Showing posts with label Boeing. Show all posts
Showing posts with label Boeing. Show all posts

Monday, March 15, 2021

Is Boeing's 737 Max Safe to Fly Again?

 

The U. S. Federal Aviation Administration (FAA) seems to think so.  Last November, the FAA lifted its order that grounded all 737 MAX aircraft for more than a year, after two fatal crashes were traced to faulty software.  While the FAA's order includes mandatory fixes that appear to address most of the issues that led to the crashes, some questions remain unanswered.

 

In October of 2018 and again in March of 2019, 737 MAX planes crashed with the loss of all on board.  As subsequent investigations proved, both disasters happened because a single faulty angle-of-attack sensor confused a piece of software called MCAS (short for Maneuvering Characteristics Augmentation System) that most pilots were unaware of.  What the pilots experienced was that the plane kept trying to run itself into the ground, despite repeated attempts to right it.  After the cause was known, the FAA and all other aviation administrations around the world grounded the aircraft until the problem could be fixed.

 

To recap the entire saga would take too long, but basically, the 737 MAX is a redesign of an older airframe with larger engines that unfortunately upset the plane's handling characteristics.  Rather than undertake a complete mechanical redesign, Boeing attempted to patch up the problems with software, including the MCAS feature that was designed to avoid stalling, which the new design was prone to.  But the MCAS relied upon data from small sensors on the plane's sides called angle-of-attack sensors, and wind conditions or other problems occasionally cause these sensors to malfunction.  The flaw in the MCAS design was that it would be thrown off by erroneous data from only one sensor (there are two on the plane), and would then jump to the conclusion that the plane was stalling (pitched up too steeply to fly).  The right thing to do in a stall is to point the nose downward, but only if you're really in a stall.  As long as the sensor was defective, the MCAS kept trying to crash the plane against the pilot's efforts to keep it in the air, and twice, the MCAS won.

 

Operating companies were required to implement several changes before taking their 737 MAX fleets to the air again.  The new MCAS software relies on both sensors, not just one, and a warning light is now required to show when the sensors disagree.  When the MCAS detects a problem, it will try to right the plane only once, instead of however long the sensors tell it to.  And the pilot will now be able to overpower the MCAS's attempts to nose down by pulling back on the control column.  Also, more extensive pilot training in specific 737 MAX simulators is required.  To add to the reassurances the FAA is trying to give that the problem really has been fixed, chief FAA administrator Steve Dickson personally piloted an upgraded 737 MAX to check on the changes himself.

 

What is not so clear is whether Boeing's engineering culture has changed much as a result of the most expensive grounding of a commercial aircraft type in history.  Every airline that owned even one 737 MAX lost tons of money as huge investments sat on the ground, ground that also had to be paid for, because you don't just stick an idle 737 MAX in your back yard till you need it again.  While Boeing has competition—the 737 MAX was designed largely to respond to Airbus's A320 inroads—a wholesale boycott of Boeing by major airlines is unlikely.  However, it is notable that since December, when it became possible to fly upgraded 737 MAX planes and the FAA equivalents in most countries lifted their own grounding bans, China has yet to do so.  Their reasons are unclear, but it sends a signal that carelessness like Boeing manifested in the MCAS fiasco will not be forgotten soon.

 

Sentiment does not come up a lot in discussions of engineering ethics, but there is a type of sentiment that tends to keep problems like Boeing's 737 MAX grounding from happening, if it is cultivated and encouraged to play its proper role.  Loyalty, faithfulness, fidelity to an organization and its reputation, an esprit de corps that embodies what it means to be an engineer who wouldn't do anything to harm the company's ultimate responsibility, namely the safety and well-being of its customers—these are inadequate attempts to describe what I mean, but they approach it.  Free-market absolutism tends to corrode such feelings, as do many manifestations of social media and a kind of cynicism that is easy to acquire in an age that considers four years a long time with one employer.  And such feelings—that's what they are primarily, feelings—are hard to acquire if you are a short-term contract worker, as evidently some of the software engineers were who developed the original MCAS.

