The only way to be 100% safe and 100% fool proof is to not fly. For a mechanical system as complex as an airplane, triple redundancy with a good pilot is pretty much the best you can hope for.
Lack of redundancies on Boeing 737 MAX baffles some involved in developing it
91–100 of 163 posts
Re: Lack of redundancies on Boeing 737 MAX baffles some involved in developing it
#92Earlier quoted context omitted.
But management also relies on customers to tell them which compromise is vital to selling a product. And in a market with such huge price-pressure as aeronautics, I can easily see how this is going to override engineer's concerns.
I don't think that any Boeing customer have said or implied that it's OK if a plane can crash as long as they save up on pilot training.
Re: Lack of redundancies on Boeing 737 MAX baffles some involved in developing it
#93Earlier quoted context omitted.
> the next gen aircrafts would only require a single person in the cockpit, and everything will be handled through automations. Hasn't that myth been around for years, along with "Planes can take off and land by themselves?" https://www.askthepilot.com/questionanswers/automation-myths...
He may be right for the state of what has actually been wired up in today’s cockpits, but conceptually I don’t see why you couldn’t fully automate a plane. Even in emergency situations, pilots are required to follow established procedures and check lists, not become creative. The pilot mentions the example of an aborted take off, I can’t think of any reason an auto pilot wouldn’t be able to perform one. And of course…
every nut and bolt can and will break. every component load increase battery size and generator load, carrying a greater risk for fires.
if you go down the path "automate with manual backup" then you introduce even more fault-prone systems: the circuitry that disable automation might be faulty and can be another fire risk all of itself and the conflict between faulty automation and manual overrides could be itself an aggravating issue in an emergency.
and even if your plane is perfect, you have to live in an imperfect environment (same argument as car autopilots really): other plane around you might have an emergency, forcing your to delay landing. the airport might have an emergency, forcing a detour, the ils could break down, even on final.
it's exceedingly hard to write software that handles the common cases well enough, imagine having to write software to handle also the unforeseeable faults.
> remote control
and this introduces a whole new topic: systems rarely used are the ones with the more reliability issues. both manual and remote override, on top of being more stuff with their own failure modes, would be rarely tested in practice until the moment they'd be needed the most.
Re: Lack of redundancies on Boeing 737 MAX baffles some involved in developing it
#94Earlier quoted context omitted.
Yep, 3 sensors can fail too. Less often however. These sensors exist to solve a problem with the MAX design. Changing and moving the engines increased the likelihood of a stall when the engines could push the nose up (as I understand it). Fine. But here's the kicker: this should be something that pilots should be trained on. They should be aware of how the MAX is different to the previous 737s and know what to do to…
The pilots were trained on how to deal with a runaway trim stabiliser. The procedure hasn't changed from the old 737, the only thing that has changed is that it is that the failure mode is more likely to occurr on the 737 MAX. From the article: “A properly trained pilot should be able to solve an MCAS anomaly or any uncommanded flight-control input through procedures that are taught to all 737 pilots,” said Menza, no…
https://www.wsj.com/articles/ethiopian-airlines-pilots-initi...
Re: Lack of redundancies on Boeing 737 MAX baffles some involved in developing it
#95Earlier quoted context omitted.
I don't think that any Boeing customer have said or implied that it's OK if a plane can crash as long as they save up on pilot training.
Didn't they "vote with their wallets"?
Re: Lack of redundancies on Boeing 737 MAX baffles some involved in developing it
#96Earlier quoted context omitted.
Yep, 3 sensors can fail too. Less often however. These sensors exist to solve a problem with the MAX design. Changing and moving the engines increased the likelihood of a stall when the engines could push the nose up (as I understand it). Fine. But here's the kicker: this should be something that pilots should be trained on. They should be aware of how the MAX is different to the previous 737s and know what to do to…
If there were specific steps that the pilots could have taken to avert disaster, why not just incorporate them into the flight software? Why resorting instead to "reprogramming" the pilot? That's what training is: programming of the human brain. One can't teach others without having first learned the lesson oneself. I'm not convinced Boeing has. I'm not convinced the company had adequately consider all possible scena…
This is by design. The flight software is deliberately kept simple enough that the pilots can be trained to understand the full workings of the flight software and what it will do in any situation.
