12 ms·
FAA safety engineer goes public to slam agency’s oversight of Boeing’s 737 Max
- violetgarden 6y agoThis is so sad. Reminds me of the Challenger where the concerns from engineering were ignored due to pressure from management.
- heymijo 6y agoThe great tragedy to me is the regulatory capture of the FAA and the erosion of trust in commercial flight.
- brokenmachine 6y agoWhy is erosion of trust in commercial flight such a tragedy?
- Raptor22 6y ago> the concerns from engineering were ignored due to pressure from management This is the norm in every company I've been in. It's infuriating.
- jjk166 6y agoThe Challenger explosion is taught in engineering school as an example of how not to communicate safety concerns. If you go through the presentation, it's terrible: they basically presented raw data in chronological order using an irrelevant infographic when they should have been showing a trend between o-ring failure and temperature. While in hindsight we know that management should have been more cautious, I could not possibly blame them for being unconvinced by such a poorly communicated argument.
- Zevis 6y ago> Michael Teal, 737 MAX chief engineer, testified to Congress that he first learned only after the Lion Air crash that MCAS relied on a single sensor Uh, what. How does something like this even happen?
- xiphias2 6y agoBoeing's management hid the details of MCAS from FAA
- heymijo 6y agoThe article shows that safety engineers at the FAA would have had the requisite knowledge to see the problems with the MCAS system, but as OP said above, there was no "issue paper" from Boeing to regulators about the system.
- rualca 6y ago> Uh, what. How does something like this even happen? By "this" do you mean "egregious lies focused on making a case for plausible deniability"?
- temac 6y agoIf he really is the chief engineer and that has any meaning, for ex if he signed off the design, should he not maybe be jailed for his failure to know what he signed?
- rurban 6y agoThat cannot be. It was widely reported that the complete South Western Airlines MAX fleet insisted on the second sensor being installed. And so they did. They bypassed the FAA rubber-stamp approval. The FAA not knowing about this is not plausible. Everybody knew that. It was a major criticism on the FAA ability to control air safety.
- rainbowzootsuit 6y agoAre you speaking of the AOA disagree "light" here? I use scare quotes above because it's not even a light, but instead an icon on the main console display. Two AOA sensors exist on all of the original 737MAX aircraft. The original MCAS would use one sensor at a time for its calculation in an alternating fashion, which would swap between flights. The AOA disagree was only an indication for the pilots and wasn't an actual upgrade to the function of the original MCAS for those that paid for the icon. Juan Brown of the youtube channel blancolirio has given really excellent coverage if you look back through his explainations. https://www.youtube.com/channel/UCphqjYZxxzjNbONVmY-0J7Q https://www.youtube.com/channel/UCphqjYZxxzjNbONVmY-0J7Q
- xiphias2 6y agoI think instead of talking about the past 2 accidents so much, at this point the question is if the current system is safe enough. I wish he went more into the details of the software certification.
- sho_hn 6y agoThe key point I took away from the article is that some complex interactions with and misbehaviors of the autothrottle system remain unaddressed in the upgrades (or at least Boeing was not ordered to make changes there, and Jacobsen chose to make this public, so presumably they remain unaddressed), so I think it answers your question.
- xiphias2 6y agoFor some reason the pilots are still confident enough to fly the new planes, though they don’t have many options now that a big part of them have been laid off because of the coronavirus. It seems that now the Boeing hopes that those complex interactions are rare enough that they don’t pose a serious problem. We’ll see in a few years.
- sho_hn 6y agoOne takeaway I got from reading many articles like this over the past two years: Airplanes are a lot like JavaScript, quirky and full of gotchas, and what the pilots rely on is being well-informed and having access to good documentation on the evil. Everything seems to rely on a complex system of diseminating errata through bulletins, checklist and manual updates and training. The best airplane might not be the most bug-free but the best documented and most well-understood. The worst airplane may be the one with the most undefined or unknown (by pilots) behavior. Part of what made this such a fiasco is that the behavior and interactions of these systems were purposely not documented and kept not just from the FAA, but pilots in particular. This meant they had no chance to do their job well and operate the equipment correctly. Add to this manufacturers reaching for "pilot error" quickly and as a pilot I'd imagine being rather pissed off. This seems interesting with the 737 in particular: It's been around for a long time and was probably considered well-understood. Boeing introduced the MAX telling everyone "it's still the same", and then threw pilots one gigantic (as well as defectively implemented) curveball. Instead, deviations from and additions to a well-known system should have been pointed out and documented especially well. It also seems to suggest there must be a system complexity ceiling where pilot recall of checklists and subsystem interaction permutations fails to scale anymore, and the addition of new systems probably needs to be evaluated against that notion. Assistance systems like MCAS are supposed to make things easier - but their edge cases and interactions potentially carry a "recall tax". Another pattern I see in articles like this (another example is the A380 engine failure in I think a Quantas plane years ago) is that planes rely on informing pilots of subsystem state through what's basically a stack of notification message dialogs with the goal to get pilots to explicitly confirm/react to each one, but that means by the time the pilot has time to work through the stack during a crisis the content may already be outdated, or there's no time to tend to the stack to begin with. There may be better UX designs possible such as master system diagrams with status? Dunno. Note: I'm a layman, and in topics like this I feel uneasy whenever I relay or suggest what may be based on wrong assumptions.
