Live data from Hacker News

Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

nytimes.com

51–60 of 280 posts

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#51
post #24

Earlier quoted context omitted.

Airspeed is required for safe flight. The failure on that flight was detected immediately, it just couldn’t be handled. AoA on a 737 MAX is not required for safe flight and the system just needs to refrain from taking any action if it fails.

But MCAS was added because the plane doesn't handle well in some situations.

I haven't heard of it ever activating except in the incident/accident flights. It's required for certification, but you would either have to be mishandling the plane or get in some extreme weather for MCAS to activate.

Think about it like the Antilock brakes on your car. Suppose the wheel position sensor fails. It's fine if the car puts up a warning light and says that you don't have antilock brakes anymore. You can drive fine without them until you can get them fixed with a minor safety impact. It's not fine if the wheel position sensor fails and this causes the car to slam on the brakes going 65mph down the highway.

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#52
This whole plane sounds like any ugly hack. They slapped very different engines on an existing airframe. Then, when it inevitability exhibited undesirable behaviour, they tried to paper over the cracks. Then they hid this information from their customers, regulatory agencies and the pilots.

It makes me wonder if there are other issues with the Max that the public doesn't know about yet.

I hope a thorough review of Boeing's internal communications is already underway. If there is proof that these decisions were made for financial gain, they should face criminal charges.

IMO, whether it was greed or just general incompetence, Boeing has demonstrated that they are not responsible enough to self-certify their aircraft.

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#53
post #28

> a fundamental overhaul to an automated system that would ultimately play a role in two crashes Are they STILL blaming the computer instead of the unstable air-frame after the engines were moved?

Because they can fix the computer and the sensors but if they have to toss out the whole airframe they're going to be out billions.

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#54
post #9

Earlier quoted context omitted.

It is not unlikely, I don't remember details, but I remember the case when two broken sensors voted over working sensor. The problem is that in order to save tiny amount of money Boing made plane rely on unreliable sensors.

It’s not unlikely... because of some vague memory you have?

It's not unlikely because it happened repeatedly:

https://www.pprune.org/rumours-news/558483-iced-aoa-sensors-...

http://avherald.com/h?article=410c9cec/0015

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#55

“After Boeing removed one of the sensors from an automated flight system on its 737 Max, the jet’s designers and regulators still proceeded as if there would be two.” No, no, no. This is just more of shifting the blame from Boeing upper management. They couldn't use two Angle of Attack (AOA) sensors as when there was a differing reading there would be no way to know the correct reading, which is why MCAS used a singl…

When 2 sensors disagree the data are considered invalid and the software is supposed to handle the case.

Usually it means showing an alarm, putting the system relying on it on degraded mode and letting the pilot manually select the sensor he thinks is correct.

Reacting to such failures is a big part of an equipment certification process.

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#56
post #49
post #4

Earlier quoted context omitted.

The problem isn’t failure, but detecting failure. If the sensor had just stopped responding, there wouldn’t have been any problem. The planes would keep flying, the sensors would get replaced, and everyone would be fine. What happened was that the sensor gave erroneous readings. The MCAS system reacted to those erroneous reading and crashes the plane. With two sensors, you can detect failure. It’s very unlikely that…

That's why you need 5 sensors or so on something this mission-critical. Enough that you can have a clear democratic majority if one or two goes on the fritz.

... or two sensors and a pilot who is in control.

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#57

This whole plane sounds like any ugly hack. They slapped very different engines on an existing airframe. Then, when it inevitability exhibited undesirable behaviour, they tried to paper over the cracks. Then they hid this information from their customers, regulatory agencies and the pilots. It makes me wonder if there are other issues with the Max that the public doesn't know about yet. I hope a thorough review of Bo…

Indeed. The article makes it sound like a foul-up late in the design process, but this plane was corrupt from the very beginning when Boeing set out to dodge the requirement for re-certifying the airframe.

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#58

“After Boeing removed one of the sensors from an automated flight system on its 737 Max, the jet’s designers and regulators still proceeded as if there would be two.” No, no, no. This is just more of shifting the blame from Boeing upper management. They couldn't use two Angle of Attack (AOA) sensors as when there was a differing reading there would be no way to know the correct reading, which is why MCAS used a singl…

This doesn’t seem correct to me, but I can’t put my finger on why. Surely if both agree that’s more certainty than a single sensor reading. Granted a disagreement would be bad, but at least you would have some warning that one of them is wrong, whereas you would have none at all if relying on a single sensor.

It doesn't seem correct to you because they might have been trying to be sarcastic. Using two sensors would admit that they might disagree, and that there might be situations where the MCAS could not work. But there cannot be a situation where the MACS doesn't work if the MAX shall have the same type rating as previous 737s, so the sensors cannot disagree, and so it would be useless and wasteful to use two sensors. Issuing that disagreement warning would completely undermine the very reason for the existence of the MCAS.

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#59
post #24

Earlier quoted context omitted.

Airspeed is required for safe flight. The failure on that flight was detected immediately, it just couldn’t be handled. AoA on a 737 MAX is not required for safe flight and the system just needs to refrain from taking any action if it fails.

But MCAS was added because the plane doesn't handle well in some situations.

Doesn't handle well is not equivalent to "is uncontrollable", though.

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#60
post #28

> a fundamental overhaul to an automated system that would ultimately play a role in two crashes Are they STILL blaming the computer instead of the unstable air-frame after the engines were moved?

The redesign did not make the aircraft unstable. I don't know how this became such a meme, but it's trivial to see that it's not true. Commercial passenger aircraft must be aerodynamically stable by FAA regulation: https://www.ecfr.gov/cgi-bin/text-idx?node=14:1.0.1.3.11#se1...

The engine change really wasn't a big deal. The net effect is "flight stick feels lighter at high AoA with high thrust." That's it. My understanding is that the 737-MAX flys more like a 757 in this regard. Nothing crazy, just a difference.

Now, that's enough to require re-certification by FAA standards, because it's enough of a difference that it could cause problems of pilot error. But going on like the aircraft wants to fall out of the sky isn't helping anyone here.

MCAS was intended to be a small tweak that avoids the re-cert. And it would have been fine if they had neutered the system such that it couldn't input such extreme trim angles, or else has more reliability as needed in a system that could have such dramatic effects when malfunctioning.

Post reply on HN