5 ms·
No, I don't think it boils down to that. It was just a one of many different design decisions (and philosophies) that has provided a stellar safety record for A
by snom390 12y ago
No, I don't think it boils down to that. It was just a one of many different design decisions (and philosophies) that has provided a stellar safety record for Airbus planes right up to the point where it contributed to an accident.
Remember that it's easy to criticize such decisions in hindsight, but the decision was taken for a reason, and approved by government agencies at the time.
- mikeash 12y agoPositive exchange of control and knowing who is flying the plane is literally one of the first things you cover when learning to fly, before you even get in an airplane for the first time. Averaging inputs in this way interferes with that in such an obvious fashion that it's really inexcusable. I really don't believe this is purely a hindsight thing. Sure, they made this decision for a reason and it was approved my government agencies at the time. However, that doesn't mean I can't think those reasons don't override the fundamental principle of always knowing who's in control of the airplane, and that the government agencies were wrong to approve it. This crash is fairly amazing in how basic a failure it was. The two main things that went wrong (confusion over who was controlling the airplane, and not putting the nose down in a stall) are both extremely basic things. It's the computing equivalent of not checking to see if your machine is plugged in, except that people die because you forget to check. It seems that training was deficient when it came to the basics, and I also think that the non-linked averaged controls are completely inexcusable and should be eliminated.
- msandford 12y agoOr, if you're going to INSIST on doing something that's maybe not too smart (non-linked controls) there are a bunch of things you could do to fix the problem: 1. Have a switch that determines "who is flying the airplane" i.e. which controls are active 2. Implement some kind of feedback even if it's not direct mechanical such as moving both joysticks with a little bit of servo force: not enough to overpower one's hand but enough for the non-flying folks in the cockpit to see 3. Have an "averaging error" sound, light up, whatever if the two joysticks have inputs which are too far from one another to make sense. This isn't great because you still have to pick one joystick to have priority and that might be non-intuitive to pilots Ultimately I think the biggest problem with the Airbus design is that it adds an extra level of indirection between pilot's inputs and airplane course. In most aircraft if you let the controls return to "neutral" the airplane will slowly return to neutral as well. In an Airbus if you let the controls return to neutral the airplane just continues to do whatever it was you were doing; if you're climbing it continues to climb; turning it continues to turn; etc. http://www.apollosoftware.com/products/flybywire/flybywire_english.pdf http://www.apollosoftware.com/products/flybywire/flybywire_e... It seems to me that this is how the problem occurred; someone yanked back on the joystick and nobody else noticed it and then it returned to neutral. But the airplane continued to try and hold attitude up. In a Boeing airplane that wouldn't be a few seconds of joystick back, it'd be a continuous holding of the yoke towards the pilots making it very obvious what was happening. The pilots shouldn't have an integrator between them and the airplane because it makes the airplane handle in very non-intuitive ways to the first 80 or so years of aviation as well as basically all the smaller planes that pilots train on prior to flying big jets.
- mikeash 12y agoReally, I don't think there's a point to discussing ways to mitigate non-linked controls. It's basically like saying, well, if you're going to keep poisonous cobras in the baby's crib, here are some ways to help avoid getting bitten.... Now, there's no reason you can't have a full fly-by-wire system with all the conveniences and safety advantages that implies along with such a system. The two controls could be mechanically linked before feeding into the system, or they could be completely mechanically independent and then use a force feedback system to link the electronically. There are interesting arguments on both sides of the Airbus fly-by-wire system, but it's ultimately a separate question.
- snom390 12y agoWell, there's a reason: Cost. Certifying and retrofitting force feedback controls on existing Airbus planes will be very expensive, and since the current safety record is so good, it's probably not going to happen unless another accident happens attributable to the same design decision.
- mikeash 12y agoThat's a good point, I was thinking from the perspective of designing a new system, not dealing with the large installed base.
- snom390 12y agoThey do have a switch to override controls on airbus planes. But of course, that's not much use when both pilots are in panic mode. AFAIK they could see how the controls were manipulated on the FDR, and I think both pilots actually applied nose-up inputs for some time.
- snom390 12y agoI'm not saying I agree with the decision, just that you have to put it in context. It would be interesting to go back and see why they chose that design. Although the failure was basic, and they certainly lacked hands-on high altitude flying experience, you have to consider that the situation they got themselves into became very confusing, to the point where they likely didn't trust any instruments or warnings they got. The right initial reaction to the situation would _not_ have been to push the nose down, but to add power and a _slight_ nose up input. However, pulling back on the stick would have been safe to do in normal law, so I think it's very likely that the most inexperienced pilot thought he still had stall protection, and that combined with control inputs that would only be appropriate in lower speed settings caused the initial sequence of events.
- mikeash 12y agoI think the initial sequence of events is entirely understandable. Where it becomes completely ridiculous is when they're losing altitude at a rapid rate despite having the stick pulled all the way back. You are stalling. That should have been abundantly clear at that point. And then, when stalling, holding the stick back is the last thing you want to do. Given the confusion and sensor trouble, stalling the plane is understandable. Keeping it stalled all the way down to the ocean is what is crazy. Designing the control system so that one pilot can't even know that the other pilot is keeping the plane stalled is likewise crazy.
- snom390 12y agoIt should have been abundantly clear, however it's not hard to imaging that if you're flying 99% of the time in an airplane that makes it _impossible_ to stall it (ie. pushing back all the way on the stick will not allow it to stall), you might be in a mindset where the possibility of a stall might not even enter your thought. The fact that the stall warning stopped due to low airspeed and came on again when they pushed the nose forward (because airspeeds became available again and the stall warning started working) only made the problem worse, and can explain why they completely lost the trust in the instruments. In the end, there's a host of factors and bad design decisions that led up to the accident, and on top of that poor high altitude training.
- MichaelGG 12y agoI'd criticize this decision even without an accident. I've minimal experience flying planes, but I have a hard time trying to come up with a reason to remove feedback. The safety record is probably due more to the redundancy and safety attitude in air travel in general. The safety record shouldn't be used to excuse specific poor design decisions.
- snom390 12y agoThe decision to standardize controls and use fly-by-wire was made for practical reasons. The Airbus philosophy was to use fly-by-wire to make different airplanes of different sizes handle the same, reducing the requirement for pilot training when moving between models. That in itself doesn't explain the averaging design choice, but it does explain why they decided on the particular fly-by-wire design they have, where in normal law the stick inputs don't have a 1-to-1 correspondance with control surface deflections (like you have on a small airplane for instance).
- inflagranti 12y agoBut fly-by-wire does not preclude the sticks being mechanically or electronically (force-feedback anyone?) linked together. This would seem to me a much better design choice which gives immediate tangible and visual feedback to the other pilot. Instead the whole system relies on the pilots to coordinate using communication and by reading the instruments, which happen on a much higher cognitive level than the tangible input IMO and are hence very hard to maintain under stress - as unfortunately illustrated by this tragedy. Hence I'd say this is much more a design issue than it is pilot error, as both senior pilots were advising the right course but the interface design allowed the inexperienced pilot to silently override control. Yes, this junior pilot probably had too little training and reacted terribly; but what's the point of having multiple pilots if they apparently don't add any additional safety because coordination amongst them has to rely on non-technical means instead of being facilitated by intuitive interface design? Where's the iPhone revolution in planes?