Boeing Knew the AOA Disagree Alert on the 737 Max Didn’t Work
aviationtoday.com
aviationtoday.com
Here's the official release from Boeing that this is just reiterating (from May 5): https://boeing.mediaroom.com/news-releases-statements?item=1...
NYTimes article: https://www.nytimes.com/2019/05/05/business/boeing-737-max-w...
HN discussion of that article: https://news.ycombinator.com/item?id=19835608
"“We were told that if the A.O.A. vane, like on Lion Air, was in a massive difference, we would receive an alert on the ground and therefore not even take off,” said Dennis Tajer, a spokesman for the union representing American Airlines pilots. “That gave us additional confidence in continuing to fly that aircraft.”
But in the last several weeks, Boeing has been saying something different. Mr. Tajer said the company recently told American pilots that the system would not alert pilots about any sensor disagreement until the aircraft is 400 feet above the ground."
i.e. the buck stops somewhere else!
There are a couple of reasons why "the existing functionality was acceptable" is a poor excuse:
- It was present on early models (it was not an optional feature)
- Its triggering indicate to the pilots that something is amiss. Especially after the 1st accident there should have been an association "AOA problems -> potential MCAS problems"
I don't have any information whatsoever to say it happened at Boeing, but saying you were not aware is sometimes not enough.
So all those lives could have been saved and they knew it in 2017? And they let two crashes happen? Explain that to the ones who got left behind...
Unfortunately, it wasn't only used by a small number of pilots, but also by MCAS. It seems that MCAS kicks in during scenarios that weren't originally intended - i.e. take-offs as well as stall scenarios - and they got two other things wrong:
* MCAS was revised to be more aggressive toward the end of testing;
* MCAS has a bug / design flaw that allowed the system to command an increasingly steep nose-down each time a pilot overrode it.
There were lots of little signs all over the place that there was a problem. Unfortunately, they didn't seem to join the dots, and each seemingly-reasonable decision they made when taken together added up to a dangerous scenario.
IMO, there would have been engineers and even some of the management chain who knew these risks, but for whatever reason, would have been pressured to make this go away. It seems like a conspiracist thing to say, but I've seen this in software engineering for years. There are heaps of perfectly legitimate pressures which will result in reduced quality and cutting of corners.. just in my work, lives are not at risk.
At worst it might be plausible that in a very specific scenario some people knew about enough of those dots that they knew it would be a PITA to go back and make everything right, but they almost certainly didn't know about enough of those dots to actually understand the scale of their fuck up there.
In which case I would say it's still a matter of someone not joining the dots, it's just makes them moderately more culpible, then steeply more incompetent the more of those dots they knew about but still didn't flag as problems.
I'd be willing to bet there are engineers who are experiencing a lot of guilt about this right now. Not many.. but maybe even a handful. These are people who might not have been able to do anything about the problem had they realised the true scale of the risk. But I'd guarantee they exist, even if only in a number one can count on one hand.
It's a failing of the company culture where these engineers were not made safe to speak up; a missing facility for those who knew, to get the message to those who would do something about it had they known. It was likely a function of unhealthy (toxic?) company culture which precluded this psychological safety.
I bet these folks feel pretty bad.. maybe even responsible. They won't speak up tho, lest being labelled or even targeted with the full blame. They will suffer in silence, in some ways like the many soldiers ordered to do things they didn't think were right, but did anyway.
A systemic failing like this, combined with the more relaxed attitude the FAA took with them, is probably about as clearly a management failing as they could get. I'd put it as even worse than the VW scandal: at least in that instance there were specific cases of malpractice / collusion.
They were wrong about this of course, but you are suggesting malice while incompetence seems much more likely.
But not knowing this would be an issue in a context like this is the definition of corporate incompetence. And that doesn't make things any better for Boeing.
This is literally mission critical design. You don't walk away from the wreckage shrugging and saying "Who knew?"
It doesn't matter if this was an engineering failure, a management failure, or an accounting failure. What matters is that it was a failure that killed people, and Boeing cannot be trusted to make safe air liners until the failure mode is discovered and eliminated.
Maybe. But it won't be. That's not how corporate engineering works. And there's no appropriate pressure to change this. Boeing have far too much influence over the governing devices that are supposed to apply the healthy pressure which would result in the outcome you describe.
I'd wager that corporate engineering standards are supposed to be a lot more stringent when you're not manufacturing widgets, but objects like buildings, bridges, or commercial airliners.
That they didn't go into introspection mode, being the only entity who could (and should) have known what the potential issue was after the LionAir crash, and didn't move hell and high water to get to the ground of it (and they very obvisously didn't) is pretty much inexcusable.
That they're still smearing the pilots, puts them, in my book, into the scum of the earth category.
There should be a special place in hell for Boeing's senior management.
edit: clarification
Boeing had their very existence and dominance in the aerospace sector severely threatened by A320neo. They needed MAX to be a hit at all costs, and this impetus, combined with the bean counterism their culture was infected with after the McDonnell Douglas merger ensured that any internal obstacles that threatened the time table for MAX would get dealt with in the short term cheapest and minimally effective way possible.
This is gross negligence at a minimum, blatant malfeasance at worst.
It can't incompetence because there will absolutely be engineers and designers who knew of the risks inherent to moving the CG and CoL and the deeper concerns of replacing these risks with a software solution (MCAS) which can relieve a human pilot of control. There is no way any self-respecting engineer with enough design influence would have been ignorant of the potential risks with this design.
It's probably not malice either because people generally aren't evil - especially those building planes which carry humans.
