Live data from Hacker News

Preliminary report into Air India crash released

bbc.co.uk

911–920 of 924 posts

Re: Preliminary report into Air India crash released

#911

Earlier quoted context omitted.

It could be defective switch springs, fatigue-induced muscle memory error, or something else. The pilot who did it saying he did not may not have realized what he did. It's pretty common under high workload when you flip the wrong switch or move a control the wrong way to think that you did what you intended to do, not what you actually did. That said Boeing could take a page out of the Garmin GI275. When power is re…

Delay is probably worse - now you're further disassociating the effect of the action from the action itself, breaking the usual rule: if you change something, and don't like the effect, change it back.

There is a relatively short window where dual engine shutdown is unrecoverable. Once you have a bit of altitude (and these jets climb at 2000-3000fpm) you have time for a restart and as thrust comes back sink rate will decrease even on one engine.

My proposal is during this window if dual engine shutdown is commanded don't do it. Treat it like it is happening - show the EICAS message, give the alert, but don't actually do the shutdown until the window has passed. This gives the pilots 10 seconds of startle factor then a bit of time to flip the switch back on.

Single engine shutdown would still behave as today so sure if one engine eats a fan blade shut it down. Not that it matters, the engine computer is going to cut fuel in that case anyway.

Insert a delay only for shutting down the remaining engine and only for X seconds after transition to air mode. A delay that the fire handle overrides.

Just a tiny bit of insurance. There aren't any emergency scenarios at low altitude where engine shutdown works but pulling the fire handle does not. You are coming right back to land at the airport no matter what.

Re: Preliminary report into Air India crash released

#912

Earlier quoted context omitted.

This is a place that puts "Hacker" in the name despite the stigma in the mainstream. Given the intended meaning of the term, I would naturally expect this to be a place where people can speculate and reason from first principles, on the information available to them, in search of some kind of insight, without being shamed for it. You don't have to like that culture and you also don't have to participate in it. Making…

> That said Boeing could take a page out of the Garmin GI275 This is not "reasoning from first principles". In fact, I don't think there is any reasoning in the comment. There is an implication that an obvious solution exists, and then a brief description of said solution. I am all for speculation and reasoning outside of one's domain, but not low quality commentary like "ugh can't you just do what garmin did". This…

First I am a pilot. Not commercial or jet rated but I like to think I have a tiny bit more insight than average.

The point of what GI275 does is as a backup instrument you are much more likely to need it when the electrical system fails or is turned off due to fire. Yet if it just remains on until shutdown pilots would frequently forget to turn it off on the ground, resulting in its battery being worn out. Because it is considered critical it delays its own shutdown. Long enough for you to notice in flight but not so long it wears out the battery (which might result in only a few minutes of power in a real emergency).

My entire point was that engine restarts take some time. If both engines eat a blade or catch fire you are screwed anyway so whether or not the fuel cutoff switch does anything at 1500ft is irrelevant. But that is so rare I don't think we have any events on record. So it might be worth inserting a delay - enough to account for standard climb rates to achieve enough altitude to make restart likely or at least possible. The delay would only be for the second engine shutdown and only for time T after going into air mode. And if the system gets it wrong, thinking the other engine is shutdown when it is not pulling the fire handle would override any delay - and pulling the fire handle is part of any engine failure or departed aircraft procedure I know of. In other words you wouldn't even need to change the QRH or emergency checklists in most cases.

I noted that engineering for aviation is complex and everything has failure modes to consider. Privately I went through several iterations of this idea and discarded them for problems with failure modes and complexity. What I proposed is boiled down to the minimal thing that would have saved this flight.

The other thing I'll say is there is a reason the computer will auto-extend some flaps/slats at slow speed even if you put the handle to zero. And there's a reason auto-throttle provides protection. And with the exception of the 737 the computer auto-starts the APU on dual engine failure. And any attempt to deploy thrust reversers in the air is ignored. And stick pushers exist for good reason.

We put in all kinds of measures to override human decisions to prevent mistakes and errors.

Re: Preliminary report into Air India crash released

#913

Earlier quoted context omitted.

This is a place that puts "Hacker" in the name despite the stigma in the mainstream. Given the intended meaning of the term, I would naturally expect this to be a place where people can speculate and reason from first principles, on the information available to them, in search of some kind of insight, without being shamed for it. You don't have to like that culture and you also don't have to participate in it. Making…

For me it's mainly about intent/unearned confidence. If someone is speculating about how such a problem might be solved while not trying to conceal their lack of direct experience, I'm fine with it, but not everyone is. If someone is accusing the designers of being idiots, with the fix "obvious" because reasons, well, yeah, that's unhelpful.

