Germanwings plane crash: Co-pilot 'wanted to destroy plane'
bbc.co.uk
bbc.co.uk
I don't have a greater point I suppose, but it seems worth thinking about. Except, perhaps-- how do you go about 'screening' for inclination to mass-murder?
The first officer shut the captain out who tried to break the door until the end.
http://www.aeroinside.com/item/3416/lam-e190-over-botswana-n...
Automate this stuff.
In the context of a pilots mental state verses malicious source code being installed on a set of flight computers, I'd have to say the computer is easier to validate. That many more people have to approve the process. With a pair of pilots the validation process is much smaller and more complex.
We need to stop thinking that machines are flawed and that humans know best. The fact of life is that machines can and do perform better than humans, the only reason flight computers don't currently is that there hasn't been the investment in making them do so. Sensors fail but that is an engineering problem that can be solved.
I was recently flying in a small airplane (SR22) and the terrain detection system was going bonkers when we were landing saying that terrain was getting close to us. They have all the data, they just need to build in some more protections.
(Not sure I'd call that a technical solution, but let's assume so.)
Trust me: Planes could fly themselves using today's technology.
In fact, pilots are trained to communicate AFTER they have gotten the plane in a state to where they can either continue the flight or ditch safely if communication would distract them from the task at hand. ATC knows this, so even if they saw the plane dropping like a sack of rocks, they would probably assume that there was a problem and that the pilots are in a position in which a steep dive will help mitigate the problem (which can happen, such as depressurization).
Ultimately I think that remote control or a comparable safety measure will become a necessity in civil aviation, because passengers will demand it to feel safer.
I think you might have missed my point. What telemetry do you think would have given ATC enough information in 8 minutes that would tell them reversing the descent is the correct course of action? If anything, the data in this flight would have indicated that the dive was initiated by the pilot, and would suggest allowing him to continue the actions. And how long would they have to discuss what should be done? The descent started 8 minutes before the plane hit the ground. That is a very short amount of time for people on the ground without full information to make the call. They would probably spend at least half that time trying to make contact with the pilot.
The bottom line is that the person best appraised of how to fly the plane is the one behind the controls, and that is how aviation has traditionally treated these situations. If a pilot wants to bring down a plane bad enough, it's mighty hard to stop them.
Anyways, and this is my speculation, I am fairly certain that remote control has been brought up many times before in aviation, and that there is a good reason why it isn't presently implemented. And as for the corner cases, those corner cases matter. This isn't a software engineering problem we are talking about.
Airline pilots are a highly selective group of people, well trained, and they are showing every day how they work with integrity. That someone has once gone over and killed himself and others should not obscure our assessment of the situation. We have about 88 000 departures per day in the world. We don't accept even ppm-range risks of disaster if we know how to mitigate them, but when we're this low, we need to be careful that "improvements" don't actually degrade performance.
Such a terrible idea in such a short sentence...
And yes, there are emergency override codes, but there are also time override-overrides from within the cabin. Even if the protocol where two members of staff are always in the cabin was broken (or absent), again, that does not stop a rogue operator from despatching with the other person.
The question is (hypothetical at this stage, there are a lot of details still unknown): have these type of doors already saved more lives than the ~150 tragically lost this week?
Ideally you'd have a door that is strong enough to be "people proof" for long enough for the entire passenger compartment to rush a dude, but not strong enough to survive the entire passenger compartment trying to get in and save the plane in this situation. Something that can survive a couple kicks but isn't a bank vault door. Pretty much a typical apartment door would be about right.
If they are outside trying to get into the cockpit, there may be time for passengers to react and neutralize them?
I very much disagree. Previously, an attacker could get to the cockpit by surprise and by suddenly overwhelming cabin crew. That is now much. much more difficult.
I disagree on this one. Bruce Schneier, who writes often, and passionately, on the ridicelousness of "security theater", cites doors (along with your your statement that passengers must resist) as having improved safety to a measurable degree.
But there isn't, sadly, an absolutely fix for every vulnerability. We can reduce the number of incidents and mitigate the risk, but some will always remain. It is the price one pays for such extraordinary freedoms and luxuries.
https://www.schneier.com/news/archives/2008/11/the_things_he...
