Showing posts with label MCAS. Show all posts
Showing posts with label MCAS. Show all posts

Monday, March 15, 2021

Is Boeing's 737 Max Safe to Fly Again?

 

The U. S. Federal Aviation Administration (FAA) seems to think so.  Last November, the FAA lifted its order that grounded all 737 MAX aircraft for more than a year, after two fatal crashes were traced to faulty software.  While the FAA's order includes mandatory fixes that appear to address most of the issues that led to the crashes, some questions remain unanswered.

 

In October of 2018 and again in March of 2019, 737 MAX planes crashed with the loss of all on board.  As subsequent investigations proved, both disasters happened because a single faulty angle-of-attack sensor confused a piece of software called MCAS (short for Maneuvering Characteristics Augmentation System) that most pilots were unaware of.  What the pilots experienced was that the plane kept trying to run itself into the ground, despite repeated attempts to right it.  After the cause was known, the FAA and all other aviation administrations around the world grounded the aircraft until the problem could be fixed.

 

To recap the entire saga would take too long, but basically, the 737 MAX is a redesign of an older airframe with larger engines that unfortunately upset the plane's handling characteristics.  Rather than undertake a complete mechanical redesign, Boeing attempted to patch up the problems with software, including the MCAS feature that was designed to avoid stalling, which the new design was prone to.  But the MCAS relied upon data from small sensors on the plane's sides called angle-of-attack sensors, and wind conditions or other problems occasionally cause these sensors to malfunction.  The flaw in the MCAS design was that it would be thrown off by erroneous data from only one sensor (there are two on the plane), and would then jump to the conclusion that the plane was stalling (pitched up too steeply to fly).  The right thing to do in a stall is to point the nose downward, but only if you're really in a stall.  As long as the sensor was defective, the MCAS kept trying to crash the plane against the pilot's efforts to keep it in the air, and twice, the MCAS won.

 

Operating companies were required to implement several changes before taking their 737 MAX fleets to the air again.  The new MCAS software relies on both sensors, not just one, and a warning light is now required to show when the sensors disagree.  When the MCAS detects a problem, it will try to right the plane only once, instead of however long the sensors tell it to.  And the pilot will now be able to overpower the MCAS's attempts to nose down by pulling back on the control column.  Also, more extensive pilot training in specific 737 MAX simulators is required.  To add to the reassurances the FAA is trying to give that the problem really has been fixed, chief FAA administrator Steve Dickson personally piloted an upgraded 737 MAX to check on the changes himself.

 

What is not so clear is whether Boeing's engineering culture has changed much as a result of the most expensive grounding of a commercial aircraft type in history.  Every airline that owned even one 737 MAX lost tons of money as huge investments sat on the ground, ground that also had to be paid for, because you don't just stick an idle 737 MAX in your back yard till you need it again.  While Boeing has competition—the 737 MAX was designed largely to respond to Airbus's A320 inroads—a wholesale boycott of Boeing by major airlines is unlikely.  However, it is notable that since December, when it became possible to fly upgraded 737 MAX planes and the FAA equivalents in most countries lifted their own grounding bans, China has yet to do so.  Their reasons are unclear, but it sends a signal that carelessness like Boeing manifested in the MCAS fiasco will not be forgotten soon.

 

Sentiment does not come up a lot in discussions of engineering ethics, but there is a type of sentiment that tends to keep problems like Boeing's 737 MAX grounding from happening, if it is cultivated and encouraged to play its proper role.  Loyalty, faithfulness, fidelity to an organization and its reputation, an esprit de corps that embodies what it means to be an engineer who wouldn't do anything to harm the company's ultimate responsibility, namely the safety and well-being of its customers—these are inadequate attempts to describe what I mean, but they approach it.  Free-market absolutism tends to corrode such feelings, as do many manifestations of social media and a kind of cynicism that is easy to acquire in an age that considers four years a long time with one employer.  And such feelings—that's what they are primarily, feelings—are hard to acquire if you are a short-term contract worker, as evidently some of the software engineers were who developed the original MCAS.

