Live data from Hacker News

Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

nytimes.com

121–130 of 280 posts

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#121
How MCAS slipped through certification process was not the main issue (mistakes in complex products can happen). The main issue was Boeing not caring that MCAS was dangerous even after discovering it.

After the Lion Air crash, it was very apparent to Boeing that MCAS was not safe. This whole article focuses on how MCAS slipped through development+certification - but really even after Boeing new the dangers of MCAS, the MAX still was allowed to fly.

It was hidden and dangerous. Then it was open and dangerous but was still defended by Boeing. Damning.

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#122
post #13

Earlier quoted context omitted.

If you get a reading of 20 on one and 34 on the other, you disregard both and disable the system. There’s a big difference between a system which must work and a system which must not go wrong. For example, the fly by wire system in an Airbus must work. A failed sensor must not disable the system. Thus, you need at least triple redundancy to keep functioning in the event of a failure. Boeing’s MCAS system, on the oth…

I've read several of these articles about the MAX and I'm not seeing the explanation for how allowing MCAS to fly the plane only on input from AOA sensors (1, 2 or 5) is different from asking pilots to fly the plane with a fogged-up windscreen. Why not cross-check against the true horizon, for example? Doesn't seem safer to unnecessarily disregard context.

The problem occurred in that that sensor had a privileged (unoverridable) pipeline to the horizontal stabilizer.

The pilots knew something was going wrong. That wasn't the issue. The issue was that the bloody thing could mistrim the plane to the point of nigh irrecoverability, and no one knew enough about it until two planes full of people plunged out of the sky.

The plane may be able to fly just fine; but the way this thing was developed and brought into mainstream use had critical problems in terms of essential information being communicated.

All the decisions and motivations behind these lack of communication have to some point been traced back to trying to circumvent regulations in order to prop up share price by scoring sales of a new airframe of comparable efficiency to the a320neo.

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#123
post #104
post #99

Earlier quoted context omitted.

The hardware isn't faulty. The problem is the way Boeing tried to achieve a zero training delta so pilots wouldn't have to get a second type rating.

the airplane did not have stable flight characteristics because of its physical design. that’s a hardware problem. MCAS only exists because of that hardware problem. the fact that boeing also did not train or tell pilots about MCAS, in order to make the airplane more financially appealing by retaining the 737 type rating, is a separate (also bad) issue.

All jetliners are unstable at altitude in cruise, and require augmentation.

https://en.wikipedia.org/wiki/Yaw_damper

Aircraft design is a giant bag of compromises between desirable characteristics, most which are in conflict with each other.

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#124

All this talk about how mcas was not designed properly or how it could be prevented from failing is eroneous. Good safe airplane design is about a neutral flying design without the need for complex systems. This plane is fundamentally flawed because the engines are in the wrong position because the landing gear is two short to fit them in the correct position. The test pilot was clear about very poor flying character…

FTA: The Max wasn’t handling well when nearing stalls at low speeds.

In a meeting at Boeing Field in Seattle, Mr. Wilson told engineers that the issue would need to be fixed. He and his co-pilot proposed MCAS, the person said.

It is not clear this translates into a fundamentally flawed design. It's a serious assertion, even though at the same time it's vague. Why did it need to be fixed? To avoid pilot training? Or to pass a FAR 25 airworthiness certification requirement? We can't tell from this reporting. Months after these accidents, people are still asking this question. The difference matters.

I'm very skeptical that software can legally be used to paper over aerodynamic flaws, as I read FAR 25. In fact, neutral design is not adequate, it must exhibit positive static and dynamic stability in all three axes. Fly by wire software doesn't make a plane with negative stability behave as if it has positive stability, the software provides various safeguards in a layered manner.

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#125
post #107

Earlier quoted context omitted.

>the airplane did not have stable flight characteristics because of its physical design. This is a gross oversimplification of the problem. In most of the flight envelope the aircraft is stable. At high alpha the aircraft has pitch problems. There are myriad ways to address this, and MCAS was one (bad) choice of many available to Boeing.

I believe the airplane is aerodynamically stable even at high alpha. What it fails in certification is the requirement to have continually increasing pitch feedback forces. I believe the pitch feedback forces are still in the stable region, just too low. This is not a flying wing or intentionally unstable airplane (as the F-16).