As is the way of things, the current manifestations of asymmetric warfare can muddy up the discussion with modern-day politics, so please allow me to remind you that science fiction authors have been predicting the rise of it since at least the 1980s, just due to the ever-rising destructive power any one individual can wield. Who or what cause happens to pick it up is an accident of history, but you can be guaranteed someone will try. This is an incentive structure that those of us on the side of civilization are going to be doing continuous battle with for a long time.
Historically, hijackings are more deadly than rogue pilots. Neither one is a particularly big threat, but hijackings are the more important threat of the two. How many potential attacks from the past decade and a half got stopped in the planning stage because "Well gee, Bob, that sounds great, but how are we going to get into the cockpit?" While this stuff is rare, I bet it's not zero.
Beyond that, does not having a locked cockpit door actually save you from rogue pilots? I don't think so. There's a lot you can do to defeat other people when you're the only one belted in at the controls. A series of violent vertical maneuvers would suffice to defeat anyone trying to get back in. Imagine if, instead of locking the door, this guy had just pushed the nose over to negative two gees, then pulled up at positive three, repeat until everyone is dead? Or, pull the breakers for the higher-level fly-by-wire systems, point the nose at the ground, apply full throttle, and rip the wings off? The thinking seems to be that there was a calm 10 minutes or so in which he could have been stopped if only the door hadn't been in the way, but the only reason there was a calm 10 minutes was because the door was in the way.
Is this true? I can't remember a single other plane hijacking that resulted in the deaths of passengers outside of 9/11.
There were definitely a couple.
http://en.wikipedia.org/wiki/List_of_aircraft_hijackings
Lots of those were resolved without death, or with just a few deaths, but many others got lots of people killed.
It certainly was debated before (here a german article from a year ago, closing with the cynical words "Than you're also dead, but at least save from terrorists. How comforting." http://www.austrianwings.info/2014/05/verriegelte-cockpittue... )
"Was geschieht, wenn sich ein Pilot zur Toilette begibt, sein Kollege im Cockpit - aus welchen Gründen auch immer - das Bewusstsein verliert oder verstirbt (solche tragischen Fälle kommen durchaus vor) und der nun außerhalb des Flightdecks befindliche Pilot plötzlich keinen Zutritt mehr zur Steuerzentrale des Flugzeuges hat? "
What happens if one pilot visits the WC and his colleague in cockpit - for whatever reason - loses his consciousness (such tragic cases do happen) and yet the pilot outside of the flight deck has no more access to control center of the aircraft?
It almost foresaw what was to happen on flight 4U9525.
"Oh yeah, we know we want to keep it level, so you pull back on the stick a bit, I'll push it an equal amount and we'll be okay." Yeeeah.
However, a potential problem with side-sticks arises because the sticks are independent -- the non-controlling stick does not mirror (i.e., no force feedback) the controlling stick movement, as would happen with the mechanically connected centre sticks/yokes. Meaning, the non-controlling pilot cannot tell what the controlling pilot is doing.
This was the problem on AF447. If you read the CVR log, one pilot was confused about how to handle the situation and, unfortunately, he took control several times during the recovery attempt. In the final seconds, he verbally states he is pulling back on the stick (attempting to climb), which revealed to the [then returned to the cockpit] captain what he was doing, but there was not enough time to correct (forward, nose down) to exit the stall before they struck the ocean surface.
(The stall warning itself was another disastrous UX problem as well, in my opinion.)
Completely agreed about the stall warning as well, I just didn't mention it. Don't warn about stalls unless there's actually danger of stalling!
If the pilot of the EgyptAir Flight 990[2] could not keep his co-pilot from crashing the plane, what could a mob of random passengers realistically do? It seems to me like the DRM problem - you can't protect the pilot and keep them from hijacking the plane at the same time.
At least the doors will prevent any of the other random 150 passengers from taking the plane. That does seem to me like an improvement.
[1] https://www.schneier.com/essays/archives/2005/12/airline_sec...
For instance, to replicate someones fingerprints all you need is a high res photo of their hand from a distance.
Then the airline will move on in the arms race by responding with a fingerprint reader that wants to have a pulse in the finger, and then it doesn't work when the user is in distress and has an extremely high pulse. And then there is an accident and we the armchair security experts come up with more bright ideas.
Last time I had an airline meal, even in first class, the knife "blade" was hard rubber mounted on a blunt metal handle. It could barely cut the food cleanly, never mind someone's finger.
Let's accept it: we may make things gradually better, but there is no silver bullet that would solve all these problems.