 

This is not a call to return to the good old days of lifetime employment by one firm, although other things being equal, reducing the turmoil and churn that job changes and uncertainties entail would probably make the lives of a lot of engineers easier.  Job tenure is not what loyalty is about, not primarily.  But while an engineer is with a particular company, there needs to be a mutual feeling that what the engineer does is the best possible job she or he can do, and what the company does is to support its engineers in doing the right thing—"right" including making enough money to stay in business as well as producing safe and reliable products. 

 

Boeing emails and other information indicates that such feelings and the behavior they engender did not prevail in the case of the original MCAS design and the subsequent efforts to get the 737 MAX approved.  Let's hope that this saga has ended with everyone involved being wiser and more dedicated to the highest ideals of engineering.

 

Sources:  I referred to an extensive article on the 737 MAX saga at https://www.cnet.com/news/boeing-737-max-8-all-about-the-aircraft-flight-ban-and-investigations/, and the Wikipedia article "737 MAX ban." 

Monday, December 30, 2019

Boeing Chief Fired Over 737 Max Controversy


On Sunday, Dec. 22, members of the board of directors of Boeing held a conference call and decided to fire Boeing CEO Dennis Muilenburg.  Since the grounding of the company's 737 Max jetliners last spring after two crashes that killed over 300 people, Muilenberg has faced increasing criticism.  At issue is the jetliner's Maneuvering Characteristic Augmentation System (MCAS), a software patch that was intended to make the 737 Max fly more like its predecessor airframes, which date back to the 1960s.  But in documents released last October, Boeing's former chief test pilot Mark Forkner wrote in an email as long ago as 2016 about "egregious" behavior of the MCAS in flight-simulator tests.

Leaders in an engineering-intensive industry face constant conflicting pressures.  On the one hand, there is the need to make a profit so that your organization can continue its existence and benefit the public in some way with its products and services.  On the other hand, demands for resources to ensure safety and reliability of those products and services cost money, and the trick is to strike a balance between excessive engineering that runs profits into the ground, and skimping on due diligence that leads to shoddy products.  Not being qualified to run a lemonade stand myself, I have nothing but admiration for executives who manage this balancing act, and until recently, Dennis Muilenburg was apparently doing it well enough for the Boeing board of directors to keep him on.

But no longer.  After the fatal 737 Max crashes in Malaysia and Ethiopia were shown to be due to unexpected actions of the MCAS, both the U. S. Federal Aviation Administration (FAA) and eventually the U. S. Congress began investigations into the development of the aircraft and the reasons why MCAS was designed in the first place.  As we mentioned in an earlier blog, a series of physical design changes involving bigger engines made the 737 MAX airframe behave very differently than its predecessors.  According to Gregory Travis, a software engineer and pilot who examined the issue, the right thing to do at this point was for Boeing to undertake a complete mechanical redesign of the aircraft, which would have been very costly in terms of both time and money.  Instead, Boeing chose to create a software patch—MCAS—that sought to make the plane handle more like it used to handle.

The problem was that under some combination of instrument failures, MCAS drew the wrong conclusions about what was going on with the plane, and took over the flight controls from the pilots in a way that was both startling and extremely difficult to overcome.  The Malaysian and Ethiopian crews were not able to do this, and their planes crashed. 

At first, Boeing blamed inadequate pilot training for the crashes, but as the firm has released more internal documents in response to Congressional inquiries and FAA requests, it's beginning to look like at least some people inside Boeing had grave doubts about the viability of the MCAS for safe flying.  Although the public has not yet obtained access to most of these documents, some emails released in October reveal that back in 2016, test pilot Mark Forkner had doubts about the MCAS even when it was only incorporated into the controls of a flight simulator.  The U. S. House committee familiar with the documents says that "the records appear to point to a very disturbing picture of both concerns expressed by Boeing employees about the company’s commitment to safety and efforts by some employees to ensure Boeing’s production plans were not diverted by regulators or others."

