The Differences Between the Plane Crash in Tapei and the Miracle on Hudson
nautil.us
nautil.us
It's an incredible human achievement.
I make a hobby of reading through NTSB avaition an maritime accident reports. It's a fascinating look at how to create almost failure free systems out of mechanical things that break and humans that do stupid things.
For instance hospitals (and some industries) measure sentinel events [1][2]. Sentinel events cause death or serious permanent injury, or events that could cause death or serious permanent injury.
1: http://en.wikipedia.org/wiki/Sentinel_event
2: I couldn't find a reference for industry, but I know they are recorded because I went through the training.
I think it's a large part of why the US airline industry has become so much safer over time. Having a lower-bound number for altitude overshoots or communication problems is immensely useful for policy.
http://en.wikipedia.org/wiki/Aviation_Safety_Reporting_Syste...
Programs like this are why much of the worlds airlines are safer. It's not a US only thing.
This sounds like focusing only on benefits and ignoring costs. That rarely leads to good overall outcomes.
This is a very useful mental error to be able to spot. A very common argument is "X has a clear benefit, so we should do it!". The benefit is absolutely real, but you also need to look at the costs to make a good decision.
Another failure mode is risk aversion. If the FDA approves something that turns out to kill 1000 people, they get in much worse media and political trouble than if they don't approve something that would have saved 1,000,000 lives. So they focus hard on costs and less on benefits.
One way to think about it is that those resources could save 100 times more lives per dollar in other areas.
A similar line of reasoning would be “In this developed country that I live in, no one dies from being poisoned by tap water. I oppose this massive overspend on making tap water potable! The resources used to reach this absolute would certainly save more lives per dollar elsewhere”.
How much would we save my making tap water less potable? What would be the consequences if we did?
Sometimes, absolute safety or near-absolute-safety is within reach and is the sweet spot for smart engineering.
There is precisely no objective reason to believe that at face value.
Flying is still pretty safe, but we shouldn't understate the impact weighted risk of activities.
Is this (fatal/survive) a typo, or does it mean you could survive where some passengers don't?
Just 2010 had 267 fatal accidents and 453 deaths, though the trend looks good. http://www.aopa.org/About-AOPA/General-Aviation-Statistics/G...
If you want to get technical about it nearly all plane fatalities are caused by a lack of altitude, but that's a different story.
http://www.asias.faa.gov/pls/apex/f?p=100:43:0::NO::P43_REGI...
Normal Accidents by Charles Perrow is a great book on the topic of how to put together complex systems that are forgiving of user error: http://en.wikipedia.org/wiki/Normal_Accidents
Here's a summary: http://users.ox.ac.uk/~kell0956/docs/systemic_failures_1.pdf
The book uses airline safety as one of its primary examples. Here's an article applying it to a previous aircraft disaster: http://boingboing.net/2011/12/08/disaster-book-club-what-you...
Um...the EU and much of Asian is doing pretty good as well.
Also, as the article mentions, the river is much less suitable for ditching than the Hudson.
*edit apart from the comparison, I think it's a pretty good article.
By contrast the Taipei flight has a perfectly good working engine and should have had no problem reaching a runway and landing with minor drama at worst.
There is no question that losing an engine in a twin prop plane on takeoff is among the more gnarly problems you can have but there is absolutely no reason the plane had to depart from controlled flight.
It is pilot error that caused the deaths of dozens of passengers, period. Without said error that plane would have been able to land at an airport and taxi back to a gate.
(Source - I have a pilots license)
Air Canada Jazz had 6 engine failures (plus 2 more problems) in the last 12 months across their DHC8 fleet (I fly with them once a month on average and never had a blip, thankfully.)
They mentioned Sullenberger's experience, but he also had more than twice the altitude when he lost engine power. Still an emergency, but he had a bit more time to think about it.
Sully, on the other hand, had a minute or two before he was going to run out of altitude, no matter what he did. Every moment counted there, in a way that it definitely didn't count in the Taipei crash (until the pilot made it that way).
The Taipei flight had a perfectly fine engine and there is no reason for any of this to happen. The plane could fly just fine with one engine out.
For the first time, I just counted the timing. Bird strike is at ~10 seconds. Pilot waits until ~20 seconds to call "Mayday". Only at ~32 seconds does he shut down the damaged engine.
If the Taipei pilot had taken the same time to get his bearings before acting, everyone might have survived.
In terms of the value of training, I love how cooly the air traffic controller responds to the Mayday.
