Alaska 737 cockpit voice recorder data erasure renews safety debate
reuters.com
reuters.com
> The NTSB has conducted 10 investigations since 2018 where the CVR was overwritten, including four runway incursions, Homendy said.
I tuned into the NTSB press brief last night, and they emphasized understanding communication is important for the best accident analysis. Homendy stated that they now do not have any record of communication between the flight deck and cabin.
Develop a standardized structure to make it searchable by different factors or combinations of factors (e.g., 777 model later than Z & decending & outside temp < X & throttle is > Y & etc.) When there's an accident, you could review similar circumstances.
From my ignorant perspective on air safety, it would seem to be a gold mine.
But what you're trying to solve, already exists without the voice recording part. It's called FOQA or Flight Operations Quality Assurance. Mandatory for airlines in Europe, not yet mandatory in the US but may be in the future.
It records hundreds of parameters from engine indications to touchdown speed, G-loading, control inputs etc. Automatically uploaded to the operator and tracked for the whole fleet. That data is de-identified and used for safety analysis and improvement.
An argument can easily be made that this extra stress will make flying less safe.
Edit: my next car will probably have mandatory spyware and unlike pilots there won't be a guaranteed no blame process if something happens. It is pretty easy to see how this will be abused by insurance companies and data harvesters.
I think I kind of understand the processes that lead to this. But I seriously wish tech people wouldn't be accepting it and even argue for it.
Tech people are arguing for accountability in a life/death scenario.
That there is no privacy in public spaces is a longstanding social/legal tradition. A cockpit is physically private for physical security reasons but the pilots in the cockpit are acting on behalf of public trust. Their social norms in that physical context are not their own to define.
If pilots want privacy they can quit and sit at home.
Just to illustrate, 5 years ago a first officer on year 2 pay would make on average 40-50k per year. In 2023 that has increased to 143k per year for all three American Airlines owned regionals (plus a 165k retention bonus). Similar for Spirit, increased to 142k standard and 145k on the Airbus. And JetBlue to 160k for the A320 and 153k for the A220.
In this market, the first airline CEO to say "well then quit and sit at home" to their union will have half their workforce walk out within months.
The law of diminishing returns very much exist, and as one of my teachers in engineering once pointed out: if you really want to use surveillance to put a dent in the crime statistics you should put it in people's living rooms and in their bedrooms.
Have you considered what the extra stress of considering ones every word during a long and stressful day can do to someones concentration?
I mean many, the thoughts about what they said earlier this morning is bad enough even if it wasn't recorded.
We already record a couple of hours or so. If you want to record more, it is up to you to come up with data for how many more air traffic accidents we can solve and also to explain how we can know that it won't make air traffic more dangerous.
This is an argument against any change that involves unknowns. I see it often, and I absolutely hate it.
Everything worked out in this case but that’s because every incident is a lesson.
This means airlines will have a smaller pool of less desirable / qualified pilots to choose from.
I get that people want their privacy, but if it saves lives, it's a workplace (like customer service and many other jobs that aren't life-threatening), that outweighs it. People get surveilled constantly in their private lives and live with the stress.
I work on larger UAS systems where we don’t have any form of mandatory recording for the FAA. We do have wireless headsets that we use for comms between the pilot, the GCS operator, the flight director, and whatever engineering support staff are on the ground. The system would allow us to record pretty trivially but we’ve debated this and explicitly decided that we get more value from being able to keep the communication as candid as possible instead of having to worry about having every word we say over comms scrutinized if there’s an incident.
If anything, the proliferation of dash cams will (and have) lead to bad drivers being appropriately charged more for insurance than good drivers. Previously, if you were cut off and collided with someone, you were always assumed to be at fault if you were behind the other driver.
Aviation is by far the safest form of transportation. In the last 10 years of data (2012-2021) there were a total of 2 passenger fatalities on US airlines across several billion passengers for that time period [1].
If you want to start recording workplaces to improve safety, there are a lot of industries to look at before aviation.
[1]. https://www.airlines.org/dataset/safety-record-of-u-s-air-ca...
Most civilians don't seem to have much sympathy.
This is irrelevant to the discussion about recording pilots.
Should all medical device software developers have the entirety of their working lives be archived in a similar manner?
First they came for, etc, but they came for me a long time ago.
The equivalent of an always-on cockpit voice recorder would be... screen recording all of your digital devices during working hours? And, turn a mic on just to be safe?
I'm a programmer on a team with other programmers, many of us remote.
We're not standing around a water-cooler talking. We're on team chats. We're reply-all'ing to email-chains. We're sharing memes. Half the time we talk across chat when we're sitting in the same room.
These aren't formal design docs or code output [the analogy to flight controls], this is our water-cooler talk, and it can all be subpoenaed in a variety of situations, to be read into court record and taken out of context for the rest of time.
