FAA Finds New Risk on 737 Max, Orders Boeing to Make Changes
bloomberg.com
bloomberg.com
The FAA can't afford another stuff up this second time around and as such I suspect they will be checking every aspect of the plane in very fine detail.
That could spell more trouble for Boeing.
It was that they found similar behavior happening in a low-speed part of the flight envelope. That required increasing the authority and losing the G-load safeguard.
In other words they thru all engineers principals out the window.
Now there is no doubt this is exactly what happened.
But the bigger question is why did this happen and why was it allowed to happen?
Boeing somehow tricked the FAA into believing, from the pilots perspective the 737-MAX and 737 were the exact same plane.
That allowed the plane to enter service quickly as it meant the pilots would not require any flight simulator retraining.
What we now know is the 737-MAX is nothing like the 737 and the level of deception that seems to have occurred is concerning.
Whether it was intentional to meet the schedule or accidental, we may never know.
For one thing, if you bring up any questions regarding an issue at all, the preferred medium of communicating it until a decision is made tends to be direct person to person with no electronic paper trail. (This insulates the company from getting caught out by E-Discovery in case of legal troubles).
Secondly, there's the practice I call anchoring. This is where you go to the regulator with a very narrow, refined question looking for an answer, explain why you think it's a good idea, and hope they don't think too much into it before saying yes you can do it. If it works, you have a document stating the regulator told you it was okay when you asked. To prevent this, you have to go to your regulator and give them a high and wide view.
A) What is the problem B) What are the relevant regulations impacted C) What additional risks are created with both answers
Businesses can be a bit squirmy when engineering folks start getting too chummy with compliance. I know I've found a good one when I don't get funny looks when asking if something questionable sounding has been run passed Compliance.
Everything I've read in this investigation reeks of anchoring toward the FAA. Especially given the whistleblower testimony as reported in the 60 Minutes Expose on the MAX.
[1]https://m.youtube.com/watch%3Fv%3DaO7_indbfME&ved=2ahUKEwje2...
I'm not at all amazed by Boeing's blatant deception and blame shifting. They've done this before, and with this same model of aircraft. https://en.wikipedia.org/wiki/Boeing_737_rudder_issues
A corporation is not a person and punishment isn't always the answer, but we are looking at a lot of deaths and this new issue sounds like it could have caused even more. If the FAA had missed this one we could have been looking at another crash. Maybe putting Boeing out of business would serve as a cautionary tale to the remaining companies in this space that they should be making more conservative choices when it comes to development of a product that has the potential to injure or kill such a large number of people.
As it is, I'm not sure what the moral of this story is for Boeing. Is it that the company is "too big to fail"? It is that they need to tough out the bad press to really be successful?
I worry that maybe it's something along the lines of "you have to crack a few eggs to make an omelette."
What could happen (but still unlikely) is that those within the company who made the decisions that led to the deaths of 300 people could be held to account in a court of law.
Sorry, I laughed. That will never happen. Boeing may go under, but those rich bastards will always be able to stay out of jail. Name me one exec of a plane manufacturing company that has gone to jail over a crash. There aren't any.
Yeah, right. Until they start cutting corners again for economic reasons. There's absolutely no change in any of those organizations driven by this incident or by an increase in standards or by safety, there are no new regulations, it's all a dog and pony show driven by money and saving their asses.
"if you look at the history of aviation improvements this isn't the first and it won't be the last time"
And that's a great argument for just letting the next horrible accident happen in a few years. Until people start demanding that at least the goal of those organizations should be Total and Complete Flight Safety, the FAA and Boeing will cut corners because "accidents will always happen, this isn't the first and it won't be the last, so who cares". Accidents will stay a calculated risk for them, in stead of something that just should never ever happen.
How fast do you think this stuff can happen?
>And that's a great argument for just letting the next horrible accident happen in a few years.
The next horrible accident is going to happen in a few years, sorry to tell you.
>Accidents will stay a calculated risk for them, in stead of something that just should never ever happen.
I'm going to assume you're no engineer.
I'm pretty sure what you're trying to get across is that Engineering is the business of enabling the taking of calculated risks, but you're doing it in a needlessly inflammatory way.
And the poster you're responding to isn't necessarily wrong either. Just because engineering allows us to identify, analyze, and calculate the impact of risks does not free us of an obligation to always favor the most conservative approach in living up to the obligation to comport ourselves in a manner consistent with serving the Public interest.
Remember the Iron Ring in all things.
Above I posted a seven year old documentary about the 787 Dreamliner, and there were the same problems of Boeing doing the FAA's work. So to answer your question: I don't really know, but it seems to be decades at least before anything changes, if at all. And that's really appalling.
>I'm going to assume you're no engineer.
I am, actually.
As an engineer you can calculate a risk like: this part under this type of load will fail at x, and then design so that x is never reached (or in a million years or so) to make a design safe.
A manager can calculate risk like: if we sell 5k planes, and we can make them $1000 cheaper by using a part that will increase the likelihood of a crash by only 2%, since the chance of a crash is already very very low, we might as well use the inferior part and make $5m extra. That way I can buy that third mansion I want.
Both are calculating risk. The engineer calculates for safety, the manager for his stock options. Which do you think is better?
My point is, the goal should always be complete safety. Even though engineers know that that is impossible, and even though lots of managers don't care at all about safety. We should still strive for it. Total flight safety should be the goal, not a byproduct of good engineering.
That's why we have the FAA in the first place, because we don't trust those managers at Boeing to make the right decisions, because experience learned us we shouldn't.
We trusted on the FAA and Boeing to hold that goal of passenger safety to the highest standards, but they betrayed that trust completely by letting Boeing do the FAA's work! Isn't that completely bonkers? Perhaps we just should scrap the FAA as well and let the Europeans certify all planes. I don't know. But right now there's nothing but ass-saving going on, and that doesn't restore trust in either of those organizations.
Lot's of people should be going to jail for this, but they wont, because they're rich and can buy their way out. Everybody knows this. That's the way the United States works. Justice is only for the rich and powerful. That's how Boeing can kill 300+ people and get away with it. As an engineer, this worries me greatly.
If upper layers "solve" it by hiring less competent people, then that is something on their conscience.
When the problem is at the top, just bearing with it at the bottom will not help at all. Even if you manage to save lives, you virtually sacrifice your own.
Because I'll just check with the next air transit regulatory body right?
[1] feel free to flip flop regulatory agencies if you so desire.
A question for the arm-chair analysts in this thread: which one has a better history of not being wrong, excluding this data point?
This agreement only works as long as both parties trust each other's certification process.
0: https://www.easa.europa.eu/document-library/bilateral-agreem...
