It is quite common and vessels often have outages that leave them Not Under Command. Usually they are safely at sea when this happens and they can drift for hours without causing problems. But of course there's always a possibility of it happening at exactly the wrong moment.
The reasons for this are the usual: lack of redundancy, lack of maintenance, overworked and understaffed crews, etc. etc. The book lays out how ships are pretty much designed to be floating disasters and the Class societies (essentially privatized regulators) are in the pockets of the builders, and they are so captured that they make rules that make it difficult to make safe vessels.
For instance, he was trying to design multi-screw vessels but the rules now assume single-screwed ships and it can be impossible to design in additional shaft alleys and still conform.
Warships have several independent backup steering options reducing finally to a worm gear at the top of the shaft with a winch handle big enough to put a gang of men on it. But ships like this will have none of that. They will have a small wheel or joystick on the bridge and if power goes out the rudder will definitely stay in the last commanded position until power is restored. Even if they had auxiliary steering they would not have the crew to man those positions.
This ship would have alternate diesel power plants called "mules" (think APUs on aircraft). It's possible that when the lights came back on that was because they got a mule started.
But really if we don't want accidents like this to happen the ship should have redundancy. A 10,000 TEU container ship is one of the largest and heaviest moving structures ever created by man. Why is it acceptable that it is driven by exactly one engine powering one screw in front of one rudder?
By the way a ship this big with only one screw is very difficult to maneuver at slow speeds. They pretty much have to be going at least 14-15knots to have any rudder authority.
Perhaps because we have a whole lot of them going and a very low frequency of events like this.
Maybe there's some lighter weight interventions we could do that would further halve the risk of something like this happening that are less costly than fully redundant engine and drive.
They're supposed to have emergency steering gear. Why didn't it work? Maybe ships should have an auxiliary genset running while near land.
This is literally the second major loss of control/allision incident this month.
https://www.tradewindsnews.com/casualties/out-of-control-con...
Seriously, in England it is a legal requirement to have redundant brakes on a freaking bicycle. A dude that hit a grandma with a bicycle due to 1 non-functional brake went to prison. But a giant container ship needs nothing?
What is the cost of fixing this bridge and + lost lifetime earning of all the people who dies + compensation to their families? Is that really cheaper than installing batteries plus electric motor?
Now imagine this ship would hit a bridge in daytime, when it’s clogged with traffic?
Cost-benefit analyses aren't designed to evaluate the total risk a business venture presents to everyone who could possibly be involved; they're designed to evaluate the risk posed by a problem that will launch lawsuits that will play out in courts for years, if not decades. Meanwhile, some injured parties settle for pennies on the dollar, laws change, and in the absolute worst-case scenario, major shareholders draw down their positions in the corporate venture that caused the problem. The world keeps on spinning, and just maybe some regulatory agency will pay attention to the report issued by the likes of the NTSB and USCG.
The process does not adequately protect the public.
And that fundamentally means until someone ‘bleeds’/a big enough disaster happens, some things won’t get fixed.
See the triangle shirt waist factory for an example of what it took to be able to force people to pay for certain kinds of fixes.
[https://en.m.wikipedia.org/wiki/Triangle_Shirtwaist_Factory_...]
Since folks aren’t currently burning down the NTSB’s offices or the like, it also seems like your opinion that the public is not currently adequately protected isn’t a majority one?
The only way we’ll ever hit zero accidents is if we are all dead, it’s impossible to do anything without some risk.
Children die at or going to/from kindergarten a few times a year I bet in the US.
But presumably they will ultimately seek reimbursement from the Dali’s insurers. As will the Port of Baltimore and anyone else who has suffered damages.
I don't mean to contribute to this already-too-charged discussion any more than to say that the answer to this question is not as obvious as you think it is. If anything, I would bet that the former is less expensive than the latter, and I say that with immense sadness. Does that make sense?
And the dude went to prison because he hit and killed a grandma while riding with reckless disregard for the safety of pedestrians. The brake thing didn’t help, but it was a side story.
The law literally says mechanically redundant, as in failure of one cannot affect the other.
It's illegal to have a single hydraulic system controlling both.
It is. Redundancy doesn't necessitate the redundant option being identical to the first.
Yes. In fact, in a redundant system, using different designs or technology is often an advantage, so that a failure mode that affects one system is unlikely to affect the other.
But if something is redundant, it is “able to be omitted without loss of function”. Front and back brakes on a bike are not there for redundancy. They are components of the same braking system: without both in service, they don't work as well.
Or to put it another way, the front brake isn’t there as a spare in case the back brake fails. It’s there because without brakes on both wheels, you can’t stop quickly in an emergency.
