• Our new ticketing site is now live! Using either this or the original site (both powered by TrainSplit) helps support the running of the forum with every ticket purchase! Find out more and ask any questions/give us feedback in this thread!

Air India crash at Ahmedabad on flight towards Gatwick - 12/06/2025

Status
Not open for further replies.

bahnause

Member
Joined
30 Dec 2016
Messages
1,010
Location
bülach (switzerland)
I've spoken to many pilots and there is an issue with the switches. There is a cover up. Easy to blame the dead guys.
The mathematical probability (P) of a single switch mechanically failing and jumping its gate is near-zero, the probability of both independent mechanical switches failing at the exact same time is: (P_Both)=P(Switch_1) x P(Switch_2).

This yields a number so astronomically low that it safely crosses the 5-sigma threshold of statistical impossibility.
 
Sponsor Post - registered members do not see these adverts; click here to register, or click here to log in
R

RailUK Forums

Belperpete

Established Member
Joined
17 Aug 2018
Messages
3,584
The mathematical probability (P) of a single switch mechanically failing and jumping its gate is near-zero, the probability of both independent mechanical switches failing at the exact same time is:(P_Both)=P(Switch_1) x P(Switch_2).
This yields a number so astronomically low that it safely crosses the 5-sigma threshold of statistical impossibility.
Not if there is a common cause to the failure, such as the way they are operated.
 

Nym

Established Member
Joined
2 Mar 2007
Messages
9,778
Location
Somewhere, not in London
Without reading all of the way through the thread.

Is there a means for the switches to routinely or non routinely operate without the direct hand on the switch method one would usually accept? Such as a magnetic trip within the switch. And if so, what is this connected to?
 

pug1

Member
Joined
6 Nov 2022
Messages
515
Location
Humber
Without reading all of the way through the thread.

Is there a means for the switches to routinely or non routinely operate without the direct hand on the switch method one would usually accept? Such as a magnetic trip within the switch. And if so, what is this connected to?
Not that I’m aware of, but I’m not familiar with the Dreamliner.

The Switches are designed to prevent non-human input moving them. There has been at least one case of inadvertent cutoff occurring on one engine, one involving a sun visor freeing itself from its holder and unfortunately landing on the cutoff switch and moving it to off. This occurred on an Air Malta 737 MAX.

Boeing are looking at the entire thrust control module to see if any slippage can occur on this particular aircraft.
 
Last edited:

Belperpete

Established Member
Joined
17 Aug 2018
Messages
3,584
We had some similar switches on equipment we used.

You pulled the switch toggle up, moved it over, and dropped it back down. It was designed so that you couldn't inadvertently operate the switch by brushing against it. They worked very well provided that you operated them as intended: pull up using thumb and finger, move over, then release.

However, if having pulled the toggle up, you then just pushed the toggle over with one finger, the toggle sometimes didn't drop properly into the latched position because of you pushing it against the stop.

The older the switch, the more likely this was to happen. I don't know if the switches on this aircraft might suffer the same problem.
 

bahnause

Member
Joined
30 Dec 2016
Messages
1,010
Location
bülach (switzerland)
The older the switch, the more likely this was to happen. I don't know if the switches on this aircraft might suffer the same problem.
The 787 alone will have done millions of flights so far. Each flight corresponds to four operations. Other airplanes might use the same or similar switches. If there was a problem, we would know.

Even after investiagions leading to the 2018 Special Airworthiness Information Bulletin (SAIB) concerning the switches, the FAA explicitly states:
“the airworthiness concern is not an unsafe condition that would warrant” an AD (Airworthiness Directive).
 
Last edited:

gabrielhj07

Established Member
Joined
5 May 2022
Messages
1,600
Location
Herts
I've spoken to many pilots and there is an issue with the switches. There is a cover up. Easy to blame the dead guys.
Any particular details? I'm sure the world's 787 operators would love to know?
 

ainsworth74

Forum Staff
Staff Member
Global Moderator
Joined
16 Nov 2009
Messages
31,067
Location
Redcar
The 787 alone will have done millions of flights so far. Each flight corresponds to four operations. Other airplanes might use the same or similar switches. If there was a problem, we would know.
That's the thing that I keep coming back to. The switches fitted the 787 (and I think with some other members of the 7x7 series of aircraft as I think it's shared design) must have accrued millions of flight hours, millions of switchings, day after day after day. The odds that not only one switch but two can encounter a catastrophic failure mode seconds apart and on the same aircraft at a critical moment of flight? Those odds must be stratospherically unlikely.

