Boeing MAX production cut signals long grounding
leehamnews.com
leehamnews.com
Certainly not the FAA who delegated their oversight to Boeing.
346 people died because of their ineptitude.
So, no they where not operated in the same fashion. It’s still been grounded in the US for good reasons, but you can’t take individual regulations in isolation.
Even larger, well-resourced geopolitical entities like the EU rely heavily on the FAA to do its job for Boeing aircraft, much as the FAA relies on the EASA to do its job for Airbus aircraft. It's not pure rubber stamping, but it's close enough that things like this can pretty easily happen if a manufacturer's home agency falls asleep at the switch.
An example of the FAA's influence: Airworthiness regulations are so closely coordinated that special numbering is used by Canada, Europe, and Japan to match the numbering of FAA airworthiness regulations for easy cross-referencing. The FAA is also delegated air traffic control responsibility for much of the world's international airspace by the ICAO.
It is basically impossible to fly a commercial aircraft on Earth without being under the – possibly very heavy – influence of US civil aviation authorities, and it would take a great many resources and serious, concerted political will by many countries to change that.
The FAA has bilateral agreements with other countries and the EU for certification[1]. I read recently but can't quickly find in this that the FAA trusts EASA's certs for Airbus flying in the US.
The Ethiopian agency also trusts the FAA and EASA for this information[2]
So, it's not really tricky here, we can blame the FAA for the crash of a US manufactured plane in a foreign land (if the problem was the FAA's certification process).
[1] - https://www.faa.gov/aircraft/air_cert/international/bilatera...
[2] - https://web.archive.org/web/20180215175924/http://www.ecaa.g...
So, EASA can’t really abandon blame as easily as they abandon responsibility. If they allow a flawed process to continue then that’s on them.
However, in this case these agreements still give EASA veto authority about what aircraft are allowed. Which is why EASA was able to ground these airplanes before the FAA did.
https://www.caranddriver.com/features/a15125313/its-all-your...
Then again, I still wouldn't be surprised if most people were just too perplexed if their car suddenly accelerated like crazy and not stay calm and hit the brakes as hard as possible right away. It might take you a second or two to get what's going on, and by then you might already have lost control.
I stood on the brakes and didn't let up. He reached over and shut off the key, which locked the steering and put us in the ditch, but at relatively low speed due to the continuous braking.
Very new cars with an entirely radio-based "key" might behave something like that.
Without electronics or software involved, many years ago (1980's or so) there was a FIAT diesel engine, that was widely used on mid-sized cars, typically the Ritmo (Strada in the US) that had a servo-brake working by depression coming from the engine that had a defective membrane.
Basically, it could happen that the membrane broke/got a hole in it and the oil from the engine would enter the combustion chamber, to the effect that the engine would go up at full revs.
And you couldn't switch it off, the only way was to depress the clutch pedal, put in fourth or fifth gear and brake hard while releasing quickly the clutch.
It was a terrifying experience for someone not very familiar with cars/engines, though most people using a manual gearbox know that by depressing the clutch and braking would stop the car (so no or few accidents caused by this issue), knowing how to forcibly turn off the engine wasn't (and still is not) common knowledge, the motor would continue going on for a few minutes until something else would break or the oil in the engine would have been mostly burned (leaving the engine with no lubrication at full revs) until the engine would seize up.
Are you saying the additional, let’s say, what?, 60kW of power being applied to the wheels will require no additional effort at the brake pedal to overcome.
Colour me unconvinced.
I’ve never tried to imitate a burnout at 70mph / I’m not convinced the circumstances are the same.
>And despite dramatic horsepower increases since C/D’s 1987 unintended-acceleration test of an Audi 5000, brakes by and large can still overpower and rein in an engine roaring under full throttle. With the Camry’s throttle pinned while going 70 mph, the brakes easily overcame all 268 horsepower straining against them and stopped the car in 190 feet—that’s a foot shorter than the performance of a Ford Taurus without any gas-pedal problems and just 16 feet longer than with the Camry’s throttle closed.
From https://www.caranddriver.com/features/a16576573/how-to-deal-...
The result of Toyota's firmware audits were terrifying [1], and I think it's still reasonable to be concerned about potential issues here. If the brake-by-wire system were to have firmware issues, your point would be moot.
