Hacker News new | ask | show | jobs
by laydn 1650 days ago
There are ~600 delivered MAX aircraft, and ~4700 still on order (including all the cancelled orders).

I don't know where you live and how often you fly and for what purpose, but, chances are, a lot of people be somewhat forced to fly on a 737 Max eventually.

2 comments

Why would anyone be scared to fly on the most scrutinized plane in history? I certainly don't care. All of the pilots flying the MAX would now receive even more in-depth training on the quirks of the new systems.

Chances of critical incident are practically zero. 180 countries have re-certified the plane and design changes were made as well.

If you don't trust the FAA or the 179 other authorities, how do you step on ANY plane?

Additionally, you don't trust the MAX yet you trust Boeing (you didn't mention their other planes)? If Boeing is negligigent, it's unlikely it's limited to a specific product. How can you then trust maintenance programs and spare parts provided by Boeing for the Dreamliner for example?

If Boeing is incompetent, trusting the Dreamliner but not the MAX is irrational.

> All of the pilots flying the MAX would now receive even more in-depth training on the quirks of the new systems.

One of the main issues was that, apart from an hour on an iPad pilots didn't receive training at all.

"even more training" is disengeneous and makes you sound like a shill. I'm sorry to say.

E: spello

Pilots are trained in dealing with stabilizer trim runaway. The first crew to encounter the MCAS problem followed it (turned off the stab trim system), and landed safely. The second crew, on the same airplane, did not and crashed. (They never turned off the stab trim system.)

http://knkt.dephub.go.id/knkt/ntsc_aviation/baru/2018%20-%20...

Boeing followed this up with an Emergency Airworthiness Directive, which was distributed to all MAX crews. It included a 2-step process for recovery.

The EA crew did not follow that procedure:

"Initially, higher control forces may be needed to overcome any stabilizer nose down trim already applied. Electric stabilizer trim can be used to neutralize control column pitch forces before moving the STAB TRIM CUTOUT switches to CUTOUT. Manual stabilizer trim can be used before and after the STAB TRIM CUTOUT switches are moved to CUTOUT."

https://theaircurrent.com/wp-content/uploads/2018/11/B737-MA...

This does not absolve Boeing of the design flaw in MCAS where it only read data from one sensor, had too much authority, and would repeatedly engage after the pilot countermanded it.

You obviously know way more than I do about this, so maybe I completely misunderstood but what I saw on one of those YouTube videos by a 737 pilot was something like that before MCAS when you got a runaway trim situation and followed the procedure and got trim back to normal and had the trim system turned off, most of the time you could turn the trim system back on and the problem would not come back. Runaway trim was usually due to some transient problem that would be gone after the system was turned off and on.

In those cases where the problem does come back it is not any worse so you can just try again. You might go a whole flight doing this if you are getting enough time between the problem recurring for restarting the trim stab system to be less annoying than not having it.

With MCAS, if I understood correctly, it would add a bias to the trim that was not reset when you restarted the trim system. Each cycle of turning it off and back on that was harmless pre-MCAS would increase that bias until you reached a point where the trim down bias was more than you could counter.

This wouldn't matter for the flights that crashed, because they didn't get to the turn it off stage, but it seems likely it would have eventually happened to some crew that did follow the procedure including the emergency directive.

The impression I got from this, and from watching many episodes of "Air Emergency", is that there is the official way to operate a plane as documented by the manufacturer, and then the unofficial way that pilots actually use that comes from combining the official way with the pilot's mental models of how the systems work to cover what can actually be done. So if the official way says to turn something off, but does not say "and then keep it off until a mechanic checks it out", and the pilot's mental model says that it is safe to turn back on, then they might turn it back on.

MCAS invalidated the mental model pilots had for the stab trim system, but the MAX-specific training they got and the emergency directive after the first crash did not do anything to tell pilots that their model was invalid.

When documenting a system and training people to use it, you really need to take into account the mental model they will have of the system. It is their mental model that people actually use to guide their interaction with the system.

