The crash of Air France flight 447 (2021)
admiralcloudberg.medium.com
admiralcloudberg.medium.com
For some crashes that have interesting causes (at least from an engineering perspective) beyond "maintenance failed to identify a problem before takeoff" or "pilots fail to identify problem or take wrong actions", I strongly recommend the articles on TWA 800 (1996) [1] and the near-crash of SmartLynx Estonia 9001 (2018) [2]. The first goes into great detail exactly _how_ the FAA discovered the root cause, whereas the second one involves a logic oversight in the flight computers of a modern Airbus plane.
[1]: https://admiralcloudberg.medium.com/memories-of-flame-the-cr... [2]: https://admiralcloudberg.medium.com/the-dark-side-of-logic-t...
I've read the accident report, a few books, and even some of the conspiracy theories and this is the best "factual" summary.
That said, I believe aerobatics and out-of-control flight training need to be a lot more common in the civilian sector for professional pilots than they are. Awareness of your angle of attack, and knowledge of how an aircraft behaves at high AOA close to (and if possible beyond) stall don't seem to be taught well in the civilian sector, or at least outside the tactical jet community. The idea that a professional pilot can't understand that a deeply stalled aircraft can be nose-up and still have a heinous sink rate is profoundly bothering to me, just like the Colgan Air pilots who couldn't recognize severe wing rock as a sign of a deeply-departed state. Both of these required (if even possible at that point) aggressive nose-down pitch inputs to break the AOA. And even then, the aircraft is going to lose a ridiculous amount of altitude before it gains enough airspeed back to give you enough pitch authority to scoop out of the ensuing dive. Horrible.
It also boggles my mind that Airbus didn't think at first to design an aircraft which avoided the split control problem they had. One person and one person only needs to be in control of the aircraft at all times.
[1]: https://en.wikipedia.org/wiki/Transair_Flight_810 [2]: https://admiralcloudberg.medium.com/dark-waters-of-self-delu...
The other answer to "people do stupid things under stress" is the common maxim that every emergency procedure in every aircraft starts the same way. Somewhere in the cockpit is probably a standard-issue mechanical 8-day clock, and the first thing you do in any emergency is stop and wind the clock. Not because it does anything to the aircraft, precisely the opposite. It makes you stop for a second or two for the "oh shit" moment to pass. Then you analyze what's actually going on. The other saying that's always briefed is "no fast hands in the cockpit." You may need to be expeditious, but you still vocalize what you're doing with your crew or wingman and methodically go through the emergency procedure. You get in a lot more trouble flipping switches willy-nilly based on what you think you have than if you just stop, breathe, and look at what the aircraft is telling you. I still can recite the steps from memory:
- Maintain aircraft control
- Analyze the situation
- Apply the appropriate emergency procedure(s)
- Land when conditions permit
A good friend of mine [UK-based] used to fly fast jets for the RAF a long time ago (we're talking Lightning/Jaguar/Tornado).
He recently commented to me that "there were operational deployments where it went from boring to bedlam in the blink of an eye much of the time"...
Teaching humans how better to manage going from boring to bedlam is the key, I think.
Random example:
https://www.linkedin.com/posts/kim-kc-campbell_a-10-pilot-re...
They did do that on the flight in question.
That seems like a crucial functional omission.
For me at least, it seems like the condition where both pilots are inputting control on the stick or rudder is always an error condition. Even if they're both inputting the same inputs.
The scheme directly contributed to the crash for two reasons; obviously if the co-pilot wasn't pulling back on the stick, they would have been able to get out of the stall. But additionally, the two crew members were spending crew resources on redundant tasks: both of them thought that they were the ones aviating and the other was in charge of figuring out why the flight computer seemed to be behaving badly. Possibly if one of them did dedicate their attention to the flight computer, they'd have figured out what the actual flight parameters were.
Q: How many pilots would attempt a stall recovery if the aircraft's instruments were not indicating they were stalled?
It's not that simple.
When the aircraft's computer considered the inputs invalid, the stall warning was muted. When they decreased the pitch (would be essential to recover from the stall!) the stall warning sounded.
"The angle of attack had then reached 40°, and the aircraft had descended to 35,000 feet (10,668 m) with the engines running at almost 100% N1 (the rotational speed of the front intake fan, which delivers most of a turbofan engine's thrust). The stall warnings stopped, as all airspeed indications were now considered invalid by the aircraft's computer because of the high angle of attack. The aircraft had its nose above the horizon, but was descending steeply.