An organization's culture is one of the hardest things to describe, but it can be one of its most important assets, or just as easily a liability.  In the quasi-military structure of most commercial firms, leadership sets the overall tone of a culture, but it's a constant struggle to maintain that tone throughout all parts of the organization. 

"Transparency" is a word that shows up a lot when a firm like Boeing appears to have been concealing information that might have made it look bad, or caused regulatory problems and delays in production.  Obviously, transparency is a relative goal.  No firm in a competitive market can afford to be completely transparent about its plans and specialized technologies.  At various times, engineering-intensive companies have tried this in the form of technical newsletters, in which their engineers bragged about their latest developments in enough detail to allow competitors to copy and improve upon them.  Needless to say, such newsletters are found today only in the dusty shelves of libraries that keep material from defunct companies, such as General Radio and the original incarnation of Hewlett-Packard. 

But transparency is a necessity when it comes to issues that affect safety.  On an individual level, the moment you feel a need to hide something you're doing, this can serve you as an alarm to lead you to question why you're hiding it.  But in an organization in which the immediate pressures tend to be in favor of shipping products and minimizing any issues that would stand in the way of that goal, it's easy to simply not say something you ought to say, or not deliver the bad news that will disrupt the schedule that marketing wants to keep. 

The buck stops at the CEO's office, and in firing Muilenburg, Boeing's board of directors has acknowledged that the company's culture has to change from the top down.  Whether a new leader can take the company back to a point where its 737 MAX jetliners can be flown safely again is still very much an open question, however.  Scrapping them or recalling them for a major mechanical redesign would probably spell an end to Boeing as a commercial-aircraft firm, leaving the field to Airbus.  But it's hard to see how anyone is going to have a great deal of confidence in a fix that is mainly software, which is how the 737 MAX got into this mess in the first place. 

Monday, October 28, 2019

A Pilot and Software Engineer's Take on the Boeing 737 Max


As of this writing, the ill-fated Boeing 737 Max series of jetliners is still grounded after two fatal crashes in which the pilots lost a battle with the plane's Maneuvering Characteristics Augmentation system (MCAS).  The U. S. Federal Aviation Administration (FAA) grounded the planes last March, and current estimates are that the planes will not be flying again before at least  2020.  This is a huge blow to Boeing and its customers who bought the planes, as billions of dollars of assets are sitting idly on the runway instead of making money. 

Only a month after the planes were grounded, a software engineer named Gregory Travis, who is also a pilot, wrote his thoughts on what happened with the Max 8 and why he thinks the problem may be intractable.  A version of his article appeared on the website of IEEE Spectrum recently, and to my mind it is the most comprehensive and damning examination yet of a situation that put thousands of lives at risk and ended up killing 346 people.

Travis points out that the 737 series was introduced all the way back in 1967.  Designing an airframe from the bottom up is a costly enterprise, so Boeing understandably would like to make incremental changes to an existing design rather than coming up with a whole new airplane every few years.  As fuel economy became more important for airlines, Boeing decided to go with more efficient engines, which for fundamental physical reasons have to be larger.  But eventually, the newer engines got so big that the ground clearance in their original positions was too small—the front fans were going to hit the ground if they didn't move the engines.  So they did move them upward and back.  But that caused another problem.

Travis drew on his experience as a pilot to note that you start playing with the fundamental handling characteristics of an aircraft when you move the engines around.  Stable flight is a complex interplay between the engine thrust vector and the center of gravity, the drag on the wings and other surfaces, and many other factors.  When the engines were moved, it made the plane tend to pitch upward with increased power, and this is not a good thing.  Upward pitch is to an airplane what tilting your head up is to your head. 

