Boeing’s Homicides Will Give Way to Safety Reforms if Flyers Organize
nader.org
nader.org
I say that because everyday at work I am fighting stupid deadlines and ridiculous suggestions to skip QA, unit tests, and other processes to meet those deadlines.
If we criminally charge executives when their products cause loss and deaths, then I suspect they will start respecting processes and sane deadlines. Right now, there are no consequences for them. The worst that can happen is their stock options lose some value or they lose their job with multimillion dollar golden parachute. All they have to do is wait a few months and then get another job or start their own business.
- Are physics computer simulations (e.g. aerodynamic flow[0]) realistic enough that engineers could have predicted the tendency for the nose to push up into a stall with the forward-mounted bigger engines while still at the CAD drawing stage? (Place some engines on the drawing with X amount of specified thrust, move them forward on the wing, then run a simulation, etc.) Or is the interaction of behavior so complex or so subtle that they had to build the real thing before realizing "Oops, our internal test pilots just noticed the plane is unstable and it looks like we need a software augmentation system!"
- Could an unchanged 737-MAX flight simulator from last year reproduce the conditions for the Lion Air and Ethopia crashes? In other words, could a pilot used his/her imagination and said, "What if we make this AOA indicator give a bad reading -- what happens with MCAS?". Similar to how a pilot can choose to simulate a flamed-out engine, could one have chosen a stress-test scenario with a broken AOA sensor? (The infamous deleted video from MentourPilot showed his simulated struggles with turning the stabilizer trim against 400mph aerodynamic loads but it's not clear if a broken AOA can be simulated.)
Yes, the 737-MAX was ultimately a failure of management and financial pressure but I'm curious if Boeing even had the technical debugging tools to predict this.
[0] examples: https://www.youtube.com/results?search_query=aerodynamics++s...
Yes. They knew full well that the MAX would do that in circumstances where a normal 737 would not. There is nothing wrong with the MAX's performance characteristics. The aircraft itself is perfectly safe to fly. What isn't safe is the half baked MCAS system they used to deal with that edge case so they could avoid having to retrain pilots.
To be clear, you're saying Boeing engineers knew this as early as the CAD drawing stage?
Any automotive engineer who designs that stuff can look at a vehicle suspension and give you a rough estimate of how the vehicle will handle under certain circumstances. People who are well versed in boat hulls can look at a shape and make the same inferences. Yes, commercial airline designers should be able to look at a design and have a rough idea of how it will handle.
It's not magic. It's physics. If your day job involved understanding that niche of applications you should be able to look at it and draw some rough conclusions.
How do we know? because the FAA approval is not ensuring me that there are not any other problematic systems where Beoing self approved the corner cuts they made. IMO a full re-approval is needed with a trust worthy institution is needed before you can claim that the airplane is "perfectly safe"
Those things must be demonstrated to get an airworthiness certificate under that part. Is this FAR all encompassing of that which makes an airplane safe or not? Because we have an airplane that was so certified, and yet we have two crashes that directly contradict their safety (hence they're grounded).
I'm less concerned that these planes are somehow, without computers, not complying with FAR 25. I'm more concerned that Boeing (and FAA) will accept a software only fix, and continue to avoid a type certificate for this derivative model aircraft, and thus avoid any additional training for pilots. Basically, I expect Boeing will take the full hit, i.e. the software was flawed and now it is fixed, so that airlines won't be dinged for any on-going training requirement.
Thus far the market isn't significantly dinging Boeing's value. Today's price is the same as it was in September of last year before either accident happened. The market is effectively saying those accidents don't matter that much, cost wise.
Unless more information comes out that suggests there was wrong doing by either Boeing or the FAA. That could change the whole calculus.
This says to me that no, they did not have the debugging tools to predict this because they had no plans to simulate it before going to market. The same was found of Toyota after their uncommanded acceleration lawsuits. In that case, the company was found to have deliberately ignored industry-standard testing procedures for mission-critical software.
Could that also be the case here?
Right. The media repeatedly reminded us that pilots only had a 2-hour orientation on an iPad for the new 737 MAX.
I was wondering if a 737 MAX simulator that could replicate the AOA failures even existed. If Boeing's own internal test pilots had no ability to synthesize a broken AOA with misbehaving MCAS in the flight sim, it means that forcing the airlines to pay more money to have all their pilots more comprehensively trained in a 737 MAX simulator may not have prevented the crashes. The 737 MAX simulator hardware/software would still had to have been modified. Pilots can't train for an edge case scenario that the simulator can't artificially produce.
Also in an alternate universe, a "more realistic" sim with AOA failure could have provided feedback loop to the Boeing engineers to adjust the MCAS software to be less aggressive and/or emphasize the need for 2 AOA sensors instead of just 1.
