Live data from Hacker News

Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

nytimes.com

21–30 of 280 posts

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#21
post #19
post #16

Earlier quoted context omitted.

> It’s very unlikely that both would fail simultaneously. If they did, it’s very unlikely that both would provide the same erroneous readings. They don't have to fail simultaneously in a flight. And they don't have to fail by internal sensor problems. There are many cases in which they can simultaneously fail and give same readings, article even mentioned such types of events: >> That probability may have underestima…

If they’re damaged on the ground, surely it’ll be noticed that the sensors are claiming an extreme AoA while just sitting there, and they’ll be fixed. AF447 is an example of a fly by wire system that has to keep working no matter what happens, thus a bunch of redundant systems and a series of alternate modes the system can fall back on to operate in a degraded state. MCAS, in contrast, is not a critical system. It co…

> If they’re damaged on the ground, surely it’ll be noticed that the sensors are claiming an extreme AoA while just sitting there, and they’ll be fixed.

AoA sensors by design don't work reliable in low speed and they don't work at all on the ground.

> AF447 is an example of a fly by wire system that has to keep working no matter what happens, thus a bunch of redundant systems and a series of alternate modes the system can fall back on to operate in a degraded state.

AF447 is a good example that two AoA sensors can simultaneously have same erroneous readings. It's not that unlikely.

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#22

“After Boeing removed one of the sensors from an automated flight system on its 737 Max, the jet’s designers and regulators still proceeded as if there would be two.” No, no, no. This is just more of shifting the blame from Boeing upper management. They couldn't use two Angle of Attack (AOA) sensors as when there was a differing reading there would be no way to know the correct reading, which is why MCAS used a singl…

This doesn’t seem correct to me, but I can’t put my finger on why. Surely if both agree that’s more certainty than a single sensor reading. Granted a disagreement would be bad, but at least you would have some warning that one of them is wrong, whereas you would have none at all if relying on a single sensor.

You wouldn’t be able to know which one was wrong but you’d be able to know and annunciate an AOA MISCOMPARE (which was an option on the Max) and then disable MCAS.

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#23
post #19
post #16

Earlier quoted context omitted.

> It’s very unlikely that both would fail simultaneously. If they did, it’s very unlikely that both would provide the same erroneous readings. They don't have to fail simultaneously in a flight. And they don't have to fail by internal sensor problems. There are many cases in which they can simultaneously fail and give same readings, article even mentioned such types of events: >> That probability may have underestima…

If they’re damaged on the ground, surely it’ll be noticed that the sensors are claiming an extreme AoA while just sitting there, and they’ll be fixed. AF447 is an example of a fly by wire system that has to keep working no matter what happens, thus a bunch of redundant systems and a series of alternate modes the system can fall back on to operate in a degraded state. MCAS, in contrast, is not a critical system. It co…

[deleted]

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#24
post #4

Earlier quoted context omitted.

The problem isn’t failure, but detecting failure. If the sensor had just stopped responding, there wouldn’t have been any problem. The planes would keep flying, the sensors would get replaced, and everyone would be fine. What happened was that the sensor gave erroneous readings. The MCAS system reacted to those erroneous reading and crashes the plane. With two sensors, you can detect failure. It’s very unlikely that…

It’s very unlikely that both would fail simultaneously. Birgenair 301 crashed into the Atlantic because mud dauber wasps built nests in both pitot tubes while the plane was on the ground. It happens.

Airspeed is required for safe flight. The failure on that flight was detected immediately, it just couldn’t be handled. AoA on a 737 MAX is not required for safe flight and the system just needs to refrain from taking any action if it fails.

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#25
post #21
post #19

Earlier quoted context omitted.

If they’re damaged on the ground, surely it’ll be noticed that the sensors are claiming an extreme AoA while just sitting there, and they’ll be fixed. AF447 is an example of a fly by wire system that has to keep working no matter what happens, thus a bunch of redundant systems and a series of alternate modes the system can fall back on to operate in a degraded state. MCAS, in contrast, is not a critical system. It co…

> If they’re damaged on the ground, surely it’ll be noticed that the sensors are claiming an extreme AoA while just sitting there, and they’ll be fixed. AoA sensors by design don't work reliable in low speed and they don't work at all on the ground. > AF447 is an example of a fly by wire system that has to keep working no matter what happens, thus a bunch of redundant systems and a series of alternate modes the syste…

Can you elaborate on AF447? I’ve never heard of the AoA sensors being connected with that crash, and a quick search indicates that they were working fine.

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#26
post #4

Earlier quoted context omitted.

The problem isn’t failure, but detecting failure. If the sensor had just stopped responding, there wouldn’t have been any problem. The planes would keep flying, the sensors would get replaced, and everyone would be fine. What happened was that the sensor gave erroneous readings. The MCAS system reacted to those erroneous reading and crashes the plane. With two sensors, you can detect failure. It’s very unlikely that…

It’s very unlikely that both would fail simultaneously. Birgenair 301 crashed into the Atlantic because mud dauber wasps built nests in both pitot tubes while the plane was on the ground. It happens.

According to Wikipedia, only one of the pitot tubes was blocked:

“The investigation concluded that one of the three pitot tubes, used to measure airspeed, was blocked.”

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#27
I really see this as a failure of the Systems Engineering process. With so many people unaware of the impacts of the changes, it’s up to the systems types to have the big picture view and make sure these sorts of things are taken into account.

Especially if as the article says a failure of the AOA sensor on the system would be Hazardous (looks like it was Catastrophic when paired with MCAS in retrospect), that would have made the functional Design Assurance level for this system DAL B, which adds enough rigour not only in the software development process but so much before you even get to that in terms of Safety Assessments and ESPECIALLY change impact analyses when the function changes.

For sure there may have been pressure from management to keep MCAS out of the manual but it’s not really up to he regulatory agency to be experts on the aircraft design, if things are being hidden by the company then I’d consider this bordering on professional misconduct on the parts of the engineers overseeing this work.

I say this as a Professional Engineer working as an aerospace systems engineer.

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#29
post #13

Earlier quoted context omitted.

> With two sensors, you can detect failure You get a reading of 20 on one sensor and get a reading of 34 on the second, which one is correct. To achieve reliability a minimum of five sensors need be used. four primary and one back-up. If three primary agree then system normal. If two primary disagree then switch to backup.

If you get a reading of 20 on one and 34 on the other, you disregard both and disable the system. There’s a big difference between a system which must work and a system which must not go wrong. For example, the fly by wire system in an Airbus must work. A failed sensor must not disable the system. Thus, you need at least triple redundancy to keep functioning in the event of a failure. Boeing’s MCAS system, on the oth…

Yup, the difference between Fail Safe and Fail Operational.

Re: Boeing Built Deadly Assumptions into 737 Max, Blind to a Late Design Change

#30
post #25
post #21

Earlier quoted context omitted.

> If they’re damaged on the ground, surely it’ll be noticed that the sensors are claiming an extreme AoA while just sitting there, and they’ll be fixed. AoA sensors by design don't work reliable in low speed and they don't work at all on the ground. > AF447 is an example of a fly by wire system that has to keep working no matter what happens, thus a bunch of redundant systems and a series of alternate modes the syste…

Can you elaborate on AF447? I’ve never heard of the AoA sensors being connected with that crash, and a quick search indicates that they were working fine.

I've confused AF447's Pitot tubes with AoA sensors. But I think point is still valid: two sensors _can_ simultaneously have same erroneous readings and we have to be sure pilots can handle such situations.
Post reply on HN