Certainly not the FAA who delegated their oversight to Boeing.
346 people died because of their ineptitude.
Certainly not the FAA who delegated their oversight to Boeing.
346 people died because of their ineptitude.
This might be too hot of a take for HackerNews, but... look at how many people the FAA has kept safe over the past 30 years. I'm pretty sure the number of people who travel without dying is very, very high. I don't disagree that their might have been some ineptitude (I'm sure you could find that anywhere for anything since it's opinion driven), but to say the FAA is all rotten because 346 died is kind of dramatic when millions have been kept safe.
In reality, major changes have been made to the way that the FAA operates and delegates authority in a series of sweeping changes since 2005 that were largely meant to cover for the fact that Congress has been severely underfunding the FAA.
The MAX is one of the first models we’ve seen wholly designed and manufactured under this new process. (substantial amounts of the underlying safety analysis of the 787 happened under the old setup)
One major change that may be relevant in this case is that whereas Designated Engineering Representatives used to do safety analysis work at Airplane manufactures in a completely parallel, firewalled cross-cutting engineering group that effectively reported directly to the FAA in a quasi on-loan model, “in order to reduce costs” the FAA allowed this to be scrapped and replaced with “Airworthiness Representatives” embedded in, and crucially answering to, the regular engineering management at the company. Company management then acts as middle-man to the FAA. AR Management at say Boeing is nominally supposed to act as independent of Boeing and represent FAA opinions, but in practice routinely pushes back on FAA requests and acts to represent the interests of Boeing management: https://www.seattletimes.com/business/delegating-aircraft-sa...
So previously if day-to-day engineering was under pressure from a manager to ship a software subsystem or complete a component design, these deadlines were unrelated to the DERs, who operated in their own safety-focused management chain under the FAA.
Now, the AR is under the same manager and pressures as everyone else to hit the ship date. It is unsurprising that quality of analysis might take a back seat to job security in such a setup.
It does not make much sense to defend the FAA by pointing at successes produced by processes that were no longer in place by the time the 737 MAX engineering programme began.
It's incredibly dangerous to propose changes to the FAA, given how much of an unqualified success they've had over the years at keeping flight safe. Don't let y our populist rage kill probably one of the best/most successful government institutions the US has ever created.
That is an incredibly ironic thing to say, because these deaths are a result of changes to the FAA, specifically, the delegation of the FAA's regulatory authority to the company being regulated. That this would not end well was easily foreseeable because it's such a blatant conflict of interest.
I was using the word in this sense:
"Irony: a literary technique, originally used in Greek tragedy, by which the full significance of a character's words or actions are clear to the audience or reader although unknown to the character."
Your fake choice of definition is even worse than what you actually meant.
All the world’s indeed a stage
And we are merely players
Performers and portrayers
Each another’s audience
Outside the gilded cageThat doesn’t sound like an argument anyone would intentionally make.
They’ve done good work, great. But these two incidents represent a fall from grace, and both organisations should be pilloried for that incompetence especially because they have a history of high standards.
An important quote from her book "Engineering a Safer World" section "Questioning the Foundations of Traditional Safety Engineering":
"Old Assumption
- Major accidents occur from the chance simultaneous occurrence of random events.
New Assumption
- Systems will tend to migrate toward states of higher risk. Such migration is predictable and can be prevented by appropriate system design or detected during operations using leading indicators of increasing risk."
So it's: either the organizations are themselves able to keep the risk from increasing (as quoted, that is even "predictable" and of course it "can be prevented") or there have to be the external influences in that direction.
In this case, the organizations themselves failed.
And yes the numbers are not the only relevant issue. It is the manner in which the original certification was done, the failure to act swiftly after the first crash, and the inordinate delay in acting even after the second crash which together seem to paint the picture of an organization which puts the interest of the manufacturer above passenger safety.
The 737 MAX additionally has a tendency to pitch up when pitching up. The more you pitch the aircraft up, the more it wants to pitch up. As you pitch up more and more, you'd like the required force on the controls to increase, but in the 737 MAX it would naturally decrease.
Thus there is a discrepancy between your perspective / opinion and the typical way that the NTSB and FAA operate: this is precisely the time to address any issues.
FAA's reputation alone was good enough for other aviation authorities to accept its certification of Boeing's MAX 8, which is why the FAA matter despite happening way outside its jurisdiction.
It's somewhat abstract, but it's an interesting question to me, which is why I asked. Does the FAA's authority to regulate aircraft construction come from Congress specifically delegating authority over aircraft construction to them- or does the FAA only effectively have the ability to control construction because they can prevent the aircraft from flying in US airspace?
The result of Toyota's firmware audits were terrifying [1], and I think it's still reasonable to be concerned about potential issues here. If the brake-by-wire system were to have firmware issues, your point would be moot.
The thought that Boeing probably needs a similar audit to shine light on some dark corners and encourage them to clean up their act also seems quite reasonable.