Would you be okay with a recorder being beside your desk at all times? Catching every conversation, even personal ones?
Currently it's your choice to participate in sending memes over email. You also have the choice to walk over and have a private conversation.
But are all zoom calls required to be archived, specifically in the medical device industry?
Certainly you have the option to make a phone call to a teammate, or walk over to someone if not remote, and say something without any record. Don't you?
Mind you, that is how people mostly work anyway. Even if I generally trust an employer to not be intrusively monitoring my communications, for anything sensitive I'm ideally going to talk in person or failing that, at least go with a personal cell call.
But we aren't talking about how to circumvent monitoring. We're talking about working when your idle socializing (while working) is monitored and logged.
[Edit: I mean, voice chit-chat. Just talking to each other. That gets recorded for pilots, and not for software engineers, no matter how long they keep our (text) chats for. Stuff gets said in person, by voice, that would never get typed out in a chat.]
Chat logs are tiny.
As such, it's a large liability, and most companies retain those sorts of records for the minimum amount of time acceptable by law/regulation/customary expectations.
If this is true your legal team is committing malpractice.
Will you too?
How about instead of that nonsense we just have a reasonable conversation and assume best intentions?
But seriously, why did you skip over the software devs? Their errors could kill many more people than a bad doctor.
Right now tons of public activity is monitored already but almost in all cases it's to catch customer abuse and never for business abuse. Monitoring everything 100% will become one of the greatest equalisers. Only people rejecting this are people in abusive power.
I have looked at my kids’ pediatrician visit summaries, and they will state “doctor did this and that”, when I know for a fact the doctor did not. So I have to send a mychart message to document that the doctor did not do those things.
Now, I understand that excessive liability is probably driving doctors to do unnecessary things and so 95% of the time, there is no ill intent, but rather shrewd judgment of not wasting time, however writing (or copy pasting) a false visit summary is not the answer.
Note: All of this is U.S. perspective, I have no idea about healthcare anywhere else.
Given how hard it is to even find half-decent doctors even taking new patients, or having appointments available this quarter let alone soon, the doctor likely doesn't need you nearly as much as you probably need a doctor. They're going to be fully booked even if they ask you to leave and decline to be filmed, so they don't have any reason to consent to it. This is one place where the "try to make the customer happy" conventional wisdom about transactional relationships seems to not apply one iota.
I'd like to point out that one thing the tech industry is bad about is figuring out which technology to definitely not build. In fact, we've collectively resisted any attempt at so doing.
But joking aside, in most places there are checks and balances between privacy impact and benefit. We all accept that some government agencies know some of our data, because the net benefit to society is bigger than the loss of privacy. And you would normally try to do such things in the least invasive way possible while achieving the benefit.
Where you go wrong in your passenger rant, is in assuming there is a big safety benefit in more recording of pilots. There were a total of 2 fatalities on US airlines in the last 10 years [1], while billions of passengers were transported. The safety record of airline transport is stellar, without more recording. So yes, I believe it is very reasonable to consider what is and isn't acceptable to the crew being recorded.
[1] https://www.airlines.org/dataset/safety-record-of-u-s-air-ca...
The recording should anyway only be retrieved under specific conditions and in a controlled environment.
In this specific case the longer recording duration may have actually aided the investigation and thus further improve airline safety.
There is also more nuance to the debate around the 25 hours change. Like you say it should only be used under specific conditions and in a controlled environment, but in the US unfortunately recordings have been leaked and have been used for disciplinary purposes instead of a blame-less investigation for safety.
Europe has had rules for 25 hour recording since 2021, as far as I know without any opposition. But European recordings have also not been misused before.
If ICAO can require keeping 25 hours why should a crew get to choose 2?
- They need to work well together, and the better rapport they have with each other the better they're likely to perform in an actual incident. Regular interaction on the job is a part of that.
- They work a job that is often remarkably boring for much of the time. Drowsiness setting in is a real concern - a degree of social interaction is good at both keeping people engaged, and at helping them gauge how alert the other crew members are.
https://en.wikipedia.org/wiki/Sterile_flight_deck_rule
I agree that the crew should feel free to chat. And when there is an accident, they should expect that the recordings are kept.
It's also unfathomably unreasonable to call for storage of all voice recordings of the flight deck in perpetuity. That's ridiculous and is privacy invading. If you want to improve the state of this industry, you are looking in the wrong place.
My workplace is my laptop, and I’m fairly certain that it records more than the airplane does. I certainly have no expectation of privacy while using it. Any meeting is recorded regardless of what is being said.
I’m sure my casual conversations would be if anyone felt I said anything valuable while muttering at my screen.
