Boeing Admits It Knew of a Faulty Safety Alert in 737 Max
digit.fyi
digit.fyi
I suppose this is just a mashup of previous articles published in newspapers, which were all discussed here. The WSJ was the first to reveal (11 days ago) that Boeing knew for a whole year that the alert device was faulty[1]. CNBC added some details[2]. A NYT link was published here and much commented[3], where a comment pointed to the official Boeing statement[4].
[1]: WSJ https://news.ycombinator.com/item?id=19772220
[2]: CNBC https://news.ycombinator.com/item?id=19780032
[3]: NYT https://news.ycombinator.com/item?id=19835608
[4]: Boeing https://news.ycombinator.com/item?id=19835901
[edit: typo]
Why is this such a common way to handle these situations?
Sure, its a nice sum of money, but I think most CEOs still prefer not having the money and the scandal not happening. That is not to say that current repercussions are enough, just that it is currently not net beneficial to have a scandal. Notably, with the current low levels of repercussions, it might still be net beneficial to risk a scandal though.
EDIT: To elaborate, getting ahead of an unfolding story is difficult even for experienced PR people. One misplaced word may be taken out of context or even used as admission of guilt in an ongoing investigation. This is generally why PR folks default to true generalities, e.g. "we care about our customers' safety" or "what happened is terrible and should be prevented from happening again".
My knowledge of PR is limited to the book "When the Headline Is You" which I highly recommend. It gives a great perspective on how companies manage themselves in the public light.
When it comes to disclosing hacks, standard practice is to disclose a small hack first then disclose that the hack was "worse than previously thought".
Examples:
https://www.slashgear.com/outlook-com-hacks-is-worse-than-mi...
https://news.vice.com/en_us/article/a3pqqb/the-facebook-hack...
https://www.scmp.com/news/hong-kong/law-and-crime/article/21...
https://www.theregister.co.uk/2018/02/13/equifax_security_br...
https://www.trustedreviews.com/news/ba-hack-investigation-36...
This comes to mind as an example of how things might have gone differently for Boeing if they'd handled this better: https://www.ou.edu/deptcomm/dodjcc/groups/02C2/Johnson%20&%2...
Even though there are two sensors, the signal from the faulty sensor was used. (Why no comparison checks or consensus checks?)
Also, there was no limit on how far the MCAS could move the stabilizer. MCAS was limited to 2.5 degrees of change 'per cycle' but each time a pilot tried to pull up the nose, MCAS reset enabling another 2.5 degree of movement. Ultimately the stabilizer was pinned in the max-down position.
Boeing and perhaps the FAA let the software into the field but it was bad/lazy software engineers that killed people.
Like all 737s, the MAX actually has two of the sensors, one on each side of the fuselage near the cockpit. But the MCAS was designed to take a reading from only one of them.
Lemme said Boeing could have designed the system to compare the readings from the two vanes, which would have indicated if one of them was way off.
Alternatively, the system could have been designed to check that the angle-of-attack reading was accurate while the plane was taxiing on the ground before takeoff, when the angle of attack should read zero.
“They could have designed a two-channel system. Or they could have tested the value of angle of attack on the ground,” said Lemme. “I don’t know why they didn’t.”
The black box data provided in the preliminary investigation report shows that readings from the two sensors differed by some 20 degrees not only throughout the flight but also while the airplane taxied on the ground before takeoff.
https://www.seattletimes.com/business/boeing-aerospace/faile...
Which begs the question of who signed off on the acceptance tests.
It's highly likely that no one jail-able person (you can't jail a corporate entity) had enough information and knowledge of the situation to meet the criteria of criminal negligence. Nobody knows the full picture. That's just the nature of building a large system like this. I know what my code does. I have a pretty good idea of how it affects the whole system. I can reason able what edge cases I don't know about might cause my portion of the system to do. I can't (with any reasonable degree of confidence) reason about the end result of that edge case being fed through the entire system.
Even this story manages to confuse the people responsible with the company where they work. It says "Boeing didn't know the feature was optional." What a crock. Surely someone knew, like the person who decided to make it optional, for starters!
That's the cornerstone of the American justice system, yes.
If calculated risks by coorperations regarinding safety come down on the less risky side, that is a good thing.