Personally I'd be happiest if the world just scrapped all the Max-es. Just scrap 'em, let Boeing go out of business, it's what they deserve now, they shouldn't exist anymore as a company. There are enough businesses that happily create planes without putting profit before people.
It's really too bad that there's no footage of either of the crashes, because if people could see what happened they would never fly one of those things again. That's why people don't fly zeppelins anymore. Not because of what people said or read, but because they saw. The Max deserves the same.
Do you want to fly in a plane which was created using the deaths of over 300 people to finalize the design?
[0] The Boeing 787: Broken Dreams, Al Jazeera Investigations, https://www.youtube.com/watch?v=rvkEpstd9os
Those people, pilots included, were thrown to the grounds.
They might not anyway.
As it is, people are irrationally afraid of flying. Plane crashes are a fetishized "nightmare scenario". Multiple crashes linked to the same plane (or company) will, likely, have terrible business consequences.
So Boeing bought it.
Are there? Besides Boeing and Airbus, which other company makes safe (or not, in case of Boeing) passenger planes? AFAIK it's a duopoly.
I don't think the main issue is outsourcing the engineering work out.
The bigger thing is they were outsourcing their management and reporting to Boeing as well. That meant rather than independent overview, Boeing managers were able to pressure shortcuts and cost cutting and could threaten engineers jobs who didn't toe the line.
But is that really what is going on here? Are they equipped to do so any longer?
"But with the MCAS activated, said Fehrm, those breakout switches wouldn’t work. MCAS assumes the yoke is already aggressively pulled back and won’t allow further pullback to counter its action, which is to hold the nose down.
Fehrm’s analysis is confirmed in the instructions Boeing sent to pilots last weekend. The bulletin sent to American Airlines pilots emphasizes that pulling back the control column will not stop the action.
Fehrm said that the Lion Air pilots would have trained on 737 simulators and would have learned over many years of experience that pulling back on the yoke stops any automatic tail maneuvers pushing the nose down." [0].
If you bought a new computer, how pissed off would you be if you lost data not because of a hard-drive failure, but because of a weird design decision of the 1 penny caps lock key? Imagine spending the time to setup a proper RAID system and losing everything because of a design decision in the keyboard.
I mean if the media keeps reporting about the small stuff that's wrong, it's going to make people go "well planes are complex and things happen" and almost ignore the seriousness of a design decision that ignores user input.
[0]: https://www.seattletimes.com/business/boeing-aerospace/faa-e...
The investigative reporting from The Seattle Times[0] indicates that safety engineers were pressured to avoid delays to rush out a competitor to the A320. Furthermore, their safety analysis was based on flawed assumptions to meet an artificial constraint of not requiring pilot simulator training in order to appease the airlines they were selling to. Finally, the FAA is allowing industry to self-certify critical systems with lax oversight.
It is easy to get lost in the technical details of why a particular catastrophe happens. The common throughline is a broken culture where deviance is normalized and those who speak out are ignored. It's the same story with Chernobyl, Fukushima, the El Faro, the USS Fitzgerald and USS John S. McCain, Air France 447, and now the 737 Max.
[0] - https://www.seattletimes.com/seattle-news/times-watchdog/the...
So the same problem that pervades society everywhere now? I’m not sure if that wasn’t the case before, but it feels to me that people previously wanted to make lots of money by building great products, and they’ve just left the ‘building great products’ part behind.
Cars have seen similar improvements. So have food hygiene, workplace safety, and most any measurable safety record I can think of.
We need new statistics, and this are the stats for the recent Boeing plane where the MAX crashed 2 times, first crash was blamed on the pilots and no serious urgent investigation was performed, the MCAS issues that were discovered were trivialized, still Beoing is trying to shift t6he blame on a bad software and not on the actual causes .
My point is that you can't use statistics that way, there are rules on how to apply them correctly and many pitfalls when applying statistics in real world scenarios.
You have some ideas about how everything used to be better in the past, and you're trying to hold onto them in the face of overwhelming evidence to the contrary.
There isn't some sudden increase in the pressure to earn money that wasn't there in, say, 2008. And while the 737 Max process was obviously flawed, the argument above was that somehow there are fundamental problems across companies and industries, not just a single model. Quote from above:
> So the same problem that pervades society everywhere now? [I]t feels to me that people just left the ‘building great products’ part behind.
While evidence of a breakdown in Boeing's ability to design safe planes would indeed lag, there are many other critical processes where regressions would show rather quickly, such as maintenance, fuel quality, air traffic control, IT security, etc.
In statistics you need some basic things to be true, like you need true random independent events, or sometimes a theorem apply only if the distribution of the events is known to have some properties.
What I understood you were implying (I was wrong, sorry) and other comments too, is that if we look at Boeing crashes (not MAX) for latest N years (but we exclude older incidents) then we can conclude things about the future statistics of the MAX.
About the rest of the industry I agree that most things got better. But for example in car industry there was a lot of competition and a lot of regulation bout safety and pollution that forced the companies to be better, if you had only 2 car making companies and have them self approve then we may get in the same situation as with the MAX.
The must read on the issue says so too.
"The Seven Signs of Ethical Collapse: How to Spot Moral Meltdowns in Companies", Marianne M. Jennings
Fukushima was designed to survive the earthquake, and it did, it just wasn't designed to survive the earthquake and also the tsunami.
[0] https://en.m.wikipedia.org/wiki/2011_Tōhoku_earthquake_and_t...
There are a couple of caveats. First, there were markers saying that an historic tsunami had come in much higher than models would have predicted. However, the are very old. It's just a rock stuck in the ground with some writing on it. Stuff like that is all over Japan (there are lots of markers around where I live -- I don't think anybody pays any attention to them at all. Probably we should, but usually they just mark boring stuff ;-) ). It's like seeing a roman road marker in Europe. Interesting, but not really note worthy. It's only after the tsunami that people saw the markers and said, "Holy cow. There's a marker here showing that a tsunami came up this far". Even then it's a far cry from seeing that to saying that we need to invalidate all our wave building models.
Secondly, I think there is some evidence that in a few years preceding the tsunami that researchers were getting worried that their wave models were not correct. I think it's even the case that nuclear plant companies were aware of this. When I first moved to Japan in 2007, there used to be a section of the Meteorological Agency of Japan that showed, among other things, a map of the farthest in a tsunami would theoretically go for all parts of Japan. It also listed maximum wave size for every single place along the coast. It noted places where sea walls were not high enough and estimated worst case damages and numbers of casualties. Around about 2009 it disappeared. I tried to find out where it went and the response I got was that it needed to be updated and that it would return at some point in the future. Of course, it never came back. At the same time, I've heard that literally a few years before the Tohoku earthquake that there was serious debate about whether or not the wave models were correct. However, I think it's pretty clear that in 1967 when they started construction at Fukushima they had absolutely no idea that they were building in a potentially unsafe area.
