Boeing employee: I would not put my family on a Max plane
mynorthwest.com
mynorthwest.com
[0] - https://en.m.wikipedia.org/wiki/De_Havilland_Canada_Dash_8
That's because most people these days have significant hearing loss.
Not sure if academic curiosity or Marketing guy looking for a lead...
I need a break from my cynical side.
If nothing else, now I’m glaringly aware that Southwest and AA are the primary U.S. carriers that fly Max’s. Chances are it would at least be a passing thought if either had a good option on a metasearch site.
As if they have to do it before buying their ticket.
It's hard to measure the impact of sentiment alone since they grounded the places pretty quickly and numbers are reported quarterly, but its very likely we would have seen travelers choosing airlines that don't fly the Max 8.
[1] https://www.peoplesworld.org/article/flight-attendants-union...
I am sure way more than 1% of the population cares if they fly on this plane.
The fact that they got this quote from an employee in their sample size of "people we talked to" is notable, IMO. Not a sign that the sky is falling, but notable.
Edit: The alternate scenario in which one of the 150k employees actually reached out to a journalist of their own violation is notable too! If they felt strongly enough to actually contact the press, then something is wrong.
Depending on the journalists' circle of friends, or friends' friends, or source pool, I'd imagine it'd be pretty hard to have all the Boeing employees you know all toe the company line, in a manner similar to the Birthday Paradox.
If you're going to call out a misrepresentation then maybe don't do it yourself? He didn't say he "doesn't know" if he would do that. He said "No. Not in a million years."
The reporting from myNorthwest is pretty shoddy, it's mostly a right-wing digital tabloid run by a talk radio station. Equivalent to the NY Post.
I would really hope that airplanes are a place where "dirty hacks" are unacceptable.
This doesn't mean they are 100% flawless, but any known potential problem areas should be well-documented and accounted for.
https://www.latimes.com/local/california/la-fi-boeing-max-de...
The airframe should be retired and they should make a new one. To push this, the FAA and other certifying bodies should treat the plane as an all-new plane with no commonality with previous 737 planes, requiring all new training for pilots and a complete, new certification process for the plane, just as if it had been a clean-sheet new design.
Airbus pilots can't safely fly their jets at cruising speed without software (envelope protection, etc) assisting them. Air France 447 crashed, killing 228 people, when that software became disabled due to bad values from frozen sensors. The pilot flying thought the software would save him from stalling but that protection was disabled, so he crashed into the ocean.
So does that mean it's a bad idea to make flight software safety critical? Probably not.
It probably just means that safety critical software must be extremely good. MCAS v1 was not good software but if MCAS v2 is good software then it could might function safely for decades. And, if MCAS v1 had been good, it would have been lauded as a great solution.
Engineering is about trade offs and maybe Boeing made the wrong trade off here. Ideally, you would have as little safety critical software as possible. But the fundamental concept of software correcting for flight characteristics seems entirely sound.
Second System Syndrome is a well known engineering pitfall. If the only thing wrong with the 737 MAX is that the MCAS v1 software is bad, and the MCAS v2 software is good, then the 737 MAX should fly perfectly well for decades.
Boeing historically built planes flown by pilots. Every aspect of the planes behavior had a way for the pilot to control it. A Boeing plane would follow a pilot right out of the flight envelope, at least maintaining a 1:1 binding of pilot intent to plane output behavior.
Airbus makes planes flown by automation, directed by pilots, that should that automation fail, requires a significant investment of skill maintenance to know what not to do at that time. This makes common UI for the pilot easier to implement, but comes with discipline degradation through having a computer that will largely ignore your daft commands until it suddenly has no way to measure your daftness, leaving you with a plane with a hodgepodge of reliable automation to reason through about whether or not the plane will do something daft if you order it to.