Bikes are very different from cars due to the short wheelbase vs high center of gravity.
At moderate or fast speeds maxim deceleration occurs when the front tire applies enough force to lift the rear tires off the pavement thus removing the impact of the rear tires. Below maximum acceleration you could use the rear break but it doesn't do anything applying the front break slightly harder would do.
At sufficiently low speeds the rear tire can help, but it's really there for redundancy as even acting alone it doesn't work very well.
So sure there’s a minimal benefit in some very specific conditions, but no they are there for redundancy.
Redundancy doesn't inherently have to cost a lot more. For example, if you have three engines driving three props, they can each be 1/3 as large, and not necessarily weigh much more if at all. But then if you lose one, you lose 1/3 power rather than experiencing total loss of control.
Yah, from aviation everyone moved to twins because tri-jets and four engine jets were too expensive in comparison. Things don't scale up or down perfectly; in practice you end up with more maintenance.
But it seems like here they lost steering, so maybe there's something better we can do to keep steering more of the time (the cutover to emergency steering gear isn't instantaneous or perfect).
- The current accident rate due to lack of redundancy isn't too awful.
- Adding redundancy increases cost, even when it seems like you have the same total power or whatever.
My bias is towards a bit more redundancy than we have now, but not massive changes.
Not just for a while. They must be able to do so indefinitely, until you run out of fuel. Of course, you are going to want to get it back on the ground long before that happens.
They showed us one such station, on the USS Hornet in Alameda, it it in the officers' dining room.
Furthermore, steering could absolutely have an electric backup for the hydraulic pumps that power the main steering gear. As long as there's some forward speed through the water, the rudder should work. But again, backups clearly aren't required or they would've worked here.
Steer-by-wire cars are required to have all sorts of redundancy so they're almost as safe as steering-shaft cars in case of an engine failure. This is a 9,900TEU ship with a 41480 kw powerplant. That a ship with so much more destructive potential is allowed to operate without the same level of redundancy as a $90k Audi, is unconscionable.
That ship spent 1 (4:30 to 5:30) hour of a presumably 10-20 day voyage in a critical control section. The tugs left the ship right around 5:08 (43 seconds into the video). A much better policy for this case would be to have required the tugs stay with the boat until it passed the main span safely.
There were no doubt maintenance issues that led to this accident, but it is exceedingly rare for these types of failures to cause this type of catastrophic result.
It’s not clear why adding ~$100k to the cost of a billion dollar ship is unreasonable
I don't know enough about the cost and safety tradeoffs made in the design of these ships to comment but your numbers are orders of magnitude off from both directions.
Second-guessing the marine engineers in this case is like the people post-9/11 who argued that future buildings should be designed to withstand the impact of a wide-body jetliner fully loaded with fuel.
It's basically not a serious argument.
http://martrans.org/documents/2006/safety/The%20_tankership_...
Just browsed the book and immediately found "the smoking gun" in the preface itself!
Mandate twin screw in the form of two fully independent engine rooms. Under the current system, 99.5% of all tankers, however large, are single screw. These ships are always a single failure away from being helplessly adrift. The book presents evidence, never before public, that there are at least ten total loss of power incidents on tankers every day. Twin screw, properly implemented, would reduce this failure rate by more than a factor of one thousand. Twin screw would also drastically improve tanker low speed maneuverability which is implicated in a number of big spills including the Aegean Sea shown on the cover.
The bridge has been there for nearly 50 years, in a port that handles around 50 million tons of cargo every year.
It seems pretty clear that whatever the cause, it was an extremely rare incident.
It may be rare in the lifetime of the bridge, but if there is a variable which has change (or is moving) then that isn't so important a consideration. For example, if container ships have recently become much larger in relation to the design requirements in place at the time of the bridge's construction.
If someone made a landscape painting today using the wet-on-wet technique, would you argue that a Bob Ross episode from years ago couldn't possibly tell us anything about it? That's silly. It's precisely applicable. Mr. Ross himself might not describe the specific location of today's trees or clouds, but he can darn sure tell you how the brush strokes add up to make a tree. Actually he's probably one of the world experts on precisely that.
Proclaiming your ignorance of extremely-well-researched expert sources is not a good look.
While it is true that the investigation into the causes of the disaster is just starting and we don't yet have a definite conclusion, user "jordanb" has done a great service in pointing us to a book written by a domain expert which had pointed out fundamental design flaws in the design of Tankers long ago. Design Flaws have no expiry date until they are acknowledged and fixed properly. In an era of disinformation/misinformation and focusing solely on profits it is important that people be shown some factual data by actual engineers/experts who were very much concerned with safety and how all concerns were flouted by concerned companies/authorities.