Roughly 20 seconds later, at 02:12 UTC, Bonin decreased the aircraft's pitch slightly. Airspeed indications became valid, and the stall warning sounded again; it then sounded intermittently for the remaining duration of the flight, stopping only when the pilots increased the aircraft's nose-up pitch. From there until the end of the flight, the angle of attack never dropped below 35°."[0]
It is not required for Part 91 (General Aviation/"Private") or Part 135 (Charter) operators.
https://www.faa.gov/documentLibrary/media/Advisory_Circular/...
Gliding skill highlight: https://youtu.be/H5UUr9RXfTY?t=1312
Some occasionally below stalling speed, if you're high enough to safely reduce margins so much that a gust of tailwind puts you below, which requires you to just calmly follow through with constant angle of attack, descending, rather than force the nose up.
Short-field landings in unfamiliar places, requiring judgements of both approach angle and terrain. Moderate to heavy turbulence all day, speed varying from stalling to redline. Retractable landing gear. Flaps if you want that source of mental load too, in all speed regimes. Constant consideration of wind. One shot landings. Mountain flying with constant consideration of where the safe exit is. Consideration of deteriorating weather. Always aware of nearest landing site.
It's really non-stop training in all the fundamental parts of flying, minus engine operation, airspace and ATC communication.
The SNES controller had 8 buttons and was operated from the safety of your couch. I'd imagine trying to correct this sort of situation is more like playing Microsoft Flight Simulator, while you're on a roller coaster, with random features of the plane not working, hypoxia clouding your judgment, and knowing 100+ lives are at stake if you fuck anything up.
I wonder if reverting back to pilot control is really the best approach in situations with faulty instruments. Perhaps it would be safer to use algorithms that can deal with bad data in a sane way. A middle ground between blindly trusting bad data (as in 737 max) and reverting to the pilot. Use other data like GPS, accelerometers, strain sensors ,fuel flow rate sensors, to sense check the primary instruments.
In this particular example, consider:
- the opposing pilot inputs being signaled only by a pair of little green lights
- the cacophony of warning lights and alarms which, together, say little more than "something is wrong"
- instruments that direct a pilot to pull up during a full stall
- sensor failures with no clear indicator
- computer safeguards suddenly removed without a stated reason
Etc. And the expectation towards the crew is to quickly and corrently reason about this stream of conflicting signals, while embroiled in a sudden emergency.
It smacks of pure engineer-driven design, assembled with serious attention to the technical issues, but with near-zero empathy for the humans who will be operating the contraption.
Reminds me of internal web tools at so many companies. They present giant messy forms, with checkboxes and dropdowns for every conceivable edge case, which have to be manipulated just so or the system explodes. And when something breaks, of course it's the user's fault every time.
If you expect an instrument to routinely fail, it just seems logical to at least have a backup.
Hearing is also the first sense to go when people panic; this flight had the stall warning blaring for over a minute straight and it didn't occur to the pilots that they may not be in overspeed, but stall.
(It is of course not perfect, sometimes conditions become dependent on one another and their order is not always great - see this simulated simultaneous engine fire and engine failure right after takeoff, where flying on your burning engine might be better than turning into a 1000ft glider: https://www.youtube.com/watch?v=ZRbLLO385_c)
So many accidents seem to happen when pilots receive a route change and have to hastily re-program the FMC.
There is no "cacophony of warning lights". The overhead panel is a designed to have all buttons not be illuminated, so if you're checking what's wrong, you can immediately tell by there being a light indicator on it. Here this was limited to two ADIRs indicating FAULT. Nothing more.
I think this might help: https://www.youtube.com/watch?v=0a06A78iXnQ
> If sensor failures occur, the controls drop down a level to “alternate law.” This law contains several sub-laws with slightly different configurations, but in general, alternate law means that some or all computer moderation of control inputs remains, but flight envelope protections are removed. The autopilot and auto thrust cease to function.
> In the event of further failures, the controls can enter direct law, in which there are no flight envelope protections and side stick inputs correspond directly to the position of the control surfaces, with no adjustment by the computer. This makes the airplane fly rather like a classic airliner, similar to most older Boeing models.
When you think of all of the Tesla accidents, this still seems to be the failure mode for autonomous systems. It's safer 95% of the time. But when it fails, it's because the users are so dependent on the systems that they don't even have the simplest of skills to prevent catastrophe.
One pilot was pushing full nose down. The other full nose up. The system _did_ tell them that they were doing this, but in the sea of other alarms, it didn't register with them.
The lack of alarm prioritization and the lack of crew resource management training in the face of an emergency seem like the major human factors here. Half of that is in the design of the plane, the other half in how the company trains their pilots to handle severe emergencies.
Most Tesla Autopilot failures aren't drivers that don't know how to drive, it's the automation making bad inputs.