It really sucks and I think it's fair to say that as humans we probably have too much hubris when it comes to our science. That fact that you have no reasonable way of knowing that you are making a mistake doesn't mitigate the problems that result from that mistake.
That doesn't mean it's easy to realise the need to do that action, it means it's not a _complex_ action in itself.
untrue
It was designed to survive both a tsunami and an earthquake. Tsunamis often are caused by earthquakes.
That Fukushima survived the Earthquake is a myth. The plants had an emergency shutdown and there was very little time for a damage assessment, which would have taken weeks or months.
Whether the plant would ever have been restarted after the earthquake is unknown. It could have been a full loss, like several reactors in Japan, which will never be restarted.
The fact that other plants have not been restarted is at least as likely to be political as it is technical.
A nuclear power plant always has an immediate shutdown in case of a strong earthquake:
'Japanese nuclear power plants are designed to withstand specified earthquake intensities evident in ground motion (Ss), in Gal units. The plants are fitted with seismic detectors. If these register ground motions of a set level (formerly 90% of S1, but at Fukushima only 135 Gal), systems will be activated to automatically bring the plant to an immediate safe shutdown.'
http://www.world-nuclear.org/information-library/safety-and-...
> The fact that other plants have not been restarted is at least as likely to be political as it is technical.
The words 'likely to be political' is no category in nuclear safety.
Take this example from 2008:
http://www.world-nuclear-news.org/C/Tepco_counts_earthquake_...
'Tepco's announcement yesterday included a section dedicated to the effects of the magnitude 6.8 Niigata-Chuetsu-Oki earthquake, which violently shook the Kashiwazaki Kariwa nuclear power plant on 16 July 2007. All seven of the reactors remained safe during the event, which caused huge damage to the region and several deaths. However, checks to establish the units' safety to return to service are proving very lengthy, and could continue into the latter part of 2008.
The ongoing inspections at Kashiwazaki Kariwa are to cost ¥122 billion ($1.13 billion) in FY2007. In addition, ¥25 billion ($233 million) will go on civil engineering repairs while a geological survey of the site is to cost a total of ¥2 billion ($18 million).'
Just the inspections after a safe shutdown for that nuclear power plant did cost more than 1 billion USD...
It's one of those problems where there are literally a million things that could go wrong and since the emergency system is not used normally, it's easy to overlook a critical problem.
So I agree with you. Fukushima was not a design error -- or at least not a design error that could have been reasonably fixed at the time that the reactor was originally designed. It was an error in maintenance. Obviously better to have a design where loss of power doesn't cause a melt down, but I don't think that these were available when Fukushima was built. CANDU reactors existed at that time, but I think they were still considered experimental. Pickering came online in 1971, so basically at the same time as Fukushima. I'm not familiar with other passive designs, so possibly someone else can make an observation.
But basically, as far as I can tell, Fukushima was a reasonably normal nuclear power plant for the time it was designed. The Air Max seems to have suffered from problems because of design decisions that are not considered normal.
This is a such an important antipattern when robustness is a goal.
The fact that the co-pilot in question kept holding the stick to the back stops was the main reason that the aircraft wallowed into the sea. Weirdly, he did let go of the stick for a brief few seconds, which was the only time during the harrowing descent that the aircraft started to behave normally, but then he pulled it back and held it back right up until impact.
Yep, the aircraft could have ignored these inputs, but the inputs are counter to what any reasonably skilled pilot would have done. (Note: Different to the MAX crashes where pulling back on the stick under speed IS the accepted way to stop a descent.)
Except on an Airbus. If the plane is in "normal law", it won't go into a stall condition. Here's the Airbus training video.[1] Note, by the way, that the automatic recovery includes going to full throttle. The throttle levers don't move, though. Unlike Boeing, where the levers are moved by the computers and the pilot can overpower that. In the 737 Max, though, it's worse, because the engines are mounted too high and full thrust pushes the nose down. So "full power and back off on the stick" will not work.
This description isn't consistent with what's in the accident report. Where are you sourcing it from?
Obviously there was some significant pilot error in this case, but a big contributor mag have been that the pilot who was trying to correct the stall didn’t understand that the plane was ignoring his input because of the averaging.
From this link: https://en.wikipedia.org/wiki/Air_France_Flight_447#Human_fa...
In April 2012 in The Daily Telegraph, British journalist Nick Ross published a comparison of Airbus and Boeing flight controls; unlike the control yoke used on Boeing flight decks, the Airbus side stick controls give little visual feedback and no sensory or tactile feedback to the second pilot.
Ross reasoned that this might in part explain why the pilot flying's fatal nose-up inputs were not countermanded by his two colleagues.
In a July 2012 CBS report, Sullenberger suggested the design of the Airbus cockpit might have been a factor in the accident. The flight controls are not mechanically linked between the two pilot seats, and Robert, the left-seat pilot who believed he had taken over control of the aircraft, was not aware that Bonin continued to hold the stick back, which overrode Robert's own control.
That suggest there was only ever one pilot flying and the way that pilot reacted to the situation had a big part to play in the final crash.
"Pilot flying" is a human-factors title, not a software function-lock. It just indicates who has control responsibility at that moment but it is not enforced by technical means.
It is intended to eliminate ambiguity in crew functions; the PF can be a newbie copilot even if the commander of the aircraft is a 30-year-service Captain who would become the PNF at that point. Its all part of Crew Resource Management theory.
There should only be one PF in a cockpit at any one time, precisely to avoid the situation that arose with the Air France flight where the computer was receiving inputs from two pilots.
Might point was I doubt that this was in fact happening and there was only ever one pilot in charge.
> the Air France flight where the computer was receiving inputs from two pilots.
The link and quotes I posted suggest that was not happening.
The system was just ignoring the other pilot (and that was the designed fault) because it also failed to tell that other pilot he was being ignored.
It didn't fail to tell him. That's what the dual input alarm is for.
Now if that alarm was raised then that suggests both pilots were in error as they both seemed to have ignore that alarm.
However that was never the reason for my original reply.
All I was replying to was idea that the flight control was doing some sort of averaging of the two pilot inputs.
That to me just seems illogical as it would asume two pilots trying to fly the same plane and that scenario will never end well.
The sounding of the alarm is in the transcripts in the accident report.
The Airbus does average the inputs if both pilots are making inputs at the same time.
Do you have a url/link/pdf that describes this behaviour?
"When both sticks are moved simultaneously, the system adds the signals of both pilots algebraically."
In particular it also says this:
To avoid both signals being added by the system, a priority P/B is provided on each stick. By pressing this button, a pilot may cancel the inputs of the other pilot.
