There was also a crash where the pilots turned too much off at once.
If you hava a lot of computerized equipment to help you you depend on the things that work. You want only that malfunctioning part off. Here the problem was that before Lion Air crash nobody but Boeing even new that MCAS existed, let alone turning deadly with the malfunctioning non-redundant sensor.
It disengaged, moved them to alternative law and one of them (the co-pilot, IIRC) didn't realize it and pilot and co-pilot gave different stick inputs. The purpose of a single button would be to put the plane in a known, easy to reason about state, even if it's not the most stable or the easier one to fly.
> The purpose of a single button would be to put the plane in a known, easy to reason about state, even if it's not the most stable or the easier one to fly.
The "known" is the problem there. The pilots there were continuously misinformed about the plane speed due to that iced measurement devices. That is what plane "knew" and what the pilots "knew" in the storm.
The autopilot handed over control to human, but then human drove it too high (the "law" here means "mode of operation"):
"The pilot continued making nose-up inputs. The trimmable horizontal stabilizer (THS) moved from three to 13 degrees nose-up in about one minute, and remained in that latter position until the end of the flight."
"A second consequence of the reconfiguration into alternate law was that stall protection no longer operated. Whereas in normal law, the aircraft's flight management computers would have acted to prevent such a high angle of attack, in alternate law this did not happen. (Indeed, the switch into alternate law occurred precisely because the computers, denied reliable speed data, were no longer able to provide such protection—nor many of the other functions expected of normal law).[55] The wings lost lift and the aircraft stalled"
> one of them (the co-pilot, IIRC) didn't realize it
But the co-pilot definitely knew that the autopilot disengaged:
"The first officer, co-pilot in right seat, 32-year-old Pierre-Cédric Bonin"
"At 02:10:05 UTC the autopilot disengaged" ... "As pilot flying, Bonin took control of the aircraft via the side stick priority button and said, "I have the controls.""
But, I'm not sure if the concept of "full manual" is anymore relevant with modern passenger jets. Are they even flyable without any computer intervention or too unstable / have too complex flying charasteristics?
Ignore what you have read about the new engine making the MAX unstable. It’s more nuanced: It’s unstable near stall.
Commercial aircraft are not fighters. They don’t need to be unstable with computers making them flyable. An unstable airliner would be an uncomfortable airliner and hence a commercial disaster.
What has changed is whether or not there is a manual connection between the yoke and the control surfaces. For reasons of cost, that connection has been going away.
Commercial airliners are stable when flying. The advantage of an unstable aircraft is high maneuverability which you don't need in a commercial airliner. Also in full fly by wire aircraft there is a "red button" that will drop the flight controls into a fail safe mode. This mode usually has much simpler control law, and disables other functionality like auto land/auto pilot/tail strike prevention.
In a non-fly by wire air craft though like the 737 max, a full manual mode is basically when you have auto pilot disengaged. There might be a mode you can enable to disable other functions like tail strike prevention/MCAS but I a haven't ever heard of it.
[0] explains that fuel efficiency considerations prompted Boeing to push the altered 737's larger new engines well forward compared to prior iterations, causing the airplane to pitch nose up in some maneuvers in unstable fashion. The MCAS system was introduced to compensate, and is the component that failed in both crashes.
Basically all planes have flight profiles where they are stable and unstable. Just because a plane is unstable in certain conditions, does not make it an unstable plane. A stable plane is a plane that is aerodynamically stable for most of its flight profile.
The 737 MAX is just not stable in every condition that the old 737 NG was. And it probably goes the other way, there are most likely flight conditions where the 737 MAX is stable but the 737 NG is not.
The difference is that pilots had been trained and have flown the old one for many years and trained to avoid the unstable conditions for the old 737.
*Flight conditions meaning: air speed, AOA, bank angle, total thrust, altitude.
> The difference is that pilots had been trained and have flown the old one for many years and trained to avoid the unstable conditions for the old 737.
I don't think that's the case. MCAS was added to satisfy a requirement in the airworthiness certifications that requires positive control forces to increase AoA. The lift generated by the engine nacelles caused this to not be the case at high AoA.
None of what has been revealed so far indicates that the pilots had issues related to the symptom, rather they had issues with MCAS. In a way the cure has been worse than the disease.
> Also in full fly by wire aircraft there is a "red button"
There is no red button as such (at least as far as Airbus is concerned). The computer decides that something has gone wrong and invokes an alternative law. You'd have to start pulling circuit breakers to manually trigger a reversion.
> Commercial airliners are stable when flying.
This is not necessarily true. All modern airliners have aggressively swept wings. This generally makes them susceptible to dutch roll in some phases of flight. They are fitted with yaw dampers to control this tendency.
Learn something new every day. Looks like Boeing has a switch the pilots can select for direct mode. But for an Airbus airplane you would have to pull the circuit breakers for the Flight Computers to drop to Direct Law.
The 737 MAX is not. That's why it has the MCAS system in the first place: the engines are too large for the airframe, making the aircraft fundamentally unstable, so they came up with MCAS to try to make it seem stable to the pilots, and then they didn't even bother telling the pilots that this MCAS system even existed.
