Both flights gave flight crews unexpected tests on unexpected situations-- something that seemed like runaway trim for the MAX, and simultaneous overspeed (better nose up) and stall (better nose down) indications for AF447.
The problem was that at some point the trim is so much that it becomes nigh impossible to hand crank the trim down, the trim flap applies so much pressure it cannot be overcome by hand. You had to disable mechanized trim because otherwise MCAS would kick in. So you would need to recognize the problem soon enough to prevent MCAS from moving the trim so far that it became unrecoverable.
(Source: Netflix documentary)
10 seconds is a long time of the trim wheel being cranked nose up. The same situation would apply to a stuck trim switch on the yoke. (Indeed, a stuck trim switch is worse in this respect because it cranks constantly and doesn't "yield" to the pilot pushing the switch the other way... of course, the checklist didn't presume a pilot should be diagnosing stuck AOA vs. stuck trim switch and thus recommended immediate use of the trim cutout switches instead of trying to electrically trim the other way).
There's a reason that trim runaway is a "recall" procedure in the QRH that pilots are expected to know-- it gets scary. http://www.b737.org.uk/images/runawaystab2020.jpg But it was the assumption before the MCAS disaster that pilots could deal with trim runaway, given that there was a history of flight crews dealing with trim runaway incidents in flight successfully. But MCAS was worse because:
A) It did it more often, so flight crews were exposed to this dangerous situation more than ever before
B) It did it in a sneakier, strange way (no constant movement of the trim wheel).
Still, some real-world flight crews did overcome MCAS doing the wrong thing without crashing, even if others failed the test.
- It's perhaps understandable why engineering teams-- pushed by management to deliver a 737 that doesn't require retraining-- decided that if flight crews could handle runaway trim, they could handle any errant MCAS activations and that the level of redundancy and fault tolerance necessary in the system would be low.
- On the other hand, real flight crews obviously do not do great when exposed to this test.
- If you give a flight crew a wacky situation with conflicting information (like AF447 or the 737 MAX)-- expect failures, even if the situation is technically 100% recoverable and flyable and some crews exposed to the situation succeed.
It's great that we have humans capable of reason up in the front of the plane, but reason is often faulty and doesn't get you the solution you need on the first try.
so i think your point is completely invalid.
There's no such protection on the 737. Nobody's done that because unlike on the Airbus, it's never safe to do so. There are, however, plenty of ways to get caught off guard in a 737 and stall it. Take a look at the UTAir and Thomsonair go arounds that got their planes to about 45° nose up. Or the 737 Air Florida planted right into the Potomac because they didn't have the elevator authority to avoid the stall. Or Fly Dubai…
As for human interactions, the 737 is a series of bad choices (especially the MAX). Take a look at the Helios Air crash, the pilots were confused by an alarm that could mean two different things. Unfortunately hypoxic pilots aren't known for their reasoning ability.
here is what happened in the airbus air france incident:
- one pilot had the sidestick full hard nose up, the other full hard nose down.
- neither pilot realized what the other pilot was doing.
on a boeing airliner:
- the controls for each pilot are physically linked.
- if pilots try to put “their” yolk into an opposing position, they will start having to physically wrestle for control.
- this type of failure mode of the air france crash wouldn’t have happened in a boeing airplane; the pilots would have realized what was going on within seconds.
general note:
- when flying, it is highly unusual for both pilots to be giving input into the controls at the same time. one pilot “has the airplane”, the other is there to assist, help with the radios, planning, etc. the handoff between who “has the airplane” is very deliberate. this was another failure mode of the air france flight.
- but my point still stands, the fact that the controls are linked makes the gp point a bit moot.
Say what? Atlas Air face planted a 767 with pilots doing just that:
> The captain’s and the FO’s opposing elevator control
> forces continued for about 10 seconds, during which the
> airplane’s dive continued to steepen. Thus, the NTSB
> concludes that the captain’s failure to command a positive
> transfer of control of the airplane as soon as he attempted
> to intervene on the controls enabled the FO to continue to
> force the airplane into a steepening dive.
Or the Air France thing that's now on the front page. In a Boeing 777.
Poor training is poor training. Physical feedback is not a safety benefit. It sounds nice in theory but in practice doesn't do much. You can easily say the same thing about A vs B thrust levers, look at that Sriwijaya Air crash. The Boeing design sounds more intuitive until you look at crashes where the feedback didn't do a single thing to help the pilots or avoid a crash.
you cannot ignore a physical link.
you can ignore an alarm.