Boeing 737 Max: Automated Crashes [video]
media.ccc.de
media.ccc.de
First, the engine placement means it has a non-linear control force curve, so it needs some system to compensate for that. Hence MCAS. This is because the landing gear can't be lengthened without expanding the gear bays, which would void the type certificate AFAICT.
Second, the larger size of the plane means that a single pilot cannot be guaranteed to be able to use the manual trim wheels in all flight modes. The force required is extreme, weaker pilots may not be capable of trimming the aircraft. This can't be fixed without changing the trim wheel size (which requires a new cockpit layout) and/or the horizontal stabilizer, both of which would void the type certificate.
Third, critical flight control systems need to be triple-redundant, and there are only two AOA sensors. Since the plane cannot be certified without MCAS (point 1) and MCAS can command a catastrophic failure (see two craters) it should be a triple-redundant system. A new AOA sensor would void the type certificate.
Canada stated that they would certify the MAX without MCAS and with required pilot training, if its performance characteristics were acceptable. Boeing has made no attempt (AFAICT) to try this, which raises suspicion that MCAS is in fact required for certification, which would make it a Fly-By-Wire system (and subject to appropriate regulations, requiring hardware changes) and not just a stability augmentation system. Essentially Canada called Boeing's bluff.
It's not the software that's the (only) issue. If it were, the plane would be flying by now.
The issue is that the plane was changed only enough to avoid a cert issue but to keep the plane flyable, software had to be implemented to keep the pilots and the plane in check.
So, the plane needs to be either redesigned or it won’t certify. You are correct in that Canada called Boeing’s bluff. But the software is the issue or the plane would not be flying anyways because it wouldn’t certify.
Why would a new (third) AOA sensor void the type certificate?
Clearly, moving engine pods alone is not without its risks.
Also the 737-10 does sit higher: https://www.geekwire.com/2018/boeing-737-max-10-landing-gear...
Watch the video from your link. The landing gear only extend on rotation. When it's on the ground the 737 MAX 10 sits at the same height as every other 737 MAX.
It's not that Boeing would have been unwilling to build an entirely new plane, their CEO announced that as the plan in 2011, it's that operators would rather they didn't.
Ford was selling a car in a class of it's own, at a price range and volume that was unmatched in the rest of the automotive industry at the time. Boeing is not.
No. Boeing wanted it to share a type rating with the rest of the 737 family, hence MCAS. This plane would be perfectly safe to fly if it had no MCAS and required a new type rating. Consider the 767 which has a stronger pitch-up characteristic and operates just fine. This meme has been debunked several months ago but keeps getting repeated along with the more ignorant 'the plane is inherently unstable'.
> The force required is extreme, weaker pilots may not be capable of trimming the aircraft.
This is true in all planes. In certain conditions, aerodynamic loads exceed the pilot's or even the hydraulic system's ability to overcome. Pilots are trained for how to recover from these conditions and regain trim authority.
> Canada stated that they would certify the MAX without MCAS and with required pilot training, if its performance characteristics were acceptable. Boeing has made no attempt (AFAICT) to try this, which raises suspicion that MCAS is in fact required for certification
This claim contradicts your first claim, as the authority indicates they will accept the plane without MCAS. So clearly, MCAS is not critical to safe the operation of the plane in the eyes of this authority.
Without MCAS the MAX loses the 737 type rating and becomes a commercial failure. Of course Boeing isn't going to even humour that avenue of action except as a last resort.
Please stop spreading thoroughly debunked misinformation.
If you're right and he's wrong, then MCAS is a non-critical system (augmentation, not fly-by-wire) and would require a mere software fix, which ought to have been completed by now.
Why hasn't it?
But their ultimate fallback plan if all else fails, will be to remove MCAS and have this thing get its own type rating and dedicated pilots.
https://www.seattletimes.com/business/boeing-aerospace/newly...
Note, these weren't "newly stringent" as if they've never been done before now. Worst case scenario bit flips by cosmic rays are textbook test cases in aerospace projects. That they weren't considered before then is a marked demonstration of lack of due-diligence or follow-through in enumerating the fault-tree.
GP didn't claim otherwise. GP claimed:
>> [...] so it needs some system to compensate for that.
And it does need that system - whether for safety is debatable, but it needs it for certification (not within the 737 family certification, but for certification full stop), because the FAA requires basically a linear control force curve.
>> weaker pilots may not be capable of trimming the aircraft. > This is true in all planes.
Source? I'd assume, in fact, that in most planes that is not the case - superhuman strength is not required to trim.
> This claim contradicts your first claim, as the authority indicates they will accept the plane without MCAS. So clearly, MCAS is not critical to safe the operation of the plane in the eyes of this authority.
No, it doesn't. There are three possibilities:
1. Without MACS, the plane is safe and certifiable, but not similar enough to be certified with the 737 family.
2. Without MACS, the plane is reasonably safe, but not certifiable under the specific FAA rule requiring linear control forces (though possibly under more lenient, eg Canadian rules).
3. Without MACS, the plane is not safe and not certifiable.
I think 2 is the case. 1 has been debunked, and you argue that 3 is false, too.
