Live data from Hacker News

Boeing altered key switches in 737 MAX cockpit limiting ability to shut off MCAS

seattletimes.com

251–260 of 341 posts

Re: Boeing altered key switches in 737 MAX cockpit limiting ability to shut off MCAS

#251
post #198
post #98

Earlier quoted context omitted.

> A brand new design would probably introduce more serious flaws than an interation of a mature design As evidenced by the ever-crashing 787s and A350s.

I rather had the exploding engines of the A380 in mind, the flaming batteries of the B787, but we can also talk earlier B737 (rudder, rivets on early models), DC-10 (cargo door), C-5 (door lock), A340 (freezing pitot tubes) etc.

The 737 rudder hardover wasn't discovered until the mid-to-late 90s, a long, loooong time after the 737 entered into service. That does not quite speak to the benefit of a mature product (how mature is 'mature'?). Case in point: the 737 trim wheel and pitch trim assembly. The deficiencies of their design were put on full display in 2018, because of MCAS. Why do you think it is that (other) modern airliners do not have a stabilizer runaway non-normal checklist? There's a whole host of issues that are inherent to the 737 precisely because of how... mature it is. I think there's probably a crossover point, when a design ceases to be mature and becomes obsolete.

(Engines on newer models can be - and usually are - iterations of older designs. The A380's RR engines are built on the same platform as the Tristar's, introduced in 1972!)

Re: Boeing altered key switches in 737 MAX cockpit limiting ability to shut off MCAS

#252

Earlier quoted context omitted.

it’s not just pr reasons. they tried to hot patch this airplane design with software, and now they are hot patching that fix. it seems it is a fundamentally flawed design that they tried to hide and get away with rather than doing the right thing. i know i don’t want to fly on a 737 max ever, and this whole ordeal with boeing and the faa has made me less confident in the airline industry as a whole. your parenthetica…

Pilots are highly trained. They go through many hours of simulated flights. After an incident like this, any pilots still flying a MAX will be drilled on this specific failure. If you start to see pilots refuse to fly it, that’s when you should worry. Aviation adapts to problems and it always has. Southwest installed additional gear on their planes to help prevent this when the first plane crashed. It’s not far fetch…

I doubt that. Pilots get used to flying on an autopilot and often make mistakes when they have to control everything manually. Recent example is a crash of SSJ100 in Moscow where the pilots failed to land the plane manually when the computer turned off.

If you make controls more complicated, pilots will make more mistakes in critical situation.

Re: Boeing altered key switches in 737 MAX cockpit limiting ability to shut off MCAS

#253

Earlier quoted context omitted.

The 737 MAX cannot be certified as a new plane so that is not an option.

Why not?

Because it has grandfathered rules that new planes don’t have it depends on. For instance no new plane design us allowed to have 737 style emergency exits.

Re: Boeing altered key switches in 737 MAX cockpit limiting ability to shut off MCAS

#254
post #143
post #118

So a lot is known at this point: 1. The A320neo caught Boeing completely off-guard; 2. The threat of the likes of American Airlines (already a mixed Airbus/Boeing customer and the largest airline in the world) placing a large A320neo order for regional aircraft operations scared the bejesus out of Boeing management; 3. For airlines like Southwest that are pure 737, the prospect of adding a plane that didn't share a c…

How hard would it be to add two more sensors to every plane? I'd imagine insanely expensive but this is clearly the ideal solution in addition to whatever patches they can do via software and existing hardware/controls in the whole plane.

This doesn't solve the problem completely. What if two of the sensors fault the same way? What if the computer turns off, will the pilot be able to do what MCAS does, manually?

Maybe it would be better just to use old time-tested design instead of saving small money at the cost of safety.

Re: Boeing altered key switches in 737 MAX cockpit limiting ability to shut off MCAS

#255

Earlier quoted context omitted.

> The engine mounting certainly does not make the plane unsafe. I don't think this is a very...'precise' statement. what is "safe" in the context of aviation? If you had no MCAS, then this plane has a very bad propensity to stall . I hope we can both agree that's an unsafe airplane. You can't just say "don't do that [pull up too much] and then you're fine". The aircraft "wants" to pitch up too high and stall, which p…

The aircraft flies fine. MCAS is a stability control system that applies in certain cases (full power, high angle of attack) where the nose pitches up. It may lead to a stall but that's not what it's correcting for and it doesn't just happen during level flight. If the MCAS system was disabled then pilots handle it manually. Trim is not an exotic concept and just takes training and understanding of the operating char…

> Also aircraft do not have millions of flight hours, they wouldn't reach a million even if they flew 24 hours a day for 100 years.