 

This is not a call to return to the good old days of lifetime employment by one firm, although other things being equal, reducing the turmoil and churn that job changes and uncertainties entail would probably make the lives of a lot of engineers easier.  Job tenure is not what loyalty is about, not primarily.  But while an engineer is with a particular company, there needs to be a mutual feeling that what the engineer does is the best possible job she or he can do, and what the company does is to support its engineers in doing the right thing—"right" including making enough money to stay in business as well as producing safe and reliable products. 

 

Boeing emails and other information indicates that such feelings and the behavior they engender did not prevail in the case of the original MCAS design and the subsequent efforts to get the 737 MAX approved.  Let's hope that this saga has ended with everyone involved being wiser and more dedicated to the highest ideals of engineering.

 

Sources:  I referred to an extensive article on the 737 MAX saga at https://www.cnet.com/news/boeing-737-max-8-all-about-the-aircraft-flight-ban-and-investigations/, and the Wikipedia article "737 MAX ban." 

Monday, February 24, 2020

Divided Loyalties: The 737 Max Warning Light Glitch


In the sixth chapter of the Gospel of Matthew, Jesus is quoted as saying "No man can serve two masters; for either he will hate the one and love the other, or he will be devoted to one and despise the other."  The context is the impossibility of serving both God and mammon (money), but one does not have to be a Christian to recognize the shrewdness of Jesus' observation that divided loyalties sooner or later lead to trouble. 

A report from Bloomberg News this week makes this saying particularly relevant to the ongoing woes of Boeing Inc., whose 737 MAX airliner is still grounded after two fatal crashes led to investigations revealing serious problems with the plane's software.  Now it appears that a warning light which could have helped mechanics fix the problem that contributed to the crashes wasn't even working, again due to software problems.

As we have mentioned in this blog before, both the Indonesian Lion Air crash in October 2018 and the Ethiopian Airlines March 2019 crash occurred when problems arose with the angle-of-attack sensors.  Specifically, one of them malfunctioned, and as a result, the defective software responded by essentially flying the plane into the ground, despite the pilots' efforts to stay aloft.  The warning light in question would have illuminated if the two angle-of-attack sensor readings disagreed, showing that one of them had a problem.  An alert pilot might have gotten a mechanic to fix the problem, which would have avoided the issue that led to the two fatal crashes.

But due to a separate software glitch, the warning light turned out not to work unless the customer also asked for an optional display showing each angle-of-attack sensor reading independently.  And 80% of 737 MAXes sold did not have that option, and so also had a defective warning light.  It's a little like if you ordered a car and found out that unless you also asked for optional fog lights, your brake lights wouldn't work. 

By itself, the sensor disagreement warning light's malfunction was not a safety violation.  But in a letter written to Congress last July, the U. S. Federal Aviation Administration (FAA) acting head Daniel Elwell said, "A manufacturer cannot alter the airplane’s features after it has been certified."  The FAA is contemplating assessing fines against the company, and such fines can range up to the tens of millions of dollars.

That is a comparative drop in the bucket in relation to the estimated $18 billion that the firm has lost so far in the 737 MAX debacle since that fleet was grounded last year.  But the details of how Boeing discovered the warning-light glitch back in 2017 and decided not to fix it immediately reveal the glaring defects in a practice that the FAA decided to halt last November:  allowing Boeing-paid engineers to act as FAA inspectors for certain aspects of the certification and approval process.

