FAA faces dilemma over 737 Max wiring flaw that Boeing missed
seattletimes.com
seattletimes.com
As a result I have no empathy for managers who are not getting their bonuses this year, or executives who get fired, or corporations who have to take loans on unfavorable terms in order to weather the storm of consequences brought on by trying to avoid following the rules and incurring the expense such rules incur in their execution.
I do feel bad for the engineers who were fired or moved out of the company by pointing out that management wasn't following the rules. I do feel badly for the employees whose livelihood depends on their working on building these amazing machines being put out of work because the consequences are playing out. And I feel a little bit bad for the airlines suffering from carrying a bunch of planes they can't fly. Hopefully people are learning life lessons in this process and the pendulum will swing back into a safer mode of rule following from the current risk taking behavior.
[1] This philosophy, sadly way too common in my opinion, is that "rules" are for idiots, and since we're not idiots we need only concern ourselves with the risks as we understand them of why the rule should be followed, and ignore said rules when we believe we have no risk of both getting caught nor having the "bad thing" the rule prevents happening (at least on our watch while it would reflect on us.).
Illegal seems like the wrong word for this sentiment as it's legal status does not depend on being caught. If I were to rob a bank, it would be an illegal act whether or not I'm caught.
Problem seems like an apt substitute.
Thus in your example robbing the bank is technically illegal but you aren’t going to court if you don’t get caught.
I know it's automatic that we assume Boeing is either nefarious or retarded in everything they do, but it's hard to see this as that big a deal when considering the bigger picture.
Tough--they should have to rewire the plane.
They cut the corner (or missed the corner) and got caught. Too bad, so sad. Maybe fire a bunch of executives this time and I might have some more sympathy later.
> For once, I think Boeing does have a point here. This is the same wiring used on the 737NG, which AFAIK is considered the safest (or one of the safest, at least) airliner ever. The point about rerouting existing wiring introducing it's own potential hazard also seems like an entirely reasonable consideration.
"Nothing happened before" does not obviate the analysis that caused the rule to be created.
Aerospace rules are generally written in blood. Ignoring them tends to spill more blood.
This is exactly the kind of issue where your reputation is crucial. If your reputation is sterling, then nobody would blink about cutting you slack in this single instance. If, however, your reputation is such that there are likely even more instances like this that haven't been found, then you should get held to the letter of the law.
You missed the point. It's not about the money, it's that rewiring might actually be less safe.
How much risk, I don't know. But slavishley following rules without bothering to understand them isn't a good idea.
Either those wires are safe, so leave them, or they are not, so rewire 6,000 grandfathered planes.
Doing some sort of hybrid where you rewire these planes, but not those, just based on the name, isn't logical.
The MAXes where built after the regulation came into place therefore you better build it in. The same way you can't sell a new car without safety belts.
No, I didn't. That's what Boeing claims by attempting to extrapolate the safety record of a plane built under previous Boeing management who had safety as priority one to the safety record of the current plane built under Boeing/McDonnell management that prioritized money over safety.
The problem is that the previous wiring might be safe given that all the surrounding systems are also built to the same safety standard as the previous 737. Unfortunately, we have plenty of evidence that the surrounding systems probably are not built to the same standard.
In addition, the airplanes responsible for this rule coming into being didn't have a safety problem either--until they suddenly did.
It's not that the planes developed a safety problem - it's that we learned that the wires being that close is a bad idea and that all planes built after we realized that should not make the same mistake.
Even if the FAA cuts Boeing some slack here (which they shouldn't - these are safety rules that exist because hundreds of people had horrific deaths), the EASA will certainly not.
If the FAA accepts Boeing's excuse, they both would be liable in case the wiring causes an accident in the future, since both would have been negligent and knew fully well the wiring was not up to current standards.
Of course they knew.
But it also seems that the old wiring design has been verified by the test of time and they have data showing the crashes weren't related to it.
So I think that ripping out all of the wiring on the planes and rushing to replace it with a new system, then rushing to test that new system, is the surest way to increase the likelihood of another system failure and possibly even kill off the Boeing brand if that happens.
The dilemma is real.
All they did was ensure their fix gets even more scrutiny and to require additional proof that it's safe.
There is only one good “proof” of safety and that’s testing.
If you don't take a manufacturers word for something you can never get into any plane ever.
As a power systems and controls engineer we make Some effort to separate wires carrying different voltages eg 24v and 480v, but positive and negative run in the same cables or conductors in the same raceway all the time with nary a second thought.
I'm guessing that your systems don't experience anything like airplane levels of vibration, or have anything like airplane numbers of fatalities if the controls fail, yeah?
