Something that stood out to me in this article was the author's opinion of how software developers are removed from the subject matter. From my experience I tend to agree but I hope we can change this. For context, I'm a software engineer and designer with a UX focus. As part of my process to design a system, interface, feature, or fix I first immerse myself into the world of the person who is using the software. Wha…
We're agile now. We don't have a solid view of the problems we need to tackle, we're just given a little user story that says "Plane noses down with these inputs" and we code it up, send it over the wall. The larger the org, the less likely the actual engineers that will design the system are invited to the planning and arch meetings. So when stupid ideas come up in those meetings, there's no one to say "no, that's d…
How the Boeing 737 Max disaster looks to a software Developer
281–290 of 306 posts
Re: How the Boeing 737 Max disaster looks to a software Developer
#282This is a very good analysis, but fatally incomplete. One really essential reason those planes crashed was that each time the MCAS triggered, it acted like it was the first time. If it added 1 degree of trim last time, it adds a second this time, a third next time, up to the five degrees that runs the trim all the way to the stops. A second reason is that, under the design still on file at the FAA, it could only add…
Regarding #6...Boeing charged $80k to unlock the software feature to gather data from more than 1 angle of attack sensor.
Re: How the Boeing 737 Max disaster looks to a software Developer
#283Earlier quoted context omitted.
Even then it doesn't matter if your software is "correct" if you don't understand/have not captured all the requirements. You could write a formally verified MCAS system in Coq or whatever that still kills people because you didn't consider the case of sensor failure (because that wasn't in the requirements). Or because you didn't consider the case of double sensor failure or a combination of extremely rare hardware…
This. MCAS was the wrong thing to build. The wrong thing, correctly built, is still wrong, no matter how perfect the formal verification.
Re: How the Boeing 737 Max disaster looks to a software Developer
#284Earlier quoted context omitted.
Will it fly? I think we live in a different world now. The 737 MAX via social media has a perception of being a "Boeing death plane" Public opinion could ground it.
From the people I've spoken to about this, I'd say less than half even know that the 737Max is a thing, never mind that it's crashed twice.
Every time there is news my entire office lights up with discussion about it. Then again, I work for a company called "Pilot" so perhaps people are more interested than average. It's not an aviation company though ;)
Re: How the Boeing 737 Max disaster looks to a software Developer
#285Earlier quoted context omitted.
> I would doubt Boeing was accurately able to assess the actual risk of MCAS causing a catastrophic failure or else the decision to rush to market wouldn't have happened. That's most likely because upper management has been cutting staff and not investing in their people. They should be sued and fined out of business. Whoever picks up the pieces will know: "Don't cut corners, or it's absolutely ruins."
I have no clue about Boeing's staffing practices but it's often the case in large organizations that the people trying to prudently hold up a project because it's not ready are looked at less favorably by those with "go-fever". I agree they should be held accountable but there's also blowback from bankrupting one of a nation's major aerospace manufacturers
So let there be blowback. Flight costs will go up if they have to, nbd. If there's too big to fail, then just nationalize them and get on with it.
Re: How the Boeing 737 Max disaster looks to a software Developer
#286Earlier quoted context omitted.
I have no clue about Boeing's staffing practices but it's often the case in large organizations that the people trying to prudently hold up a project because it's not ready are looked at less favorably by those with "go-fever". I agree they should be held accountable but there's also blowback from bankrupting one of a nation's major aerospace manufacturers
> I agree they should be held accountable but there's also blowback from bankrupting one of a nation's major aerospace manufacturers So let there be blowback. Flight costs will go up if they have to, nbd. If there's too big to fail, then just nationalize them and get on with it.
The "too big to fail" issue is an important one, though many Americans tend to hate the idea of nationalization because in their minds it's a social evil.
Re: How the Boeing 737 Max disaster looks to a software Developer
#287Earlier quoted context omitted.
Stab trim cutout is not the only way to disable MCAS. Extending the flaps any amount also disables MCAS. Turning on autopilot also disables MCAS, though this isn’t entirely effective since spurious AoA readings may quickly disable the autopilot again.
One question I've had is why Boeing changed the design of the stab cutout switches from the 737NG from a pair of switches - the right side switch that disabled the autopilot control of trim and the left side that disabled the trim motors entirely [1] - to a design with a similar pair of switches, but each controlling the primary and backup control motors of the elevator trim [2] instead of controlling the source of t…
Not sure about the Max's # of trim motors, but the Max definitely doesn't have input source cutoff switches.
Re: How the Boeing 737 Max disaster looks to a software Developer
#288Earlier quoted context omitted.
> I agree they should be held accountable but there's also blowback from bankrupting one of a nation's major aerospace manufacturers So let there be blowback. Flight costs will go up if they have to, nbd. If there's too big to fail, then just nationalize them and get on with it.
I meant blowback bigger than just consumers pocketbooks. Issues related to national security because the nation just lost one of it's primary aerospace contractors. The "too big to fail" issue is an important one, though many Americans tend to hate the idea of nationalization because in their minds it's a social evil.
Re: How the Boeing 737 Max disaster looks to a software Developer
#289Earlier quoted context omitted.
> imagine some nice dirt-loving wasps have built nests in all of your pitot tubes All of them? And I didn't notice any of them during preflight? And none of them were there on the previous flight? And I didn't notice that the airspeed was not alive on the takeoff roll? Not going to happen. > or they've iced over Again, pretty freakin' unlikely on takeoff flying out of Addis Ababa. And this is another thing a pilot ca…
> > imagine some nice dirt-loving wasps have built nests in all of your pitot tubes > All of them? And I didn't notice any of them during preflight? And none of them were there on the previous flight? And I didn't notice that the airspeed was not alive on the takeoff roll? Not going to happen. You underestimate the abilities of people to fuck things up. Birgenair Flight 301 - one tube blocked by mud dauber wasp, lead…
Re: How the Boeing 737 Max disaster looks to a software Developer
#290Earlier quoted context omitted.
The airlines knew what they were doing when they didn’t pay for the “upgrade” and they doubly knew when they didn’t pay for it after the first crash. Airline management is just as culpable in this debacle.
This is bonkers. Nobody anywhere in the world should expect that one buys an airplane which is unsafe by design. Also, the idea that there are two versions of a plane, one that kills people and one that doesn't, and if you buy the wrong one that's completely your fault is just insane.
For example, backup fire extinguishers in the cockpit? Optional. Extra oxygen masks? Optional. Advanced radar? Optional. There are hundreds of items like this on every model, whether it's Boeing or Airbus or someone else, because their customers WANT them to be optional.
And by the way, not all airlines do this. American paid for the upgrades. Southwest paid for the upgrades.
So maybe you should ask yourself why it is that Lion Air and Ethiopian Air were willing to spend huge amounts of money on a new jet, then spend some $1-$2 million on optional upgrades, and yet not include the MCAS upgrade in those options (and they were made well aware of it, as you can see from other airliners purchase of these upgrades). Or for that matter maybe you should ask why Lion Air knew that the plane was having trouble with the AoA sensors for several flights prior to the crash, and yet did not perform the required maintenance on them (a serious violation) and did not pass along information to its next crews (also a serious violation), who were caught completely unaware.
Airlines run at 2, 3% margin, and they do so by trimming costs at every possible area. Sometimes those areas are safety related. Airlines are not some doe-eyed naive little up who just trust whatever Big Boeing/Airbus tells them. They know how the planes work, they have their own pilots, they have their own engineering teams, they have their own specialists and experts, and they make decisions to sacrifice safety for savings, and they do it ALL THE TIME.