For the record I don't think the designers of the switch or Boeing are idiots. The switches have guard notches and the throttle quad has metal guard edges to help prevent accidental activation.

As far as we know this is the first accidental dual engine cutoff at low altitude; with just a bit more altitude (not sure of how much exactly) the engine that had restarted and was ramping would have started producing enough thrust to arrest their descent. That makes the margin of "unrecoverable" a lot smaller than you might initially think.

Bottom line is it is worth considering implementing some protection here:

  1. It can be done in software without a lot of complexity
  2. The transition to "air mode" is relatively reliable.
  3. The failure scenario is the system doesn't provide the protection but because the failure we protect against is very rare that is acceptable
  4. It typically fails "safe": allowing shutdown without delay and worst case is a delay in shutdown.
  5. The fire handle overrides delay; if things are going so wrong the delay matters the engine isn't coming back and pulling the fire handle is likely already part of your checklist.
The benefit being elimination of the small window after takeoff where accidental dual engine shutdown is unrecoverable.

Obviously before implementing something like this the proper engineering and failure analysis has to be done.

Re: Preliminary report into Air India crash released

#914
post #862
post #661

Earlier quoted context omitted.

The murder suicide angle isn't particularly worthy of assumption yet. Have you ever put your phone in the fridge? Pilots deactivate the fuel cutoff at the end of the final taxi to the gate. This makes flipping these switches a practiced maneuver , capable of being performed without conscious thought, regardless of whether they came with safety locks installed. Brain farts are a real phenomenon, and an accidental fuel…

The evidence points to inadvertent fuel cutoff switch movement rather than pilot error, or intentional pilot action. Most likely cause being locking mechanism failure combined with takeoff acceleration forces. Investigation and preliminary report is not showing critical evidence that would help clarify. Like the full transcript of pilot conversations that is clearly already available, and if these switches had any ma…

[deleted]

Re: Preliminary report into Air India crash released

#915
post #869

Earlier quoted context omitted.

I was deferring to the judgement of the local people. I was not making my own decision on the tradeoffs. Also, your implication that the tradeoff is lives is unfair, I don't think that's the tradeoff, rather I think they were expecting that other types of alerts would be sufficient.

You're deploying a recent disaster, that killed scores of people, as evidence that people want something done when it isn't appropriate - and you aren't even willing to take a stance on whether what was done was appropriate? That's pretty weak tea. It really undermines your argument. If you aren't willing to take a stand on that, use a different example. Otherwise you aren't saying anything. You're calling on people…

You're not quite understanding me, and I can see it's because I was not very careful in how I wrote, and that's on me.

But I'm going to let this drop because I would basically have to start over to explain myself, and I don't think there's any useful purpose in doing so.

Re: Preliminary report into Air India crash released

#916

Earlier quoted context omitted.

Same manufacturer, Air India 171 was a 787-8 though.

The affected table includes these models as well: 787-8, -9, and -10

Yes, the S.A.I.B. was about the switch, which is used in many airplanes, and _should_ be checked and replaced. But they didn't. Because it wasn't mandatory. So my guess is those 50-70€ per switch were too expensive for the airline?

They reported that they replaced the whole middle console twice, so I cannot accept the 'it's pricey' or 'it's non-mandantory' as an excuse.

Hackers gona hack, so I'd like to get my hands on those switches, or better the whole fuel control panel. The pictures don't let me see or feel if a loose front panel could lift those shiny glowy locking knobs up by, say, 2.3mm and therefore unlock those switches, for example.

Only picture I could find online about this malfunctioning switch:

https://www.xuefeiji.org/public/uploads/weixin_mpimgs/e3/e36...

which looks like a really nasty 'mechanical inadequacy': half of the locking mechanism is the shiny glowy knobs. And they could _turn_. WTHolyF!? What where they smoking when designing or reviewing this?

In this fine post here, if you can read chinese or click the translation button on your browser:

https://www.xuefeiji.org/bbs/show-294.html

(CAVE: I'm not inside boeing's tech support system so I cannot verify this from the original maintainance manual, since they seem to be practically guarded as trade secrets...)

I tried to order some of those switches (766AT613-3D and 766AT614-3D) and hope they get delivered ... this year. Anyone here got their hands on those switches to test their feel when handling or their resiliency?