Not impossible and it's important not to just assume which is why it's vital that the switches are checked and tested as part of the investigation. But the chances of the switches suffering a failure and bringing down the aircraft have to be miniscule...
 

Bletchleyite

Veteran Member
Joined
20 Oct 2014
Messages
112,941
Location
"Marston Vale mafia"
Not impossible and it's important not to just assume which is why it's vital that the switches are checked and tested as part of the investigation. But the chances of the switches suffering a failure and bringing down the aircraft have to be miniscule...

I'm leaning this way too, i.e. towards the idea that a person switched them either deliberately or by mistake/in confusion. Though is there any commonality between them that could cause the same fault to switch both, e.g. incorrect installation?
 

TravelDream

Member
Joined
7 Aug 2016
Messages
1,158
I've spoken to many pilots and there is an issue with the switches. There is a cover up. Easy to blame the dead guys.

Which pilots are these? There aren't that many 787 pilots in the UK - Probably about a 1000-1500 between BA, Virgin, Norse and tui.

There are about 1250 787s in service and they have been operating commercially coming up to about 15 years now.

The 737 Max (and newer NGs) and the 777 family have essentially the same start switch mechanical design (the logic, especially on the 737, is different - but that's not what is being claimed as the problem). That's 1000s more aircraft.

If there were a problem that would cause both to fail almost simultaneously, it would have been noticed.
 

pug1

Member
Joined
6 Nov 2022
Messages
515
Location
Humber
That's the thing that I keep coming back to. The switches fitted the 787 (and I think with some other members of the 7x7 series of aircraft as I think it's shared design) must have accrued millions of flight hours, millions of switchings, day after day after day. The odds that not only one switch but two can encounter a catastrophic failure mode seconds apart and on the same aircraft at a critical moment of flight? Those odds must be stratospherically unlikely.

Not impossible and it's important not to just assume which is why it's vital that the switches are checked and tested as part of the investigation. But the chances of the switches suffering a failure and bringing down the aircraft have to be miniscule...
Going against my principles here but if we’re talking the purely hypothetical (I’m not by any means proposing this as a possible root cause) but there have been countless incidents and accidents that are made worse by the human input correcting the wrong failure. Kegworth being one example where the crew shut down the good engine after an engine failure with the resulting crash and fatalities. Now there is absolutely no procedure for touching fuel cutoff switches at or just after rotation, any engine failure (V1 cut) requires a priority to get away from the ground on the good engine. So it’s highly unlikely that one popped out of its desired location and the PM was busy shutting the wrong one down at that phase of flight.

I suspect this may be a catastrophic bag of problems, maybe why it’s taking so long to scrutinise the mechanical aspects of the thrust control module. We aren’t even aware of the full CVR transcript, but a snippet as far as I’m aware.
 

edwin_m

Veteran Member
Joined
21 Apr 2013
Messages
28,589
Location
Nottingham
If one of the pilots had detected a problem that required shutting down an engine, their training would tell them to say this to the other pilot and get agreement on the course of action such as which one to shut down. If that had happened then I think we'd know about it, as it's much less damaging to all concerned that what we do know which is something like "why did you shut down the engines?" and "I didn't". Also if a problem occurs right at takeoff, they should be climbing to a safer altitude before doing anything about it. So I don't believe the evidence available points to shutting down in response to a problem, only to a very unlikely concurrent failure or to intentional and malicious action.
 

pug1

Member
Joined
6 Nov 2022
Messages
515
Location
Humber
If one of the pilots had detected a problem that required shutting down an engine, their training would tell them to say this to the other pilot and get agreement on the course of action such as which one to shut down. If that had happened then I think we'd know about it, as it's much less damaging to all concerned that what we do know which is something like "why did you shut down the engines?" and "I didn't". Also if a problem occurs right at takeoff, they should be climbing to a safer altitude before doing anything about it. So I don't believe the evidence available points to shutting down in response to a problem, only to a very unlikely concurrent failure or to intentional and malicious action.
I’m not suggesting that is the case in this instance. Of course like I said the procedure for a V1 cut is to climb the aircraft away from the ground, all procedures (QRH/ECAM actions if Airbus) would be run through at a later point, once at a safe altitude. It was a tangent in response to ainsworth74s question.

