Live data from Hacker News

Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

nytimes.com

71–80 of 280 posts

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#71
This was premature automation caused by not fully understanding the context. Results in less friction at the cost of enabling a black swan. Bad trade off. The Viking Sky cruise ship that was 1 minute away from releasing its damage potential of about 1300 people. 4 engines stoped simultaneously to protect them selves. Risking the entire ship in one of Norway’s most dangerous waters during harsh weather. There are so many similar examples. Tank turrets self protecting and killing soldier during peace time. Automatic gearbox on military vehicle self protecting against overheating although vehicle is under enemy fire, but the sensor can’t know that.. we need to rethink how “security automation” should work. How do you know if an override is relevant? How to train the operator?

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#72
post #13

Earlier quoted context omitted.

If you get a reading of 20 on one and 34 on the other, you disregard both and disable the system. There’s a big difference between a system which must work and a system which must not go wrong. For example, the fly by wire system in an Airbus must work. A failed sensor must not disable the system. Thus, you need at least triple redundancy to keep functioning in the event of a failure. Boeing’s MCAS system, on the oth…

I've read several of these articles about the MAX and I'm not seeing the explanation for how allowing MCAS to fly the plane only on input from AOA sensors (1, 2 or 5) is different from asking pilots to fly the plane with a fogged-up windscreen. Why not cross-check against the true horizon, for example? Doesn't seem safer to unnecessarily disregard context.

MCAS only exists to paper over a small handling deficiency. Apparently nobody (at least nobody with the power to force a change) thought that it could pose a safety problem. It’s not safety critical, so who cares if it fails? Except that it can fail in a way that crashes the plane.

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#73
post #49
post #4

Earlier quoted context omitted.

The problem isn’t failure, but detecting failure. If the sensor had just stopped responding, there wouldn’t have been any problem. The planes would keep flying, the sensors would get replaced, and everyone would be fine. What happened was that the sensor gave erroneous readings. The MCAS system reacted to those erroneous reading and crashes the plane. With two sensors, you can detect failure. It’s very unlikely that…

That's why you need 5 sensors or so on something this mission-critical. Enough that you can have a clear democratic majority if one or two goes on the fritz.

My point is that it’s not mission critical. You can lose MCAS and be just fine. That’s why two sensors would suffice.

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#74
post #71

This was premature automation caused by not fully understanding the context. Results in less friction at the cost of enabling a black swan. Bad trade off. The Viking Sky cruise ship that was 1 minute away from releasing its damage potential of about 1300 people. 4 engines stoped simultaneously to protect them selves. Risking the entire ship in one of Norway’s most dangerous waters during harsh weather. There are so m…

It’s like these examples of security automation are designed to have the exact opposite effect as chaos engineering.

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#75

This whole plane sounds like any ugly hack. They slapped very different engines on an existing airframe. Then, when it inevitability exhibited undesirable behaviour, they tried to paper over the cracks. Then they hid this information from their customers, regulatory agencies and the pilots. It makes me wonder if there are other issues with the Max that the public doesn't know about yet. I hope a thorough review of Bo…

> This whole plane sounds like any ugly hack. They slapped very different engines on an existing airframe. Then, when it inevitability exhibited undesirable behaviour, they tried to paper over the cracks. Then they hid this information from their customers, regulatory agencies and the pilots.

Don’t forget, the system they used to paper over the cracks had a single point of failure.

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#76

This whole plane sounds like any ugly hack. They slapped very different engines on an existing airframe. Then, when it inevitability exhibited undesirable behaviour, they tried to paper over the cracks. Then they hid this information from their customers, regulatory agencies and the pilots. It makes me wonder if there are other issues with the Max that the public doesn't know about yet. I hope a thorough review of Bo…

The sad thing is that we'll probably see this plane fly again by the end of the year, because the millions of dollars in retrofits will still be cheaper than having to scrap all existing planes.

We have no idea what other potentially lethal corners have been cut. What if they go back into service, after several months of retrofitting all of them at Boeing maintenance hangers, and then the following year there are two more deadly crashes from some other overlooked hack.

Really, these planes need to be scrapped. The engines, equipment, seats, etc can all be stripped and used in other planes, but the air frames will need to be recycled and this line of planes should end here.

Even if it doesn't (probably won't), I highly doubt we'll see another generation of 737s. They did survive the rudder problems way back from the... 80s? or 90s? .. So their reputation might recover, but they still can't make the types of planes airlines want and keep that name/certification.

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#77
post #64
post #41

Boeing engineers did consider [MCAS activation due to failed sensor] in their safety analysis of the original MCAS. They classified the event as “hazardous,” ... could trigger erroneously less often than once in 10 million flight hours. The incuriosity of all parties to an event categorized as hazardous is astonishing. Boeing says it's a system that's completely transparent to the pilot, and therefore there is no nee…

If the pilots had recieved training, then they could be a backup. So probably whoever did that safety analysis was assuming pilots would know how and when to turn off the system, but the pilots in fact didn't know this system existed at all.

Administrative mitigation like pilots are usually the least preferential ways of mitigating hazards. Humans are often the least consistent, most fallible part of a system. If there were engineering solutions available I would hope Boeing would implement them.

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#78
post #4
post #2

Is this only me, or all this one-vs-two AoA sensor talk seems some kind of diversion from the real problem with this plane. I mean, if one-sensor based MCAS failed twice so early in the life span of the plane model, what is the probability that a two-sensor model will fail pretty soon as well? The math should be simple, we have all data needed: combined hours flown by all planes of the type and number of failures (at…

The problem isn’t failure, but detecting failure. If the sensor had just stopped responding, there wouldn’t have been any problem. The planes would keep flying, the sensors would get replaced, and everyone would be fine. What happened was that the sensor gave erroneous readings. The MCAS system reacted to those erroneous reading and crashes the plane. With two sensors, you can detect failure. It’s very unlikely that…

Well the other issue is the system used that bad sensor data to automatically correct the pilots with no indication of why or how to even turn it off. The pilots knew the system was wrong and couldn't force the place to correct.

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#79

“After Boeing removed one of the sensors from an automated flight system on its 737 Max, the jet’s designers and regulators still proceeded as if there would be two.” No, no, no. This is just more of shifting the blame from Boeing upper management. They couldn't use two Angle of Attack (AOA) sensors as when there was a differing reading there would be no way to know the correct reading, which is why MCAS used a singl…

Why only two AoA sensors, then? Why not a hundred?

There are standards for how many independent inputs are needed based on the criticality of the system. It's not just a guess as to how many are sufficient. That's why the categorization of MCAS correctly ('catastrophic' vs. 'hazardous' is important)

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#80
post #4
post #2

Is this only me, or all this one-vs-two AoA sensor talk seems some kind of diversion from the real problem with this plane. I mean, if one-sensor based MCAS failed twice so early in the life span of the plane model, what is the probability that a two-sensor model will fail pretty soon as well? The math should be simple, we have all data needed: combined hours flown by all planes of the type and number of failures (at…

The problem isn’t failure, but detecting failure. If the sensor had just stopped responding, there wouldn’t have been any problem. The planes would keep flying, the sensors would get replaced, and everyone would be fine. What happened was that the sensor gave erroneous readings. The MCAS system reacted to those erroneous reading and crashes the plane. With two sensors, you can detect failure. It’s very unlikely that…

Would you not need three sensors? With only two, wouldn’t it be difficult to determine which is correct?
Post reply on HN