The second flight totally did get to the turn-it-off stage. They turned it off multiple times. Unfortunately, during that process, they neglected to manage their throttle, leaving it at near full takeoff thrust the whole time, and reached a very high speed. Thus, while they could turn off MACS, they were unable to manually restore trim with MACS off due to the strong physical forces on the stabilizer. There was probably a recovery path for them where they lowered speed, then corrected the trim manually, but they didn't see it.

Some day, there will be an AdmiralCloudberg write up on it, but he hasn't done it yet: https://www.reddit.com/r/AdmiralCloudberg/

In the Internet era, I can directly access reports from leading experts. Why would I be interested in a reddit user?
I mean, that's all well and good, but assuming that your pilots will correctly diagnose and correct a failure of a new system that may or may not have similar symptoms to existing emergencies is still a really poor practice. If MCAS had been designed to command a continuous forward pitch moment until the AOA excursion had resolved, it would have very accurately resembled a pitch trim runaway following an AOA probe failure. As it was, it clearly didn't have a strong enough resemblance.

Safely operating a poorly designed aircraft can be done, but it starts with explaining the deficiency in exhaustive detail in a bold typeface in a prominent place in the operating manual, with clear warnings to avoid certain flight regions, and a well-documented emergency procedure. For example:

MCAS FAILURE: If you experience repeated momentary uncommanded nose-down pitch excursions. 1. Conduct RUNAWAY PITCH TRIM procedure. 2. Do not reset pitch trim circuit .

Unfortunately that would have required new training.

Runaway stab trim is very easy to diagnose. The airplane pitches, the two big wheels on either side of the console start spinning, and there's a loud clacking sound.

The MCAS failure exhibited as runaway trim.

> it clearly didn't have a strong enough resemblance.

I disagree. The trim randomly and repeatedly coming on and driving the pitch down is runaway trim.

> a well-documented emergency procedure

Like this one distributed to ALL 737MAX crews:

Boeing Emergency Airworthiness Directive

"Initially, higher control forces may be needed to overcome any stabilizer nose down trim already applied. Electric stabilizer trim can be used to neutralize control column pitch forces before moving the STAB TRIM CUTOUT switches to CUTOUT. Manual stabilizer trim can be used before and after the STAB TRIM CUTOUT switches are moved to CUTOUT."

https://theaircurrent.com/wp-content/uploads/2018/11/B737-MA...

>Like this one distributed to ALL 737MAX crews:

...after their poorly designed system caused a plane crash.

If you have a 737 type rating and can speak to type-specific training standards I would love to be educated, but the defining characteristic of runaway trim failures that I've experienced is that the trim keeps going in one continuous motion until it can't go any further or you manually shut off the system. A momentary, uncommanded attitude change would initially make me want to troubleshoot the autopilot, rather than the trim system. This is exactly why you have to describe new systems and their failure modes in detail, even if they have elements in common with and use the same emergency procedures as existing failures.

And again, victim blaming instead looking at the real perpetrator that is Boeing
It is the pilots' responsibility to READ, UNDERSTAND, REMEMBER and FOLLOW any Emergency Airworthiness Directives sent to them. Flying an airplane is not a joke. Pilots who are unwilling to do this should turn in their pilots' wings.

Crashes are usually due to a combination of factors. Boeing certainly shares considerable blame for the poorly designed MCAS system.

More issues:

1. how did a defective AOA sensor get past checks and be installed?

2. how did a defective AOA sensor pass inspection tests on the airplane?

3. why was the LA flight allowed to fly, when the previous flight experienced stab trim runaway?

4. why was the LA flight crew not informed of the anomalous behavior on the prior flight?

Air travel is made safe by addressing all factors that led to an accident.

The second design flaw is manufacturing stretched airplanes in the first place, which are hacks in general. Even as an amateur one can see that the proportions are off without understanding anything else. They look ugly and fly ugly.

The stretched cargo version of the MD-11 had many issues and accidents, particularly during landing.

> an amateur

While there is something to the notion that if it looks like it will fly it will fly, remember that the general configuration of modern airplane design took many, many years to settle down on. Even the Wrights got it wrong (putting the stabilizer in the front made it unstable).

The notion of swept wings, that seems so natural today, was a very long time in coming, for another example.

For a third, the aerospace people keep finding ways to make the wings more efficient. Notice the winglets on the wingtips? Those are fairly new.

