Showing posts with label air safety. Show all posts
Showing posts with label air safety. Show all posts

Monday, February 10, 2025

The Potomac Mid-Air Collision: The Role of ADS-B

 

That headline is supposed to make you wonder what ADS-B is, as I did the first time I read about it.  The mid-air collision, of course, is the tragedy that happened last January 29 when American Airlines flight 5342 from Wichita, Kansas, was coming in for its final approach to runway 33 of Ronald Reagan Washington National Airport.  About half a mile from the end of the runway, the plane collided with a Black Hawk helicopter.  Both aircraft crashed into the Potomac, killing all 64 on board the airliner and the three crew members on the helicopter.  It was the worst U. S. air disaster in terms of fatalities in over twenty years, and the U. S. National Transportation Safety Board (NTSB) is continuing its investigation following a briefing held Feb. 6 for members of Congress.

 

As reported in a piece from CNN, NTSB chair Jennifer Homendy said at the briefing that it was not clear whether a system called ADS-B in the helicopter was working at the time of the crash.  The critical nature of this question becomes clear when we realize that the height of the helicopter at the time of the crash is something that hasn't yet been explained.

 

Airliners coming in for a landing have to follow a definite glide path in order to reach the runway, and so there are strict restrictions on where other aircraft can go near airports as busy as the Reagan National.  The Black Hawk helicopter was flying something called Route 4, and was practicing what are called "government continuity operations."  In other words, if the President and other key government figures have to get out of town in a hurry, they are going to travel by Black Hawk helicopter, and the people flying the helicopters have to keep in practice. 

 

Presumably, the routes flown by these helicopters are height-restricted so planes approaching the airport will pass above the helicopters.  Whether the Black Hawk involved in the mid-air collision was too high is a critical question, which is where ADS-B comes in.

 

That acronym stands for Automatic Dependent Surveillance—Broadcast, and it is a souped-up version of the transponders that commercial aircraft have had for years which tells air-traffic controllers what height a plane is flying.  And that system was a step up from the old follow-the-blips technology that traffic controllers had to use in the early days of radar-assisted air traffic.  Knowing how high an aircraft is helps a controller decide whether two converging blips just mean a harmless intersection of two flight paths at different altitudes, a scary near-miss, or a disaster like the one that happened last month.

 

When fully operational, an ADS-B unit in the Black Hawk would have updated air traffic controllers every second with a GPS-determined three-dimensional location data burst.  This is vastly superior to what the controllers' radar can tell them on its own.  And knowing that the helicopter was high enough to collide with the American Airlines plane would have at least allowed the controllers to alert the pilots to the problem.

 

That is exactly what happened only a day before, when an air traffic controller warned an Embraer ERJ 175 to abort a landing at a different runway at Reagan National because a nearby helicopter was flying at 300 feet.  Although there appeared to be enough altitude difference between the two aircraft, the controller alerted the passenger plane's pilot anyway, who flew around and landed successfully later.  Whether the helicopter in this incident was a Black Hawk or something else is not clear from published reports.  But near-misses like this can provide warning flags for safety-conscious operators, who can apply lessons learned and prevent major disasters such as the one that happened January 29.

 

Late last week, crews successfully recovered all the major pieces of both aircraft involved in the accident, and the hope is that among the rubble is information about whether the helicopter's ADS-B system was working, malfunctioning, or turned off.  The signal that ADS-B transmits is readable by anybody, so in an actual emergency flight carrying the President to parts unknown, it's likely that the system might be turned off for security reasons.  In peacetime it's fine to announce your exact location to all and sundry, but in a combat situation it's the last thing you want to do.

 

The bottom line on this accident remains to be discovered, as we still don't have critical questions answered such as the one about the ADS-B system.  Speaking statistically, if one decided to stage a mid-air collision, one would have quite a challenge, because the volume of air occupied by a Black Hawk is not that large, and exquisite timing and aiming would be required.  Unfortunately, the statistics were not favorable on that deadly evening.

 

According to a Wikipedia article on the ADS-B, the U. S. somewhat lags behind other countries in requiring adoption of the system by most aircraft.  I suspect it is a fairly costly piece of avionics, involving data links to a plane's GPS system and a 1-GHz-range microwave transceiver and antenna.  Both aircraft were definitely equipped with ADS-B, but as mentioned above, it has not been determined whether the Black Hawk's unit was operational at the time of the crash. 

 

More generally, this incident provides a good reason to speed up the adoption of ADS-B, which provides faster and more accurate data to air traffic controllers, who need all the help they can get.  Another issue unearthed at this early point in the investigation is that the control office in charge of the airspace was understaffed at the time, and one controller was handling situations normally dealt with by two individuals.  Whether this understaffing contributed materially to the collision remains to be seen, but the Federal Aviation Administration, which oversees air traffic control operations, is not exactly a poster child for governmental efficiency.  Other countries such as Canada have transformed their FAA equivalents into private non-profit organizations, paying for them by user fees, and sometimes this makes things run better and cheaper.  But that is an argument for another day.

 

We will keep an eye on the investigation of Flight 5342's crash, and hope that lessons learned will be applied to keep anything like this from happening again.

