Live data from Hacker News

USS McCain collision ultimately caused by UI confusion

arstechnica.co.uk

71–80 of 369 posts

Re: USS McCain collision ultimately caused by UI confusion

#71
post #70
post #24

Earlier quoted context omitted.

The path to a disaster has been compared to a tunnel [0]. You can escape from the tunnel at many points, but you may not realize it. Trying to find the 'real cause' is a fool's errand, because there are many places and ways to avoid the outcome. I do take your meaning, reducing speed and following well established rules would have almost certainly have saved them. 0. PDF: http://www.leonardo-in-flight.nl/PDF/FieldGui…

Are you recommending the 2nd edition specifically? There is a 3rd edition available: https://www.amazon.com/Field-Guide-Understanding-Human-Error...

No, I just didn't notice (speaking of confusing UI, Amazon seems to do everything possible to move UI elements small and large on a basis so arbitrary as to seem completely random)

Re: USS McCain collision ultimately caused by UI confusion

#72
post #63

Everyone in the chain of command in 7th fleet (from ADM Smith on down through the captains and those standing watch) should have been separated and potentially prosecuted for negligence. UI confusion would be an excuse for an untrained civilian being put on the bridge and told to run the ship, but not for professionals, and obviously many systems failed for this to happen. When the military runs well, it runs on acco…

From what I hear the Navy has been very diligent about accountability. There are problems you can't really hard-ass yourself out of.

Re: USS McCain collision ultimately caused by UI confusion

#73
There was a ferry accident involving a similar transfer of control problem in New York harbor.[1] Ferries have a lot of maneuvering modes and directional thrusters, because they do so many dockings, and so they have a more complex control problem. The pilot put the system into a backup dumb mode while in cruise, then changed stations to where he could best see the dock while still in the wrong mode. Rammed the dock at 12 knots. 79 injured, 4 seriously.

This is bad design. All the controls that can steer the ship should be tied together and move together. How to do that was figured out decades ago.

The Navy still has this thing where they hate to give control of both speed and steering to the same person. The helmsman and engine room take orders from the officer that has the conn. But that officer doesn't actually operate the controls. Some enlisted sailors do. This dates from the age of sail and steam. Merchant shipping gave this up decades ago.

Back in the 1950s, the U.S. Navy built the USS Albacore. This was an experimental submarine to test out the teardrop-hull concept. It wasn't nuclear; it was just a test vehicle to see how such a hull form handled. It was expected to be more maneuverable than previous designs, so it was set up with aircraft-like controls. One person sat in the pilot's seat, strapped in facing forward, looking at aircraft-type instruments, and controlled all the maneuvering controls. It was a very agile craft.

The brass hated it. The person in the pilot's seat was really the one in charge. The officers were just back-seat drivers. To this day, the Navy sets up nuclear submarines so that different people steer, control power, and control buoyancy.

(The British in WWII tried to control aircraft with multiple people. As bombers got bigger, they wanted to put a senior officer in charge, but younger people were better pilots. So they had an "aircraft commander" back-seat driving, as well as a pilot handling the controls. This did not work out at all and was rapidly dropped.)

[1] https://www.ntsb.gov/news/press-releases/Pages/PR20140408c.a...

Re: USS McCain collision ultimately caused by UI confusion

#74
post #65
post #55

Earlier quoted context omitted.

I believe this is the official transcript: https://www.bea.aero/uploads/tx_elyextendttnews/annexe.01_04... I see that the first link I posted doesn't contain everything, but I don't see any major omissions either. At 2:11:37.5, Robert takes control of the plane. According to the report, he pushed the stick to the left twice. Bonin then took back control. Figure 69 on page 96 of the report you linked shows Bonin's pit…

Figure 69 shows Bonin's stick inputs before Robert took control (and a few seconds after). As explained on p. 182 of the report, Robert pressed the override switch at this point and took control, so Bonin's stick inputs would have been ignored. Bonin then took back control by himself pressing the override switch. In effect, then, at this late stage, the pilots were fighting over the stick. If it had been a physical f…

There's a big difference between unknowingly fighting over the controls and knowingly fighting over the controls. If Robert had realized that Bonin was making the completely wrong control input then maybe he would have put a stop to it somehow. "Stop that, you'll get us all killed" is likely to be effective. He could have told the captain about it as soon as the captain arrived, rather than just before impact. Note that when the incorrect input was finally identified by someone other than Bonin, it was corrected immediately, it was just far too late.

According to the report, ~20 seconds after the events I described above, the plane was still above 30,000ft and recovery was still possible. Yes, the problem developed before this, but it sure looks to me that the bad control design was a major factor in the failure to correct the problem.

Re: USS McCain collision ultimately caused by UI confusion

#76
post #17

The real cause of the collision was poor seamanship and failure to follow the COLREGS on the part of the bridge crew of the destroyer. Most specifically they were seriously in violation of Rule 6: the Safe Speed Rule http://navruleshandbook.com/Rule6.html Every vessel shall at all times proceed at a safe speed so that she can take proper and effective action to avoid collision and be stopped within a distance appropr…

A number of the worlds largest ferries - 50% longer than USS McCain - are routinely navigating in very restricted and crowded waters in the archipelagos of Stockholm and Helsinki with a clearing under the keel of just a few meters.

