5 ms·
> The 737 MAX is unstable inherently for the sake of mileage This is blatantly false. The MCAS system isn't running a PID control loop or anything like that. I
by VBprogrammer 8y ago
> The 737 MAX is unstable inherently for the sake of mileage
This is blatantly false. The MCAS system isn't running a PID control loop or anything like that. It's applying stupidly simple logic to its inputs and giving equally simple outputs.
At worst you could claim the aircraft is less stable than the original 737. But more specifically I'd say the 737 Max exhibits undesirable control behaviours at the approach to the stall. The MCAS system was required to make this behaviour certifiable.
- acqq 8y agoAs the plane "approaches a stall" the plane is actually in danger. Traditionally, the pilot is trained (on the simulator) to reflexively (every second matters) move the controls to avoid the danger in case of any problems (the different actual problems are simulated and separately trained for). But the new Boeing 737 Max planes exactly at that dangerous moment behave differently to the pilot's input than what the pilot was trained for, because these new planes have different geometry. They are new, but being sold as the "same old." Selling point: "no pilot's retraining needed." Boeing of course knew that planes behave differently, but actively tried to hide that, as much as not even reporting and documenting to the pilots that there's a new device built-in ("MCAS") to "move the controls itself" differently than what the pilot would do based on this training. Now, if the MCAS misbehaves, the pilot is supposed to recognize that the "moved controls" are undesired, manage to turn the MCAS off fast enough (even using a circuit breaker! according to the Boeing's explanation after the first crash), and then again rescue the plane which behaves differently than the plane for which he's trained to have built-in reflexes!" The pilots are supposed to be trained in the simulators to be prepared for the behavior in extreme situations, not to have a new plane that behaves by-design exactly not as they are trained. The way they were trained, when some undesired movement occur, their reflex reaction corrects the problem. Not so in this case. Their trained reflexes didn't help. Instead, the faulty MCAS continues. That's why even the circuit breaker step is mentioned. But even after turning the MCAS off, the plane still behaves differently because it is actually of different geometry. All that can happen at the moment the plane is not high enough to be safe to do enough maneuvering instead of hitting the ground. EDIT: responding to the answer under this post: > you seem to be assigning a lot of weight to a very minor system "I" seem? At this very moment there is a world-wide belief that what you name "very minor" issues lead to death of 350 people in only 5 months time-span, to the point of grounding all the MAX planes. Also relevant: https://news.ycombinator.com/item?id=19398267 https://news.ycombinator.com/item?id=19398267
- VBprogrammer 8y agoYou've said a lot but I'm unclear what actual point you are trying to make. I'm fairly certain you have no actual flight training because you seem to be assigning a lot of weight to a very minor system.
- xbb100 8y agoPeople on professional pilot forums [1] call the MCAS "HAL 9000" and "Artificial Stupidity". [1] They are flying airliners for a living, not small planes.
- VBprogrammer 8y agoIt's a well acknowledged fact that 90% of professional pilots online have only piloted their computer desk. The other 10% may never have piloted the aircraft in question or are 'shooting the shit' rather than presenting their professional opinion.
- salawat 8y ago>on MCAS triviality A system that takes an external input and directly translates that to control surface deflection without checking with or notifying an operator, is not trivial. The AoA sensor, previously largely irrelevant in civilian aviation as posted by an earlier poster, became a deadly concern seeing as a malfunctionimg sensor pumping inaccurate data to a downstream control unit with seemingly no way to validate or reject incoming bad data would respond just as happily to a reading 20 degrees off of where it should be. That this happened in a manner completely foreign to someone thoroughly experienced with a 737 just exacerbates the risk. Especially when said response is no longer overriden in the traditional response in old airframes. This is a usability regression, and should have been explicitly documented. You seem very convinced that MCAS is some trivial system when it is very clear physically and legally speaking that that +/- 2.5 degree stabilizer movement at the right time is what the air-worthiness certification is dependent on. >on re-cert as 737, and failure to train Just because the damn thing flies doesn't mean basic automation system architecture, design, and ethical principles stop applying. You do not make a decision for an operator/user and not communicate the importance to them ahead of time. Doing so fundamentally changes the nature of the device. To put it another way: >"If you change the working parts, you make a different machine."-The Protomen, Father of Death Or if you prefer someone a bit more established here's Edward W. Demmings view on it: >"Every system is perfectly designed to get the results it gets." From which comes the corollary: >"Given two systems, if one produces results irreproducible in the other, then the systems are not the same." >On Software that has the potential to kill people Has no one learned from the lessons of THERAC-25? How many more need to die before "hide interlocks in software and skimp on training" stops claiming lives? I fight the attitude that leads to these types of poorly thought through decisions every day in far less life threatening systems. Seeing it happen in such a high stakes industry just makes it all the more painful to have to endure. >on appeals to occupation/authority You don't need a pilot's license to connect the dots. You just need time, the right skill set and exposure to engineering in multiple contexts, and enough exposure to human social dynamics to realize that the MCAS augmentation is exactly the type of innocuous looking change to have slipped through the cracks. When you're in the trenches developing highly complex systems, you are in a highly faith based environment in the sense that while you are working from empirical measurements and simulations you have to have faith that all the relevant questions have been asked and answered. Engineers frequently discount the impetus of Sales/Business pressure, then turn around and don't question the deadlines those commitments made elsewhere, and accept the consequences thereof (I.e. questions not asked/answered due to time constraints). As I said before. I'm waiting for more data. Even if MCAS isn't involved, the above mentioned issues are gross failures of system implementation that need to be remedied or otherwise addressed. I'm not arguing it's one and done, but even if it turns out leprechauns swarmed the plane en masse disassembling it in flight, enough information has come to light that anyone can see there has been some serious ball dropping going down; ball dropping so serious that uninitiated customers are speaking out in discomfort instead of simply "leaving it to the eggheads". I am very vocal on issues like this. I have been told I have a knack for the highly technical subjects, the inquisitivenes to run down things I don't know, and a bullish propensity to follow the facts wherever they lead. I see it as my responsibility to ask and find answers to the questions others don't even know how to ask, and to present them as best I can so that others may understand and come to their own judgements. Hell, I even learn something every now and again.