Not saying that’s great. Just saying that airline staff may currently have more privacy than most.
So long as the recording is properly encrypted, and the access is properly managed, privacy will be preserved.
If those things aren't true, then there is a privacy violation, regardless of the 2 hour time constraint.
For one police officers are often able to turn on and off recording themselves, so it becomes as much of a protection for them as for everyone else. That is: if they are good police officers.
Secondly, unlike pilots, the police force in many countries does not have a stellar track record.
Edit: I do have some concerns. Yes, police brutality absolutely exists. But there also seems to exist a subset of the population - also represented here - who think police can be like superman and whenever they aren't that's because they are evil and enjoy harming innocents.
So I guess they had similar objections to being recorded 24x7 and that was accommodated in the rules around body cams.
Storing something for two hours is still storing it. The point was why is it bad if it is listen to for X minutes in a month, but okay if it is listen to for X minutes today? I can see no reason at all why two hours is okay if five isn't. I could understand if the argument was that nothing should be stored at all.
> The point was why is it bad if it is listen to for X minutes in a month, but okay if it is listen to for X minutes today?
That wasn't the point and the problem is who is listening, why, and what they may do with the information.
What can you say that I can hear on a recording that would stress you out if I listen in 3 hours but not if I listen after 1 hour? Is 2 hours okay but 2,5 is perpetual suddenly? That's a strange hill to die on. Zero hours make sense. 2 and no more or less seems ... strange. Why 2 and not 3? 33? 0,3?
Actually yes, it is the point. As has already been exhaustively pointed out in this thread the issue is the difference between two hours on the airplane that auto-erase and perpetual recording available to the company for whatever purpose they can dream up.
> Is 2 hours okay but 2,5 is perpetual suddenly?
That's not what the word "perpetual" means. "Perpetual" means "forever" as in "we never delete these recordings".
>"This is a proposal from the NTSB to the FAA to raise the CVR recording time from 2 hours to 25 hours, in line with ICAO."
You are arguing two hours is fine, but 25 hours is "perpetual recording". That is a strawman.
When I go into the office to meet with customers or whatever, there aren't cameras and microphones everywhere. I can use a personal cell phone (which is all I have these days anyway). And, honestly, for something personal but not in any way getting into legal issues, I have no problem communicating over chat or a video call.
And while we're at it, why stop with CVRs? Software is a key component of all engineering domains today, and thus a critical safety factor.
All MacBooks (the most popular developer machine today) have built-in microphones. We should using them to record all dev conversations (after all, there's zero incremental hardware cost to doing so), as well as all keystrokes of anyone who writes software, 24/7, so that we can retrospectively analyze why they failed to avoid writing buggy code and the decisions that led to it.
Everyone who has had their PII leaked will rejoice, knowing that we can finally "get" those nasty open- and closed-source developers who created CVEs.
"B-b-but, that's different!"
There's a clear and obvious difference between a self-important person who writes software and a person who pilots hundreds of folks over top of thousands of other folks in a slow and only mildly explosive missile.
If we record every action of the pilot of a plane, why wouldn’t we also record every action of the developers who wrote the autopilot software, or the fly-by-wire software?
As a developer, every final action is also recorded in the performance of their job. That's what Git is for, and that history lasts for quite a lot longer than 2 hours.
The original comment suggested recording every action from the cockpit and using it for analytical data. The final action isn’t the goal. The steps and discussion that got them to the final action is. Hence recording every step the pilot takes, and the equivalent would be also recording every discussion that the software developer made that influenced them to write the code the way they did.
Saying “the git commit is there, that should be good enough to know the result” is like saying “the pilot landed the plane, that should be good enough to know the result”. Why do we even need CVRs at all? The final action is right there, right?
So again, why record everything the pilot says but not everything the developer that wrote the autopilot says?
For a pilot that just flew a 12 hour flight with a malfunction that would be of obvious benefit.
For a developer that introduced a bug 8 months ago, maybe not so much. Even if you recorded every interaction the dev had over that time period nobody would be able to go through everything and get sensible information.
If ‘directly responsible for lives’ is the rationale for voice recording pilots in the course of their jobs, and not developers, since developers are not directly responsible, but indirectly responsible, can we also expand the list of professions to include always recording police, firemen, and all medical professionals all the time.
I suspect making sure that surgeons know that anything they say during the course of their job, can and will be held against them in a court of law, will not serve to improve the quality of the work they do.
As you can imagine, this is not a situation that US pilots want to be subject to and they are probably right that safety would actually be made worse.
For audio recordings, in the absence of an incident, I see no reason to do it.
And note that the real problem is with authentication (MACs, or digital signatures), not encryption. Public availability of those records is actually probably beneficial. It's a common misconception to think that you need to encrypt while in reality you perhaps need to encrypt, but first you absolutely must authenticate.
