Live data from Hacker News

Lack of redundancies on Boeing 737 MAX baffles some involved in developing it

seattletimes.com

101–110 of 163 posts

Re: Lack of redundancies on Boeing 737 MAX baffles some involved in developing it

#101
> “Our proposed software update incorporates additional limits and safeguards to the system and reduces crew workload,” Boeing said in a statement.

... "reduces crew workload" so that they have a chance to figure it out in time and survive. Nice move.

EDIT to add: I guess I find it a bit annoying that, instead of admitting that they're fixing a terrible bug, they're cloaking it in some corporate "we're adding even more cool new features" speak.

Re: Lack of redundancies on Boeing 737 MAX baffles some involved in developing it

#102
The crux of the matter:

> if the group had built the MCAS in a way that would depend on two sensors, and would shut the system off if one fails, he thinks the company would have needed to install an alert in the cockpit to make the pilots aware that the safety system was off.

> And if that happens, Ludtke said, the pilots would potentially need training on the new alert and the underlying system. That could mean simulator time, which was off the table.

Re: Lack of redundancies on Boeing 737 MAX baffles some involved in developing it

#103
post #20
post #2

Despite the headline, the article ends with: That triple-sensor system isn’t foolproof, however. In 2008, on a customer-acceptance flight of an Airbus A320, two of the angle-of-attack sensors froze and those two sensors then outvoted the third. When the pilots went to demonstrate the stall-prevention system, they were not aware of the malfunctioning sensors. The plane crashed, killing the seven people on board. The s…

Yep, 3 sensors can fail too. Less often however. These sensors exist to solve a problem with the MAX design. Changing and moving the engines increased the likelihood of a stall when the engines could push the nose up (as I understand it). Fine. But here's the kicker: this should be something that pilots should be trained on. They should be aware of how the MAX is different to the previous 737s and know what to do to…

> These sensors exist to solve a problem with the MAX design.

No, the sensors existed before the MAX they are used by the autopilot system. With the MAX they are now also used by the MCAS system.

Re: Lack of redundancies on Boeing 737 MAX baffles some involved in developing it

#104
post #64

Earlier quoted context omitted.

The pilots were trained on how to deal with a runaway trim stabiliser. The procedure hasn't changed from the old 737, the only thing that has changed is that it is that the failure mode is more likely to occurr on the 737 MAX. From the article: “A properly trained pilot should be able to solve an MCAS anomaly or any uncommanded flight-control input through procedures that are taught to all 737 pilots,” said Menza, no…

It doesn't present as runaway trim, though. It's a small change in the trim, repeated every few seconds, which can be counteracted on the control column but will eventually add up. Small trim changes are usually happening all the time.

This is my understanding.

In a typical run-away trim, the trim wheel will move a great distance. It's very noticeable, both audibly (the wheel makes a clack-clack-clack noise) and visibly (there are white paint flashes on the wheel). And, obviously, the plane nose goes up or down by more than expected. The correct remedy is to disable the auto trim control via switches on the panel (located near the trim wheels).

The MCAS will adjust the trim in small increments every 10 (or is it 20?) seconds. Yes, a pilot should notice this, but because it's intermittent, it's more likely they don't "see" it as run-away trim, and just a slightly abnormal trim (EDIT - problem made worse because pilots were not informed MCAS existed - it's not a failure more they have trained on). They may attempt to remedy this with the manual trim control (a rocker switch on the control yoke). This does NOT disable MCAS, it only re-trim the plane. MCAS will re-engage due to faulty AoA sensors repeatedly until either the pilot disables all auto-trim with the switch on the panel OR the plane runs into the ground.

Re: Lack of redundancies on Boeing 737 MAX baffles some involved in developing it

#105
post #96

Earlier quoted context omitted.

If there were specific steps that the pilots could have taken to avert disaster, why not just incorporate them into the flight software? Why resorting instead to "reprogramming" the pilot? That's what training is: programming of the human brain. One can't teach others without having first learned the lesson oneself. I'm not convinced Boeing has. I'm not convinced the company had adequately consider all possible scena…

Even if it has enough sensprs, the flight software has no situational awareness. This is by design. The flight software is deliberately kept simple enough that the pilots can be trained to understand the full workings of the flight software and what it will do in any situation. The entire flight control algorithm is probably only a few hundred lines of psudocode. It's a catch 22: We are fully capable of designing a p…

Not sure about the "able to do so since the 80s" part, but generally, I agree.