In this instance there is just too scant information to even speculate. I’m disappointed that some have gone straight to intentional human interference, my point is that they will be completing the investigation in accordance with ICAO Annex 13, the fact they still appear to be scrutinising the mechanical suggests it might be some time before we get some answers, and all is not as ‘simple’ as some might think.
 
Last edited:

Cloud Strife

Established Member
Joined
25 Feb 2014
Messages
2,962
I'm leaning this way too, i.e. towards the idea that a person switched them either deliberately or by mistake/in confusion. Though is there any commonality between them that could cause the same fault to switch both, e.g. incorrect installation?

There's no real commonality there: the switches are held in place with independent brackets, so there's no possible way that both could be flipped at the same time through an incorrect installation. Boeing have had over a year to find something wrong and they haven't, and as much as Boeing is a mess these days, they're still not going to cover up issues with the switches or any other hardware if it could potentially cause another crash.

There was an interesting article recently on the BBC News website with this statement:


Cox says accidental switch movement is extraordinarily unlikely.

After reviewing the histories of Boeing's 757, 767, 777, 787 and 737 Max fleets - more than 400 million flight hours - he found no case in which a switch failure shut down an engine.

The chances of two such failures occurring within a second of each other, he says, are "one in a trillion or more".

The Canada-based investigator said the preliminary report made it clear that the crash resulted from "human action in the flight deck, not a mechanical or electrical problem with the aircraft".

The rest of the article is very interesting, because for instance, it seems as if the investigation will be able to correlate exactly when the engines failed with the moving of the switches.
 

LYuen

Member
Joined
20 Jun 2022
Messages
197
Location
Manchester
There's no real commonality there: the switches are held in place with independent brackets, so there's no possible way that both could be flipped at the same time through an incorrect installation. Boeing have had over a year to find something wrong and they haven't, and as much as Boeing is a mess these days, they're still not going to cover up issues with the switches or any other hardware if it could potentially cause another crash.

There was an interesting article recently on the BBC News website with this statement:




The rest of the article is very interesting, because for instance, it seems as if the investigation will be able to correlate exactly when the engines failed with the moving of the switches.
It is a conflicting design but there is no practical alternative - the fuel switches should not switched easily by accident, but pilots need to operate them quickly, as they are part of the memory items if they need to restart the engine mid-air.
Imagine - stalling a car at lights and muscle memory kicks in to get the car going again.
You can find videos of how to operate the switches - the 'pull and lift' process takes less than half a second for each engine. It meant to be easy and subtle, which can surprise the other pilot in the cockpit.

My personal speculation, I think the only missing piece is the timeline - whether the RAT deployment was initiated before or after one pilot did the fuel cutoff? If it was after, it could be some situation in the cockpit that (probably wrongly) triggered the pilot to cutoff fuel as part of the memory item. If it was before, there is no explanation. Either way, it was poor cockpit resource management not checking with the pilot before his action.
 

pug1

Member
Joined
6 Nov 2022
Messages
515
Location
Humber
It is a conflicting design but there is no practical alternative - the fuel switches should not switched easily by accident, but pilots need to operate them quickly, as they are part of the memory items if they need to restart the engine mid-air.
Imagine - stalling a car at lights and muscle memory kicks in to get the car going again.
You can find videos of how to operate the switches - the 'pull and lift' process takes less than half a second for each engine. It meant to be easy and subtle, which can surprise the other pilot in the cockpit.

My personal speculation, I think the only missing piece is the timeline - whether the RAT deployment was initiated before or after one pilot did the fuel cutoff? If it was after, it could be some situation in the cockpit that (probably wrongly) triggered the pilot to cutoff fuel as part of the memory item. If it was before, there is no explanation. Either way, it was poor cockpit resource management not checking with the pilot before his action.
There’d be no memory item at that phase of flight that would require cutoff movement. I’m not sure where rudder trim is on the 787 but on the aircraft I’m familiar with it’s not too far from the cut off switches, even then that’s a completely different input. I don’t envisage any way you could confuse the two at all, not least because you’d most likeky only use rudder trim in the case of a singe engine failure after V1 and you wouldn’t use it before suitably climbing away.

In terms of engine failure in flight, there is a memory item flow but the pilot monitoring will confirm actions the pilot flying is making at each point - with variations depending on nature of the event (I.e engine fire or mechanical failure).

I will caveat though, and again I don’t want to hypothesise at the moment because armchair investigating never considers the full picture, there are cases of pilots making otherwise completely notational selections during points of stress. That is absolutely not to say that’s what happened in this instance, as we have very little to go off it’s unwise to speculate in my view.