The one engineering truism is "There's no free lunch." You're trading a reduction in something (hopefully that isn't important / used) for an increase in something (that is important).
So when we see capacity increases, fuel efficiency increases, reliability increases... I'd hazard to say that comes with increased complexity.
And at some point, it's more dangerous to let a pilot fly a highly engineered aircraft on full manual than it is to let a team with access to the technical specifications and time generate an approved, stepwise, degradation flowchart for pilots to work through.
In the same way the best solution to an engine timing issue isn't "Work the valve timing by hand" but rather "Degrade to a less efficient but more reliable profile" through to "Degrade to a static profile that keeps the engine operating after multiple failures."
You really don't want to be burdening pilots with more work.
The failure here seems to be in a poorly designed degradation route, not in the idea itself.
My understanding is that there is a button on the stick to disable the autopilot if the pilot just wants to be maneuver. And a circuit breaker to really shut the thing down if there is something wrong, as it happened during the accident.
You don't want to disable everything at once, and put too much cognitive load on the pilot during the worst times. Especially not safety systems like MCAS is supposed to be.
Part of the problem with the Max is that it handles differently compared to the old 737, so a pilot used to flying a 737 isn't immediately ready to fly the Max. To quote a pilot on the issue;
"I think it is unconscionable that a manufacturer, the FAA, and the airlines would have pilots flying an airplane without adequately training, or even providing available resources and sufficient documentation to understand the highly complex systems that differentiate this aircraft from prior models." [1]
Unless you're confident flying that specific model of that particular plane just turning off auto-pilot is really dangerous. Planes aren't all the same, so "knowing how to fly" doesn't really work, especially on take-off and landing where the margin of error is very, very small.
Airplanes don't have big red buttons that turn off all automation because it's always the wrong thing to do.
You can't press a button without understanding how it will affect the plane. How do you know the automation is at fault? Maybe there is mechanical damage and the only reason you're in the air is the automation? By the time you understand if the red button can be safely pressed, you understand what is generally causing the problem. So you can disable that specific automated system, which you can do today.
Also, automation is very very rarely at fault, it basically never happens. But accidents are often avoided, and many accidents would have been avoided, if pilots let go of the controls and let the automation and the inherent stability of the airframe return the flight to normal.
I can't think of a single time when that big red button is a good idea.
Boeing just recklessly didn't tell these pilots what to watch out for, what automated systems existed, and to save some money didn't include the basic safety equipment they needed.
> Boeing just recklessly didn't tell these pilots what to watch out for
I can't really contest that. The pressure to sell it as identical to previous models and skip certification and training steps seems to have played a part on this.
The strong correlation between more automation and increased flight safety over the last few decades should be strong prior for continuing to increase it, current events non-withstanding. After all, since 1970 airline travel has increase 10-fold, while fatalities have decreased by the same factor. Combined, you risk of dying on any given flight today is just 1% what it was in the haydays of pilot jocks.
Contrary to what our instincts tell us, automated systems are potentially far saver than humans could ever be: You can take as much time as you need to think of the best reaction in every scenario; they will execute whatever best practice you come up with every single time without needing constant (re-)training, they don't drink, they don't suffer strokes, they don't get tired, etc.
The failures we have seen tend not to involve any errors in judgement by the automated system. Instead, they almost invariably result from faulty sensor input. For the 757 Max, the angle-of-attack sensor seems to have failed, and relying on input from just a single sensor seems catastrophically negligent.
Such failures cannot reliably be avoided by giving humans more control. With a sensor showing a large AOA and the "STALL! STALL!" alarm blaring, a pilot would take the same action MCAS took, at least initially.
For the two recent crashes, the pilots would probably have recovered. But they had the advantage of daylight and clear skies. At night, in bad weather, and even in the best conditions, hundreds of planes have crashed because the pilots suffered some sensory illusion. See, for but one example, https://en.wikipedia.org/wiki/Air_New_Zealand_Flight_901, which crashed into a mountain because the crew mistook it for an ice shelf. Air France 447 (https://en.wikipedia.org/wiki/Air_France_Flight_447#Accident) is even closer to the current crashes. It shows pilots taking manual control of the plane while fatally misjudging its attitude. There are many other examples where pilots get disoriented in, for example, clouds. The typical story is the plane coming out of the cloud inverted without anyone on board having noticed. Our sensory organs aren't equipped to measure complex movements in 3D: you can roll a plane without ever spilling the champagne glasses in first class.
> Our sensory organs aren't equipped to measure complex movements in 3D
That's why you trust what the instruments say. On both MAX crashes (and AF447) what happened is that the plane was doing things the crew didn't understand. If there were a clear indicator they had more than the usual amount of authority (say, chaining the cockpit lighting color to red) or a clear way to disengage the computer assistance and put the plane in an easy to reason about state, which, I assume, would be useful if the plane is doing something for a reason you don't know about. Like you said, the two MAXes would be saved. AF447 is less clear, but, still, if we find the machines so much more capable, then we should remove the humans altogether (that would probably safe AF447).