Just like the Boeing disasters have shone the spotlight on Civilian Aeroplane Safety, this disaster shines a spotlight on Tanker Safety, arguably a far far more important topic since almost all the world trade of goods and oil is dependent on them exclusively.
Thanks to that, they aren't performing an accurate cost/benefit analysis.
AFAIK the water around the bridge is only like 50 feet deep and the ship itself is about 150 ft high. It wouldn't even really sink, just get stuck on the bottom. A crane ship would come unload it and then tugboats would pull it out.
The worst case scenario though does take a long time if it gets fully grounded and stuck beyond the ability of tug boats to pull it out. A company specializing in marine salvage has to come in to cut it up in place and haul the ship away piece by piece. They use large cutting chains that they pull back and forth to cut through the metal. It's a fascinating process: https://www.youtube.com/watch?v=Ndr2a7AQ8b4
In this case it seems the ship wasn't full, but it's not hyperbole to estimate it as being worth a billion dollars fully loaded. Cars aren't the cheapest things you can ship in containers, but they're far from the most expensive either, and they're what the Port of Baltimore specialises in.
Most ships use flags of convenience, so the regulatory structure is pretty much nothing.
Would you still believe this if it was demonstrated that the system lacking redundancy was - due to factors beyond the scope of this conversation - more safe by an order of magnitude than the steering system that includes redundancy but in a different medium?
Put differently: do you think the Space Shuttle should have had ejection seats? If yes, what about an Airbus A320 flying a normal commercial route?
If you really want chills, think about this: a conscious decision was made with covil aviation that it was more economically feasible to sacrifice the human lives on board, and resolve the rest through lawsuits.
In short: if you know/are critical to the process of murdering extra-natiomals, you warrant a life saving device.
If you're a civillian, you're a line item in a potential series legal judgements.
Military aircraft are subject to failure from being shot at. Aircraft in combat will fail much, much more often than properly maintained civilian aircraft.
Civilian aircraft don't have election seats because situations where they would be useful are exceedingly rare.
Do you think it's even feasible to install ejector seats for 10-30 passengers? What do you think will happen if they all fire at once?
What I'm decrying, however, is our practice of letting actuaries and lawyers be the final arbiters of what is desirable to engineer.
> lack of redundancy
This is what I am surprised at from many angles. It seems to me that the ship, the port (in the form of lack of tugboats), and the bridge (in the form of lack of secondary protection of the pillars) all had a lack of redundancy and secondary options.
But the ship's pilot [1] (not captain) should know exactly how the boat will handle and the exact course of action. Pilots are extremely well paid ($200-$400k) and the tests are very stringent. Friends have told me that the Narraganset Bay pilot test involves drawing every shipping navigation bouy on a map by hand to within ~200 yards from memory alone, compass, ruler and scaled map provided.
[0] https://www.balticshipping.com/vessel/imo/9697428/seafarers
> The Florida Alliance of Maritime Organizations reported that Florida pilots' annual salaries range from US$100,000 to US$400,000, on par with other US states that have large ports. Columbia Bar pilots earn approximately US$180,000 per year. A 2008 review of pilot salaries in the United States showed that pay ranged from about US$250,000 to over US$500,000 per year.
Pilot != Master
Pilots are very highly paid
It is insane for a 100,000 tonne vessel, that takes so long to stop due to its incredible inertia, that can find itself many thousands of miles from land, to rely on one engine, one gearbox, one shaft and one rudder; without sufficient secondary and tertiary back-up systems. Why was there no battery back-up, or motor on the shaft? Surely the bow thrusters should have a battery back-up to stop such a lurch to starboard.
How can all of the generation and all electrical busbars fail at once? Even if the fuel was bad, surely the generators should draw on separate fuel tanks. For such a large and relatively modern ship to suffer a total power failure is complete corporate incompetence.
If, as some allege, the refrigeration containers were causing problems, and total power outages occurring before sailing, the vessel should not have sailed, certainly at night. If this is the case, The Master needs locking up. But, poor man has to take the blame, because he is cheaper than a Danish Master and his Singaporean employer (if he is employed and not a contractor) also operating in a cheaper flag state than Denmark. The Singaporean Company also needs hitting hard if the culture was the cause of the Captain sailing after such alleged pre-sailing power outages.
Maersk outsource to reduce personnel and running costs. They use the cheapest crews, cheapest ships and need hitting very very very hard. We might then stop this culture of wealthy shipping companies using every method possible to avoid complying with IMO and more rigorous Nation State standards, operating in the shadows and ducking accountability and responsibility.
I think it was something like bad fuel killing the generator.
[1] - https://warontherocks.com/2021/10/cant-sail-away-from-cyber-... (2021)