> "Boeing 737 MAX killed 346 people. So, it seems that death is not a deterrent."
I really don't understand your point, unless you're implying that there was a meeting where Boeing planned to kill those people. I am not an aviation expert, but what happened with the MAX seems to be a product of the certification process, urgent business needs, systems engineering issues, and bad internal communications at Boeing.
I haven't seen any evidence that someone specifically predicted the chain of events which would unfold on those flights, and clearly communicated the issue, then had executive(s) respond that it was 'worth the money'.
As an aside, I have seen quotes about the 787, which were similar to those in your linked article (mostly with respect to production quality issues), yet the 787 has not had similar accidents. One problem with working on such huge projects is that the line engineers do not understand that managers are constantly hearing alarmist 'warnings' which don't pan out. If 1% of Boeing staff give false alarms in a year, that means there are 1600 false alarms.
> I haven't seen any evidence that someone specifically predicted the chain of events which would unfold on those flights, and clearly communicated the issue, then had executive(s) respond that it was 'worth the money'.
People understand the consequences of what they say. I doubt that most people will say that statements out loud, even when they know that are true.
But, people knew and money was involved.
* February 2018
“I don’t know how to refer to the very very few of us on the program who are interested only in truth…”
“Would you put your family on a MAX simulator trained aircraft? I wouldn’t.”
“No.”
* August 2015
“I just Jedi mind tricked this fools. I should be given $1000 every time I take one of these calls. I save this company a sick amount of $$$$.”
I have read similar quotes about most modern aircraft development programs, yet aviation is quite safe. The fact you can find a few alarmists in a company of 160,000 is rather unsurprising.
Those quotes would be much more convincing if those employees put every prediction they ever made on the record, not just the ones that turned out to be sort-of right in hindsight.
From manager's perspective, you can't listen to everyone complaining about being rushed, understaffed, and underfunded (, because everyone looking to cover their butts in a bureaucracy does all three). On the other hand, you have to be on the lookout for credible issues.
If someone does not make specific and testable predictions which turn out to be right, they are useless alarmists. If you want to read about how to assess predictors (and improve predictions), I suggest you read: https://en.wikipedia.org/wiki/Superforecasting:_The_Art_and_...
I did not present a false choice between two options, I only defined what an alarmist is. I regard alarmists as an extreme on the spectrum of forecasters.
Bifurcating would have been saying that everyone is either a superforecaster or an alarmist, and I never said that.
You may not agree with me, but that doesn't mean that I fell into a logical fallacy.
It's more that there were several meetings where issues were raised that would kill people if they occurred, and those in charge decided the risk factors were minimal enough that they could execute on the plan.
Nobody planned to kill the astronauts on the Challenger. Such a systemic failure to anticipate and manage risk correctly is a team effort and heavily incentive-driven. Putting incentives in place that reward risk-taking increases the odds someone will die.
I think I have a very different understanding of the root cause of the o-ring failure on Challenger than you do.
The common understanding seems to be that the managers decided to launch when the booster temperature was cold (though not necessarily out of limits), and some were warning that it may cause some unforeseen issues.
My read is that each limit in the operations manual should have been backed by a test to failure, or at least a simulation of what would occur if the vehicle was operated outside the limits. Such a process allows the operators to clearly understand what can go wrong, and why the limits are set where they are. This is what they did on the SSMEs, but not on the boosters (because they thought the boosters were fairly simple).[0]
Of course, no one planned it. But encouraging or demanding to take shortcuts is what caused it.
I have been in software industry for 15 years and this happens all the time, being forced to release unfinished features, asked to ignore security, backups, etc. I would imagine same thing happens in other industries.
My understanding of the MAX issues is that the issues were not really shortcuts, though they might look that way in hindsight (because every mistake looks that way in hindsight).
From my non-aviation perspective, it looks like they basically pieced together a bunch of complex systems, with each team making a number of (different) assumptions about each system. The systems themselves were influenced by FAA requirements to maintain the old certificate, which meant that certain desirable changes were impossible, so workarounds were devised. The problems were due to misunderstandings about how the systems would work when assembled, and these issues were not discovered and/or communicated. It really seems like a systems engineering problem, aggravated by a number of external influences (including business reasons and certification).
There is no FAA requirement to maintain the old certificate. Boeing and it’s customers wanted to do that for cost savings.
It is supposedly costly in time and money to acquire a new rating but it has been done obviously.
The airlines wanted a single pool of interchangeable pilots flying in name interchangeable planes (their existing 737s and the 737 MAX). Supposedly one of the airlines threatened to take new business to Airbus and had penalties written into the contract to make the 737 MAX fly under the existing certificate.
So it wasn’t the old certificate driving these issues, it was Boeing and it’s customers wanting to maintain the old certificate that drove the issues. That is a very large difference.
Perhaps my previous post was vague, but I meant 'FAA requirements [of commonality, required to] maintain the current certificate'.
The FAA may be in the right or in the wrong, but it has made certifying new designs almost prohibitively expensive and time-consuming; for evidence of this, simply look at the Cessna 172 (still in production on a 60-year old certificate), and what happened when Bombardier tried to put a new airliner into production.
You're definitely right that the airlines wanted interchangeable type ratings for crew, but the issue slightly more complicated than you're painting it.
I never argued the old certificate forced the issues, the certification system just strongly incentivized 'upgrading' the 737. This was one of many causes.
Wrong. Boeing engineers raised up concerns that were dismissed.
“Frankly right now all my internal warning bells are going off,” said the email. “And for the first time in my life, I’m sorry to say that I’m hesitant about putting my family on a Boeing airplane.” [1]
>>"I haven't seen any evidence that someone specifically predicted the chain of events which would unfold on those flights, and clearly communicated the issue, then had executive(s) respond that it was 'worth the money'."
In large projects like the MAX, there are always people raising concerns.
I think that's a really interesting question, but I think the answer is orthogonal to your dichotomy. In my experience, very successful projects depend on the great managers that know who to listen to in each different situation, and they know how people will react in each situation.
One of the best examples of this is Dave Lewis, who lead the design of the F-4 Phantom II, one of the most successful fighter aircraft of all time. He directed the structural design team to design for 80% of the required ultimate load, because he knew that everyone was conservative in their numbers; then the design was tested. The structure ended up lighter than comparable aircraft, and the Phantom II had phenomenal performance.
This comparison is flawed in several respects. The most obvious is that cigarette companies spent decades intentionally misleading the public about the dangers of their product. This is not the same as just selling a potentially dangerous product, especially one where the dangers are so viscerally obvious as with a parachute.
If you use a parachute one time in case of emergency, yes, it is a life saving device that still has a high level of risk. However, I believe they were referring to the people that choose to parachute for sport/recreation rather than emergency situations.
But in the case of parachutes, it's not the device, it's the activity. I know it's splitting hairs, but it's important, especially when it comes to assigning moral responsibility to manufacturers.
The mails from the case are good to understand the internal discussions: https://www.theguardian.com/business/2020/jan/10/737-max-sca...