History may show who won that argument, (Airbus does exist), but the fact does remain today that aircraft that one wants to certify as flying just like another aircraft (MAX flying like a 737) should actually do so. The MAX doesn't; the technological fix intended to make it so was not developed to a sufficient standard of rigor, or communicated to pilot clearly enough, to transparently account for that aerodynamic divergence.
The problem is multi-faceted, yes; but the statement that the MAX suffered from a fundamental design flaw is absolutely accurate.
The flaw exists aerodynamically, and in the fundamental engineering process through which it was certified.
[1]https://www.aerosociety.com/news/audio-the-d-p-davies-interv...
But my understanding is that other jets have a similar pitch up characteristics and no one considers them to be fundamentally flawed. That the 737 MAX design creates a new problem vs the 737-NG does not necessarily mean it's fundamentally flawed.
I'd only consider it a fundamental flaw if MCAS can't actually be designed to compensate for the problem. An unsolvable problem due to bad design = fundamental flaw.
Otherwise having to stick a windshield on the front of an airplane could be considered a fundamental flaw. But it's not considered one because of very strong laminated materials compensating for the the problem. And yet it's still a huge potential risk. Windshields have cracked, broken, clouded up, etc.
MAX, however, has additional problems where its flyability is adversely impacted when flying at high Angles of Attack when the engine nacelles (positioned higher and in front of the wing) creates extra lift in front of the center of mass of the aircraft. This creates divergences from the normal "control feel" of the older aircraft.
When at low power, and high AoA, (such as might be experienced on descent), sudden applications of power can cause pitch up, which can put the plane at an AoA that experiences this handling divergence. MCAS, in it's second form, was intended to induce a controlled mistrim to compensate for both it's original purpose (high speed, high AoA divergence from 737 NG handling), and a low speed, high AoA handling divergence.
It was being modified to handle the low speed case that removed an extra G-Load based cross check, and greatly increased the authority the MCAS system commanded, due to the larger deflections required to induce attitude changes in the low speed portions of the flight envelope.
The fundamental flaw I mention, is several fold.
Requirementswise:
A)The MAX had to be developed yesterday to allow Boeing to maintain dominance/market share in narrow body civil transport against the A320neo. (They needed it fast)
B) It had to be cheap. They needed minimum overhead cost to appease airlines, and comparable fuel efficiency to the A320neo. This meant no blank slate redesign. This locked them into the 737 type cert.
This meant (to an engineer):
C) It had to fly exactly like a 737... Without being one (They need it to be right).
In engineering, there is a common saying:
You can get it done cheap You can get it done fast. You can get [everything you want] done right).
Pick two.
For success, they needed all three, and delivering the third was not allowed the flexibility to intrude on either of the other points of the triad areas of process.
The only way this project could have ended was with a breakdown somewhere in the process. That breakdown was in communication and propagation of the significance of the aerodynamics change. That failure in communication was bundled in the "fast and cheap" directive. The "right" directive required the aerodynamics divergence, and the software control system reconfiguration to compensate for it. The cheap and fast also required that the software solution not be driven by a dual sensor system, as that wouldn't have been allowed through without simulator training by the FAA, as testified to by a whistleblower as reported in the Australian 60 minutes expose.
The whole thing is just a Greek tragedy in an engineering project's clothing. Hubris, greed, equivocation, catastrophe... It's all there.
I'm still not yet aware of any reason that they won't be able to eventually make the MAX design safe and functional.
It's a very interesting example of engineering/business dynamics. I'll be happy whether the MAX flies successfully or gets totally scrapped, as long as no one else dies in a MAX from negligence.
And before anyone says "hurr durr it pitches up" (or something like that) the amount it pitches up when wide open at low speed is perfectly fine from a performance standpoint but it is not similar enough to the old plane to get away without retraining pilots, hence the software.
The device has been performing admirably (as far as I know) for over 12 years in the field with no issues due to those few lines of code.
Hacks are everywhere in engineering. As long as the analysis behind it is rigorous and the hack is provably correct, I'm OK with it.