If you can back up the claim that 1 is debunked with a credible source, I suggest shorting Boeing stock because it means the 737 max is a complete failure, the line will likely be killed as it won’t be able to compete with the Neo, and stock price going to plummet through the floor.
Showing the strength required to trim a 737 in certain circumstances.
Yet, there has been no information released, at least publicly, as to the bare airframe flight characteristics (bare as in sans MCAS).
The reasons for the initial inclusion of the MCAS seems like it may have been related to the augmentation of the "touch and feel" of the flight controls, but we simply do not know at this point what were the reasons for the increase of it's operating envelope and authority.
> Please stop spreading thoroughly debunked misinformation.
If you have a source for the debunking, I would appreciate if you could share it. In the meantime, our best bet is to hope for one of the other CAA-s to conduct said bare airframe tests.
I suspect that one must also consider that the Boeing's PR department is busy coloring the narrative in a favourable way.
Source: https://www.faa.gov/news/media/attachments/Final_JATR_Submit...
Recommendation R3.4:
The FAA should review the natural (bare airframe) stalling characteristics of the B737 MAX to determine if unsafe characteristics exist. If unsafe characteristics exist, the design of the speed trim system (STS)/MCAS/elevator feel shift (EFS) should be reviewed for acceptability.
Observation O3.4-A: The original implementation of MCAS was driven primarily by its ability to provide the B737 MAX with FAA-compliant flight characteristics at high speed. An unaugmented design would have been at risk of not meeting 14 CFR part 25 maneuvering characteristics requirements due to aerodynamics.
Observation O3.4-B: Extension of MCAS to the low-speed and 1g environment during the flight program was due to unacceptable stall characteristics with STS only. The possibility of a pitch-up tendency during approach to stall was identified for the flaps-up configuration prior to the implementation of MCAS.
Finding F3.4-A: The acceptability of the natural stalling characteristics of the aircraft should form the basis for the design and certification of augmentation functions such as EFS and STS (including MCAS) that are used in support of meeting 14 CFR part 25, subpart B requirements.
In short, Boeing designed a full-authority flight envelope protection system, just like Airbus has. Except for the fact that Airbus uses a full triplex system (3 ADIRU-s with their own set of sensors), while Boeing went with a single source of data, treating the wetware on the seat as the pseudo duplex channel ("you are the backup", while neglecting to inform them of their role, or their potential physical inability to accomplish this, nor provide accurate force feedback in sims). Now they are trying to sell us a duplex/pseudo-triplex model with the consolation that while the beast still has half a brain (pun intended), it is at least more tame. All this while simply neglecting to tell us, the pilots and the flying public, exactly why it was needed in the first place. See O3.4-B above.
Disclaimer: pilot.
Does it fail? I will grant you this: 1) A significant number of people would refuse to fly it. 2) Pilots would need to be trained to the new type. 3) There would have to be more simulators constructed to handle the training load, and the airlines would likely force Boeing to bay for that.
OTOH: All the 737 ground equipment and gates and so forth will work perfectly fine. It seems to me that with suitable discounts, it would sell through. Not an easy sale, certainly.
Does the 737MAX really become an economic loser?
I agree with all of your corrections except this one. I've read that this yo-yo or rollercoaster maneuver was described in old 737 manuals decades ago, but then removed. It's not in the current manuals and I haven't heard anyone else claim that it was ever trained for by airline pilots, either back then or now.
I get the impression that Boeing decided some decades ago that needing to retrim without the motor and at extreme airspeeds and aerodynamic load was so unlikely that they didn't need to prepare pilots for it.
This would probably be true if they hadn't introduced a system that makes the stabilizer try to kill you, and then tied the off switch for that system to the off switch for the trim assist motor.
(A reason to be pedantic on this point is that it's important to know whether the lack of having performed this maneuver can be reasonably described as a pilot error.. although in the MAX cases there probably wasn't enough altitude to perform it anyway at the speeds involved.)
It does not qualify for a new one. The crew alerting system (EICAS) does not meet modern standards.
https://www.seattletimes.com/business/boeing-aerospace/boein...
https://www.youtube.com/watch?v=PlaMQBEg-9M
“In the course of the investigation, a new type of flight assistance system known as the Maneuvering Characteristics Augmentation System (MCAS) came to light. It was intended to bring the flight characteristics of the latest (and fourth) generation of Boeing's best-selling 737 airliner, the "MAX", in line with certification criteria. The issue that the system was designed to address was relatively mild. A little software routine was added to an existing computer to add nose-down trim in situations of higher angles of attack, to counteract the nose-up aerodynamic moment of the new, much larger, and forward-mounted engine nacelles.”
“Apparently the risk assessment for this system was not commensurate with its possible effects on aircraft behaviour and subsequently a very odd (to a safety engineer's eyes) system design was chosen, using a single non-redundant sensor input to initiate movement of the horizontal stabiliser, the largest and most powerful flight control surface. At extreme deflections, the effects of this flight control surface cannot be overcome by the primary flight controls (elevators) or the manual actuation of the trim system. In consequence, the aircraft enters an accelerated nose-down dive, which further increases the control forces required to overcome its effects.”
One pilot has to move all focus to it, without touching the other controls.
It is still baffling to me how everything, from one sensor to a control system that can overwhelm the pilots with stick forces with no sanity checks in software, got through Boeing and then the FAA.