> ...the F.A.A. outsourced key elements of the certification process to Boeing itself, and that Boeing’s safety analysis of the new plane contained some serious flaws, including several relating to the mcas.
This sounds insane. Is there a reasonable explanation?
They also want to make a profit and therefore might make compromises in security. There is a reason we have independent inspections like everywhere we deem sensible enough to pay for it as a society.
It's tricky when it comes to software systems though. Imagine you had to inspect a new Boeing. It would be ok to look at the construction and see it was stuck together ok but hard to understand all the software systems unless you'd helped write them. Normally with software written by others you find the problems by using it and seeing it have bugs or crash, not by inspecting the code.
In this case I imagine someone at Boeing knew moving the elevator jack 2.5 degrees based on one sensor was unsafe hence them selling an optional upgrade that made the system safe. That seems kind of criminal.
I'd agree if the problems is within the software "black box" (the software term, not the aircraft thingy).
But to me it currently looks like it's largely a problem of how the different systems interact and how it's communicated to the users aka pilots. That's something one should be able to spot from the flowcharts/blueprints or whatever they have to document system integration.
Except for the fact that they really like to throw their customers and pilots under a bus if it's convenient to them.
This was, in my opinion, one of the most disgusting aspects of this whole sordid story. They had to cut back after the Ethiopian crash, but blaming everybody else seems a big part of their DNA.
After the Lion Air crash it wouldn't have been unreasonable to assume pilot error. Almost all recent accidents have been pilot error.
I read somewhere that the sensor was misreading by 20° and Lion should have noticed.
Should Boeing have shipped the system with a single point of failure by default? Probably not.
Should the FAA have raised questions about that? Probably.
Should Boeing have considered a test case where a pilot didn't know about MCAS? Probably. But we don't know that they didn't. Perhaps they did and their test pilots recovered the plane in time. That would make it a Lion Air training failure.
There's no single point of blame here, but thankfully the airline industry reacts as a whole to incidents like this and takes as many steps as possible to make sure it doesn't happen any more.
Well, how could they train for it, when Boieing conveniently hushed over such a significant change, because it was commercially expedient? Until the Lion Air crash the airlines and their pilots didn't even know that such a system is in place.
According to an AA pilot the entire training consisted of less than an hour presentation on an iPad, in which the new behavior wasn't mentioned at all.
Add to that that Boeing offered a paid upgrade which at least would make pilots aware that the system malfunctions.
This paid upgrade sounds a bit like "Nice plane you have here, would be a shame if it crashes"
No matter how you look at it: Boeing displayed despicable behavior in this whole sorry mess. Behavior which comes back now to bite them badly.
I don't disagree with your reasoning, for what it's worth. I just think there really should be a special place in hell for the Boeing executives who allowed this to happen. Especially after the first crash.
Again, unless I've missed a statement, we don't know if Boeing has tested for this case internally.
This case being "pilots untrained and unfamiliar with the MCAS system recovering from a catastrophic systems failure / error".
They are at fault no matter what though from straying from their long held principle that the pilot has the final say on control of the aircraft. Inputs from the yoke and throttle levers should always supercede the computer.
The pilots could have been trained to understand all the control surfaces on the airplane and how to identify their configuration.
From what is reported about the Lion Air crash it sounds like the pilots may not have sorted out what the stabilizer trim was set to and what to do to correct it. Hopefully that is not the case as such a situation would be a glaring problem with pilot competence.
This is all fairly irrelevant to the fact that the safety procedures themselves seem unjustifiable. How could the FAA have raised questions if they weren't even doing the testing?
Nobody in either the article or this train of comments has suggested that it was unreasonable to assume pilot error after a single crash. The problem is the oversight process which allowed it to be certified in the first place.
The airline industry isn't responsibly reacting, they're reacting after trying for quite some time to ignore the problem because it's becoming increasingly obvious that they and the FAA have been horrendously negligent, and ignoring it isn't working anymore.
Everyone these days want to 'delegate' work to someone else if permissible by law, and sometimes even if they are not, I guess. I have a feeling the report would come out with, 'due to lack of funding and experts, some of the work had to be 'delegated' to Boeing' etc...
> It turns out that the F.A.A., with congressional approval, has “over the years delegated increasing authority to Boeing to take on more of the work of certifying the safety of its own airplanes,”
This ran through Congress. Not that any of them or the bureaucrats at the FAA will face penalty.
I am not aircraft specialist, but I have seen similar things in IT/telecommunication.
I think this is competence issue. F.A.A don't have people and tech to really understand/analyse anything that is going on with modern plane.
More broadly USA specifically likes usage of contractors, some other countries at least try do have technical competence in govermental agency.
So that is mostly question, why F.A.A don't have third party, like Lockheed Martin, to audit Boeing, but that is probably against Boeing (and reverse situation Lockheed Martin) commercial interest (like trade secrets).
When I read it I was reminded of a report I heard in the Private Eye (UK magazine), in which they mentioned that large firms were both managing the accounts of Russian companies suspected of wrong-doing and auditing them.