They seem to manage avoid colliding with both commercial traffic and the numerous sailing yachts while doing 18-20 kn.

Accidents have happened, but it's not recurring events. One exception in the Baltic see is the Polish M/S Jan Heweliusz, that was involved in a number of of accidents, until it finally capsized in hard weather.

Re: USS McCain collision ultimately caused by UI confusion

#77
post #73

There was a ferry accident involving a similar transfer of control problem in New York harbor.[1] Ferries have a lot of maneuvering modes and directional thrusters, because they do so many dockings, and so they have a more complex control problem. The pilot put the system into a backup dumb mode while in cruise, then changed stations to where he could best see the dock while still in the wrong mode. Rammed the dock a…

In the steam days, it was a major operation to adjust the output of an engine. Valve linkages had immediate effect on the output, but you also had to adjust the boiler heat input to keep the temperature within limits. Far enough back, there were men shoveling coal into the boilers who had to be told to slow down or speed up.

Do you think it's mainly bureaucratic inertia that keeps it separate? Or is there something more complicated about controlling engine power than I imagine?

Re: USS McCain collision ultimately caused by UI confusion

#78

Earlier quoted context omitted.

> > Amazing that someone would design in multiple steering wheels, only one of which is active, and no big indicator to make it super-obvious which one it is. > Decent odds you've flown on an airplane with a similar UX for primary flight controls. Ah, well Airbus does a few things. 1.) A "dual input" warning is issued if there is an attempt at using both controls simultaneously. 2.) There are lights to indicate when…

I believe the warning can change depending on which of the 3 flight modes the aircraft is in at the time. Big contribution to AF447's demise was that the aircraft was in 'alternate flight' mode and the crew assumed it was still in 'normal flight' mode and made a lot of their judgement calls accordingly. For an industry that is so safety conscious, I believe this is a huge flaw in disaster control. To put it in contex…

I'd argue it's more like getting dropped into single user mode. No friendly GUI, but the underlying systems are the same. The flaw with any sort of safety net is that you get used to it and forget the basics of aviation.

The big problem was that the pilot-in-command simply forgot (or did not know) how to fly the plane. He overcorrected in reaction to turbulence and the rest is history. Normal law does not allow the pilot to set an angle of attack that would lead to a stall. In the alternate law modes this protection is not there and so when the PIC didn't adhere to the rule of "don't pull up while in a stall" there was no safety net to prevent him from exacerbating the situation. In fact he kept pulling back when the stall alarm went off.

A better UI would not have solved the self-inflicted problems. From the findings sections in the wiki entry:

- The pilots apparently did not notice that the aircraft had reached its maximum permissible altitude

- The pilots did not read out the available data (vertical velocity, altitude, etc.)

- the crew made inappropriate control inputs that destabilized the flight path;

- the crew failed to follow appropriate procedure for loss of displayed airspeed information;

- the crew lacked understanding of the approach to stall

- the crew lacked practical training in manually handling the aircraft both at high altitude and in the event of anomalies of speed indication

- the two co-pilots' task sharing was weakened both by incomprehension of the situation at the time of autopilot disconnection, and by poor management of the "startle effect", leaving them in an emotionally charged situation

- the crew did not respond to the stall warning

A better cockpit may have given the pilots a better chance of surviving but definitely wouldn't have guaranteed a better outcome. One only needs to look at Asiana to see that even Boeing, with their contrasting approach to UX, can't save pilots who lack basic airmanship. My understanding is that most long-haul pilots will fly a fairly small number of segments each month, and that most of those segments are going to involve a huge amount of time spent in the middle of nowhere with autopilot on. This leads to atrophying of skills needed to manually fly a plane.

Conversely, one only need to look at Qantas' QF32 incident to see that good airmanship can absolutely make catastrophic failure survivable. Yes, there is a lot of information to process in an emergency... but the Qantas crew took that information and delegated appropriately. The Air France pilots lost their cool and fucked up.

Re: USS McCain collision ultimately caused by UI confusion

#79
post #73

There was a ferry accident involving a similar transfer of control problem in New York harbor.[1] Ferries have a lot of maneuvering modes and directional thrusters, because they do so many dockings, and so they have a more complex control problem. The pilot put the system into a backup dumb mode while in cruise, then changed stations to where he could best see the dock while still in the wrong mode. Rammed the dock a…

[deleted]

Re: USS McCain collision ultimately caused by UI confusion

#80
> The report found that the McCain did not have the right type of watch on duty for navigation in congested waters and that watchstanders' training was insufficient. But there was never a warning signal from the Alnic of impending collision or a change of course by the merchant in an effort to avoid the collision. "Despite their close proximity, neither JOHN S MCCAIN nor ALNIC sounded the five short blasts of whistle required by the International Rules of the Nautical Road for warning one another of danger," investigators found, "and neither attempted to make contact through Bridge to Bridge communications."

What a comedy of errors.

Post reply on HN