I do not buy Cloud Strifes final conclusions, I don’t think it’s physically impossible for there to have been a catastrophic malfunction. Also not to say that was the cause of this accident, but Boeing and the authorities are obviously spending a lot of time investigating the thrust control module - we also can’t rule out the possible impact of liquid spillages on the centre console…
 

Ted633

Member
Joined
15 Mar 2018
Messages
555
There’d be no memory item at that phase of flight that would require cutoff movement. I’m not sure where rudder trim is on the 787 but on the aircraft I’m familiar with it’s not too far from the cut off switches, even then that’s a completely different input. I don’t envisage any way you could confuse the two at all, not least because you’d most likeky only use rudder trim in the case of a singe engine failure after V1 and you wouldn’t use it before suitably climbing away.

In terms of engine failure in flight, there is a memory item flow but the pilot monitoring will confirm actions the pilot flying is making at each point - with variations depending on nature of the event (I.e engine fire or mechanical failure).

I will caveat though, and again I don’t want to hypothesise at the moment because armchair investigating never considers the full picture, there are cases of pilots making otherwise completely notational selections during points of stress. That is absolutely not to say that’s what happened in this instance, as we have very little to go off it’s unwise to speculate in my view.

I do not buy Cloud Strifes final conclusions, I don’t think it’s physically impossible for there to have been a catastrophic malfunction. Also not to say that was the cause of this accident, but Boeing and the authorities are obviously spending a lot of time investigating the thrust control module - we also can’t rule out the possible impact of liquid spillages on the centre console…
My initial theory was that one pilot may have operated them instead of the landing gear lever (muscle memory and all that). You’ll be amazed how many times flaps have been retracted instead of the gear! However, there were no call outs from the pilots (as far as we know anyway) that would’ve precluded a gear up selection. But that could just be because of poor standards.

I’m a licensed engineer on the 787 and have never known the fuel switches to be ‘sticky’ and be at risk of jumping out of their positions, despite countless engine runs.
I personally think a malfunction is out of the question. One pilot asked the other ‘why did you do the cutoff?’. That says to me the switches physically moved. If the switches didn’t move, that question wouldn’t have been asked. These switches cannot move on their own and would take a substantial whack to get them to move (which the CVR would easily pick up)
For me, this was either pilot suicide or a monumental balls up from one of the pilots.
 

pug1

Member
Joined
6 Nov 2022
Messages
515
Location
Humber
My initial theory was that one pilot may have operated them instead of the landing gear lever (muscle memory and all that). You’ll be amazed how many times flaps have been retracted instead of the gear! However, there were no call outs from the pilots (as far as we know anyway) that would’ve precluded a gear up selection. But that could just be because of poor standards.

I’m a licensed engineer on the 787 and have never known the fuel switches to be ‘sticky’ and be at risk of jumping out of their positions, despite countless engine runs.
I personally think a malfunction is out of the question. One pilot asked the other ‘why did you do the cutoff?’. That says to me the switches physically moved. If the switches didn’t move, that question wouldn’t have been asked. These switches cannot move on their own and would take a substantial whack to get them to move (which the CVR would easily pick up)
For me, this was either pilot suicide or a monumental balls up from one of the pilots.
I just don’t think, from the snippet of CVR transcript we’ve been allowed to see, which is as far as I’m aware literally what you’ve posted plus the mayday call 9 seconds after the switch(es) are set to RUN, that we can adequately deduce anything here at all.


The click of the switches should be audible on the CVR - they may be available on the Dreamliner DFDR as a discrete parameter within the frame layout too, or they may be derived from another sensor upstream - I’m not sure on that without access to the ARINC 429 (767 in the case of the Dreamliner?) layout/configuration documentation for that particular aircraft*. Even so, the data can be compromised in the event of electrical surge/unusual state rendering it, at that specific moment, invalid.

It is plausible that the switches themselves never moved at all, but the system believed they did downstream and the sensors picked this up and the derived switch positions established that they were at CUTOFF purely because of this. Because the full CVR transcript hasn’t been released, we do not know whether this is the case or not - however if it’s confirmed that the RAT deployed before cutoff, as some accounts suggest, then a downstream failure is more plausible than simply human error/input. ELMS/FADEC/fire logic can change the commanded state without physical movement of the switches. Indeed I believe these considerations have been one of the reasons for the delay in publishing the final draft report, whilst Boeing and GE do a deep technical dive.

