Live data from Hacker News

Behind the Lion Air Crash, a Trail of Decisions Kept Pilots in the Dark

nytimes.com

61–70 of 83 posts

Re: Behind the Lion Air Crash, a Trail of Decisions Kept Pilots in the Dark

#61

Earlier quoted context omitted.

Yes, there should definitely be visual and auditory warnings as well when MCAS is engaged. When the autopilot is doing something so important as struggling to prevent a stall (and in its mind, failing, because of the faulty AoA sensor), it definitely needs to be raising alarms. Also, given how important the AoA data apparently is, it may not be displayed prominently enough. In clear weather, level flight flying, it s…

When anything in a 737 moves the stabilizers, physical wheels in the cockpit loudly turn right next to the pilots. In the case of a stabilizer runaway, it's really obvious. (See https://www.youtube.com/watch?v=3pPRuFHR1co&t=154 ) MCAS is just one of many different systems on a 737 that can automatically adjust the stabilizer. Because there are so many things that could be the cause of the problem, the checklist proce…

Thanks. So that blaring and the wheels turning is what we assume happened 24 times in that cockpit before the crash?

If I understand this right the pilots must have known the plane did adjust stabilizers, but they didn't have a way of finding out why it did it. And per checklist they shouldn't have cared for the why, but just cut-out the automatic control.

Re: Behind the Lion Air Crash, a Trail of Decisions Kept Pilots in the Dark

#62

Boeing should face some major fines for this, and additional regulation is going to be needed to make sure this doesn't happen in the future. This all seems to come down to the fact they wanted to avoid having to retrain pilots ($$$), so these automation changes were kept in the dark. The crew before them dealt with this same problem but they successfully cut out the trim system. They got lucky and they should have b…

From what I can tell, the previous crew did not get lucky, they just followed the checklist which would have solved the issue in this case.

Auto-trim beyond the elevator authority is not a problem as the pilots can take manual control of the trim by grabbing the trim wheel (its in a very obvious spot on the 737).

The actual fix is hard as adding another alarm can get tricky from a UX perspective during an emergency. Probably the only “fix” is to reinforce the value of following the checklist.

Re: Behind the Lion Air Crash, a Trail of Decisions Kept Pilots in the Dark

#63
When we first heard this crash was due to a change in computer-controlled stabilizer behaviour, my question was "why on earth did Boeing do this?". Perhaps I didn't read deep enough, but the summary explanation that it was to improve handling was a poor answer.

I guess what really bugged me about it is how un-Boeing-like this behaviour was; a computer overriding a pilot (even if there is a way for a pilot to override it in turn). It's fundamentally an Airbus-esque design.

As I read this article though, everything fell into place. As you read it you start to see, with utter clarity, exactly how this happened organizationally.

It's well known that Airbus uses software flight envelope protection to enable them to reduce the safety margin applied to the airframe, reducing weight. In other words, fuel efficiency is improved by making airframes less airworthy and compensating for it in software. I don't actually disagree with this as such; it's been demonstrated to be a sound approach, but historically Airbus's domain.

Essentially, it seems like what happened here is that Boeing finally felt the need to adopt similar techniques to compete with Airbus on fuel efficiency (though regarding engine size issues, not airframe safety margins, but still making a plane's airworthiness more caveated and fixing it in software). Essentially, we're witnessing the point at which Boeing feels its traditional user interface philosophy (do what the pilot says) is conflicting with market pressures.

If this were a new plane with a new type rating, this wouldn't be unreasonable. Trying to tack this on to an existing plane, and not only that, but doing everything in your power to minimise the amount of transition training, is OTOH extraordinarily egregious.

The problem with this change isn't so much that Boeing's reasoning for not telling pilots about it isn't logical. If anything, the problem is that their reasoning is utterly logical: the checklist will solve the problem anyway, no matter the cause. You can see how this decision must have percolated through different teams at Boeing, through regulators, via this unimpeachable-seeming logic. The market pressures involved (fuel efficiency and retraining costs) would have made it particularly hard to contest. It's a completely logical line of reasoning... yet here we are with fatalities.

I'm very interested to note, though, this new revelation (to me at least) that the yoke behaviour re: extreme deflection mitigating stabilizer runaway was removed in the MAX. So what was Boeing's justification for this change? Was it even mentioned? If not, what on earth were the regulator's justifications for allowing it to go unmentioned? I want to hear those justifications, since it seems impossible to justify. I was under the impression that compatibility of type ratings fundamentally revolved around an absence of differences in how two planes handle, and how they respond to the yoke.

I should add, the reliance on a single sensor is also remarkable; makes me wonder if this entire subsystem was really rushed and not given proper design review, which would make sense given the circumstances (panicking to get a product to market).

Re: Behind the Lion Air Crash, a Trail of Decisions Kept Pilots in the Dark

#64
post #26
post #8

Earlier quoted context omitted.

To use a car analogy ... You can always override cruise control by stomping hard on the brake (like to avoid an imminent crash). That's how it's always worked and you've gotten used to this, and done it on occasion when warranted. Now imagine that the next generation of adaptive cruise-control/"auto-pilot"/whatever comes out, and stomping on the brakes no longer does anything. You have to first disable the cruise con…

I do not think this is a good analogy. Firstly, there is no single equivalent to "slamming on the brakes" for uncommanded nose-down. This could be caused by a variety of faults, and pilots are trained to respond in a fashion that will be effective for even those in which the first thing to try doesn't work. There is a standard procedure in place to use in this type of situation - arguing that the pilots should only b…

>your argument essentially hinges on the assumption that pulling hard back on the stick is a sufficient solution for all the problems that may happen with a plane with the exception of a fault with MCAS (the new system).