As I said elsewhere, the airplane was quite literally falling as fast as it was moving forward. I don't really fault the plane for considering that condition erroneous. And it didn't throw away a warning, it instead marks the speed tape with a bright red "SPD" instead of showing any airspeed. This is likely the better alternative over getting persistent stall warnings if one of your airspeed indicators fails.
Here's how that condition would've looked: https://docs.flybywiresim.com/pilots-corner/a32nx-briefing/p...
And I totally agree, there's no good solution to helping the pilots in such a catastrophic situation. They were probably going to ignore audible warnings and most visual cues anyways, considering how tunnel visioned they were from the moment the auto pilot gave back the controls to the pilots.
Sensory overload and no clear readout of what is actually broken (pitot tube icing in this case) is bad but the fly-by-wire joystick configuration is what really doomed this flight. In Boeing airliners and many other types of aircraft the control sticks are mechanically linked together: you can physically feel if the other pilot is fighting your inputs:
> “Controls to the left,” Robert said, still worried about their bank angle. Pressing the priority button on his side stick, he took control and locked out Bonin, but Bonin immediately pressed his own priority button and assumed control again.
If the controls were mechanically linked Robert would have recognized his inputs were being overridden and would have been able to save the plane.
* The ECAM did show IF SPD DISAGREE: ADR CHECK PROC.
* The plane did shout DUAL INPUT several times, and a button to lock out the other pilot is right on the stick. You can hear it being used by Bonin.
I'd say this is a failure of lack of crew resource management (not even technical ability) more than anything else.
And there were _several_ incidents with Airbuses that were caused by dual inputs.
The real problem is that someone who doesn't look at his most critical instrument* in instrument flying conditions, causes a stall, doesn't respond to stall warnings, doesn't communicate, refuses to hand over controls even though he doesn't understand what is happening, is in the cockpit at all. Either the training was inadequate, or deficiencies in Bonin's flying were overlooked.
That the off-duty captain standing behind them is the first to vocalize they're at 10000 ft and stalling is indeed not great.
Aircraft emergencies are all about keeping you out of panic so that your natural instincts don't surface, because pretty much every natural or intrinsic human instinct, if followed, will just result in you flying the plane into the ground. Every sense you have is overwhelmed with "things aren't working the way I know they are supposed to and my control inputs seemingly have random results", and in a panic, your brain REALLY wants to revert to "just keep going up, away from danger", which is the opposite of what you need to do 95% of the time.
The only fix in this case would have been literally evicting that pilot from the cockpit, and there's no button for that.
Military jets have such a button. Maybe commercial needs to take some inspiration?
I think my sibling comment is probably right, Bonin would've required much more severe shouting to take his hand off the stick.
Certainly worth reading: https://bea.aero/uploads/tx_elyextendttnews/annexe.01.en.pdf
If a pilot stubbornly wants to keep control maybe out of desperation or panic - and performs actions which are counterfactual to the knowledge of aerodynamics every pilot is taught, there is no instrument system which can salvage this catastrophe.
["Bonin acted like an idiot" - not my words, but two of my CFI friends, who discuss aviation topics on weekends often over beers.]
When I asked him about this accident, I brought up this specific point - the mechanical non-linkage.
Sure, the Airbus is fly by wire (there are no "mechanics"), but you can still program one joystick to mimic the other joystick, right? As far as I know, the Airbus plane actually averages the inputs..?? [0]
Anyway, he sorta-angrily gave me the same explanation as I just saw posted here as well: it was a crew management issue. (which of course may have played a huge role).
I am not a pilot so I am probably missing something. But he (the Airbus family member) did seem quite defensive about this. What portion was internalized corporate-comm "we are not at fault" reasoning? What portion was engineering hubris of "fly by wire is unquestionably superior to mechanical linkage"?
I don't know. But I do find it strange... and indefensible. When does the average of inputs make sense? I'm open to an explanation. Is there a good one?
---
[0] See https://news.ycombinator.com/item?id=4224707 from 2012.
"This input was averaged (read: canceled) with the other pilot's nose up input."
(and further down in the same sub-thread)
"The AF447 inputs were averaged."
It happened in one accident, where pilots were literally tugging the yokes in opposite directions. They were literally struggling against each other to fix the attitude.
In the Air France situation, there's no way for the plane to "know" which pilot's input is correct, so I don't have a good answer, but "just average two drastically different inputs" seems crazy.
That's come up at least twice in NTSB ship accident reports. Some ships have more than one control station. This is usually to allow driving from a control station out on a bridge wing, where the pier can be seen clearly. A high speed ferry plowed into a dock in New York City in 1993 because of confusion over which station had control. "The NTSB concludes that the propulsion control system on the Seastreak Wall Street used poorly designed visual and audible cues to communicate critical information about mode and control transfer status."[1] Big throttle levers at each station, but only the ones at one station at a time did anything. The levers did not move together.