As far as ICAO ANNEX 13 is concerned the investigations follow an interrelated pattern of technical, human and organisational because they are often consequential and can identify systemic failures that require all the holes in the ‘Swiss Cheese’ to line up before they identify a risk. Sadly sometimes it can take catastrophic events to manifest and become apparent subsequently!

It could of course be intentional human interference, but as I continue to caution it is by no means nailed on and there is zero evidence of a cover up at this time. Accidents such as these often have countless avenues for investigation and given the time they’re putting into it I would suggest it may not be a simple case of intent or even ‘monumental balls up’.

I find it interesting, with reference to the BBC article linked to slightly up thread, that the one ‘commentator’ who is apparently involved in Canadian air safety ‘chose’ to remain anonymous. I’m always skeptical when a ‘source said’, because often times that source is either not credible or simply made up. In the case of the BBC I’m tending towards the former. Having been involved peripherally in numerous air safety investigations (internally, thankfully usually events that no external party would ever read - certainly [touch wood] no fatal events!) the caution is always that it’s human nature to jump to the conclusion and make the root cause fit the event. Investigators are trained not to do that. This goes for the Indian investigators too.

*on further research it would appear the switches do record as a discrete parameter.
 
Last edited:

edwin_m

Veteran Member
Joined
21 Apr 2013
Messages
28,589
Location
Nottingham
It is plausible that the switches themselves never moved at all, but the system believed they did downstream and the sensors picked this up and the derived switch positions established that they were at CUTOFF purely because of this. Because the full CVR transcript hasn’t been released, we do not know whether this is the case or not - however if it’s confirmed that the RAT deployed before cutoff, as some accounts suggest, then a downstream failure is more plausible than simply human error/input. ELMS/FADEC/fire logic can change the commanded state without physical movement of the switches. Indeed I believe these considerations have been one of the reasons for the delay in publishing the final draft report, whilst Boeing and GE do a deep technical dive.
None of that is consistent with what we do know from the CVR.

If Pilot 1 didn't directly observe or hear pilot 2 moving the switches then he would have become aware when both engines started spooling down, which has a number of other causes that are fairly unlikely but more plausible than his colleague turning the switches off at that critical moment. So if he asked pilot 2 why he turned off the switches then he must have been thinking through possible causes and observed the switches had been turned off. If pilot 2 had done so deliberately and maliciously then it would be natural for him to deny it, whereas if it was some kind of muscle memory they I doubt pilot 2 would have done so.

It's also possible that pilot 1 turned off the switches then asked pilot 2 why he did it in an attempt to throw blame elsewhere (the CVR has separate channels for each pilot so they will know who said what). But either of these points to a deliberate intent by one of the pilots.

The probability of both switches operating spontaneously within a second of each other is vanishingly small - as mentioned the number of flight hours across all aircraft fitted with this type of switch is immense, and there have been no reports of anything like that. On the other hand there has been at least one confirmed case of pilot suicide (Germanwings) and several more strongly suspected. So in my view deliberate pilot action is the more likely cause - though I do agree the investigators should go to all possible lengths to investigate other possible explanations.
 

pug1

Member
Joined
6 Nov 2022
Messages
515
Location
Humber
None of that is consistent with what we do know from the CVR.

If Pilot 1 didn't directly observe or hear pilot 2 moving the switches then he would have become aware when both engines started spooling down, which has a number of other causes that are fairly unlikely but more plausible than his colleague turning the switches off at that critical moment. So if he asked pilot 2 why he turned off the switches then he must have been thinking through possible causes and observed the switches had been turned off. If pilot 2 had done so deliberately and maliciously then it would be natural for him to deny it, whereas if it was some kind of muscle memory they I doubt pilot 2 would have done so.

It's also possible that pilot 1 turned off the switches then asked pilot 2 why he did it in an attempt to throw blame elsewhere (the CVR has separate channels for each pilot so they will know who said what). But either of these points to a deliberate intent by one of the pilots.

The probability of both switches operating spontaneously within a second of each other is vanishingly small - as mentioned the number of flight hours across all aircraft fitted with this type of switch is immense, and there have been no reports of anything like that. On the other hand there has been at least one confirmed case of pilot suicide (Germanwings) and several more strongly suspected. So in my view deliberate pilot action is the more likely cause - though I do agree the investigators should go to all possible lengths to investigate other possible explanations.
With all due respect this is the difference between investigative analysis and armchair speculation. Note that I was offering plausible avenues for investigation, certainly not an exhaustive list of considerations

‘The CVR is not consistent’? I’ve made the point quite clearly that we’ve not seen the transcript. We’ve been fed comments made with zero context. We do know one pilot said ‘why did you move the switches’ the other pilot said ‘I didn’t’. We had a mayday call. It’s well known in human factors that startle factor impacts conscious decision making for between 30 and 60 seconds. From the moment of the event to the moment of impact we had 30-40 seconds. We cannot simply deduce from snippets of a CVR transcript what was occurring on the flight deck, if anything that short snippet is potentially completely misleading and is without context.

