This is insane
What are the chances that even a very well trained and experienced major US airline crew would forget to turn of the engine anti-ice within 5 minutes of non-icing conditions? Greater than zero for sure.
This is insane
What are the chances that even a very well trained and experienced major US airline crew would forget to turn of the engine anti-ice within 5 minutes of non-icing conditions? Greater than zero for sure.
>The device sounds a warning after 25 seconds of inactivity by an engineer. If the engineer fails to respond to the warning tone within 15 seconds, the system applies the brakes and stops the train.
https://www.newstimes.com/local/article/Alerter-system-preve...
Although on reflection, that undersells the level of stupidity being proposed here. The pilots need to not only respond to no prompt, but be actively monitoring a condition changing state so that they can then perform the unprompted action.
So, in all seriousness... by what algorithm are the pilots performing this assessment that is not something a computer can perform? How on Earth is it not cheaper and faster to add that to the system than petition a government agency for an exemption? What are all the computers on a plane even for other than monitoring state changes and performing actions in response? Even high-assurance, safety-critical coding should be able to outpace a Federal bureaucracy on something like this comfortably.
I've heard stories of cases where development orgs were given the option of changing a line of code or re designing the hardware. They of course redesigned the hardware.
If you are no longer capable of building safe planes, your next best option is to petition the government to accept unsafe planes.
If your company can't build safe planes, the real "next best option" is to fix your company.
Loss of market share. As in, customers actively looking at the type of aircraft when they book a ticket. Airplanes becoming reluctant to ordering Boeing.
At this time, every $1 you invest in making it known what Boeing does since 15 years, results in $2 or $3 of loss of market share for Boeing. Absolutely the time to buy ads to promote articles about Boeing.
I would actually trust Comac more than Boeing, as Comac has something to prove, whereas Boeing has been proven to crash planes and bribe the FAA.
In 2013 they received frames (the circular structures that make the fuselage) which instead of being machined, has been created manually. Voids were all in the wrong place because the workers had taken the blueprints symmetrically.
Did they ditch the frames? Of course not? They remade the cuts so that it fits upside down! And soldered the I-beam parts that had been cut! Result: The circular frames, which are a critical structural component, have twice as many gaps and holes and soldered sections than the designed piece.
Bulkheads, circular frames, MCAS… It’s appalling engineering practices.
And the dinner party system with FAA, introduced by Mac Donnell’s practices when it was bought over, has to stop. They should not be friends in real life.
Boeing's staff and plant are strategic assets, its executives and shareholders aren't. The US government could totally let harm come the latter group.
Ask yourself: would you take a position at Boeing trying to "fix the company"?
The only way out of this is to poach the few remaining employees that still have technical knowledge, setup a new company that refuses to employ everyone with a vested interest in Boeing, and take their market. This is hard for aerospace because of the sheer complexity of the product and the baseline quality levels needed to deliver a safe experience.
As an executive with guaranteed $xM in pay over a few years?
Sure — if I fail, I’ll just use that position as a stepping stone to my next executive role.
Why wouldn’t I take a shot at something positive, when there’s little to no downside?
This is why we have the world that we do.
I believe the board and executives would genuinely want me to fix it.
But it may nevertheless be impossible due to organizational mechanics, entrenched bureaucracy, short-sighted shareholders, etc.
I was just pointing out that it’s ridiculous to pretend nobody would want the job because it’s likely to fail when there’s only upside, for both yourself and the company. A literal win-win.
Implying there’s something negative in my comment because it’s easy to be cheaply cynical (and the cheap cynicism in the comment I originally replied to) is what’s actually wrong with the world — and why things are so bad.
Who gives up on something that only has upsides without even trying?
So here's the more detailed sincere response, based on experience working in a similar large, similarly dysfunctional technology company (and also knowing people who spent several years at Boeing specifically):
It is usually not possible for a chief executive to fix a company. The reason is simply sheer complexity. A company of 100,000 people has potentially 100,000! (factorial) different working relationships within it. In practice it's less because not everyone communicates with everybody else, but even a small department of 100 people has more different relationships than anyone can possibly keep track of. No one executive is going to know every single employee, every team, every project. And without them having those personal relationships, they don't have enough trust to convince people to alter their behavior.