If an aircraft's pitch exceeds a certain angle, depending on the angle of attack (the angle between the plane's fuselage and the air moving past it), it can stall, which basically makes it fall out of the air.  The modified 737 was edging dangerously close to a dynamically unstable condition, which is not something a commercial airliner should do.  Travis said that the right thing to do at this point would have been to redesign the whole airframe to deal with the changed position of the engines.  In his words, "The airframe, the hardware, should get it right the first time and not need a lot of added bells and whistles to fly predictably. This has been an aviation canon from the day the Wright brothers first flew at Kitty Hawk." 

But instead of doing that, Boeing chose to develop a software patch that included the MCAS—a complicated system of interacting compensation fixes, pilot warnings, and poorly considered feedback loops that were vulnerable to faulty inputs from angle-of-attack sensors, which can easily be fooled by surface winds or other transient phenomena. 

Most modern airliners are "fly-by-wire" systems in which there is no direct mechanical connection between the pilot's stick and pedals, and the airplane's control surfaces.  Instead, a computer both takes in the pilot's commands and feeds back to the pilot something approximating the "feel" of manually operated controls, so that the pilot senses he or she is flying a plane and not a video game.  But the MCAS was apparently designed so that when it sensed a situation in which the nose needed to be pointed down, it would in effect grab the controls away from the pilot and do what it knew was right—even if it was wrong.  And the feedback motors that would do this were simply too powerful for the pilots to overcome.  In a reference to the famous HAL 9000 computer in the film 2001: A Space Odyssey, in which the computer tries to kill everyone on board for its own rather obscure purposes, Travis writes "MCAS gaslights the pilots. And it turns out badly for everyone. 'Raise the nose, HAL.' 'I’m sorry, Dave, I’m afraid I can’t do that.'"

We are well down the road that leads to 100% control of airplanes by robotic systems.  Nevertheless, we are far from arriving, and in the meantime there has to be effective and safe cooperation, not competition, between the human pilots and the software that runs the plane.  But in trying to cut corners by fixing an airframe problem with software, and poorly designed software at that, Boeing may have painted itself, and all its customers who bought 737 Max 8s, into a corner that it can't get out of.  Every month that goes by without an FAA-approved plan to fix or retrofit Max 8s so they can fly safely again is an indication that the problem revealed by the MCAS-related crashes may be deeper and more far-reaching than most people thought at first.  The fact that an engineer with deep expertise in both software and flying saw what was evidently going on within a month of the groundings tells me that he's probably on to something.

The historian of technology Henry Petroski says that engineers often learn more from failures than from successes.  We should learn a lot from the 737 saga, but it may prove to be an expensive lesson.  The 737 Max began commercial flights only in 2017, and I'm sure Boeing and its customers were counting on many years of revenue from their purchases.  If the design ends up being scrapped, it will amount to the largest recall in aviation history.  But if even just most of what Travis says is true, that is well within the realm of possibility.  Regardless of what patches Boeing may come up with, I'm never going to feel entirely comfortable flying in a 737 Max again. 

Sources:  Readers are urged to see Travis's complete article, which goes into greater depth than I have been able to here.  It is on the website of IEEE Spectrum at https://spectrum.ieee.org/aerospace/aviation/how-the-boeing-737-max-disaster-looks-to-a-software-developer.

Monday, April 08, 2019

Boeing Confirms Software At Fault In Ethiopian Crash


Last Thursday, Apr. 4, Ethiopian Transport Minister Dagmawit Moges released a preliminary report into the crash of an Ethiopian Airlines Boeing 737 Max 8 outside Addis Ababa last month, killing all 157 people on board.  Cockpit voice recordings and data from the flight recorder make it very clear that, as Boeing CEO Dennis A. Muilenberg admitted regarding both this crash and that of an Indonesian Lion Air flight last fall, "it's apparent that in both flights the Maneuvering Characteristics Augmentation System, known as MCAS, activated in response to erroneous angle of attack information."  Boeing is currently scrambling to fix both that software problem and another minor one uncovered recently, but as of now, no 737 Max 8s are flying in the U. S. or much of anywhere else.  And the FBI is reportedly investigating how Boeing certified the plane.

