Live data from Hacker News

USS McCain collision ultimately caused by UI confusion

arstechnica.co.uk

101–110 of 369 posts

Re: USS McCain collision ultimately caused by UI confusion

#101

A key occurrence during this mishap: 0127 The Officer of the Deck ordered course to the right to course 240T, but rescinded the order within a minute. Instead, the Officer of the Deck ordered an increase to full speed and a rapid turn to the left (port). These orders were not carried out. 0129 The Bosun Mate of the Watch, a more senior supervisor on the bridge, took over the helm and executed the orders. I've witness…

Yep, but that freeze is limited with more training, and mixed watches when teh newbs have to be rotated in for the real thing so the "hold my beer" guys aren't outnumbered 10 to 1 by the frozen folks.

Re: USS McCain collision ultimately caused by UI confusion

#102

Earlier quoted context omitted.

I believe the warning can change depending on which of the 3 flight modes the aircraft is in at the time. Big contribution to AF447's demise was that the aircraft was in 'alternate flight' mode and the crew assumed it was still in 'normal flight' mode and made a lot of their judgement calls accordingly. For an industry that is so safety conscious, I believe this is a huge flaw in disaster control. To put it in contex…

I'd argue it's more like getting dropped into single user mode. No friendly GUI, but the underlying systems are the same. The flaw with any sort of safety net is that you get used to it and forget the basics of aviation. The big problem was that the pilot-in-command simply forgot (or did not know) how to fly the plane. He overcorrected in reaction to turbulence and the rest is history. Normal law does not allow the p…

QF32 had 5 (!) rated pilots in the cockpit and managed to communicate and delegate effectively. That's truly an amazing accomplishment.

Re: USS McCain collision ultimately caused by UI confusion

#103
Militaries are good at making horrible UI. :-) I used to work at early warning radar, that should notify our tops about incoming ICBMs. When there's a target, classified as "suspicious" or "something that's going to fall onto {our, neighbour} territory", the following happens: - very loud sine 1200Hz tone starts sounding - the only output device, "fast-printing device", starts dumping hexdumps of internal structures to long 10cm wide paper (like toilet paper). - the whole chain of command start yelling to each other (downwards), demanding data and info about the target.

So as the last person in that food chain, you're in the middle of panic, 1200Hz are drilling into your brain, damned thing prints hexdumps, and you need to apply binary shifts and ANDs, convert from floating point hex to decimals and pray that there's enough paper in damned FPD.

I could never imagine worse UI, it's strange that we didn't start WW3 in those conditions.

Re: USS McCain collision ultimately caused by UI confusion

#104
post #77

Earlier quoted context omitted.

In the steam days, it was a major operation to adjust the output of an engine. Valve linkages had immediate effect on the output, but you also had to adjust the boiler heat input to keep the temperature within limits. Far enough back, there were men shoveling coal into the boilers who had to be told to slow down or speed up. Do you think it's mainly bureaucratic inertia that keeps it separate? Or is there something m…

> Valve linkages had immediate effect on the output, but you also had to adjust the boiler heat input to keep the temperature within limits. Can you not vent some of the steam, so the same volume of steam is being produced and the temperature the same but only some of it goes to the drive?

This would mean wasting fuel, no?

Re: USS McCain collision ultimately caused by UI confusion

#105
post #73

There was a ferry accident involving a similar transfer of control problem in New York harbor.[1] Ferries have a lot of maneuvering modes and directional thrusters, because they do so many dockings, and so they have a more complex control problem. The pilot put the system into a backup dumb mode while in cruise, then changed stations to where he could best see the dock while still in the wrong mode. Rammed the dock a…

I would be interested in seeing additional sources that support the theory that political machinations, not practical concerns, decided how many pilots a modern warship requires.

The Apache Attack Helicopter is renowned for being especially difficult to fly [1], and I wonder if Navy wished to avoid having a similarly single, not-so-easily-replaced bottleneck.

[1] https://www.airspacemag.com/daily-planet/hardest-to-fly-8713...