Regardless of the details, the intended relationship between the FAA and private airplane manufacturers such as Boeing is inherently adversarial, to the extent that the point of having a regulatory agency is to ensure that the entity regulated doesn't get away with murder, or its corporate equivalent.  A simple example is the state of food manufacturing and sale in the U. S. prior to the establishment of the U. S. Food and Drug Administration, the history of which can be traced back to 1906.  Before then, it was perfectly legal to sell candy colored with arsenic-containing dyes to children, or fruit with traces of the arsenic-containing insecticide Paris green.  Once laws were passed against such abominations, the laws had to be enforced, which meant that chemists and inspectors paid by the government went out, collected samples, and tested them for harmful ingredients.  If found, the government used the evidence to levy fines and other penalties against the firms, and the U. S. food supply took a notable turn for the better.

But note that the integrity of the inspectorate—those charged with checking the output of the private manufacturers—owed their livelihood not to the manufacturers directly, but to the government.  This is a sound principle to ensure against corruption and divided loyalties, but one that was neglected when Boeing convinced the FAA to allow some of its employees to do inspections that the FAA would normally undertake.

According to the Bloomberg report, one such "inspector"—a Boeing employee authorized by the FAA to decide such matters—chose to let the warning-light glitch go until a future software update rather than issuing an immediate order to repair all the defective planes.  A clearer case of letting the fox watch over the henhouse would be hard to find. 

This lax procedure is probably not unrelated to the fact that Boeing is the only U. S. maker of large commercial aircraft.  Its only serious global competitor is the European combine Airbus.  If there were three or four viable U. S. airline manufacturers, the FAA would be in a stronger position to levy serious and even firm-threatening penalties against Boeing, the reason being that the other hypothetical firms could take up any slack and still allow the U. S. airline manufacturing business to function. 

But both Boeing and the FAA know that is not the case, and that whatever Boeing does, the FAA isn't going to do anything on its own that would threaten the company's existence and put the U. S. out of the international airliner business. 

There are many bad things about monopolies, and one of the worst is that they encourage laziness, both on the part of the monopoly itself and on any agency charged with keeping an eye on it.  In surrendering some of its authority to Boeing employees, the FAA preserved the appearance of vigilance while relinquishing the reality.  When it ended such cozy arrangements last November, it took a step in the right direction of putting a respectable distance between itself and the industry it is charged with regulating.

But cultures and perceptions do not change overnight, and both Boeing and the FAA have a long way to go before they recover some of the public trust that went down in flames in the 737 MAX crashes. 

Sources:  The Bloomberg report on the prospect of FAA fines for the warning-light glitch was carried on the Fortune website on Feb. 21, 2020 at https://fortune.com/2020/02/21/boeing-737-max-warning-light-new-faa-fines/.

Monday, December 30, 2019

Boeing Chief Fired Over 737 Max Controversy


On Sunday, Dec. 22, members of the board of directors of Boeing held a conference call and decided to fire Boeing CEO Dennis Muilenburg.  Since the grounding of the company's 737 Max jetliners last spring after two crashes that killed over 300 people, Muilenberg has faced increasing criticism.  At issue is the jetliner's Maneuvering Characteristic Augmentation System (MCAS), a software patch that was intended to make the 737 Max fly more like its predecessor airframes, which date back to the 1960s.  But in documents released last October, Boeing's former chief test pilot Mark Forkner wrote in an email as long ago as 2016 about "egregious" behavior of the MCAS in flight-simulator tests.

Leaders in an engineering-intensive industry face constant conflicting pressures.  On the one hand, there is the need to make a profit so that your organization can continue its existence and benefit the public in some way with its products and services.  On the other hand, demands for resources to ensure safety and reliability of those products and services cost money, and the trick is to strike a balance between excessive engineering that runs profits into the ground, and skimping on due diligence that leads to shoddy products.  Not being qualified to run a lemonade stand myself, I have nothing but admiration for executives who manage this balancing act, and until recently, Dennis Muilenburg was apparently doing it well enough for the Boeing board of directors to keep him on.