To prevent attackers from muting all but the required majority of crew members, sensors all over the plane must be able to record any emergency code words spoken in the event of an attack, which will enact certain security measures (depending on the code word could lock or unlock the possibility to enter the cockpit, notify air security etc). This system should of course not be able to be deactivated.
And if you really wanted to make things sure, you could install majority-authorization buttons on every seat setup to be pressed by a percentage of boarded people within a period of mere seconds, which would allow the people on the plane to make a decision. For an attacker it is not possible to make all those people press the button, since he would not know who is not complying.
Of course you can also have some remote mechanism of unlocking, although the security implications of remote authorization and transmission of commands would be complicated to get right and open too many attack vectors.
Any procedure that aircraft crew is supposed to handle also needs to be something that is trained, memorized, and practiced regularly. Certain simplicity is ideal.
Thus rendering the doors essentially useless, as hijackers threaten to kill passengers one-by-one until the crew (who will generally outnumber the 1-2 people in the cockpit) open the door.
About the only thing I could think of is some way for people to report a problem like this and air traffic controllers on the ground having a way to take over control of the plane from people inside the plane. But that too could have problems (what if the air traffic controller on the ground is the murderous one, and now he is crashing planes that the pilot can't control).
I think it's a near impossible problem to fully solve. The closest thing I can think of is positive train control (PTC) which sets safe boundaries and overrides the operator if the train exceeds those boundaries. In this case maybe the plane simply can not be flown into the airspace around the Alps no matter how much the pilot wants to.
We just told the guards to sod off as we had our own private transport plane we were waiting for. Who on earth would hijack their own plane? Especially as there were 30 armed people on board?
That's the safest way to travel!
Even then, there are considerations like not allowing the cockpit to kill all com links / power so that people outside the cockpit are still able to communicate with the ground to get the root pwd, and as mentioned elsewhere the person inside the cockpit could change their strategy to make recovery of control difficult or impossible even in this case (EDIT: e.g. throwing the plane about). Also, you'd probably want >1 ATC person to authorise to reduce the chance of the door being unlocked by someone at ATC in cahoots with hijackers.
If you're descending into an airport near NYC it's possible that you need to fly towards the city, turn and then continue descending to land. If you hit the autopilot external override at the right time you could be lower than the tallest buildings and get locked into flying into them without enough time to react.
The real solution would seem to be what other people in the thread are suggesting; you must always have two people in the cockpit. At least one pilot and possibly another crew member.
At this point, pilots are really there to take care of unusual situations that the computer can't (which do happen from time to time.)
Source: I have a pilots license.
YEEEEAAAAHHHHHHHHHHH
The pilot can override the code by locking the door in which case it can only be opened from the cockpit for some minutes (5-20).
(4) If one pilot leaves a pilot duty station of an aircraft when operating at altitudes above 25,000 feet MSL, the remaining pilot at the controls shall put on and use an approved oxygen mask until the other pilot returns to the pilot duty station of the aircraft.
Additionally, it's either US airline operating procedure (or perhaps FAA regulations, I couldn't find it though) for a second crew member to stay in the cockpit when one of the pilots has to leave.
In hindsight a policy of always having at least two people does seem preferable. (And, just a little reminder here: Just because someone is willing to fly a plane with 149 other people on board into a mountain doesn’t mean they would be willing to do other awful things, too, like acting violently in person against another person, for example a flight attendant. Preventing this kind of behavior may well be about putting in place many small hurdles.)
I think it’s pretty clear that people in the cabin should never be able to access the cockpit against the express will of people inside the cockpit (preventing scenarios in which someone violently forces someone with knowledge of how to access the cockpit – e.g. a pilot coming back from the toilet – to divulge that information and gaining access that way), so realistically you can only throw people at this problem – and throwing people at this problem is thankfully in this case relatively straightforward and shouldn’t really have any other negative consequences. I don’t see a technical solution to this problem, but there might not have to be one.
Seems like a sensible idea with hindsight.
* An EgyptAir flight in 1999 - http://en.wikipedia.org/wiki/EgyptAir_Flight_990
* A Silkair (Singapore airline) flight in 1997 - http://en.wikipedia.org/wiki/SilkAir_Flight_185
There is debate in both flights as to whether it was murder/suicide, but the evidence is totally overwhelming that it was. Horrific but thankfully massively rare (as you might expect.) I do hope this isn't the cause here :(
http://en.wikipedia.org/wiki/Royal_Air_Maroc_Flight_630
and
http://en.wikipedia.org/wiki/Japan_Airlines_Flight_350
...and of course deep suspicions remain about MH370.