 

Sources:  I referred to an ABC News article on the ADS-B question at https://6abc.com/post/washington-dc-plane-crash-major-pieces-helicopter-deadly-midair-collision-recovered-ntsb-says/15882589/, an NBC news article on the helicopter's route at https://www.nbcnews.com/news/us-news/black-hawk-helicopter-investigation-pilots-flight-path-dc-plane-crash-rcna190031, and a CNN article on the day before's near-miss at https://www.cnn.com/2025/01/30/us/dca-plane-helicopter-crash-invs/index.html, besides the Wikipedia articles on "2025 Potomac River mid-air collision" and "Automatic Dependent Surveillance—Broadcast."

 

P. S.  This blog lost one of its most faithful and long-standing readers with the passing of David Jenkins, K4COG, on Feb. 1.  I met David in 1980 at a lecture I gave at the Bible translation organization Wycliffe Bible Translators, and being fellow amateur-radio operators, we hit it off and kept in touch for the following 45 years.  He will be sorely missed by his family and many friends.  To Dave, I say "God bless and 73."


Monday, January 06, 2025

Jeju Airlines Flight 2216: A Deadly Combination

On Sunday Dec. 29, the Boeing 737-800 carrying 181 people on Jeju Air Flight 2216 from Bangkok to the South Korean regional airport in Muan crashed, killing all but two flight attendants on board.  The circumstances of the crash are yet another example of how problems that may not be fatal individually can combine to create a major tragedy.

 

Following an apparently normal flight from Thailand, on the approach to Muan the pilot was warned of the presence of birds near the runway.  According to the Wikipedia article on the accident, during their approach the pilots issued a mayday, apparently due to a bird strike.  They were given permission to land in the opposite direction to their initial approach.

 

On the ground, residents reported hearing loud bangs before the plane landed, and smoke was seen coming from one engine, suggesting that birds may have disabled it.

 

For reasons yet unknown, the landing gear was not deployed before the pilot attempted a second pass at the runway.  The plane landed nose-up and skidded for 1200 meters on the engine nacelles.  A video made by a bystander shows the plane traveling toward the end of the runway, apparently intact and not on fire yet.

 

But 250 meters beyond the end of the runway, the plane encountered the concrete foundation of an instrument-landing-system antenna array.  The plane was going fast enough to destroy all of the fuselage except for a small section of the tail, in which the two survivors were found with serious injuries.  Everyone else—175 passengers and four crew members—died.

 

The damaged flight recorder was recovered and is being analyzed in the U. S. for clues as to why so many things went wrong at once.  But even at this early stage in the investigation process, a few things are clear.

 

A bird strike disabling one of the two engines of a 737 is not by itself a fatal occurrence.  If the other engine is operating normally, there is enough power and control remaining for a skilled pilot to land the craft and even take off with one engine, given enough runway distance.

 

A failure of landing gear to deploy, by itself, is also a survivable problem.  If ground crews have enough notice to spread foam on the runway and be prepared for a post-landing fire, planes have successfully landed (a "belly landing") without operating landing gear.  The feat is very tricky, however, and always damages the plane extensively, and any obstructions on the ground or past the end of the runway can destroy the plane.

 

And that is exactly what happened when the 737-800, which up to that point had survived the belly landing relatively intact, struck the concrete antenna-array foundation 250 meters beyond the end of the runway.  Aviation experts say that barrier should not have been allowed to be erected so close to the flight path.  It is an obvious undesirable feature of airport architecture to have a solid substantial structure that won't break away in the possible path of belly-landing aircraft.  Some South Korean architectural firm is going to have to answer some hard questions in the near future.

 

So we see that the accident involved at least three independent, although possibly related, problems:  the bird strike or whatever it was that apparently killed an engine, the failure of the landing gear to deploy (whether through mechanical failure or human error), and the placement of a potentially plane-destroying concrete obstruction in the flight path.  Eliminating any one of these issues could have resulted in a scary but survivable landing.  But all three of them combined to produce the most deadly aircraft accident on South Korean soil in that nation's history.

 

This accident comes at a supremely fragile point in the political history of South Korea, which is currently being run by an acting president after Yoon Suk Yeol, who was duly elected in May of 2022, declared martial law, was impeached on Dec. 14, 2024, and replaced by Han Duck-soo, who was impeached in turn on Dec. 27, and replaced by Choi Sang-mok.  A national tragedy such as the Jeju Air crash would be a blot on even a popular president's record, but coming at this time of instability, it will only add to the general level of tension and anxiety in the country.

 

Our sympathy extends to the hundreds of relatives, loved ones, and friends who lost passengers at this holiday time.  Until the flight recorder is examined, we can't know exactly what was going on in the cockpit during what was clearly an emergency.  And in the aftermath of such a tragedy, assigning blame is not going to bring anyone back from the dead, although it might give a sense of closure to some. 

 

South Korea is a fascinating case study of a culture which propelled itself from a rather backwards agriculture-based traditional model to one in which cutting-edge technology fuels a so-far thriving economy.  Curiously, though, South Korea has the world's lowest total fertility rate.  At 0.78, it is well below the replacement rate of about 2.1 (the average number of children born to a woman over her lifetime), and is already having a deleterious effect on the country's economy and social life.  Losing family members is always hard, but in a country where marriage and childbearing have become relatively unpopular, a tragedy like this one must make things seem even worse.