Most commercial planrs fly 3000 hours a year. There are about 400 787-Max planes built - that's a million flight hours per year already (if they weren't grounded...)

Re: Boeing altered key switches in 737 MAX cockpit limiting ability to shut off MCAS

#256
post #176

Earlier quoted context omitted.

The A350 has 4 AoA sensors: I suspect it is a lesson learned from an A320 that had 2 AoA sensors froze in the same position, outvoting the only AoA sensor that was still working. In other words: failures are not always independent.

I still don't see how a frozen AoA sensor cannot be detected by the reduction in noise or correlation with other sensors (such as gyroscope or accelerometer).

The trick is to detect conditions like this with virtually zero false positives. Say the sensor fails one in 100,000 times and your algorithm has a 1/100 change of flagging a false positive in the case where the sensor is in fact working properly. Then the chance of a real failure successfully detected is:

    0.00001 * 0.99 = 0.0000099
The chance of a false alarm is:

    0.99999 * 0.01 ~= 0.01
Thus:

    P(failure|alarm) =  P(alarm|failure)*P(failure)
                        ---------------------------
                                P(alarm)

                     =   0.99 * 0.00001
                        ----------------
                        0.0000099 + 0.01

                    ~= 0.001

 
So alerts from your seemingly ok-ish algorithm will be false alarms 99.9% of the time!

Re: Boeing altered key switches in 737 MAX cockpit limiting ability to shut off MCAS

#257

Earlier quoted context omitted.

>so low to the ground because it was designed to support a non-jetway use case (which is now non-existent) Complete bullshit. I’ve boarded/deplaned without a jetway in Beijing, SLC, JAC, and AMS in the last couple of years alone.

I meant to say "no ground support whatsoever". I've deplaned 737s and 320s on the tarmac recently too (at big airports), and they used mobile stairs. It's the stairs integrated into the aircraft itself that the 737 was designed around, and that's what's antiquated. Hell, just flying the stairs around with you is very fuel inefficient.

I think it's a little bit of everything (stairs, tech, loading/unloading) but the main reason prrrobably was being able to throw bags into the cargo hold without the need for GSE - the airstair could've easily been made taller.

Re: Boeing altered key switches in 737 MAX cockpit limiting ability to shut off MCAS

#258

Earlier quoted context omitted.

I'm not an engineer but what about: A) Adding two more angle-of-attack sensors so a pilot can be reasonably sure of auto-adjust will work. Retrofitting those would be expensive, of course. B) Put the two buttons back the way they were and add a "light" indicator an angle-of-attack sensor failure. C) More pilot simulator training so pilots know what to expect in the unusual situation that the system fails. I suspect t…

You need three redundant sensors for safety-critical systems, so that if one fails you know which one is failing. Airbus has three AoA sensors (and three of others as well) on their planes for this reason. And it's worth pointing out that 737s already have two of these sensors, but don't use them both for MCAS (?!?!).

It is not certain that the 737 AOA ectually needs to be safety critical. You could just ignore the AOA data completely and divert. The pilot should still have sufficient instruments and training to land safely.

Re: Boeing altered key switches in 737 MAX cockpit limiting ability to shut off MCAS

#259
post #169

Earlier quoted context omitted.

I can help with that -- the MAX is suffering hull losses per flight completed at a rate about 100x that of comparable planes like the A320. Totally off the charts.

It’s such a weird statistic to use though. One crash takes a really long time to recover from in that score. So even if the 737 Max was magically fixed tomorrow, the score wouldn’t change.

Hundreds of people died. It should leave a long-term impact on Boeing's safety record. It should take them a long time to recover and regain trust.

Re: Boeing altered key switches in 737 MAX cockpit limiting ability to shut off MCAS

#260
post #176

Earlier quoted context omitted.

The A350 has 4 AoA sensors: I suspect it is a lesson learned from an A320 that had 2 AoA sensors froze in the same position, outvoting the only AoA sensor that was still working. In other words: failures are not always independent.

I still don't see how a frozen AoA sensor cannot be detected by the reduction in noise or correlation with other sensors (such as gyroscope or accelerometer).

Majority vote is a very simple system to reason about. What you’re describing adds a whole bunch more complexity.

For the noise sensor scenario, is the sensor failing or is the ancillary (and single point of failure) noise sensor failing? What happens when you have a false positive like that and a false negative on another sensor?

For the correlation scenario, when you have two systems that disagree, how do you determine which one is failing? Are their precisions and tolerances sufficiently close that you’ll get a warning at a useful point in time?

Post reply on HN