There's a saying in aviation that one pilot may have a thousand hours of experience, while another pilot may merely have a hundred hours of experience repeated ten times.
Capt. Sully is known for being involved in aviation safety before Flight 1549 put him on the front page. It was like decades of training and experience, was leading up to that one day in January 2009 when Flight 1549 was able to land safely in the Hudson.
Some career pilots have very little stick-and-rudder (& thrust lever) experience, and fly on autopilot for thousands of hours. Shutting down the wrong engine is either very poor piloting, or a systemic training issue.
I believe the true failure here wasn't shutting down the wrong engine, but trying to shut down the bad engine at all while still so low. Shutting down a failed engine is not a priority. It can windmill and tear itself to shreds for a little bit while you keep the airplane flying, get to a safe altitude, and figure out what to do. Multi-engine pilots I've talked to about this have said that it's standard procedure not to shut down a bad engine below a certain altitude, precisely so you're not screwed if you go for the wrong one by accident.
A common cause of aviation accidents is a pilot responding to an emergency by making it worse. A safety class I went through recently presented a case where a pilot thought he was low on fuel, decided to land at a nearby airport, botched the landing by coming in high, fast, and downwind, and crashed off the end of the runway. Turned out the fuel gauge was faulty. There's a famous C-5 crash that's similar to this Taipei crash, in which an engine failed, the pilot shut down the opposite engine by mistake, and then botched the landing because he flew as if he still had three engines instead of two. A semi-frequent cause of glider crashes is a pilot failing to lock their canopy which then comes open in flight, and the pilot tries to fix it instead of flying the airplane. They key isn't to ensure you do the right thing fast, but to make sure you prioritize and don't do anything fast that isn't immediately necessary. Engines fail? Find a spot to land, right now. One engine fails? Keep climbing and breathe, then take your time to decide what to do next.
Certified passenger turboprop aircraft (ATR-72 included) should be able to maintain altitude, without feathering the failed engine.
I was thinking of British Midlands flight 92, where an experienced crew that were new to the 737-400 misread the vibration instruments, and shut down the wrong engine, at altitude. Poor training on the -400 differences was a major factor.
Experienced pilots do screw up occasionally, but good CRM usually avoids a mistake snowballing into a fatal crash.
In a Cessna 150, I had the window come open on takeoff. Same aircraft, same instructor, same thing happened to my dad years before. He told my dad to "Fly the plane".. I knew not to close the window until at a safe altitude. He just smirked a little.
That's not quite what happened. The vibration instruments on earlier models were known to be unreliable, so the pilot tried to figure out which engine had failed using other indications (I forget which).
I found this out by accident after being prescribed a beta-blocker for typical blood pressure reasons while I was trying to deal with some panic-attack issues that were serious enough to need a mild benzodiazepine. After starting the beta-blocker, the need for the benzo just went away. While the benzo was effective at blocking part of the recursive/positive-feedback loop of panic, the beta-blocker was much better at preventing the feedback loop from forming at all.
Later on, a friend of mine who attended RISD mentioned that the drug of choice that was sought by all the art students was beta-blockers, so they could present their projects without all the stage fright.
/* obDisclaimer: This is not medical advice. Taking any drug can be dangerous. See a real doctor. etc */
I did teakwondo and kickboxing. When I was starting Teakwondo (~16 year old) first sparrings were dominated by fear and anxiety. I didnt know how to act, what to expect, I was physically shaking. Fast forward few months and I was in control, anxiety turned into excitement, fear into caution. My body and mind learned to use that sudden adrenaline injection to my advantage. Two years later I moved to kickboxing. Its very different sport, more violent, faster and can be significantly more painful in the ring, nonetheless my experience from teakwondo translated perfectly. Since then I had couple of dangerous situations on the street (drunk idiots, football fans etc) and again I was in control of my body and reactions, my previous experience of being punched repeatedly in the face inside the ring helped me stay calm :)
Second example is virtual. Eve Online is a space themed MMO. Everything you own in the game has to be earned or paid for with real money, and all losses are persistent and final. Someone kills your ship worth two months of heavy missioning? its GONE forever. This design choice makes Eve Online the only computer game inducing real fight-or-flight reaction that I know of(outside tournaments/leagues). Losses can be as small as 10 minutes of your time (couple of cents), and as severe as $1000 blink mission ship you spend whole last year to build. First PVP fights in Eve were exactly the same as my first sparring 10 years before :) heart pounding, hands shaking, sphincter gripped tight etc :) and mistakes ending in expensive wrecks. It took some time and experience to fully take control of the situation.
