[1] https://twitter.com/David_Slotnick/status/176545419893241038...
[1] https://twitter.com/David_Slotnick/status/176545419893241038...
This would be a bad legal strategy. Playing this through as a lawyer:
1. You will be asked to produce it in a lawsuit
2. It will come out it does not exist but should.
3. You will be absolutely and totally excoriated in the lawsuit, in the court of public opinion, and by your regulators.
4. You will prolong the news cycle of your malicious belligerence, and it may even spike higher when it comes out the docs don't exist but should.
5. You will be forced to settle the lawsuit at very high cost, and because you were totally belligerent, you will be regulated much harder, which has a higher-than-the-lawsuit cost most likely
Meanwhile, admitting you are missing shit you should not be, because the contractors played games (or even if it is just you):
1. You will be forced to settle the lawsuit at high cost
2. You will be less excoriated because you owned up to your failure, and because you look more like a bumbling company instead of belligerent and malicious.
3. You will probably be regulated more, but probably less than you did in the first scenario because of #2
The net expected value of the first strategy is much lower than the second.
They can't prevent themselves from losing or being excoriated, they can only try to make it have less cost.
I’m obviously not Boeing’s attorney, but given the industry they’re in and the amount of scrutiny they’re under, they don’t need their lawyers to fabricate situations that drive up their billables. They’re quite busy enough already.
"Boeing admits knowing of 737 Max problem" - https://www.bbc.com/news/business-48174797
"...Boeing has admitted that it knew about a problem with its 737 Max jets a year before the aircraft was involved in two fatal accidents, but took no action..."
Faking paperwork after the fact is unambiguous mens rea and “inadvertently made an alarm feature optional instead of standard” is not.
"Downfall: The Case Against Boeing" - https://www.imdb.com/title/tt11893274/
Time is running out, and the situation doesn't make them look good, but it seems they're not ready to abandon hope just yet.
I can imagine that for each plane could exist millions of documents, hidden away on different servers. Best-case scenario they could claim that a subcontractor was order to create it and lost it.
From experience I saw a company where people would have single copies of documents stored on hard drives, personal cloud drives, memory sticks, etc. They were always able to find what they needed, but there were a few close calls.
This is where being under so much pressure to produce the documentation, somebody ends up magic-ing it into existence. I wonder if they even have a chain of custody that would highlight that forms, etc, were retroactively created?
Sometimes for good reason (you are on a classified project, etc). Sometimes for bad reason (we don't want anyone to be able to prove anything).
The latter is something bad lawyers suggest. It basically never works to get the company off the hook. I'm not going to say "never never", but most of the time it leads to a situation where it's easy to convince a jury you are malicious and evil.
Even without a jury, i will simply put your peers who don't do that on the stand and make you look like you have a non-standard policy of hiding things.
Or i'll find the human who asked why. Because in any company of any size, people eventually ask each other why they are being asked to do this, and someone will say the wrong thing ("You know why we do this"). Most of them will not lie for the company because they don't buy it either.
etc
This sort of hiding strategy goes wrong in many many ways, and only goes "right" in a remarkably small set of circumstances.
I would say 'that is an unethical but 'reasonable' strategy for a rich CEO or whatever as an individual' (where reasonable here is 'probably would work' not 'morally sound').
It is an unreasonable one for the company as the company.
> Boeing also acknowledged the possibility that the documents the NTSB is seeking may not exist.
> "If the door plug removal was undocumented there would be no documentation to share," Greenwood said in his statement. "We will continue to cooperate fully and transparently with the NTSB's investigation."
In which case the NTSB will hopefully pin the blame on the lack of a functioning system of record that tracks such events.
You have to trust your workers to not undo some random bolts here and there at some stage.
Alternately the process should be to do nothing until the system studies the action and defines the process. But even then you have a proofing run where you probably should have extra documentation. And arguably in a high safety environment- this would be preferred.
In an environment where process exceptions are the norm, people begin to deprioritize handling exceptions properly. Everything can't be critical or emergency all the time.
And once that deprioritization happens, safety critical process exceptions begin being treated like all other exceptions. Because they're all exceptions, and there are so many.
And eventually normalization of out of bounds situations via repeated team exposure leads to catastrophe.
NASA lost two shuttles via the same organizational problem.
There are doors on an aircraft - you enter through them, they have inflatable slides attached. Then there are plugs - plugs that fill a space (this is one, there are a lot, basically any penetration of the pressure vessel). If there were a space where a door could be but isn't on this model, you need to plug it (hence, door plug or...plug door). In terms of assembly, maintenance, operation, etc. they have different functions and those functions have different documentation and traceability requirements. Doors are meant to be opened and closed - that is different from being removed (i.e., 'taking the door off its hinge'). That leaves us here:
* Doors can be opened and closed (this does not require documentation because it is part of the normal function)
* Doors can be removed, which is different from opened and closed (requires documentation because it is not part of its normal function, requires inspection after reinstallation)
* Plugs cannot be opened and closed (opening and closing them is not part of their normal function so...to whit...doing so is impossible within the vocabulary/concept of documentation rules, they are not designed for regular use)
* Plugs can only be REMOVED (documentation required, inspection required just like a door removal)
Where does that leave the door plug? is undoing the bolts and pushing it up off the stop blocks opening it or is it removal? In the minds of Boeing and the FAA - that is removal. In the minds of line workers, opened a door.