The thought that Boeing probably needs a similar audit to shine light on some dark corners and encourage them to clean up their act also seems quite reasonable.
[1] https://users.ece.cmu.edu/~koopman/pubs/koopman14_toyota_ua_...
As another sign of this, Toyota both stonewalled the investigation and later fired the director of the division in charge of ECU engineering, and rebuilt the division.
>cannot be ruled out
That seems like a very weak statement. If you asked a software auditing firm to inspect your massive codebase they're not going to "rule out" any bugs either.
It's not about software verification. In this case, the verifier would have given it a pass (with respect to this particular accident).
It's about bad management/bad requirements:
- "minimization of pilot training is the overarching requirement"
- "it's okay to feed only a single sensor into MCAS, even though there are two of them on the plane"
- "it's okay to sell critical safety equipment as options costing extra"
- "it's okay to not tell any pilot about any of this, since we practically didn't change anything".
This particular one is not about C++.
I'm coming down on the side of the cause of these accidents was due to the failure to properly type certify the aircraft. Because they were trying to avoid that they failed to do the system analysis and testing including simulator testing that would have easily found this.
This might be too hot of a take for HackerNews, but... look at how many people the FAA has kept safe over the past 30 years. I'm pretty sure the number of people who travel without dying is very, very high. I don't disagree that their might have been some ineptitude (I'm sure you could find that anywhere for anything since it's opinion driven), but to say the FAA is all rotten because 346 died is kind of dramatic when millions have been kept safe.
It's incredibly dangerous to propose changes to the FAA, given how much of an unqualified success they've had over the years at keeping flight safe. Don't let y our populist rage kill probably one of the best/most successful government institutions the US has ever created.
That is an incredibly ironic thing to say, because these deaths are a result of changes to the FAA, specifically, the delegation of the FAA's regulatory authority to the company being regulated. That this would not end well was easily foreseeable because it's such a blatant conflict of interest.
I was using the word in this sense:
"Irony: a literary technique, originally used in Greek tragedy, by which the full significance of a character's words or actions are clear to the audience or reader although unknown to the character."
Your fake choice of definition is even worse than what you actually meant.
All the world’s indeed a stage
And we are merely players
Performers and portrayers
Each another’s audience
Outside the gilded cageIt's somewhat abstract, but it's an interesting question to me, which is why I asked. Does the FAA's authority to regulate aircraft construction come from Congress specifically delegating authority over aircraft construction to them- or does the FAA only effectively have the ability to control construction because they can prevent the aircraft from flying in US airspace?
FAA's reputation alone was good enough for other aviation authorities to accept its certification of Boeing's MAX 8, which is why the FAA matter despite happening way outside its jurisdiction.
And yes the numbers are not the only relevant issue. It is the manner in which the original certification was done, the failure to act swiftly after the first crash, and the inordinate delay in acting even after the second crash which together seem to paint the picture of an organization which puts the interest of the manufacturer above passenger safety.
That doesn’t sound like an argument anyone would intentionally make.
They’ve done good work, great. But these two incidents represent a fall from grace, and both organisations should be pilloried for that incompetence especially because they have a history of high standards.
An important quote from her book "Engineering a Safer World" section "Questioning the Foundations of Traditional Safety Engineering":
"Old Assumption
- Major accidents occur from the chance simultaneous occurrence of random events.
New Assumption
- Systems will tend to migrate toward states of higher risk. Such migration is predictable and can be prevented by appropriate system design or detected during operations using leading indicators of increasing risk."
So it's: either the organizations are themselves able to keep the risk from increasing (as quoted, that is even "predictable" and of course it "can be prevented") or there have to be the external influences in that direction.
In this case, the organizations themselves failed.
Thus there is a discrepancy between your perspective / opinion and the typical way that the NTSB and FAA operate: this is precisely the time to address any issues.
The 737 MAX additionally has a tendency to pitch up when pitching up. The more you pitch the aircraft up, the more it wants to pitch up. As you pitch up more and more, you'd like the required force on the controls to increase, but in the 737 MAX it would naturally decrease.
In reality, major changes have been made to the way that the FAA operates and delegates authority in a series of sweeping changes since 2005 that were largely meant to cover for the fact that Congress has been severely underfunding the FAA.