Re: USS McCain collision ultimately caused by UI confusion

#106
It's not just boats that have safety-critical UI design problems. The avionics in airplanes are becoming so complicated that managing the avionics is almost more difficult than flying the plane.

I'm a private pilot who has been flying a Cirrus SR22 for twelve years. In that time it has gone through two major glass cockpit avionics revisions. In the first revision, called the Avidyne, the autopilot was either on or off. In the current revision, called the G-1000, the autopilot can operate in two modes: AP mode, where the autopilot is actually flying the plane, and FD or flight-director mode, where the autopilot does all of the calculations to figure out where the plane should be flying and displays a target on the primary flight display, but the actual control of the plane is still in the hands of the pilot.

If the plane is stable, it is very easy to get fooled into thinking the autopilot is flying the plane when in fact it is not. There are only two visual indicators that tell you if the autopilot is actually flying the plane: a small green LED on the autopilot console, which is down near your right knee, and another small annunciator on the primary flight display. It looks like this:

http://is3.mzstatic.com/image/thumb/Purple71/v4/9a/36/ad/9a3...

The autopilot indicator is indicating AP mode in that image. See if you can spot it.

It has happened to me more than once that I thought I had the autopilot engaged when in fact I had only turned on the flight director. I predict that one of these days someone will die because they made this mistake in instrument conditions.

Re: USS McCain collision ultimately caused by UI confusion

#107
post #104

Earlier quoted context omitted.

> Valve linkages had immediate effect on the output, but you also had to adjust the boiler heat input to keep the temperature within limits. Can you not vent some of the steam, so the same volume of steam is being produced and the temperature the same but only some of it goes to the drive?

This would mean wasting fuel, no?

What's that got to do with anything?

The comment was about the ability to vary power at all, not doing it efficiently.

Are you going to choose to crash into something because it's wasting fuel to vent part of the steam?

Re: USS McCain collision ultimately caused by UI confusion

#108
post #73

There was a ferry accident involving a similar transfer of control problem in New York harbor.[1] Ferries have a lot of maneuvering modes and directional thrusters, because they do so many dockings, and so they have a more complex control problem. The pilot put the system into a backup dumb mode while in cruise, then changed stations to where he could best see the dock while still in the wrong mode. Rammed the dock a…

It makes some sense to me. Conning officer instructs helmsman which direction to go. Helmsman then executes that and monitors/adjusts to stay on that heading without further attention. Same for speed. The officer is then free of the tasks of monitoring and adjusting speed and direction and can focus on what's happening outside of that.

Re: USS McCain collision ultimately caused by UI confusion

#109
post #77

Earlier quoted context omitted.

In the steam days, it was a major operation to adjust the output of an engine. Valve linkages had immediate effect on the output, but you also had to adjust the boiler heat input to keep the temperature within limits. Far enough back, there were men shoveling coal into the boilers who had to be told to slow down or speed up. Do you think it's mainly bureaucratic inertia that keeps it separate? Or is there something m…

> Valve linkages had immediate effect on the output, but you also had to adjust the boiler heat input to keep the temperature within limits. Can you not vent some of the steam, so the same volume of steam is being produced and the temperature the same but only some of it goes to the drive?

I think their point is that when changing engine output is labor-intensive, it made perfect sense to have an officer giving orders and somebody else implementing them. Why the command structure hasn't shifted to accommodate modern technology is an interesting question

Re: USS McCain collision ultimately caused by UI confusion

#110
post #3

Amazing that someone would design in multiple steering wheels, only one of which is active, and no big indicator to make it super-obvious which one it is. Also amazing that there's a mode where moving a control sometimes controls all engines, sometimes just one.

I can imagine the requirements doc that led to that, where some Pentagon wonk was thinking "What happens if the helmsman is shot? If there's engine damage? If the helmsman is shot and there's engine damage?" and wrote all of those cases in, and completely forgot about the case where the bridge crew gets super confused because they triggered an edge case in the software and have no idea how to regain control of the sh…

Well, it's a warship. In their defense, they really have to plan for people dying and part of the ship being destroyed.
Post reply on HN