Can write something about bike riding(crashing), but it will be the same story again :)
I wonder if pilots with military background, trained in battle sims in high pressure situations, are significantly better at handling emergency. My own experience makes me think definitely yes.
Human instinct is to slow down, but on a bike this will have the effect of widening your turn radius—totally counterproductive. To tighten the turn radius, you need to accelerate and lean in (which you can do unless you're already dragging a knee).
Or when you're on ice and you really want to turn but just have to keep going straight until you hit a patch where you'll get some grip from the mountain cover.
Also, as tragic and sad as the crash in Taipei is, the swerve of that little yellow car in the dashcam still, and imagining the occupants' reactions as a they swerved to avoid the plane that was crossing in front of them, is quite priceless.
Our ancestors' attempt to explain it by inventing elemental gods and pleasing them...does nothing.
The entire public discourse of investigation, of which the actual result producing investigation is just a part, serves a narrative purpose akin to the ancients' gods. To some extent there's a spectacle of rigorous investigation and explanation in public discourse, and to that extent it's like worship for harvest. It makes us feel things are getting better when perhaps there are areas where we have little control. So there's a social utility and an engineering utility. That's the thesis anyway! Maybe it's all social or all engineering, tho I think each of those less likely than providing both.
How long would it take to restart an engine and gain speed again?
Humans are absolutely terrible at two kinds of tasks: 1) boring, rote tasks that require continuous attention for long periods of time and 2) high-stress, quick decision bursts.
Which pretty much describes flying a plane.
For TransAsia, the point is that a computer wouldn't have needed to land. It still had engine power and could have moved the plane to a stable situation.
The problem is that the TransAsia-type pilots and situations far outnumber the Sullenberger's.
I don't see why this is an argument for full automation.
One thing that most people don't realize is that if Capt. Sully had lost one engine, and turned hard into the dead engine to return to LaGuardia, chances are he would have crashed. He made the right call to confirm (dual) engine failure.
Its also well known that a controlled crash landing is better than trying to stretch the glidepath, and loosing control.
I suspect that "automated" airliners will be programmed with crash landing areas for the 0.00001% its actually needed. There was a mishap when a F/A-18D crashed on final, both engines out, and its theorized that if the pilot had flown the pattern higher the jet would crashed away from the houses. A lot of factors lead to the crash, and 4 people in the houses died.
Of course, flying dead-stick instrument approach with low clouds is almost unheard of.
> The problem is that the TransAsia-type pilots and situations far outnumber the Sullenberger's. That is a huge problem. A lot of training programs are very scripted, regimented, and do not encourage pilots to make decisions like intentionally putting a jet into the water.
NASA trained the shuttle crews for unrecoverable situations (that don't result in an emergency landing) so the crew would still keep functioning and hopefully bailout.
The same way a human does: by assessing all the options, running little simulations to see which is the best one, and then picking that one. When you're over a densely populated area and lose all power, landing on water is kind of a no-brainer actually because all other possibilities lead to certain disaster.
So your powerless computer is going to land the plane?
And just to be clear, if you somehow lose all electrical power on a modern airliner you are completely screwed no matter what or who is flying it, because the controls won't work anymore. The pilot, whatever its nature, immediately becomes a passenger.
As a pilot myself I can tell you that in EP there are really only a handful of criteria you look for when determining a place to land:
1. Minimize risk of ground personnel 2. Minimize obstructions between air and ground (ie. poles, trees and wires are bad) 3. Maximize straight and flat ground 4. Maximize featureless ground etc...
Given where Newark is, and Sully's flight condition, there was really only one place that would show maximum differentiation in human density and allow for landing: Hudson. The trick is knowing how to land on water with *a passenger jet - something remarkably simple to compute given environmental parameters (CG, load, wind, etc...) and a few simulations.
As was rightly pointed out, the key to success here was calm - something Sully learned starting at the USAF Academy (I'm a fellow grad as well, shout out where you can take it!) and was what let him do computer level calculations so quickly.
Well it did. One of the (probably lifesaving) actions that Sullenberger did was to deploy the RAT which meant electrical power was maintained. This was not a checklist item, merely something he though useful. This meant the computers were still firmly in control when the aircraft ditched and the stall protection they gave certainly helped the ditching.