The MAX is one of the first models we’ve seen wholly designed and manufactured under this new process. (substantial amounts of the underlying safety analysis of the 787 happened under the old setup)
One major change that may be relevant in this case is that whereas Designated Engineering Representatives used to do safety analysis work at Airplane manufactures in a completely parallel, firewalled cross-cutting engineering group that effectively reported directly to the FAA in a quasi on-loan model, “in order to reduce costs” the FAA allowed this to be scrapped and replaced with “Airworthiness Representatives” embedded in, and crucially answering to, the regular engineering management at the company. Company management then acts as middle-man to the FAA. AR Management at say Boeing is nominally supposed to act as independent of Boeing and represent FAA opinions, but in practice routinely pushes back on FAA requests and acts to represent the interests of Boeing management: https://www.seattletimes.com/business/delegating-aircraft-sa...
So previously if day-to-day engineering was under pressure from a manager to ship a software subsystem or complete a component design, these deadlines were unrelated to the DERs, who operated in their own safety-focused management chain under the FAA.
Now, the AR is under the same manager and pressures as everyone else to hit the ship date. It is unsurprising that quality of analysis might take a back seat to job security in such a setup.
It does not make much sense to defend the FAA by pointing at successes produced by processes that were no longer in place by the time the 737 MAX engineering programme began.
The 737 Max could become the Edsel of airplanes.
If they don't both give the same reading, MCAS turns off.
There’s no problem if one fails but what if both fail and both corroborate a bad reading?
Certainly the cost of 3 such sensors would not be as high as the cost of another crash.
This is why the parent poster is arguing for 3 sensors (and the real reason for tripling). If not all sensors agree but 2/3 do, it is more probable that the two sensors are correct than the 1 sensor disagreeing.
MCAS being automatically disabled when the sensors agree but leaving the pilots with electronic trim control seems like a perfectly adequate solution. The MCAS system was never even necessary for flight, it was only necessary for certification. In the situations where it's meant to be active, which are a limited subset of all high angle of attack scenarios, it's fine system to have if it's working correctly. But it should never be active outside of that limited set of scenarios. It should never be active when both angle of attack sensors aren't indicating a high angle of attack within a reasonable distance of each other.
Frankly, if two sensors are indicating a high angle of attack and one is not, it's probably still sensible to disable MCAS. I don't have any of the real numbers, but the chance of a 737 being in a low speed high angle of attack scenario is low in the first place, possibly sufficiently low that "two sensors being wrong and the aircraft being in level flight" might be more likely than "aircraft is near stall and one sensor is wrong."
To know for sure we'd need at least the hard data on what modes of failure these sensors have, how likely any of those modes is to occur and what the expected readouts from those failure modes are, and how likely a 737 is to encounter a low speed stall scenario. We, or at least I, don't have any of that. But my gut says that two sensors are sufficient iff the MCAS system is only active when they agree.
Furthermore, the chance of two sensors being wrong actually goes up if you have three sensors, rather than two. Correct me if I'm wrong, stats was never my strong point, but it seems to me like the cumulative binomial distribution is relevant here:
#lang racket
(require math/number-theory)
(define (general-binomial p k n)
(* (binomial n k)
(expt p k)
(expt (- 1 p)
(- n k))))
(define (cumulative-general-binomial p k1 k2 n)
(apply +
(map
(λ (k) (general-binomial p k n))
(range k1 (add1 k2)))))
Chance of a single sensor failing, if each has a 1% chance of failure (sanity check): > (cumulative-general-binomial .01 1 1 1)
0.01
Chance of two or three out of three sensors failing, if each has a 1% chance of failure: > (cumulative-general-binomial .01 2 3 3)
0.00029800000000000003
Chance of two out of two sensors failing, if each has a 15 chance of failure: > (cumulative-general-binomial .01 2 2 2)
0.0001
Two out of three sensors failing is three times more likely than two out of two sensors failing!(In other words, two broken sensors voting out a third working sensor is more likely than two out of two sensors being broken.)
Because as soon as one sensor fails that aircraft will go in for maintenance.