There’s a separation of concerns. The NTSB is solely concerned with finding out what happened. The FBI handles criminal investigations. The FAA is concerned with running air traffic control, regulations, and research.
> The regulation was introduced in 2009 following study of two fatal crashes: TWA 800 in 1996, in which an electrical short is believed to have caused a spark in the fuel tank and an explosion; and Swissair 111 in 1998, when an electrical short caused a fire in the cockpit.
This is appalling as this company exhibits the same excuses as before "there was no problem yet". Persistence in unfit behaviour at its best.
In fact, similar statements are valued in the aeronautical industry (engine failure rates, etc).
The Max failed much earlier than those 200Mi hours.
Then walk. Seriously. If you want to totally eliminate the potential sources of failure from flying, then walk. Drive. Take a rowboat. But don't fly, because you can never categorically eradicate the potential sources of failure in an aircraft - any aircraft.
> If one of my loved ones died due to this defect, as unlikely as that would be, I would not be satisfied with the explanation that "It never happened before in the previous 200 million hours, so no one deemed it worthy of fixing".
You probably also wouldn't be satisfied with "In our best estimate, fixing it was likely to introduce more problems than it solved", even if it was precisely the truth. But put yourself in the other position: If one of your loved ones died due to this fix, would you be satisfied with "But we eliminated the original failure possibility"? Somehow, I doubt it...
But you can make sure that the known potential sources of failures are dealt with.
I'm not an idiot. I understand that there is always some risk in flying. My point was that the idea is to eliminate risks to the best of our ability. That should have been obvious by my post. If we know there's a preventable risk, prevent it.
> You probably also wouldn't be satisfied with...
If that was the recommendation of the regulators, I'd accept that. I don't like the idea of manufacturers policing themselves. We have regulatory bodies precisely because we don't want companies making 'cost effectiveness' a factor in deciding which safety features to implement. Boeing attempting to circumvent regulations is how they ended up in this bind to begin with, resulting in many deaths.
> If one of your loved ones died due to this fix...
In what world would this be satisfactory at any level? I'm not sure exactly what your point is here. If the company is ordered by regulators to retrofit the aircraft to comply with new safety regulations we expect them to do it in a competent manner, don't we? That's not to say that I expect them to retrofit every existing 737... That's another matter entirely.
In the same way, what's the probability of introducing a new defect when replacing the wiring harnesses? It's not zero. It's never zero.
So the answer to "should we fix this issue?" is not "yes, of course". It's "will the fix make things better, or worse?" And of course, you don't know with certainty, but you make your best estimate of the probability of the new problem being worse than the old, and then you decide.
So even if "eliminating risks to the best of our ability" is in fact the right goal, that doesn't always equate to "eliminate this risk", even if we can do so.
> I don't like the idea of manufacturers policing themselves.
Here I agree with you completely. We've seen that movie; let's not watch it again.
Saying "there was no problem yet" about something that's only been in service for a relatively short time, yes.
Saying "there was no problem yet" about something that has been in service since the 1960s, not so much. If the FAA were to force Boeing to change this wiring on the 737 MAX, to be consistent, they would also have to change it on every single 737 of every model that is still in service--including many airplanes that have been in service for decades with no problem.
That's a very different argument from "the FAA skimped on the MAX before, so we shouldn't let them skimp on it again".
I think this is a reference to the stabilizer, because the elevators are controlled by cable connected to the yoke and are hydraulically powered. Since stabilizer (trim) can overpower elevator force, uncommanded changes in this control surface could be really bad, depending on how a short manifests into control surface movements.
I can't assess the relative probabilities: a short happening vs the fix inducing some other problem. But I do wonder whether there's another way to mitigate it.
This is the same memory item Boeing thought would mitigate MCAS, since that is essentially a runaway stabilizer trim, although in retrospect behaving in a very different manner making it much harder to diagnose.
> Furthermore, the electrical power in that wire could circumvent the cutoff switches in the cockpit that, in the event of such a stabilizer runaway, are used to kill electrical power to the tail. Theoretically, the pilots could be unable to shut it off.
If the 737 Maxes can't be adequately fixed then send them back, refund the purchase price.
Yes, I know that. Presumably the same would apply to other aircraft models certified before 2009 (when the new wiring regulation was issued) that might have the same problem (as I posted elsewhere in this discussion, it's quite possible that other aircraft types certified before 2009 have the same problem--we don't know because nobody has looked).