You raise the point of Germanwings, this is a complete red herring. We knew the cause of this event within 48-72 hours. It is over a year since the AI171 incident, yet we are none the wiser, had Boeing suspected foul play, they would most likely have at least alluded to it at this point. Regardless of mistrust of the investigating authorities agenda, which in itself is questionable since there are other Indian agencies contributing to lengthy delays to prevent this intentional interference narrative from permeating, at least prematurely and without an exhaustive multi faceted investigation.

The investigators simply do not have conclusive evidence yet, hence the reason for the delays.
 
Last edited:

Belperpete

Established Member
Joined
17 Aug 2018
Messages
3,584
That's the thing that I keep coming back to. The switches fitted the 787 (and I think with some other members of the 7x7 series of aircraft as I think it's shared design) must have accrued millions of flight hours, millions of switchings, day after day after day. The odds that not only one switch but two can encounter a catastrophic failure mode seconds apart and on the same aircraft at a critical moment of flight? Those odds must be stratospherically unlikely.
But the situation I described was not a catastrophic failure, but a switch failing to latch because it has not been operated correctly. In such a scenario, with the same pilot operating both switches, it is likely that he will be operating both switches in the same manner, giving a common mode failure mechanism. If only one pilot out of thousands is doing this, and only one in every thousand of his switchings fails to latch, you could easily build up millions of no-issue switchings.

As I said, my experience with a similar type of "lift, pull, drop" switch in a different application was that we could get a situation where if you pushed it across with one finger, you could get it into a state where it didn't latch correctly. It took a lot of patience, many attempts, and we had to push the switch very slowly, but if we tried hard enough we could get the switch into that state. We weren't too bothered, as in our application the consequences were merely undesirable, not catastrophic, and the likelihood of it happening in practice were considered negligible. But there was a possibility of getting the switch in that position. It was the only explanation we could find why the switch had turned off by itself.

From the photos I have seen, the two switches seem to be quite close together, and in a position where a pilot could accidentally brush a jacket or shirt sleeve against both together, when leaning over them to operate a control further back. It is therefore critical that the switches should latch properly, to avoid accidental operation.

I would therefore expect the investigation to rule out any possibility of a switch failing to latch correctly. Because if there is even a remote possibility of a switch failing to latch, then there will be a possibility of both switches failing to latch, particularly if there is a common mode failure mechanism.

The idea that something has worked thousands or millions of times without problem is superficially reassuring. However, if the probability of something going wrong is extremely low, say one in a million, then you may need several million operations before the problem is realised. Or circumstances to have changed in some way.
 

pug1

Member
Joined
6 Nov 2022
Messages
515
Location
Humber
But the situation I described was not a catastrophic failure, but a switch failing to latch because it has not been operated correctly. In such a scenario, with the same pilot operating both switches, it is likely that he will be operating both switches in the same manner, giving a common mode failure mechanism. If only one pilot out of thousands is doing this, and only one in every thousand of his switchings fails to latch, you could easily build up millions of no-issue switchings.

As I said, my experience with a similar type of "lift, pull, drop" switch in a different application was that we could get a situation where if you pushed it across with one finger, you could get it into a state where it didn't latch correctly. It took a lot of patience, many attempts, and we had to push the switch very slowly, but if we tried hard enough we could get the switch into that state. We weren't too bothered, as in our application the consequences were merely undesirable, not catastrophic, and the likelihood of it happening in practice were considered negligible. But there was a possibility of getting the switch in that position. It was the only explanation we could find why the switch had turned off by itself.

From the photos I have seen, the two switches seem to be quite close together, and in a position where a pilot could accidentally brush a jacket or shirt sleeve against both together, when leaning over them to operate a control further back. It is therefore critical that the switches should latch properly, to avoid accidental operation.

I would therefore expect the investigation to rule out any possibility of a switch failing to latch correctly. Because if there is even a remote possibility of a switch failing to latch, then there will be a possibility of both switches failing to latch, particularly if there is a common mode failure mechanism.

