Live data from Hacker News

Lack of redundancies on Boeing 737 MAX baffles some involved in developing it

seattletimes.com

61–70 of 163 posts

Re: Lack of redundancies on Boeing 737 MAX baffles some involved in developing it

#61
I am a designer and implementor of vital speed and distance measurement systems, with triply modular redundancy, used in mass transit application.

I cannot even imagine what the designers of this thing are going through now. It must be terrible.

To make it worse, it's a confusing topic. There are two pillars to the design of such system.

1. Faulty sensor must be detected with a very high probability. The typical way to achieve that is redundancy and diversification. The exact amount of redundancy depends on the reliability of the sensor considered. In most cases, it is sufficient to have 2 sensors, but of different models, in order to avoid common mode of failure.

2. In case of a failure, the system must have a graceful degradation, and in aeronautics, this means a clean handover to the pilot.

So, in the case of this MCAS thing, having two sensors is not necessarily a bad thing, and what M. Kornecki reports is 100% correct. What looks strange is the way a single failure was managed by the software, and how the procedure to recover was quite complicated and, even worse, not exported to the training material of the pilots. In my world, we called this "exported safety requirement application conditions" - SRACs, and verification of their proper allocation is a big chunk of the safety case. More than discussing architecture, in my view, the investigation must explain why the organisation failed to perform this activity.

The case for a third sensor can be made to decrease the likelihood of having to bypass the system ("belt and suspenders", as says M. Kornacki), but based on my experience, it will not be sufficient. As other correctly report here, it's not a silver bullet.

Ultimately, the degradation scenario and pilot handover is part of the overall system safety.

Re: Lack of redundancies on Boeing 737 MAX baffles some involved in developing it

#62
post #51

Earlier quoted context omitted.

He may be right for the state of what has actually been wired up in today’s cockpits, but conceptually I don’t see why you couldn’t fully automate a plane. Even in emergency situations, pilots are required to follow established procedures and check lists, not become creative. The pilot mentions the example of an aborted take off, I can’t think of any reason an auto pilot wouldn’t be able to perform one. And of course…

IMO pilots are there in case shit really hits the fan, or birds hit the turbofans: I doubt computers would be creative enough like Sullenberger and decide to land on a river. And 2 pilots means 2 brains that can divide the workload...

Fair point, but even then you could have a remote pilot telling the plane what to do with the automation executing the strategy (given the latency).

Re: Lack of redundancies on Boeing 737 MAX baffles some involved in developing it

#63
I'm gonna take a punt on the root cause of this mess: cost cutting / bonus seeking managerialisim. In my experience people high up in the decision chain with no technical expertise often have blind faith in what "technology" can accomplish.

Re: Lack of redundancies on Boeing 737 MAX baffles some involved in developing it

#64
post #20
post #2

Despite the headline, the article ends with: That triple-sensor system isn’t foolproof, however. In 2008, on a customer-acceptance flight of an Airbus A320, two of the angle-of-attack sensors froze and those two sensors then outvoted the third. When the pilots went to demonstrate the stall-prevention system, they were not aware of the malfunctioning sensors. The plane crashed, killing the seven people on board. The s…

Yep, 3 sensors can fail too. Less often however. These sensors exist to solve a problem with the MAX design. Changing and moving the engines increased the likelihood of a stall when the engines could push the nose up (as I understand it). Fine. But here's the kicker: this should be something that pilots should be trained on. They should be aware of how the MAX is different to the previous 737s and know what to do to…

The pilots were trained on how to deal with a runaway trim stabiliser. The procedure hasn't changed from the old 737, the only thing that has changed is that it is that the failure mode is more likely to occurr on the 737 MAX.

From the article: “A properly trained pilot should be able to solve an MCAS anomaly or any uncommanded flight-control input through procedures that are taught to all 737 pilots,” said Menza, noting that the emergency information Boeing distributed in December reiterated those procedures.

Here's a video of a competent 737 pilot showing those exact procedures: https://www.youtube.com/watch?v=xixM_cwSLcQ

Obviously the MCAS system is badly designed, but any automation system can fail and pilots need to know how to deal with it.

Re: Lack of redundancies on Boeing 737 MAX baffles some involved in developing it

#65
post #47

Earlier quoted context omitted.

I am puzzled by the apparent lack of a "this plane is heading straight into the ground" sensor that should have overridden the MCAS.