However, if we're willing to not do anything to all those planes, even though we now know they have a potential issue, then we can't just insist on doing something to 737 MAX planes either, since the cost-benefit calculation in both cases is the same: we have a bunch of planes already in service, we now know there's an issue with them, do we fix it or not?
> regulatory agencies need to set a firm precedent to deter other manufacturers from playing fast and loose with the rules
For any 737 MAX aircraft that have not yet flown, I would agree with you. However, tearing apart aircraft that have already been flown to fix this issue might cause more problems than it solves. The teardown would be extensive and any repair that extensive risks introducing some other issue that didn't exist before and which could cause problems in the future. That makes it a different cost-benefit calculation.
I certainly agree that Boeing should not be the ones making that calculation. It would be nice if the FAA didn't either, but had some other agency such as the NTSB do the root cause analysis to estimate the relative risk of doing the repair on already flown planes vs. not doing it.
No, it didn't. There were plenty of problems prior to the flight that lost the Challenger, and plenty of problems prior to the flight that lost Columbia. NASA management just refused to pay attention to the engineers that were telling them there were problems.
I was absolutely shocked that only after the Columbia accident the underside of the craft was inspected in orbit. It shocks me that in more than a hundred flights, nobody in NASA management had enough curiosity to force someone to look for significant tile damage made during the ascent.
Learning how to build and fly things in air and space is pretty much the agency's job description.
But I would not trust Boeing to make that calculation and even the FAA's reputation has been dented (which is why I think they are being hard-arses about it) but it could be retrofitting is not the right choice.
I would probably be happier if the FAA and the ESA decided independently whether to allow it.
In this particular case the fact that it is aviation standards for wire separation at issue, when those are typically stupefyingly conservative, means that "doing nothing" may well be the safest course. But I am NOT an expert in this area, so don't trust me!
One way to help make the decision is to try and get money out of the equation. If the two options are "pay for the rework" or "pay a fine equal to the cost of the rework", then any company that opts for the fine might actually believe in that approach.
I get your point, but isn't it ultimately about money anyway? If they can wire a plane correctly when they're building it, they surely can rewire a plane later - they might have to remove more stuff, worst case scenario reverting the plane to the same state it would be for an original rewire, and I suppose the reason they don't want to do that is money.
I can't understand the decision to "ship" with a potentially catastrophic failure that would cost many lives otherwise. I don't think this should be a dilemma. IMHO the two sensible options from a regulator point of view seem to be "make the plane safe to fly, and if that's expensive, tough luck" and "don't fly the plane".
Similarly, if safety trumped all else, there would be no aviation industry.
I'm not an aerospace expert, but I know that even major automakers usually won't allow their dealers to do repairs to wiring harnesses because it poses too much risk.
A popular topic on online car forums is electrical gremlins, almost always from crummy electrical repairs.
[1] some makes/models are particularly subject to this (FIAT do you hear me?) , and it is very common to need to spray some WD-40 or similar once a year or so on contacts/connectors of tail lights/turn lights.
If the repair doesn't make the planes safe according to the regulations they should have been built for, then the planes need to be scrapped.
If the repair makes the plane meet the letter of the regulations but introduces risks that the regulations didn't consider, you've done a good job at meeting regulations but a bad job at managing actual risk.
In fact, there is another possibility: that the planes were never airworthy and should have never be flown in the first place and, if they can't be made airworthy, then they should be scrapped.
Although, to play devil's advocate with Boeing's point: if you are to say that those planes are not airworthy because of their cable spacing, then no 737 is airworthy, as the regulation is new.
Boeing is claiming that the service time of their wiring setup is sufficient evidence to justify an exception to applying the harsher model.
It is not an incredulous claim, and not a trivial dilemma.
When you're dealing with complex wiring harnesses and wiring runs, there are always problems. For example, the A380 and one of Boeing's new airliners were delayed because stuffing the wiring harness in the nose didn't work.
In the case of airplanes, things flex and bend, causing wire chafing.
So there's no black and white answer to, "Is the wiring perfect?"
The only good solutions are:
1) When new airplanes are made, improve the wire layout
2) When old airplanes get a heavy maintenance check (D-check), possibly inspect and redo the wiring then.
3) Consider using conduit for safety-critical runs. Makes it harder to inspect, though. :)
Anyway, the Swissair 111 fire/crash was because of new gambling screens igniting flammable materials. Sure that was an electrical fire, but from adding entertainment equipment.
Swissair 111: "flammable material used in the aircraft's structure"
https://en.wikipedia.org/wiki/Swissair_Flight_111
Source: commercially-rated pilot
Boeing will pay twice because their incompetence highlighted the incompetence of the FAA.