- heymijo 6y ago"In his letter, Jacobsen recommends that Boeing upgrade the MAX’s autothrottle logic to either disconnect or give the pilots a warning when the computer registers invalid data. In the upgrade to the MAX that allowed it to return to service, the FAA did not require any such change but did add an explicit instruction that pilots in this kind of emergency should “disengage the autothrottle.”" In the many articles about the MAX that have shown up on HN the underlying concern seems to be that this is still not a safe plane. This excerpt is scary. Anyone with aviation experience want to weigh in?
- creamytaco 6y agoOf course it's not a safe plane, common sense says so. Would you trust a bunch of bureaucrats and corporate sellouts with your life, when engineers have been ringing alarm bells for years? Not only will I never fly this plane again, but I'll do my best to avoid Boeing altogether. Given that I'm European, it should be fairly easy.
- dataflow 6y ago> I'll do my best to avoid Boeing altogether https://www.reuters.com/article/us-airbus-probe/airbus-bribery-scandal-triggers-new-probes-worldwide-idUSKBN1ZX2MW https://www.reuters.com/article/us-airbus-probe/airbus-bribe...
- saiya-jin 6y agoThis is about Airbus bribing to get more deals, which is abhorable but common practice in any multinational corporation even these days, be it soda, weapons or banking. Boeing is about utterly incompetent management killing 300+ civilians +-knowingly, and acting like little children. Still refusing to take blame, still refusing to actually fix the source of the issue. As a passenger, I and my family are in direct risk from this incompetence. Yes, in almost duopoly in civilian flying, I will take Airbus anytime. And never, ever, fucking ever 737 Max.
- 6y ago
- everybodyknows 6y ago> Ahead of his planned retirement from the FAA at the end of this month. Free at last to speak hard truth.
- neonological 6y agoHe’s consciously risking his retirement package. They can fire him. Read the article, it says this.
- rkagerer 6y agoThat's not quite what it says. Rather, his prospects for gigs involving FAA interaction from the other side: Now sharing his concerns with the press for the first time, he’s risking his post-FAA employment prospects. .... After retiring from the FAA, Jacobsen hopes to work part-time. Someone with his credentials would typically find lots of lucrative freelance work at smaller aerospace companies who need help navigating the maze of FAA regulatory compliance to certify their products. Now, he may struggle to get such gigs if he’s perceived as an antagonist of the agency. “I recognize this could cost me future employment opportunities,” Jacobsen said. “But I feel like my allegiance right now is to these families.” It doesn't mention any retirement package.
- neonological 6y agoYou're right, I misinterpreted it. I thought the "post-FAA employment prospects" was the package, but of course it means actual post employment opportunities. I'm just skimming through it too quickly. As of right now my post has 7 upvotes and no downvotes which means 7 people agreed with me. That means either a lot of people didn't read the article or they misread the article like I did. I wonder how many downvotes my post will get after they read your comment which essentially categorically proves my initial reply is completely and utterly wrong. Which goes to show how many people just skip over reading the article and go straight to the comment section for a summary/full analysis.
- dotancohen 6y ago
- nlbrown 6y agoI wonder what the pilots of the Max have to say about the airplane? There could be greater potential for human error if pilots are distracted by the idea that something could fail at any moment.
- bathtub365 6y agoThis isn’t different than when flying any other aircraft. Something can already fail at any moment from the engines, avionics, control systems, hydraulics, and electrical systems. That’s why pilots have emergency training and emergency checklists. The question is whether Boeing is providing the appropriate training to deal with new potential failures introduced by the new design.
- ilaksh 6y agoThe fact that no Boing or FAA leaders are going to prison points to severe structural issues in our society.
- igorstellar 6y agoDo you think our prisons have enough capacity to take more people in? I think the proper punishment for the leadership would be something like getting their retirement package away and leaving the industry without an ability to get back in.
- __blockcipher__ 6y agoI’m not endorsing the idea of prison time, but the short answer is: yes, of course there’s room, assuming we’re talking about C-suite level executives and maybe 1 or 2 hops below. That’s just a handful of potential prisoners and would be quite manageable.
- hedora 6y agoUS prisons house about 0.7% of the population, or about 1.4M people (depending on the source). The US has about 200,000 CEOs. Not all CxO’s are crooks, but if they were, we could jail all the CEO’s and an average of 6 of each one’s direct reports using our existing prison infrastructure. I’d wager the average criminal CxO does significantly more ongoing damage to society than the average person in US prisons would if released.