The entire flight control algorithm is probably only a few hundred lines of psudocode.
It's a catch 22:
We are fully capable of designing a plane that safely flys itself from airport to airport without any pilots, to handle most emergency situations. We have been able to do so since the 80s.
But we are not able to put a pilot in the loop on such a plane without massive safety implications. To have a pilot in the loop, the software has to be kept super simple so the pilot can diagnose it in an emergency and take the correct action.
Either we have the flight software that is situational aware and authorised to take any action, or we have a super simple software and a pilot in the loop. There is no safe middle ground.
Re: Lack of redundancies on Boeing 737 MAX baffles some involved in developing it
#97Earlier quoted context omitted.
The pilots were trained on how to deal with a runaway trim stabiliser. The procedure hasn't changed from the old 737, the only thing that has changed is that it is that the failure mode is more likely to occurr on the 737 MAX. From the article: “A properly trained pilot should be able to solve an MCAS anomaly or any uncommanded flight-control input through procedures that are taught to all 737 pilots,” said Menza, no…
Per initial reports the black box data suggests that the procedure was followed, but the MCAS was re-engaged, looks like investigations are ongoing if the MCAS can re-engage automatically or if the trim was too hard to manually override and re-engaged by the pilots to be able to use the electric trim to level the plane. https://www.wsj.com/articles/ethiopian-airlines-pilots-initi...
Did the pilots fail to notice the MCAS problem before it put the plane too far out of trim?
Could they have saved the plane if they stuck to the procedure and kept adjusting the trim by hand?
Why does MCAS override even direct pilot trim up commands?
Is the runway trim procedure even viable on older 737s once the trim goes past a certain point? Or are we just lucky that it never happens?
Re: Lack of redundancies on Boeing 737 MAX baffles some involved in developing it
#98I am a designer and implementor of vital speed and distance measurement systems, with triply modular redundancy, used in mass transit application. I cannot even imagine what the designers of this thing are going through now. It must be terrible. To make it worse, it's a confusing topic. There are two pillars to the design of such system. 1. Faulty sensor must be detected with a very high probability. The typical way…
I can't even imagine a sensor failure having zero redundancy, much less changing control inputs to a complicated system like a multi-engine jet. This is completely against everything I know about engineering and I find even discussion of this being possible to be deeply offensive. The fact that it happened twice and hundreds of people are dead is just mind boggling.
Re: Lack of redundancies on Boeing 737 MAX baffles some involved in developing it
#99Earlier quoted context omitted.
Yes there is. If you put too many sensors then there is always one in need of repair. And then it becomes dangerous: the pilot and maintainer ignores the alarm, delay replacement, leading slowly to a failure. This is why the redundancy choices and availability calculations should always be made pondering the maintenance burden.
Well, I've been working in mass mobility and they had 4x redundancy with different sensor types. The more sensors went bad, the more restricted the operation regime became as it went through degraded modes. And the on-board systems were of course aware of the status of the sensors. I think that created the right incentives: you could ignore a faulty sensor or two, but the results were increased travel times, so costs…
Re: Lack of redundancies on Boeing 737 MAX baffles some involved in developing it
#100Earlier quoted context omitted.
Maybe the problem hasn't been shouted from a high enough rooftop yet.
Or more likely it doesn't really matter, and in a couple years nobody will really remember this about Boeing. They'll go back to being a big airplane producer that has a stunning safety record, which they are despite this issue.
Yes, mistakes were made, yes, we should find ways to avoid this happening in the future, no, automation isn't the enemy. Without automation in flying at the current number of airplanes in the sky we'd probably have one or two crashes a day. The fact that 2 crashes in half a year make the news is thanks to the amazing safety of modern airplanes.