I don't work for nor hold stock in any airline or aviation manufacturer, I can just adequately judge risks.

You are the one who thinks 180 separate, independent regulators colluded to protect a company at the risk of the people they are supposed to protect. Any argument against the MAX has to be against the regulators as well as Boeing itself.

Why is the Dreamliner acceptable and the MAX is not? Same company manufactured and maintains them, after all.

> Why is the Dreamliner acceptable and the MAX is not?

I remember [1?] hearing that Emirates threatened refusing 777s & 787s from one of Boeing's plants due to repeated quality control issues. Have not tracked the issue.

> 180 separate, independent regulators colluded to protect

Not necessarily. But if 180 _independent_ bodies were effectively independent, one of them would probably have found issues with the max. But they are not operating effectively independent.

[1] https://www.reuters.com/world/middle-east/emirates-doubts-fi...

The plant with the quality control issues is the non-unionized one.
The MAX (before design updates and re-certification) has a fatal crash rate of 3.08 per million. Meanwhile 11.9 per 100,000 people die in car crashes.

The MAX, before being fixed, was significantly safer than a car.

Do you refuse to get in a car, since it's substantially more deadly than a MAX?

Different airframes. Different issues here.
I think he means more training now.

Not really disingenuous at all.

What’s remarkable is that MCAS functioned so well that not a single pilot had noticed it prior to Lion Air.
Why would anyone be scared to fly on the most scrutinized plane in history?

Finding a bug is not the same as fixing a bug, and finding lots of bugs doesn't mean you've found them all.

So I imagine your position is that the software industry should swear off products altogether when they have a serious bug, right?

Did you make a conscious effort to rid yourself of OpenSSL after Heartbleed? After Heartbleed, OpenSSL received mountains of extra funding as well as unprecedented scrutiny.

Guess what happened after the MAX disasters? Extra funding and unprecedented scrutiny. In fact, no plane has been scrutinized more.

"Most scrutinized" means that you might have a fair chance at finding a higher proportion of them, though.
That's not what was being talked about. Sure, it's the safest aircraft out there, but that's like saying "the safest car". No-one is going to go and seek out the safest car, maybe stay away from unsafe ones, but as long as the general level of safety is high, people will fly on anything.

The problem here is just simply ethics. Boeing did a bad thing, therefore I will refuse to use this plane. If enough people think similarly, Boeing will be punished harshly by its clients, as airlines see that the plane is not profitable due to its public image.

The problem is not about if the MAX is the safest airplane now. If Boeing can get away with it like that then it lowers the general airplane safety in my opinion. Now that Boeing has designed an airplane by cutting corners to safe money (even though it did cost them a lot, the government saved them), then this means that other airplane manufacturers must also cut corners to stay competitive.
You seem to be labouring under the illusion that airliner manufacturing is a competetive industry. But i'm not aware that Boeing has any real competitior other then airbus. The phrase "to big too fail" looms very large and is very real here. So no, this won't have an adverse affect outside of Boeing. The real problem is the culture that allows such a disaster and then, worst of all, tries a cover up. With the full aid of a government regulator (for heavens sake!). To the entire world. Apparently not afraid that being caught out would have worse consequences. A massive public breach of trust and hints of corruption. The way the FAA was the last country in the world to ground the MAX, it makes the US look like some 3rd world dictatorship.
> If Boeing is incompetent, trusting the Dreamliner but not the MAX is irrational.

The 787 has its share of problems, but at least it's newly designed and has to conform to the latest safety regulations, not an over 50 year old design like the 737 MAX. If it wasn't such an old design, the odd placement of the engines which couldn't fit under the wings and therefore the "workaround" for the issues caused by this odd placement (MCAS) would not have been necessary...

Boeing has never made an airliner that was fully dependent on computer assistance. They have no heritage in this domain and apparently don't care enough to pay for capable testing. It will always be risky to fly these no matter how much scrutiny is applied.
Indeed, my wife already has had to. Apparently it is uniquely uncomfortable to boot, even for a short (5'2") and thin (110lb) woman. I'm 6' tall and dreading the day I have to fly on this.
Depends on how they configure the cabin, but it's been the same as any other 737 whenever I've flown on it (5'10", 180lb)