4 ms·
I am surprised there apparently is no dead man’s switch in these locomotives.
by rgj 5y ago
I am surprised there apparently is no dead man’s switch in these locomotives.
- flyinghamster 5y agoThere is one, but it was rendered ineffective by the engineer's application of the independent brakes on the locomotive. This is another one of those classic cascades of errors, with each mistake paving the way for the next. It just floors me that he didn't come to a complete stop before disembarking the locomotive.
- michaelt 5y agoI'm surprised there's not a dead man's switch which reliably brings the train to a halt in these locomotives :)
- foobarian 5y agoLike a RFID tag or something on the engineer, that would let the train shut down if not found. Of course the engineer might accidentally leave that in the cabin.
- wolrah 5y agoThe biggest problem with failsafes of that nature is that they get disabled, either because the users find them annoying day-to-day or because something in the system failed in the field and getting the equipment back in service was prioritized over maintaining all safety checks. Most dump trucks have alarms that will go off if the bed is raised while moving and some modern ones can even limit speed while the bed is raised (there are plenty of legitimate uses for driving slowly with the bed up), yet it seems like we don't go a month without someone slamming one in to a bridge.
- jtbayly 5y agoThe problem was the misaligned switch. He was attempting to avoid damage, and was under the impression that the train was stopping.
- jandrese 5y agoThe reason he got off was the train was about to blow through an improperly configured switch. He jumped off at the last minute to flip the switch mere seconds before the train made it there. As people have mentioned with modern systems there is rarely one single point of failure. It usually requires the failure of multiple systems in close succession. In this case the rails were slick with rain, the switch was erroneously in the wrong configuration, the engineer misconfigured his locomotive in haste, the engineer dismounted a moving the locomotive against policy, the engineer failed to board the locomotive due to the wet handholds being slick as well as the train picking up too much speed, and only then did they have the full on runaway train. Changing any one of the above variables and there is no incident.
- superjan 5y agoNow the question is: why did he think it was acceptable to disembark? The report says this was an experienced engineer with a clean record. If it had worked, he probably expected he would get away with it. That’s the real problem.
- mannykannot 5y agoHis expectation that he would be successful may have rested on several misapprehensions: He thought he had engaged dynamic braking and thought it would be effective at that speed. On account of the first issue, he did not realize that increasing the engine output would cause the train to accelerate (as opposed to merely energize the field windings, as it would with dynamic braking properly selected.) In addition, "the engineer seemed to believe, in error, that an automatic brake application would improve braking power on single locomotive with the independent brake fully applied" (from the conclusions of the report.) Plus he was acting in haste, and therefore not thinking it through.
- jandrese 5y agoHe has the choice of sticking to policy but having an accident, or ignoring the policy to avert the accident, only to cause a different accident later due to some additional factors.
- rgj 5y agoA dead man’s switch should be fail-close, and enable operation when functioning, not disable operation upon disfunction. The latter is vulnerable to double failures, the former is not.
- iSnow 5y agoI think a dead man's switch is mentioned: "The Alerter system is connected directly to the air brake system which functions to provide an automatic full service penalty application of the air brake system, and a power knock out (PC) caused by failure to acknowledge the time out feature usually about 40 seconds. When the Alerter time out has expired, the engineer must acknowledge by tripping the acknowledging switch which will reset the time out feature. The Alerter system is nullified when locomotive brake cylinder pressure of 20 psi is developed in the Independent Application and Release pipe. This also prevents the P2A Application Valve from triggering a service brake application and PC action."
- rgj 5y agoA dead man’s switch should be fail-close, and enable operation when functioning, not disable operation upon disfunction. The latter is vulnerable to double failures, the former is not.