From this link: https://en.wikipedia.org/wiki/Air_France_Flight_447
As pilot flying, Bonin took control of the aircraft via the side stick priority button and said, "I have the controls."
Which again suggests at least in this case, Bonin was the only one flying the aircraft.
But, it’s the same basic idea. The PNF thought he’d gotten control of the plane, and didn’t understand why his input wasn’t having an effect. He didn’t get feedback from the stick telling him a different input was being honored. And neither pilot appears to have been fully aware that they were in a flight control mode where there was a risk of stalling. The PF especially never seemed to have made that connection, and the PNF took a fairly long time to call it out. As a result, the PF may not have been aware that he needed to actively keep the angle of attack inside the flight envelope.
So, PNF tries to pitch down, but isn’t aware the plane got put back into a mode where he isn’t in control. PF is pitching up, but isn’t aware the plane switched to a mode where this could lead to a stall. That’s the similarity I was getting at.
From the reported control traces, there was no prolonged period of dual input. There were 3 or so brief moments of dual control input (1 - 2 seconds), during which a warning was sounded. The pilots never spoke out loud about it, but we can infer that they heard the dual input warning and were aware when it happened because the sequence of events was the same each time; inputs from both joysticks received -> aural dual input warning -> input from one joystick stops.
Something about the idea of two pilots inadvertently fighting each other for control of the aircraft has definitely caught peoples’ imagination. But it didn’t happen.
The available evidence suggest this averaging thing never happened and certainly was not the cause of the crash.
What we have is situation of two pilots in close proximity to each other not communicating and the captain unfortunately caught in the toilet.
But there are multiple major factors leading up to that, including the lack of high altitude training in direct law, and that the simulator didn't exactly simulate high altitude stalls, and that the stall warning stopped when the angle of attack was beyond the sensor limit. All of these things are major and the final report really sank a lot of blame on Airbus and Air France as well as pilot startle effect basically stopping their brains from working the problem. The senior pilot who arrived didn't have that, and quickly figured out the source of the problem but by then it was too late, not enough altitude to recover.
The co-pilot apparently didn't realize that the sensor issue that disabled the autopilot also disabled the stall prevention. And that's despite an audible "STALL" warning being repeated in the background.
The captain was not in the cockpit when the whole situation started, but as he re-entered the cockpit during the stall he saw one of the co-pilots holding back on the yoke and told him to push the yoke forward to prevent the stall. The co-pilot followed the instructions, but only for a few seconds before pulling the yoke back again.
All of this is to say if the plane hadn't been known to ignore user inputs in most situations, the co-pilot might not have assumed the Airbus would do the right thing and climb no matter what when pulling back on the yoke. So in a sense, never ignoring user inputs might have also saved Air France 447.
Every piece of software is a mechanism. In order to truly be able to safely use something without outside aid, one must have a complete mental map of the mechanics of the system in question. Abstraction helps; but not when you start getting into high-risk contexts.
This might have convinced him that easing off on the stick was actually causing the stall, which was tragically misguided.
This is not a problem with how the system works, since this behaviour is explicitely communicated to pilots. It even says right on the instrument panel what control law the plane is in. There are only a handful of control laws and the differences aren't that complex. Anyone with sufficient experience in flying Airbus products knows this.
At least according to the official accident report, neither of the pilots at the controls consistently made nose down stick inputs.
A principle of zero automation fallback in case of confusion ? something that is hardcoded deep in the design so that people in charge (pilot crew) can know for sure that whatever happens is in their hands ?
There is a simple procedure, which is already part of the standard memory checklists. What to do in case of runaway trim. The pilots must/should be able to notice the trim wheels spinning, they then can disable trim motors and fall back to manually cranking them.
The problem is, panic makes a mess of almost anybody. Sure, pilots shouldn't be anybody, but we know how much cost cutting has been going on.
https://www.netairspace.com/photos/N37474/United_Airlines/Bo...
And it turns out this can/happens even with the electronic motorized way, and there is a maneuver to work around the load. But it got removed from the manual...
https://www.pprune.org/tech-log/619326-boeing-advice-aerodyn...
A flabbergasted reporter then asks him if he means to say that MCAS was designed to push the nose down 21 times. The CEO then blamed the pilots for not following procedures!
He repeatedly avoids avoiding admitting that any mistakes were made. He was so intent on avoiding blame that he gave me no confidence that Boeing could learn from its mistakes. The longer he talked, the less confidence I had in Boeing as a company.
I have no idea why this guy still has his job.
Edit: unsure if this video is correct, but the MCAS system is classical "solution" to how in software a junior programmer would patch their software by adding more complexity to the code without realizing what that changes would further affect. It felt like they gave up on some solid solution and just decided to added a sensor who would overwrite pilot manuver.
A similar situation would be downgrading a size of tires on a new model of a car (to be competitve with other auto makers that lower the price) and simply adding software blockage that you cannot turn wheels as violent as you could before because on thin thread that would lead to a car tipover.
The whole video - if correct, paints a grim picture of profits above PAXes...
If Boeing would say "we're at fault", people would sue them (more than now) and have greater chance at winning those lawsuits, since Boeing already admitted to being at fault.
I can imagine Boeing, and the Boeing CEO, is trying very, very hard at walking a fine line of not admitting being at fault, but also saying that they are "taking responsibility" (since they have 300 souls, public opinion, and lawmakers against them). They have to convince people (those that matter, ie those stopping operation and sales) that the MAX and Boeing are safe.
You could have a perfect aircraft with no flaws, and a human could still manage to crash it. See the Germanwings flight for a good example.
If not you have a lot of faith in people's willingness to sacrifice themselves to save others.
The problem for Boeing is the history of flying has many examples of planes with poor safety records being rejected by the flying public.
Only time will tell if the 737-MAX joins that illustrious group, but the more the plane stays in the news for all the wrong reasons, the better are it's chances.
USAir Flight 427
United Airlines Flight 585
Eastwind Airlines Flight 517
Silkair Flight 185
Copa Airlines Flight 201
China Southern Airlines Flight 3943
MetroJet Flight 2710
But there are also many examples of aircraft with terrible early safety records that never recovered from their bad start.
From Boeing? They have a history of sorting their shit out. Maybe this time is different, but I doubt it.
They also seem to have a bad habit of blaming the dead pilots for not being able to fly they broken planes.
You seem to be overlooking the 787 - a few early models set on fire. Sure, nobody died, but that was more luck than judgement.
Then I think, that as a consequence of the analysis of the two crashes, in general a better understanding of certain flight states has been reached. In the light of this better understanding, other bugs might be discovered which previously have been missed.