The idea that something has worked thousands or millions of times without problem is superficially reassuring. However, if the probability of something going wrong is extremely low, say one in a million, then you may need several million operations before the problem is realised. Or circumstances to have changed in some way.
Agreed, and sensible in the spirit of the hypothetical. In my experience, even in otherwise non-newsworthy air safety events, there is rarely one single point of failure. Often times it is a systemic or systematic failure that has played out because all of the holes in the ‘Swiss Cheese’ aligned.
 
Last edited:

Annetts key

Established Member
Joined
13 Feb 2021
Messages
3,787
Location
West is best
As I have said before, in order to have a good enough understanding of the system, we need to know how the cut-off switches are actually wired up including the supply feed and what they actually feed.

Is the feed to each cut-off switch fed via an independent fuse or MCB (trip) or do they share a single fuse or MCB (trip)?

Or do they share a supply with some other equipment?

Do they directly feed to each fuel pump? Do they feed a relay that then controls the fuel pump? Or are they wired as inputs to an electronic or computer module,which then controls the fuel pumps?

Without these details, the speculation is pointless.

I do agree that a mechanical failure of both switches is unlikely, especially going on what little information we have.
 

Cloud Strife

Established Member
Joined
25 Feb 2014
Messages
2,962
had Boeing suspected foul play, they would most likely have at least alluded to it at this point.

I would argue the opposite, actually. This is a (regional) cultural problem: even alluding to pilot suicide would have the Indian public demanding blood, and the Indian aviation market is absolutely vital for Boeing. For that reason, I think they're content to do exhaustive research, with their (lack of) actions telling the story to those that can read between the lines.

It's also possible that pilot 1 turned off the switches then asked pilot 2 why he did it in an attempt to throw blame elsewhere (the CVR has separate channels for each pilot so they will know who said what). But either of these points to a deliberate intent by one of the pilots.

So, what should be the case:

The pilot flying in the right hand seat would have had his hands on the yoke, looking out through the HUD. With the fuel switches where they are, he wouldn't have had them in his peripheral vision, especially not when looking through the HUD. So, I think he can be ruled out as responsible here: if his hands were anywhere *but* the yoke, the captain would have been duty bound to question what he was doing and why. Given the very hierarchical nature of India, it seems highly unlikely that the captain would simply ignore his first officer having his hands astray on takeoff.


This video is well worth a watch: it shows the takeoff procedure for the first officer (in the right hand seat) flying. You can see at the V1 call, the captain removes his hand from the throttle, and "rotate" is called out shortly afterwards. The pilot flying is looking through his HUD the entire time, he doesn't need to look at the instruments or otherwise. So, you can see how easy it would be for the captain to move the switches unnoticed. The exact timeline will be crucial, and this really should have been published in the first report.
 

pug1

Member
Joined
6 Nov 2022
Messages
515
Location
Humber
I would argue the opposite, actually. This is a (regional) cultural problem: even alluding to pilot suicide would have the Indian public demanding blood, and the Indian aviation market is absolutely vital for Boeing. For that reason, I think they're content to do exhaustive research, with their (lack of) actions telling the story to those that can read between the lines.



So, what should be the case:

The pilot flying in the right hand seat would have had his hands on the yoke, looking out through the HUD. With the fuel switches where they are, he wouldn't have had them in his peripheral vision, especially not when looking through the HUD. So, I think he can be ruled out as responsible here: if his hands were anywhere *but* the yoke, the captain would have been duty bound to question what he was doing and why. Given the very hierarchical nature of India, it seems highly unlikely that the captain would simply ignore his first officer having his hands astray on takeoff.


This video is well worth a watch: it shows the takeoff procedure for the first officer (in the right hand seat) flying. You can see at the V1 call, the captain removes his hand from the throttle, and "rotate" is called out shortly afterwards. The pilot flying is looking through his HUD the entire time, he doesn't need to look at the instruments or otherwise. So, you can see how easy it would be for the captain to move the switches unnoticed. The exact timeline will be crucial, and this really should have been published in the first report.
Problem is I know for a fact you’re absolutely wrong, looking at this from rather extreme prejudice and using that to create your own narrative of what’s happened. Nothing more. Your point about not having the switches in his peripheral vision is absolute garbage too - the physical switches may not be in a given moment, but the actions of the PM absolutely would be if it were to be the movement of the switches.