 

We look forward to the results of the investigation into this accident.  But already there are lessons to be learned about airport architecture, about emergency landing procedures, and about the damage birds can cause when they fly near airports, as birds are always going to do.  The year 2024 ended badly for air safety, with the apparent shooting down of Azerbaijan Airlines flight 8243 which we covered only last week, and now the Jeju Air crash.  Let's hope the lessons from both of these tragedies are learned quickly and applied to make air travel in 2025 even safer than ever.

 

Sources:  I referred to a Reuters article on the Jeju Air crash at https://www.reuters.com/world/asia-pacific/south-korea-extends-boeing-737-800-inspections-following-fatal-crash-2025-01-03/, a CBS News report at https://www.cbsnews.com/news/south-korea-plane-crash-police-raid-jeju-air/, and the Wikipedia article "Jeju Air Flight 2216." 


Monday, December 30, 2024

The Tragedy of Azerbaijan Airlines Flight 8243

 

Early Christmas morning, an Embraer regional jet took off from Baku, Azerbaijan, which is on a peninsula extending from the middle of the western coast of the Caspian Sea.  It is also the capital of Azerbaijan, a small country squeezed between Iran to the south and Russia to the north.  Flight 8243 was headed to the provincial Russian capital of Grozny, and the normal route from Baku to Grozny lay along the eastern shoreline of the Caspian Sea. 

 

But things were not normal in Grozny.  In addition to heavy fog, Grozny was undergoing intermittent drone attacks as a part of the war with Ukraine.  Russian forces were deployed in the area and equipped with surface-to-air missiles.  Russian military personnel were also using electronic countermeasures that disable and falsify GPS data that airliners normally use for navigation.

 

Around half an hour into the short flight, the pilot had to switch to a more rudimentary type of guidance control than GPS due to this interference.  Shortly after getting permission to land at Grozny, something happened to make the pilot change his mind about landing there.  Passengers later reported hearing loud bangs at the time.  Thinking initially he had suffered a bird strike, the pilot reported loss of control and began asking about weather at other nearby airports.  Almost simultaneously, Russian authorities implemented a "closed-skies" order over Grozny, but Flight 8243 was already there.

 

External data indicates the plane then diverted from its intended path toward the east, ultimately flying across the Caspian Sea, which took nearly an hour.  The pilot activated an emergency signal on the plane's transponder, equivalent to a modern-day SOS, and requested an emergency landing at Aktau, Kazakhstan, on the eastern coast of the Caspian Sea.  His hydraulic systems were failing by this time, making control of the plane extremely difficult.  He managed to lower the landing gear and circled the Aktau airport in an attempt to land.  But his radio went out and the plane crashed about 3 km short of the airport, breaking into two pieces.  The nose section caught fire, but the tail section landed upside down and remained largely intact.  There were 29 survivors, including two crew members and two children, but all the survivors suffered injuries, some of them life-threatening.

 

News images of the plane showed what looked like bullet holes in the fuselage, consistent with an attack on the plane by an antiaircraft missile such as the Russian Pantsir-S1, which uses fragmentation munitions that throw shrapnel over a wide area.  On Saturday, Dec. 28, Russian president Vladimir Putin apologized for the "tragic incident" but stopped short of taking responsibility for the accident. 

 

Investigation of the crash continues, but from what we know now the sequence of events is fairly clear.  By virtue of drone attacks in its airspace, Grozny is in a war zone.  Flying into a war zone is a risky business, but at the time the Azerbaijan flight took off, there were no formal warnings extant closing Grozny's airspace.  Antiaircraft installations such as the Pantsir-S1 rely on low-frequency radar, which can give a general idea of the size of a target but nothing too specific.  If a nervous antiaircraft crew was waiting in a fog for a drone target and saw something show up on radar, it is at least understandable that they might choose to fire at it, although there are lots of good reasons not to.  That seems to be what happened .  Once the plane sustained damage to its tail section, the pilots gradually learned the extent of damage as they realized it wasn't birds, but something more serious.

 

As hydraulic fluid leaked out, they would have experienced gradual loss of control and reverted to using throttle thrust to steer the plane.  The late pilots deserve credit for making it all the way across the Caspian Sea, because ditching the plane in the water might have made it hard for anyone to survive.  As it happened, almost half the passengers and two crew members made it out alive.  For those airline travelers of us who envy first-class passengers near the front of the plane, it is some rueful comfort to note that most if not all of the survivors were in the rear half that broke off. 

 

Since the accident, several countries, including Azerbaijan, Kazakhstan, Turkistan, and Israel have banned flights into various Russian cities, citing safety concerns.  This is belated recognition that the war in Ukraine has spread through Russia in a way that no one anticipated at the start, and is yet another cost of war.

 

Other things being equal, wars are to be avoided.  But if a country is at war, what restrictions should be placed on domestic and international air travel?  Civilian deaths during wartime have been a part of war since the beginning, but the scale of air travel means that one mistake can cause hundreds of deaths.  News reports recalled the fate of Malaysian Airlines flight 17, which crashed in 2014, killing all 298 people aboard when Moscow-backed Ukranian separatists shot it down over eastern Ukraine.   

 

One searches in vain for a technological solution to such problems.  Deliberately targeting for destruction a commercial airliner of a foreign nation is a heinous act tantamount to terrorism, and it is not clear that the Azerbaijan crash resulted from a deliberate attack.  Given the circumstances of fog, it is more likely a case of mistaken identity, and Russia has launched a criminal investigation of the incident.  That may or may not throw more light on the situation. 