On top of that, almost everyone in the US also has some form of collision avoidance technology now, as well (either TCAS or ADS-B).
And there's plenty of times where the only time I could hear ATC was with the squelch full open, trying to pick a faint signal out through the static. Digital modes are terrible for this.
We're talking about something like a landing clearance. It doesn't have to be completely off the chart. And yes you can inject a message like that successfully, without the ATC ever knowing.
TCAS is equally broken - doesn't have authentication codes / signatures. It's actually more vulnerable since it has higher priority than ATC.
Digital modes can encode speech more efficiently than analog modes, thus reaching further on the same link budget. For example ADS-B is "audible" as far as the curvature of the planet allows - my own antenna can hear messages from up to 200mi away.
It really is a serious problem.
See: https://en.m.wikipedia.org/wiki/Cliff_effect
https://www.selby.com.au/blog/what-is-the-digital-cliff-2
Up in the air, I can also hear AM analog voice transmissions from 200 miles away, so that's not really a good measure of performance. Both modes already do that. Benefit of having an unobstructed line of sight from several miles of altitude. :)
https://cybernews.com/news/century-old-technology-hack-broug...
It's only a matter of time before this happens in aviation, but unlike in the trains case it doesn't have to be just an availability problem (all trains stopped safely), it can be a "remote code execution" problem.
It took 6 months to find him, and mind you that that guy was the opposite of clever (he was talking from his bathtub, from what I remember, and he started out not even knowing the ATC language).
Also, it really makes sense to think ahead just a bit, you know. Not everything has to be triggered with an accident, and in this case we're likely talking about terrorism, since no one would do this without realising just how bad the legal consequences are.
And if another voice comes over the freq giving you instructions that don't make sense, the response is going to be a polite version of "WTF?"
There really is no way to do it safe without authentication codes or digital signatures.
PS. And the readback can be just jammed.
Every modern airliner has dual-redundant or better GPS-aided inertial navigation systems, and every professional pilot is trained on procedures for flying in the airspace system after losing all their (multiple) radios. This is literally not a risk worth spending the millions/billions it would cost to mitigate, any more than Joe Average Internet User needs to hire a professional cybersecurity firm to secure his home Wi-Fi router.
https://arstechnica.com/information-technology/2019/05/the-r...
On a foggy day when the visibility is right at minimums, I can imagine a huge risk of aircraft being sent off-course right before landing. Hopefully the pilots would still be able to recover the situation - the TOGA button is right there on the thrust levers on most aircraft - but nobody is infallible.
I would imagine that some military transport aircraft have backup, INS-based navigation systems that create a synthetic glidepath without external radio signals. Airbus have been trying to introduce such systems on commercial airliners for quite a while, although that is intended to allow landing on more remote runways rather than specifically to improve security against malicious interference.
All that is to say that the lack of fatal aviation accidents that we know were caused by malicious radio interference doesn't in any way make the attack less feasible.
Digital signatures, even with conventional X509 certificates straight out of the OpenSSL library, would go a long way to mitigate this risk. What about the risk of the signatures failing? The worst-case scenario is that the pilots get a warning on their ECAM display: "Comms not secure". That should at least alert them to the possibility of false readings even if it can't correct them.
(as well as to keep it private & encrypted, and only accessible with a warrant from a judge)
If the FAA does not mandate, at least, this from now on, it will just add to the pile of evidence that they are in Boeing's pocket.
PS: Secondary backup. No existing system has to change. Just an outer layer of backup tapping into the existing data recording loop.
It's sad too because analyzing every cockpit conversation with AI to highlight things that may cause common confusion could be invaluable. Instead, the short-sighted leadership in today's business world will use it for (job) performance analysis and to penalize workers for failing to act like robots :-(
Full privacy preservation.
I don't see how it's in the interests of Boeing to keep the mandate at 2 hours. If it gets extended, it's likely that in future incidents they will have more evidence of pilot error than they do now since that is the primary cause of accidents (even for Boeing), plus I am sure they can print some nice invoices for the costs of the upgrades to existing fleets.
- most pilot errors resulting in an incident occur close to the incident and thus the # of times it's their fault will drop off with longer recording time
- the longer recording time may allow for some complaints about the Boeing aircraft or some clunking noises to be identified which could indicate an issue with the aircraft
(aka “aircraft defects”)
PS: I mean it.
(disclaimer: Founder tier pricing. General pricing may vary - up)
/s
Former NASA Engineer, baby B-)
> peak HN arrogance
Take peak HN arrogance, balance it against peak bureaucratic promises plus peak actual cost, and let me know what you come out with.
It's the pilots' union that is opposing this. I doubt Boeing cares either way. If anything they'd want the extra data.