You understood exactly what was going on and were wholly confident it would be reliable. And more to the point, you wouldn't have counted it as a mark against the product's reliability.
A hack could be completely reliable (for the same hardware, library versions, and compiler), but still be a "dirty hack". And whether a hack is "dirty" is very subjective and, IMO, based more on how obvious the fix is (e.g. radians -> degrees -> function -> back to radians because the library documentation is wrong is less bad than a non-obvious hack like multiplying by 1 or something to avoid a compiler codegen bug because of a hardware bug).
I think this horse has been thoroughly beaten, so I'll leave it here.
I used to code for Medical Devices. One of the rules of thumb we used for our level of comfort with a design (apart from formal Failure Analysis, etc...) was whether or not we'd be OK with having it used on one of our kids.
When you review someone's code (or mechanical design, or electronics) and you have to decide if you're OK with it being used to treat or diagnose your loved ones, it forces you to confront the immediate reality of the impact of your work. Suddenly that hack might not seem like such a good idea after all.
The same could be said about 1940s German "racial scientists", who had years of training convincing themselves about the genetic superiority of their people and the dangers coming from the "Jewish race".
I guess most shiny things of any reasonable complexity look pretty dirty from the inside. There is just no way around it.
Knowing how the airplanes are designed and built made me a much less anxious flyer.
But I totally agree, and I do not think you're wrong..
It wasn't a remark on the aircraft, it was a remark on how Boeing's employees are feeling right now.
If you read beyond the first two paragraphs the context is clear.
I agree that just one employee opinion it's not important or so relevant by itself.
But, for most people, a human face for a problem makes the problem easier to understand and to sympathize with the situation. So, it seems that the journalist decided to give voice to Stuart as an stylistic choice. HN readers may like or not this choice. But, it does not invalidate the content of the article.
An example does not invalidate the rule. It would be interesting to discuss the content more than the style, even that it's also a valid discussion.
My take out of the article is that lack of trust on upper management is part of the problem.
> “I want to think that I work for one of the best companies in the world. I want to think that when I come home from a 10-12 hour shift that I’ve done something good. But I don’t know because I see the lies. They’re going back on everything that they’ve told us. So it’s really difficult for me to feel good about any of it.”
Most people see themselves as good persons. Most people wants to do a good job. When your company leadership fails you there is a conflict between that believe and reality. That is why company leadership is so important and it should not only respond to share holders but to all stakeholders in the company including customers and employees.
- Interviewing one person with the necessary data and analysis to backup a certain conclusion. This would be a consultation with the Subject Matter Expert. Opinions backed by data. E.g interview with climate scientist on the impact of global warming
- Interviewing one or more people to put a face to a story. It has the effect of humanising an issue. To be viewed critically and with the realisation that it’s an emotional appeal. To be used to inform yourself only if it’s backed by data in another way/form
These two are not the same when it comes to making informed opinions.
Companies that only care about shareholder value run the risk of becoming parasites preying on society, looking for any way to extract value from society.
A healthy company should balance the needs of their shareholders, their employees, their customers, and society at large. Only if you balance those 4 concerns can you have a healthy, sustainable business that's a boon to society rather than a bane.
[0] Example: https://www.forbes.com/sites/stevedenning/2017/07/17/making-...
Current aircraft and flying is very safe. Even with the recent 737 fiascos, flying those is by far safer than driving to work. If I am OK with taking a road trip on vacation I am OK with flying Max.
This is not to say that improvements, re-certification and additional pilot training are bad. But from a purely practical point of view (which I try to practice for routine decisions), if we want to improve safety, there are better areas to spend $$ and / or hours than on endless re-polishing of a system that is super safe already. Life is dangerous; estimate your micro-deaths and extract most utility and fun from each of our 1e6 microlifes. My 2c.
