IANAP, but a lot of the root cause analysis around the 737 max crashes was that they were sufficiently different and so should have required re-certification of pilots before being allowed to fly them. Due to the costs involved, Boeing made the ultimately fatal mistake of minimising these changes to airlines so that pilots didnt know what they were flying (insofar as some of the subsystems).
IMO this is a bad take. MCAS was a fine system, the different aero charicteristics were fine. The only problem is that Boeing cheaped out and made MCAS depend on a single sensor for critical decision making. If they just had 3 sensors like any other saftey critical system none of these problems would have happened.
I've tried to explain this before but it's been pretty negatively received. The assumption that safety critical systems on jet aircraft have triple redundancy is a misconception. At least in so far as any kind of automated, transparent to the pilot, monitoring and switching.
For example, the front of the 737 does have 3 pitot tubes. However, these drive the air data computers for the pilot and the copilot positions. The 3rd one drives a small set of backup instruments. A fourth at the rear of the plane is an input to the hydraulic pitch and feel computer. The Airbus is closer to what some might imagine but the switch between the 3 data sources is still manual (AF447 might have reached Paris if this wasn't the case).
There is another argument that adding more AoA sensors would have had a negligible impact on safety given they are exposed to the same environmental conditions. The main outcome was limiting the authority of the system, it would have prevented both accidents.
No, it would have been fine if
1) they had 3 sensors and
2) the system was in the flight manual and the pilots were trained on the system. If this means needing a new type certification, then so be it.
Which would have been a hard sell to mgmt and maybe stopped the whole project. But it should have been stopped if it wasn't profitable with new training included.
They did, before the two crashes there were other incidents (e.g. a Lion Air flight just the days prior to the one that crashed where a third pilot was in the cabin by accident and his quick thinking saved the plane: https://www.cnbc.com/2019/03/20/lion-air-boeing-737-saved-by... )
There were also optional safety systems that lower cost carriers in the undeveloped/developing world didn’t buy, which would have prevented most of the incidents.
Do you have a reference for this? To my knowledge there was an optional AoA disagree indication (which was on a multi-function display so it's hard to argue it was any kind of cost saving). It's unlikely this would have been a factor in preventing either accident. A small warning indication with no actionable steps would have been low on the priority list for a pilot wrestling for control of the aircraft.
Yes. But it wasn’t just about training the pilots, those systems/sensors should have been present even in the cheaper planes (or the cheaper planes simply shouldn’t have been sold).
It's worse because we literally did all this before. When the stick-shaker came out to help pilots know of impending stall conditions, the second one on the copilot's side was an optional extra! This despite the fact that the copilot is the Pilot Flying quite often in standard practice.