I think the reasons for the missing data need to be established before we go calling for sweeping change.
EDIT: It appears the recorder had continued operation and thus overwrote the data. This is a failure in procedure. Procedures are in place for securing evidence in incidents such as this and for some reason the ball was dropped.
The ICAO 25 hour standard seems reasonable to me as someone in the industry.
What's your technical solution to this aspect? The solution must be "technologically trivial" which I take to mean implementable today or in the near future with no change to how current regulations or laws work or to how current workstreams outside of the secondary backup system work (i.e., no change is required like having the judiciary start using crypto). We are also using the strict definition of "only." It should be technologically impossible for any person or entity to access the data without a warrant.
This violates rule 2 by not assuring that a warrant is necessary because somebody at the government institution has the private key (assuming that institution is not the judge): It should be technologically impossible for any person or entity to access the data without a warrant
(not same as open-access: judge must authorize playback)
I'm not suggesting otherwise.
> it will just add to the pile of evidence that they are in Boeing's pocket.
I don't understand the connection between the lack of voice recordings and how that is proof of the FAA protecting Boeing rather than the lack of voice recordings as proof of the FAA protecting the pilots.
In a crash scenario obviously power will be lost at some point and not return so the data is safe.
In a malfunction scenario standard procedure would be to pull the box before powerup so even if maintenance doesn't get to the plane quickly or the pilot's incident report arrives after a few hours the recording related to it is still present and maintenance can go back and grab it. Or for scenarios where a malfunction beings on the early part of a multi-segment flight plan the data would still be available.
But for pilot privacy the recordings are not held forever. During normal operations the plane will be powered down, eg while parked in-between flights, and when powered up older recordings get truncated.
All telemetry should be streamed to a cloud service in real time. Absolutely no reason not to do that. No one should ever need to "search" for a plane or wonder what happened to it.
Catastrophic crash scenarios are not the only scenarios where data preservation is desirable.
That's exactly why I said "In a malfunction scenario" in my comment.
Modern aviation uses essentially a blameless post-mortem incident reporting process where pilots are encouraged to report when something unexpected happens - even though the airplane wasn't damaged and no one was injured. This has helped tremendously both in discovering issues that could be the cause of a crash in the future as well as improving training for other pilots.
But very rarely is any data recovered in these situations. If things worked as I noted maintenance would have enough time to grab the data after the report without storing the recordings forever.
Breaks during cases don't happen when you're in private practice in anesthesiology.
The voice recorder overwrites itself on a two-hour loop. Two hours of voice data takes about a gigabyte of space at most. There is no technical barrier to right sizing this, and there is nothing special about the aerospace use case that prevents it.
Why would anyone think a two-hour buffer for something so critical would be appropriate? And why would it continue to overwrite itself after it’s grounded? Why is there no backup? Has it never been thought relevant to gather, say, an entire flights worth of data instead?
This highlights a complete failure on multiple levels and an inability to critically think about the problem space. How much time was spent implementing a system that under most circumstances where it would be needed would render itself entirely useless?
>Debate about whether to adopt the longer recording standard weighs considerations about cost and privacy implications against safety.
>The U.S. FAA has previously rejected the NTSB's call for mandating the retrofitting aircraft with new cockpit voice recorders, saying the costs would be significant at $741 million versus $196 million under incremental upgrades it proposed.
>Pilots have also opposed the move, with the union representing pilots for air-freight company Atlas Air telling the FAA the longer recordings would be an invasion of worker privacy.
Whether or not a "technical barrier" exists is a non-sequitur. Just because you can get a $10 audio recorder on aliexpress that records 200 hours, doesn't mean it takes $10 to implement this change per plane.
I bet many investigators would be very happy with the aliexpress implementation ...
Im starting to wonder if the yet to be certified 777X will store for more than 2 hours as it takes 16 hour flights.
This airplane was brand new. It should be using something more modern.
And then suggesting to revoke the licenses of a crew that at one of the most stressful moments in their career, right after a major incident, forgets to pull a circuit breaker is ridiculous. Luckily that is not how things in the aviation industry are done.
Workers responsible for multi-million dollar machines and sometimes hundreds of human lives. I doubt anyone but the pilots care one bit about their on-the-job privacy.
Mandate the 25hr recording duration.
Mandate that full playback can only be done for accident investigation purposes By NTSB, unless requested by the crew(s). Some limited duration carve-out to allow maintenance crews to listen to last 15 mins to verify operation.
That’s silly. And we all know it. Nothing in a cockpit is “private” in this regard when it comes to transport of hundreds of people.
> cost
There it is. That’s all it ever is. If the cost of doing it right is higher than the fines of gambling with doing it wrong, the wrong way will always be chosen.
This is bog standard corporate life under capitalism.