[1] https://users.ece.cmu.edu/~koopman/pubs/koopman14_toyota_ua_...
As another sign of this, Toyota both stonewalled the investigation and later fired the director of the division in charge of ECU engineering, and rebuilt the division.
>cannot be ruled out
That seems like a very weak statement. If you asked a software auditing firm to inspect your massive codebase they're not going to "rule out" any bugs either.
https://www.caranddriver.com/features/a15125313/its-all-your...
Then again, I still wouldn't be surprised if most people were just too perplexed if their car suddenly accelerated like crazy and not stay calm and hit the brakes as hard as possible right away. It might take you a second or two to get what's going on, and by then you might already have lost control.
Without electronics or software involved, many years ago (1980's or so) there was a FIAT diesel engine, that was widely used on mid-sized cars, typically the Ritmo (Strada in the US) that had a servo-brake working by depression coming from the engine that had a defective membrane.
Basically, it could happen that the membrane broke/got a hole in it and the oil from the engine would enter the combustion chamber, to the effect that the engine would go up at full revs.
And you couldn't switch it off, the only way was to depress the clutch pedal, put in fourth or fifth gear and brake hard while releasing quickly the clutch.
It was a terrifying experience for someone not very familiar with cars/engines, though most people using a manual gearbox know that by depressing the clutch and braking would stop the car (so no or few accidents caused by this issue), knowing how to forcibly turn off the engine wasn't (and still is not) common knowledge, the motor would continue going on for a few minutes until something else would break or the oil in the engine would have been mostly burned (leaving the engine with no lubrication at full revs) until the engine would seize up.
I stood on the brakes and didn't let up. He reached over and shut off the key, which locked the steering and put us in the ditch, but at relatively low speed due to the continuous braking.
Very new cars with an entirely radio-based "key" might behave something like that.
Are you saying the additional, let’s say, what?, 60kW of power being applied to the wheels will require no additional effort at the brake pedal to overcome.
Colour me unconvinced.
I’ve never tried to imitate a burnout at 70mph / I’m not convinced the circumstances are the same.
>And despite dramatic horsepower increases since C/D’s 1987 unintended-acceleration test of an Audi 5000, brakes by and large can still overpower and rein in an engine roaring under full throttle. With the Camry’s throttle pinned while going 70 mph, the brakes easily overcame all 268 horsepower straining against them and stopped the car in 190 feet—that’s a foot shorter than the performance of a Ford Taurus without any gas-pedal problems and just 16 feet longer than with the Camry’s throttle closed.
From https://www.caranddriver.com/features/a16576573/how-to-deal-...
I'm coming down on the side of the cause of these accidents was due to the failure to properly type certify the aircraft. Because they were trying to avoid that they failed to do the system analysis and testing including simulator testing that would have easily found this.
It's not about software verification. In this case, the verifier would have given it a pass (with respect to this particular accident).
It's about bad management/bad requirements:
- "minimization of pilot training is the overarching requirement"
- "it's okay to feed only a single sensor into MCAS, even though there are two of them on the plane"
- "it's okay to sell critical safety equipment as options costing extra"
- "it's okay to not tell any pilot about any of this, since we practically didn't change anything".
This particular one is not about C++.
The FAA has bilateral agreements with other countries and the EU for certification[1]. I read recently but can't quickly find in this that the FAA trusts EASA's certs for Airbus flying in the US.
The Ethiopian agency also trusts the FAA and EASA for this information[2]
So, it's not really tricky here, we can blame the FAA for the crash of a US manufactured plane in a foreign land (if the problem was the FAA's certification process).
[1] - https://www.faa.gov/aircraft/air_cert/international/bilatera...
[2] - https://web.archive.org/web/20180215175924/http://www.ecaa.g...
So, EASA can’t really abandon blame as easily as they abandon responsibility. If they allow a flawed process to continue then that’s on them.
However, in this case these agreements still give EASA veto authority about what aircraft are allowed. Which is why EASA was able to ground these airplanes before the FAA did.
Even larger, well-resourced geopolitical entities like the EU rely heavily on the FAA to do its job for Boeing aircraft, much as the FAA relies on the EASA to do its job for Airbus aircraft. It's not pure rubber stamping, but it's close enough that things like this can pretty easily happen if a manufacturer's home agency falls asleep at the switch.
An example of the FAA's influence: Airworthiness regulations are so closely coordinated that special numbering is used by Canada, Europe, and Japan to match the numbering of FAA airworthiness regulations for easy cross-referencing. The FAA is also delegated air traffic control responsibility for much of the world's international airspace by the ICAO.
It is basically impossible to fly a commercial aircraft on Earth without being under the – possibly very heavy – influence of US civil aviation authorities, and it would take a great many resources and serious, concerted political will by many countries to change that.
So, no they where not operated in the same fashion. It’s still been grounded in the US for good reasons, but you can’t take individual regulations in isolation.