I can't find the numbers easily right now, but I'd really like to see "deaths / person-hours flown on a 737 Max" vs. "deaths / person-hours driven".
Besides, when people describe flying as "safer than driving", the implication is that you're more likely to end up dying one way than the other. So any measure of "deaths per x" (x is miles, hours, or whatever) needs to be followed with "typical x per lifetime".
The U.S. motor vehicle accident rate is about 1.2 fatalities per 100,000,000 vehicle miles travelled. Figure a car's average speed is 30mph so 1.2 fatalities per 3.3 million hours = 0.36 fatalities per million hours. Therefore on an hourly basis, the 737MAX is very roughly 5x more dangerous than driving. OTOH the 737MAX averages about 400mph, so per mile it's probably something like 2-3x safer.
If you’re over 10K feet in the air there is some room for recovery procedures, but if you haven’t reached cruising altitude you have much less time before a plane finds itself impacting the ground.
Per-mile travelled isn’t an adequate standard to compare aircraft with other modes of transit when talking about safety.
Scrolling with my mouse is super safe – a system that can crash you into the ground at 500+mph and that relies on single (possibly faulty) sensor is not super safe.
Great, so they've managed to convince people this was a software problem...
The 737 Max doesn't even have enough physical sensors to supply the software with enough data to conduct true voting logic (something typically found on "safety critical" systems). The spec also didn't even have the software use both sensors it did have to detect defective inputs.
The aircraft design was faulty before even one line of code was written. This wasn't a software bug. It wasn't a software design defect. The actual specifications and the physical design of the aircraft itself were flawed, and software was poorly used to plug the gaps.
And its not really an aerodynamic issue either.
Boeing have a massive procedural issue where they didn't do proper safety analysis of how the system works as a whole. The fact that they didn't identify this failure case as a major issue makes you wonder what other failure cases (on other planes too) that they missed.
The original version of MCAS only moved the stablizer by 0.6 degrees, and only in situations with high angles of attack AND abnormally high g loading. That's the version they ran the safety analysis on, it relies on two types of sensors that shouldn't fail simultaneously. Later they modified MCAS to move the stablizer by much larger amounts (2.6 degrees, 4x larger) and they removed the high g loading restriction so it would operate in more situations. This also means it was now relying on a second sensor.
And they never re-ran the safety analysis.
I think the issue Boeing has now is credibility, and the idea that there may be other MCAS-type issues lurking.
> we were told certain things such as ‘the companies that bought these planes, a lot of them, their countries didn’t require them to go through the test flight process that needed to happen.’ So we were told, ‘Hey, that’s not on us, that’s on them. We have this program, they’re suppose to take it, they don’t have to take it, that teaches them how to use this thing.’”
To me (as a layperson), it seems pretty obvious that Boeing specifically didn't mention MCAS in the flight crew operations manual because it would have meant extra training/certifications to fly the MAX, and there is a pretty clear profit motive to avoid that. By attempting to weasel out of this by saying things like "a pilot should never see the operation of MCAS in normal flying conditions" and "not a separate system to be trained on" [1], as well as the above paraphrasing, it doesn't exactly inspire confidence that Boeing is really putting passenger safety above all else, which is what I as a non-stockholding potential passenger would prefer.
[1] https://en.wikipedia.org/wiki/Maneuvering_Characteristics_Au...
Yes, because it's difficult to recover when MCAS goes wrong, even when you know about it. The pilots of Ethiopian 302 turned MCAS off and still crashed[0].
https://www.seattletimes.com/business/boeing-aerospace/boein...
At low altitude, even with full knowledge, MCAS can make the aircraft unrecoverable. Aircraft should not fly without it being corrected. The Ethiopian crew maybe have had knowledge of MCAS.
Wouldn’t you have said that after the first MAX crash? I mean if you’re a pilot and a 737 crashes, wouldn’t you be ALL OVER every detail of that crash?