The U.S. Navy went all the way to touch-screen throttles. After a collision involving confusion over which of three control stations was driving, they're going back to big handles.[2]
The Airbus system has been criticized, but it's two people sitting side by side. The ship systems have control stations much further apart.
[1] https://www.ntsb.gov/investigations/AccidentReports/Reports/...
[2] https://www.theverge.com/2019/8/11/20800111/us-navy-uss-john...
- It should have a needle to eject caps on it, so that pilots don’t forget the caps (Brisbane accident, among many),
- The needle should also sense, if not remove, the ice (Air France accident),
- It should wake up the pilots and reset controls to fixed values for the current altitude, since when Pitot tubes fail, autopilot and autothrottle are worse than worthless (they will automatically crash the plane).
Hard disagree. No matter how bad the UX, there just isn't any conceivable situation where Bonin's pulling up the rudder for minutes on end wasn't suicidally dangerous, or made any sense at all.
His inexperience cannot be denied. Must have been terrifying for the pilot when the plane's safeties and automation suddenly disengaged. Uncertainty and panic must have seized him and never let go.
But in video games you likely have good visibility and an external view. AF447 did neither. The human ear is actually really terrible from telling a pitch up stall condition from a pitch down overspeed one, lacking visual references.[1]
[1]: https://en.wikipedia.org/wiki/Sensory_illusions_in_aviation (somatogravic)
This incident was rookie flying behavior coupled with a complete disregard of situational awareness. The flight UX of Airbus isn't that bad: 330 & 340 have a much better panel layout & less clutter than their Boeing counterparts from late 90s.
When the controls were pegged at full aft deflection, the stall warning would cease, because instrument readings in the deep stall were considered invalid by the computer. Whenever the pilot would start to push forward to recover, the computer stopped rejecting the readings, and started sounding the stall warning again!
So every time the pilot started to do the right thing, the airplane would start screaming "STALL STALL" at him, and he would pull the stick back again to make it stop.
I firmly believe that they would still be alive if the stall warning had either not been installed at all, or had functioned properly.
The summary blames the accident on poor training and the typical EFIS "pilot out of the loop" problem, rather than very specific issues like this. Which makes very much sense IMO.
And this is only part of the many things that went wrong. Also it's important to realize the system worked as designed and in every other situation this behaviour would be beneficial. I don't think this was even changed after the accident.
As one of the other things that contributed, the pilot should never have got into this situation in the first place. Which is explained by the poor stall training focusing only on low altitude stalls (which makes sense as this is by far the most likely time for them to occur, but the difference with high altitude should of course be explained as it is being done now.
As with any major incident it's a matter of multiple errors compounding in just the worst way possible.
> During flight 447’s plunge toward the sea, the flight directors disappeared every time the forward airspeed dropped below 60 knots. This was because an airspeed below 60 knots while in flight is so anomalous that the computers are programmed to reject such a reading as false. Furthermore, at an angle of attack threshold which corresponded quite closely to 60 knots, the stall warning would cease for exactly the same reason. This created an unfortunate correlation, wherein Bonin would pitch up, the angle of attack and airspeed would exceed the rejection thresholds, the flight director would stop telling him to fly up, and the stall warning would cease; then if he attempted to pitch down, the angle of attack data would become valid again, the flight director would tell him to pitch up, and the stall warning would return. This perverse Pavlovian relationship could have subconsciously conditioned Bonin to believe that pitching down was causing the plane to approach the stall envelope, and that by pitching up he was actually protecting the plane against stalling. This violated basic aeronautical common sense, but by this point Bonin and common sense might as well have been on different planets.
These AA instructional videos by Captain Vanderburgh are fascinating - even to a non-pilot like myself.
They are especially relevant as we dip our toes into automobile auto-pilot and the "automation dependency" that comes along with it.
Of particular note in this video:
@ 12:30: "... tactily connected to the airplane ..."
@ 14:15: "... we see automation dependent crews, lacking confidence in their own ability to fly an airplane are turning to ther autopilot ..."
@ 17:35 - 18:15: (just listen)
https://admiralcloudberg.medium.com/children-of-the-magenta-...
The badassery men are capable of when they accept this and drive instead of allowing themselves to be driven is the stuff of legends.
https://en.wikipedia.org/wiki/Mercury-Atlas_9
https://en.wikipedia.org/wiki/Gordon_Cooper
> Cooper lost all attitude readings.
> [a short-circuit] left the automatic stabilization and control system without electric power.
> Cooper noted that the carbon dioxide level was rising in the cabin and in his spacesuit.
> "Things are beginning to stack up a little."