When we blogged about the Ethiopian crash three weeks ago, there were significant questions as to whether the MCAS alone was at fault, or whether pilot errors contributed to the crash.  But according to a summary published in the Washington Post, Minister Moges said that the pilots did everything recommended by the manufacturer to disable the MCAS, which was repeatedly attempting to point the plane's nose downward in response to the single faulty angle-of-attack sensor output.  But their efforts proved futile, and the plane eventually keeled over into a 40-degree dive and crashed into the ground at more than 500 mph. 

Our sympathy is with those who lost relatives and loved ones in both crashes.  Similar words were spoken by CEO Muilenberg, on whose head lies the ultimate responsibility for fixing these problems.  In doing so, he and his underlings will be dealing with how to smoothly integrate control of life-critical systems when both humans and what amounts to artificial intelligence are involved.

This is not a new problem, but it has transformed so much over the years that it seems new. 

I once toured a museum near Lowell, Massachusetts which preserved a good number of the original pieces of machinery used in one of the many water-powered textile mills that used to dot the landscape in the early 1800s.  Attached to their main water turbine was a large, complicated system of gears, flywheels, springs, levers, and so on which turned out to be the speed regulator for the mill.  As looms were cut in and out of the belt-and-shaft power distribution system, the load would vary, but it was important to keep the speed of the mill's shafts as constant as possible.  The complicated piece of machinery I saw turned out to be a sophisticated control system that kept the wheels turning at the same rate to within a few percent, despite wide variations in load.

I'm sure that from time to time the thing might malfunction, and in that case a human operator would have to intervene, shutting it down if it started to go too fast, for example, or if continued operation endangered someone caught in a belt, say.  So humans have been learning to get along with autonomous machinery for almost two hundred years.

The difference now is that in transportation systems (autonomous cars, airplanes), timing is critical.  And because cars and planes travel into novel situations, not all of which can be anticipated by software engineers, conditions can arise which make it hard or impossible for the humans who are ultimately responsible for the safety of the craft to respond.  That increasingly seems to be what happened to Ethiopian Air Flight 302, as evidenced by the black-box data clearly showing only one angle-of-attack sensor to be transmitting flawed data. 

Such issues have happened numerous times with the limited number of autonomous cars that have been fielded in recent years.  We know of at least two fatalities associated with them, and there have probably been many more near-misses or non-fatal accidents as well. 

But even a severe car wreck can kill at most a few people.  Commercial airliners are in a differenc category altogether.  They are operated by (mostly) seasoned professionals who should be able to trust that if they follow the procedures recommended by the manufacturer (in this case, Boeing), they will be able to deal with almost any imaginable contingency, even something like a stray plastic bag jamming an angle-of-attack sensor (this is my imagination working, but something had to make it give an erroneous reading).  In the case of the Ethiopian crash, the implied promise was broken.  The pilots did what they were told would disable the MCAS, but it didn't disable, and with disastrous results.

It is unusual for a criminal investigation to be aimed at the civilian U. S. aircraft industry, whose safety record has been achieved under mostly cooperative conditions between the Federal Aviation Administration and the firms who make and fly the planes.  Obviously it is too soon to speculate about what, if anything, will turn up from such an investigation.  In teaching my engineering classes, I sometimes ask if anyone has encountered on-the-job situations whose ethics could be questioned.  And I have heard several stories about how inspection or test records were falsified in order to pass along defective products.  So such things do happen, but one hopes that in a firm with a reputation such as Boeing's, incidents like this are rare. 

The marketplace has ways of punishing firms for bad behavior which are not just, perhaps, but nonetheless effective.  With the growth of Airbus, Boeing knows it has a formidable rival for commercial aircraft, and any company with millions of dollars' worth of capital sitting idly on the ground as the 737 Max 8s wait for properly vetted software upgrades is bound to be having second thoughts about going with Boeing the next time they need some planes.  I would not want to be one of the software engineers or managers dealing with this problem, as the reputation of the company may be hinging on the timeliness and effectiveness of the fixes they will come up with. 