It is about privacy, it's easy to verify the history of pilot's unions concerns and objections.
Incorrect. This is a struggle of ratio between regulation and lobby..
CVRs were always highly contentious when introduced, due to exactly the situations you see today in the media. The pilot unions were concerned that these recordings would be released to the public, both out of context and releasing private personal data not relevant to the public - especially if anything at all salacious could be found.
There were strict protections about CVR data never being released, but of course those restrictions more or less no longer exist today in reality - leaks abound.
I think those that dismiss this concern entirely are the folks who cannot think critically. It highlights a legitimate concern for workplace privacy, of which the Overton window has shifted drastically into less privacy expectations over my lifetime. The public will nearly unanimously call for 25 hours here, but this was not the case even 40 years ago.
I think the benefit outweighs the concerns in this particular case, but you are now seeing the same fight regarding cockpit video recorders. I can't say the pilots are wrong given the history of CVR data breaches.
If I were a pilot I'd grudgingly support the existence of the CVRs, but I can't say I'd really like the idea. I've seen how sound bites get taken completely out of context and sound worse than they were intended at the time. I've also seen how CVR data is absolutely critical in resolving some accidents. It's all a tradeoff, but certainly not an immediately obvious one unless you value privacy at zero.
Edit: The idea behind the 2 hours thing, was that 2 hours would be plenty of time to record anything relevant to an actual accident. Either the plane is in pieces and recording has stopped, or the recordings get pulled on successful landing after declaring emergency. The entire intent was to limit what was available to only the accident sequences - not general chit chat 5 hours prior to any event while they were waiting for taxi clearance. Technical limitations at the time also didn't hurt this argument.
Also I think it's good to point out that relying on the pilots to pull the breaker after an incident is not ideal and one of those things that the union has absolutely kept in as a feature, not a bug. This has obviously been abused.
Declaring an emergency (standing alone) should not be a reason to pull the CVR, IMO. There should be an aviation-safety related reason at a minimum. (Declaring an emergency to facilitate expedited handling for a passenger medical emergency should not trigger a need to preserve the CVR recordings, as one concrete example.)
Your opinion/take on this is relatively new. While technically (legally) correct, there was a whole lot of social pushback on this statement or idea even in my lifetime.
This take on workplace privacy has not been the social standard for very long, and is certainly not a universally shared opinion.
Edit: To avoid comment spam here on an irrelevant side-subject. I didn't say it was a regression or a bad thing. I simply am pointing out it has massively shifted in a relatively short period of time. There was serious public debate about introducing these at all just a generation ago. Now it's seen as completely normal to have your entire workday recorded with zero expectation of privacy. It's a rather drastic shift in society.
So if you don't agree, you can't think critically. Got it.
Or maybe, we did think about it critically and simply don't agree.
There are various way this can be solved. We have modern encryption that could make this far, far safer then it is today. We have methods from data leaking. We have process to only allow data to be decrypted if required.
This would actually force us to really think critically about who has what access when. In planing this the airlines, unions, FAA should sit together with some technical experts and think of this critically.
This seems less complex to me then a modern high bypass turbo engine.
There are not. You cannot solve a social problem with a technical solution. If the data exists, it can and likely will be used.
> This highlights a complete failure on multiple levels and an inability to critically think about the problem space. How much time was spent implementing a system that under most circumstances where it would be needed would render itself entirely useless?
I was responding in particular to this. It does not highlight an inability to think critically unless you value privacy at zero and only look at these recordings as a technical problem. Under most circumstances when it's needed this system has functioned exactly as designed. You read about the failures because they are the exception. Believing that CVRs as-designed fail under "most circumstances" would be a lack of critical thought to me. I was limiting my scope to this statement.
I would actually agree with you in general if for not that comment. It simply means we disagree. But it surely does not mean no one has thought critically about this subject when it was introduced or since.
The only way to stop the CVR from recording is to depower the airplane (which is one of the steps you take prior to an emergency evacuation) or to pull the circuit breaker if the airplane needs to stay powered.
A pilot would never pull the circuit breaker without confirmation from management or safety to do so. It’s just not done routinely. Depending on the airline, it may not even be the pilot’s responsibility to do so. Every airline has a binder (likely, several binders) full of procedures to follow after a NTSB-reportable accident. No one person is expected to do the job of many.
Could even have some indicator in the cockpit that it's in emergency mode for the pilots to turn it back to loop mode in case of a false positive.
I will absolutely, unreservedly dismiss the concern of a pilot for privacy in the cockpit because I can think critically. The notion that someone deserves privacy in the cockpit of commercial aircraft is outrageously silly and utterly indefensible. Pilot your own personal aircraft if you want that privacy.