But no longer.  After the fatal 737 Max crashes in Malaysia and Ethiopia were shown to be due to unexpected actions of the MCAS, both the U. S. Federal Aviation Administration (FAA) and eventually the U. S. Congress began investigations into the development of the aircraft and the reasons why MCAS was designed in the first place.  As we mentioned in an earlier blog, a series of physical design changes involving bigger engines made the 737 MAX airframe behave very differently than its predecessors.  According to Gregory Travis, a software engineer and pilot who examined the issue, the right thing to do at this point was for Boeing to undertake a complete mechanical redesign of the aircraft, which would have been very costly in terms of both time and money.  Instead, Boeing chose to create a software patch—MCAS—that sought to make the plane handle more like it used to handle.

The problem was that under some combination of instrument failures, MCAS drew the wrong conclusions about what was going on with the plane, and took over the flight controls from the pilots in a way that was both startling and extremely difficult to overcome.  The Malaysian and Ethiopian crews were not able to do this, and their planes crashed. 

At first, Boeing blamed inadequate pilot training for the crashes, but as the firm has released more internal documents in response to Congressional inquiries and FAA requests, it's beginning to look like at least some people inside Boeing had grave doubts about the viability of the MCAS for safe flying.  Although the public has not yet obtained access to most of these documents, some emails released in October reveal that back in 2016, test pilot Mark Forkner had doubts about the MCAS even when it was only incorporated into the controls of a flight simulator.  The U. S. House committee familiar with the documents says that "the records appear to point to a very disturbing picture of both concerns expressed by Boeing employees about the company’s commitment to safety and efforts by some employees to ensure Boeing’s production plans were not diverted by regulators or others."

An organization's culture is one of the hardest things to describe, but it can be one of its most important assets, or just as easily a liability.  In the quasi-military structure of most commercial firms, leadership sets the overall tone of a culture, but it's a constant struggle to maintain that tone throughout all parts of the organization. 

"Transparency" is a word that shows up a lot when a firm like Boeing appears to have been concealing information that might have made it look bad, or caused regulatory problems and delays in production.  Obviously, transparency is a relative goal.  No firm in a competitive market can afford to be completely transparent about its plans and specialized technologies.  At various times, engineering-intensive companies have tried this in the form of technical newsletters, in which their engineers bragged about their latest developments in enough detail to allow competitors to copy and improve upon them.  Needless to say, such newsletters are found today only in the dusty shelves of libraries that keep material from defunct companies, such as General Radio and the original incarnation of Hewlett-Packard. 

But transparency is a necessity when it comes to issues that affect safety.  On an individual level, the moment you feel a need to hide something you're doing, this can serve you as an alarm to lead you to question why you're hiding it.  But in an organization in which the immediate pressures tend to be in favor of shipping products and minimizing any issues that would stand in the way of that goal, it's easy to simply not say something you ought to say, or not deliver the bad news that will disrupt the schedule that marketing wants to keep. 

The buck stops at the CEO's office, and in firing Muilenburg, Boeing's board of directors has acknowledged that the company's culture has to change from the top down.  Whether a new leader can take the company back to a point where its 737 MAX jetliners can be flown safely again is still very much an open question, however.  Scrapping them or recalling them for a major mechanical redesign would probably spell an end to Boeing as a commercial-aircraft firm, leaving the field to Airbus.  But it's hard to see how anyone is going to have a great deal of confidence in a fix that is mainly software, which is how the 737 MAX got into this mess in the first place. 

Monday, October 28, 2019

A Pilot and Software Engineer's Take on the Boeing 737 Max


As of this writing, the ill-fated Boeing 737 Max series of jetliners is still grounded after two fatal crashes in which the pilots lost a battle with the plane's Maneuvering Characteristics Augmentation system (MCAS).  The U. S. Federal Aviation Administration (FAA) grounded the planes last March, and current estimates are that the planes will not be flying again before at least  2020.  This is a huge blow to Boeing and its customers who bought the planes, as billions of dollars of assets are sitting idly on the runway instead of making money. 

