Live data from Hacker News

Boeing 737 MAX crash and the rejection of ridiculous data

philip.greenspun.com

101–110 of 194 posts

Re: Boeing 737 MAX crash and the rejection of ridiculous data

#101
post #40

How does it feel to enter a world where software is killing people ? Driven a new car lately ?

> How does it feel to enter a world where software is killing people ? How is this new? Software has been killing people for a long time.

Smaller groups, yes it has. Software is in everything now so you have to actively avoid it.

Re: Boeing 737 MAX crash and the rejection of ridiculous data

#102

Earlier quoted context omitted.

Ah, see, I'm American. ;) The lane assist can be disabled and a cyclist who hard-brakes in front of me is taking their life in their hands because my Ford only stops if I touch the brake (it just stops as hard as it needs to to minimize risk of impact, regardless of how soft I push the pedal). (Sidebar: I almost feel like that cyclist game is something that should be solved with more sensors. If it's a common issue,…

The cyclist issue is something I don't consider a fault of software or the car's design. Driving/Cycling/Walking in front of a high speed vehicle who has the right of way to the point that they need to break means you should not have been there to begin with. The car's only other option is to hit the cyclist, so as far as I'm concerned it's doing it job correctly. Like you mention a dashcam is likely the only remedy…

[deleted]

Re: Boeing 737 MAX crash and the rejection of ridiculous data

#103
post #66
post #18

Earlier quoted context omitted.

I agree that we frequently see this on HN in regards to aviation. However, I don;t think it applies to Greenspun. He's a knowledgeable and active pilot himself.

Lots of people are, that doesn't mean they aren't armchair quarterbacking. I know how to fly airplanes and helicopters, does that make me an expert on the flight dynamics of 737 MAX?

I think it's fair to say that his knowledge of aircraft plus his knowledge of software and electrical engineering qualify him to speculate.

Its quite likely he has greater knowledge of both subjects than the person who physically implemented MCAS.

Sadly, no speculation is necessary. Had that change been included in MCAS the Ethiopian crash wouldn't have happened.

Re: Boeing 737 MAX crash and the rejection of ridiculous data

#104
post #4

Do we actually have the raw data from the sensor in the flight recorder, or do we have the flight computer's account of that sensor's data? > IF AOA > 15 AND AOA And if the AOA is frozen at 16 due to some fault? What is a loss of signal interpreted as? Does it use last-known value? 0? 100? How often does the AOA get sampled? Is there any attempt to smooth the data? Was the data corrupted (bit errors) during transmiss…

You seem to be arguing multiple sides here.

Philip Greenspun's speculation is a plausible concern, that is all it needs to be a valuable point, that type of data limit handling ought to be considered as the system is looked at. I read his post that he was talking a specific simple example, all the other types of things you mention could also be looked at. How the AoA sensors failed, any potential issues with signal handling, and especially what happened with the Lion Air AoA sensor repaired in Florida need to be investigated, that sensor repair sure seems to be. (BTW data handling in aviation is pretty interesting,

Greenspun is a fairly unique combination of EE/CS/past MIT lecturer/geek and experienced pilot, including holding an ATP certificate and flying for regional airlines.

The system as implemented could not have a "re-command full-nose down after reset". To start with there is not really a "reset" for MCAS. The pilot's only way to fully disabling MCAS continuing to do bad things is via STAB TRIM cutout switches. The STAB TRIM cutout switches are required to handle lots of other problems. e.g. runaway full nose down trim. The stabilizer trim system itself is a dumb as a rock, and has no idea where the trim should be set to if the power is restored to it. I suspect the only likely sensible behavior of the trim system itself is that it makes no automatic change. If MCAS is driving the trim wrong and if it was possible to remove the MCAS input to the trim system then the pilot should be able to reset the trim they want (with then hopefully functioning electric trim switches), or allow the autopilot to do it (outside of MCAS the A/P is the other automatic system that manages the stabilizer trim). The problem is that was not anywhere in Boeing's plans here, there was no way to separate MCAS going nuts and commanding extreme trim changes, from the actual stabilizer trim system.

