Live data from Hacker News

Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

nytimes.com

91–100 of 280 posts

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#91
post #40

Earlier quoted context omitted.

I have the impression that people are overlooking the sensors. They are suppose to be very, very, reliable. Two different planes got wrong reading from sensor in the same side, this seems to be a red flag for me. I wonder in what side of the sensor cable the problem is.

They’re not expected to be that reliable. They’re small vanes sticking out the side of the nose, vulnerable to bird strikes. The article mentions hundreds of reported failures over the years. The way to make the system reliable is redundancy.

The article says it had 122 failure due bird strikes plus 85 unnamed problems in about 30 years of data.

Considering the number of flights, that does sounds reliable to me.

I still think two failures in the same sensor, in the same airplane, under the same condition, in less than one year did not happen by chance.

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#92

Earlier quoted context omitted.

But MCAS was added because the plane doesn't handle well in some situations.

I haven't heard of it ever activating except in the incident/accident flights. It's required for certification, but you would either have to be mishandling the plane or get in some extreme weather for MCAS to activate. Think about it like the Antilock brakes on your car. Suppose the wheel position sensor fails. It's fine if the car puts up a warning light and says that you don't have antilock brakes anymore. You can…

I haven't heard of it ever activating except in the incident/accident flights.

You wouldn't hear about it unless the activation was triggered by egregious pilot error and you're scouring aviation news sites.

It's not fine if the wheel position sensor fails and this causes the car to slam on the brakes going 65mph down the highway.

Been there, done that. It's an unpleasant failure mode, but it is survivable.

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#93
post #39
post #31

Earlier quoted context omitted.

First: I said it’s very unlikely, not impossible. Second: the failure of AF447’s pitot tubes was detected immediately and the system switched to an alternate law as a result; this contributed to the crash because the pilots were less familiar with how the system operated in that mode. Third: AoA sensors operate by a completely different mechanism so even if this was what happened (it wasn’t) this demonstrates nothing…

> With two sensors, you can detect failure. It’s very unlikely that both would fail simultaneously. If they did, it’s very unlikely that both would provide the same erroneous readings. > First: I said it’s very unlikely, not impossible. > You’re just badly arguing details while ignoring the actual point here. My point here was that with two AoA sensors you can't reliably detect failure. They can both fail simultaneou…

[deleted]

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#94
post #31
post #30

Earlier quoted context omitted.

I've confused AF447's Pitot tubes with AoA sensors. But I think point is still valid: two sensors _can_ simultaneously have same erroneous readings and we have to be sure pilots can handle such situations.

First: I said it’s very unlikely, not impossible. Second: the failure of AF447’s pitot tubes was detected immediately and the system switched to an alternate law as a result; this contributed to the crash because the pilots were less familiar with how the system operated in that mode. Third: AoA sensors operate by a completely different mechanism so even if this was what happened (it wasn’t) this demonstrates nothing…

You’re just badly arguing details while ignoring the actual point here.

What was the point? Two sensors (in this case alpha vanes) can fail at the same time and in the same way on an Airbus:

https://avherald.com/h?article=47d74074

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#95
post #72

Earlier quoted context omitted.

I've read several of these articles about the MAX and I'm not seeing the explanation for how allowing MCAS to fly the plane only on input from AOA sensors (1, 2 or 5) is different from asking pilots to fly the plane with a fogged-up windscreen. Why not cross-check against the true horizon, for example? Doesn't seem safer to unnecessarily disregard context.

MCAS only exists to paper over a small handling deficiency. Apparently nobody (at least nobody with the power to force a change) thought that it could pose a safety problem. It’s not safety critical, so who cares if it fails? Except that it can fail in a way that crashes the plane.

MCAS only exists to paper over a small handling deficiency.

Per the article MCAS was originally intended to handle uncommon edge cases but was extended to cover additional (low speed) deficiencies. This expanded scope is what made MCAS as problematic as it is because it did away with the second input (accelerometer) and expanded the authority dramatically (from something like 0.6 degrees to 2.4 degrees of stabilizer movement).

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#96
post #13

Earlier quoted context omitted.

> With two sensors, you can detect failure You get a reading of 20 on one sensor and get a reading of 34 on the second, which one is correct. To achieve reliability a minimum of five sensors need be used. four primary and one back-up. If three primary agree then system normal. If two primary disagree then switch to backup.

If you get a reading of 20 on one and 34 on the other, you disregard both and disable the system. There’s a big difference between a system which must work and a system which must not go wrong. For example, the fly by wire system in an Airbus must work. A failed sensor must not disable the system. Thus, you need at least triple redundancy to keep functioning in the event of a failure. Boeing’s MCAS system, on the oth…

There’s a big difference between a system which must work and a system which must not go wrong. For example, the fly by wire system in an Airbus must work. A failed sensor must not disable the system. Thus, you need at least triple redundancy to keep functioning in the event of a failure.

Fly-by-wire Boeings still only have two alpha vanes. Go ahead, take a look at the next 777 or 787 you come across.

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#97
post #38

I'm surprised no one has mentioned Therac 25 or Normal Accidents yet. For reference, the Therac 25 was a computer-controlled radiation therapy machine involved in several over-exposures due to replacement of physical controls with computer based ones without complete understanding of the interactions of the controls. The Max feels very much like that. No one can really keep a whole aircraft in their head, much less a…

I don't see these as equivalent, at least not based on what I've learned about the cases (feel free to correct). As I understand, Therac-25 was due to software bug and a genuine design process inadequacy that allowed it to cause a problem, that could happen with people acting entirely in good faith, simply because they didn't know better. That's why they created standards to address the design process. With 737MAX...…

It's not the equivalent, but it is the consequence of a chain of incremental changes, each of which is not sufficient to subvert safety margins, but together they change the paradigm.

As to bad faith, yes, I'm sure there was some of that, but generally decisions like these don't look like bad faith to the people making them. It's easy to get swamped by technical details.

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#98
post #85

The day someone very high up the corporate ladder truly gets held responsible for this type of greed & negligence and will be put a way for a long prison sentence would be a good day for society. But I am not holding my breath... But I hope that the CEO Dennis Muilenburg deep down understands he seriously fuxxed up real bad and every now and then is having a hard time falling a sleep in his $10M mansion knowing that…

I agree. I think the FAA failed in it's mission also.

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#99
post #88

Earlier quoted context omitted.

In what world is scrapping the airframes due to a (serious) software fault the best and most sensible solution? Do you believe there could be undiagnosed problems with the wings, fuselage, tail, hydraulics, electrics, fueling system, gear, etc.?

In what world is scrapping the airframes due to a (serious) software fault the best and most sensible solution? A world in which the faulty software was required to fix faulty hardware.

The hardware isn't faulty. The problem is the way Boeing tried to achieve a zero training delta so pilots wouldn't have to get a second type rating.

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#100
post #37

Earlier quoted context omitted.

The point is that, as safety-critical equipment, you can't fly the plane if one is broken. So you'd need to have two fail within a single flight, and fail in the same way, in order to cause an incorrect activation of MCAS. With just one sensor, it's much more likely. Note that Airbus uses three of these sensors on their planes, so that when one fails you know which one it is, and can still rely on the signals from th…

That was my original question. What is the probability of them failing at the same flight in the same way (say they got frozen at the same angle, hit by blizzard, etc, etc). Intuition is that the chances are high given their low MTBF.

[deleted]
Post reply on HN