 

But in the meantime, it is pretty clear that anyone flying anywhere near locations in either Russia or Ukraine where missile or drone attacks have happened is taking a large chance, much larger than the usual risks of air travel, which are infinitesimal under peacetime conditions.

 

The crowning irony is that this accident happened on Christmas Day, the celebration of the birth of the Prince of Peace.  A writer named Paul Kingsnorth recently made the news by giving a speech entitled "Against Christian Civilization."  His point was that while Christ urged peace, the Western phenomenon known as Christian civilization has perfected the art of war better than any other civilization in history. 

 

We live in a fallen world, and as long as there are bad actors, good actors sometimes need to do harsh things.  And people make mistakes.  Honor goes to the pilots of Flight 8249 who saved many of their passengers under horrible conditions, and sympathy to the loved ones left behind.

 

Sources:  I referred to Associated Press articles on the crash at https://apnews.com/article/azerbaijan-airliner-crash-aktau-kazakstan-embraer-872800d95273ee96e0950192a32e5228 and https://apnews.com/article/russia-putin-plane-crash-azerbaijan-a5b0ffa3e410df53556b0cd824f32a6f, as well as the Wikipedia article "Azerbaijan Airlines Flight 8243."  Paul Kingsnorth's talk in its published form can be accessed at https://www.firstthings.com/article/2025/01/against-christian-civilization.

Monday, January 08, 2024

The Mostly Good News of the JAL Flight 516 Crash

 

Any air transportation fatality is tragic, and our sympathy is extended to the loved ones of the five crew members of the Japan Coast Guard plane who died in a collision with Japan Air Lines (JAL) flight 516 on Tuesday Jan. 2.  But considering that the JAL Airbus 350 had 367 passengers and 12 crew members on board, and every single one of them survived, this accident could have been so much worse.

 

Investigation of the crash will continue for months, but initially it appears that while the JAL flight was cleared to land on runway 34R at Haneda Airport, one of the two international airports in Tokyo, a much smaller Japan Coast Guard De Havilland turboprop was supposed to be waiting to enter the runway.  However, possibly due to a misunderstanding or communications error, the De Havilland was already on the runway as the JAL aircraft was landing.

 

The two aircraft collided, killing five of the six crew members on the Coast Guard plane and sending the Airbus 350 skidding down the runway.  It eventually ground to a stop with the right engine still running. Dramatic video footage of the wreck shows passengers escaping down inflatable ramps in the red glow of the engine's fiery exhaust.

 

The JAL flight crew were unable to use the plane's PA system, so they resorted to megaphones in order to direct the passengers to usable exits amid the smoke that quickly filled the cabin.  The wide-body carbon-fiber-composite A350 was designed for quick evacuation, but until now the evacuation procedure had only been tried out in drills.  Eyewitnesses say none of the passengers appeared to be carrying luggage, which probably helped evacuate the plane quickly.  The plane's captain was the last person to leave the aircraft.  Despite the presence of over 100 fire trucks and the efforts of firefighters, the A350's fire spread throughout the plane and completely destroyed it.  But other than bruises and minor injuries, all the passengers and crews made it out safely.

 

According to a BBC report on the crash, after a 1985 accident in which a JAL aircraft collided with a mountain and killed 520 people the company pledged that they would "never again allow such a tragic accident to occur."  And a look at commercial aircraft fatalities over the years shows a generally declining trend since the 1970s, with a low of 59 deaths worldwide in 2017, for example. 

 

This is the first total loss of a carbon-fiber-airframe A350, and the Airbus designers should be justifiably proud of the way the plane took the punishment of a crash landing without coming apart.  Carbon does burn, after all, while aluminum doesn't burn as easily, and one might be concerned that a carbon-fiber plane would be more dangerous in terms of flammability.  But the JAL 516 crash proved that under the particular circumstances of this accident, the Airbus managed to protect every human being inside from a fiery death.

 

Turning to the causes of the crash itself, increasing aspects of commercial flying have been computerized and automated.  But the processes of taxiing, takeoff, and landing are mostly still done manually by the pilots and copilots. 

 

Decades ago, railroads devised a system called "interlock" which helps prevent settings of switches that would put a train on a track occupied by another train.  Planes aren't trains, but it seems that with modern GPS systems installed on every commercial plane, some sort of coordinated alarm process could be designed to inform pilots when they are straying onto a runway that they have not yet been authorized to enter. 

 

Of course, such a system could cause more trouble than it's worth.  And cockpits are already overflowing with alarms, flashing indicators, and other distractions that sometimes encumber pilots more than helping them. 

 

But when you look into any multiple-fatality accident, regardless of the engineering field, you will typically find that there were precursors:  less serious non-fatal incidents that nevertheless resembled the big awful one, but for some reason turned out to be either harmless or only slightly harmful.  These near-misses are full of information about how to avoid the big awful accident, if only engineers and safety people will pay attention to them.

 

In the JAL-Coast Guard plane crash, five people died, but that was only a small fraction of the number who could have perished, had it not been for the excellent safety procedures and obedience of the passengers who evacuated Flight 516 so quickly.  So in terms of what could have happened, this crash was more of a warning than a full-fledged tragedy. 