Suddenly, door plug and plug door become potentially different concepts. One is a plug for a door and is discussed and documented like a plug. The other is a door that serves the purpose of a plug...and is discussed and documented like a door. What seems to have happened is that workers opened the plug , which isn't 'possible' - meaning they 'removed' the plug and treated it like opening it. That meant it didn't trigger anything about a required set of procedures to do so, didn't trigger inspection, didn't trigger documentation, didn't trigger inspection, just got closed up and moved down the line.
I've dealt with a lot of these...a personal favorite was a company I worked with having someone who couldn't read be responsible for recording each serial number he stamped on each federally tracked part in our factory. He relied on his memory of the last serial number he did the day before.
The plug was of course installed when the plane was delivered, otherwise there would have been a door-sized hole in the side of the plane when it was delivered.
The bolts of the plug were probably originally installed, but some rework was required in the area during final assembly, which required the plug to be removed and put back, and during that process the bolts were not reinstalled. It’s (lack of) documentation of that removal-and-reinstallation that are the subject of the article we are discussing here.
What I have read varies. Some say the door plug was installed and bolted. Some say the door plug was installed but not bolted. Some say the door plug wasn't installed - which I suspect from a lot of prior experience is a linguistic gap between engineers and reporters on installed but not bolted.
I remember reading but can't find at the moment something suggesting that inspecting the door plugs and the bolts was a required Boeing assembly line 'job' (think 'ticket'). But none of that matters if someone, as has been reported, later uninstalled the bolts to fix something else, without creating a record of doing so, because they misunderstood the specific procedure they were undertaking.
If they really do allow line workers to interpret federal regulations themselves, that's quite a problem. But I doubt this was a decision made by someone that turns a wrench.
> You have to trust your workers to not undo some random bolts here and there at some stage.
Why? We don't trust surgeons to remove correct limbs, why we should trust some contractors thrice removed from actual accountability? There are checklists for a reason.
> "If [it] was undocumented there would be no documentation to share..."
So... Maybe documentation exists. Maybe not. Either way, maybe they did not share it.
Shouldn't the reporting make it clear how much of a non-answer this is, or are they intentionally writing news reports laced with dry humor?
How surprising that hobbyist act like hobbyist. When real money gets involved, all of sudden inconvenient things no longer are "critical" so no documentation is needed for them. What a coincidence...
Something like that is likely what's happening here.
If outsourcing is a de facto means of avoiding responsibility, then guess what the consequences are.
The executive leadership should lose their own (potential?) personal money over this incident. Until that happens, nothing will get fixed.
Boeing is in so, so much trouble here.
They straight up said, we don't know.
Rumsfeld
The context is that he'd previously said we had to invade Iraq because of the imminent threat of the weapons of mass destruction.
So he's using a trivially true and non-interesting statement about "unknown unknowns" to evade questions about previous statements where he claimed to know something.
In other words, it was garbage response. He deserves mockery, scorn and a criminal trial.
I’m not sure that’s quite accurate, although it’s not that far off either. The full context is here:
https://web.archive.org/web/20160406235718/http://archive.de...
His “unknown unknowns” response was, to me, a basically fair if evasive response to whether there is any evidence of a direct link between Baghdad and terrorists as far as supplying WMDs. He essentially said “we don’t know what we don’t know.”
To me the more damning answer is the follow up later in the conference, where he strongly implied that he has evidence but can’t disclose it. That just misled the public and is far worse than the “unknown unknowns” comment in my view.
I recall reading (probably a Twitter thread) a while back that showed entries in one Spirit Aero work logging system that showed the plug had been unbolted, and that there was no corresponding entry in the QA system that's required whenever a plug is removed. My gut feel its that someone was rule-bending, and they probably unbolted and slid the plug out of the way of the rivet holes they needed to fix, but didn't want to admit to "opening" the plug and having the QA audit records and self justified that they "didn't actually open it" when they unbolted and moved it (and failed to rebolt it when they put it back).
see comments by "throwawayboeingN704AL"
(Terminology as described further upthread at that link: CMES is an official record system for the plane. SAT is described as "Like Slack" and not an official record of the plane and its maintenance)
"finally we get to the damning entry which reads something along the lines of “coordinating with the doors team to determine if the door will have to be removed entirely, or just opened. If it is removed then a Removal will have to be written.” Note: a Removal is a type of record in CMES that requires formal sign off from QA that the airplane been restored to drawing requirements.
If you have been paying attention to this situation closely, you may be able to spot the critical error: regardless of whether the door is simply opened or removed entirely, the 4 retaining bolts that keep it from sliding off of the door stops have to be pulled out. A removal should be written in either case for QA to verify install, but as it turns out, someone (exactly who will be a fun question for investigators) decides that the door only needs to be opened, and no formal Removal is generated in CMES (the reason for which is unclear, and a major process failure). Therefore, in the official build records of the airplane, a pressure seal that cannot be accessed without opening the door (and thereby removing retaining bolts) is documented as being replaced, but the door is never officially opened and thus no QA inspection is required. This entire sequence is documented in the SAT, and the nonconformance records in CMES address the damaged rivets and pressure seal, but at no point is the verification job reopened, or is any record of removed retention bolts created, despite it this being a physical impossibility."
Is there not some dependency tree such that a cascade of sign-offs are required when one thing is changed? Clearly, changing the seal has dependencies which should automatically be flagged.
https://leehamnews.com/2024/01/15/unplanned-removal-installa...