MCAS should turn off as soon as a single sensor fails, and three sensors are therefore unnecessary. Two sensors are sufficient to detect when a single sensor fails. If you only have two sensors and two fail, then MCAS remains active and your plane crashes. But that's not likely to happen. However that's more likely to happen if you have three sensors and try to use two sensors to vote out a third, in order to keep MCAS active when a sensor fails. In that configuration, a double failure (causing a crash) is three times more likely.
My conclusion is turn off MCAS as soon as even one sensor disagrees with the others. And if that's how MCAS is configured, then three sensors is unnecessary overkill. If you want overkill, you may as well double up the sensors on both sides and have four instead of three; all the better right?
I understand that's not what you mean, that the sensor indicating a situation closes to nominal flight should be chosen, but I think the sticky part is that MCAS isn't a system meant for normal flight conditions. MCAS is only supposed to be active when the aircraft is in an extreme scenario. So in fact if the sensor with "less-extreme adjustment" is preferred, in a way that actually means the system functions as I suggested: MCAS is disabled if the sensors disagree. But not quite. In your scheme if both the sensors are extreme but disagree, MCAS would be active to the lesser extent. But in my scheme, if both sensors are extreme but disagree, MCAS would be totally inactive (while leaving the pilot with electronic stabilizer trim control of course, allowing the pilot to manually do anything MCAS would be capable of doing.)
If I understood correctly, MCAS trimmed it so much that the pilots were unable to bring it back manually.
This sounds like Boeing engineers didn’t even put a limit on the maximum trimming that MCAS can do, not even to the maximum theoretical limit for the plane/engines.
Not only that, MCAS controlled an electric motor which turned the trim wheel and which could apply more torque than a human turning it manually. The only way to disable MCAS was to cut power to that motor. MCAS pointed the aircraft at the ground, and it was impossible to trim the aircraft to achieve level flight again.
Mind, MCAS was supposed to be a crutch to fly at the edges of the flight envelope, something that a regular pilot would never encounter because under normal conditions pilots wouldn't find themselves in a regime where MCAS would be activated. That was the idea, instead we had two hull losses within 6 months!
The issue from the Ethiopian crash was that, in the extreme trim angle, there was simply too much force on the screw to turn manually. This condition is trained for, and the solution is to let the plan angle down to relieve the aerodynamic pressure on the control surface. That gives you an opportunity to manually control the trim wheels.
The pilots did not have the benefit of altitude to perform this maneuver, so (likely) instead re-enabled the electric trim in a bid to use it to reduce the nose-down trim before the MCAS would re-engage. This proved fatal.
Scroll down slightly for the empennage diagram, right hand side, item 3.
https://www.seattletimes.com/business/boeing-aerospace/boein...
I also doubt customers will really vote with their feet given that the number one factor when booking a ticket is price. If some people choose not to fly on them it will create supply/demand imbalances in the market which would be interesting.
Agreed. As the article points out:
"Passengers eventually returned to flying the 787 and to other airplanes that were grounded: the McDonnell Douglas DC-10, the Douglas DC-6, the Lockheed Constellation and even the de Havilland Comet."
If Boeing really needed to cut these corners in order to remain competitive, then having to redo those corners might make them too expensive or inefficient for the market.
This is not my domain, but it reminds me of financial fraud, accountability of those at the top, and the consequences they face.
I was studied accounting in the wake of the major accounting scandals of the late 90's/early 00's. The Sarbanes-Oxley legislation was passed. It states that the CEO and CFO are directly responsible for their company's financial statements.
AIG was the first major accounting fraud post Sarbanes-Oxley. Investigated by the SEC, determined non-criminal, CEO stepped down, and that was his consequence. [1]
Boeing's CEO, Dennis Muilenberg, has the blood of 346 people on his hands. He is at the top, it is his organization, and his responsibility. I hope an investigation determines if it is criminal.
I think one of the major shifts I would like to see in our society is holding those in power to account. Whether it's accounting, aviation, banking, it doesn't matter. As it stands those at the top rarely pay for their malfeasance.
[1] https://vc.bridgew.edu/cgi/viewcontent.cgi?article=1145&cont...
