4 ms·
Why was a safety critical system (which was really only needed to place a bandied on retrofitting bigger motors on an older frame design) being sold as an "opti
by Relys 8y ago
Why was a safety critical system (which was really only needed to place a bandied on retrofitting bigger motors on an older frame design) being sold as an "optional package". You need at least 3 redundant sensors in any safety critical system. This is just basic rocket science. Boeing and the FAA are negligent and should not be trusted.
- crocal 8y ago« You need at least 3 redundant sensors in any safety critical system « Huh? Says who?
- ivalm 8y agoSays everyone? Most avionics on modern commercial jets have triple redundancy.
- crocal 8y agoNope. Even if it were true in avionics (not my trade), not « any » safety system need triple redundancy to be safe (e.g. safety relays).
- PuffinBlue 8y agoYou need at least three in any system that can deliver conflicting data so that if one faults then the other two can 'out vote' the faulty one. That allows the system to have at least one failure and still operate. With just two sensors any fault is an unidentifiable failure - how does the system know which is correct when there are just two votes? It may be there's a third input from some other sensort, but then technically we're back to at least 3 sensors voting on the issue.
- crocal 8y agoThis could be true in avionics where availability and safety are more or less the same. In other applications where there is a fail safe mode like nuclear (stop fission) or land transportation (hit the brakes), you do not need that. The statement « any » is too strong.
- dreamcompiler 8y agoIt's an AoA sensor. Planes flew without AoA sensors for 100 years; it's a useful sensor but not a critical sensor. Pilots and autopilots are perfectly capable of flying planes without it. If two AoA sensors disagree, you just stop making decisions based on the AoA sensor and fly the plane without it.
- inferiorhuman 8y agoThe crux of the problem is that the NG/MAX isn't certified to fly with malfunctioning alpha vanes. On the NG and MAX the effort required to move the control column varies based on the angle-of-attack (a.k.a. elevator feel system). On the MAX the airspeed calculation is influenced by the AoA and MCAS is triggered by data from a single alpha vane with no sanity checking. Functioning alpha vanes are critical on the MAX and NG.
- dreamcompiler 8y agoThat's the huge design flaw. They should have made the AoA sensors either critical and triply redundant, or not critical at all (as is typical).
- jasonwatkinspdx 8y agoWith one sensor you have no choice but to simply trust the reading and hope for the best. With two sensors you can compare, and if they disagree beyond some epsilon of tolerance you can fail safe by deactivating the system. With three sensors, you can compare them, and if one is out of bounds vs the other two, you can fail operational by continuing to operate the system while also alerting the operator to the needed maintenance.
- crocal 8y agoYes, and so you do not need three sensors to have a safe system in certain applications. It is sufficient to fail safe.
- MrOwen 8y agoEven think about distributed systems like databases. You absolutely should not call 2 db servers that are configured in a cluster as "redundant" You introduce things like split brain and broken quorum voting (not even possible without a third node) in the event a network connection is severed between them.
- crocal 8y agoYou can use 2 dbs if you apply the STONITH principle (Shoot The Other Node In The Head). Typically, when one node decides to be master, it can switch off with certainty the other one. Routinely used in HA (Highly Available) industrial applications.