The Seattle times report[0] that the delegation was largely politically motivated in an effort to save time on the certification so that Boeing would not be left behind with respect to Airbus.
So it is not a competency issue, so at best it was mostly capacity related: the FAA didn't have enough resources to certify at the speed Boeing needed. Of course, the fact that you are certifying yourself might also speed things up for other reasons than purely your willingness to allocate more resources.
It's not necessarily terrible. Boeing obviously has a strong financial interest in safety. The Fight Club theory of managing an acceptable number of fatal mistakes really doesn't hold for the airline industry, because their failures are large and public, because people are inherently afraid of air travel, and because the investigation of plane losses tend to produce far more definitive results than car crashes.
This investigation seems to be turning against Boeing. They will survive, but it almost definitely will cost them far more than whatever they saved by cutting corners. There will also be changes to the certification process, and non-US authorities will take a hard look. Any new incident would become an existential risk for Boeing.
It's important to remember that a company like Boeing isn't a single person. People working on the certification process would usually have incentives that differ from the company as a whole: they do not individually reap the benefits of cutting corners, but bear the brunt of any mistakes, including moral responsibility, possible criminal charges, and an end to their careers.
Such schemes are employed in many industries. Usually, corporate structures and cultures prevent the sort of top-down pressure that people imagine being at play here. Threatening your safety engineers (fire marshals, data protection officers, etc) with job loss for doing their job would result in whistleblowers and lawsuits. It will be interesting to see how exactly this failed at Boeing.
Clearly, Boeing didn't have enough interest. The idea that self preservation should be enough to make companies "do the right thing" ignores the fact that if they cut corners, people die. If the CEO could be held criminally liable, that might work, but in this case the only downside for Boeing will likely be share price drops.
It's not necessarily terrible. The software industry obviously has a strong financial interest in avoiding tech debt. Surely any reasonable software company with the long view would invest in a solid architecture, well defined processes..
The insanity is hidden somewhere here. Peekaboo - there it is..
This is the way most engineering work is certified, actually. A standards bureau creates a standard, the engineering design organization follows it and self-certifies that they did.
Only in case of failure is the self-certification process checked for errors, usually by insurance investigators, because they have the most incentives to do so.
The visible examples of public failures investigated by public agencies are the exception, in my understanding.
Exactly. This is how the medical device industry does it. One important part you skipped was the mandatory audits of the development process (often with little or no warning: FDA audit team announces that they'll be there tomorrow).
I honestly don't think there's any other realistic way of doing it properly. The true experts are the ones doing the work.
I'm an aerospace engineer and I work in certification. This is par the course. The regulatory authority allows delegates to make findings of conformance w.r.t. airworthiness standards for aeronautical products. These delegated engineers have narrow specialties and are delegated for only specific ATA chapters or subsections. So Boeing will have a few delegated engineers whose only job is to certify Chapter 28 'Fuel Systems' components. These delegated engineers act as 'Design Approval Representatives' (DARs). They do this through something called an 'Organization Designation Authorization' (ODA). This is the regulators way of allowing some trusted individuals to make decisions on behalf of the regulator. This is often because these engineers are experts in their fields so they take on full responsibility. It's the equivalent of an engineers 'stamp' in civil engineering.
> In October of 2017—six months after the 737 MAX was certified—President Donald Trump signed a law that allows aircraft manufacturers to press the FAA to give them authority over how they certify components considered to be low- or medium-risk items. And if the manufacturers can convince the FAA that something falls into one of those two categories, they could essentially have free rein over how they certify their craft as safe. [0][1]
It is not a reasonable explanation, but the explanation is that the FAA is underfunded. It cannot handle the work itself, and cannot afford to contract it out.
It is not realistic for the FAA to do all the work independently, but now it cannot even effectively audit the self-certification.
This sounds a lot like regulatory capture [1]. It's becoming more and more clear that the institutions that were / are(?) great at ensuring the safety of the public have been undermined by special interest.
For a really striking example of regulatory capture, look no further than the FCC.
One way to make sure that regulatory capture does not happen, is to ensure that money is not part of lobbying. But that's another discussion.
A single sensor for an automated system that can control the flaps?
No redundancy on a system that can control flight. A system that is supposed to help avoid a stall scenario.
That alone is a crazy oversight, let alone differences between safety analysis and actual capabilities.
This stinks of truly awful management - the rules of the sky were written in boood. Ignoring them has shown serious consequences, because we already knew not to do this.
>A system that is supposed to help avoid a stall scenario.
This article doesn't get the point right. From this article it sounds like some optional "helper" system for pilots to avoid stall. Another article got it right, the plane itself is unstable because of big engines if the MCAS is not there to stabilize it. So its not some optional system, that the pilots would switch off when manually controlling the plane, its there for the plane to fly at all.
It's closer to a 'helper' than what you're suggesting.
There's no instability whatsoever in level flight, at least relative to other planes. The issue is that the large surface area of the engine nacelles is far forward of the plane's CoM. The effect of this is that the control stick becomes 'lighter' as you approach high AoA. This is considered acceptable - though not ideal - in many aircraft, but would have changed the pilot rating requirements from the old 737s.