All the engineers in the world can't stop a bunch of executives capable of creating an environment so full of confusion, second guessing, and clouded communication capable of allowing these types of tragedies to occur.
The mechanics of the problem laid bare were simple. The problem ended up being the levels of obfuscation and lack of coordination/miscommunication surrounding the certification process that allowed the aircraft to be certified and flown with a clearly uncategorized avionics system, and insufficient communications to pilot's that in the end could have negated the technical need for a more robust system, if they'd only known to look out for it..
You can talk all you want about how regulators should have required recertification, how Boeing shouldn't have just strapped a couple of higher bypass ratio engines onto the bottom of a 737 in the first place, or how it information about MCAS should have been presented.... but in the end, it's possible there would not have been accidents (or maybe more of them because of unexpected stalls, we'll never know) if there had been sanity checking of response values from either of the AoA sensors and if MCAS capped how many times it could trim.
edit: it sucks to work on critical systems. In case it comes off differently, I feel badly for those involved. Nobody gives them credit thousands (more?) times a year an automatic flight control system engages and saves hundreds of lives without any passengers knowing. They ended up making MCAS because of decisions made outside of the realm of their control.
Watch the Australian 60 Minutes Expose on the MAX. A whistleblower has come forward and stated that they had to pipe in only a single sensor's input to avoid costly simulator training, which management pushed as an absolute necessity to avoid.
I love Engineering. I love doing things right. I can't deny though that when you've got business breathing down your back, everyone seems more interested in getting what they want instead of what actually solves the problem in a sound way, that things never degenerate to the point where the engineering teams throw up their hands and say "Eff it! Take your plane and choke on it!"
This is a textbook case of toxic engineering culture yielding toxic engineered product. Richard Feynman said it best after the Challenger disaster, and his words ring as true now as they did back then.
"For a successful technology, reality must take precedence over public [or customer] relations, for Nature cannot be fooled."
Since they happened halfway around the world, it seems like we judge it differently?
This is a huge management mistake. Teams need a direction, consistency, and time to execute. During that time managers often need to keep things on track and keep up team morale, but also need to know that they have to step back and be more passive while the team is executing. Constantly changing things means the teams are distracted, probably a little frightened, and not operating where they could be.
Who would? Surely some people like to risk but why would you take such a risk when there are so many safer options(i.e airbus)?
So plenty of executives lack such qualms.
(I think we later learned the simulators are buggy around MCAS, but his intentions were in the right place...)
As for choosing: Almost every single time I fly there is zero choice of plane if you fix the departure and arrival city, date, and approximate time. In the cases where there are multiple airlines it’s not uncommon to see late plane changes.
Especially between 737-800 and MAX8 because they are commonly operated by the same carriers and the swap is simple from a seating perspective.
Why should we listen to Stuart? They don't list his job, so he could be just about anyone.
Most Boeing jets that you can book a flight on today are some of the safest the world has ever seen. For example, the 777 has been in service 25 years with only a few serious accidents we can conclusively say are related to the aircraft design or operation. The 737-NG (precursor to the MAX and also in service ~25 years) experiences one hull loss incident for every 4 million or so departures. Even their other fairly new jet, the 787, has never experienced a hull loss or fatality in almost 8 years of commercial service.
Its one thing when the system offers assistance but when it takes over to the degree you cannot fix it and lives are in danger it needs to be reworked
The engines push the cog forward which causes more lift at high thrust. This is not an airframe issue but a loading issue. FAA requires load limits and practical methods to check and resolve loading issues. Let me pause here. We can simulate the 737MaX design by taking an older 737, filling with 1/4 passengers and load them all in the front of the plane. Tada we have a forward cog scenario. Could the plane fly? Sure but the plane will want to nose up more than usual. What does the flight manual say? Reseat passengers to fix cog over limits, or limit throttle inputs if not over limit. So would a properly designed MCAS system solve this problem? Yes. But Boeing didn’t properly design MCAS the second time around.