And there is absolutely an "Overton window", but it is wrong to think that whatever way it moves is a regression or worsening (which is the classic "everything is always getting worse" melodrama). Sometimes the way things are is not rational or optimized, but just are.
The 2 hour thing was nothing but a technical limit (a literal loop of magnetic tape), and every other justification is retconning.
The 2 hour thing was 30 minutes when it was magnetic tape. It moved to digital a while ago and that's when the unions negotiated it to 2 hours after some incidents. The 2 hour limit was not based on anything technical that I'm aware of.
The privacy stuff is absolutely not reconning. Heck, it was pretty much the most talked about topic over the water cooler when I was doing some IT contract work for ALPA in my teens.
My memory is certainly fuzzy but not quite that fuzzy.
This sort of negligence is intentional. My guess would be it started as a requirement for analog recording and was carried over without change and purposefully left at two hours when equipment went digital. The fact that EU has a 25 hour length requirement and the FAA refuses to update their rules to extend to some reasonable length tells us everything we need to know about this situation.
i'll bet lunch the actual recorder hardware in the airplanes is the same with the only difference being a knob set to EU rules or FAA rules.
https://www.reuters.com/business/aerospace-defense/us-faa-wa...
At least the voice recorder is 2 hours instead of half an hour now. But watching those incident videos I've seen a couple that ended up being investigated but the pilots didn't pull the circuit breaker and the investigation was based on the flight recorder, specially in those cases where things end up fine.
For the most severe incidents, recording stops at the end of the incident. The current two hours is an increase of the previous 30 minutes. The old 30 minute limit made a little more sense at the time considering the mechanical nature of the recorders at that time.
I think if the plane is still operational for 2 hours then the data is a lot less important than the alternative scenarios.
Its unbelievable how often the voice recording gets overwritten. This has been a problem for literally decades. How this is not solved is mind blowing.
This would be trivial to store, and trivial to upload. People have wifi in the plane but somehow we can't upload a few voice recordings and other flight data. (and before somebody jumps on me, yes its not 'trivial' but its a hell of a lot easier then about 1000 other things a modern plane does). And private as an argument doesn't' really work either.
The amount of valuable data lost is mind blowing. Not just in cases where things fail, but also in cases where everything goes right.
And then, somehow they don't have cameras that allow pilots to see the engines and other vital parts of the plane. Somehow passenger can fucking watch movie. But if a captain wants to know if the engine fell of the plane they have to send somebody from the cabin crew to run around and look out of the window.
Probably people in the 70s who thought having a recording at all is star trek stuff.
This wasn’t sci-fi stuff even back then.
There a lot of things today that are less human-usable than they were a half-century ago, but also much more flexible and less expensive. We're still in a weird transitional phase post-transistor.
In the next one, yes. Note the goal is not to do blaming and shaming, but to reduce anything similar happening, and to increase effectiveness of response. For example did multiple alarms go off, so it took longer for the crew to establish what the problem was? How quickly and effectively did the crew respond to the problem, and did the procedures they followed work effectively? How saturated were the crew with things to do? How well did training scenarios correspond to the actual event? How well did CRM work? [1]
As a result of looking at those, changes like the following could be made (and have been done as a result of previous investigations):
* Updating how alarms are prioritised and presented
* Updating flight management systems
* Updating the procedures to troubleshoot and respond to this kind of event
* Reducing workloads
* Updating training scenarios
* Using the incident as a good example of something being handled
It really should have enough to save at least the longest flight possible.
However if that theory is indeed true, it's clear that he wanted to disappear without a trace. In that case it would have made sense to keep it running especially because it only keeps the last 2 hours.
But yeah if it had been longer he would have turned it off in that scenario. It would be best if the CVR had a backup battery (and internal protection is that shorting out). In fact I remember reading in several admiral Cloudberg articles that the CVR and CDR data was incomplete due to bus power loss during accidents.
In a post iPod era and with a budget greater than the cost of an iPod, this is a non-issue. I wonder what the real issue is.
They must allow data to be recovered in as many cases as possible, prioritizing that over raw data storage amount or convenience.
The "it took longer than 2h to retrieve the voice recorder" seems one of the dangers then. And at least just as likely as many others, e.g. it's easy to imagine this happening together with "being stuck in a remote place".
In most crashes, both recorders lose power so it's not a problem. In cases like this and the plane is fine, the pilots need to pull the breakers.
Recorders have been found months after accidents and still retain all data.
But add to that the requirement that pilots have to remember to pull the CVR fuse to stop it overwriting, and then the malicious case where pilots have seemingly intentionally pulled the CVR fuse prior to illegal actions in order to disguise those actions, this is clearly a beyond brain dead system.
The local recording should be more than two hours, but these days there's no justification for it not also being continuously uploaded.
