So all those lives could have been saved and they knew it in 2017? And they let two crashes happen? Explain that to the ones who got left behind...
So all those lives could have been saved and they knew it in 2017? And they let two crashes happen? Explain that to the ones who got left behind...
Unfortunately, it wasn't only used by a small number of pilots, but also by MCAS. It seems that MCAS kicks in during scenarios that weren't originally intended - i.e. take-offs as well as stall scenarios - and they got two other things wrong:
* MCAS was revised to be more aggressive toward the end of testing;
* MCAS has a bug / design flaw that allowed the system to command an increasingly steep nose-down each time a pilot overrode it.
There were lots of little signs all over the place that there was a problem. Unfortunately, they didn't seem to join the dots, and each seemingly-reasonable decision they made when taken together added up to a dangerous scenario.
IMO, there would have been engineers and even some of the management chain who knew these risks, but for whatever reason, would have been pressured to make this go away. It seems like a conspiracist thing to say, but I've seen this in software engineering for years. There are heaps of perfectly legitimate pressures which will result in reduced quality and cutting of corners.. just in my work, lives are not at risk.
At worst it might be plausible that in a very specific scenario some people knew about enough of those dots that they knew it would be a PITA to go back and make everything right, but they almost certainly didn't know about enough of those dots to actually understand the scale of their fuck up there.
In which case I would say it's still a matter of someone not joining the dots, it's just makes them moderately more culpible, then steeply more incompetent the more of those dots they knew about but still didn't flag as problems.
I'd be willing to bet there are engineers who are experiencing a lot of guilt about this right now. Not many.. but maybe even a handful. These are people who might not have been able to do anything about the problem had they realised the true scale of the risk. But I'd guarantee they exist, even if only in a number one can count on one hand.
It's a failing of the company culture where these engineers were not made safe to speak up; a missing facility for those who knew, to get the message to those who would do something about it had they known. It was likely a function of unhealthy (toxic?) company culture which precluded this psychological safety.
I bet these folks feel pretty bad.. maybe even responsible. They won't speak up tho, lest being labelled or even targeted with the full blame. They will suffer in silence, in some ways like the many soldiers ordered to do things they didn't think were right, but did anyway.
A systemic failing like this, combined with the more relaxed attitude the FAA took with them, is probably about as clearly a management failing as they could get. I'd put it as even worse than the VW scandal: at least in that instance there were specific cases of malpractice / collusion.
They were wrong about this of course, but you are suggesting malice while incompetence seems much more likely.
But not knowing this would be an issue in a context like this is the definition of corporate incompetence. And that doesn't make things any better for Boeing.
This is literally mission critical design. You don't walk away from the wreckage shrugging and saying "Who knew?"
It doesn't matter if this was an engineering failure, a management failure, or an accounting failure. What matters is that it was a failure that killed people, and Boeing cannot be trusted to make safe air liners until the failure mode is discovered and eliminated.
Maybe. But it won't be. That's not how corporate engineering works. And there's no appropriate pressure to change this. Boeing have far too much influence over the governing devices that are supposed to apply the healthy pressure which would result in the outcome you describe.
I'd wager that corporate engineering standards are supposed to be a lot more stringent when you're not manufacturing widgets, but objects like buildings, bridges, or commercial airliners.
That they didn't go into introspection mode, being the only entity who could (and should) have known what the potential issue was after the LionAir crash, and didn't move hell and high water to get to the ground of it (and they very obvisously didn't) is pretty much inexcusable.
That they're still smearing the pilots, puts them, in my book, into the scum of the earth category.
There should be a special place in hell for Boeing's senior management.
edit: clarification
Boeing had their very existence and dominance in the aerospace sector severely threatened by A320neo. They needed MAX to be a hit at all costs, and this impetus, combined with the bean counterism their culture was infected with after the McDonnell Douglas merger ensured that any internal obstacles that threatened the time table for MAX would get dealt with in the short term cheapest and minimally effective way possible.
This is gross negligence at a minimum, blatant malfeasance at worst.
It can't incompetence because there will absolutely be engineers and designers who knew of the risks inherent to moving the CG and CoL and the deeper concerns of replacing these risks with a software solution (MCAS) which can relieve a human pilot of control. There is no way any self-respecting engineer with enough design influence would have been ignorant of the potential risks with this design.
It's probably not malice either because people generally aren't evil - especially those building planes which carry humans.
In saying that tho, there was almost certainly a "trade off" decision which was made, and thoroughly justified which traded safety for something else: most likely project delivery schedule. Was this motivated by economic reasons? Who knows. But the trade-off decision which sacrificed safety (even if in largely unknown, distant terms) would have definitely been there and was certainly a conscious decision. IMHO.
They already have an internal whistleblower willing to testify that driving MCAS from a single sensor was a deliberate regulatory hack.
Hanlon's razor only applies when no evidence to the contrary exists. That is not the case here.
See the Austrailian 60 Minustes expose.