Boeing Backs Simulator Training for 737 Max Pilots in Reversal
bloomberg.com
bloomberg.com
Translation: Safety is not our highest priority. It's up there, but profitability is higher.
That’s exactly what I would hope pilots experience.
Southwest has had three fatalities in 48 years of operation, and in only one of those was pilot error a contributing factor, so saying their pilot training prioritizes profits over safety is unfounded snark.
"Because MCAS is only designed to operate in rare conditions while pilots are manually flying, pilots should never see the system in operation."
Unless there has been some change other than to MCAS, the manual trim wheels are still the only option to correct runaway horizontal stabilizers.
I have a vision of... dissimilar sized gears, or something...
What MCAS added was that it could keep reactivating. You got what looked like runaway trim, stopped it, and a few seconds later MCAS would kick in again. Each cycle of this could end up accumulating net trim until you got into the high force region and could no longer manually turn the trim wheels.
In addition, I believe MCAS itself has been modified. I have not seen a clear description of the changes, but they might include additional redundancy, rejection of improbable data, warnings that there are these problems, warnings whenever MCAS activates, restrictions on how much it can change the trim, and a cutout switch for MCAS that keeps the electric trim functioning.
In the worst case, manual retrimming with the wheels is still the last resort. I have seen it suggested, by sources generally considered reliable, that (prior to the Max) the need for the manual trim has been so rare that its use is not part of simulator training for any 737. I do not know if that will change, but if so, it would seem to raise the question of whether pilots of earlier variants also need additional training in its use (I would guess that it is most difficult on the largest and heaviest variants.)
great. that's confidence inspiring.
commercial simulators are designed to work 18 hours a day, 7 days a week. you can use them more, but eventually you will fall behind with periodic maintenance and certification testing.
A single sensor failing and causing unlimited automatic shifts in pitch is a nightmare I will not fly on.
HN folks here seem hesitant to say this.
But without the dumb ability to do repeated activations it would've been a much less severe problem.
The error was in the specification.
So in this situation, the claim is that braindead contractors mechanically implemented something to spec by force of law? Sure, then whoever designed the logic is accountable.
In 99.9% other environments, the distinction is collapsed because the implementor typically has responsibility to design sub-component level logic correctly, to high-level requirements, but also to overall business need and in service to even higher level project goals, and the team that designed the logic is also implemented by the same team.
thus the invention of a discipline called 'systems engineering'..
i would say in 100% of engineering development, the design is done as a system, and specific requirements are allocated to design elements (like MCAS software). Each of these elements is tested against the requirements.
aeronautical engineering is a very specific skill. so is aircraft controls. so is airworthiness. a software engineer is an expert in software, not these other disciplines.
In fact, achieving a functional and fully correct piece of software based on such a specification is not at all a trivial task, as experienced software engineers will well appreciate.
Because while the specification may describe a certain sequence of inputs that should result in a certain sequence of outputs, it probably does not prescribe the exact data structures, memory layout, logic flow, and computational steps required to guarantee the correct output is always produced from a given set of inputs.
And the people being paid to create the necessary data structures, algorithms, calculations and control logic in order to implement the design specification... those developers are specifically not in a position to make systems design engineering changes to the underlying specification itself.
I think the parent post is an example of this problem taking on flesh. It has been so long since we realized the folly of over-specification in most projects that we have lost memory of there being cases where having a body of people engineering the system and specifications distinctly from the people who implement them actually does matter a great deal.
As a software engineer and not a systems engineer, I thank you for your comment. It has great clarity.
IMO the risk of a mistaken activation that leads to an accident is extremely remote with these changes.
The new software now only does a single stabilizer movement. They have eliminated all known failure conditions which might cause multiple movements.
With only a single movement, the pilots will be able to counteract the force.
Two sensors is not quite as good as three sensors. It can't know which sensor is bad. But it can disable itself and prevent unintended activations.
The new software, when combined with adequate pilot simulator training to both disable MCAS when it encounters an issue, and to fly the plane in with MCAS disabled makes things safe enough.
But how does this fix the problem that MCAS was supposed to be a band-aid over (That the plane is aerodynamically unstable during take-off, and pulling too much on the stick will cause the plane to easily stall)..?
The new MCAS sounds like it will only protect against this instability once - and, if overriden, will not do anything to protect against a stall?
MCAS is not even enabled during take-off, which makes it hard to see how it could be meant to address supposed stability problems during take-off. It can't come on until the flaps are retracted.
It's not that the MAX stalls super easily, It's not an instability. It's just that the controls feel wrong when approaching stall. The FAA have pretty precise regulations about how much backpressure the pilots should feel when approaching stall.
In normal flight, the plane is never anywhere near stalling, so MCAS never activates. Nor do the pilots encounter this weird stall.
The combined chances of both MCAS being disabled AND the pilot not recognizing the stall is pretty low.
But this is why the simulator training is important, so the pilots are familiar with the new feel as the plane approaches stall.
The whole reason the MAX exists is because of Southwest. If southwest didn't throw their weight around and loudly announce they were considering Airbus, the MAX would likely exist in a non-737 configuration right now.
So wait, it's a customer's fault that the supplier cheated the regulations?
I think the problem is that they trust a system that got corrupted or never was that robust in the first place.
Seeing how this thing unfolded, I don't really believe that people making claims are in good authority to make those claims.
That they should in no way proves that they do. Computer programmers build all sorts of foot-guns with the idea that they'll be clever enough to avoid them in the future. I expect pilots are a little more humble and self-aware than that, but they're still human.