> Turning to his understanding of star patterns, Cooper took manual control of the tiny capsule and successfully estimated the correct pitch for re-entry into the atmosphere.
> Cooper drew lines on the capsule window to help him check his orientation before firing the re-entry rockets.
> "So I used my wrist watch for time," he later recalled, "my eyeballs out the window for attitude."
> "Then I fired my retrorockets at the right time and landed right by the carrier."
https://www.vanityfair.com/news/business/2014/10/air-france-...
All of his articles about transportation disasters (Columbia, M/V Estonia, many other plane crashes) are very good and highly recommended.
My most sincere admiration and thank you notes to the author for putting all of this together in such a great way!
In this case, ultimately, the pilot and the co-pilot were exerting opposite controls. One to pull up, one to push the nose down. In a stall you push the nose down to gain aerodynamic lift. That's like Flying 101. But I guess when you panic, the natural instinct of wanting to pull up kicks in when you're rapidly losing altitude. Still, training?
I saw another one the other day: Ethiopian Air Flight 961 [1] from 1996. This accidently ultimately came down to a single switch being on: manual cabin pressurization. This was on because a pilot reported an error in a previous flight and maintenance were trying to replicate it. The pilots (and passengers) passed out from hypoxia and didn't put on their oxygen masks. Again, not putting on your mask? Pretty basic. Also, Flying 101. If you lose (or don't have) pressurization, drop your altitutde. You get below 8000 feet and you're fine.
There was an error but it wasn't ignored and it wasn't entirely obvious, causing revisions to be made. Also, hypoxia can impair judgement very quickly. But why keep climbing when something is wrong?
[1]: https://en.wikipedia.org/wiki/Ethiopian_Airlines_Flight_961
This is a very bad design - at a bare minimum an incredibly loud and annoying alarm should go off if the pilots are fighting controls, because neither knows what the plane is receiving as an input.
You can see it used here: https://youtube.com/shorts/nBmPXrBpp3Y
You hear the normal 50.. 30.. etc. callouts and then when the captain goes full thrust you hear "priority left" which is the override button being pressed to pitch for go-around.
That's much nicer than what we have teaching with traditional controls. Because at that point overpowering a startled pilot is a bit hard.
FDR visualization: https://www.youtube.com/watch?v=0a06A78iXnQ
Interesting that the FO flying from the left seat did not recognise that callout as a big thing to react to.
(Unless you manage to hit the priority button for 40 seconds - but I assume that's for locking out a broken stick that's doing inputs at rest)
It's a bit different for a training captain like in the video. They know these are the first officer's first landings on the real aircraft, so when things go wrong they take over.
Section 6
> When a dual input situation is detected, the two green priority lights located on the cockpit front panel flash simultaneously.
> After the visual indication has been triggered, a synthetic voice “DUAL INPUT” comes up every 5 sec, as long as the dual input condition persists.
According to Wikipedia, this warning system worked as intended:
> Confused, Bonin exclaimed, "I don't have control of the airplane any more now", and two seconds later, "I don't have control of the airplane at all!"[42] Robert responded to this by saying, "controls to the left", and took over control of the aircraft.[83][44]
> He pushed his side-stick forward to lower the nose and recover from the stall; however, Bonin was still pulling his side-stick back. The inputs cancelled each other out and triggered an audible "dual input" warning.
> ...
> Bonin heard this and replied, "But I've been at maximum nose-up for a while!" When Captain Dubois heard this, he realized Bonin was causing the stall, and shouted, "No no no, don't climb! No No No!"[85][44]
> When Robert heard this, he told Bonin to give him control of the airplane.[2] In response to this, Bonin temporarily gave the controls to Robert.[44][85][2] Robert pushed his side-stick forward to try to regain lift for the airplane to exit the stall. However, the aircraft was too low to recover from the stall. Shortly thereafter, the ground proximity warning system sounded an alarm, warning the crew about the aircraft's imminent crash with the ocean.
In this case it had degraded to loose some of those protections due to icing of the sensors.
That was confusing to the junior co-pilot, and they skipped basic procedures on who has control resulting in opposite inputs and a loss of control.
People act like this situation wouldn't have happened had they had boeing style connected controls, but it's pretty likely that in this state, Bonin would have actively been wrestling with the controls to point the nose up in that state too. The only way to keep Bonin from killing everyone would have been to restrain him. There is no reliable way to "knock" someone out of that kind of panic state.
The only solution would have been physical restraint. Bonin was an active threat
If he doesn't, then I guess then you can resort to force.
I believe the best solution is what Airbus implemented after this incident. An alert if there is dual input, and a button for the captain's side to override the other side. No need to wrestle, press the priority button and take over control.