See page 30 at 33.00
I don’t know the same about my car, which is why I’ll take it over a Max any day, and that’s why Boeing is having to PR themselves out of this mess.
"ignorance is bliss"
If you knew how much software went into a car vs. an airplane, you might think twice. Airplanes seem more complicated than cars, but software-wise they are much simpler. Cars have millions upon millions more SLOC than airplanes. You think MCAS is bad, how about cars that have sudden loss of steering, emergency brakes that mysteriously engage, or a throttle that can't be disengaged?
Serious design flaws in airplanes are these big dramatic events. Serious design flaws in cars pop up in the news every day, and we just ignore them [1][2].
[1] https://www.consumerreports.org/car-recalls-defects/mazda3-r...
[2] https://www.consumerreports.org/car-recalls-defects/more-car...
But one-off car fatalities that kill 1-3 people happen regularly and they add up. The self-driving variety pop up with the highest visibility but if you go searching you'll find tons of accidents where brake failure at highway speeds cause a fatal crash.
I do concede that distracted driving and alcohol play a much bigger role in the large amount of car fatalities than software flaws. But I still stand by my original assertion that you are more likely to die due to the effects of a software flaw in your car than due to a software flaw in the 737 Max.
Yes, there's the self-driving stuff, and there have been some egregious examples, but those systems also save lives by preventing accidents. Lane departure warnings, automatic braking, and electronic stability control all, on the balance of things, make driving much safer.
The whole point of my comment was to put to bed the irrational fear of flying. You are still more safe travelling long distances in a faulty flight system such as the MAX than you are by car. There are just too variables to account for in cars, one of which includes increased software complexity.
Secondly, what are the exact figures you're using to show that the 737 MAX is safer than cars? And now compare it to other planes, the more realistic comparison? I'm not taking planes to places that are within driving distance. The 737 MAX was waaaay less safe than other planes.
I agree with you, that's exactly what it was. All of the components worked as designed. But it's pissing against the wind on HN to say that.
[1]https://www.cnn.com/2010/WORLD/asiapcf/02/04/japan.prius.com...
Braking systems have been partially modulated by software for decades, i.e. ABS, TCS, ESC.
Additionally, other software controlled systems can induce mechanical issues. For example, in the case of the Toyota unintended acceleration debacle, an engine at WOT typically does not produce vacuum. However, power-assisted brakes almost universally are vacuum-powered. So, if the software-controlled throttle gets stuck wide open, you lose power-assist to the brakes.
https://users.ece.cmu.edu/~koopman/pubs/koopman14_toyota_ua_...
>how about cars that have sudden loss of steering
Citation needed. I've never heard of a car having this problem, and it's generally impossible because there's a mechanical link between the steering wheel and the front wheels.
>or a throttle that can't be disengaged?
Citation needed. I've never heard of this happening where it's been proven to be real and not a publicity stunt. All the problems with "unintended acceleration", including on Toyotas a while back, have been shown to either be people using aftermarket carpet mats, or even people faking it. What's more, turning off the car in an emergency is not hard, even in push-button-start cars. Now of course, we can blame some wrecks from faulty systems on poor driver training, drivers who just aren't very good, drivers who can't handle an emergency, etc. This simply does not apply in an airplane: pilots go through a LOT of training to get that job, so if they crash anyway, that points to an unforgivable mistake in engineering or manufacturing.
https://www.usnews.com/news/national-news/articles/2018-09-1...
https://www.ncconsumer.org/news-articles/ford-issues-recall-...
As I understand it large trucks existed prior to power-assist, they just hired big strong chaps who could wrestle the steering.
We probably don't want (and Boeing doesn't want) to make 737 Max certification have a "Physical strength check" where you need to exert so-and-so much turning force for so-and-so many seconds or you can't fly their plane. So probably trim wheels need a re-think, whether that happens as part of the 737 Max work, its immediate aftermath or not for years because this incident scares manufacturers away from changing anything about trim.
Seismic shifts in safety considerations do happen, we haven't seen the last of them. And they aren't always ultimately for the better. Titanic had a few effects, many of them really good, but one notable one is that it pushed the narrative that you need to provide and test a LOT of lifeboats on an ocean liner. Titanic, as you can probably all recite, did not have enough lifeboats. But in practice lifeboats are very much a last resort for an ocean liner captain. You've got a whole lot of civilians who are incompetent at sea at the best of times, probably panicking and now you're trying to successfully get them into smaller boats under supervision of a relatively smaller number of crew. Some of them are likely to be injured or even die. A ship's master would prefer _anything_ over putting passengers into lifeboats, except them all drowning. Almost always the sensible course of action, taken by the ship's master, will be to take the still working ship to any port and unload the passengers. Yes even if the ship is somewhat on fire, or has grave engine problems, almost anything except actually sinking right now.
Meanwhile just owning the lifeboats means your crew have to keep testing them and servicing them, each time also has a chance of injury or death as crew fall into the water, boats fall on the crew, and so on. So owning a suite of lifeboats for your ocean liner (which you weren't planning to crash into an iceberg at any time) is probably a net negative in terms of injuries and deaths.