If I've got a wicked sharp pairing knife and I cut my finger while peeling something with it then I'll be more careful, but chances are that as the pain fades I'll relax - maybe I'll always be careful with that particular knife but when I get a new pairing knife the memory will be detached.
Boeing needs more than the vague memory of bad PR and low profits for a quarter or two to learn this was unacceptable - and the American legal system is unable to apply a lesson, while the general business culture refuses to learn the lesson.
That's why pageandrew said "pilot unions" and not just "pilots". I doubt that SW, for example, is ready to try to break a strike by pilots in order to force the 737 Max back into service.
Which leaves us with pageandrew's comment: "If pilots and pilot unions are satisfied with the results, I'm satisfied with the results."
By that argument, no union could ever do anything in opposition to a company. That is, I think your argument is utterly flawed.
Their business model depends on the business of their member's beings successful. This doesn't mean they cannot oppose company actions, it means though they want the planes in the skies and not on the ground.
That is, your logic still doesn't hold.
And if you aren’t aware of what plane is operating your flight then you risk having to cancel very late and re-book a likely much more expensive ticket.
I always try to select my seats at time of booking, which requires knowing the model+revision of the plane. Is that weird?
There’s been plenty of times my plane has been changed out at the last minute due to weather or mechanical issues.
Apps such as Flighty (and I'm sure others, possibly even those without subscription) will provide access to those well ahead of time and notify you about changes.
It is unfortunate that "changing the plane type" is not grounds to change your ticket however.
It is useful for changing plans if the plane changes days or weeks before departure, but as you say it’s not ground for cancelling or changing your ticket, so buying new tickets every time one sees a 7M8 pop up is going to be really expensive with airlines that have many of them. I guess the better idea then is to avoid those airlines entirely, but that might not be possible at all destinations.
Similarly, driving NYC to LA is vastly less safe than flying from NYC to LA commercially. That doesn't make the roads unsafe.
How so? Is flying still safer than driving a well-maintained car and observer safety best practices? Or is it safer in regards to grand scheme of things and you might be one of those drivers that be drunk driving? Well, you can not drink and drive, it's not really random from a personal perspective.
In 2014, incidents where at least one driver had a detectable amount of alcohol in their system accounted for 36% of traffic fatalities in the US. Even if you exclude those fatalities entirely, driving is still 70x more dangerous.
Now of course you can claim that you're just a better driver than the average person (like 93% of Americans do [3]), but no matter how good of a driver you are, I doubt if it would come anywhere close to making up for a 70x difference.
[1] http://faculty.wcas.northwestern.edu/~ipsavage/436-appendix....
[2] https://crashstats.nhtsa.dot.gov/Api/Public/Publication/8122...
Also, these statistics are about commercial flights on perfect routes v.s. all the drivers on all kind of roads. I looked a bit and it seems like the accidents on the highways are significantly less likely and the deaths rete per crash is lower too.
A fairer comparison would be small chartered jets v.s. Uber, commercial coach services v.s. commercial flights on similar routes and so on.
I don't know even if it's a meaningful comparison anyway, on long journeys or on short ones they do not overlap.
When you are in an aircraft, the biggest risk is takeoff and landing. After that, assuming a well maintained aircraft, most of the risk is mitigated by the fact that your flight deck has thousands of hours of experience and most major components of the aircraft have some level of redundancy. The crew are not even allowed to eat the same meal to rule out food poisoning.
Safer in what regard?
"Flying is safer than driving" claim probably comes from some metric that is relevant to insurance companies when calculating premiums but irrelevant to private travellers because they can choose not do drive drunk or take risks.
The claim that "flying is safer than driving" is based on fatalities/mile traveled.
https://travel.usnews.com/features/why-air-travel-is-actuall...
https://fortune.com/2017/07/20/are-airplanes-safer-than-cars...
After the FAA let themselves get hoodwinked by Boeing, this means a lot less than it used to, and it will take time to restore a reputation for being a legit independent check.
Also of note, the US Air Force has been refusing delivery of the air tankers Boeing is building because of manufacturing sloppiness. Bad engineering and poor quality manufacturing seems to be a hallmark of Boeing these days.
Choosing not to fly is pretty simple (If you accept that some locations are simply off limits). Flying "another plane" is NOT simple, unless you completely avoid airlines that have MAX8's, or avoid flying where a MAX8 may be used.
The problem is amplified by a few statistical problems: 737-800 is probably the most common jet around. Most (all?) MAX8 operators have 737-800's. That means any time you book a flight where a 737 may be used, it can be either a 737-800 or a MAX8. You can't know.
You can always turn around when you see a MAX8 in your gate, but you can't know when booking that a MAX8 won't be used, even if it says 737-800 when you book. So unless you are ready to turn around in the gate when you see a MAX8, you simply can't book that airline. Depending on whose wedding or what job interview you were flying to, turning around at the gate might not be so appealing either.
Pilots often know a great deal about the general design qualities of the planes they fly. Defective parts happen, parts wear down, sensors break, etc. When a sensor or mechanism breaks, pilots recognize the symptom and override the feature that uses the broken part.
737 MAX tries to bolt the big engine on the little plane (old design), with minimal changes. This plane may not be necessarily defective on its own, the MCAS was created to compensate. But it will activate incorrectly with a defective sensor. MCAS was designed not be overridable (or optionally so, if you shell out for it?). Why not put in an override? Because Southwest offered Boeing a financial incentive bonus if they provided 737 MAX with minimal/no new training requirement. If the plane has a new indicator light and a new switch to override a feature, you have to train pilots on how and when to do so. Instead, Boeing decided to "just" rely on MCAS.
> Boeing can convince AA and Southwest pilots to give them vote of confidence
Pilots have the most to lose, their trust should be valuable.