Only a month after the planes were grounded, a software engineer named Gregory Travis, who is also a pilot, wrote his thoughts on what happened with the Max 8 and why he thinks the problem may be intractable.  A version of his article appeared on the website of IEEE Spectrum recently, and to my mind it is the most comprehensive and damning examination yet of a situation that put thousands of lives at risk and ended up killing 346 people.

Travis points out that the 737 series was introduced all the way back in 1967.  Designing an airframe from the bottom up is a costly enterprise, so Boeing understandably would like to make incremental changes to an existing design rather than coming up with a whole new airplane every few years.  As fuel economy became more important for airlines, Boeing decided to go with more efficient engines, which for fundamental physical reasons have to be larger.  But eventually, the newer engines got so big that the ground clearance in their original positions was too small—the front fans were going to hit the ground if they didn't move the engines.  So they did move them upward and back.  But that caused another problem.

Travis drew on his experience as a pilot to note that you start playing with the fundamental handling characteristics of an aircraft when you move the engines around.  Stable flight is a complex interplay between the engine thrust vector and the center of gravity, the drag on the wings and other surfaces, and many other factors.  When the engines were moved, it made the plane tend to pitch upward with increased power, and this is not a good thing.  Upward pitch is to an airplane what tilting your head up is to your head. 

If an aircraft's pitch exceeds a certain angle, depending on the angle of attack (the angle between the plane's fuselage and the air moving past it), it can stall, which basically makes it fall out of the air.  The modified 737 was edging dangerously close to a dynamically unstable condition, which is not something a commercial airliner should do.  Travis said that the right thing to do at this point would have been to redesign the whole airframe to deal with the changed position of the engines.  In his words, "The airframe, the hardware, should get it right the first time and not need a lot of added bells and whistles to fly predictably. This has been an aviation canon from the day the Wright brothers first flew at Kitty Hawk." 

But instead of doing that, Boeing chose to develop a software patch that included the MCAS—a complicated system of interacting compensation fixes, pilot warnings, and poorly considered feedback loops that were vulnerable to faulty inputs from angle-of-attack sensors, which can easily be fooled by surface winds or other transient phenomena. 

Most modern airliners are "fly-by-wire" systems in which there is no direct mechanical connection between the pilot's stick and pedals, and the airplane's control surfaces.  Instead, a computer both takes in the pilot's commands and feeds back to the pilot something approximating the "feel" of manually operated controls, so that the pilot senses he or she is flying a plane and not a video game.  But the MCAS was apparently designed so that when it sensed a situation in which the nose needed to be pointed down, it would in effect grab the controls away from the pilot and do what it knew was right—even if it was wrong.  And the feedback motors that would do this were simply too powerful for the pilots to overcome.  In a reference to the famous HAL 9000 computer in the film 2001: A Space Odyssey, in which the computer tries to kill everyone on board for its own rather obscure purposes, Travis writes "MCAS gaslights the pilots. And it turns out badly for everyone. 'Raise the nose, HAL.' 'I’m sorry, Dave, I’m afraid I can’t do that.'"

We are well down the road that leads to 100% control of airplanes by robotic systems.  Nevertheless, we are far from arriving, and in the meantime there has to be effective and safe cooperation, not competition, between the human pilots and the software that runs the plane.  But in trying to cut corners by fixing an airframe problem with software, and poorly designed software at that, Boeing may have painted itself, and all its customers who bought 737 Max 8s, into a corner that it can't get out of.  Every month that goes by without an FAA-approved plan to fix or retrofit Max 8s so they can fly safely again is an indication that the problem revealed by the MCAS-related crashes may be deeper and more far-reaching than most people thought at first.  The fact that an engineer with deep expertise in both software and flying saw what was evidently going on within a month of the groundings tells me that he's probably on to something.

The historian of technology Henry Petroski says that engineers often learn more from failures than from successes.  We should learn a lot from the 737 saga, but it may prove to be an expensive lesson.  The 737 Max began commercial flights only in 2017, and I'm sure Boeing and its customers were counting on many years of revenue from their purchases.  If the design ends up being scrapped, it will amount to the largest recall in aviation history.  But if even just most of what Travis says is true, that is well within the realm of possibility.  Regardless of what patches Boeing may come up with, I'm never going to feel entirely comfortable flying in a 737 Max again. 

