Live data from Hacker News

Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

nytimes.com

11–20 of 280 posts

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#11
post #2

Is this only me, or all this one-vs-two AoA sensor talk seems some kind of diversion from the real problem with this plane. I mean, if one-sensor based MCAS failed twice so early in the life span of the plane model, what is the probability that a two-sensor model will fail pretty soon as well? The math should be simple, we have all data needed: combined hours flown by all planes of the type and number of failures (at…

If MCAS is disabled for some reason because of sensor failure, how does that factor into the common type rating? Same goes for if they significantly lower how much input it provides.

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#12
post #2

Is this only me, or all this one-vs-two AoA sensor talk seems some kind of diversion from the real problem with this plane. I mean, if one-sensor based MCAS failed twice so early in the life span of the plane model, what is the probability that a two-sensor model will fail pretty soon as well? The math should be simple, we have all data needed: combined hours flown by all planes of the type and number of failures (at…

Not necessarily a diversion, but certainly not the only cause in a proper failure analysis.

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#13
post #4

Earlier quoted context omitted.

The problem isn’t failure, but detecting failure. If the sensor had just stopped responding, there wouldn’t have been any problem. The planes would keep flying, the sensors would get replaced, and everyone would be fine. What happened was that the sensor gave erroneous readings. The MCAS system reacted to those erroneous reading and crashes the plane. With two sensors, you can detect failure. It’s very unlikely that…

> With two sensors, you can detect failure You get a reading of 20 on one sensor and get a reading of 34 on the second, which one is correct. To achieve reliability a minimum of five sensors need be used. four primary and one back-up. If three primary agree then system normal. If two primary disagree then switch to backup.

If you get a reading of 20 on one and 34 on the other, you disregard both and disable the system.

There’s a big difference between a system which must work and a system which must not go wrong. For example, the fly by wire system in an Airbus must work. A failed sensor must not disable the system. Thus, you need at least triple redundancy to keep functioning in the event of a failure.

Boeing’s MCAS system, on the other hand, doesn’t need to work. The plane flies just fine without it. It merely needs to not go crazy. Two sensors is sufficient.

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#14

“After Boeing removed one of the sensors from an automated flight system on its 737 Max, the jet’s designers and regulators still proceeded as if there would be two.” No, no, no. This is just more of shifting the blame from Boeing upper management. They couldn't use two Angle of Attack (AOA) sensors as when there was a differing reading there would be no way to know the correct reading, which is why MCAS used a singl…

This doesn’t seem correct to me, but I can’t put my finger on why. Surely if both agree that’s more certainty than a single sensor reading. Granted a disagreement would be bad, but at least you would have some warning that one of them is wrong, whereas you would have none at all if relying on a single sensor.

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#15
post #3
post #2

Is this only me, or all this one-vs-two AoA sensor talk seems some kind of diversion from the real problem with this plane. I mean, if one-sensor based MCAS failed twice so early in the life span of the plane model, what is the probability that a two-sensor model will fail pretty soon as well? The math should be simple, we have all data needed: combined hours flown by all planes of the type and number of failures (at…

The AOA sensors are effectively a consumable, and would undergo regular replacement over the life of the aircraft, the odds of BOTH of them failing at the same moment in the same flight is very very small.

Ok, that makes sense. But are the hours at which they got replaced are on order (or several) of magnitude lower than a two-sensor failure can occur? I hope it is calculated.

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#16
post #4
post #2

Is this only me, or all this one-vs-two AoA sensor talk seems some kind of diversion from the real problem with this plane. I mean, if one-sensor based MCAS failed twice so early in the life span of the plane model, what is the probability that a two-sensor model will fail pretty soon as well? The math should be simple, we have all data needed: combined hours flown by all planes of the type and number of failures (at…

The problem isn’t failure, but detecting failure. If the sensor had just stopped responding, there wouldn’t have been any problem. The planes would keep flying, the sensors would get replaced, and everyone would be fine. What happened was that the sensor gave erroneous readings. The MCAS system reacted to those erroneous reading and crashes the plane. With two sensors, you can detect failure. It’s very unlikely that…

> It’s very unlikely that both would fail simultaneously. If they did, it’s very unlikely that both would provide the same erroneous readings.

