Live data from Hacker News

How the Boeing 737 Max disaster looks to a software Developer

spectrum.ieee.org

281–290 of 306 posts

Re: How the Boeing 737 Max disaster looks to a software Developer

#281

Something that stood out to me in this article was the author's opinion of how software developers are removed from the subject matter. From my experience I tend to agree but I hope we can change this. For context, I'm a software engineer and designer with a UX focus. As part of my process to design a system, interface, feature, or fix I first immerse myself into the world of the person who is using the software. Wha…

We're agile now. We don't have a solid view of the problems we need to tackle, we're just given a little user story that says "Plane noses down with these inputs" and we code it up, send it over the wall. The larger the org, the less likely the actual engineers that will design the system are invited to the planning and arch meetings. So when stupid ideas come up in those meetings, there's no one to say "no, that's d…

The Agile Manifesto calls for frequent conversations and demos with customers so developers understand customer needs and acceptance criteria. If you’re given a story card & there is no customer interaction, then there’s a chance the team is calling itself Agile without actually using Agile.

Re: How the Boeing 737 Max disaster looks to a software Developer

#282
post #151
post #74

This is a very good analysis, but fatally incomplete. One really essential reason those planes crashed was that each time the MCAS triggered, it acted like it was the first time. If it added 1 degree of trim last time, it adds a second this time, a third next time, up to the five degrees that runs the trim all the way to the stops. A second reason is that, under the design still on file at the FAA, it could only add…

Regarding #6...Boeing charged $80k to unlock the software feature to gather data from more than 1 angle of attack sensor.

That's 100 false. There are people below you correcting this and you still haven't changed this. The paid option to display AoA information was supposed to be used by military pilots who are familar with how to interpret information from AoA sensors.

Re: How the Boeing 737 Max disaster looks to a software Developer

#283
post #29

Earlier quoted context omitted.

Even then it doesn't matter if your software is "correct" if you don't understand/have not captured all the requirements. You could write a formally verified MCAS system in Coq or whatever that still kills people because you didn't consider the case of sensor failure (because that wasn't in the requirements). Or because you didn't consider the case of double sensor failure or a combination of extremely rare hardware…

This. MCAS was the wrong thing to build. The wrong thing, correctly built, is still wrong, no matter how perfect the formal verification.

So true. The problem is in the system at a higher level. It is not really a software defect that killed all those folks.

Re: How the Boeing 737 Max disaster looks to a software Developer

#284
post #258
post #233

Earlier quoted context omitted.

Will it fly? I think we live in a different world now. The 737 MAX via social media has a perception of being a "Boeing death plane" Public opinion could ground it.

From the people I've spoken to about this, I'd say less than half even know that the 737Max is a thing, never mind that it's crashed twice.

That is very interesting as it's been front-page news regularly in pretty much every newspaper (ok, I only read the NYT and WSJ, but it's quite the topic of discussion on those two papers).

Every time there is news my entire office lights up with discussion about it. Then again, I work for a company called "Pilot" so perhaps people are more interested than average. It's not an aviation company though ;)

Re: How the Boeing 737 Max disaster looks to a software Developer

#285
post #276

Earlier quoted context omitted.

> I would doubt Boeing was accurately able to assess the actual risk of MCAS causing a catastrophic failure or else the decision to rush to market wouldn't have happened. That's most likely because upper management has been cutting staff and not investing in their people. They should be sued and fined out of business. Whoever picks up the pieces will know: "Don't cut corners, or it's absolutely ruins."

I have no clue about Boeing's staffing practices but it's often the case in large organizations that the people trying to prudently hold up a project because it's not ready are looked at less favorably by those with "go-fever". I agree they should be held accountable but there's also blowback from bankrupting one of a nation's major aerospace manufacturers

> I agree they should be held accountable but there's also blowback from bankrupting one of a nation's major aerospace manufacturers

So let there be blowback. Flight costs will go up if they have to, nbd. If there's too big to fail, then just nationalize them and get on with it.

Re: How the Boeing 737 Max disaster looks to a software Developer

#286
post #276

Earlier quoted context omitted.

I have no clue about Boeing's staffing practices but it's often the case in large organizations that the people trying to prudently hold up a project because it's not ready are looked at less favorably by those with "go-fever". I agree they should be held accountable but there's also blowback from bankrupting one of a nation's major aerospace manufacturers

> I agree they should be held accountable but there's also blowback from bankrupting one of a nation's major aerospace manufacturers So let there be blowback. Flight costs will go up if they have to, nbd. If there's too big to fail, then just nationalize them and get on with it.

I meant blowback bigger than just consumers pocketbooks. Issues related to national security because the nation just lost one of it's primary aerospace contractors.