Sources:  Readers are urged to see Travis's complete article, which goes into greater depth than I have been able to here.  It is on the website of IEEE Spectrum at https://spectrum.ieee.org/aerospace/aviation/how-the-boeing-737-max-disaster-looks-to-a-software-developer.

Monday, July 29, 2019

What Price Safety? The 737 Max 8 Saga Continues


In March and April, I blogged on the tragic and costly software problems plaguing Boeing's 737 Max 8 jetliner.  Briefly, after two crashes in Ethiopia and Malaysia in which a total of 346 people died, evidence pointed to a software problem in the fly-by-wire plane, and the U. S. Federal Aviation Administration (FAA) grounded the plane after numerous other nations did the same in March.  In May, Boeing claimed that they had fixed the software problem, and since then Boeing and the FAA have been running extensive tests to verify that the problem has in fact been solved.  On June 3, Boeing CEO Dennis Muilenberg said that he expected the FAA to declare the plane flightworthy by the end of the year, but declined to give a specific timeline. 

In the meantime, all 387 existing MAX 8s are sitting on the ground instead of flying and generating revenue for the airlines that own them.  This has caused big headaches for both American Airlines and Southwest, which recently announced that it is terminating service to New Jersey's Newark Airport simply because it doesn't have enough planes owing to the MAX 8 groundings.  And American's losses are running in the range of $400 million, largely due to the groundings.

Most of the time, when software fails to do what it should, the consequences are fairly minor.  If it's one feature on some software on your laptop that acts up, maybe you lose some work, or even get so turned off by the problem that you swear never to buy that software again. But you remain healthy and nobody dies.

Then there's the whole issue of software security, and making sure malevolent attacks don't disable or otherwise inconvenience users.  Software companies are used to dealing with such things by now, and generally stay up to date with patches that prevent hackers from doing major damage, as long as the users install the patches.

These kinds of environments are what most software developers are used to working in.  The bigger the organization and the more critical the software, the more bureaucracy is involved, but that's not necessarily a bad thing.  I spoke with a software engineer many years ago who worked for a regional telecommunications company.  She told me that she'd been spending most of the previous year on changing exactly one line of code.  The reason it took so long was that a bunch of other engineers had to take that change and try it out in all sorts of other situations and find out what its ramifications were, and whether it would cause problems down the road. 

Telecomm companies are rather shielded from competition, and so taking a year to change one line of code may be fairly routine, I don't know.  So maybe we shouldn't be that surprised if it now takes six more months for the FAA to make sure that the changes Boeing has made in their 737 MAX 8s are really going to make things better and not otherwise. 

Thing is, the phone company didn't have to shut down and wait for my software engineer friend to finish her job.  But when software is intimately tied in with a multimillion-dollar piece of hardware that you can't use just a little of, and the software makes the whole thing unusable, it creates a spectacle that we haven't seen since the week or so after 9/11/2001 when all domestic U. S. flights were grounded.  And that period, plus the general fear of flying it engendered, hit the airlines with an economic punch that took them years to recover from.

Fortunately, the MAX 8 problem doesn't appear to have frightened people away from flying in general.  Because of the scarcity of seats, the airlines have been able to charge more, and so revenues at American and Southwest are actually up, despite the shortage of planes.  Nevertheless, Boeing has set aside nearly $5 billion in case it ends up having to pay its customers for loss of revenue, and lots of airlines around the world are going to think very hard before they place any more orders with Boeing.

Unlike mechanical failures, software failures are not simply a function of physics.  Software is so dynamic and dependent on the exact conditions and history of its environment that it is virtually impossible to "prove" it won't fail under any circumstances, except in rare and rather academic cases.  Some day, I hope the whole history of this fiasco will come out, as it will be a fascinating study in how software engineering ethics failed in this instance, and it will harbor lessons for how safety-critical software should not be written. 