In this case it would seem that no effort was made to hide the fact it was intentional.
Just because the governments of the countries involved didn't like the outcome of the investigations (far more so in the case of the Egyptair flight) doesn't mean it was covered up by the perpetrators, this was clearly for political/religious reasons - the failure mode suggested by the Egyptian investigators was totally unsupported by evidence.
"Your loved ones" died in an aircraft crash. They why of it matters less, and can wait for an accurate answer instead of rampant speculation.
As for the year time frame, it really can take up to a year to figure out. As you say, they're working from an incomplete puzzle. Perhaps the black box does say XYZ, but is that the whole story? They added a lot more security hardware to cockpit doors of late, was it suffering a malfunction? Or perhaps the copilot was panicking trying to figure out how to work around a malfunctioning button and froze up? Or he was knocked unconscious by the sudden descent? Many of these aircraft are 15+ years old at this point, an electrical fault is certainly not out of the question.
Speculation helps nobody but the press at this point.
PS. To the downvoters, please remember that we're barely two days into the investigation, and we're relying on "silence" and a third party report on very preliminary findings to jump to these conclusions.
So we just have to wait a little longer and must take into account the answer will never be found.
The most plausible interpretation is that the co-pilot through a voluntary act had refused to open the cabin door to let the captain in. He pushed the button to trigger the aircraft to lose altitude. He operated this button for a reason we don't know yet, but it appears that the reason was to destroy this plane.
edit: plus, the other pilot was knocking on the door and asking him to open it. So... there was an audience. He also certainly knew the black box would record those moments.
But I give up, this is pointless.
I would not be surprised to learn in the coming days that he did say things. But I don't think we'll find out until the investigators have a solid grasp of what this means for the investigation.
The fact that they could not, and for the voice recording it is obvious they tried, means that the pilot deliberatively blocked the door again for not letting them go in.
He also cries before hitting ground.
https://twitter.com/flightradar24/status/581073962274328576/...
Someone determined to crash a plane would not have too much of a problem incapacitating any cabin crew member (by surprise most likely) before his attempt. I believe that having a second person in the cockpit is more useful (and seemingly essential) if the Pilot/Co-Pilot loses conciousness in order for the door to still be opened.
Killing someone is extremely easy if the other person trust you. You get behind her and hit her with a heavy object in the head or in the nape.
If the pilot is busy doing something like piloting the plane, it is very easy for a copilot to get rid of her.
That makes it physically easy, but the psychological demands of that situation are clearly very different from turning a knob. I think there's good reason to think that there are people who would do the former, but not the latter. If the pilot is inclined to crash the plane due to overwhelming depression, for example, I doubt that this pilot is likely to also kill a flight attendant with his bare hands.
In this specific case, it may be possible that the co-pilot would not have forced the situation where he was in sole control of the plane.
The emotional side of me wants to call the man a coward, and a coward wouldn't be openly aggressive towards a flight attendant, but that's not a very productive point of view. In future cases, there's just no reason why a future murderous co-pilot couldn't be more aggressive, so it's still a situation worth considering.
If true, the only case where having a second person present would be one where an unrelated emergency develops that requires immediate attention at the moment the first person becomes unconscious. I think that scenario is handled by requiring both officers to be in the cockpit at the times where such emergencies are most likely to develop (take off and landing)
Also, that second person would have to be able to fly the airplane. That would mean having a 3-person crew flying the plane (something that Airbus has worked hard at getting rid of for cost reasons), or having a bathroom in the cockpit (impractical, I guess)
In this case I think a remote operator could have seen that something was wrong for minutes, and could have taken over control of the plane, but of course, having that ability carries its own risks.
This seems like a huge risk that wasn't considered when the new strengthened cockpit doors were installed.
That's what I thought, too. Does the pilot also (always?) have a key to the cockpit door in his pocket (risk, because than a terrorist could steal it while the pilot goes to toilet) so that he could reenter the cockpit? So for me a plausible explanation is the the co-pilot had a medical emergency while alone in the cockpit. Now comes the question:
Would pressing the descent button in this case perhaps even increase the chance of survival (in this case the co-pilot was doing a quick-witted decision) or not?
On long flights pilots are also rotated in and out of rest breaks.
I just asked a friend who used to be a pilot for Ryan Air and he said he had never received one.