This will eliminate the possibility of your employer or some technician spying on you through this vector as it would require the government to also have a significant interest in a single case.
> "(It) would significantly infringe upon the privacy rights of pilots and other flight crew members, as well as drastically increase the likelihood that CVR recordings will be misused or disseminated without authorization," the union said in a Dec. 28 response to the FAA's 25-hour proposal.
I'm not sure I agree that flight crews of passenger aircraft should have an expectation of privacy while flying planes. It seems like one of those kinds of jobs where the risks involved and need to gather forensic data in the event of an accident should outweigh the pilots' privacy concerns. Maybe add some regulation w.r.t. disseminating the recordings outside of releases by the NTSB as part of accident investigations.
It seems like one of those kinds of jobs
where the risks involved and need to gather
forensic data in the event of an accident
should outweigh the pilots' privacy concerns
Reading between the lines, I think the concern is that pretty much any flight might contain minute violations of things like the "sterile flight deck rule"[1] and it would probably be easy to find a reason to fire any given pilot if airlines could just comb through endless amounts of recordings.You could probably overcome the pilot objections if there were real penalties for misappropriating the recordings, like they have in the "privacy heavy EU". As it stands today, the pilot objections aren't really unreasonable.
SpaceX is US military contractor with very high security clearance. Starlink is literally used in war against nation state attackers.
I absolutely recognize Musk's contribution to things that I value and respect.
I also think it's a little absurd how often he's brought up in completely unrelated discussions. It's a little like how whenever someone mentions that at-home electricity storage is a bit of an open question, people bring up flywheels, even though Powerwalls are a much more reasonable approach, just because they think flywheels are rad. The amount of times people try to shoehorn a Musk-related technology, (or even say "Hey let's get Elon on this, I bet his infinite money and brains could solve e.g. food distribution with um drones and Starlink and Boring Company I don't know he'll figure it out) makes it a little hard to take his biggest proponents seriously.
A recent Reddit post discussed something positive about Texas. The replies? Hundreds, maybe thousands, of comments by Redditors, all with no more content than some sneering variant of "Fix your electrical grid first", referring to the harsh winter storm of 2021 that knocked out power to much of the state. It was something to see.
If we can dismiss GPT as "just autocomplete", I can dismiss all those Redditors in the same way; as NPCs. At least GPT AI can produce useful and interesting output.
Various aircraft data are already uploaded in flight ("stream" would be an exaggeration though) as you can see from the MH370 example you cited. The data uploaded are increasing as companies like Rolls-Royce become more of a data company.
The black boxes are pretty robust (assuming you can find them!) and uploading the voice data is probably not worth the cost.
Ask the families of MH370 how well Inmarsat works.
(2) With that many planes you start to get into Starlink bandwidth issues. Cant it support that many? I honestly don't know
(3) Its a new complicated piece of equipment that may fail. What if the transmitter is broken? Blackbox systems are much simpler
(4) A lot of this data is already transmitted (speed, altitude, position, etc, just not voice), so no need to build a system for it.
Bandwidth issue for a bunch of audio files? I think we can figure that out.
> (3)
I don't think a single person would suggest we replace the Blackbox. This would be in addition, not instead.
> (4)
I'm sue the plane produces lots of data that isn't transmitted. It would generally be smart to transmit far more data then we currently do and I'm not sure those methods are up to large increases.
But if they are, then yes that would be good.
For bandwidth - there are typically around 10k planes in the sky at any time, and that number typically grows. Thats 10k audio files streaming at a time, all day, every day. Add to that the nominal Starlink traffic that already causes bandwidth issues and you end up with probably non-trivial bandwidth issues until there is larger scaleup
How is that worse compared to now where we don't even know where the plane is? Just the underwater search cost $200M, with no results. Would've costed more if they didn't give up so easily.
It doesn’t help when the aircraft gets destroyed, but it does create fairly big databases for analysis and preventive maintenance.
And as I said, no idea how US-only aircraft differ, hardware and software wise, from their European airspace brethren. Do no, it is propably not as easy as going into maintenance mode and set a toghle from 2 to 25 hours on the voice recorder firmware.
The issue here is likely legal liability, as evidenced by the pilot’s union opposition to longer recordings.
> The U.S. requires cockpit voice recorders to log two hours of data
So.. what happens when a crash happens at 2:01 into a flight, you have just one minute of audio? how is that in line with the requirement to keep 2 hours of audio?
> The maintenance team went out to get it, but it was right at about the two-hour mark
> The plane's flight data recorder and cockpit voice recorder were sent to NTSB labs on Sunday to be read but no voice data was available
So as soon as that 2-hour mark is hit, the CVR secure-erases everything it recorded and starts anew? (data-recovery was not possible???) ... I feel like something is missing here...