The problem with such a story may be that it could be too hard for anybody except specialized software engineers to understand.  But then again, it may boil down to management problems, as so many ethical issues do.  Already there has been speculation that the FAA was allowing Boeing to conduct too many of its own safety tests, and basically just taking Boeing's word for it that everything was okay.  Only when we have enough details about how the problems happened and how they were fixed, can we judge whether the FAA has been lax or negligent in this area.

In the meantime, software engineers everywhere except Boeing can be glad that their work is not going under the microscope of the FAA's inspection.  But there are plenty of other types of software that are life-critical:  for example, software for medical devices, automotive software, even the software that lets first responders communicate with each other.  A failure with any of these products can have life-threatening implications. 

So maybe the lesson here for software engineers is:  program as though your life depended on it.  If more programmers had that attitude, we'd all have much better software.  Maybe not so much of it, but that might not be a bad thing either.

Sources:  The report describing CEO Muilenberg's comments appeared on the CNBC website on June 3, 2019 at https://www.cnbc.com/2019/06/03/boeing-plans-to-fly-a-boeing-737-max-certification-flight-soon-ceo-says.html.  Reuters reported on Southwest leaving Newark at https://www.reuters.com/article/us-american-airline-results/boeing-737-max-groundings-plague-u-s-airlines-frustrated-southwest-exits-newark-idUSKCN1UK1N5.  I also referred to the Wikipedia articles "Boeing 737 MAX" and "Boeing 737 MAX groundings."

Monday, April 08, 2019

Boeing Confirms Software At Fault In Ethiopian Crash


Last Thursday, Apr. 4, Ethiopian Transport Minister Dagmawit Moges released a preliminary report into the crash of an Ethiopian Airlines Boeing 737 Max 8 outside Addis Ababa last month, killing all 157 people on board.  Cockpit voice recordings and data from the flight recorder make it very clear that, as Boeing CEO Dennis A. Muilenberg admitted regarding both this crash and that of an Indonesian Lion Air flight last fall, "it's apparent that in both flights the Maneuvering Characteristics Augmentation System, known as MCAS, activated in response to erroneous angle of attack information."  Boeing is currently scrambling to fix both that software problem and another minor one uncovered recently, but as of now, no 737 Max 8s are flying in the U. S. or much of anywhere else.  And the FBI is reportedly investigating how Boeing certified the plane.

When we blogged about the Ethiopian crash three weeks ago, there were significant questions as to whether the MCAS alone was at fault, or whether pilot errors contributed to the crash.  But according to a summary published in the Washington Post, Minister Moges said that the pilots did everything recommended by the manufacturer to disable the MCAS, which was repeatedly attempting to point the plane's nose downward in response to the single faulty angle-of-attack sensor output.  But their efforts proved futile, and the plane eventually keeled over into a 40-degree dive and crashed into the ground at more than 500 mph. 

Our sympathy is with those who lost relatives and loved ones in both crashes.  Similar words were spoken by CEO Muilenberg, on whose head lies the ultimate responsibility for fixing these problems.  In doing so, he and his underlings will be dealing with how to smoothly integrate control of life-critical systems when both humans and what amounts to artificial intelligence are involved.

This is not a new problem, but it has transformed so much over the years that it seems new. 

I once toured a museum near Lowell, Massachusetts which preserved a good number of the original pieces of machinery used in one of the many water-powered textile mills that used to dot the landscape in the early 1800s.  Attached to their main water turbine was a large, complicated system of gears, flywheels, springs, levers, and so on which turned out to be the speed regulator for the mill.  As looms were cut in and out of the belt-and-shaft power distribution system, the load would vary, but it was important to keep the speed of the mill's shafts as constant as possible.  The complicated piece of machinery I saw turned out to be a sophisticated control system that kept the wheels turning at the same rate to within a few percent, despite wide variations in load.