Some people seem to be suggesting that this is some sort of advanced stability system; the reality is that this is just an automated trim adjustment. Clearly it's very important, but the idea that the plane couldn't fly at all without it is absurd.
Per HN guidelines, I don’t usually comment on why I flag, but I flagged this: It’s little more than a recapitulation of the Seattle Times story which was posted and discussed here extensively already.
The 737 Max saga is certainly right in the HN wheelhouse, but it’s becoming difficult to pull signal from noise when so many articles with so little new information are rocketing to the front page daily.
Biggest losers with such incidents is the credibility of US government, government agencies, and institutions. Other countries used to rubber stamp approvals once a US institution had certified something. The nepotism, politicization, and corruption in such institutions is eroding the credibility and creating barriers and preferential treatment US companies and products used to receive worldwide.
FAA, FTC, US Treasury, US military all have lost credibility in recent years.
Sure. The easiest and most direct approach would be a questionnaire along the lines of "an FAA certification improves my confidence in the product (1: strongly disagree, 5: strongly agree)". Then just get every group you care about to regularly answer the survey.
You can also measure indirect effects, like how many agencies rubber stamp standards and certifications by the agency in question.
The interesting question isn't if it's measurable but if somebody measured it and is sharing the data
> - Understated the power of the new flight control system, which was designed to swivel the horizontal tail to push the nose of the plane down to avert a stall. When the planes later entered service, MCAS was capable of moving the tail more than four times farther than was stated in the initial safety analysis document.
> - Failed to account for how the system could reset itself each time a pilot responded, thereby missing the potential impact of the system repeatedly pushing the airplane’s nose downward.
This likely would not have been included in the simulator, right? So, even if pilots had be given more training, it would not have done much good. The system would still be acting different to the training.
Interesting... Are the commercial flight simulators using an actual physics / aerodynamic model with all the components -- or just empirical data and lookup tables / expectations? I suppose in the latter case, behavior is more likely to deviate from reality?
i think in this case there is no '737 MAX' simulator, as the existing 737 simulators were considered identical for flight training.
back to your question, most full fidelity flight simulations use actual models that are validated against flight test data. and in most cases, they run the same software code as is used in the actual air vehicle.
which brings us back to the question..is a 737 MAX the same as other 737's? No.
Should the FDA not approve drug studies funded by pharmaceutical companies? If that were the case, the world would be a far worse place. Of course there are drugs that gain approval that shouldn't, some of which get pulled. I am a patient currently on three psychiatric medications daily, with a history of four major depressions one of which resulted in a nearly successful suicide attempt when I was 29. I am also a 70-year-old retired neurosurgical anesthesiologist with 38 years of experience in academic and private settings. During that time, I published over 100 scientific research papers, many of which reported on the first human trials of experimental drugs later approved for general use in anesthesiology. As such, I had to get approval from our institutional review boards before beginning the studies, which when completed and written up were then anonymously reviewed by three experts before being published in major journals in my field. Even with such rigorous filtering, some fraudulent papers appear, sometimes on a major scale resulting in retractions of hundreds of publications, headlines, and resignation and firing of scientists (though criminal charges are very rare). Patients get harmed and even die as a result of these falsifications. But the balance is still much to the positive side. In the end, we assume that the great majority of people have a moral compass that points toward honesty. Otherwise, our society collapses.
Thanks for sharing your personal experiences, especially your history of depression. It’s not something that most people are willing to speak about because of the social stigmas associated.
The cynic in me thinks that society needs to reward honesty and/or disincentivize dishonesty instead of relying on personal ethics for most matters though.
Being open about my history is WAY easier — and far less likely to bring negative repercussions — now that I'm 70 and retired. My 35-year-old daughter and 67-year old brother wish I'd shut up about it, but I believe that the more open I am, the more good it will do.
As a software engineer having to deal with OPS teams that are reluctant to push new software updates to production because according to them, well, most of the time developers introduce new bugs in new releases, so they rather stick with what they have.
Anyway, I would not want to be the software engineer in charge of the Boeing 737 MAX 8 new update. Imagine what will happen if there is another accident after the software update? Do you think the proposed software solution is enough?
77 comments
[ 3.3 ms ] story [ 160 ms ] threadIf you hava a lot of computerized equipment to help you you depend on the things that work. You want only that malfunctioning part off. Here the problem was that before Lion Air crash nobody but Boeing even new that MCAS existed, let alone turning deadly with the malfunctioning non-redundant sensor.
The best was not even to enter that storm.
The "known" is the problem there. The pilots there were continuously misinformed about the plane speed due to that iced measurement devices. That is what plane "knew" and what the pilots "knew" in the storm.
The autopilot handed over control to human, but then human drove it too high (the "law" here means "mode of operation"):
"The pilot continued making nose-up inputs. The trimmable horizontal stabilizer (THS) moved from three to 13 degrees nose-up in about one minute, and remained in that latter position until the end of the flight."
