activated and remained active until near the end of the recording. Also, the airspeed, altitude and flight director pitch bar values from the left side noted deviating from the corresponding right side values. The left side values were lower than the right side values until near the end of the recording.
...
At 05:39:06, the Captain advised the First-Officer to contact radar and First Officer reported SHALA 2A departure crossing 8400 ft and climbing FL 320.
...
At 05:39:42, Level Change mode was engaged. The selected altitude was 32000 ft. Shortly after the mode change, the selected airspeed was set to 238 kt.
At 05:39:45, Captain requested flaps up and First-Officer acknowledged. One second later, flap handle moved from 5 to 0 degrees and flaps retraction began.
Bear in mind stick shaker and divergent instrument readings all this time.
Why not just return and land, leave the flaps configuration alone (which would have inhibited MCAS), especially since this is exactly how the Lion Air flight started.
I know this is easy to critique from the comfort of my chair, and the pilots are not here to defend themselves, but some things in this narrative just don't make sense.
Experience sounds like a good thing on the face of it, but it also adds noise where all of these indications sound familiar enough, and yet nothing in particular stands out and tells you to leave flaps alone. That suggestion isn't even in the emergency airworthiness directive. And still at the time of this event there's no simulator that can be configured for MCAS upset so that pilots can experience it in various phases of flight.
Also, the priority in a flight control problem is to fly the plane, get it stabilized, understand the problem, and turning back to the airport is inconsistent with that. Fly runway heading is the proper thing to do, it's less complicated. A turn increases angle of attack, increases drag, it makes a high angle of attack situation worse, and if you're trying to climb it reduces your rate of climb.
But check Boeing's MCAS bulletin, which is the only official information pilots received about MCAS at the time of the flight.
http://www.b737.org.uk/images/aoa-bulletin.jpg
It makes zero mention of flaps. It doesn't recommend avoiding retracting them or trying to land as soon as possible.
Trying to land as fast as possible is typicality a bad idea. Planes which have just taken off are almost always over their maximum landing weight. Even if you ignore that, the extra stress of trying to land as soon as possible could cause the pilots to make more errors.
Procedures for issues on take off are typically focused on continuing to climb to gain as much altitude as possible to give the pilots time and space to assess the problem before dumping fuel and landing. The more altitude you have the more time you have to recover.
And unfortunately, climbing through 5000 feet requires retracting the flaps.
I don't know the most likely consequence of flying with flaps 5 above Vfe. Maybe flaps would (asynchronously) depart the airplane, or induce flutter at a much lower than usual airspeed. Either of those is an extremely high risk of losing the aircraft.
MCAS should be disabled at this time and this is confirmed further in the report.
> At 05:40:41, approximately five seconds after the end of the ANU stabilizer motion, a third instance of AND automatic trim command occurred without any corresponding motion of the stabilizer, which is consistent with the stabilizer trim cutout switches were in the ‘’cutout’’ position
the crash happens full three minutes later.
The other is that they make a convincing case that the problem is resolved. I don't know if that's possible given today's default hate for big corporations, we'll see. They've done it before with the 737 and the rudder problem it had in the 1990s or so. That problem led to a few fatal crashes, but I'm not sure it ever got the attention that this story is getting. The news cycle was different then.
I would absolutely fly on one once the problem is corrected.
What I would worry about is departure stalls, as MCAS doesn't seem to solve these. I wonder whether there isn't another 10E-5 to 10E-6 risk in there and people have just been lucky so far. Another MAX8 crash involving a stall would kill this plane I think, as it would prove much more that it's inherently unsafe.
That only holds if errors are statistically independent. See also Common Mode Failure [1].
[1] https://en.wikipedia.org/wiki/Common_cause_and_special_cause...
Now assuming 40.000 road deaths per year in the US and 300.000.000 citizens we have 0.000133 probability to suffer a road death a year. Assuming one 737MAX round trip per quarter we have 8 take-offs so .00008 probability to die in a 737MAX. Assuming commuter 40 trips a year we have a risk much higher than the average road death risk.
The problem is Boeing, not the MCAS system.
I don't think Boeing can be fixed.
When CEO said "We're taking a comprehensive, disciplined approach, and taking the time, to get the software update right.", I wondered if they would characterize their initial design the same way.
It's shameful to even try to pin it on software. The fundamental problem is that they didn't want to do the right thing by admitting and teaching pilots that this plane has different flight characteristics and they need to train for flying a similar, but different plane.