- platinumrad 6y agoNo, one of the severe structural issues in our society is our habit of trying to solve all of our problems with imprisonment.
- vkou 6y agoOur society does not try to solve high-level problems with prison, only low-level ones. Steal $500 from your boss, you may get prison time. Your boss steals $500 from each of his employees through wage theft, and the worst he would face is being out some money from losing a civil labour lawsuit. That's because most high level behaviour has an incredibly high bar that it needs to meet to be criminal, with a lot of subjective argument over intent. The bar for low level crime is much easier to meet. Take something that doesn't belong to you? Hit your neighbour with a club? Ingest a taboo mind-altering chemical? All of those are crystal-meth-clear violations of the social contract.
- marshmallow_12 6y agoIt seems a bit presumptuous to call how the FAA dealt with Boeing "oversight". "Total subservience" might be closer to the mark. there is IMO an excellent series of articles documenting exactly what the problems with MCAS were and how it went wrong. It's written by a pilot called Bjorn on leehamnews.com if anyone is interested.
- thewileyone 6y agoHard to disagree with him when he says to just take out MCAS. It was never a critical component that was required for flight. That's what Boeing should have done.
- breakingcups 6y agoAm I wrong in remembering that the reason the MCAS is on the MAX in the first place is because they moved the engines to a position which creates dangerous situations, which was compensated by software (MCAS), so that Boeing could avoid having to re-certify the airframe?
- hanniabu 6y agoAh yes, the bad decision feedback loop. Instead of fixing the root cause you just add another layer of bad decisions. I suppose the most recent layer is the "good enough, let's just sweep any further complaints under the rug" logic
- V_Terranova_Jr 6y agoHaving been involved with a large U.S. Government aerospace project that ultimately failed (there are a lot of USG program failures, and a lot of them in aerospace) Mr. Jacobsen's statement that "FAA leadership seems to be denying any wrongdoing" sadly seems to ring quite true. So does the FAA PM asking him why he was in meetings related to MAX even though it may not have been in his formal "swim lane". There is generally a very sad reticence to acknowledge mistakes within organizations, but failure to earnestly acknowledge, show contrition, and learn from mistakes is dereliction of duty in the public sector in my view. In my own experience, I was a lone voice asking "What are we going do based on learning from this that lessens the likelihood of future such failures?" It was and is an unpopular question. I don't foresee any organizational changes taking place, even though they should. And I don't just mean staff changes, I also mean clear commitments to principle, intent, and wiser behavior.
- WalterBright 6y agoThe article says: "The ET302 pilots, however, jumped immediately to the step in the checklist that Boeing emphasized in its bulletin after the Lion Air crash: hitting the cutoff switches to stop MCAS from pushing the jet’s nose down. In their rush to do that, they didn’t first bring the nose back up with the electrical switches and didn’t disengage the autothrottle." What the bulletin (actually an EMERGENCY AIRWORTHINESS DIRECTIVE) says is: "Initially, higher control forces may be needed to overcome any stabilizer nose down trim already applied. Electric stabilizer trim can be used to neutralize control column pitch forces before moving the STAB TRIM CUTOUT switches to CUTOUT. Manual stabilizer trim can be used before and after the STAB TRIM CUTOUT switches are moved to CUTOUT." https://theaircurrent.com/wp-content/uploads/2018/11/B737-MAX-AD-1107.pdf https://theaircurrent.com/wp-content/uploads/2018/11/B737-MA... The pilots simply did not follow the procedure. Note that this procedure was followed in the first incident of MCAS failure, and the Lion Air airplane recovered and landed safely. (That same airplane crashed on the very next flight with a different crew on it.)
- WalterBright 6y agoWhat I posted was 100% factual.
- dboreham 6y agoBut horrific. "To prevent the computer from flying your plane into the ground perform this complex and counterintuitive set of steps that may involve muscle forces you don't have". Nice. How about "make computer not fly plane into ground?"
- WalterBright 6y ago> complex Here's the procedure: 1. trim back to normal with the electric trim switches 2. turn off the stab trim system. It simply is not complicated. > muscle forces you don't have Turning two electrical switches? > counterintuitive That's debatable, but consider that much of flying is counterintuitive - for example, stall recovery. Humans have not evolved to fly, and do not have the right intuition about it. That's why pilots get extensive training. Keep in mind that all three crews experiencing MCAS failure used the electric trim switches to trim it back to normal. One of them then turned it off, the surviving crew. On the plus side, finally, after maybe a hundred articles about the 737MAX, the paper finally acknowledged that the pilots did not follow the emergency procedure. Progress. > How about "make computer not fly plane into ground?" I did not absolve Boeing's role in the crashes.