I'm sure that from time to time the thing might malfunction, and in that case a human operator would have to intervene, shutting it down if it started to go too fast, for example, or if continued operation endangered someone caught in a belt, say.  So humans have been learning to get along with autonomous machinery for almost two hundred years.

The difference now is that in transportation systems (autonomous cars, airplanes), timing is critical.  And because cars and planes travel into novel situations, not all of which can be anticipated by software engineers, conditions can arise which make it hard or impossible for the humans who are ultimately responsible for the safety of the craft to respond.  That increasingly seems to be what happened to Ethiopian Air Flight 302, as evidenced by the black-box data clearly showing only one angle-of-attack sensor to be transmitting flawed data. 

Such issues have happened numerous times with the limited number of autonomous cars that have been fielded in recent years.  We know of at least two fatalities associated with them, and there have probably been many more near-misses or non-fatal accidents as well. 

But even a severe car wreck can kill at most a few people.  Commercial airliners are in a differenc category altogether.  They are operated by (mostly) seasoned professionals who should be able to trust that if they follow the procedures recommended by the manufacturer (in this case, Boeing), they will be able to deal with almost any imaginable contingency, even something like a stray plastic bag jamming an angle-of-attack sensor (this is my imagination working, but something had to make it give an erroneous reading).  In the case of the Ethiopian crash, the implied promise was broken.  The pilots did what they were told would disable the MCAS, but it didn't disable, and with disastrous results.

It is unusual for a criminal investigation to be aimed at the civilian U. S. aircraft industry, whose safety record has been achieved under mostly cooperative conditions between the Federal Aviation Administration and the firms who make and fly the planes.  Obviously it is too soon to speculate about what, if anything, will turn up from such an investigation.  In teaching my engineering classes, I sometimes ask if anyone has encountered on-the-job situations whose ethics could be questioned.  And I have heard several stories about how inspection or test records were falsified in order to pass along defective products.  So such things do happen, but one hopes that in a firm with a reputation such as Boeing's, incidents like this are rare. 

The marketplace has ways of punishing firms for bad behavior which are not just, perhaps, but nonetheless effective.  With the growth of Airbus, Boeing knows it has a formidable rival for commercial aircraft, and any company with millions of dollars' worth of capital sitting idly on the ground as the 737 Max 8s wait for properly vetted software upgrades is bound to be having second thoughts about going with Boeing the next time they need some planes.  I would not want to be one of the software engineers or managers dealing with this problem, as the reputation of the company may be hinging on the timeliness and effectiveness of the fixes they will come up with. 

Boeing has been reasonably transparent about this problem so far, and I hope they continue to be up-front and frank with customers, regulators, investigators, and the public about the progress they make toward fixing these software issues.  People have been learning to get along with smart machines for centuries now, and I am confident that engineers can overcome this issue as well.  But it will take a lot of work and continued vigilance to keep something like it from happening in the future.

Sources:  The Washington Post carried the story "Additional software problem detected in Boeing 737 Max flight control system, officials say," on Apr. 4 at https://www.washingtonpost.com/world/africa/ethiopia-says-pilots-performed-boeings-recommendations-to-stop-doomed-aircraft-from-diving-urges-review-of-737-max-flight-control-system/2019/04/04/3a125942-4fec-11e9-bdb7-44f948cc0605_story.html.  I also consulted a  Seattle Times article at https://www.seattletimes.com/business/boeing-aerospace/fbi-joining-criminal-investigation-into-certification-of-boeing-737-max/ and the original report from the Transport Ministry of Ethiopia, which the Washington Post currently has at https://www.washingtonpost.com/context/ethiopia-aircraft-accident-investigation-preliminary-report/?noteId=6375a995-4d9f-4543-bc1e-12666dfe2869&questionId=7ad6fc9d-5427-415d-b719-34ad0b3fecfd&utm_term=.55ff25187605.