(no title)
bkdbkd | 6 years ago
What is painful, is that the pilots recognized that the system was in error, and attempted to correct it, but were unaware that it had the capability to override them. They were unaware because the designers intentionally hid the mechanism. That is made the mechanism hard to see, understand, and needing special knowledge to disable. The designers had not considered all failure modes, but acted as if their implementation was failure-proof and never to be tampered with.
The question in this case is how can one verify something like an automated aircraft system? And more importantly, if there is a technique or practice to assure the system is valid, is the company trying to build it mature enough in its engineering practices to follow it properly?
logfromblammo|6 years ago