Edit. I should have to say this but I'm not defending Boeing here. I'm saying it's not at al unforeseeable that the other planes, even ones by other manufacturers are just as bad. Clearly they thought nothing was abnormal about this one until it started falling out of the sky. I see this kind of like diesel-gate. If one of them is cheating they're probably all cheating.
https://www.engadget.com/2015/05/01/boeing-787-dreamliner-so...
You’ve said they can’t have larger engines because ground clearance is low... we already know that... but why must ground clearance be low?
This was super helpful to small carriers at the time, but as time has gone on it's caused problems.
I'm sure that costs more money. If it were on all 737 MAX aircraft, perhaps the engines could be lower. It'd be like a kneeling bus that gets lower when stopped to take on passengers.
Another option would be to make the engines move. They could be folded up or slid up-forward when driving around the airport. The FAA might have issues with this though. I don't know of any aircraft that does transformer stuff while zooming down the runway.
Short video with gear model in action: https://www.youtube.com/watch?v=F4IGl4OizM4
https://www.geekwire.com/2018/boeing-737-max-10-landing-gear...
Scroll down for a nice diagram: http://www.b737.org.uk/737max10.htm
And also you can't just redesign the landing gear without redesigning a substantial portion of the wings.
As long as it remains sufficiently 737-shaped airlines can keep flying it to all the place they've been flying 737s for decades.
The reason they didn't want to do a clean sheet redesign of the 737 was to avoid pilot recertification, not because of ground infrastructure. Airports are already used to servicing dozens of different types of planes. Adding one more to the mix wouldn't materially change anything.
Separately, there's the issue that the A380 is so large that you need multiple jetways (at least one for each level) to efficiently load and unload everyone. Maybe you could slowly unload an A380 by debarking everyone off the lower level and forcing everyone on the upper level to walk down the plane's internal staircase, but this is extremely sub-optimal. In practice airlines don't do this; they use specialized gates set up for the A380's special needs.
It is turning out to have been a pretty bad decision, even from a mercenary point of view.
They can't do an in-depth forensic analysis of everything without unlimited money.
Unfortunately, that comparison algorithm had a flaw - it got confused when it received spikes of invalid data with a certain timing pattern and erroniously used the invalid data. That pattern shouldn't have been possible. No-one has been able to figure out any possible cause for it even in retrospect, and they certainly didn't anticipate it. However, the engineers designing the system did realise that the flight computers could have subtle bugs triggered by specific data timing - so not only did every flight computer have a monitoring channel running independently-written code checking its calculations, that monitoring channel was intentionally not synchronized with the main channel or any other flight computers. This meant every time one of the flight computers acted on bogus data and forcibly pitched down, the monitoring channel calculated values so different that the fault detection disabled its ability to do so within a few seconds.
The maximum allowed authority and the altitude at which the system was enabled were also much more carefully restricted than MCAS, so it couldn't take such erroneous actions in situtations where the pilot might be unable to recover. Combine the two safeguards, and something like Qantas Flight 72 with a few passenger injuries but no crash was pretty close to the worst-case scenario that could be caused by this weird and incredibly unlucky issue.
Huh, this is new to me. I thought it was simply that two sensors failed, and their failed values outvoted the correct value in the quorum vote with the third sensor. What's the mystery about?
A microprocessor failed and output corrupted data.
However, the problem with the max seems to be that instead of designing for failure - assuming that critical systems might fail and the plane should recover gracefully from the failure of most internal systems - they seem to have designed for success, and made the assumption that no part of the plane will ever fail. And that's obviously not realistic, and we're seeing the consequences of it here.
The 737 MAX only looks bad because it's track record so far is that it's a death trap.
It was a huge deal and the plane was grounded for three month due to those battery fires.
Originally the engineers did not account for battery fires and needed to refit a compartment to seal the batteries in case a fire occurs.
Luckily it was either on approach, or they could emergency land the plane when the problem occured.
A burning lithium battery in a flying plane is one of the worst imaginable scenarios you can encounter during a flight and is a fucking big deal.
Edited to add : https://en.wikipedia.org/wiki/Boeing_787_Dreamliner_battery_...
0.5% of all 737 MAXes which exist have killed everyone on board. No other mass market production airliner in recent history has that sort of record, AFAIK.
The Concorde is the only thing that's worse. The A310 is closer than anything else at 1.35 fatal crashes per million miles vs the 737 MAX's 3.08- and that one was also designed to share a common type rating with an existing design.
Case in point: Wine. They've been at it for years and the emulation layer is still far from perfect. It works 99% of the time which is good enough for games, but I wager not for airplane control systems.
However, I have to admit, reverse engineering a home desktop is different from a airline software, considering that bugs can instantly kill people.
They actually did. It's called Tu-4: https://en.wikipedia.org/wiki/Tupolev_Tu-4
In fact, divergence from MATLAB is considered a bug. Admittedly, the entire point there is a free and open source replication of MATLAB, and is only really necessitated by licensing.
Boeing's engineers weren't tasked with making MCAS generally work like a 737. They were tasked with making MCAS work exactly like a 30+ year old aircraft model, complete with quirks and faults. An impossible task.
You're saying they set out to make not-a-737 behave physically as a 737. Yes. I concur. I seem to have hyperfocusef on the replication part and not enough on the plane part.
Boeing deserves a 9-figure fine though, and its shareholders should lose massively to make sure this doesn't happen again.
Instead what they've had is 2 weeks to fix it for 6 months, which is a very different kettle of fish.
The problem is that this is not actually a software problem. It’s an airplane design problem, and Boeing is trying to convince you that it’s just the software.
Even if the software is perfect, this plane remains a flying coffin until it is redesigned from scratch.
The only real fix is not to fly on this plane.
When doing root cause analysis there is a pyramid with people problems at the top, then deeper technical problems, process problems, culture problems and value problems.
Most root cause analysis stops with people problems, or technical problems while all the root cause analysis I've done never showed that problems end there. Culture and value have often been the underlying causes.
How can we trust that assessment? What if the plane is inherently unsafe? There's been no critical 3rd party review of the plane without MCAS in operation. Everything is a Boeing talking point. Their proposed fix is 2 AoA sensors (on top of whatever slapped-together software updates), and if they disagree, disable MCAS. That's going to decrease the MTBF of that system. So, IMO, the real question is, why should MCAS even be allowed if it's so easily disabled? Either the planes can fly without it or they can't.
Which pilots should have had anyway, even if it didn't require a new type rating.
As a side note, it’s really unfortunate that we won’t get an NTSB-level (both in detail and widespread respect for the organization) report on what went wrong and how it happened. I’m not sure the Ethiopian and Indonesian authorities will really (be able to) dig into MCAS and all the details of its development as deeply as we’d like. I expect that some of the reporters covering this story will write books (Dominic Gates and Jon Ostrower in particular), and those will be the most authoritative accounts.