I'm not aware of any specific tests for suicidal ideation, but the FAA explicitly disqualifies pilots diagnosed with bipolar disorder, and other personality disorders are cause for concern.
I don't know if carriers include other checks. IMO it would be weird if they didn't - but I'm not a carrier.
My guess is that if it's aggressive suicide there will be some high-stress triggering incident in the recent past - debt, blackmail, a weird sexual history, a relationship breakup, or something of that ilk. Possibly even a very negative work review from an insane boss.
If there's nothing at all, that would be very strange and unusual.
Also from memory a 1st class was pretty much a 3rd class with stricter limits and an electrocardiogram which is why it costs microscopically more. At least in the old days if you got a 1st after it expired, it acted like a 2nd for the remainder of the year, and a 3rd for the next year, but a 1st cost more, so I didn't bother (not expecting to achieve ATP cert within 6 months of my solo LOL)
Crudely and inexactly but more or less true, you need a valid 3rd to be a general aviation pilot, a valid 2nd to haul cargo or be a bush pilot, and a valid 1st to work for an airline. Things will be slightly different in Germany but less different than you'd think... we have trust agreements to allow them to fly here and us to fly there so things are vaguely similar but it doesn't matter if my details are slightly off.
http://flighttraining.aopa.org/students/presolo/special/medi...
Finally you have to be realistic. If 25% of the population experiences a mental health issue at some point in their life or whatever ridiculously high percentage, then given the huge fraction of the population flying with issues, issues obviously almost never cause a problem, its right up there with meteor strikes. So you end up with false positive/negative issues. If you assume all men have been dumped by a girlfriend at least once that means roughly 3e9 false positive if you assume all dumped dudes are going to mass murder an entire airplane, a false positive rate of eight nines I think? That idea would be up there with banning German pilots, after all one of them apparently did kill a lot of people and the false postive rate is staggeringly lower than banning all people with mere claustrophobia or a bad attitude or whatever.
Rather than banning what we cannot see, maybe we should just start seriously considering scenarios where one pilot is a malicious actor.
Air travel used to be substantially less safe. Improvements in safety have all but eliminated crashes due to mechanical failure, weather, mid-air collisions, etc. They've done nothing to prevent crashes due to rogue pilots, though. If the rate were constant, they'd be much more visible now because they'd make up a much larger proportion of the much smaller number of crashes.
Btw, my brother knew some details about the accident before they were public news, I assume there must be some pilot grapevine where more details about the accident must be shared. Like I imagine most other pilots must be, he's very shaken by the incident. It's a matter of professional pride amongst the pilot community, I assume.
My father would sometimes be called as an expert witness for blackbox analysis. As a child, I remember him falling into deep depression whenever he had to do that, and he was always given a couple weeks' vacation time whenever that happened.
http://www.pprune.org/rumours-news/558654-airbus-a320-crashe...
Alcoholism is very common with pilots, though. This much I know, because I met many pilots through him and my father, and boy do they enjoy their drinks.
In my dad's time (he was "almost" a WW2 veteran, he was gonna fly on the second Mexican squadron, but the war ended before Mexico sent that squadron), being a pilot was comparable to being a movie star. So much prestige, so much partying. Some of that culture from the middle of the 20th century still lives on, and many pilots still, well, burn bright and burn fast.
Not sure how much of that still goes on - a lot, I would guess.
The paper quoted in "suicide note" wikipedia article ([1]) says that "the note-leaving rate remained almost constant (23.4–36.2%)"
[1] http://onlinelibrary.wiley.com/doi/10.1111/j.1440-1819.2005....
It would be nice before someone is accused of deliberately killing 150 people for no reason to confirm that
- the correct code was put in - there was no malfunction in the door release system - and the descent was deliberate
I haven't read anything on possibly alternate scenarios causing the crash, yet they all seem more probable.
2020: Airbus announces no-pilots planes
2025: All airplanes are now required to be auto-piloted
2030: It's been 5 years without a single accident(Note that I didn't mention anything about webservers, or Internet; are you sure the in-flight entertainment systems are separated from the control network by anything else than a firewall rule? See other embedded systems, and how secure they are. Start with...IDK, Toyota's gas pedal code, see how well such safety-critical code was written: https://users.ece.cmu.edu/~koopman/pubs/koopman14_toyota_ua_... )
Why would you think that the parent assumes 100% reliable SW? Having SW more reliable than humans would be enough reason to replace humans with it. This does not seem impossible to me.