 

If the cause does turn out to be due to pilot error, I think it's time to consider some sort of automated system that at a minimum, warns a pilot when he is about to stray onto a runway for which he hasn't been authorized.  Not being a commercial pilot, I may be speaking out of ignorance and there may be such a system in place already.  But it seems like if there was, we would have heard about it.  Warning systems can only do so much, but if a light or voice had warned the Japan Coast Guard pilot that he didn't belong on the runway yet, his crew members might not have died, and 379 other people might not have had to run for their lives before their plane burned up. 

 

It's good to know that those inflatable ramps are actually good for something, and that the practice evacuations in aircraft manufacturers' test facilities that some people make fun of ("Sure, try doing that with smoke in the cabin and screaming people everywhere") can actually be realized in a real-life emergency.  But what would be even better is if this accident encourages new safety features that would keep the precipitating cause from happening anywhere, ever again.

 

Sources:    I thank my wife for alerting me to the BBC article on this crash at https://www.bbc.com/news/world-asia-67870119.  I also referred to statistics at https://www.statista.com/statistics/263443/worldwide-air-traffic-fatalities/

and https://ourworldindata.org/grapher/aviation-fatalities-per-million-passengers, and the Wikipedia article "2024 Haneda airport runway collision." 

Monday, September 05, 2022

The Thin Line of Trust: China Eastern Airlines Flight 5735

 

Back in March, we blogged about the crash of China Eastern Airlines Flight 5735, which crashed on March 21 during a flight from Kunming to Guangzhou, killing all 132 people on board.  At the time, it was too early to draw any conclusions, as the investigations had just begun and the flight data recorders had not yet been recovered.  Within days, however, the voice and data recorders were found, and the data recorders were sent to the U. S. National Transportation Safety Board (NTSB) for analysis.

 

In April, rumors began to circulate in China that the crash was caused deliberately by someone on the flight deck.  These rumors were substantiated when several U. S. news outlets, including the Wall Street Journal and ABC News, reported in May that U. S. officials had determined that someone in the cockpit had pushed the control stick forward to initiate the dive from 29,000 feet that led to the crash.  The Civil Aviation Administration of China (CAAC) has neither confirmed nor denied these reports, while grumbling that "unofficial speculation" can interfere with the ongoing investigation.  Nevertheless, until further official information is made available, it looks like deliberate action on the part of someone in the cockpit may well have caused the crash.

 

The Wikipedia article on the crash lists the three members of the flight crew:  Captain Yang Hongda, who had been a Boeing 737 pilot since 2018; First Officer Zhang Zhengping, an award-winning commercial pilot with more than a decade of experience, including the training of 100 other pilots; and Ni Gongtao, a trainee with less than 600 hours of flight experience whose official duties were simply to observe the more experienced pilots. 

 

The psychology of a flight crew is a somewhat neglected but vital aspect of the smooth functioning of the team, who must cooperate effectively under both routine and emergency conditions.  Any time there is more than one person involved in a situation, there will be questions of authority and precedence.  That is why the very titles of the flight crew indicate a precedence of authority, the captain being in charge of both first and second officers. 

 

An excessively rigorous adherence to the priorities of rank can be detrimental, as the 1997 crash of Korean Air Flight 801 illustrates.  Despite errors the captain of that flight made in his approach to the Guam airport, he was not challenged by the other two members of the flight crew until six seconds before the crash, by which time it was far too late to do anything.  Since that time, Korean Air and other flight organizations have emphasized that the authority of the captain is not absolute, and if the other members of the flight crew see that the captain has made a mistake, they should take positive action to correct it.

 

But in the case of Flight 5735, it would be hard to believe that deliberate action to crash the plane would be taken by more than one of the three flight-crew members.  If we assume that only one of the three men on the flight deck decided to crash the plane, that raises several hard questions.

 

First, one would think that two men determined to save themselves and the passengers could overpower one man bent on destroying the plane.  While I have no details of how a 737 cockpit is arranged, it's hard to imagine a way that one man could impose his will on the others and remain at the controls, if the other two were determined to stop him.

 

As long as we're imagining things, suppose the suicide pilot, let's call him, somehow smuggled a firearm along with him, and threatened to shoot anyone who interfered with him?  That would be awkward, but conceivable.  And it's not clear whether pilots go through the same security checks that passengers do, and if they do, how easy it would be to evade them in order to carry a gun on board.

 

Neither of those scenarios seem too credible.  An interesting fact from the record of the flight before the crash is that it briefly leveled off around 8,000 feet before continuing its plunge into the mountains.  This might indicate a temporary turn for the better in the cockpit battle for the controls. 

 

Another possibility is that the suicide pilot shot or otherwise disabled the other two crew members before implementing his flight to doom.  This almost makes more sense, but it still leaves open the question of how he was able to disable them:  a gun?  Some kind of spray?  A struggle would still have to take place.

 

A second question is, which of the three flight crew members may have done it?  The award-winning Zhang Zhengping would seem least likely, having invested his life in his career.  The CAAC investigated the backgrounds of all three of the crew and found nothing unusual such as outstanding debt or personal troubles that would obviously account for suicidal intent. 

 

A third possibility is that someone from the passenger area broke into the cockpit and forced the plane to the ground.  This involves the question of how mechanically difficult such a feat might be. 