The #1 problem with the airframe is that it is not identical to the original 737 airframe. Therefore it shouldn't have been certified as a 737, and it should have required pilot training.
Boeing has been using software to emulate a 737 airframe to avoid the pilot training costs. This approach itself is fraught with problems, and I hope the FAA puts a hard stop to these non-solutions.
The 737 MAX airframe is substantially more like a 737 NG airframe, than a 757 is to a 767. Etc. It sounds like you have a problem with how airplanes are type certified, not a problem with the airframe.
Indeed, it might very well be questionable that the 757 and 767 have the same type rating. But then, even though they have the same type rating they do still have difference training. Is iPad difference training really adequate? Who evaluated this? Were there contrary opinions?
What this results in, is a non-compliant stick force response curve at high AoA. This violates FAA regulations which state that the stick force required to bring a plane to a stall must consistently increase all the way to the stall. No sickening or decreases in apparent required stick force are certifiable as airworthy for Civil Transport Aircraft.
This was explained in a recent Seattle Times Article. I also posted it here as a theory back in March abouts.
[1]https://www.seattletimes.com/seattle-news/times-watchdog/the...
[2]https://news.ycombinator.com/item?id=19568158
[3]relevant FAR 25.173, see stick force requirements
MCAS was designed to artificially induce a mistrim which has the end result of smoothing out that force curve. Initially it was only for high-speed, high-G, but was eventually loosened to accommodate the same behavior happening at a low speed low G part of the flight envelope.
This is a hack in the truest sense of the word, because you'll notice the regs indicate the plane having to be within a certain point of appropriate trim; except in those flight regimes, the trim is artificially massaged from what the pilot set it to, to what MCAS thinks it should be, which is determined by the input of only a single AoA sensor.
In short, the airframe is aerodynamically flawed in some of the most fundamental ways known to the aviation community. It can work; given a correct MCAS system. There was no excuse, however, to hide this from both regulators and pilots.
Hope that explains things.
I do not see how software augmentation can be permitted to compensate for a deviation from FAR 26.173. That section is titled: Static longitudinal stability. Software augmentation cannot cause an airplane that lacks positive static stability to have positive static stability.
You have to understand that what you're proposing represents such a magnificent perversion of FARs, if true, that it is not conceivable to me that this is not a big f'n deal in the aviation community. It would be the elephant in the room, that somehow Boeing and the FAA permitted an airplane that in fact does not have certifiable positive static stability in one or more axis, to have been certified because of a software routine; let alone a software routine with no redundancy and is easily disabled in flight with no documentation on the consequences.
Let me put another fine point on it: I do not care if there are 50 AoA sensors and 100 independent computers on this airplane to compensate for a FAR 25.173 deficiency (or pick any of the other axis for that matter). You cannot use a goddamn computer to make an airplane statically stable when aerodynamically it is not statically stable. At least not without changing the FARs. As they are written, transport category airplanes must comply with FAR 25, and I see nothing in FAR 25 that permits computers papering over aerodynamic requirements.
I absolutely 100% agree. At no point have I intended to imply that any software solution should justify exceptional certification of an unairworthy frame as airworthy; in case that isn't clear.
I've only tried to communicate the fact that the software can physically remedy the behavior enough to apparently bring it within the capability of a human to control (as has been demonstrated by the non-crashed flights, as Boeing will inevitably argue).
I absolutely, unequivocally reject any argument that the software fix is compliant with regulations as written, or should be accepted as an acceptable remedy in it's current form.
I've had my view somewhat shaped by D.P. Davies in regard to the application of "gadgets" for certification. I think that any such system must be essentially bulletproof, and avoided at all costs by engineering the problem out if possible; and if allowed must unquestionably get the point across to the pilot that they are in dangerous waters.
The 727 had it's Stick Pusher in the U.K. This seems to be a modern retreating of the same path, and to be honest, I'm siding more toward the conservative side you hold of not allowing MCAS to remedy these handling faults. It really would be an example of the slippery slope of normalization of deviance in action.
I really hope all pilots, aerodynamicsts, and engineers take notice, and speak up. I can sit in these threads and try to spread understanding to the nine winds; but I'm some dude on the Net, who has no professional affiliation to any of this, but a big fat keg of outrage because this is not Quality damnit.
This is such a tired argument.
How much money do you think Boeing is going to make for its shareholders if its planes are crashing and fleet is grounded?
What sort of mindset must one have to assume that once a person becomes a "manager" or "executive" they are suddenly immoral or evil? Such an odd worldview.
I guarantee no one at Boeing make the conscious effort to kill hundreds of people for a bonus. Mistakes happen. People of all standing are corrupt. We fix the issues and move on, not cry about executives, board members and shareholders (of which most people on this board are striving to be).
It's well known that large US companies offer perverse incentives for their executives. As long as they don't do anything super illegal, there's often no recourse. I mean, recent history is replete with examples of executives optimizing-for-bonus.
Becoming an executive at a publicly traded company is a joyous and public acceptance of capitalism. Capitalism is objectively bad, given the state of the world.
If Boeing can put out faulty products that kill people will no recourse, that's not capitalism, that's the government allowing these criminals to continue operating unchecked.
Two relatively new Boeing 737-MAX airplanes crash in relatively quick succession. A critical flaw in the aircraft is exposed to the public. Significant numbers of people refuse to fly in a 737-MAX.
Southwest made a substantial investment in 737-MAX airplanes, and cannot make their money back. They approach Boeing and Boeing gives them a 75% discount on a 737-MAX replacement. Or, Boeing shrugs their shoulders and says, "huh". Southwest cancels all future orders with Boeing and buys Airbus.
Or, Boeing waves their hands and says, "We fixed everything. The 737-MAX is perfectly safe now." The next week, Southwest relaunches their fleet and books 100% occupancy. They negotiate with Boeing about the $millions lost while the fleet was grounded and get back to business as usual. For the next 5 years, a 737-MAX crashes every year killing everyone aboard, but bookings stay high. All ticket prices go up $25 to fund the payouts to crash victims. Bookings stay high. Business continues as usual.
See all the very different directions capitalism can take you? I continually struggle to understand the mindset where all blame goes to the government and there is no individual responsibility for consumer choices. We've seen it over and over with Wells Fargo, GM, Facebook, and the list goes on.
Government can serve a meaningful purpose in the regulation of capitalism. But also, capitalism can and must serve a critical role in the regulation of capitalism.
I have had the opportunity to observe a very wide variety of businesses in several industries and have noticed the same thing as multiple studies - a high degree of sociopathy among execs. My conjecture is that this is both because aggressive sociopathy will help people rise among the ranks, and also because the structure of business will tend to actively select for those traits (unless active counter-selection is implemented).