The MCAS is designed to prevent an aerodynamic stall; a situation where the plane is pointed too far up and as a result starts heading straight for the ground. It does do by detecting the plane pointing too far up, and pushing it back down. If it did not function when the plane was descending rapidly it would not be fit for its designed purpose.

[deleted]

Re: Lack of redundancies on Boeing 737 MAX baffles some involved in developing it

#66
From the information that keeps leaking out it appears the 737 MAX has some serious design faults.

What is going to interesting is to see how quickly the FAA certifies the new software changes this second time around.

The current perception would be the FAA was too quick to certifying the original MCAS as being safe.

I suspect the second time around that certification process is going to take a lot more time and effort and is going to be much harder to achieve.

And the final nail in the 737 MAX coffin might be that even when that certification arrives, Boeing then needs to convince paying passenger that is now safe to climb on board the aircraft.

Re: Lack of redundancies on Boeing 737 MAX baffles some involved in developing it

#67
post #20
post #2

Despite the headline, the article ends with: That triple-sensor system isn’t foolproof, however. In 2008, on a customer-acceptance flight of an Airbus A320, two of the angle-of-attack sensors froze and those two sensors then outvoted the third. When the pilots went to demonstrate the stall-prevention system, they were not aware of the malfunctioning sensors. The plane crashed, killing the seven people on board. The s…

Yep, 3 sensors can fail too. Less often however. These sensors exist to solve a problem with the MAX design. Changing and moving the engines increased the likelihood of a stall when the engines could push the nose up (as I understand it). Fine. But here's the kicker: this should be something that pilots should be trained on. They should be aware of how the MAX is different to the previous 737s and know what to do to…

If all three AoA sensors are mounted to the side, they're likely to freeze at the same pitch if they do freeze. So unless you have multiple different ways to measuring AoA three sensors do not protect against this failure mode better than two does.

Re: Lack of redundancies on Boeing 737 MAX baffles some involved in developing it

#68

What I fail to understand is why do they not design an overriding scheme to MCAS, such as an "above-threshold" pull on the stick by the pilot. I can recall that this was a classic design by Boeing. Whatever the number of AoA sensors, the system should be easy and straightforward to disable. Those logics of "let's guess automatically if that sensor is failing" are just pushing the problem further. The real problem is…

The airline manufacturers have to push for automatic systems as they are the one of the features that sells. One of a close friend of mine who works at Airbus said that the company believes the next gen aircrafts would only require a single person in the cockpit, and everything will be handled through automations. Airbus aircrafts are more automated than Boeing. If Boeing does not work on the automation part, it coul…

Automation is not bad per se. What I mean is that there must be an opportunity for human override at all levels of automation (and as seamless as possible) in case of machine failure. It does not deny that it could be done by one pilot only, or half a pilot or even somehow a remote human intervention.

When designing a critical system such as an aircraft, you must include human authority into it. No technology will ever be 100% foolproof. This is not a stance against technology, automation or innovation, it's a matter of concept : most of systems (and aircraft in particular) are human-machine systems.

You cannot design an unoverrideable automatic mechanism. Think of how you can appreciate the capacity of full control over your computer and your OS (happy OpenBSD user here, for the record).

Re: Lack of redundancies on Boeing 737 MAX baffles some involved in developing it

#69
post #50

What I fail to understand is why do they not design an overriding scheme to MCAS, such as an "above-threshold" pull on the stick by the pilot. I can recall that this was a classic design by Boeing. Whatever the number of AoA sensors, the system should be easy and straightforward to disable. Those logics of "let's guess automatically if that sensor is failing" are just pushing the problem further. The real problem is…

New overriding scheme means more training. The selling point of 737MAX is any 737 pilot can fly on it without new training.

I can't stop thinking whether similar "compromises" had been made when redesigning the airframe. It's engineering after all. The engineers could be pressed by the management to make certain changes for the sake of profit.

Re: Lack of redundancies on Boeing 737 MAX baffles some involved in developing it

#70
post #27
post #25

Earlier quoted context omitted.

Maybe the problem hasn't been shouted from a high enough rooftop yet.

Or more likely it doesn't really matter, and in a couple years nobody will really remember this about Boeing. They'll go back to being a big airplane producer that has a stunning safety record, which they are despite this issue.

The airline industry is growing and there are only two manufacturers who can build hundreds of planes on time. Airbus is already near full capacity. It would be impossible NOT to buy Boeing if you want planes.
Post reply on HN