As long as this MCAS software even exists on the plane, I'll never fly on one again. If they take MCAS out, certify, and train properly then I'll fly on them. Otherwise, no.
The problem is they can't take the MCAS out.
The MCAS is there to fix a design fault whereby the plane has a tendency to pitch up automatically (and hence have a chance of stalling) when accelerating, due to the oversize engines and their placement.
There has been the mention that the customization of planes in a certain way exposed this error - that's the bullshit part. Planes are complicated, the testing of them is complicated, allowing your marketing/sales team arbitrarily inject feature flags into your life or death machine to maximize profits is silly.
Make a thing and prove it is safe, if you wish to modify said thing, then prove the new version is just as safe - and don't allow corners to be cut with something as dangerous and expensive as a plane, these things aren't cheap and they don't need to rapidly iterate versions, they can move slowly and safely and be held to a standard of provable safety that I agree would be unreasonable for software like windows or instagram.
As an aside, I would offer more leeway to Cessna, given their focus on the individual consumer market and emphasis of customization, if someone ordered the plane equivalent of the small pizza with half sausage no cheese and no sauce[1], but not too much more leeway due to the danger these planes can have on others.
I would rather there be guaranteed liability: have the execs set up a legal system to refund the entire order book and voluntarily plead guilty to federal charges in the event of another > 10 MAX deaths. But frankly, if Boeing is at fault for 340 deaths they should already be doing that.
That said, it seems likely that in the US Boeing is liable to their customers (airlines and aircraft owners) for fraud. In theory, the entire organization could be disbanded under RICO, but Boeing is a defense contractor, so more likely they pay to settle damages. I could see them getting away with paying for the costs of repairs, retraining and the lost revenue for planes already delivered in the US.
It also seems likely that Boeing is spending incredible amounts of money on PR to control the fallout. I expected the release of this report to be near the top of Reddit, but on reddit's /r/news the BBC report on this was sitting at only 21 net upvotes after 3 hours. (As of 8 hours ago.)
Like putting a very big engine in a small car: it’s a different car.
Isn’t that kind of the whole point?
Add in the facts that Boeing has been caught red-handed implementing a half-baked engineering solution as a regulatory dodge, and that this solution has to date crashed two aircraft and killed 346 (IIRC) people, and your view starts to look downright naive. You might call these tragedies "working out the kinks"; I call them wholly preventable, and evidence that human lives don't carry the proper weight in Boeing's financial calculus.
And speaking of the previous 737s, perhaps you should read: https://en.wikipedia.org/wiki/Boeing_737_rudder_issues
Which is to say, early defects in construction which were later resolved is not actually wholly uncommon to just this aircraft line, and planes of that model are still literally flying around today.
I'm also not sure why you'd reply to my comment when you clearly either haven't read it or have no interest in actually replying to the substance of it.
What would you suggest? Mothballing the MAX line for a wholly new aircraft? Arguably the MAX has significant flight testing time in production, to which one defect was found and is being remedied. A new aircraft would have less testing comparatively, and as noted, older aircraft really aren't inherently safer, as the 737's history shows.
My point was that the MAX will likely be the safest choice to fly in, and I don't think you offered up any logical argument saying otherwise.
I would suggest a fine-toothed audit of every single change made in the MAX aircraft, with particular attention paid to whether said changes were made solely in the interest of skirting regulations to sell more planes faster.
Because that is the point: Boeing's decision-making process is now highly suspect. It is pretty clear that the MCAS would not exist in anything like its current (flawed) form if Boeing hadn't been trying to avoid the pilot retraining requirement.
This is not a typical life-cycle for an engineering defect/flaw.
Hell no, I'll take Airbus or any other manufacturer over this crapware any day, even if I have to pay extra for the tickets. Boeing lost any trust in how they handled this, for very, very long time.
This topic is currently way beyond pure engineering issue, most human beings including me consider morality as quite an important aspect for example.
Unless I hear about some significant and measurable shift in the way company thinks and operates regarding to safety (nothing in the PR stuff discussed here), its a shady company with profits-above-safety mentality. No, thank you I can vote with my money
https://www.flightglobal.com/news/articles/boeing-wins-first...
Risk = probability x impact.
Even if probability has reduced (who knows by how much), impact is the near-certain death.
Avoid.