Actually, I think they absolutely should. And then it should be made illegal to have a plane that has any such requirements, so these planes should be deemed unairworthy, and Boeing should be forced to scrap them. Either that, or female pilots should be able to claim discrimination, and every female or otherwise not-strong-enough pilot should get a free lifelong chief pilot salary as part of the settlement.
Basically, this plane should never have been built. It's a 1960s design, and because of crappy regulations that allowed this, Boeing kept making this 1960s tech because it was "grandfathered". Newly-built planes should not be allowed just because they were OK 50 years ago, when they aren't good enough according to modern standards.
Steer by wire is becoming much more common. It’s already in luxury cars and, like most features, will probably eventually trickle into economy car designs
I did see one source indicating a roughly 25% increase in steer by wire by 2026, but it’s behind a paywall so I’m not sure how good that source is. According to a Tesla forum, there’s still a mandate for mechanical linkage
EPS has been on production cars now since the 1990s, and I've never heard of any software problems with those at all. In fact, it's probably been more reliable than hydraulic systems since it doesn't have so many moving parts, just an electric motor, and no hydraulic fluid to leak or get contaminated (due to not being replaced on time, a common thing for people to skip on maintenance).
Steer-by-wire is a no-go for now, because it's illegal to not have a mechanical linkage. That might eventually change when we get driverless cars, but there's no sign that those are coming nearly as quickly as many people used to think; there's just too many problems with them.
“Recalled products do not contain the updated software that mitigates the effect of the condition. When the system voltage drops below 8.8 volts for more than 1 second — e.g., during low-speed turns — EPS assist is disabled”
Honda has had similar recalls.
I don’t know if that can be used to claim software caused the initial hazard but does indicate software is used to mitigate safety issues with the implication that software failures can lead directly to hazards
This isn't very different from old hydraulic-assist cars that also had the assist die or be too low when there was some problem (fluid too low, pump failure, belt failure, etc.). Was it ever a big problem? No, not really. If your power steering fails in a parking lot, it's a pain, but you're already barely moving, so you just stop. At worst, you might have a minor fender-bender.
I don't see how this is a software problem; this is an electrical problem. The only software issue here is the decision to shut down the EPS instead of bringing it back online when the system voltage goes high enough.
Personally, I'd say the fundamental problem here is actually the fact that cars still have 12V electrical systems, and batteries that are really meant for starting only, not for continuously supplying heavy electrical loads (like EPS). Carmakers should have gone to 42V or 48V systems ages ago.
I don’t know the specifics of the system safety analysis but if the software is used to mitigate a hazard, it’s usually considered safety critical. In this case, if it shuts the EPS off, or fails to bring it back online, it it would significantly affect the vehicle handling dynamics. Again, I don’t know their classification scheme but I would assume the steering is a safety critical system. Some reports claim the vehicle lost all handling control, but I’m a little skeptical of that claim.
In any event, I wouldn’t consider it no issue. Recalls cost a lot of money. In the GM case it affected 1MM cars. I didn’t look up the cost of each fix, but I wouldn’t be surprised if it cost nine figures. I doubt they would go forward with a recall of that magnitude for a trivial issue.
I could see the same rationalization for MCAS. The system safety analysis didn’t claim an MCAS failure was catastrophic and they already had a procedural mitigation in place if it did fail. It wouldn’t take much to convince someone that such a recall fix was no big deal. This is part of the problem with systems using safety critical software
And, as you pointed out, it was a systems interaction problem. Losing power steering at speed isn't great, but it's recoverable (maybe less so if you're weak and you're driving some big stupid SUV, rather than a small economy car), and losing power brakes is also bad but recoverable because you have enough vacuum in the system to do a full stop (but only 1 usually), but tie them together, at speed, and also (worst of all) lock the steering wheel, and you have a recipe for disaster. This is far, far, far worse than losing your power steering assist at parking-lot speeds.
This is the traditional way to deal with system hazards. What has been talked about is the need for changing the way we think about software failures on safety critical systems, distinct from traditional failure mode approaches.
"The result is that software-related accidents involve a new type of accident, which can be called a component interaction accident: None of the components fail (all satisfy their specified requirements) but the problems arise from dysfunctional interactions among the components."[2]
I'm not familiar with the specifics of that case, but having a low system voltage is more likely at parking lot speeds because the alternator isn't turning very fast, whereas at speed the alternator should be generating enough power to run everything including EPS, but maybe they underspecced the alternator, so I can see it happening. Still, losing your power assist at speed is still dangerous of course, but it is recoverable, and it's nothing like having a critical system fail in an aircraft. Failures in cars are always safer than in aircraft, because you're already on the ground. This is why safe design is so important in aircraft: if something goes wrong in a car, it might result in a wreck of a few vehicles at worst (multiplied by the number of cars experiencing that failure), but many times tragedy is avoided because the driver just needs to steer away from traffic and avoid running into something too fast. In an aircraft, there's no such thing as a "fender bender"; crashes are usually fatal, and they usually carry dozens to hundreds of passengers.
>Recalls cost a lot of money. In the GM case it affected 1MM cars. I didn’t look up the cost of each fix, but I wouldn’t be surprised if it cost nine figures.
That seems high: you're assuming each car cost $1000 to fix there. That's a lot of money to fix one component; at that volume, the part probably cost well under $100 each, and as another poster noted, the dealer labor required was pretty small.