Not that I particularly care. I hope Boeing goes bankrupt.
That'd be said. I hope their top 3 or 4 management layers go to jail. For a long time. They've been criminally negligent.
The whole engineering approach reeks of management mandating to "just fix it with gaffer tape", if it costs time or gets expensive.
Boeing's despicable behavior in the whole sordid affair also doesn't exactly help.
While I'm sure that there's a lot of scrutinity going into the recertification of the plane, such systems are so immensely complex that it begs the question: What else was missed?
I, for one, would be extremely reluctant to step into anything 737 after the NG. Even at the price to forego a direct connection.
Doesn't it require other agencies in Europe and China to do the same? How useful is a fleet that can't fly in large segments of the world?
[1] https://www.faa.gov/aircraft/repair/media/easa_us_roadshows....
Could they convert the entire fleet into cargo jets, or does the configuration not match that role?
Because pilots' lives don't matter?
If a plane isn't safe for passengers, it isn't safe for the crew.
Cargo plane fly mostly twice per day (base to sorting center and back), so they use older planes. They use more fuel per mile, but acquisition costs are low.
You can't just repurpose brand new planes for cargo use, it's not economically viable.
Plus, it would mean the safety of cargo pilots is less important than the safety of passengers...
For example, crew rest requirements adopted in 2010 don't apply to cargo: https://ttd.org/policy/ensure-one-level-of-safety-for-all-ai...
That's likely a big part of the problem. Fishing a new wire is generally very difficult, and there are probably rules that say it has to be secured every X meters. Airplanes generally don't use much conduit, so I suspect they'd have to at least partially tear apart the plane to do this right.
It's true that the wiring harness is already proven with 737 NG. And it's probably true rewiring 737 MAX is a higher risk than doing nothing.
But IF this issue causes an accident without attempt to fix it, Boeing as a company might never recover. Even one such case could be enough.
So both not doing anything and fixing it carry a huge risk. Not fun to be Boeing these days...
It's also shocking to me that the MAX may be rectified when depending only on one angle-of-attack sensor (the one that caused the two prior crashes). They should mandate that at minimum 2 redundant sensor must exist, at minimum. Really it should be 3 sensors for flight critical input, as has been the case for all modern airplanes.
Do you have a source for this? Last I read, there were 3 main categories of fixes, the first being to read both sensors.[1]
[1] https://www.businessinsider.com/boeing-737-max-mcas-fixes-20...
Fixing the wiring issue would mean fixing it on every single 737 in service, not just the 737 MAX. Many of those airplanes have been flying for decades with no incidents. Tearing them apart to rewire them might make things worse overall, not better, since any repair always has the risk of introducing some other problem.
And?
F.e., NHTSA has called the ongoing recall of airbags made by the major automotive parts supplier Takata "the largest and most complex safety recall in U.S. history.” Over 41.6 million vehicles have been recalled due to the faulty airbags.
Different makes, models, years - but faulty part is faulty part and millions of cars were recalled and fixed.
Replacing a faulty airbag on a car is a lot less complicated and risky than replacing many feet of wiring on an airplane.
No it wouldn't as 737 was certified before the new regulation. It is in the article:
> That earlier 737 NG model didn’t have to meet the current wiring-separation standards because they came into force long after that jet was certified.
Just like with cars - you can drive a car from 70ties without airbags or crumple zones but you cannot buy a new car without airbags as it won't be able to pass the latest regulations.
Imo in this case the main issue is not the safety (seeing how the older planes aren't falling out of the sky) but setting a precedent where the certification authority has missed an issue which is not according to regulation - do the manufacturer gets a free pass or it is their responsibility to make the item according to regulation in the first place and it doesn't matter if it was missed during the certification process.
I know the previous 737 models were grandfathered. What I am questioning is the argument that, even though we accept this wiring flaw on all grandfathered 737s, it must be fixed on the 737 MAX just because Boeing made a different mistake (MCAS) on the 737 MAX. (If they hadn't made the MCAS mistake, the FAA wouldn't be reviewing the certification of the MAX and wouldn't have found the wiring issue.)
> setting a precedent where the certification authority has missed an issue which is not according to regulation
Is this the first time the FAA has missed a certification issue? I don't know, but I doubt it.
If the FAA has missed certification issues before, has the manufacturer always been forced to rework all affected aircraft when the missed issue is discovered? Again, I don't know, but I doubt it.
In any case, these certainly seem like relevant questions to ask before coming to a conclusion.
They also require a computer that has the inputs for it.
Why they didn't go with three is probably a good question. Airbus did.