I don't read it that way. To me, it's specifically based on removal (without notice to pilots) of a function that would absolutely have terminated a trim runaway condition.

In other words, Boeing eliminated one well-known and trained-on trim runaway fix, and didn't tell the pilots. This is different from saying that stick pullback is a universal solution.

Re: Behind the Lion Air Crash, a Trail of Decisions Kept Pilots in the Dark

#65
post #53

Earlier quoted context omitted.

Yes, there should definitely be visual and auditory warnings as well when MCAS is engaged. When the autopilot is doing something so important as struggling to prevent a stall (and in its mind, failing, because of the faulty AoA sensor), it definitely needs to be raising alarms. Also, given how important the AoA data apparently is, it may not be displayed prominently enough. In clear weather, level flight flying, it s…

Southwest has added enhanced AOA indicators to its Max fleet as a result [0]. Lion Air didn't even have the basic (optional) AOA Disagree alert[1] [0] https://theaircurrent.com/aviation-safety/southwest-airlines... [1] https://www.reuters.com/article/us-indonesia-crash-boeing-ao...

It makes you wonder why such a seemingly important alert is optional. Cars these days can't come without seat belts, brakes, ABS, traction control, ESC, and more, but apparently seemingly essential safety features on planes are optional??

Re: Behind the Lion Air Crash, a Trail of Decisions Kept Pilots in the Dark

#66
post #8
post #6

Earlier quoted context omitted.

One interface change was the effect of 'pulling hard back on the stick' in case of runaway stabilizers. That worked with the old system, but not with MCAS. This seems to be exactly the interface change that lead to the crash.

To use a car analogy ... You can always override cruise control by stomping hard on the brake (like to avoid an imminent crash). That's how it's always worked and you've gotten used to this, and done it on occasion when warranted. Now imagine that the next generation of adaptive cruise-control/"auto-pilot"/whatever comes out, and stomping on the brakes no longer does anything. You have to first disable the cruise con…

Or that the system fights your stomping hard on the brake by accelerating. In the Lion Air crash, the system fought the pilots by aggressively nosing down. That it was doing this because of faulty sensor data, is different than how other 737's behave in the same situation.

Re: Behind the Lion Air Crash, a Trail of Decisions Kept Pilots in the Dark

#67
post #41
post #37

Earlier quoted context omitted.

The point is that their response may have worked for this particular fault, but would not have worked in general. There is a reason that there are more procedures than "pull back on the stick" - pilots do not know what the fault is. > they developed an unconscious/intuitive mental model of the plane If the plane has a fault, it's frequently not going to behave like their unconscious model says it should. In the happy…

> Take it up with the FAA and the airlines? Sure. It's not just Boeings fault. I believe the FAA will course correct from this and probably all changes to flight controls will need to be reported to pilots. More lessons written in blood.

It's still more Boeing's fault than anyone else's though. They were the ones who made this change and then tried to hide it to the fullest extent possible, so that it wouldn't trigger mandatory retraining.

Re: Behind the Lion Air Crash, a Trail of Decisions Kept Pilots in the Dark

#68

Earlier quoted context omitted.

> That's how it's always worked and you've gotten used to this but still, instead of going trough the full checklist they stopped and tried repeatedly whatever fixed the issue in the past/on the simulator. a more complete analogy: "follow these ten step do diagnose a bug on the software" "but last time it was just a compilation flag, I'll check the compilation flags" "bug persists" "last time it was just a compilatio…

From what I understand, part of the problem was that it helped temporarily... and then the system pointed the nose down again.

yeah I'm not siding with Boing here, what I'm saying is that pilots are given checklists for a reason, and going by the usual hunches instead of following the checklist as they were supposed to is as much a failure in training as is a failure in the plane user interface.

Re: Behind the Lion Air Crash, a Trail of Decisions Kept Pilots in the Dark

#69
post #40

Earlier quoted context omitted.

Why was a method that wasn't in the official checklist "relied upon"? Pilots following some undocumented, non-standard procedure sounds like their fault rather than Boeing's.

Who knows? Have you ever been taught an undocumented procedure by the expert and been told to use it regardless of what the manual states? Happens all the time? Is a pilot in a position to affect Boeing beauracracy?

Sorry but how could Boeing design any plane if they can't assume pilots will follow the manual or any checklists?

Re: Behind the Lion Air Crash, a Trail of Decisions Kept Pilots in the Dark

#70
post #26
post #8

Earlier quoted context omitted.

To use a car analogy ... You can always override cruise control by stomping hard on the brake (like to avoid an imminent crash). That's how it's always worked and you've gotten used to this, and done it on occasion when warranted. Now imagine that the next generation of adaptive cruise-control/"auto-pilot"/whatever comes out, and stomping on the brakes no longer does anything. You have to first disable the cruise con…

I do not think this is a good analogy. Firstly, there is no single equivalent to "slamming on the brakes" for uncommanded nose-down. This could be caused by a variety of faults, and pilots are trained to respond in a fashion that will be effective for even those in which the first thing to try doesn't work. There is a standard procedure in place to use in this type of situation - arguing that the pilots should only b…

I strongly agree. I've read most of the other comments here, and as an armature pilot myself, I think most of the responses to you are missing the point.

Its extremely unfortunate, but these pilots had ~10 minutes of flight time between their request to return to the airport noting aircraft control issues, and their crash, during which they completely failed to follow their checklists. Lion Air put those under-trained (if we're being generous) pilots into that cockpit and they are the only ones who carry responsibility for this crash.

Its anecdotal, but most of my older flight instructors have been lamenting the loss of critical pilot skills in the industry, and this appears to be just another example of that.

Post reply on HN