I was estimating at $100 per fix (since it's just the labor cost of software). At roughly $120 per labor hour multiplied by 1MM vehicles is where I came up with the nine figure mark. At $1k per fix, it would be in the 10 digits. Regardless, it was overshot and I corrected it with the details in a reply (since I couldn't edit the original). It only comes in at 0.5 hours per fix. Not chump change but the decision to fix it may also have been influenced by the Toyota accelerator and GM ignition recalls that got a lot of press.
Many modern cars have computer control of brakes, accelerator and even steering, so a software flaw could stop you in the opposing lane just as you start to pass a car, or accelerate and steer you into a bridge pillar (and since that car was already steering the car before that, the driver may not be able to react in time)
In addition, there's no evidence that Airbus planes have design flaws as bad as MCAS. So why fly on a 737MAX when any other plane out there is safer?
https://en.wikipedia.org/wiki/Qantas_Flight_72
Edit: To be clear, while this was 10 years ago and noone died, this incident seems to me to be a bit worse than the issues with the 737 MAX in that with the A330, there is no shutting off the systems that caused this issue, as they are part of the flight controls. Fortunately the causes were investigated and while the exact cause of the issue was not identified, the computer systems were updated to deal the fault scenarios identified in the investigation.
In a fly by wire aircraft.
Well no one can fly one right now as they are all grounded. However, once they get approval for a fix from all countries, the airplanes get updated with said fix, and the pilots get whatever training required for the fix and thus can start flying again, why not fly them? Presumably, that failure type should never happen again and its record seems fine outside of this 1 problem.
That's a big assumption. The planes are already unmanageable, even if MCAS is fixed: human pilots aren't strong enough to turn the trim wheels manually in an emergency.
>and the pilots get whatever training required for the fix
I don't see how this is possible without forcing pilots to get a totally different type rating for this aircraft. That's the whole reason they put MCAS in there in the first place: to avoid a different type rating, which would require an expensive add-on certification.
With all the different government agencies going to be manually inspecting the updated plane themselves, the MCAS problem is going to be put under a microscope by dozens of different countries and if they do approve it and deploy it, then I am going to take there word for it as having mitigated the MCAS problem and won't care about stepping on a 737 max as its track record outside of this 1 problem is fine.
If it does not get approved or deployed, then who cares because you won't even have the option to fly it as it will stay grounded. Regardless of what happens, checking what plane I will be flying on will not impact my decision when choosing flights.
What if it does get approved, but only by some countries? So, for instance, suppose the US approves it, but China and the EU don't? Then, it probably won't stay grounded, because this plane is usually used for shorter-distance travel. Southwest Airlines, for instance, exclusively uses 737-type aircraft, and all their travel is domestic US, so an EU ban wouldn't affect them at all.
I for one wouldn't feel too confidant about the FAA approving this plane with the EU regulators refusing to, considering what a criminally-negligent job the FAA did in approving it in the first place.
Operation of the trim wheel and the forces acting on it are the same as the 737 NG. If this worries you, you shouldn't take any 737.
The wheel in that video can not be turned manually because of the aerodynamic forces acting on it. Pilots are trained extensively to recognize a runaway trim condition and stop it before it gets to that point. At lower angles a roller coaster maneuver can be used to turn the trim manually.
The MCAS was definitely poorly designed but everyone is downplaying the poor pilot response and maintenance issues involved with the crash. Lion Air pilots flew a plane with a stall warning going on for a full hour instead of landing ASAP. Then when the plane got to the ground, the company saw it fit to fill it up with people again and fly it with a critical system malfunctioning due to unknown causes.
They dodged responsibility because boeing had a serious design issue but their behavior was criminal, even more so than boeing. I wouldn't fly any lion air plane.
The speaker talks about trimwheel behaviour. Pilots train for runaway stabilizer trim, but that's continuous movement of the trimwheel, faulty MCAS looks much like regular speedtrim. Also, activating electric trim activates another round of MCAS. Obviously you shouldn't take Lion Air, but after this talk Boeing doesn't look safe now either.
The exception being modern fly-by-wire planes that simply don't have an option of manual override.
The speaker talks about trimwheel behaviour. Pilots train for runaway stabilizer trim, but that's continuous movement of the trimwheel, faulty MCAS looks much like regular speedtrim
Empirically, the Lion Air plane exhibited the same MCAS behavior on its last (successful) flight. So it's at least possible for pilots to recognize it as a runaway trim and act accordingly. Obviously you shouldn't take Lion Air, but after this talk Boeing doesn't look safe now either.
After reading the Lion Air report my conclusion is that the MCAS was poorly designed but it's also an easily fixed problem on an otherwise safe design and there's so much focus on boeing that they will take action and fix it. Meanwhile nobody cares about Lion Air and if they keep flying broken airplanes eventually they're going to kill more people, with or without MCAS.Also, the AoA-vane was replaced with a faulty part, and never retested after install if I recall correctly. A procedure complicated by the fact the plane would have had to have been started, shutdown, then restarted since the Flight Computer switches from side-to-side each flight.
So a maintenance tech may have accidentally tested the wrong computer assuming the documentation wasn't up to snuff. Can't say as I've seen that part of the documentation myself; but considering they left MCAS out of the pilot docs, I somehow doubt that it was greatly elaborated on in the maintenance docs as well.