Interestingly after the accident the NTSB and Airbus made a number of ditching simulations and it showed just how hard it was for pilots to achieve the correct entry mandated by the ditching certification (minimum speed, -1 degree approach). However one pilot, an Airbus test pilot, managed to do much better than this by levelling out at high speed and very low using the radar altimeter. He the allowed the speed to decay until the aircraft touched the 'water'. This unusual proceedure probably couldn't be done by many pilots but it could be done by a computer.
This is a training issue more than any definitive "proof".
Good luck finding pilots. And how do those pilots get that 20,000 hours?
Humans are bad at some tasks. This is an example of one of them.
Sure, but there's the same problem with computer pilots: how do they establish a tremendous track record of safety such that people won't freak out? I don't mean "rationally decide that a computer flying is better than a person" but instead, emotionally accept it's a better idea?
The odds in traditional aviation are pretty good these days; better than driving. But nobody wants to be the first person to be killed by a computer pilot. Acceptance is going to be a tough road.
Like autonomous cars, autonomous airliners have been steadily sneaking up on us for a while, and the first fatalities have already happened. It's a smooth function, not a pure on/off.
We've had tremendously advanced autopilots for a long time, but there have always been people up at the front, supposedly in charge.
It's the difference between getting on a bus with a guy in the drivers seat who has auto-braking so he doesn't accidentally rear-end someone and getting on a bus with no driver at all. People are OK with the first, but less likely to be OK with the second.
I'm not saying it's rationally correct for people to behave this way, but they do behave this way.
For one thing, I think it means the transition will be easier than most people fear. As we get more and more automated, we'll start making entire flights from gate to gate without human intervention. At some point, somebody will say, "It's been three years since the last time a human airline pilot actually did anything, so clearly you're all comfortable with being flown around by a computer, let's take that final step" in a convincing manner.
Personally, I don't want to be the last person killed by a human pilot. :)
Agreed, though, that safety in aviation is generally quite good.
There was a similar issue in November of last year on flight to Barcelona, luckily, the pilots managed to restart the systems just before 150 people would have died.
If the computer piloting the plane was designed by the same criteria -- economics -- as the plane was, it'd have pretty much the same crash rate per passenger * mile. It has everything to do with managing costs and acceptable risks, and not some inherent insafety of flight. An airplane can be made just about as reliable and reliable against pilot errors as you want. The technology is there, has been for decades, it's only matter of costs and performance.
The crashed plane was a two-engine model, designed so in case of one engine failure it could still fly safely. However, the margin of safety was small enough that once the wrong engine was throttled back, the plane became uncontrollable before the engine regained enough power. Spinning up engines takes certain, well-known, time. It'd be entirely possible to design and build a plane that would handle such accidental throttling gracefully. All you need is one more engine, or larger wings giving more lift at slow speed and thus allowing it to remain in the air long enough to recover.
The crux is the airlines choose not to go for either option simply to cut costs, accepting lower safety margin.
Now consider fully automatic plane flown by computer -- designing and debugging a robust hardware/software solution is very costly. Especially when it comes to handling tricky, rarely-occuring cases, like unexpected failures. Throw in both cost of handling of multiple versions of planes -- different engines, different avionics, and handling of flightworthiness reduced by wear and tear. Also attach the risk of mismatched configuration, with no experienced pilot inside to spot the problem.
In the end, the amount of money spent on development, and the level of redundancy of software/hardware autopilot would be dicated by cost-cutting and going for what the airline deems acceptable risks.
The computer pilot would be just as (un-)safe as human pilot, for the reasons of economics. Safety is calculated and kept per passenger * mile, not dictated by current technology.
This is pure absurdity. How can you insist that economics of software development equate to the economics of human labor?
Economics drives everything but one of the main points of software development is the economic advantage it brings in terms of skill and cost.
All things considered, software is cheaper to be skilled, and economically speaking, will always outperform equivalent modern-cost human labor at these tasks. Dollar for dollar at scale, at least.
Software isn't perfect but if it wasn't economically superior to human labor none of us would have a job right now.
However, there is absolutely no reason to assume that different approaches will arrive at the same trade offs. Of course a software pilot has cost/benefit trade offs, but they could potentially be more favorable trade offs than you get using a human pilot. The entire point of improving technology is that the balance of trade offs gets more favorable.
Actually it is the passengers that want to cut costs. Us in other words.
http://www.rvs.uni-bielefeld.de/publications/compendium/inde...
Note that bad engines do not always stop. Often times they are just on fire, or are vibrating, or losing pieces ...
No. I've watched too many episodes of air crash disasters to support this.