If it's the same general setup as on the medical side with the FDA, then it's a virtual certainty that liability will fall with some compliance and QA types, as well as any engineers or engineering managers who signed the relevant documents. Those signatures are all legally binding, and represent to everyone up the chain that the systems in question are functioning properly. If the government can show that the systems in question could not have been functioning properly, they got you. (Another thing we learned from our lawyers about the FDA side, each document that you signed, represents one count of lying to the federal government at a minimum. Multiply that by the number of documents signed to get a single system through, and you get an idea of why you should never sign anything if you have any reservations at ALL. No matter how slight the reservation. No matter how much pressure the higher ups put on you. I think the rules are the same on the FAA side. So these guys have really stepped in it.)
That said, they may be able to snag a few executives here or there, but only if they can prove who knew what, and when. Execs, you would think, would be pretty careful about liability type things, so they could look very hard and not find anything on any of the execs. It would not be collusion or preferential treatment, it's just hard to find that kind of a smoking gun in a mountain of electronic documents and messages. (I strongly suspect that if the government were to press hard enough though, that some of the engineering managers and compliance types would turn state's evidence to get lighter sentences. At that point, you could probably get some execs I'd imagine? Still might be hard though.)
The engineers and QA/Compliance folks, though, should really be consulting with outside counsel. Just as a precautionary measure. I wouldn't trust Boeing execs to not throw me under the bus.
And this time around, it looks like a pretty big bus. I don't think you survive this hit.
tl;dr: 737 NG and MAX aircraft are fundamentally unsafe because of systemic lapses in regulatory oversight. These aircraft cannot be made safe economically due to Boeing's regulatory capture of the FAA, so it's best to never fly on them.
In my mind, Boeing as a passenger transport company is, or should be, finished. How they acted regarding the 737 NG and MAX are criminally-unforgivable.
I remember reading that the MCAS system uses the exact same physical contacts as the pilot's electrical trim adjustment switches.
I'm wondering if they're trying to change their software implementation to more cleanly separate the two abstractions in the code in order to avoid having to do a hardware or firmware change on the jackscrew motor controllers.
If before, the signalling was such that the signalling was handled as a sort of one off block jammed into some function somewhere, they may now have to be doing much more thorough refactoring to separate out those interfaces, and improve the traceability, testability, and readability, all with the overhead of a system likely reclassified to "catastrophic" system hazard rating.
Either way, after some number crunching of my own, I can only see going forward with MCAS reasonable if there is some way to discretely disable its' ability to signal the jackscrew motor while leaving the electronic trim available in case of erroneous MCAS activation in the future, because with the requisite torque involved to quickly actuate that control surface against potential overspeed loads exacerbated by elevator up pitch commands, you'd need the electric motors, period.
Without taking into account friction, and using the stabilizer dimensions of the 737-800, in air conditions approximate to Addis Ababa, at 350 knots, discluding extra load from elevator up, and assuming an M24 jackscrew thread, it would have taken 357 ft-lbs torque to actuate against that wind load.
That's the output of a non-trivial automotive engine to bring that down to something the non-mathematically inclined can recognize, and while theoretically may be possible to gear for from a hand crank, I'm not confident I'm going to be able to figure out a gear train that can gear reduce enough to allow anywhere near enough speed when rotated by one pilot to get that horizontal stabilizer where it needs to be in so short a length of time.
Either way, I foresee a lot of chaos, and scrutiny moving forward in the handling of this, and can only hope we can finally come to terms as a nation with why certain regulatory agencies are worth the cost of investing in if only to keep the seeds of such tragedies as happened here from ever being able to germinate again.
Not really. I am no expert, that is why I no longer trust FAA/Boeing telling me it is safe any more, at least in this particular case. As a passenger, I would avoid buying tickets from this plane even it means more cost
Also I don't want to fly in a plane where 'trained' pilots have to fearfully watched every feet they climb to quickly overturn a system that malfunctions.
* Manual MCAS cut-out switch that leaves the electronic trim available, without resorting to "hacks" like using the flaps.
* AoA disagree warning option on all planes, maybe even auto-cut out MCAS when disagree happens.
* Simulator training for all pilots on all MCAS failure scenarios and flying without MCAS.
https://www.npr.org/2019/04/05/710477435/boeing-to-slow-prod...
> had a common link of a malfunctioning flight-control software called MCAS.
My understanding is the software was fine, it was faulty sensors with no redundancy and poor feedback displays to pilots.
And who is managing one sensor only or not providing the feedback? The MCAS software
The software is quite flawed (and operates differently than how it was described to the FAA) but there are two (thus redundant) sensors being used in a not-so-redundant manner.
