Live data from Hacker News

Preliminary report into Air India crash released

bbc.co.uk

421–430 of 924 posts

Re: Preliminary report into Air India crash released

#421

Earlier quoted context omitted.

We dont know about that one at all.

please. pilot puts everyone to sleep but himself, turns everything off, then does a flyby of his hometown and then puts himself to sleep? the only one more obvious is the german one.

without a black box all of this is supposition.

Re: Preliminary report into Air India crash released

#422

Earlier quoted context omitted.

Mentour Pilot is a fantastic channel.

Anyone who does on-call should look into aviation disasters. Crew resource management, the aviate-navigate-communicate loop, it's all very applicable. ('WalterBright is an excellent source of commentary on applying lessons from the airline industry to software.) But I did burn out on Mentour Pilot after a while, I just had my fill of tragedy.

A long time ago I had a colleague turn me on to Sidney Dekker’s “Drift Into Failure”, which in many ways covers system design taking into account the “human” element. You could think of it as the “realists” approach to system safety.

At the time we operated some industry specific, but national scale, critical systems and were discussing the balance of the crucial business importance of agility and rapid release cycles (in our industry) against system fragility and reliability.

Turns out (and I take no credit for the underlying architecture of this specific system, though I’ve been a strong advocate for this model of operating) if you design systems around humans who can rapidly identify and diagnose what has failed, and what the up stream and down stream impacts are, and you make these failures predictable in their scope and nature, and the recovery method simple, with a solid technical operations group you can limit the mean-time-to-resolution of incidents to The issue with both methods (human or technical recovery) is that both are dependent on maintaining an organizational culture that fosters a deep understanding of how the system fails, and what the various predictable upstream and downstream impacts are. The more you permit the culture to decay the more you increase the likelihood that an outage will go from benign and “normal” to absolutely catastrophic and potentially company ending.

In my experience companies who operate under this model eventually sacrifice the flexibility of rapid deployment for an environment where no failure is acceptable, largely because of an lack of appreciation for how much of the system’s design is dependent on an expectation of the fostering of the “appropriate” human element.

(Which leads to further discussion about absolutely critical systems like aviation or nuclear where you absolutely cannot accept catastrophic failure because it results in loss of life)

Extremely long story short, I completely agree. Aviation (more accurately aerospace) disasters, nuclear disasters, medical failures (typically emergency care or surgical), power generation, and the military (especially aircraft carrier flight decks) are all phenomenal areas to look for examples of how systems can be designed to account for where people may fail in the critical path.

Re: Preliminary report into Air India crash released

#423
post #381

Earlier quoted context omitted.

Or you simply interlock the engine cutoff with the thrust lever position, any position other than idle prevents shutdown. This all goes through the flight computers already. If there’s a fire or similar problem the fire handles will cut off fuel without the normal shutdown procedure, but the normal switches only need to be used at idle thrust. I wonder if Airbus has this logic, since their philosophy is to override t…

According to AI, Airbus places these switches on the overhead panel, so that alone would make it harder to inadvertently move them. Apparently, Airbus "protections do not extend to mechanical or FADEC‑controlled systems like the engine‑fuel shutoff valves. If you deliberately pull and flip the ENG MASTER lever to OFF, the FADEC will immediately close the LP and HP fuel valves and the engine will flame out. If you the…

And that's why you don't trust AI.

As another commenter said the Airbus engine start/stop controls are located behind the thrust levers, and according to the A350 operations manual which I got my hands on there are two conditions required for the FADEC to command engine shut down: Run switch to off, thrust lever to idle.

So if that's correct on an Airbus aircraft you can't just switch off the engines when they're commanded to produce thrust. This also seems to be backed up by the difference in the guards for those controls in the Airbus cockpits.

Re: Preliminary report into Air India crash released

#424

Earlier quoted context omitted.

Sure, but you can open the door, pull the handbrake, or turn the wheel so hard you lose control of the vehicle. These are all similarly preventable, but maybe not worth the risk of being unable to open the door, brake or steer if the safety mechanism fails closed, or if your situation is outside the foresight of its designer. Also, you don't need multiple certifications and 1500 hours of experience to drive a car.

On a Tesla (and presumably other cars) opening the door engages Park. There's no handbrake to pull, and turning the wheel so hard to lose control is next to impossible. Maybe on an oily wet or loose surface.

On my Tesla Model Y there's a hand brake on the push button of the right lever. On the left hand lever there's another push button, the windshield wiper liquid. Guess what have I mistakenly, and scarely, done twice already when driving at highway speeds when my windshield was a little dusty?