Boeing has been reasonably transparent about this problem so far, and I hope they continue to be up-front and frank with customers, regulators, investigators, and the public about the progress they make toward fixing these software issues.  People have been learning to get along with smart machines for centuries now, and I am confident that engineers can overcome this issue as well.  But it will take a lot of work and continued vigilance to keep something like it from happening in the future.

Sources:  The Washington Post carried the story "Additional software problem detected in Boeing 737 Max flight control system, officials say," on Apr. 4 at https://www.washingtonpost.com/world/africa/ethiopia-says-pilots-performed-boeings-recommendations-to-stop-doomed-aircraft-from-diving-urges-review-of-737-max-flight-control-system/2019/04/04/3a125942-4fec-11e9-bdb7-44f948cc0605_story.html.  I also consulted a  Seattle Times article at https://www.seattletimes.com/business/boeing-aerospace/fbi-joining-criminal-investigation-into-certification-of-boeing-737-max/ and the original report from the Transport Ministry of Ethiopia, which the Washington Post currently has at https://www.washingtonpost.com/context/ethiopia-aircraft-accident-investigation-preliminary-report/?noteId=6375a995-4d9f-4543-bc1e-12666dfe2869&questionId=7ad6fc9d-5427-415d-b719-34ad0b3fecfd&utm_term=.55ff25187605.

Monday, March 18, 2019

Are the 737 Max 8 Crashes Single-Point Failures?


A friend of mine who formerly worked at NASA was talking about his volunteer work at his church, which is to operate the video camera that records the pastor's sermon.  He's going to ask them to buy a second camera, and when I asked him why, he said, "Single-point failure.  That camera goes out, we're up a creek without a paddle." 

The same concept that can be applied to as humble and non-life-threatening a situation as recording sermons also applies to highly complex systems such as Boeing's 737 Max 8, a new version of the popular 737 aircraft that is in service around the world.  But new evidence from the Mar. 10, 2019 crash of a 737 Max 8 outside Addis Ababa, Ethiopia in which 157 people died indicates that a single-point failure may be responsible for both that disaster and a similar crash of another 737 Max 8 on Oct. 28, 2018 in Indonesia that killed 189.

The single-point failure possibility involves a new anti-stall system called MCAS, which Boeing installed on the Max 8 version of their 737s when the two engines were moved forward compared to earlier versions.  Because this move made the aircraft more prone to stall, the MCAS system was intended to make the plane handle more like older 737s, reducing the need for extensive pilot retraining.  But evidently, pilots were not thoroughly informed that the new MCAS system was in place and activated until the Ethiopian crash brought attention to the system.

The system works by monitoring information from two sensors called angle-of-attack (AOA) sensors.  These are small fins that stick out from the side of the aircraft rather like wind vanes, and rotate to sense the direction of local airflow with respect to the fuselage.  In a stall, the plane is tilted nose-up excessively with respect to the direction of airflow.  This makes the sensor turn at an angle that the onboard computers use to figure out that it's time to take over the controls from the pilot and push the nose down.

Normally, according to a post on aviationstackexchange.com, the onboard computer takes the output of both AOA sensors into account, and if one indicates a stall and the other doesn't, perhaps just a warning is issued to the pilot.  But according to a New York Times report, the MCAS anti-stall system activates even if only one of the two sensors says the nose is too high.  If anything happens to make one of the sensors give a false reading—a stray updraft from the backwash of a flight that just took off, for example—the MCAS goes into action and pushes the nose down, even if the takeoff is proceeding normally.