I believe the airplane is aerodynamically stable even at high alpha.

That would put you at odds with Boeing's test pilots.

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#126
post #80
post #4

Earlier quoted context omitted.

The problem isn’t failure, but detecting failure. If the sensor had just stopped responding, there wouldn’t have been any problem. The planes would keep flying, the sensors would get replaced, and everyone would be fine. What happened was that the sensor gave erroneous readings. The MCAS system reacted to those erroneous reading and crashes the plane. With two sensors, you can detect failure. It’s very unlikely that…

Would you not need three sensors? With only two, wouldn’t it be difficult to determine which is correct?

You don’t need to determine which is correct. MCAS is not a safety critical system and can just shut down if the sensors disagree.

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#127
post #13

Earlier quoted context omitted.

If you get a reading of 20 on one and 34 on the other, you disregard both and disable the system. There’s a big difference between a system which must work and a system which must not go wrong. For example, the fly by wire system in an Airbus must work. A failed sensor must not disable the system. Thus, you need at least triple redundancy to keep functioning in the event of a failure. Boeing’s MCAS system, on the oth…

There’s a big difference between a system which must work and a system which must not go wrong. For example, the fly by wire system in an Airbus must work. A failed sensor must not disable the system. Thus, you need at least triple redundancy to keep functioning in the event of a failure. Fly-by-wire Boeings still only have two alpha vanes. Go ahead, take a look at the next 777 or 787 you come across.

Presumably the AoA sensors are not required for that system to function.

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#128

How would you design your bureaucracy so that this kind of thing can't happen? I see this type of failure all the time in organizations big and small. Sometimes things are just too complex to have an auteur that can understand the entire system and when every department strives to optimize for its specific goal shit can really hit the fan.

Eventually, artificial intelligence.

Maybe not in the near future, but as technology progresses and every manufacturer strives to optimize their designs with the latest features, it will become an unsourmountable task to oversee every aspect of it (efficiently). I'm not talking about actively designing, but rather for warning/flagging for potential error. In very complex enterprises like global transport or building skyscrappers there is a lot to learn from experience and little human time, but it might be very cost-efective to train all-observing self-learning AI to look over everyone's shoulder, and warn you about using the right type of bolts, or how the coming heavy rains in Guatemala might affect your supply chain.

It's not that far-fetched when you realize it doesn't need to really understand anything, just be very good at playing word association and micromanaging.

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#129
post #28

> a fundamental overhaul to an automated system that would ultimately play a role in two crashes Are they STILL blaming the computer instead of the unstable air-frame after the engines were moved?

The redesign did not make the aircraft unstable. I don't know how this became such a meme, but it's trivial to see that it's not true. Commercial passenger aircraft must be aerodynamically stable by FAA regulation: https://www.ecfr.gov/cgi-bin/text-idx?node=14:1.0.1.3.11#se1... The engine change really wasn't a big deal. The net effect is "flight stick feels lighter at high AoA with high thrust." That's it. My unders…

The meme comes from the fact that according to the technical definition of aerodynamic stability, the MAX has pitch instability at high AoA.

FAA certification regulations appear to be willing to accept minor deviance in regard to them so long as they can be convinced there are sufficient technological controls in place to manage the instability.

This is the danger of self-certification by the way. The company signs off that everything is fine, and the regulator is blissfully unaware they've been rused until after people have already died.

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#130
post #114
post #104

Earlier quoted context omitted.

the airplane did not have stable flight characteristics because of its physical design. that’s a hardware problem. MCAS only exists because of that hardware problem. the fact that boeing also did not train or tell pilots about MCAS, in order to make the airplane more financially appealing by retaining the 737 type rating, is a separate (also bad) issue.

Citation needed. FAR 25 applies to all transport category aircraft. The section on stability (§§ 25.171 - 25.181). In exactly what manner is the airplane not stable, with or without MCAS?

i haven’t looked at the fars in quite a few years, but i’m pretty sure there would be stuff in there that references stuff like pitch stability (which is how i’d define the “hardware problem”), is that not the case? i’m afk atm.

i still maintain my macro point, either way.

making the airframe on a pax airliner aerodynamically stable during normal takeoff and landing operations seems like basic “good engineering” to me.

Post reply on HN