"A second consequence of the reconfiguration into alternate law was that stall protection no longer operated. Whereas in normal law, the aircraft's flight management computers would have acted to prevent such a high angle of attack, in alternate law this did not happen. (Indeed, the switch into alternate law occurred precisely because the computers, denied reliable speed data, were no longer able to provide such protection—nor many of the other functions expected of normal law).[55] The wings lost lift and the aircraft stalled"
> one of them (the co-pilot, IIRC) didn't realize it
But the co-pilot definitely knew that the autopilot disengaged:
"The first officer, co-pilot in right seat, 32-year-old Pierre-Cédric Bonin"
"At 02:10:05 UTC the autopilot disengaged" ... "As pilot flying, Bonin took control of the aircraft via the side stick priority button and said, "I have the controls.""
But, I'm not sure if the concept of "full manual" is anymore relevant with modern passenger jets. Are they even flyable without any computer intervention or too unstable / have too complex flying charasteristics?
Commercial aircraft are not fighters. They don’t need to be unstable with computers making them flyable. An unstable airliner would be an uncomfortable airliner and hence a commercial disaster.
What has changed is whether or not there is a manual connection between the yoke and the control surfaces. For reasons of cost, that connection has been going away.
In a non-fly by wire air craft though like the 737 max, a full manual mode is basically when you have auto pilot disengaged. There might be a mode you can enable to disable other functions like tail strike prevention/MCAS but I a haven't ever heard of it.
[0] https://hackaday.com/2019/03/14/mcas-and-the-737-when-small-...
The 737 MAX is just not stable in every condition that the old 737 NG was. And it probably goes the other way, there are most likely flight conditions where the 737 MAX is stable but the 737 NG is not.
The difference is that pilots had been trained and have flown the old one for many years and trained to avoid the unstable conditions for the old 737.
*Flight conditions meaning: air speed, AOA, bank angle, total thrust, altitude.
I don't think that's the case. MCAS was added to satisfy a requirement in the airworthiness certifications that requires positive control forces to increase AoA. The lift generated by the engine nacelles caused this to not be the case at high AoA.
None of what has been revealed so far indicates that the pilots had issues related to the symptom, rather they had issues with MCAS. In a way the cure has been worse than the disease.
There is no red button as such (at least as far as Airbus is concerned). The computer decides that something has gone wrong and invokes an alternative law. You'd have to start pulling circuit breakers to manually trigger a reversion.
> Commercial airliners are stable when flying.
This is not necessarily true. All modern airliners have aggressively swept wings. This generally makes them susceptible to dutch roll in some phases of flight. They are fitted with yaw dampers to control this tendency.
The 737 MAX is not. That's why it has the MCAS system in the first place: the engines are too large for the airframe, making the aircraft fundamentally unstable, so they came up with MCAS to try to make it seem stable to the pilots, and then they didn't even bother telling the pilots that this MCAS system even existed.
So when we see capacity increases, fuel efficiency increases, reliability increases... I'd hazard to say that comes with increased complexity.
And at some point, it's more dangerous to let a pilot fly a highly engineered aircraft on full manual than it is to let a team with access to the technical specifications and time generate an approved, stepwise, degradation flowchart for pilots to work through.
In the same way the best solution to an engine timing issue isn't "Work the valve timing by hand" but rather "Degrade to a less efficient but more reliable profile" through to "Degrade to a static profile that keeps the engine operating after multiple failures."
You really don't want to be burdening pilots with more work.
The failure here seems to be in a poorly designed degradation route, not in the idea itself.
My understanding is that there is a button on the stick to disable the autopilot if the pilot just wants to be maneuver. And a circuit breaker to really shut the thing down if there is something wrong, as it happened during the accident.
You don't want to disable everything at once, and put too much cognitive load on the pilot during the worst times. Especially not safety systems like MCAS is supposed to be.
"I think it is unconscionable that a manufacturer, the FAA, and the airlines would have pilots flying an airplane without adequately training, or even providing available resources and sufficient documentation to understand the highly complex systems that differentiate this aircraft from prior models." [1]
Unless you're confident flying that specific model of that particular plane just turning off auto-pilot is really dangerous. Planes aren't all the same, so "knowing how to fly" doesn't really work, especially on take-off and landing where the margin of error is very, very small.
[1] https://www.politico.com/story/2019/03/12/pilots-boeing-737-...
You can't press a button without understanding how it will affect the plane. How do you know the automation is at fault? Maybe there is mechanical damage and the only reason you're in the air is the automation? By the time you understand if the red button can be safely pressed, you understand what is generally causing the problem. So you can disable that specific automated system, which you can do today.
Also, automation is very very rarely at fault, it basically never happens. But accidents are often avoided, and many accidents would have been avoided, if pilots let go of the controls and let the automation and the inherent stability of the airframe return the flight to normal.
I can't think of a single time when that big red button is a good idea.
Boeing just recklessly didn't tell these pilots what to watch out for, what automated systems existed, and to save some money didn't include the basic safety equipment they needed.
I can't really contest that. The pressure to sell it as identical to previous models and skip certification and training steps seems to have played a part on this.