 

A cursory Internet search reveals that there are no private bathrooms in airliner cockpits, meaning that the door to the passenger area has to be open to allow pilots to answer calls of nature.  Updated regulations after 9/11 mandate that at least two crew members must be in the cockpit at all times, so for example, only one pilot on Flight 5735 could leave the cockpit at a time.  A patient terrorist with a first-class seat having a view of the cockpit door could therefore wait until the door opened and make a threatening move, perhaps holding a flight attendant hostage at knifepoint (assuming he could smuggle a knife on board).  But he would still have to overpower three determined flight crew members to do the dastardly deed.

 

Well, I think we've had enough of these dismal speculations for one column.  Suffice it to say that deliberate human action looks like the most likely explanation for the fate of Flight 5735.  We may never know much more than that, unless there are clues in the cockpit voice recorders that remain to be unveiled.  Despite all the modern technology that is deployed to ensure air safety, as long as people fly the planes, we have to trust those people.  And once in a very great while, someone decides to betray that trust.

 

Sources:  I referred to the article "Flight data suggests China Eastern plane deliberately crashed:  Wall Street Journal report" posted on May 18, 2022 at https://www.cnn.com/2022/05/18/china/china-eastern-crash-wsj-report-inlt-hnk/index.html.  I also referred to the Wikipedia article on Flight 5735.   

Monday, May 23, 2016

EgyptAir Flight 804: Clues to a Tragedy


Early last Thursday morning, May 19, EgyptAir Flight 804, an Airbus A320 carrying 56 passengers and 10 crew members, went down in the Mediterranean on its way from France's Charles De Gaulle International Airport to Cairo.  The plane apparently broke up in the air and there are no survivors.  Search parties have begun to recover pieces of the wreckage, and data transmitted from the plane suggests that a bomb might have caused the crash.  But a definitive conclusion about the cause will have to await the recovery of the flight data recorders, if they can be found.

Generally speaking, commercial aviation safety has been a spectacular success story.  If you drive to the airport, the risky part of your journey is over once you park the car.  But determined terrorists can evade security measures to bring a plane down, and no amount of design improvements can make a modern airliner 100% secure against attacks.  In the case of Flight 804, we are fortunate to have information transmitted by the Aircraft Communications Addressing and Reporting System (ACARS) that has provided material for early speculation about the cause of the crash.

Within a day, a number of sources provided news media with ACARS data transmitted for a period of about two minutes around the time of the crash.  Two indicators associated with windows on the right side of the cockpit and several smoke alarms went off.  An aviation expert cited in The Telegraph (UK) speculated that a bomb in or near the right side of the cockpit could have blown out a window, and the resulting cabin depressurization at cruising altitude would have caused condensation fog that can set off smoke alarms.  As the plane broke up, the ACARS system could have kept working, which explains the length of time between the initial transmission and when communication was lost.

ACARS has been helpful in investigating other crashes, such as the Malaysian Air Flight 370 that went down over the Indian Ocean on Mar. 8, 2014.  Although numerous pieces of that plane have been recovered in widely separated locations, the underwater search for the main body of the aircraft continues to this day. 

The part of the Mediterranean over which EgyptAir Flight 804 went down includes some of its deepest waters, over 3000 meters (more than a mile) deep.  So it will be a challenge to find the flight data recorders, especially if the search takes longer than 30 days, which is about as long as the recorder underwater locator beacons operate. 

The continuing mystery of the Malaysian Air Flight 370 crash led to calls for live streaming of flight-recorder data in addition to hard-copy logging on the plane, and in the ACARS data that was recovered for the EgyptAir flight, we see that even in the absence of regulations requiring such streaming, airlines have begun to take advantage of digital communications channels to transmit data that can be helpful both for maintenance and in case of a crash.  Other improvements that could be made to flight-recorder technology include automatic ejection and flotation, as is already done for recorders on military aircraft.  Instead of sinking with the plane, military flight recorders are ejected during the crash and automatically deploy flotation devices which makes them much easier to locate on the water's surface.  Since national governments usually bear the burden of paying for underwater searches, you would think that they would see the logic in offering to reimburse airlines for the additional expense of military-style flight recorders.  But logic isn't the only consideration in international politics.

If the flight recorders and cockpit voice recorders are recovered, the question of whether the crash was deliberate will probably resolve itself pretty quickly.  If it was indeed a deliberate act, the question then becomes one of criminal investigation, and the security at De Gaulle International Airport will come under scrutiny.  As long as airliners are flown by human beings, the trustworthiness of the pilots is an essential link in the security chain.  Assuming the pilots were not themselves part of a conspiracy, that leaves the possibility that someone planted a bomb somewhere in the cockpit.  While cockpits are now typically sealed off from the rest of the plane during flight, it's possible that maintenance workers or others can get into them while a plane is on the ground.  The Telegraph reported that the short stopover in France may not have allowed security personnel enough time to give the plane a thorough going-over before it took off for Cairo.

Whatever the cause of the crash turns out to be, we will learn something from it.  If it was mechanical failure, which seems unlikely but is still possible, it may affect all A320 Airbuses out there, but if there is such a problem it hasn't shown up more than once, apparently.  If, as seems more likely, there was a deliberate act of sabotage, the technique used by the saboteurs will have to be guarded against in the future. 