New designs are prone to ill decision-making from engineers, drivers and pilots alike. Every pathway of let's do it differently is the beginning of a journey of fine-tuning loops until stability.

Re: Preliminary report into Air India crash released

#425

Earlier quoted context omitted.

> The aircraft achieved the maximum recorded airspeed of 180 Knots IAS at about 08:08:42 UTC and immediately thereafter, the Engine 1 and Engine 2 fuel cutoff switches transitioned from RUN to CUTOFF position one after another with a time gap of 01 sec. The Engine N1 and N2 began to decrease from their take-off values as the fuel supply to the engines was cut off. > As per the EAFR, the Engine 1 fuel cutoff switch tr…

> Boeing's probably gonna have a big sigh of relief over this one. The 787 is 15 years old, and this particular plane was 10 years old. It always seemed unlikely to be a major, new issue. My money was actually on maintenance.

While unlikely, there have been issues before that took decades to surface (e.g. Aloha Airlines where a 737 manufactured more than a decade earlier became a cabriolet due to Boeing underestimating sea water corrosion and short flight cycles), or the 737 rudder issues where the planes were also 10+ years old.

Re: Preliminary report into Air India crash released

#426

I'm completely ignorant about this matter, but why is it even possible to cut off fuel while taking off? Shouldn't there be a control that completely disables this? Is there actually a situation where cutting off both engines could be necessary and wouldn't lead to a catastrophe?

The general principle of aircraft control is that the pilot has the final say on how it is operated, not the designer, because you never know when you will need to take extraordinary measures. And the pilot generally prefers to return to the ground safely.

Re: Preliminary report into Air India crash released

#427

Earlier quoted context omitted.

Bad analogy because pilots are trained and rehearse and practice memory items until they are instinctual. > impossible by design. Deflecting that the human is the weakest part of the system. One or other may have panicked and made a mistake, made a mistake unintentionally, went crazy and doomed the flight, or intentionally doomed the flight for some socioeconomic reasons. These are speculative possibilities that we d…

Forget my words then and take those from aviation experts. The fact that a pilot would cut off fuel from both engines, in sequence while taking off is virtually impossible to happen unless deliberate. Hence the hand brake comparison, it does not come natural to use it while driving.

Bare in mind there have been there have been what, 100+ million flights? so "virtually impossible" things can, and will happen

Re: Preliminary report into Air India crash released

#428

Earlier quoted context omitted.

A rodent chewing on wires. Vibration-induced chafing. Tin whiskers causing an intermittent short. There are many possibilities, those came to mind first.

We know that the switches physically moved from the run to the cutoff position because one of the pilots noted that they were in the wrong position. We know that they were moved back to the run position because they found in that position. I don't understand how a short could explain that - it really seems like someone would have had to physically move the switches.

Do we know that the pilot noticed they were in the wrong physical position, or did some other status indicate the engie fuel had been cut? I would be surprised if there was only one channel for this information

Re: Preliminary report into Air India crash released

#429

Earlier quoted context omitted.

This is a place that puts "Hacker" in the name despite the stigma in the mainstream. Given the intended meaning of the term, I would naturally expect this to be a place where people can speculate and reason from first principles, on the information available to them, in search of some kind of insight, without being shamed for it. You don't have to like that culture and you also don't have to participate in it. Making…

> That said Boeing could take a page out of the Garmin GI275 This is not "reasoning from first principles". In fact, I don't think there is any reasoning in the comment. There is an implication that an obvious solution exists, and then a brief description of said solution. I am all for speculation and reasoning outside of one's domain, but not low quality commentary like "ugh can't you just do what garmin did". This…

> This is not "reasoning from first principles".

It literally is. Accidental/malicious activation can be catastrophic, therefore it must be guarded against. First principles.

The shutoff timer screen given as an example is a valid way of accomplishing it. Not directly applicable to aircraft, but that's not the point.

> "ugh can't you just do what garmin did"

That's your dishonest interpretation of a post that offers reasonable, relevant suggestions. Don't tell me I need to start quoting that post to prove so. It's right there.

Re: Preliminary report into Air India crash released

#430
post #72

it makes sense to me that the pilot who said "I did not do it" actually did do it without realizing it, was supposed to be putting the landing gear up when he committed a muscle memory mistake. it happened around the time the landing gear should be up, and this explanation matches what was said in the cockpit, and the fact that the landing gear wasn't retracted. I think this idea was even floated initially by the you…

Is there a video feed of the cockpit inside the black box?

If not there should be one as even my simple home wifi camera can record hours of hd video on the small sd card. And If there is, wouldn't that help to instantly identify such things?

Post reply on HN