The "too big to fail" issue is an important one, though many Americans tend to hate the idea of nationalization because in their minds it's a social evil.

Re: How the Boeing 737 Max disaster looks to a software Developer

#287
post #179

Earlier quoted context omitted.

Stab trim cutout is not the only way to disable MCAS. Extending the flaps any amount also disables MCAS. Turning on autopilot also disables MCAS, though this isn’t entirely effective since spurious AoA readings may quickly disable the autopilot again.

One question I've had is why Boeing changed the design of the stab cutout switches from the 737NG from a pair of switches - the right side switch that disabled the autopilot control of trim and the left side that disabled the trim motors entirely [1] - to a design with a similar pair of switches, but each controlling the primary and backup control motors of the elevator trim [2] instead of controlling the source of t…

EDIT: Oops, there's only one trim motor on the NG. Both trim switches must be actuated on the yoke switches though. But the input cutoff switches still work the same way I originally stated.

Not sure about the Max's # of trim motors, but the Max definitely doesn't have input source cutoff switches.

Re: How the Boeing 737 Max disaster looks to a software Developer

#288
post #286

Earlier quoted context omitted.

> I agree they should be held accountable but there's also blowback from bankrupting one of a nation's major aerospace manufacturers So let there be blowback. Flight costs will go up if they have to, nbd. If there's too big to fail, then just nationalize them and get on with it.

I meant blowback bigger than just consumers pocketbooks. Issues related to national security because the nation just lost one of it's primary aerospace contractors. The "too big to fail" issue is an important one, though many Americans tend to hate the idea of nationalization because in their minds it's a social evil.

Yeah, it's a tough lesson. We shouldn't put all of our eggs in one basket. We have other aerospace contractors anyway.

Re: How the Boeing 737 Max disaster looks to a software Developer

#289
post #207

Earlier quoted context omitted.

> imagine some nice dirt-loving wasps have built nests in all of your pitot tubes All of them? And I didn't notice any of them during preflight? And none of them were there on the previous flight? And I didn't notice that the airspeed was not alive on the takeoff roll? Not going to happen. > or they've iced over Again, pretty freakin' unlikely on takeoff flying out of Addis Ababa. And this is another thing a pilot ca…

> > imagine some nice dirt-loving wasps have built nests in all of your pitot tubes > All of them? And I didn't notice any of them during preflight? And none of them were there on the previous flight? And I didn't notice that the airspeed was not alive on the takeoff roll? Not going to happen. You underestimate the abilities of people to fuck things up. Birgenair Flight 301 - one tube blocked by mud dauber wasp, lead…

No technology is ever going to completely protect you against an incompetent pilot.

Re: How the Boeing 737 Max disaster looks to a software Developer

#290
post #183

Earlier quoted context omitted.

The airlines knew what they were doing when they didn’t pay for the “upgrade” and they doubly knew when they didn’t pay for it after the first crash. Airline management is just as culpable in this debacle.

This is bonkers. Nobody anywhere in the world should expect that one buys an airplane which is unsafe by design. Also, the idea that there are two versions of a plane, one that kills people and one that doesn't, and if you buy the wrong one that's completely your fault is just insane.

Frankly, you have no idea what you're talking about. This is how the airline industry works. Airlines WANT cheap planes and they ARE WILLING to and DO skimp on some safety features to save money. Airlines WANT safety features, at least some of them, to be optional so that they aren't forced to spend money on them if they don't want them.

For example, backup fire extinguishers in the cockpit? Optional. Extra oxygen masks? Optional. Advanced radar? Optional. There are hundreds of items like this on every model, whether it's Boeing or Airbus or someone else, because their customers WANT them to be optional.

And by the way, not all airlines do this. American paid for the upgrades. Southwest paid for the upgrades.

So maybe you should ask yourself why it is that Lion Air and Ethiopian Air were willing to spend huge amounts of money on a new jet, then spend some $1-$2 million on optional upgrades, and yet not include the MCAS upgrade in those options (and they were made well aware of it, as you can see from other airliners purchase of these upgrades). Or for that matter maybe you should ask why Lion Air knew that the plane was having trouble with the AoA sensors for several flights prior to the crash, and yet did not perform the required maintenance on them (a serious violation) and did not pass along information to its next crews (also a serious violation), who were caught completely unaware.

Airlines run at 2, 3% margin, and they do so by trimming costs at every possible area. Sometimes those areas are safety related. Airlines are not some doe-eyed naive little up who just trust whatever Big Boeing/Airbus tells them. They know how the planes work, they have their own pilots, they have their own engineering teams, they have their own specialists and experts, and they make decisions to sacrifice safety for savings, and they do it ALL THE TIME.

Post reply on HN