Either way, sixty-six lives have been lost in what was in all probability an avoidable tragedy.  Most of the time, the vastly complex systems of design engineering, maintenance, operations, and security for air travel work essentially perfectly, and when we get on a plane we don't usually give much thought to the question of whether we'll be getting off  under our own power or not.  But the price of such liberty is eternal vigilance, and I hope the lessons eventually learned from this tragedy make future ones even less likely.

Sources:  I referred to reports from CNN.com at http://www.cnn.com/2016/05/21/middleeast/egyptair-flight-804-main/ and The Telegraph (UK) at http://www.telegraph.co.uk/news/2016/05/21/egyptair-crash---smoke-detected-inside-the-aircraft-cabin-as-sea/, as well as the Wikipedia articles on Aircraft Communications and Addressing System, flight recorders, and Malaysia Airlines Flight 370.

Monday, April 06, 2015

Airline Pilots as Human Infrastructure: Neglect At Your Peril


By now, enough information has emerged from the March 24 crash of a Germanwings plane in the French Alps to show that the co-pilot, Andreas Lubitz, deliberately flew the plane into the ground after waiting for the pilot to leave the cockpit and locking him out.  Data from the flight's recently recovered "black box" showed that Lubitz sped up the plane's descent in the moments before it flew into a mountain in the French Alps, killing all 150 people on board.  It also appears that Lubitz suffered from depression and was suppressing information about his condition from his employer.

For most of recorded history, suicide was a private affair.  But when trains, planes, and automobiles came along, it became technologically possible to take a lot of folks with you when you died, if you happened to be driving or flying.  And here is where the issue of what I'm calling "human infrastructure" comes in.

It's not a very good phrase, but I can't think of another one to describe the state of mind of a person whose job, mediated by engineered transportation, makes them directly responsible for the safety of others.  I'm going to stick my neck out here and claim that in certain periods of history, the committing of certain acts was essentially inconceivable.  The evidence for my claim is that nobody ever did them.

Here's one example.  Unless I've missed something (which is always possible), I believe there is no recorded case in the 19th century of any locomotive engineer (engine driver, in the UK), of his own free will, deliberately causing a train wreck that killed himself and injured or killed large numbers of other people.  It was technologically possible to do that back then, but as far as I know, nobody did. 

But in the last couple of years, we have seen at least two cases—the Germanwings crash and Malaysia Airlines Flight 370, that disappeared over the Indian Ocean—of airline pilots apparently taking their own lives and those of their passengers too.  And this doesn't include things like the hijackings that destroyed the Twin Towers in New York City on Sept. 11, 2001.  The hijackers were not authorized pilots, but they managed to learn enough about flying to do what they did.

What if the world of the 1800s was such a place that the kind of people who signed on as locomotive engineers were essentially incapable of seriously considering a suicidal act that would betray the trust extended to them by their employer and their passengers?  And what if the twenty-first century is such a different place that, despite the best efforts of airlines to screen and inspect their pilots, the kind of people who get hired as pilots include a few to whom crashing a plane with lots of people on board is not only conceivable, but seems like the best thing to do at the time? 

The kind of person you do want to pilot your aircraft is someone like Chesley Sullenberger, whose sense of responsibility to his passengers was so strong that he spent his spare time making a study of aircraft safety and devised contingency plans for various unlikely mishaps, such as having all your engines fail due to clogging by birds during takeoff.  That is exactly what happened to him on Jan. 15, 2009, as he flew US Airways Flight 1549 out of New York's LaGuardia Airport.  Sullenberger expertly maneuvered the powerless plane to a safe water landing, and everyone survived. 

Not every pilot can be a Sullenberger, but is it humanly possible to weed out the Lubitzes?  One can imagine draconian measures, such as firing any pilot who gets treated for depression.  But that would immediately lead to situations such as Lubitz apparently got into, in which he was suppressing the fact that he was seeking help for his condition. 

As long as we let human pilots control aircraft, we extend trust to them to do the right thing in whatever circumstances arise.  Some may think it obtuse or irrelevant for me to point out that in the nineteenth century, your average locomotive engineer probably believed in God, Heaven, and a Hell for people who deliberately killed themselves and took others with them.  It was a kind of belief that is not that common today among college-educated individuals, which is the only pool we take airline pilots from. 

This is not a call for all airline pilots to be Bible-believing fundamentalists.  After all, it is presumably Koran-believing fundamentalists who flew the hijacked planes into the Twin Towers.  But something has changed in the metaphysical background if we compare the 1800s to modern culture, and it has changed in a way that has made formerly inconceivable acts not only conceivable, but do-able, at least by a few bad apples.

In the days to come, we will see calls for more technological fixes that will prevent pilots from deliberately crashing planes.  Something may need to be done along these lines, and if it's effective and doesn't lead to other problems, I hope it will be.  But what I think is more important is a renewed look at the human side of the situation:  the way pilots are chosen and the way airlines keep tabs on them for subtle hints that things are not going well.  Lubitz appears to have been a loner, and while there's nothing illegal or immoral about that, it's a modern situation that has few historical precedents.  Airline pilots have such great responsibilities that it might be worth sacrificing some of their privacy to ensure that they will carry out their duties in a manner worthy of the trust we extend to them.