However I do agree with your sentiment about (all the other) bad mistakes. In my view when a seemingly largely self-regulated group goes off and designs something with so many glaring issues (single AoA sensor source, lack of documentation and training, not even having a standard AoA disagree alert, etc.) and other possible issues (rationale of extension of MCAS trim authority, trim wheel forces needed to crank mechanical trim at stabilizer trim limits, Boeing slowness in responding to issues etc.) then everything needs to be looked at. My hope is there are very thorough investigations, of the actual systems, of all the proposed remedies (which separately, I am not convinced are enough), of Boeing, and of the failure of FAA oversight here. And I hope that is done as fast as possible, and as slow as really needed.

Re: Boeing 737 MAX crash and the rejection of ridiculous data

#105

Maybe someone can illuminate this. This comment seems to say that Boeing has recently implemented a bunch of fixes to prevent MCAS from activating in various scenarios, which allegedly make MCAS safety a non-issue: https://philip.greenspun.com/blog/2019/04/08/boeing-737-max-... I'm not knowledgeable on planes, but some parts of this make me wonder if these fixes will cause the opposite problem. For example if the two…

> Either MCAS is necessary safety equipment, in which case this sounds dangerous, or it isn't, in which case why bother?

The situation is more subtle than that. A simple analogy is that MCAS is like ABS on a car. ABS is not required to drive a car safely and does not activate during normal driving. ABS activating when it should not can cause a crash. Likewise, the intended scenario in which MCAS activates is abnormal and requires a combination of conditions that are unlikely without several errors in judgement by the pilot.

There's another layer though: it's possible to get the 737 MAX into a situation where the standard stall recovery for other 737s, which starts with lowering the nose using the elevator is insufficient. Instead, both the trim and the elevator are required; MCAS does the trim part automatically.

Re: Boeing 737 MAX crash and the rejection of ridiculous data

#106
post #85
post #19

Earlier quoted context omitted.

Philip Greenspun is a highly experienced pilot: https://philip.greenspun.com/flying/milestones

Honest question, is his experience in small aircraft applicable at all to jetliners? How much carryover, beyond core theory of flight dynamics, is there from piloting a single prop to an Airbus or even a regional jet?

He part owns a Pilatus PC-12, which is pretty much a single engine regional jet. It isn't your grandfather's Cessna.

Re: Boeing 737 MAX crash and the rejection of ridiculous data

#107
post #30

There are several inexcusably egregious errors in the design of the MCAS system, and this "solution" addresses none of them. - Single point of failure: The system makes command decisions based on the readings from a single sensor. The fact that nobody asked (or was bothered by the answer to) the question "what happens when that sensor fails?" is negligence. - No re-training of pilots: Pilots were not aware of new way…

>No re-training of pilots: Pilots were not aware of new ways in which the plane might take command away from them, and were left in the dark with only seconds to react to a deadly situation

Both the Lion Air and Ethiopian Air flights recovered from the initial MCAS. The mistake was assuming that pilots could reliably recover from a runaway trim situation. That might have been true when that was a more common failure and when pilots had more experience flying with manual trim.

Re: Boeing 737 MAX crash and the rejection of ridiculous data

#108
post #85
post #19

Earlier quoted context omitted.

Philip Greenspun is a highly experienced pilot: https://philip.greenspun.com/flying/milestones

Honest question, is his experience in small aircraft applicable at all to jetliners? How much carryover, beyond core theory of flight dynamics, is there from piloting a single prop to an Airbus or even a regional jet?

He has first officer experience flying a CL-65 Canadair Regional Jet.

Re: Boeing 737 MAX crash and the rejection of ridiculous data

#109
post #30

There are several inexcusably egregious errors in the design of the MCAS system, and this "solution" addresses none of them. - Single point of failure: The system makes command decisions based on the readings from a single sensor. The fact that nobody asked (or was bothered by the answer to) the question "what happens when that sensor fails?" is negligence. - No re-training of pilots: Pilots were not aware of new way…

Among all the MCAS noise, this is the best summary of the problem that I've seen so far.

Re: Boeing 737 MAX crash and the rejection of ridiculous data

#110
post #51
post #19

Earlier quoted context omitted.

Philip Greenspun is a highly experienced pilot: https://philip.greenspun.com/flying/milestones

I too have hundreds of flights and am also a programmer, but I would not assume having both skills would make you anything more then an armchair quarterback. If you have not written code that runs planes, what knowledge are you basing your idea off of. IMO. i too also play games, but i wouldn't assume to tell a game developer how to write their code.

https://i.imgur.com/cQ8ECYK.jpg
Post reply on HN