(My hypothesis is:

Hand on throttle, Hand pushes throttle full forward to start, Hand rests on throttle while accellerating, then pilot does the routine rotate and plane takes of and all is fine and Hand lets go of throttle, Hand falls on both switches directy behind the throttle: Click-click-WTF?-BOOM.)

Of Course almost anyone involved in the airplane industry would prefer this to be a clear-cut case of 'pilot error' or 'Terrorism/Insanity' - but that doesn't exnorate the manufacturer or owner of building and flying an airplane where the engines can be shut off while taking off, IMHO.

As an aside, I especially like the disclaimers on the last page of Honeywells catalogue (this one: https://www.farnell.com/datasheets/2604543.pdf) - don't use it for anything safety-of-live related. - if it breaks because we delivered junk, we'll replace the switch - nothing else.

(I'm paraphrasing. Some laywers migth find a way to get out of this. I hope Boeing doesn't.).

Re: Preliminary report into Air India crash released

#917
post #661

Earlier quoted context omitted.

The murder suicide angle isn't particularly worthy of assumption yet. Have you ever put your phone in the fridge? Pilots deactivate the fuel cutoff at the end of the final taxi to the gate. This makes flipping these switches a practiced maneuver , capable of being performed without conscious thought, regardless of whether they came with safety locks installed. Brain farts are a real phenomenon, and an accidental fuel…

If it were possible for a trained pilot to "brain fart" cut fuel to a 787 as it is taking off that would be a huge design flaw.

Did I hear "Design Flaw"? On a Dreamliner??

Well I'd Never sputter Good Ma'am or Sir, ARE you implying something like a "MAIN BATTERY EXHAUST"¹ retrofitted to a flagship product because management was impatient and wanted the lighter, better, faster, stronger lithium-ion-battery for their rushed 787-sized baby?

¹) https://media.cnn.com/api/v1/images/stellar/prod/14011413401...

Re: Preliminary report into Air India crash released

#918

Earlier quoted context omitted.

https://ad.easa.europa.eu/ad/NM-18-33 well hold your horses there... from the FAA in their 2019 report linked above: > The Boeing Company (Boeing) received reports from operators of Model 737 airplanes that the fuel control switches were installed with the locking feature disengaged. The fuel control switches (or engine start switches) are installed on the control stand in the flight deck and used by the pilot to sup…

Totally different airplane with a totally different flight deck, designed generations apart. The fact that the manufacturer is the same is irrelevant. You are trying to draw parallels between the ignition switch in a 1974 Ford Pinto and a 2025 Ford Mustang as if there could be a connection. No.

There Is a connection: The same type and make of switches, which already where officially found to be prone to subtle malfunction and ought to be checked and replaced. Read the SAIB. Look at the switches. https://www.xuefeiji.org/public/uploads/weixin_mpimgs/e3/e36...

Your argument of being "totally different" flight decks or fordy ignition switches aside (ignoring that one is allowed to to drive both mentioned cars using the same license, but not two different generations of airplanes, ignoring that the biological concept of generation implies kinship), this affair reminds me of https://en.m.wikipedia.org/wiki/General_Motors_ignition_swit...

Re: Preliminary report into Air India crash released

#919

Earlier quoted context omitted.

> It's difficult to conclude anything other than murder-suicide. You're leaping into the minds of others and drawing conclusions of their intent. One of them moved the levers. It could've been an unplanned reaction, a terrible mistake, or it could've been intentional. We may never know the intention even with a comprehensive and complete investigation. To claim otherwise is arrogance.

The car equivalent is being on a highway and "mistakenly" pulling the hand brakes, except that there are 2 hand brakes and you need to first unlock both of them. That's very hard to do by panic and mistake, if not impossible by design.

Nope, I strongly disagree with that comparison. One doesn't need to pull up a big stick in hand using elbow and shoulder to flip this fuel switch _down_. Would a car's hand brake stop your engine if it's thumb-push-button lock failed silently and you happen to let something fall on it, like a hand? no. But this little fuel switch would.

Re: Preliminary report into Air India crash released

#920
So many garbage takes here - this report wants to imply pilot error and without all the data/audio that remains a remote possibility but the truth is it is far more likely that this plane experienced a total electric failure following liftoff and the onboard computer entered some form a failsafe mode which set the fuel valves to a default closed state.

The pilots were likely immediately trying to relight the engines which is the correct reponse but sadly they didn't have the altitude to see the process through.

My guess is the truth here (i.e. Boeing equipment malfunction) or at least the framing of it is being used as a chip in trade deal negotiations which are active and ongoing.

Post reply on HN