[1] See http://avherald.com for example.
Zero 737 Maxes have crashed on US soil. The same cannot be said of other 737 types.
There's the NY Times Magazine article that reminded everyone of the word 'airmanship' [1] although it wasn't terribly well-received [2], [3] by some other pilots.
If you don't want to read all those, basically pilots in richer countries might be more likely to also be private pilots and more familiar with how an aircraft 'feels' that translates to a better sense of what's happening in larger aircraft. Combine a lack of that in poorer countries with the dumpster fire of Boeing's choices, crap replacement parts, and 'limited' training regimens and you have a fatal error chain forged.
The criticisms focus on the idea that heroic pilots who could recognize and avoid the situation probably aren't the norm. Further, there's often prejudice against pilots from developing countries even when they are competent; neither of these excuse the systemic failure and getting to the conclusion of "but for the pilots the crashes wouldn't have happened" is somewhere between insulting and reductive.
[1]: https://www.nytimes.com/2019/09/18/magazine/boeing-737-max-c... [2]: https://medium.com/@elanhead/the-limits-of-william-langewies... [3]: https://www.planeandpilotmag.com/explosive-new-york-times-st...
My fleet sums to ~100k trips and zero (human) deaths. The 737MAX can't claim such a low number of deaths per trip.
Regardless, we can choose our metrics to paint whatever picture we want to paint and any metric we choose is of little use anyway because it's an apples to oranges comparison.
737 Max had ~500K death-free trips before its first crash.
According to https://randy.newairplane.com/2018/05/22/737-max-a-year-of-s... the Max had only made 41k flights total in May 2018, six months before the first crash.
Only two 737 MAX have ever crashed (both outside of the US), so the 3.08 figure is an extrapolation, not necessarily reality. After the software update it might have gone another 500K flights (or more) without a crash, leaving the figure at 2.0 (or smaller).
Let's say you need to travel from NYC to San Diego.
Let's assume a car death rate of 1.25 deaths per 100 million vehicle miles (a figure that popped up in Google). But that includes motorcyles and pedestrians, so let's play it safe and call it 1 death per 100 million miles.
By now we are comparing apples (chance of death by trip) to oranges (chance of death per mile traveled) but let's press on.
Distance from NYC to San Diego is 2,800 miles. So your chance of dying en route to San Diego is about 1 * 2,800 / 100,000,000 or ~30 in a million chance if using a car. Whereas with the MAX it is ~3 in a million (if you take a direct flight), or an order of magnitude more safe.
[1] I found 11 fatalities per trillion miles for planes, and 12.5 fatalities per billion miles for cars (in the US).
It's hard to find a good statistic that would make modes of transport comparable. But if I'd pick one I'd pick time spent (are 10 hours on a plane more or less safe than 10 hours in a car)
I'd be more interested in knowing where FATAL accidents occur, on the suspicion that most people do not live on highways and local streets are traveled at lower speeds.
edit: nvm I found it on wikipedia, for United Kingdom 1990–2000: https://en.wikipedia.org/wiki/Aviation_safety#Transport_comp...
air/car deaths/h = 4.2x so... on this metric, not like "1000x safer"
That number confused me (I expected to be zero point something).
For the reference, the actual numbers in Wikipedia are: deaths per billion hours traveled: air = 30.8 ; car = 130
30.8 / 130 ~ 0.24
Take that 4.2/20 and you have 0.21. Or flip it around the 737 Max is 5 times more dangerous than a passenger car. That's drunk driver territory.
it’s rarely the CAR that kills you. It’s other drivers or your own negligence.
In the 737max case it’s Boeing that killed you.
Airplanes are faster than cars, and the average trip is longer. So, even if the pax fatality rate per distance is much better for aircraft (a factor of 200 to 1000, say), the fatality rate per trip is not that much better (a factor of 2 to 10, say).
Some more notes:
- That is for part 121 aviation (airlines). General aviation fatality rates are much worse (you're 15 times more likely to die in a small plane than in a car for the same distance, and 250 times more per trip...)
- An airliner also carries many more pax. The above numbers are per pax; if you base it per vehicle, then a plane is only about 5 times safer than a car for a given distance, and about 20 times more likely to crash than a car per trip.
- About 4% or so of all B747 or A300 ever built have been complete hull losses. (Newer planes are safer, presumably, but also haven't been around that long, so the statistics are not entirely trivial to compare.)
That doesn’t make a defective flight system a greater or lesser problem. It’s irrelevant.
Aggregate data is tough to interpret anyway for a cross country trip. Traffic deaths per 100M miles vary from 1.83 (South Carolina) to 0.54 (Massachusetts). Also, motor vehicle aggregate numbers include all trips — if you compare common carriers, busses and rail are dramatically safer than private cars.
Oh, I totally agree. I was just trying to put into perspective the fact that even defective flight systems are incredibly safe and that our fear of flying is often irrational...
That sounds like something lawyers would study rather than engineers.
compute it per hour traveled and see
So, with all the lag in getting the aircraft into service, its plausible that in the next 10 months the type could rack up 500,000 flights, since thats just a little more than 4 flights a day per aircraft on average.