In saying that tho, there was almost certainly a "trade off" decision which was made, and thoroughly justified which traded safety for something else: most likely project delivery schedule. Was this motivated by economic reasons? Who knows. But the trade-off decision which sacrificed safety (even if in largely unknown, distant terms) would have definitely been there and was certainly a conscious decision. IMHO.
They already have an internal whistleblower willing to testify that driving MCAS from a single sensor was a deliberate regulatory hack.
Hanlon's razor only applies when no evidence to the contrary exists. That is not the case here.
See the Austrailian 60 Minustes expose.
Of course, the fact that they kept the aircraft in service without bothering to diagnose the issue that almost got everyone killed on the previous flight is a counterargument in itself. There's more than enough gross negligence to go around in this case, unfortunately.
Edit: actually, it appears that Lion didn't spring for the "optional" warning indicator feature in the first place.
AIUI, there was no "optional warning indicator feature" at all. The AOA disagree warning should have been a standard feature. Only the indicator of the current AOA was the optional feature.
Clear negligence on both sides, with Boeing being responsible at much grander scale.
That (besides any personal penalty that might be appropriate, of course) might realign the incentives for the next set of managers facing similar choices somewhere else, but it won't happen.
By all means I support axing those responsible and criminal charges where/if appropriate, but a company death sentence does not serve the public interest.
More abstractly, if you value human life at a high enough dollar value and make corporations liable for loss thereof, they will expend effort to preserve human life. It appears that currently the externality of killing people is priced at a level where Boeing does not mind killing people.
I don't know if lawsuit liability is the best way to police corporate behavior, but it is big part of the system we currently have in the USA.
Again, I'm not saying they did no wrong. I'm just saying criminal accountability for those responsible is better than corporate death sentences.
Monopolies aren’t capitalist. Monopolies keep putting us in uncomfortable situations like this. There’s a reason we have regulations to keep them from happening (or at least break them apart post facto) even if we choose not to use them.
If saving those jobs is the goal, we should work towards that instead of saving the company in hopes that this will also save jobs.
[citation needed]
https://www.quora.com/How-many-plane-crashes-does-Boeing-hav...
With the exception of the MD-11, there is no statistically significant safety record difference between jet transports put into service since 1980, Airbus and Boeing included.
On a side note check a lot of large companies today, corporate debt has gone crazy due to buybacks. They’ve converted any stockholder equity remaining into debt, especially after tax cuts and low interest rates. In a bankruptcy, bond holders get paid first.
Passive investment and Fed also plays part. Joe 401k and systemic index tracking leads to no public awareness of companies financial health. Buy no matter what the largest cap stocks in proportion to size. Fed is completely aware of all this. Interest rates must never rise otherwise everything seizes. December’s reaction was just that.
[1] https://www.spiegel.de/international/business/suspicions-of-...
If you can't do what you set out to do without being grossly negligent, or resorting to bribery, then perhaps you shouldn't be doing what you are at all.
Businesses seem to have forgotten they are not money pumps first and foremost. They are there to do a job, and are currently failing epically at doing so in an ethical manner.
I'd put down a corporation like I'd put down a dog should it show a tendency for wanton destruction and bloodshed..
The difference, however, is that you can hardly acuse them of mass murder for corporate greed and profit.
And that's exactly what Boeing management did after the Lion Air crash. They knew, or must have known, that they're selling a potential death trap and did exactly shit about it (except promising a fix, delivered eventually, which should compensate for "incompetent pilots").
Look up whataboutism. Because your argument is quite a perfect example.
Would it be correct to say that your suggestion stems from a general dislike of corporations, rather than from the circumstances of this particular case?
I want to point out that I don't want everyone working for Boeing out of a job, I want people that invested in Boeing to lose that investment (so that other boards in the future are incentivized to hold other management teams accountable) and to erase the obviously dangerous safety culture that currently exists in the company. I'm sure that their employees and assets could be useful for their competitors.
The FAA confirmed the discussion and that it deemed the issue "low risk" at the time.>
So the FAA is culpable as well as Boeing
If you accept this, then the question might turn to how it was possible for the FAA to be weakened to such a degree that this corporate influence was possible. FAA are the regulator - at the end of the day, safety lies with them. Perhaps it's the responsibility of committee and congressional oversight to the aviation regulator? Perhaps the buck stops with the government representatives who have allowed this mess to be possible in the first place?
Ironically, however, Europe has called the FAA to task before on several models of Boeing aircraft that weren't implicitly design safe. See the D.P. Davies Interview w.r.t the Boeing 727 certification process.
They cut corners, and did not inform pilots of the inherent risk that existed in a manner concomitant with the severity of the result. This originated in a desire to submit an aerodynamically deviant aircraft, yet attain type airworthyness certification with minimal friction.
Lion Air may be last in safely operating aircraft, but the design standards were generally written in such a way where even the worst operators stood a good chance of going up, and getting back down free of harm.
Obviously, that is no longer the case.
And if this can be traced to someone with influence, how was it possible for the company to be structured so that a single point of failure was possible - that speaks to a larger problem and then puts the senior exec on the chopping block too.
The critical jump pilots had to make was that this was a trim runaway event. AOA indicators were not connected to the trim system before.
Unless you change it to "It’s certain the AOA disagree light would not have saved the two flights", you are basically arguing for presence of AOA disagree light.
In this case I agree with the FAA's initial decision for this indicator. Its extremely unlikely having it working would have prevented the two crashes. The mere fact that it might have helped doesn't make the original decision incorrect.