The ONLY way to have prevented Bonin from crashing the plane would have been to remove him from the controls. He was doing the same thing that lifeguards are warned about; when the human brain is in that kind of panic state, it will happily do things that it should know will inevitably lead to it's own death, like scrambling in such a way that you drown the lifeguard trying to rescue you.
Aircraft UX should be made in such a way that there's never the slightest of doubts about something as fundamental to its function as where the inputs that its using are coming from.
Bonin just went to primal instincts, full fight or flight, and was "taking matters into his own hands" even despite the fact that he was aware he wasn't doing anything useful. The other pilot even told him to stop, but he didn't. He wasn't a copilot in this scenario, but rather a direct adversary to recovery of the plane.
He should have been treated as a rogue pilot the second he started panicking, but the other guy was kinda busy. He was not acting rationally in any way. Had he dropped dead from a heart attack, AF447 would be an interesting anecdote instead of a tragedy.
How do you train pilots for: "In very rare cases, especially during a crisis, you may need to physically harm your coworker to prevent them from causing the death of hundreds of people, but definitely don't do it if you're the one causing the problem, which you will never figure out if you ARE the one causing the problem"
One trick that often works is to put your hand in front of their eyes. Humans have a deep instinct to want to see at all times, so they'll let go of the controls and use their hands to remove yours. No need for physical harm.
Alternatively, we just kinda have an understanding that if your pilot goes into panic, and the copilot can't figure out a way to get them out of it, everyone dies.
Of course, then what if they panicking pilot decides they have to restrain you so they can continue what they are doing?
here is the story - https://en.wikipedia.org/wiki/Disappearance_of_Frederick_Val...
American 587 is another example where, in response to normal wake turbulence, the pilot mashed the rudder back and forth so hard it broke the stabilizer.
There is an airspeed, called maneuvering speed (Va), at or below which it should not be possible to use the flight controls to remove parts of the aircraft. (The aircraft should run out of control authority or stall prior to exceeding any load limits [which is well before the removal of parts].) Every student pilot is taught this prior to passing their first knowledge test and checkride.
The problem with that is the certification rules for Va are for a single input, not for a cyclically reversing sequence of inputs (which is what the first officer of AA 587 did).
As the details became clear, this was a big topic of learning for many pilots, including myself. AA 587 was caused by the flight crew, but I don't put it into the "insane pilot error" category.
This is factually incorrect.
If you read the Final Report you will see that the FP1 (the one that have placed the abnormal inputs in the side stick) did not had the appropriate training; actually the scenario that happen has not even in the trainings (Nightly mid-atlantic flight with screen disagreement with one of the FP missing that I’m normal law).
At least for me, this accident was one of the top 3 most important in terms of safety measures and changes in aviation because the entire industry needed to think about the role of automation, training design, cockpit design, etc.
Two possible reasons in this case.
1) Bonin might not have understood he was in full manual control, and that the computer was no longer restricting his pitch up command to the maximum advisable pitch.
2) The stall warning was intermittent on the way down, because it turns off below a certain air speed. Of course, low air speed contributes to stalling. They were stalling the whole time, but ironically as they started to gain air speed (a good thing) the stall warning would kick in because it was no longer below the lower limit for a stall warning.
Also there's the ever present reason of panic, brain-lock, confusion, etc.
1. Airline human resources deviated from the traditional practice of hiring experienced rudder and stick pilots.
1. Overly permissive company attitudes toward crew rest and a lack of awareness about how it can affect vigilance and fitness for duty.
1. Breakdown of the ceremonies that transfer command and control in the cockpit.
1. Lack of training for high altitude stall recovery.
1. Activities performed in low altitude stall recovery training scenarios are orthogonal to a successful recovery in high altitude stall scenarios.
1. Automation surprise followed by alert saturation combined with incongruous perceptual signals and loss of situational awareness.
1. Aircraft control systems that failed to resolve the ambiguous delegation of authority (double PF) dilemma.
1. Highly compressed timeline of events in a physically disorienting environment.
1. What else?
That's the flight that seeing all the details about on television gave me the fear of flying that I have these days, specially when above the ocean.
I just can't overcome this.
It’s gonna be over quick.
It’s gonna be bang, people are gonna scream, you’re gonna be the most scared you’re ever gonna be for like 15-90 seconds and then it’s all gonna be over.
That’s if you even get to hear the bang in the first place.
So microscopically small chances of something bad happening times not so small chance of dying in a plane crash = nothing to worry about, you have to be incredible lucky to be so unlucky.
Do you mean a total loss of a passenger airline?
Because there was:
- "Prime Air" crash in 2019 ( https://en.wikipedia.org/wiki/Atlas_Air_Flight_3591 ), it was a total loss of a cargo airplane.