I suppose someone with full access to data from e.g. FlightAware could try to see how many total logged flights there were.
They perform tons of analyses like FMEA on their processes, their designs, then they have tons of SimIL/SIL/HIL testing partially derived from those analyses to verify their safety case, and at almost every layer of the development lifecycle they do tons of fault-injection oriented verification.
The MCAS system went through an amount of rigor that dwarfs anything applied to typical software or IT infrastructure, but the issue persisted due to fundamental underestimation of risk associated with this kind of failure and a confusingly terrible design & implementation from a functional-safety and human factors perspective.
As I've mentioned elsewhere, more self-inspection at packing plants, combined with higher line speeds "for worker safety," is why I recently went vegetarian.
I think the mismatch may be that these are all-manual designs, and the 737 is much larger now than when it was first designed, plus the first design didn't have automated systems counteracting your inputs.
The 777 got a similar upgrade that did include a new wing design.
Ultimately Boeing is looking to introduce an all-composites design that fills the 737 and 757 roles, but airlines desires for crew commonality might push that back.
Though note the A320 is a newer design than the 737; the A320neo as a result didn't have the big problem of the 737 MAX: because its landing gear was always longer, because it was always designed for high-bypass turbofans, it could easily fit the larger engines under its wings without having to relocate the engine mounting.
The 737 MAX is a world away from the original 737 (hell, the shortest 737 MAX is 6.6m/23% longer than the original 737 design!), whereas the A320neo is much, much closer to the original design. The 737 MAX has ~80% parts commonality with the previous-generation 737 NG, yet alone the original 737; the A320neo has 95% with its predecessor, which _is_ the original design.
Probably even earlier. The trim wheels in the Boeing 707 look pretty similar to the 737.
There's a very obvious shared design between the 707 and 737 cockpit that goes beyond anything you could attribute to general cockpit design.
https://i.pinimg.com/originals/1b/67/96/1b67964cc0e7c178bb8b... (707)
https://cdn.jetphotos.com/full/6/22047_1484863414.jpg (737-200)
https://airbus-h.assetsadobe2.com/is/image/content/dam/chann...
It has trimwheels.
Similarly, when I consulted with one of the major airlines (although not in flight operations) I was told that many of the physical specifications of airplanes were driven/limited by airport gates. That is, wingspans, fuselage curvature, door height, etc. need to be within certain ranges so that it could use existing gates unmodified. This was one of the biggest issues with adoption of the Airbus A380...airports had to build new gates just to support them. I understand that is an issue with the 737-MAX: to place the much larger engines in a place that wouldn't screw up the balance (e.g. under the wings instead of out in front of them) would make the plane inconveniently high off the ground.
And even that may not be enough.
It's quite plausibly physically impossible if the pilot happens to be less strong than this one, or if the aircraft's situation is worse than this simulator's.
In particular, the Ethiopian flight was in extreme overspeed (if I recall, past the max safe structural speed for the plane!), which increases all of these forces. I'm not sure whether that was being modeled by the simulator, or if the simulation's model of trim wheel force is a correct one.
There's certainly no guarantee that a pilot can produce the force required to relieve aerodynamic load on the stabilizer here. It's a purely mechanical system.
Now, would you point your nose down knowing that you may not be able to point it back up again?
This obviously wouldn't work in cases like the Ethiopian, where the plane had very little height over ground due to the high mountains around the airport.
Edit: the point isn't that the maneuver had prevented the accident, but that its existance in the flight manuals shows that it was known that the trim forces could be higher than what the pilots could apply to the trim wheels.
https://nymag.com/intelligencer/2019/04/what-passengers-expe...
(Still, they could have asked ATC for an speed reading or used other measurements to convince themselves that it was safe to slow down.)
Being reluctant to push the nose down when in a bad situation would cause pilots of any aircraft to fail their first hour of stall training.
It's more worrying that, since the procedure was removed from manuals and training, the pilots might simply not have realized that it would help.
While the Ethiopian crew did have the overspeed warning going off, it was well below the "do not exceed" and "max dive" speeds.
I'm not sure whether that was being modeled by the simulator, or if the simulation's model of trim wheel force is a correct one.
It wasn't. Boeing's already admitted that their simulators don't correctly emulate the forces on the trim wheel.
Climb-out from Adis Ababa (a hot and high airport) means you've got precious little excess in terms of sacrificial power to begin with. The MAX 8 could only take-off at all due to an unusually long runway as I recall.
That simulation would have ended in a crash if they didn't abort it.
So the pilots strength did not seem to matter and the situation was about as bad as it gets.
We've seen it again and again: Industries do not "self-regulate." How many people have to die before the "REGULATION BAD!" people are put in their place?
As mentioned in the talk, the problem is, that reality differs, and the MCAS actions don't appear to the pilot like a normal trim runaway. Actually, the day before the Lion Air crash, the machine already had the same problem, but the pilots (as the story goes due to the advice of a third pilot present) did activate the cut out switch and solved the problem.
That still doesn't explain why Boeing didn't implement at least consistency checking with the other sensor. And of course, we know now, how wrong Boeing was in their assumption.
Unfortunately the next day, the other crew did not do this. And on the Ethiopian Air flight, they did activate the cut out switch, but way to late and didn't regain control of the machine, as it was out of trim too far.