If the company is in trouble in the first place, that means that the way they do business is no longer adapted to the marketplace. So you need to get the company to make changes. But if you root cause each individual problem, you find that the company is fractally fucked up. The employee is usually acting according to the incentives available to them; if they did things differently, they would fail to get the cooperation needed to accomplish their goals (at best) or lose their job (at worse). And that's the key part: in a big company, achieving any goal, regardless of how small, requires the cooperation of many different people. In a normal functioning company things mostly work because these habits of cooperation grew up in good times, working culture & processes adapted themselves to the activities that actually made the company money, and so when people just do their jobs good things basically result. But as the company grows and ages, it ossifies. Over time they want to do things like introduce a new jetliner, but find that the right combination of people with the right skillsets to do things like make engine nacelles that don't explode no longer exist.
This is why advice for turnaround CEOs is "get the wrong people off the bus and the right people on the bus". And they frequently hire outsiders, or folks from much earlier in the company's history. Their first task is to stabilize finances. Their next task is to identify the parts of the company that are still functional, then double down on them (often made harder because these folks were often laid off as part of stabilizing finances). Their next task is to sell off or lay off all the folks that are embedded in organizations that are no longer serving the company's purposes. Remember that there are > 100K employees, and you're building a product of exceptional engineering complexity, and that nobody knows everything the company is doing. It's pretty hard to have enough visibility into the company's product, engineering, supplier relationships, employee base, finances, etc. to do this correctly.
I think it's very likely that nobody currently at Boeing has the ability and willingness to make the kinds of changes they would need to make in order to become a functional company again, because Boeing has spent over two decades systematically purging senior engineers from management and leadership in order to become another crappy company full of empty suits with MBAs, who don't understand the product they're making, and don't care if they're literally killing people and the company is rotting out from under them as long as they can monetize the rot to make their quarterly numbers.
If the use fails the plane crashes.
Two very different problems.
This is very good.
The correct analogy would have been: if the driver did not press the button then the train accelerates until they do. Not good.
Over night most normal operations cease, so it's quiet on the bridge. But an officer is on duty to keep watch, because the ship is still moving, often relatively fast, and it needs a human to obey pre-existing route plan decisions, observe changing conditions, stay alert to other vessels and so on. However, the bridge (on a modern large ship) is warm and dark and at night tired humans in warm dark rooms will sleep.
So BNWAS will (if operating correctly) periodically need to be "nudged" to show that the officer on watch is awake and somewhat paying attention. If they do nothing for a while the BNWAS will alert them and if they ignore that it will eventually alarm critical crew, often the Master ("Captain") of the ship or other senior officers who are asleep in their cabins.
Now of course nobody wants to leave a nice dream to discover that instead of your teenage girlfriend agreeing to go on that picnic you never got to that sound is their boss, very angrily demanding to know what the fuck you're doing curled up by the radar console. So unfortunately sometimes after a serious incident (e.g. cargo ship has "decided" to wait right next to a small island a few miles from the usual route from 4am until midday, and then when it gets to a dock it seems very smashed up at the bottom as though it was grounded and had to wait until higher tides lifted it clear...) we find the BNWAS has been disabled crudely (it's not as though ship's crew tend to be IT experts)...
But this is a completely different scenario. The BNWAS is not something which causes a disaster if you forget to react, it's an alarm to prevent such disasters which would otherwise be commonplace.
https://en.wikipedia.org/wiki/Bridge_navigational_watch_alar...
Instantly reminded me of: https://en.wikipedia.org/wiki/Sifa
[1] Moral Crumple Zones: Cautionary Tales in Human-Robot Interaction by Madeline Clare Elish
Also note that blaming the human has been Tesla's strategy for avoiding responsibility on their software drive system failures.
