4 ms·
If someone connected a big industrial stop switch to a solenoid and pointed that solenoid at the trigger of a rifle aimed at the person pressing the button I do
by VBprogrammer 8y ago
If someone connected a big industrial stop switch to a solenoid and pointed that solenoid at the trigger of a rifle aimed at the person pressing the button I don't think you would expect anyone to look particularly hard at the person who manufactured the switch.
If it was indeed a bird strike which took out the sensor then they seem to be completely beyond all possible blame. Even if it wasn't I'm sure they could point at a host of documentation regarding the usual MTBF of their sensors and why this application was inappropriate.
- peteradio 8y agoSo you are saying this was probably not spec'd for this criticality? I guess I'm curious for more information on this. Obviously don't blame the sensor manufacturer without cause but why are these things so buggy?
- VBprogrammer 8y agoThe sibling comment says it better than I ever could. It's a mechanical device exposed to 500mph wind speeds and temperatures from 40c to -50c. It's a wonder that they work at all. I don't think they are particularly prone to failure though. MCAS aside, having the stick shaker activate along with a host of other indications would probably be cause for a precautionary diversion by most pilots. Having no autopilot and / or an unreliable altitude would most likely disqualify the aircraft from entering RVSM airspace which is where these aircraft would normally operate.
- salawat 8y agoYes and no. Yes, the sensor is appropriate for use as an input to a safety critical system. No, it is not appropriate for a safety critical system to behave in such a manner where if that one vane failed, to kill everyone on board. While the sensor caused the cascade via it's input, it was the implementation of the listening system that allowed the rest to happen. Safety critical systems are designed with graceful degradation in mind. The fewer sources of information the system has, the more conservative it's contribution to the overall state of the system should become. There should have been integration with the second AoA sensor, pilot notification of disagree, and a lessening of the authority of the system in favor of the pilots. The pilots could then have turned the plane around, and landed it. Boeing is also on the hook for not highlighting the compounding risk presented by an airspeed unreliable failure compared with a stab trim runaway. I'd also wager they should have had an MCAS disable separate from the stab trim cutout as a result.