This makes your argument another case of "let's assume we have strong AI; then pilotless aviation is easy-peasy." In other words, one of your unstated assumptions is still firmly in the realm of science fiction.
This is nightmare fuel. I cannot imagine what they went through. No human should have to end their life this way...such a tragedy.
Maybe they didn't start screaming until it was obvious that they were going to crash, but they knew that the captain couldn't get back into the cockpit long before that.
A possible idea is to release the lock (allowing entry using the PIN) if the board computer determines that a crash is likely. (This is safe, because it's unlikely that there is an attacker who wants to enter the cockpit and at the same time a situation likely to result in a crash.)
This clearly only helps against the problem with the locked door, but it seems comparatively easy to implement.
Edit: Another idea: The autopilot should prevent a crash and the only way to disable it should be by pressing two buttons at opposite sides of the cockpit (so two persons have to cooperate).
Honestly, I wanted to help with something constructive here but I don't think we will ever solve the problem of crazy people in the cockpit.
Autopilot engaged.
Your autopilot has malfunctioned and has initiated a steep dive. This has knocked the other pilot unconscious.
> DISENGAGE AUTOPILOT
You need another person to disengage the autopilot. Autopilot remains engaged.
> DISENGAGE AUTOPILOT USING YOUR FOOT
The buttons are too far apart, you cannot reach both at the same time. Autopilot remains engaged.
>
The plane hits the ground and disintegrates. YOU HAVE DIED. Do you want your posessions identified (Y/n)?
> _
After 2001 the pilots were considered "good" and the rest of the crew and passengers "bad".
But what happens when pilot intentions are not good? In this case the crew and passengers are impotent to save their selves.
This is probably what happened in the last two missed airplanes too.
The same is happening with the Government, after 2001 the people have given too much power to the Government because they considered it "good" against the "bad" guys. But as the people in Germany knows, the people in the Government could be the bad guys.
I think we will see personal driving banned in some cities (CBDs at least) or routes in the coming decades as self-driving cars come to dominate our roads.
http://www.aeroinside.com/item/4946/lufthansa-a321-near-bilb...
I'm curious if the plane has enough input to determine "if we continue this course we will crash into the mountain range", and if it does, why can't it take automatic corrective action and override the pilot?
There's a good chance someone commenting here has worked in this area and could provide a very insightful response.
I believe it doesn't (not an expert though), as it'll assume you've lost control of the airplane and will try to recover. However in this case the descent was at a fairly standard speed. But yeah the autopilot will not override the pilot if the airplane seems under control.
1. the legal responsibility lies with the pilot(s); therefore there always needs to be an option to override or even shut down the computer
which is partly caused by
2. computers and their programs are anything but perfect; computer-assisted issues are usually resolved by human input ("speed is 253...254...255...oh look we're actually moving backwards, now what?!" "now we fly manually, you dumb toaster, because we're obviously not in the situation you think we are.").
In other words, "take control completely away from people and give it to automatics" is a recipe for a far more frequent trouble than an unpredictable outlier event.
But seriously, stuff like that already happened, multiple times. Most famously, http://www.dailytech.com/Lockheeds+F22+Raptor+Gets+Zapped+by...
Except when something very unexpected happens (e.g. not all sensor malfunctions can be distinguished from a reading that's outside of the usual range, yet plausible); in such situations, automatics disengage and people need to step in.
In other words, you can only get so many reliability nines and still be profitable for mass transport (as opposed to, for example, Space Shuttle).
The plane is acting on sensor information, hardware and software, which might be flawed. That is why the pilots always need to be able to do a manual override.
Take for instance the Air France 447 crash: the first problem was freezing of pitot tubes to measure airspeed. That alone would have messed up auto-pilot. Then, the not very experienced co-pilot flying the plane also reacted wrong, and then the plane came down; the captain did not start to correct things in time.
http://www.bea.aero/en/enquetes/flight.af.447/rapport.final....
During that they obviously didn't think that any pilot would suicide the plane by flying it into the ground.
All the while there is value in driving planes into the ground, it's an unwinnable solution.
It doesn't... usually. Everything can be overridden.