If management is depending upon a reality distortion bubble to keep the company out of trouble, then they're not going to listen to anyone who tries to pop that bubble.
This entire article comes across as though an old man has read something he doesn't like in the newspaper and is suddenly an expert on it in order to justify his outrage when in reality the situation is much more nuanced than his understanding.
Are people really that greedy? You don't want to think they are, but at the same time you struggle to come up with any reason other than money for doing what Boeing did.
It's really a sad statement on how people behave.
To put an automated system on top of your force assists just seems like asking for trouble. In layman's terms, the more you pile on, the more that can go wrong.
All that said, as a matter of full disclosure, I only know how to fly planes, not really an aeronautical engineer.
These all can be done in reasonable and safe ways. Boeing just didn't do it.
You treated the symptom, not the problem.
The problem is Boeing's willingness to cut corners and risk lives in the name of profit.
You can't fix that with software or pilot training.
I don't see a problem with the idea of delegating aspects of flight to the computer - just fix the software engineering practices that lead to this tragedy. Please. :)
Boeing's practice of cutting corners is why 300+ people are dead
I'm guessing the next step for FAA and EASA will be to revise the process under which this approval was granted to Boeing.
At least part of the blame lands on the authors of the regulations that led to this.
Clearly Boeing gets lots of blame too. As with most engineering screwups of this magnitude, multiple organizational failures contributed.
In a modern fly-by-wire aircraft, "flight envelope protection" is deeply integrated into the control system. It is something that pilots are trained about; when the system is in a degraded mode because of a sensor failure, it tells the pilot, and pilots are trained how to deal with that.
Fly-by-wire brings large benefits such as a reduction in weight, lower assembly costs, lower maintenance cost, and better comfort because fly-by-wire can counteract turbulence. These are passed on to the consumer in the end.
To avoid any investment in engineering or pilot training, Boeing bolted a half-baked "flight envelope protection" system on when moving the engines caused a change in the flight envelope. Too bad they didn't tell the pilots...
I wouldn't say that the 737 MAX should never fly again but the plane should get a new type certificate and pilots should be retrained.
As a passenger one thing you can do is fly Jetblue because they don't have any 737s in their fleet. Also ask airlines about the A220 and E195-2 airliners. These are smaller than the 737 but feel larger from a passenger perspective and also have lower seat*mile cost. Try them out, you'll be impressed!
First of all, while most public know evidence points at MCAS as the source for the crashes, the accident investigations have not concluded yet. The article doesn't even mention that. But, with all what we know so far, Boeing has good reasons to significantly overwork the MCAS software and is doing so.
I am not an aviation expert, but from all I have heard about the 737 MAX (from actual pilots), it looks like the airplane itself is not the issue, it was the specific faults in the MCAS implementation and that the pilots were not properly trained on the aircraft. Beyond fixing the obvious issues with the MCAS implementation, the biggest item for bringing the 737 MAX back into business needs to be pilot training. Training both how to fly the machine with MCAS deactivated as well as dealing with the potential failure szenarios of the MCAS system.
Of course, the whole certification process for the 737 MAX needs to be reviewed to guarantee that the machine has the level of airworthyness one would expect. This is probably the most time-consuming step on the way to restoring its flight-status, but the most necessary one.
Assuming that the 737 MAX after a significant update to the MCAS system passes a proper certification, in contrast to the article I would strongly argue for it to return into service. As much as we know for now, the machine isn't inherently unsafe to fly. But a cancellation could have drastic effects on air travel safety. Boeing decided against a new design in 2011 because of time constraints, and it is now 8 years later. A proper replacement for the 737 MAX wouldn't be ready for many years, probably only at the end of the next decade. If you are worried about safety, you certainly don't want Boeing to rush the development of a new design. Also, there would be little alternatives for replacement. Airbus could increase its output, but that also bears risk of general safety. As does flying the machines, the 737 MAX was meant to replace for more years.
So, unless other issues with the 737 MAX are found in review, it definitely should be put back into business.
This would destroy the main selling point for Boeing (training pilots for a different type rating is a massive expense and headache for airlines), and would also mean that across the world there would be no pilots allowed to fly the existing 737MAX.
The point about not cancelling the 737MAX because of the risk that the new models developed would be rushed and unsafe due to Boeing rushing the development of a new design is... not very plausible I'm afraid.
Yes, I think that at least more training/certification of the pilots for the 737 MAX is needed.
My argument was, that after fixing MCAS and proper recertifying the 737 MAX there is no fundamental reason not to put it back into business. And that not putting it back into business also carries some safety risks. I never claimed that it should be put back into business because of that.
But Nader didn't present a fundamental reason why the machine would be unsafe and completely ignored the consequences of permanentely grounding the 737 MAX.