So, sure, one does not automatically change by becoming a manager (although there are psych studies indicating high income causing reduced compassion for others), but there is good reason to expect higher "immoral or evil" behavior in higher ranks.
https://www.scientificamerican.com/article/how-wealth-reduce...
https://www.globalpolicyjournal.com/blog/06/10/2016/wealth-c...
Each person is only responsible for their own bad decisions. It's likely there is no one person who signed the memo that said "casualties totally okay, make more money!" Instead we'll find several people signing off on several bad decisions, each person myopic enough to be able to honestly claim they had no idea something this bad could happen.
It would be nice to see the buck stop at, say, the CEO, but I haven't seen that happen. In many cases the CEO will claim that they gave blanket performance goals and that the execution of those goals was too technical for them to actually understand, or that those technical details were hidden from them by people below them who were trying to hide things (rather than only deliver the type of information the CEO really wanted).
if you cut corners on engineering to reduce costs and nothing bad happens, that good engineering actually
Suppose Bob fires a gun into a crowded area and happens not to hit anyone. I didn't hurt anyone! It's my right as a consequentialist!"
Bob still goes to prison.
Beyond that, engineering is about using a principled approach, by definition. Throwing something together ad-hoc and finding that it happens to work, is not what is meant by 'engineering'.
A core scope of engineering is to make technologies to make life of people better without killing them. To reduce cost is a one of instrumental goals helping business to do more than it might have done without it.
To risk someone's life is a very bad idea, even if it increases profits.
It's not obvious how the responsibility for those deaths should be allocated.
What's the tolerance threshold for airline fatalities?
Meaning what?
The more fundamental problem is that corporations are run by people who, mostly, care more about themselves than the company they are running, and more about this year than the future. Boeing needed to suck it up and accept a couple years' poor sales, in order to get an effective competitor to Airbus' latest. In the long run, or even the medium run, this would give the best monetary results, as well as save lives.
But, it would mean bad financial results this year and next year, and the corporate business environment is biased against that. If the CEO makes decisions which give worse results this year and next, but better results later, he will not be around in his job to enjoy those better results. So, he optimizes for the near term, and rolls the dice (with other people's lives).
The biggest exception to this would be companies where the CEO is the founder, who usually has the ability to retain his job through a bad year or two.
Of course, the CEO should have made the right decision anyway, and accepted the consequences, because people's lives are at stake and anyway it's not like he would starve if he got fired next year. But, if we're talking about incentives and conflicts of interest, that's the real issue, not money vs. lives (because both point in the same direction, of making the plane safe), but short term vs. long term and CEO vs. the company as a whole.
I can't imagine any airline making a deal at 50% list price with the current perception of that death trap with the public.
50% of list price, btw, is in the ballpark of usual discounts granted to end customers by Boeing and Airbus[1].
While I'm not privvy to any internals (obviously) my take is that IAG essentially gets the plane for free in exchange for a PR win for Boeing.
[1] https://en.wikipedia.org/wiki/Competition_between_Airbus_and...
I’m going to assume there’s a real issue they are trying to report on, but Gell-Mann effect is strong with this one and some key information is missing.
In addition I'm sure airlines not flying the MAX will be using that fact as a marketing tool (i.e. we only fly Airbus etc) so you could limit your bookings with just those airlines.
As an example of this, here in Australia I know one of the carriers is planning to fly the Max some time next year.
If they go ahead with that plan, I will be making sure not to book with that carrier at least for the next few years.
If that's correct, aren't there possible risks for flying a plane that had such a long period of inactivity?
This is the really big problem Boeing now faces.
For these planes to fly again they need to be certified safe to fly again.
However since the FAA was one of the last authorities to ground the plane, it really does not matter what outcome they achieve in their current investigation.
Other aviation authorities around the world will take their own time to investigate if the plane should be allowed to fly.
The conundrum for Boeing is it wants the plane back in the air ASAP but I'm sure many of the world aviation authorities are in no real rush.
I always do this anyway just out of curiosity. Also if it's a plane I enjoy flying on it makes me look forward to the trip that much more. I have to admit that if I spotted "737 MAX" on there I seriously doubt I would book that trip, even after these issues are eventually resolved.
Answered your own question. Assuming Boeing doesn't just scrap this, most airlines will operate either it or the A320neo, not both.
The new plane might quickly turn into a internet meme.
I don't know where y'all went to school, but I was never able to self-grade my year-end exams.
Absolutely unthinkable banana republic behaviour and not a single head rolled (except for the about 350 poor dead souls who had to pay for this corruption with their life).
Hanlon's Razor is useful in some scopes, but imagine applying it to banking, politics, corporate regulation or law enforcement. Depending on your position, not doing due diligent and acting ethically is malice.
It may be mismanagement or incompetence, but I don't know if it gets to the degree of malice. Here's how I see it working:
FAA is obligated to provide oversight. FAA is also not given resources to do due diligence themselves (e.g., one inspector may be responsible for multiple airframes, meaning there is no possible way to know the systems in intimate detail to catch everything). To mitigate the lack of resources, they contractually obligate or delegate the oversight to the manufacturer who (presumably) does have that system knowledge. However, it's still the FAA's job to ensure the manufacturer is doing due diligence on oversight. This can easily become a catch-22...without resources to catch the manufacturer errors (e.g., FAA was apparently unaware of software configuration changes), it makes it tough to throw the red flag when everyone is clamoring to keep the schedule moving. They have to defer to the system "experts".
The above is not based on personal experience with this particular case and I'm not saying the FAA is not culpable. I just don't think it's due to deliberate malice. It's the same issue all over the government in terms of oversight. Oversight functions are often the easiest to scale back during budget crunches which, over time, will increase the risk of bad events. Then there is an uproar, the pendulum swings the other way, people want to fund oversight functions until they are once again lulled into complacency by the lack of bad events (which is actually an indication that the oversight is working).
There is likely some degree of bribes in most government organizations. It's a cancer that needs to be removed, but the real question is whether it's at a level that makes true governance infeasible.
I would love to see the government acting as a proper and impartial oversight role. But are taxpayers willing to pay for it? Sure, we can make a case for increased funding to support the FAA after 737-MAX, but what about what about when things seem to be going smoothly? And this is just one sector...would taxpayers be willing to provide the same resources to the FDA, EPA, OSHA, and all the other stretched-too-thin organizations?
The reason it doesn’t work like that is because of pressure on them to keep up wih the requests, and keep the businesses running. That pressure can’t be just their professional guilt, there is I think enough ways the industry affects them so they can’t just refuse to lower standards or accept to delegate part of their work.
That pressure, is what I call bribes. Be it preferencial treatment, exchange of favors, or straight up money going to decision makers to make sure the FAA doesn’t hurt plane makers.