> I'm curious if the plane has enough input to determine "if we continue this course we will crash into the mountain range"
Yeah. "Whoop Whoop TERRAIN". "Whoop Whoop PULL UP"
Haven't actually heard the recording, but those are probably among the alarms in the cockpit. The pilot is still required to raise the altitude.
http://en.wikipedia.org/wiki/Ground_proximity_warning_system
As other comments pointed out, sensors are still faulty. Not sure if any airplanes actually have auto pull-up capability.
http://www.nytimes.com/2015/03/27/world/europe/germanwings-c...
In the best-case scenario, if someone in the cockpit wants to keep people out, it sounds like the security mechanisms provide a way to do for for at least five and a half minutes.
edit: oh, they just make it impossible to select text at all... nice.
If the inhabitant of the cockpit chooses to respond with a locking command (in the case of the A320, moving the door switch forward); the door will remain closed no matter how hard you try.
Who, What, Why: How are cockpit doors locked? http://www.bbc.co.uk/news/blogs-magazine-monitor-32070528
Apparently they need to survive a grenade blast!
May be self-driving planes is next stage of aviation evolution just like drones for military purposes.
If we look outside, technological trends and intents of organizational leaders are in the direction of more automation and lesser human dependence.
Perhaps the numbers don't yet justify proper investment in this area, but we have to be getting pretty close to at least thinking about it seriously now.
If Pilot had a root pass for the door lock, this could have ended up differently.
My sincerest condolences to families of passengers..
The point with the designs now is that once they are locked, they stay locked, and no amount of killing hostages gets it opened.
But fuck that co-pilot.
But a pilot with time alone in the cockpit can most likely trick the flight computers into whatever mode he wishes.
In any case, you're right that the automation (by whatever name) can already override the pilot in many cases. But it's a really tricky problem because you can easily make things worse instead of better. For example, one reason that Air France 447 crashed was that one of the pilots was commanding the airplane as if it were in a fly-by-wire mode it was not actually in. The plane had already stalled, but he was flying it as if the computers would prevent him from stalling, rather than taking proper corrective action. A proper recovery maneuver would have saved it. This is ultimately pilot error, but automation is a strong contributing factor. For another example, Asiana 214 crashed because the pilot assumed the airplane was doing more for him than it really was, trusting the automation to keep his speed steady, which it wasn't set to do. Again, pilot error, but with automation as a contributing factor.
It seems likely that automation is a net gain when done right, but it requires careful consideration.
The co-pilot flies. That's why there is a co-pilot.
(On really long flights there can be two co-pilots so that pilots can work in shifts, but medium-range flights like this can physically be flown by one pilot, two are there for safety).
Now, consider that programmers make mistakes (even in aerospace) much more frequently than pilots decide to commit suicide. If a software system is given first-authority instead of a pilot you'll have more deaths due to the system than due to pilots intentional attempt to destroy a plane. The problem of suicidal pilots can be addressed by a number of known mechanisms, none of which jeopardize the safety of a flight. Pernicious problems of software quality are still incredibly difficult to address in any context.
As to "why is it not implemented" - because it would create far, far more problems than it would solve, without a measurable benefit.
All the technology exists for me to build a drone swarm to patrol my house constantly on the inside and out, deliver me a video stream, and to deter intruders with non-lethal force. That doesn't mean I just need to order the parts, assemble them, and use.
There is no off the shelf remote fly-by-wire for an Airbus A320 or any other passenger jet. Plenty of companies have done it as a one-off thing. This is for either testing UAV systems or using the plane as a crash test vehicle. This usually involves the same team of engineers that equipped the aircraft monitoring every single parameter in real time. The military has actually received criticism for conducting weapon systems 'tests' in this manner.
There is a huge difference between that and commercial operations of such a system. In a commercial environment, you can't have a team of engineers on constant standby. For planes flying for research purposes over unoccupied areas a high risk of total loss of control is completely acceptable. Commercial and military remote control aircraft all have systems that intentionally crash the vehicle if communications is lost and it leaves a designated area. This prevents potential loss of life due to mundane software bugs. You can't ethically build a system that intentionally crashes an airliner full of people as a response to a software bug.
"Terrorism is commonly defined as violent acts (or the threat of violent acts) intended to create fear (terror), perpetrated for a religious, political, or ideological goal, and which deliberately target or disregard the safety of non-combatants (e.g., neutral military personnel or civilians)."
This guy is a mass murdered, not a terrorist (in the usual sense of the word).
It depends on the motivation of the pilot i.e. Did he intend to create fear? At this point the motivations remain unclear, so it can't be termed an act of terrorism.