- A deadly crash in SF in 2013: https://en.wikipedia.org/wiki/Asiana_Airlines_Flight_214
And a couple more deadly incidents.
I wouldn't count cargo planes if I were evaluating risk as a passenger.
Due to maintenance error, everyone in the plane including the crew black out of hypoxia and crash on the land. There are horrific pictures from the site.
What made me not being afraid of flying was to get familiar with the technicalities of the flights, it's less scary the more you understand it.
I'm generally suspicious of technical solutions to human-factors problems. But I can't help wondering if some combination of voice stress analysis and measuring pilot coordination might be able to produce a warning that would have prompted the flight crew to see that they had stopped flying in an orderly way.
Easy to say speculate, though, when you're not in that situation.
I guess I don't know what you could do with that, flashing another alarm at an already overstressed flight crew seems like it's unlikely to help?
And that has usually been the "airbus way", whereas Boeing has more had a notion of throw things to the pilots often enough so they know what they're doing.
When in normal law, the plane pretty much flies itself. When the computer has uncertainty with its sensors, it drops out of normal law, and expects the pilots to fix the problem.
You're asking that the computer, when it is uncertain in its sensors, to the point where it can't fly under normal law, and where the pilots are expected to fix the problem should actively stop the pilots from taking the 'wrong' actions.
What do you think would happen when the pilots are taking the right actions, but the computer's faulty sensors end up preventing them from doing so?
Who is ultimately in charge in a sensors-out situation? The human? Or the computer? Which of these do you believe should have the final say on flight decisions?
----
If you say 'The computer', I'll have to ask you: How well did that work out for the 346 people killed by Boeing's MCAS, which, thanks to a faulty sensor, was utterly convinced that the 737 was too nose-up, and happily flew the damn thing right into the ground, despite the best efforts of the human pilots.
Asking the computer to fly the plane when its sensors are broken is like asking the pilot to fly the plane with no eyes.
Maybe at some point it became clear that the pilots were doing nothing to actually save the plane, and then the computer could have been justified in ignoring them, and trying to solve the problem itself?
> If you say 'The computer', I'll have to ask you: How well did that work out for the 346 people killed by Boeing's MCAS, which, thanks to a faulty sensor, was utterly convinced that the 737 was too nose-up, and happily flew the damn thing right into the ground.
Because the programming of that computer was criminally stupid. It continued making an assumption despite the fact that the other evidence it had available to it was sufficient to conclude the assumption was false, but it wasn’t programmed to consider any of that other evidence. That a computer with crap software kills people is a problem with that crap software (and the failed regulatory system that allowed it), and not evidence against any proposal not involving such software
How about we let the system whose sensors are functioning ultimately be in charge?
The goal is to reduce those as far as possible, and we may be at or close to the point where any further improvements in one area cause problems in others.
But I still think this particular situation could have been helped somehow. Maybe planes need emergency deployable pitot tubes like they have emergency backup ram air turbines for power.
I don't think the takeaway from this is 'In an emergency situation, where the plane knows that it can't make good decisions, it should lock the pilots out and try to fly itself.' By definition, if the plane knew how to fly itself, it wouldn't be an emergency situation!
----
[1] If the plane is so confused that it can't even detect that its in a stall[2], I can't trust it to fly itself.
[2] The stall alarm would turn off when the plane was stalling, and would turn on when it was recovering from a stall!
This is the root of the main Airbus/Boeing disagreement about design; Airbus leans towards the "pilot and dog" [37] arrangement, Boeing leans toward "let the pilot figure it out".
But the reality is the more and more the computer can handle strange situations, the further the pilots get from being able to react to even stranger situations. That doesn't necessarily mean you shouldn't have additional laws to prevent going from normal law direct to "whelp, it's your plane now, bro".
[37] Old joke: https://jalopnik.com/the-thought-of-a-single-pilot-airliner-...
Even leveling the plane off would probably have recovered from the stall, if done early enough.
And the plane knew it was stalling, it kept yelling "STALL, STALL" - the stall warnings are triggered by another sensor, not the pitot tubes.
The production value on those videos is really high. They are information dense and the creator goes out of his way not to sensationalize.
The mechanics are clear, but aren't pilots trained _ad nauseam_ precisely against this kind of events? It read like this was two panicking guys shouting at each other.
By contrast, listening to the recording of the Hudson River landing, it was stunning just how eerily calm the pilots was there. You hear them opening the manual and reading from it IIRC!
I don't mean it like, they're dumb cos I watched a YouTube video, I just don't understand. Especially since, as the article claims, pitot tubes all freezing at the same time is somewhat common.
