but none quite like this one.
but none quite like this one.
https://www.thejournal.ie/us-ireland-boeing-4538567-Mar2019/
It was appropriate, I think, for the FAA not to ground the fleet after the first crash. It was also arguably appropriate for the FAA not to ground the fleet immediately after the second crash, but then after some time when it became apparent that the failure mode was sufficiently similar (as they did).
However, what has emerged since then certainly damaged the reputation of the FAA. But it was not a matter of a few hours, it was a matter of careful investigation and evaluation over months.
If true, that would indicate these pilot reports were not given the full scrutiny that they deserved.
Sure, those things take time, but a more decisive action should have been taken sooner.
It might not justify a full ground but at least it should have justified a very strongly worded Advisory Notice to pilots (not sure of the specific nomenclature for this document) also the AOA disagree light should have been made default ASAP.
So no, FAA has a lot to blame here.
"Peter Defazio, the chairman of the House Transportation Committee, said an FAA analysis following the Lion Air accident but before the Ethiopian Airlines crash concluded there would be 15 fatal MAX accidents if there was no fix to MCAS. DeFazio asked Dickson why wasn’t airplane grounded then? He did not have an answer."
https://leehamnews.com/2019/12/11/faa-no-max-certification-u... (I think the first report was in the WSJ, but that's behind a paywall)
The last one also happened in SEA and had some initial duelling finger pointing so it worked well as a PR gambit to be the first to block it.
Especially in the middle of a trade war involving product quality issues and Boeing is the closest thing to a US state run aircraft manufacturer. It’s always been a beacon of American protectionism well before the recent administration.
So basically there was a ton of political will potentially involved here.
The DC-10 cargo door issue is probably the closest thing. Took two accidents, 346 fatalities and a House of Representatives investigation to get the flawed design fixed: https://en.wikipedia.org/wiki/McDonnell_Douglas_DC-10#Cargo_...
Is the Boeing mistake really that bad, or is it because this is the first such aviation design mistake to happen in our post-2010 everyone-is-online world? Remember that the tails on 737s used to just...fall off back in the '90s.
For the record, I don't think the 737 MAX should have ever been cleared to fly with the current version of MCAS. But I can't help but believe that there had to be some boneheaded designs in the past that cost hundreds of lives that we just don't think about today.
In any case, I hope Boeing has learned from this and revised its engineering processes to go back to its previous prestigious roots. I also hope against hope that we will finally see some executives go to prison for approving this.
There have been plenty of others in the past that do not detract from the magnitude of this one.
Then the 737NG went on to have the best safety record of any plane ever. So while the MAX problem is pretty bad, and social media vastly complicates the PR angle, there is precedent for recovering from this. Certainly with as many MAXs as have been built there is enormous incentive to get it fixed. It's not realistic to expect them to scrap the planes.
They wanted this airframe to be able to do something it was never designed for. Instead of redesigning it from the ground up, which costs money both for development and for recertification, they tried to correct the problem in software.
They didn't want to have to retrain pilots, so they pretended nothing really changed, again through software.
And of course FAA testing is expensive, so instead the FAA blindly trusts Boeing.
So a plane that should have been more thoroughly redesigned, recertified, with pilots retrained, got none of those things in order to save costs, and the FAA just blindly trusts Boeing that it's okay. Boeing clearly betrayed that trust.
It's not just a single honest mistake, it's a policy that drove everything towards this mistake. I think that's why a lot of people are so upset.
Boeing bears a lot of responsibility but taking Boeing to task without taking a look at the system in which it operates seems short-sighted.
My cynical view is that little will change in this era.
The MBA piece of it is why I'm cynical. "Ho-ho-hold on one second. This installation has a substantial dollar value attached to it." --- C.J. Burke "Aliens"
The context is airbus has an advanced and fuel-economic model that was eating Boeing market share. Boeing decided to produce one more version of the 737 model - it fit the category and as a fuel-efficinet "drop-in replacement", it was very competitive but was rather aerodynamically unstable. So Boeing added a software system to compensate but didn't tell anyone, didn't make it dependent on redundant sensors and basically produced a plane where, once the facts were all out, it became obvious it could never fly again - not because it could never be made safe but because making safe would involve admitting how flagrantly you initially skirted safety. No one flies on the "once this was utterly unsafe but now we've fixed it" plane if they really have fixed it.
Everything about the plane was super advanced but cheap-as-could-be, including the software. But by that token, none of this seems the fault of "software culture", indeed, there's been no implication that the software was at fault in the crashes, just the total shitshow design package, which was indeed the fault of finance and management pushing this approach through.
It had two pitch sensors but each is paired with a single computer. There was an optional add on to use both sensors in some way but this is unreliable as well since you don’t know which is right. It was when the plane was flying with the failed sensor (every other time since only one sensor failed) that they ran into the problem.
At least from my readings of how you are supposed to build robust systems from unreliable parts, this is a terrible way to design a system.
See https://www.seattletimes.com/business/boeing-aerospace/faa-c... for info on the sensors.
Search for Jim Gray and fault tolerance on how to build reliable systems from unreliable parts. You need redundant parts with voting (which implies more than 2 sensors and more than 2 computers), error detection, etc... Supposedly the Space Shuttle computer systems were designed right although much of the rest of the Shuttle wasn’t designed right.
The Boeing way relied on the pilots to compensate for mechanical or software failure. Unfortunately, they seemed to willingly choose to not inform pilots of MCAS and there seemed to be failure scenarios where recovery is difficult.
Lastly, I think it is part of the job of a software engineer to push back on requirements and designs that don't work even if it is a failure in the system. Falling back to built as spec'd isn't worth of being called engineering.
As far as we know the MCAS behaved exactly according to specifications. All of its flaws seem to be intentional (e.g. only using one AoA sensor, not being easy for the pilots to disable, not being explained to the pilots).
On the 737MAX crashes the single angle of attack indicator being used as input to the MCAS malfunctioned and in response the system set about repeatedly forcing the plane into a dive with no clear indication of why this was happening. Compounding this was the utter lack of training on the MCAS system, which wasn't even mentioned in the pilot manual or IPad-based training that was also used by US airlines.
There's a world of difference between these accidents.