Before this article I would have said, approaches zero chance a type certificate would be required. But the idea it would take 6-8 months to get it flying again? That's so outside the realm of what I was expecting that there must be some talk about it.
What kind of long term implications could this have for the Aerospace industry in the US? Will we see some fundamental changes in safety oversight, or design, for these aircraft? Is this a "back to the drawing-board" moment for Boeing and the 737?
The Ethiopian airlines crew followed Boeing's post-Lion Air safety bulletin and still crashed. There's no safe way to operate a 737 Max in its current state. The hypothetical recovery techniques (e.g. point nose down to release pressure on the horizontal stabilizer) only work at high altitude, which is notable if Ethiopian airline's AOA sensor was damaged by a bird strike right after take-off.
Nobody who understands the current state of this investigation should be saying they'd be comfortable on a 737 Max without changes. The "pilot training" narrative isn't just dead, but dead, buried, with a tomb stone.
Sure, pilots should have received training on MCAS existing, but MCAS was commanding trim changes that aren't easily recoverable under any circumstances and certainly not if you follow procedure and disable electronic trim. Nobody should fly on the 737 Max until an update completed, I'd go so far as to suggest that the US/EU should ban ferry flights.
That's not quite right. Manually operating the motorized trim as soon as unwanted nose-down trim is detected prior to disabling it with the cutout switches appears to be a viable means of recovery. It's also an undocumented, timing-sensitive procedure in a critical phase of flight, which is not anything resembling what airline pilots want from their planes.
That's what the Lion Air crew did. They died. The Ethiopian Airlines crew followed Boeing's safety bulletin. They also died.
But I do take your point, which may prove to be correct. It is hypothetically possible to electronically trim against MCAS then immediately cut out the electronic trim system before MCAS has a chance to re-initiate (5 secs after last trim command). Then you mechanically trim for the remainder of the flight, which should be possible without too much pressure on the horizontal stabilizer.
It is crazy to think that that may ultimately be the life saving procedure here, given its complexity/nuance. Particularly for a largely undocumented (for flight crew) system.
I find the design of this system shockingly ill-considered. At the very least, it should require input from both sensors and not activate if the sensors disagree. It seems to me a better system would be to automatically add some nose-down trim if the pilot applies full forward pressure on the stick since the primary underlying concern is insufficient elevator authority in certain impending stall conditions for that standard pilot response to be effective.
From what's visible so far in the investigations Boeing (a) botched the MCAS implementation and (b) failed to train pilots on differences between the Max and previous models. Cure those two and the problem seems to be solved.
Why does anyone think this? The MCAS system rarely engages.
The issue is simply to make the stick behavior similar to the older 737s at high AoA. For an older 737, when you're pitching way up, you really have to pull on the yoke to keep that high AoA. The plane naturally wants to return to a neutral AoA, so you have to fight it. With the new design, the engine position keeps the plane from wanting to return to the neutral AoA, at least to the degree it did before. Hence, the 'stick feel' at high AoA is lighter. You don't get the same tactile feedback about being near a stall. (you still have the stick shaker)
The MCAS is simply there to bring back that resistance to extreme AoA, and thus make it less likely to accidentally stall. MCAS isn't even active with flaps down (i.e. around takeoff and landing) so can't possibly affect those aspects of flight.
It's a questionable design for a number of reasons, but it's not at all necessary for flight, let alone 'basically impossible' without it.
For Lion Air, the pilots didnt run (or even recall) the checklist so didn't disable MCAS.
However Ethiopian appears much worse, pilots did run the checklist, had some success with MCAS turned off but couldn't operate the manual trim (unclear why). They then made the fatal decision to turn back on electric trim (and MCAS with it) and MCAS almost immediately nosed them down into an unrecoverable state.
I had a heck of a time parsing that. I kept trying to read the "grounding" as something related to electrical grounding, wondering what "long grounding" was in that context and how Boeing had screwed it up
> Boeing hasn’t announced what the second software problem is. LNA is told it is the interface between the MCAS upgrade and the Flight Control System, but specifics are lacking.
> LNA interprets these combined events as indicative the MAX will be ground well past the Paris Air Show in June.
Somewhat poor choice by the writer here given the association.