Had they left it cut out, they would have been able to keep it under control, had they adjusted the trim and then cut it out, they would have been in a decent position to come back and land. It will be interesting to see what the investigation finds about why it was cut back in and then left.
Flight systems (fuel feed, hydraulics) assume a gravitational vector toward the bottom of the aircraft. Flying inverted would starve fuel and hydraulic systems.
1. A purchase option for an instrument/indicator that shows discrepancies between Angle of Attack sensors on each wing.
2. In the KC-46A Pegasus it seems the pilots are able to override the MCAS system by simply pulling on the controls.
For me, #2 would have been an interesting discussion as perhaps Boeing chose not to re-use this system because it might delay certification. Imagine being the person who (may) have made the call to create a worse software than something that existed to sneak past compliance.
From the 767-2C type certificate:
> The Boeing 767-2C has not been evaluated by the Flight Standards Board. No pilot type rating or training, checking and currency requirement determinations have been made.
Note the only 767-2Cs built were to certify the type, no airline has ordered the freighter aircraft.
For me, in a crisis with a lot of burning questions, one I haven't seen raised much is: who changed the MCAS behavior after the FAA "saw" the first version? Someone decided this should happen, and someone implemented it (perhaps the same person). Forget the C-suite for a moment; someone in middle management made this call. Shouldn't they answer for it?
When stuff like this happens, it's a process issue, not an issue with a particular engineer. It's human nature to try to assign blame to people and that's why it's so important to avoid that. Whatever process created the flawed product is where the blame lies.
Somewhere in the group that produced MCAS, there's a process to permit changes to be submitted, reviewed, accepted or rejected, implemented and tested along with the documentation produced at each stage.
Maybe that process is broken, maybe it isn't. From the outside we can't tell. However, as responsible professional software developers what we should do is understand that these are system problems and not just look around for someone to pin the blame on.
These are systems problems, I fully agree, but they aren't only systems problems. The systems in question are people. They have minds, personalities, and agency. Eliding this - sorry for saying so - makes phrases like "whatever process created the flawed product [...]" sound absurd, borderline callous.
I hate to resort to what by now is a web forum trope, but would you look the MAX victims' families in the eye and say, word for word, what you wrote above: "No, 'they' shouldn't" be held to account? Come on dude.
[0] https://www.seattletimes.com/seattle-news/times-watchdog/the...
To get a list of mirrors for a file, copy the URL of the file you want to download, and append ?mirrorlist to get a list of mirrors.
For example, here's the list of mirrors for the video in 1080p MP4 format: https://cdn.media.ccc.de/congress/2019/h264-hd/36c3-10961-en...
I had the same issue with another link posted today where the video wasn't loading at first. I downloaded it from a mirror using wget at over 200 Mb/s.
EDIT: I guess only option is to download the video file and switch the audio language as browser's player cannot do this.
EDIT2: from html - there are multiple sources, english is the first one, though player starts automatically from the second source. Link to english video: https://koeln.ftp.media.ccc.de//congress/2019/h264-hd/36c3-1...
EDIT3: after couple reloads and waiting couple dozen of seconds native html video player have switched to some custom CCC player with settings option available. Probably needed some time before JS fully loaded and did it's job. Apparently /u/lovehashbrowns had loading issues, so this sounds related. Maybe CCC is getting hug of death from HN, Reddit or whatever.
Warrant against hyperbole: I'm not against the idea of self driving cars. In fact I have a Tesla and use auto steer daily.
Car manufacturers already have to make calls not only about whether these features are worth it for the greater good, but also whether or not it will make the car too expensive.
Or how the extra strong glass they use prevents emergency responders from quickly getting through in case of emergency?
Or unintended consequences created by instability and regression in Neural Network based self-driving systems after an OTA update?
It's happening every day; to not overly pick on Tesla, Volkswagen, Nissan, and BMW were caught cheating in one way or another on emissions. Takata using substandard materials in airbags.
Don't have the links on-hand, but these have just been a handful of what I recall over the last 10 or so years.
The problem I can't figure out is how to get people as in an uproar over something less dramatic than an aircraft crash to properly signal to industry that inferior quality is not acceptable.
This is all business as usual apparently. I never felt comfortable or like I was even a good fit in an environment where apparently success is gated by how much you can get away with not having to disclose, and how much scrutiny you can avoid.
It's actually caused me quite the crisis of faith as a contributor to industry in general. At some point, no matter what level I'm at, someone is going to make a decision to abuse something I put in place for them.
What exactly does that leave the responsible course of action as for someone who is opposed to furthering unethical business by facilitating it via automation? How does one effectively conduct themselves so as not to become an unwitting accomplice via obfuscating skeevy business practices through automating them? I'm not satisfied with the answer of "just do your part, and get paid, the chip is on someone else's shoulder". I've spent too long watching industry do what it does to be able to realistically anticipate any company doing things the "right" way by default. I simply can't entertain Hanlon's Razor anymore. Not when 2nd and third order effects of decisions are so rarely taken into account by those around me.
I sure hope I figure something out, or the new year is not going to be fun... Sorry for the digression... Your question has just been related to something that has been weighing heavily on my mind recently.