Contrary to what our instincts tell us, automated systems are potentially far saver than humans could ever be: You can take as much time as you need to think of the best reaction in every scenario; they will execute whatever best practice you come up with every single time without needing constant (re-)training, they don't drink, they don't suffer strokes, they don't get tired, etc.
The failures we have seen tend not to involve any errors in judgement by the automated system. Instead, they almost invariably result from faulty sensor input. For the 757 Max, the angle-of-attack sensor seems to have failed, and relying on input from just a single sensor seems catastrophically negligent.
Such failures cannot reliably be avoided by giving humans more control. With a sensor showing a large AOA and the "STALL! STALL!" alarm blaring, a pilot would take the same action MCAS took, at least initially.
For the two recent crashes, the pilots would probably have recovered. But they had the advantage of daylight and clear skies. At night, in bad weather, and even in the best conditions, hundreds of planes have crashed because the pilots suffered some sensory illusion. See, for but one example, https://en.wikipedia.org/wiki/Air_New_Zealand_Flight_901, which crashed into a mountain because the crew mistook it for an ice shelf. Air France 447 (https://en.wikipedia.org/wiki/Air_France_Flight_447#Accident) is even closer to the current crashes. It shows pilots taking manual control of the plane while fatally misjudging its attitude. There are many other examples where pilots get disoriented in, for example, clouds. The typical story is the plane coming out of the cloud inverted without anyone on board having noticed. Our sensory organs aren't equipped to measure complex movements in 3D: you can roll a plane without ever spilling the champagne glasses in first class.
That's why you trust what the instruments say. On both MAX crashes (and AF447) what happened is that the plane was doing things the crew didn't understand. If there were a clear indicator they had more than the usual amount of authority (say, chaining the cockpit lighting color to red) or a clear way to disengage the computer assistance and put the plane in an easy to reason about state, which, I assume, would be useful if the plane is doing something for a reason you don't know about. Like you said, the two MAXes would be saved. AF447 is less clear, but, still, if we find the machines so much more capable, then we should remove the humans altogether (that would probably safe AF447).
This sounds insane. Is there a reasonable explanation?
https://www.seattletimes.com/business/boeing-aerospace/faa-e...
In this case I imagine someone at Boeing knew moving the elevator jack 2.5 degrees based on one sensor was unsafe hence them selling an optional upgrade that made the system safe. That seems kind of criminal.
But to me it currently looks like it's largely a problem of how the different systems interact and how it's communicated to the users aka pilots. That's something one should be able to spot from the flowcharts/blueprints or whatever they have to document system integration.
This was, in my opinion, one of the most disgusting aspects of this whole sordid story. They had to cut back after the Ethiopian crash, but blaming everybody else seems a big part of their DNA.
I read somewhere that the sensor was misreading by 20° and Lion should have noticed.
Should Boeing have shipped the system with a single point of failure by default? Probably not.
Should the FAA have raised questions about that? Probably.
Should Boeing have considered a test case where a pilot didn't know about MCAS? Probably. But we don't know that they didn't. Perhaps they did and their test pilots recovered the plane in time. That would make it a Lion Air training failure.
There's no single point of blame here, but thankfully the airline industry reacts as a whole to incidents like this and takes as many steps as possible to make sure it doesn't happen any more.
Well, how could they train for it, when Boieing conveniently hushed over such a significant change, because it was commercially expedient? Until the Lion Air crash the airlines and their pilots didn't even know that such a system is in place.
According to an AA pilot the entire training consisted of less than an hour presentation on an iPad, in which the new behavior wasn't mentioned at all.
Add to that that Boeing offered a paid upgrade which at least would make pilots aware that the system malfunctions.
This paid upgrade sounds a bit like "Nice plane you have here, would be a shame if it crashes"
No matter how you look at it: Boeing displayed despicable behavior in this whole sorry mess. Behavior which comes back now to bite them badly.
I don't disagree with your reasoning, for what it's worth. I just think there really should be a special place in hell for the Boeing executives who allowed this to happen. Especially after the first crash.
This case being "pilots untrained and unfamiliar with the MCAS system recovering from a catastrophic systems failure / error".
They are at fault no matter what though from straying from their long held principle that the pilot has the final say on control of the aircraft. Inputs from the yoke and throttle levers should always supercede the computer.
From what is reported about the Lion Air crash it sounds like the pilots may not have sorted out what the stabilizer trim was set to and what to do to correct it. Hopefully that is not the case as such a situation would be a glaring problem with pilot competence.
Nobody in either the article or this train of comments has suggested that it was unreasonable to assume pilot error after a single crash. The problem is the oversight process which allowed it to be certified in the first place.
The airline industry isn't responsibly reacting, they're reacting after trying for quite some time to ignore the problem because it's becoming increasingly obvious that they and the FAA have been horrendously negligent, and ignoring it isn't working anymore.
From the article:
> It turns out that the F.A.A., with congressional approval, has “over the years delegated increasing authority to Boeing to take on more of the work of certifying the safety of its own airplanes,”
This ran through Congress. Not that any of them or the bureaucrats at the FAA will face penalty.