They don't have to fail simultaneously in a flight. And they don't have to fail by internal sensor problems. There are many cases in which they can simultaneously fail and give same readings, article even mentioned such types of events:

>> That probability may have underestimated the risk of so-called external events that have damaged sensors in the past, such as collisions with birds, bumps from ramp stairs or mechanics’ stepping on them.

And AF447 gives an example when such erroneous readings combined with pilot errors may lead to.

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#17
post #2

Is this only me, or all this one-vs-two AoA sensor talk seems some kind of diversion from the real problem with this plane. I mean, if one-sensor based MCAS failed twice so early in the life span of the plane model, what is the probability that a two-sensor model will fail pretty soon as well? The math should be simple, we have all data needed: combined hours flown by all planes of the type and number of failures (at…

I have the impression that people are overlooking the sensors. They are suppose to be very, very, reliable. Two different planes got wrong reading from sensor in the same side, this seems to be a red flag for me. I wonder in what side of the sensor cable the problem is.

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#18
post #15
post #3

Earlier quoted context omitted.

The AOA sensors are effectively a consumable, and would undergo regular replacement over the life of the aircraft, the odds of BOTH of them failing at the same moment in the same flight is very very small.

Ok, that makes sense. But are the hours at which they got replaced are on order (or several) of magnitude lower than a two-sensor failure can occur? I hope it is calculated.

The point is that, as safety-critical equipment, you can't fly the plane if one is broken. So you'd need to have two fail within a single flight, and fail in the same way, in order to cause an incorrect activation of MCAS. With just one sensor, it's much more likely.

Note that Airbus uses three of these sensors on their planes, so that when one fails you know which one it is, and can still rely on the signals from the two remaining good ones. Then you replace the failed sensor before the next flight.

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#19
post #16
post #4

Earlier quoted context omitted.

The problem isn’t failure, but detecting failure. If the sensor had just stopped responding, there wouldn’t have been any problem. The planes would keep flying, the sensors would get replaced, and everyone would be fine. What happened was that the sensor gave erroneous readings. The MCAS system reacted to those erroneous reading and crashes the plane. With two sensors, you can detect failure. It’s very unlikely that…

> It’s very unlikely that both would fail simultaneously. If they did, it’s very unlikely that both would provide the same erroneous readings. They don't have to fail simultaneously in a flight. And they don't have to fail by internal sensor problems. There are many cases in which they can simultaneously fail and give same readings, article even mentioned such types of events: >> That probability may have underestima…

If they’re damaged on the ground, surely it’ll be noticed that the sensors are claiming an extreme AoA while just sitting there, and they’ll be fixed.

AF447 is an example of a fly by wire system that has to keep working no matter what happens, thus a bunch of redundant systems and a series of alternate modes the system can fall back on to operate in a degraded state.

MCAS, in contrast, is not a critical system. It could shut down with no problems at all. These crashes happened only because it didn’t shut down when faced with a failed sensor, because it couldn’t detect the failure.

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#20
post #4
post #2

Is this only me, or all this one-vs-two AoA sensor talk seems some kind of diversion from the real problem with this plane. I mean, if one-sensor based MCAS failed twice so early in the life span of the plane model, what is the probability that a two-sensor model will fail pretty soon as well? The math should be simple, we have all data needed: combined hours flown by all planes of the type and number of failures (at…

The problem isn’t failure, but detecting failure. If the sensor had just stopped responding, there wouldn’t have been any problem. The planes would keep flying, the sensors would get replaced, and everyone would be fine. What happened was that the sensor gave erroneous readings. The MCAS system reacted to those erroneous reading and crashes the plane. With two sensors, you can detect failure. It’s very unlikely that…

It’s very unlikely that both would fail simultaneously.

Birgenair 301 crashed into the Atlantic because mud dauber wasps built nests in both pitot tubes while the plane was on the ground. It happens.

Post reply on HN