Oh, you floored it while the car was pointed at the wall? It has cameras, why didn't the car disable the go pedal?
This is happening more and more with cars, and it seems inevitable that it will happen in other spaces as well, as software is expected to protect us from ourselves.
Slap a temperature sensor on/in/near the heater
Monitor current through the heater for temperature coefficient response
Capacitive sensing of ice on the heater
A timer that shuts off the heater after some time and a buzzer to alert the crew
You could even have a thermal fuse with a manual time-limited override
Honestly there's so many easy ways to prevent thermal runaway that creating a situation where THE ENGINE FALLS OFF is inexcusably negligent.
My space heater has no less than three independent, redundant safeties. As does my clothes iron, my coffee pot, my slow cooker. It really is not that complicated.
Matt Stoller wrote a compelling article asserting that the breakdown at Boeing resulted from the breakdown of the separation between their military and civilian divisions: https://www.thebignewsletter.com/p/the-coming-boeing-bailout
If you think about it, civilian standards must be way higher than military ones; you're talking about millions of people per year who can't bail out of a crashing plane.
MCAS is a reflection of their systems integration engineers not being the caliber and experience they need: it was obviously a defective design.
If they had done what they needed to do and designed a new plane from scratch, those people wouldn't be dead.
OR if they'd simply acknowledged the changed characteristics of the plane, struck deals with purchasers to subsidize training expenses, and let pilots fly it themselves... those people wouldn't be dead.
Boeing's recent behavior, as reported by this article, warrants further disgust and ought to be featured in the mainstream news.
And sensing icing on an inlet isn’t as simple as you make it out to be.
Maybe this is overly optimistic, but I'm confident they could figure out something if they wanted to.
The latest Tesla features manual window wipers and if you don't use them right the car explodes.
1. Wait for people to report a problem 2. Inform users that they were doing it wrong, it was always intended for you to do it the other way
E.g. how to hold your iPhone.
Reference?
I think the one they went with was much better.
In its petition to the FAA, Boeing argues the breakup of the engine nacelle is “extremely improbable” and that an exemption will not reduce safety.
“The 737 MAX has been in service since 2017 and has accumulated over 6.5 million flight hours. In that time, there have been no reported cases of parts departing aircraft due to overheating of the engine nacelle inlet structure,” the filing states.
Read: happens at least twice a week
Wow, that's a great phrase. "No reported cases" is a serious weasel-phrase, and "parts departing aircraft" is much easier to take than "things falling off planes."
>I fly the MAX. That switch is left on all the time by accident. If it was a catastrophic issue we certainly would already know. https://www.reddit.com/r/aviation/comments/18z8mk6/737_max_d...
which I guess is reassuring in a way.
(I hear from the rumor mill, something similar is happening at Google).
Edit: Also depending on altitude ambient temperature can vary over a range of several hundred degrees - it gets really really cold at 40,000ft.
The problem isn't knowing whether or not you're in possible icing conditions if you think to ask the question, but rather reliably remembering to evaluate it every single time you enter and exit possible icing conditions.
* SAT - static air temp (air temp before the ram rise).
It should be a caution light or something at least.
But ATPs don't have any trouble evaluating "am I in potential icing conditions?" as they've been doing it for one to many thousands of hours previously.
This kind of mistake has been made so often and lives have been paid that I find it crazy that it's still being proposed.
If it were just a temperature thing, you'd think it could be automated, but I don't think that's really the main thing they're dealing with here.
In theory this means switching the system off when you exit the clouds.
This is usually pretty noticeable, but maybe less so at night, since you might be breaking out into a pocket or a clear layer between other layers, without visibly seeing much of anything outside.
I would hesitate to comment on the feasibility of this beyond what the interviewed persons have said, precisely because they're not clarifying (to the readers in any case) what the actual thresholds here are. And the interviewees don't seem convinced that this is a reasonable/safe requirement.
But easy to forget to check the instrumentation.