If you speak German, this piece in Süddeutsche Zeitung from 2015 is enlightening: https://www.sueddeutsche.de/wirtschaft/zertifizierung-von-au...
(edit): Podcast link if of interest - http://www.private-eye.co.uk/eyeplayer/play-350
So it is not a competency issue, so at best it was mostly capacity related: the FAA didn't have enough resources to certify at the speed Boeing needed. Of course, the fact that you are certifying yourself might also speed things up for other reasons than purely your willingness to allocate more resources.
[0]: https://www.seattletimes.com/business/boeing-aerospace/faile...
This investigation seems to be turning against Boeing. They will survive, but it almost definitely will cost them far more than whatever they saved by cutting corners. There will also be changes to the certification process, and non-US authorities will take a hard look. Any new incident would become an existential risk for Boeing.
It's important to remember that a company like Boeing isn't a single person. People working on the certification process would usually have incentives that differ from the company as a whole: they do not individually reap the benefits of cutting corners, but bear the brunt of any mistakes, including moral responsibility, possible criminal charges, and an end to their careers.
Such schemes are employed in many industries. Usually, corporate structures and cultures prevent the sort of top-down pressure that people imagine being at play here. Threatening your safety engineers (fire marshals, data protection officers, etc) with job loss for doing their job would result in whistleblowers and lawsuits. It will be interesting to see how exactly this failed at Boeing.
The insanity is hidden somewhere here. Peekaboo - there it is..
There is a great deal of goal alignment between airplane designers, large air travel companies and safety regulators.
Only in case of failure is the self-certification process checked for errors, usually by insurance investigators, because they have the most incentives to do so.
The visible examples of public failures investigated by public agencies are the exception, in my understanding.
I honestly don't think there's any other realistic way of doing it properly. The true experts are the ones doing the work.
[0]https://arstechnica.com/information-technology/2019/03/boein...
[1]https://www.bnnbloomberg.ca/boeing-had-too-much-sway-checkin...
It is not realistic for the FAA to do all the work independently, but now it cannot even effectively audit the self-certification.
[0]: https://www.seattletimes.com/business/boeing-aerospace/faile...
For a really striking example of regulatory capture, look no further than the FCC.
One way to make sure that regulatory capture does not happen, is to ensure that money is not part of lobbying. But that's another discussion.
[1] https://en.wikipedia.org/wiki/Regulatory_capture
In that case they won't be swayed so easily by special interests.
There are people willing to work for the good guys for half the money, but not for order of magnitude less.
No redundancy on a system that can control flight. A system that is supposed to help avoid a stall scenario.
That alone is a crazy oversight, let alone differences between safety analysis and actual capabilities.
This stinks of truly awful management - the rules of the sky were written in boood. Ignoring them has shown serious consequences, because we already knew not to do this.
This article doesn't get the point right. From this article it sounds like some optional "helper" system for pilots to avoid stall. Another article got it right, the plane itself is unstable because of big engines if the MCAS is not there to stabilize it. So its not some optional system, that the pilots would switch off when manually controlling the plane, its there for the plane to fly at all.
> So its not some optional system, that the pilots would switch off when manually controlling the plane, its there for the plane to fly at all.
And that fact makes it utterly damning that there is absolutely no redundancy. A single sensor?
It's a critical component. No redundancy on a system that can control flight.
There's no instability whatsoever in level flight, at least relative to other planes. The issue is that the large surface area of the engine nacelles is far forward of the plane's CoM. The effect of this is that the control stick becomes 'lighter' as you approach high AoA. This is considered acceptable - though not ideal - in many aircraft, but would have changed the pilot rating requirements from the old 737s.
Some people seem to be suggesting that this is some sort of advanced stability system; the reality is that this is just an automated trim adjustment. Clearly it's very important, but the idea that the plane couldn't fly at all without it is absurd.
The 737 Max saga is certainly right in the HN wheelhouse, but it’s becoming difficult to pull signal from noise when so many articles with so little new information are rocketing to the front page daily.
FAA, FTC, US Treasury, US military all have lost credibility in recent years.
You can also measure indirect effects, like how many agencies rubber stamp standards and certifications by the agency in question.
The interesting question isn't if it's measurable but if somebody measured it and is sharing the data
> - Failed to account for how the system could reset itself each time a pilot responded, thereby missing the potential impact of the system repeatedly pushing the airplane’s nose downward.
This likely would not have been included in the simulator, right? So, even if pilots had be given more training, it would not have done much good. The system would still be acting different to the training.
https://en.wikipedia.org/wiki/X-Plane_(simulator)#Flight_mod...
back to your question, most full fidelity flight simulations use actual models that are validated against flight test data. and in most cases, they run the same software code as is used in the actual air vehicle.
which brings us back to the question..is a 737 MAX the same as other 737's? No.
The cynic in me thinks that society needs to reward honesty and/or disincentivize dishonesty instead of relying on personal ethics for most matters though.
Anyway, I would not want to be the software engineer in charge of the Boeing 737 MAX 8 new update. Imagine what will happen if there is another accident after the software update? Do you think the proposed software solution is enough?