It's the same problem we see with Tesla, Uber, etc and autonomous cars. If it's to be truly autonomous, it needs to do so without ANY human intervention. As soon as a human is added to the loop, the system needs to be understandable by any human operator.

In the case of the MAX, even with Redundancy sensors, there is the possibility enough of them fail that the plane doesn't "know" how to resolve the problem. So, control must be returned to the pilot with enough time and enough information to avert disaster.

Re: Lack of redundancies on Boeing 737 MAX baffles some involved in developing it

#106

I have a question since many years that I am afraid to ask so straight. There is the AF447 and those 2 Boeing MAX that I remember where people will always talk about redundancy of the sensors, or their maintenance. But really, I want to know why the software and hardware of the aircraft fails to understand that whatever actions it has performed automatically or inputs/actions by the pilots, or any other important eve…

I only know a little bit about aerospace programming, but from what I do know complicated chains-of-reasoning are avoided like the plague. With every additional step of program reasoning the probability that you got it right decays exponentially. As a result, simple controllers with clearly defined areas of responsibility are elevated above all else. It is the pilot's job to integrate the information coming to them from all areas of the plane. Yes, a computer could do it, but once you get past three or so sensors the programmer's ability to reason about what might happen shrinks to nothing in comparison to the pilot's ability to see what is happening.

Re: Lack of redundancies on Boeing 737 MAX baffles some involved in developing it

#107
post #99
post #82

Earlier quoted context omitted.

Well, I've been working in mass mobility and they had 4x redundancy with different sensor types. The more sensors went bad, the more restricted the operation regime became as it went through degraded modes. And the on-board systems were of course aware of the status of the sensors. I think that created the right incentives: you could ignore a faulty sensor or two, but the results were increased travel times, so costs…

Wiring harnesses are a major weight savings. If you wired them all in serial, then that wire is a single point of failure. Otherwise you’d have 65k wires going to each one.

No, you put them on a bus like so many other things in modern vehicles today. They don't need their own separate wires or even their own bus. With lots of sensors, you're going to have several independent buses anyway, so a failure on that bus would only make you lose a fraction of your sensors.

Re: Lack of redundancies on Boeing 737 MAX baffles some involved in developing it

#108
post #100
post #27

Earlier quoted context omitted.

Or more likely it doesn't really matter, and in a couple years nobody will really remember this about Boeing. They'll go back to being a big airplane producer that has a stunning safety record, which they are despite this issue.

Which is also the correct thing to do. Despite our president and some NYTimes columnists being scared of automation (apparently they only agree when they're wrong), automation has saved so many lives that a failure like this doesn't affect the big picture. Yes, mistakes were made, yes, we should find ways to avoid this happening in the future, no, automation isn't the enemy. Without automation in flying at the curren…

Automation is definitely not the enemy.

However, automation that is designed in a criminally negligent manner is. People who create such designs should be put in prison, and we should not be using products from them ever again.

Re: Lack of redundancies on Boeing 737 MAX baffles some involved in developing it

#109
post #61

I am a designer and implementor of vital speed and distance measurement systems, with triply modular redundancy, used in mass transit application. I cannot even imagine what the designers of this thing are going through now. It must be terrible. To make it worse, it's a confusing topic. There are two pillars to the design of such system. 1. Faulty sensor must be detected with a very high probability. The typical way…

>I cannot even imagine what the designers of this thing are going through now. It must be terrible.

Their poor decisions led to this. Single sensor as input to autopilot to augment the nose!?

Re: Lack of redundancies on Boeing 737 MAX baffles some involved in developing it

#110
post #102

The crux of the matter: > if the group had built the MCAS in a way that would depend on two sensors, and would shut the system off if one fails, he thinks the company would have needed to install an alert in the cockpit to make the pilots aware that the safety system was off. > And if that happens, Ludtke said, the pilots would potentially need training on the new alert and the underlying system. That could mean simu…

It seems like we are determined to live in a Gilded Age Fantasy Camp. It's like the Titanic not having enough lifeboats.

I've been around the block. I know Big Corp will always place value on profits over safety, but we seem to be entering an age where they feel unconstrained.

Post reply on HN