The altitude records of both 737s involved in the crashes in Ethiopia and Indonesia show that the pilots went on a desperate roller-coaster ride, executing climbs and descents every half-minute or so three or four times before the final descent and crash.  This is consistent with a struggle between the MCAS and the pilots, although other causes could be responsible as well.  Following the Ethiopian crash, China and many other countries grounded all 737 Max 8 and Max 9 planes, and later last week, the U. S. followed suit.

Boeing says it is working on a software upgrade for the planes involved, but it may not be available until April, and so until then, millions of dollars' worth of aviation assets will be out of service.  But that's better than having another 737 crash on takeoff. 

It is too soon to draw definite conclusions about the causes of these crashes.  That has to wait for the analyses of black-box records and other pertinent data.  But investigators have already found that the horizontal stabilizer in the Ethiopian plane was set to push the nose down, which is not something you normally do on takeoff.  And the fact that the MCAS can be triggered by only one AOA sensor is enough reason to take measures such as grounding planes until a remedy can be developed and installed.

Planes are designed by people who work in organizations, and successful designs of safe planes emerge from an exceedingly complex process involving thousands of designers, technicians, supervisors, inspectors, regulators, and other interested parties.  Successful companies manage to evolve with new young staff replacing retired engineers and managers while maintaining the core principles and knowledge that is essential to making planes safe.  And one of those core principles, so easy to understand that even I get it, is to avoid single-point-failure situations whenever possible by installing backup systems and procedures. 

If what the Times reported is true, someone dropped the ball with regard to the MCAS system's behavior in response to only one erroneous sensor.  It could take months or years to figure out how this design error happened.  But the lesson is one that has to be learned if Boeing is to recover from this sequence of disasters, which it probably will. 

It's also possible that the accidents involved pilot error in combination with a misbehaving MCAS.  If the pilots didn't know that the MCAS was even installed, or were unfamiliar with what flying the plane with an activated MCAS is like, their actions with regard to it may have contributed to the crashes.  Part of the problem here is that the MCAS rarely activates under typical flight conditions.  Perhaps there is something about the meteorological conditions at the two airports involved which gave rise to a single AOA sensor error that persisted long enough to cause the accidents. 

These and other speculations will have to await the full accident reports, which may not be available for months.  But in the absence of more knowledge, grounding the 737 Max 8 and 9 planes until the single-point-failure problem with MCAS can be addressed and demonstrated to be fixed is the wisest course.   



Postscript:  After I posted this blog, I received an informative email from a reader who wishes to remain anonymous.  He has given me permission to post it here, as it sheds more light on the concept of single-point failure:

Dear Mr. Stephan,

     I am writing to you in order to add some of my thoughts on your recent post  'Are the 737 Max 8 Crashes Single-Point Failures?' 

     In determining a single point of failure it would seem necessary to choose a boundary for the system or sub-system and also define what the goal of the system is.  In your example the goal is to record the pastor's sermon, and the entire system consists of a video camera and an operator.  So, in this case the video camera is a single point of failure, and adding a second camera provides redundancy.

     In the case of the MCAS the overall goal is to maintain a safe flight path.  The failure of a single AOA sensor may cause the MCAS to make inappropriate changes to the horizontal stabilizer trim.  But there are other subsystems that provide redundancy, most notably the stabilizer trim cut out switches.  The proper use of these switches is a memory item for both pilot and co-pilot.  So, in this broader context, the AOA sensor may not be a single point of failure with regards to the goal of maintaining a safe flight path.

     This design was probably used as the failure to pitch down at the onset of a stall at low level may result in a condition from which recovery is impossible, while an erroneous change in horizontal stabilizer trim can be corrected by timely intervention by the pilots.

And finally, I would like to thank you for your blog.  It provides detailed and nuanced analyses of engineering problems that I have not found elsewhere.

(Name withheld)

Sources:

Boeing 737 technical site:  http://www.b737.org.uk/index.htm

Juan Browne's (a 777 pilot and an air frame and power plant mechanic) YouTube channel:

FAA Advisory Circulars:


Mentor Pilot (a 737 pilot and line training captain) YouTube Channel:
-->