And it's hard to predict, you do tons of emergency situations during all the flight training they would have gone through in sims and actual planes, but in the back of your mind you still know it's coming and not a real emergency when the instructor pulls the power out to simulate an engine failure or tapes up a piece of paper to block the airspeed indicator.
If nothing else, it provides complexity to the situation, which I felt was somewhat missing from the article.
I think we do test pilots for alcohol and drug before a flight, but can we also test them for reaction and a couple of hazard scenarios? Do you think it is too much?
About the sensors, is there any inexpensive way to increase the heat or anything to prevent it from happening again?
But lack of sleep is a real issue. Even more on the US side since rest rules are worse than European. Somehow it doesn't get the attention it deserves.
IMO this is almost a cultural issue. We don't prioritize sleep as much as we should and even hold lack of sleep as something to be idolized (i.e. sleep = laziness). How many times do we hear about those CEOs or Founders that wake up super early after only 5 hours of sleep. They're driven, they're hungry, they have something you don't. You're just lazy.
Everyone "knows" we need more sleep just like we know we should floss every day but we have better things to do.
God it's going to be tough for my son who refuses to sleep before 10pm.
I've noticed huge changes in my mood and the mood of my children when we get enough sleep. In my experience their meltdowns/tantrums (and mine as an adult) are either related to lack of sleep or hunger.
Sleep deprivation is a real problem that many may not realize until they get into the rhythm of healthy sleep.
I really recommend watching a breakdown of the instruments during the incident.[2] Things happen fast.
[1]: https://docs.flybywiresim.com/pilots-corner/advanced-guides/...
I hope I'm never in that position...
The fact that the whole situation deteriorated less than 10 minutes after the Captain went to rest, it’s one of the biggest contrafactuals about this case.
As in “if the captain didn’t go to sleep, they’d have been fine”?
The Captain also lost the screen disagreement that happened.
With all these sources of information, the autopilot could have said "Hey the pitot tubes are giving me weird data, but no worries. Still flying the plane. Carry on."
Why didn't that happen?
I think this is probably the main sticking point. I don't think you can do this accurately without some direct measurement. If the plane thinks its air speed is fine but it's actually approaching its stall speed because it guessed its airspeed incorrectly, that'd be really bad.
Here's the relevant sentence: "Crews involved in similar incidents reported that they assumed the brief stall warnings were generated by the erroneous airspeed readings, a not unreasonable interpretation which breaks down only when one learns that the stall warning calculations are based on angle of attack and do not incorporate any airspeed data."
> From the A330/A340 FCTM (Flight Crew Training Manual) section 8.110.4:
> The ADRs provide a number of outputs to many systems and a blockage of the pitot and/or static systems may also lead to the following:
> …
> Alpha floor activation (because AOA outputs from the sensors are corrected by speed inputs)
From what I can tell, these systems are all pretty complicated and have undergone significant real world testing to ensure that the expected protections actually work, assuming the flight computer is receiving accurate data. Which is precisely why they have Alternate Laws - if they can’t guarantee that these protections can work, then they won’t.
"All of this happened near instantaneously, leaving the pilots completely in control of the airplane with little advance warning."
Complex systems have such a low-window for handling or preventing failure that it is impossible to deal with it at manual scale unless we have a super-good control panels and copilots.
Why we need a lot more work on observability and interpretability while operating complex systems.
I also wonder if he had much passion for flying or was just following his father footsteps. I wish they would value passion more, easily demonstrated with military/glider (I must miss some..) experience.
https://99percentinvisible.org/episode/children-of-the-magen...
Cannot say if it is good or bad to be honest, I believe Airbus themselves decided on the English term law to translate the french term.
The word "law" can mean several things depending on the context and it's not uncommon to hear of a system following some subset of rules as operating under a certain "law".
If it's more palatable, you can `s/law/mode/g` even though you may technically have a few different possible modes under some higher "law/regime" [0]
[1]: https://roosterteeth.com/watch/black-box-down-2020-7-30
> pilots into a state of paralyzed agitation..
> all the while trying desperately to understand..
> But there is a reason, written between the lines of the cockpit voice recorder transcript, hidden away within the mysterious code that governs human behavior, a key to the secrets of the profoundly irrational. Its lessons could not be more important, even for those who believe themselves above the doomed crew of flight 447, as the boundary between the responsibilities of man and machine grows ever dimmer.
> Overwhelmed by the noise of the warnings, the terrifying vibrations, and the wildly fluctuating instrument readings, his brain seemed to shut down, paralyzed by confusion and fear.
Citations needed.
Pitot tube icing is one of those issues where automation becomes useless entirely.
while (true) {
try {
airspeed = getAirspeed();
} catch (Exception e) {
log.warn(“”,e);
}
}