Boeing has used it's market power to keep these away from passenger and airlines.
So it's not just a matter of people getting killed. It's people getting killed so you can pay more for airline tickets, have less room and comfort when you fly, have less frequent flights, hear more noise from airplanes, and experience more global warming.
As for global warming note also that the 737 has terrible takeoff performance, even under favorable conditions it has twice the takeoff distance of some much larger airliners. Every hot summer you will hear that "airplanes are grounded because of the heat, but really "737s are grounded because of the heat" because the 737 can barely take off as it is.
This is what secular stagnation looks like. It is undercompetition and underinvestment, just like we see with wireline internet service in the US. Don't let neoliberals fool you with the "there is no alternative" line because there is.
*There is probably some room here for a joke about how people leave Vegas heavier than they were when they landed.
737 SUX and that is it.
The situation can be easily and safely fixed in software, but it will cost a lot of money.
The MCAS system needs to step back to being an advisory-only system, just warning the pilots if it thinks a stall is immanent (and validate sensor inputs too). Then we will need to have extensive pilot training to deal with the different flight characteristics in the 737 MAX.
This means a new type rating, which costs time and money... which the MCAS system was created to avoid.
But yeah, the system as-is shouldn't be allowed to continue.
This is written by Ralph Nader, taking the extreme position has been his MO since 1965. As far as I can tell he takes a very hard position, in order to try and move the needle of public sentiment.
There is already a stall warning alarm on all modern planes and have been for decades.
I've only flown Cessnas (which all have stall warning horns), but from what I've read the intention of the MCAS is to reproduce the "stick feel" of an older 737 at high angles of attack and high thrust.
The MAX is not "fly-by-wire" it has mechanical cable linkages from the stick to the control surfaces, forces are transmitted in both directions which the pilot can literally feel as resistance to control inputs. Boeing inadvertently changed the feeling of the airplane's response to the pilot. An older 737 would present much more resistance to pulling the plane harder into a stall, the MAX has less resistance. MCAS was intended to provide artificial resistance.
Yes, which by intentional design doesn't cover every situation you would encounter with the 737 MAX... because they wanted to make it more similar to the 737 NG. Which, I think we can agree, was a mistake.
That's impressive.
Everyone keeps saying software is the problem, but the real problem is Boeing's willingness to prioritize profits over safety.
I can't, but Boeing can fix things with software and a lot of money. They need to do what they've been unwilling to do, which is go for a new type rating.
I also can't fix the current imbalance between profit and safety within Boeing.
Public confidence in the DC-10 was destroyed after it had a series of related and back-to-back accidents. The plane was relegated to cargo status and Douglas never recovered financially, eventually selling to Boeing.
No, it went back into passenger service and received further orders. American Airlines removed the "DC-10" sticker from the nose and carried on.
I flew on the last commercial passenger service of a DC-10 in 2014.
Say what?
For instance, the fact that the center of thrust is further forward (compared to other 737s) means that the plane pitches up when you give it more throttle. The default response to a stall is to increase the power, which pitches the nose up, which raises the angle of attack, which makes the stall worse. This inherent instability is why the MCAS was added to the MAX.
An airframe is supposed to have a nose down tendencies upon stalling, which would make it recoverable.
The Max may be more prone to stalling, but no one in their right mind would design a commercial airliner which can’t be recovered from stall.
Exactly, which is why the nose-up tendency of the MAX is an issue.
Some airplanes can’t be (reliably) recovered from stall, that’s another issue altogether.
The issue here is MCAS. If they just trained the pilots on the handling characteristics of the MAX the increased stall tendency compared to a normal 737 would be a non-issue and they wouldn't need MCAS as the handling is still within the bounds of "perfectly reasonable".
Also an aerodynamically unstable plane isn't a plane in which a stall is irrecoverable. It's a plane that, left to its own devices, will not make things better for you.
> An aircraft has to be stall proof not stall prone.
The F-117 begs to disagree.
[1]: https://www.npr.org/2019/04/04/709999296/ralph-nader-calls-f...
HN is showing a trend of purely blaming Boeing, but there were in fact several failures. Any one of: pilot training [There's a runaway stabilizer trim procedure that's actually a memory item for 737 pilots], not allowing single sensor inputs for flight control systems [FAA spec failure], the decision to allow the MCAS system to command an extreme amount of trim [engineering failure, should have been limited to a sane value] could have prevented the accidents.
Sure, the sensor needs a redesign and some automation decisions were hot garbage, but 'never fly again' is just FUD.
Are you sure that only that except that MCAS all the other systems are fine and Boeing didn't cheap out on other systems, redesigned other things, other small updates etc? IMO the plane needs to be re-approved, this time for real.