The system is likely biased toward people who don't stop work. Any single decision may have a low probability of catastrophe but if you roll the dice enough times it'll catch up to you. But until it does, those types of managers will get promoted because they "get things done" (i.e. they don't stop for due diligence)
The 787 is an advanced and innovative plane. It blazes the way in terms of seat-mile cost, comfort, fuel consimptoon, etc.
The 737max is a half-baked response to the re-engined a320 and also the somewhat smaller planes like the a220 and e195-2 that beat the 737 in cost per mile and noise as well as being more comfortable. (Think of the Japanese cars that were small on the outside and big on the inside compared to 1970s American cars)
The 737max tried to innovate as little as possible, and that is where it got into trouble.
I think Boeing still thinks that it can get the FAA to avoid a simulator training requirement but they won't and by trying they will delay the recertification at the expense of airlines, shareholders, etc.
https://www.govexec.com/defense/2016/06/computer-crash-wipes...
Because engines are purchased separately from the aircraft, the buyers and engine manufacturers must be in a bind, since the buyer needs to pay for the engines for Boeing to fit them, whether the plane enters service or not.
This is, to my layman's understanding, could be considered an "engine problem" because how the newer more fuel efficient engines with their bigger bypass fans don't fit under the wings of the 737. That's not an engine manufacturers problem.
(It makes more sense to classify it as an airframe design compromise problem, but it's about those big fat geared turbofans not working with the little landing gear legs which let them get the doors down nice and low, but put the wings too close to the ground to fit the more modern engines.)
One of our clients was Boeing, and we made a lot of sensors for them: anything from landing gear stuff, cabin oxygen and pressure sensors... you get the picture. Quite a lot of them were ultimately destined for the 787.
I also remember manufacturing sensors for Hamilton-Sunstrand... who would then fit them in 737 rudder assemblies and then sell them to Boeing. The whole subcontracting business was very byzantine in its complexity!
I also distinctly remember Boeing execs coming over very frequently to give updates, feedback, etc.
But GE don't make "737MAX8 engines" specifically. They make the range of engines they have, and Boeing (and Airbus and Bombadier et al.) get to choose which one they want, given the constraints of their aircraft.
You _could_ fit a 500cu inch big block V8 into a Miata. Bit it's not gonna handle the same as it does with a 2L 4 cylinder in it, and it's gonna stick out the bonnet.
We're all quite used to having problems described in the least threatening way but I'm thankful that I've never had to do so about something that could result in people dying.
Lines of code, from the internet[1]: Pacemaker: 100k Boeing 787: 5M Chevy Volt: 10M Modern car: 100M
[1] https://www.visualcapitalist.com/millions-lines-of-code/
* Writing everything three times for three different computers with three different architectures in three different ways (e.g. numerical vs symbolic integration)
* Using obsolete programming languages for the same reasons doctors use latin
* Has to be usable by poorly trained pilots, while tired, on the other side of the planet in complete darkness with half the systems failing.
* Nobody dies if you web/game crashes. The plane has to still be flyable in unimaginably bad conditions like a total engine loss by deploying a windmill (ram air turbine), therefore every scenario is accounted for.
Caveat is we usually find new scenarios by crashing planes, not by thinking about them first. Kind of a definitional thing: if you'd thought of it, it wouldn't have crashed.
Obsolete languages: Old language (or Latin) does not bloat the size of your code astronomically.
Usability in specific conditions: does not apply to a car or pacemaker. Yes, for an airplane, it can make the design phase lengthy and difficult but the actual size of the code will not bloat astronomically.
From some of the discussions I have seen on HN, writing safety-critical software is not a question of adding millions of lines of code - to the contrary, safe software must be clean and readable.
The Linux kernel was 15M lines in 2013 [1], more than half of that was drivers. Windows XP was apparently 45M lines, the 2009 Debian distribution 300M lines [2].
So you're into millions of lines just to execute "Hello world" on a PC.
Simple control systems generally don't use an OS. E.g. Arduino is as simple as it gets, here [3] is a 30-LOC example snippet for a HTTP client. But if you dig down into the included libraries (most of it is on GitHub) you'll find that there's (quick estimate) 10-20k lines of code involved in executing those 30 lines. And you haven't actually _done_ anything yet, that's just the infrastructure to allow C code to interact with the hardware with a few standard libraries for math and IO.
Modern cars are complex enough to have OSes [4], with the corresponding code complexities.
In short, web developers vastly underestimate the code complexity of interacting with hardware in a low-level language because it's not something they deal with. The umpteen million lines of OS kernel and device drives are done by someone else, and for people who just _use_ a PC it (mostly) "just works", to the extent that even advanced users aren't aware of the complexity behind it.
[1] https://en.wikipedia.org/wiki/Linux_kernel#Codebase
[2] https://unix.stackexchange.com/questions/111281/exploding-am...
[3] https://www.arduino.cc/en/Tutorial/HttpClient
[4] https://www.quora.com/What-operating-systems-are-used-in-car...
How many I/O devices/drivers does a pacemaker talk to? How many of those are written by/customized by the pacemaker's developers?
If you include the underlying stack, then also my <body>Hello world</body> runs on tens of millions of lines of code (Browser+OS).
A pacemaker would presumably be similar to Arduino: A simple processor, no OS. 100k lines (your numbers) isn't all that much, given that C standard libs are into the tens of thousands alone. Pacemakers have sensors to detect heartbeat, logic to send an electric pulse only when needed, and have an interface where medical personell can hook up a computer to adjust some parameters. So 2-3 IO channels at a minimum (one or more sensors, one or more outputs for the electric pulse, and some sort of wireless interface for adjustments).
> Are you suggesting a passenger car runs its own Linux distro?
According to Quora (last link in my reply above) the most common alternatives are Windows Embedded Automotive, a Linux derivative, and QNX. Why? To avoid writing millions of lines of fairly complex code on their own, of course. Just like a desktop developer saves a ton of work by writing on top of the OS rather than implementing their own OS from scratch.
> If you include the underlying stack, then also my <body>Hello world</body> runs on tens of millions of lines of code.
Yes, but that's the point: The numbers for lines of code in a pacemaker or car includes the entire stack. If you want to compare it to web development, you'll need to include the full stack there too.
Software bugs notwithstanding, too much computer means less human piloting and less actual hand flying experience. It might lead to a lower bar of acceptance to be a pilot, or discourage the types of people who actually love flying (since it's mainly done by the computer). More software can mean more complacency, less attention and engagement, less feeling of authority (by being so conditioned to surrender to the computer) and less "feeling" for what is right and wrong in any situation ("the light is green, that means no issue with this thunderstorm, company policy says fly the route when the light is green") .
It's perfectly okay to let some jobs (or mechanical assemblies) be manual even when they could be made auto.