Sources:  For information on Lubitz, I referred to a CNN article updated on Apr. 3 at http://www.cnn.com/2015/04/03/europe/france-germanwings-plane-crash-main/.  I also referred to the Wikipedia articles on US Airways Flight 1549 and Chesley B. Sullenberger.

Monday, January 28, 2013

Boeing’s 787 Battery Eggs: All in One Lithium Basket


Excuse the tortured metaphor, but the old advice about not putting all your eggs in one basket applies to engineering as well as to other fields.  The implication is that if the basket with all your eggs slips and falls, you’ve lost everything.  Boeing hasn’t lost everything, but the battery troubles besetting its new 787 Dreamliner could not have come at a worse time.

The 787, the latest-model wide-body jetliner from Boeing that seats up to 290 passengers, has been in commercial service since October 2011, less than a year and a half.  It boasts the latest high-tech advances such as a mainly carbon-fiber airframe for reduced weight and fuel consumption, and mostly electrical control systems, rather than the older pneumatic or hydraulic actuators.  Consequently, its electrical power requirements are about triple that of earlier comparable airliners, and so the electrical power system of the 787 was boosted accordingly.  Like a car, the engines (or turbogenerators driven by engines) provide most of the electrical power in flight, but for emergencies and times when the generators aren’t running, the 787 needs batteries, also like a car.  But lead-acid or even nickel-cadmium batteries were seen to be too heavy for the advanced jet, so designers chose to use two 60-some-pound auxiliary power units (battery banks) that employed lithium-cobalt batteries.

Now, lithium batteries have both virtues and vices.  Their main virtue is that they have the best energy-weight ratio of just about any commercial type of battery, meaning you get more stored energy in a 60-pound lithium battery than you would in the same weight of nickel-cadmium or lead-acid batteries.  So far, so good.  But lithium is one of the more reactive metals, and the chemistry of lithium batteries is very touchy with regard to storage temperatures, charging rates, and defects such as little metal needles that sometimes grow through insulating layers and short the things out.  When any of these problems happen to a severe enough degree, the battery can catch fire.  And once a lithium battery is on fire, there’s very little you can do except to wait till it burns itself out, because all the ingredients for the fire are already inside the battery.  Even the FAA recognizes this because it doesn’t require any fire-fighting equipment to put out lithium-battery fires—just adequate ventilation to make sure the hazardous fumes from the fire don’t harm passengers or crew, and don’t spread the fire to other parts of the plane. 

But there is evidence that in the two lithium-battery fires that occurred on 787s in the last couple of months, even these safety systems didn’t work properly.  After these fires in Boston and Japan, the FAA and most other national air-safety agencies grounded the entire fifty-plane fleet of 787s until the battery problem is resolved. 

This problem clearly could have been worse.  The planes could have crashed, but in the incidents so far, the pilots discovered the problem in enough time to land the planes safely.  In the past, lithium-battery fires in a plane’s cargo compartment have caused the loss of the plane, and that is why you are not allowed to carry loose non-rechargeable lithium-ion batteries in checked luggage on air flights.  (Didn’t know that, did you?)  But anybody who owns or leases a multi-million-dollar investment like a 787 knows that every day you can’t fly it is a big hole in your pocket, and also seriously disrupts flight schedules that were made assuming the new 787s would be available. 

It looks like the planes were designed almost in the expectation that the batteries would catch fire some time or other, even though the ventilation systems apparently didn’t work as well as planned.  The fix is likely to be a challenge, because the plane’s entire electrical system is designed around lithium batteries.  Substituting an older type of battery is feasible, but will involve a major redesign, adding weight and probably space and a lot of certification tests to ensure that the fixes aren’t worse than the original problem. 

We may be getting ahead of the game if we assume the lithium batteries are going to come out of the 787s altogether.  The fact that the fires happened so close in time, after over a year of service, says to me that there may have been some kind of well-controlled slipup either in the manufacture of those particular batteries, or the design of those particular planes.  If engineers and investigators can isolate—and ideally, reproduce—the cause of these fires, and it turns out to be fixable, then it may be a simple matter of making sure those particular conditions don’t happen again, and the planes can fly safely again with the lithium batteries they were originally designed for. 

The trouble with these investigations is that once you get a lithium fire going, there isn’t a lot left to pick through to see what started it.  In the “Sources” section at the end of this blog, I’ve put a URL for a little video that I must say about at the outset, “Kids, don’t try this at home.”  It shows a guy taking apart an ordinary consumer lithium battery and setting fire to it.  After you watch that video, you may have second thoughts about buying a lithium anything, though most people don’t go around taking propane torches to their batteries.

We can be thankful that the battery incidents did not result in any fatalities, and I for one hope that the problem turns out to be discoverable, reproducible under controlled conditions, and fixable.  But in any case, Boeing has some lithium-colored egg on its face for the time being, and has about fifty reasons—equal to the number of 787s sold—to get to the bottom of the problem and solve it to everyone’s satisfaction.

Sources:  I referred in the preparation of this piece to an article in the Tacoma, Washington News-Tribune by John Gillie published online on Jan. 27, 2013 at http://www.thenewstribune.com/2013/01/27/2451132/787-battery-fire-correction-may.html.  I also referred to the Wikipedia articles on Boeing and the Boeing 787 Dreamliner.  The lithium-fire-from-battery video can be viewed at http://www.youtube.com/watch?v=BliWUHSOalU.