In any system failure there is a chain of events that leads up to the ultimate failure, concentrating solely on Boeing's mistakes in these crashes overlooks all the other points at which they could have been averted:
1. In the Lion Air crash, there were some significant maintenance issues that lead up to the replacement for a failing AoA sensor with a used part older than the aircraft failing as well.
2. There were some significant failings in Crew Resource Management in the accident flights.
3. There appear to be issues in the pilots abilities to deal with unexpected situations. This is why simulator training exists, so that pilots can encounter unexpected issues and deal with them correctly.
4. The failure that lead to MCAS being activated also caused a whole ton of warnings to be activated, which may have been a situation Boeing was not expecting, and therefore did not put into the minimum baseline training they create.
5. The flight computer system and MCAS was implemented problematically, relying on one input because the expected control authority was very low, and then when that was not changed the system was not re-architected.
6. Boeing's designs reflect a US-centric expectation of pilots. In the US we expect pilots flying airliners to have spent at least 1500 hours flying before they can even sit in the co-pilot seat. In other parts of the world I have heard numbers as low as 240 hours, so pilot testing will need to reflect this going forward.
I like your approach: Pilot's failures caused the crash, and Boeing made an honest mistake. And you seem to think it would have been fine flying in the US. You do realise plane crashes and industrial accidents do happen in the US?
A safe system assumes they are operated by humans who are not infallible, and should not go up in flames from minor issues. Otherwise we must conclude Chernobyl reactor was a perfectly fine design.
Are we trying to solve engineering problems by getting emotional about them or something?
Your position seems to be that it was a combination of innocent engineering mistakes and substandard behavior by the pilots.
> The flight computer system and MCAS was implemented problematically, relying on one input because the expected control authority was very low, and then when that was not changed the system was not re-architected.
Do you have a personal stake in Boeing or something? Because you appear very biased indeed. There were several ethical breaches that resulted in these tragic catastrophes.
We can try to blame Boeing for the lack of this training, but Boeing cant force airlines to do anything but the type specific training. They cant force airlines to do recurring training, they in-fact rely on the regulators to setup structures to make sure this all happens.
I don't have a personal stake in Boeing, I have a personal stake in not dying because someone decided breaking one link in the failure chain was adequate.
* These would be the cases where the pilot crashes the plane on purpose, for which some airlines have dealt with systematically and with associated training on prevention.
My point is, there are a lot of technical and ethical oversights you are glossing over. There is a reason why all the 737 Max are grounded and have been grounded for months. These crashes weren't simply due to lack of pilot training. There were multiple ethical and technical oversights and negligence by Boeing that resulted in these tragedies.
So we are expected to believe that Boeing never connected the dots between:
1. We design planes for US pilots
2. We sell planes abroad
3. Incidents abroad can ground an entire aircraft series
This makes them seem more incompetent, not less. It's not like they have no say in what's considered standardized training for the series.
From my understanding of the issue, Boeing just needs to stop the cost saving measures that led to needing software to stabilize an otherwise unstable plane.
The choice to make is how difficult you will allow features to be, and how many difficult features you will add.
The answer has to be at least moderately high to get the plane off the ground. If it's too high then you have a bunch of deaths.
It's okay to say Boeing went too far on the scale, but to say they never should have been on the scale is misguided. Intelligence of the operator has to cover for certain aspects of the design.
This is wrong, it is unethical to approach engineering a system like this. In investigating these crashes, all the failures that lead up to the accident must be identified, all of the possible solutions must be explored. Sometimes its an easy fix, sometimes like United 173 we have to change the whole culture inside the cockpit to fix the problem (Cockpit Resource Management). Sometimes the solution wont show up until years later, so accidents from decades prior are used to formulate solutions to problems that had not been solvable until the right technology, either hard mechanical technology like hydraulic fuses, or physiological technology like CRM, comes along.
I feel like this attitude that there's only one thing to fix every time something goes wrong is why we see colossal fuckups in the software and infosec industries and I think that needs to change. System failures require systematic solutions, not just some quick fix or patch.
4. Which is not at all what happens with runaway trim. Also runaway trim that pilots are trained on is a consistent and relatively slow trim. The MCAS upset form is intermittant, and can be but isn't always, aggressive and comes with a ton of other data in the form of various instrumentation disagree warnings and possibly stick shaker going off which NEVER happens in a runaway trim situation.
6. Boeing's design and US-centric expectation of pilots didn't prevent US Air 427 from crashing. Literally everyone in the world expects pilots won't pull back on the yoke at stall. Yet these U.S. pilots did that. Colgan Air 3407, same thing, captain pulled back on the yoke during a stall making the stall worse, recovery impossible. Both accidents, each pilot had more than 1500 hours experience.
In US Air 427, the pilots aren't centrally blamed because the failure mode was a) caused by an airplane defect, a servo failure, b) the airplane's subsequent behavior was so abrupt and aggressive that the startle factor was pretty much not that surprising.
So why is it that the standard should be different for ET302 in particular? But also LNI043 and LNI610? Why would the blame not centrally be on Boeing even if the pilots made some mistakes, just like U.S. pilots have also made some mistakes yet weren't blamed as the proximate cause? And what mistakes did ET302 pilots make other than trusting electric trim being reenabled wouldn't immediately try to murder them?
Like I told you before: overspeeding the plane, preventing them from restoring the trim condition with the trim wheel.
I get that if you're not climbing as much as you'd like, it's tempting to have a ton of power in. But the maximum airspeed of the plane is chosen because there are undesirable handling characteristics -- like not being able to manually retrim, or even worse things like aileron reversal-- above it. At some point you need to pull back power.
If you're out of trim because of electric trim misbehaving, turning electric trim back on may not be the smartest thing, too.
And then I can't even understand what happens next: if you touch the trim switch, MCAS can't do stuff for awhile. If they're going to re-enable electric trim, why didn't they then fully fix trim with the trim switch? How is MCAS able to actuate and worsen the existing out of trim condition?
20+ degree down angle inside of three seconds. The negative G sent them to the roof. I'm a certified fight instructor, and I've never experienced negative G.
MCAS killed them.
No, but overspeed does.
> A power reduction for transport category airplanes always causes a nose drop a requirement of certification
Please cite. If you point to 25.173/25.175, note that it refers to trim speeds and return to trim speed, not power. The plane was climbing before crossing Vmo / power could be reduced to maintain Vmo and the current climb rate.
> I'm a certified fight instructor, and I've never experienced negative G.
What? You've earned a spin endorsement, then. You've experienced the little negative G (in most planes) as you tip and enter the incipient spin. It's fun. The first time I did it I said "oh shit" and let go of the yoke to grab my seat. :P Also kinda alarms me that if you're an instructor you've never pushed a little negative.
The reason that '427 pilots aren't blamed is that it's unclear that with perfect inputs that the plane was recoverable. We also excuse them a bit because the situation became unrecoverable in a matter of seconds since it manifested, instead of a longer time with the MCAS upsets.