Let’s stay with evidence rather than speculation. Your argument relies on cultural assumptions and video‑based inference of a situation that hasn’t even been confirmed (who was PF/PM) and even the CVR transcript has not, as far as I can see, confirmed who said what. All of this still fails to address the electrical/systemic failure modes, the derived vs physical switch state issue, the valid questions over when the RAT deployed (this is extremely important, as there’s a discrepancy here) or the 30–60 second startle window which can and does make even highly trained pilots act irrationally, including using incorrect memory actions. Until those are eliminated - and many other things you simply would never consider, intent cannot be asserted.
 
Last edited:

Belperpete

Established Member
Joined
17 Aug 2018
Messages
3,584
That's the thing that I keep coming back to. The switches fitted the 787 (and I think with some other members of the 7x7 series of aircraft as I think it's shared design) must have accrued millions of flight hours, millions of switchings, day after day after day. The odds that not only one switch but two can encounter a catastrophic failure mode seconds apart and on the same aircraft at a critical moment of flight? Those odds must be stratospherically unlikely.

Not impossible and it's important not to just assume which is why it's vital that the switches are checked and tested as part of the investigation. But the chances of the switches suffering a failure and bringing down the aircraft have to be miniscule...
Agreed, but if you apply the same logic to the aircraft type, how many millions of hours, day after day, that type of aircraft has operated without incident, then the chances of an incident with the aircraft has also to be miniscule. But it happened, which is why the miniscule cannot and should not be ruled out.

To take an analogy with the rail industry. A wrong side failure occured. The contacts of a relay had become sticky, and very occasionally one of its contacts wasn't opening. Now, there are thousands of this type of relay in service, and they had racked up millions of hours in service, probably billions of switching operations without incident. So why had this particular relay failed? Detailed testing found that the heat from the relay coil was evaporating the glue on the label attached to the relay coil. How could this happen? Every component in the relay was highly specified, right down to the type of sticky label to be used. It was found that the label manufacturer had changed the type of glue being used, and had failed to tell the relay manufacturer. So this relay wasn't in fact exactly the same as all the seemingly thousands of identical relays.

So why hadn't other relays with the same label failed in the same way? Because there were slight differences in how often they were operated, the temperatures of the relay rooms they were in, etc etc. However, the potential for other relays to fail in the same way was there, so every relays using that type of label had to be tracked down and replaced.

For two components to fail together, usually needs some kind of common mode failure mechanism. However, there are a lot of things common to those two switches that may be different to other seemingly identical switches. The people operating them, their close proximity, the particular cockpit they were in, the fitter who installed them, where and how they were stored prior to fitting them, who made them, the manufacturing batch, etc etc. So again, although highly unlikely, I don't believe that a common mode failure can be ruled out, out of hand.

Just because there is a miniscule chance of something happening, doesn't mean it didn't happen.
 

pug1

Member
Joined
6 Nov 2022
Messages
515
Location
Humber
Agreed, but if you apply the same logic to the aircraft type, how many millions of hours, day after day, that type of aircraft has operated without incident, then the chances of an incident with the aircraft has also to be miniscule. But it happened, which is why the miniscule cannot and should not be ruled out.

To take an analogy with the rail industry. A wrong side failure occured. The contacts of a relay had become sticky, and very occasionally one of its contacts wasn't opening. Now, there are thousands of this type of relay in service, and they had racked up millions of hours in service, probably billions of switching operations without incident. So why had this particular relay failed? Detailed testing found that the heat from the relay coil was evaporating the glue on the label attached to the relay coil. How could this happen? Every component in the relay was highly specified, right down to the type of sticky label to be used. It was found that the label manufacturer had changed the type of glue being used, and had failed to tell the relay manufacturer. So this relay wasn't in fact exactly the same as all the seemingly thousands of identical relays.

So why hadn't other relays with the same label failed in the same way? Because there were slight differences in how often they were operated, the temperatures of the relay rooms they were in, etc etc. However, the potential for other relays to fail in the same way was there, so every relays using that type of label had to be tracked down and replaced.

For two components to fail together, usually needs some kind of common mode failure mechanism. However, there are a lot of things common to those two switches that may be different to other seemingly identical switches. The people operating them, their close proximity, the particular cockpit they were in, the fitter who installed them, where and how they were stored prior to fitting them, who made them, the manufacturing batch, etc etc. So again, although highly unlikely, I don't believe that a common mode failure can be ruled out, out of hand.

Just because there is a miniscule chance of something happening, doesn't mean it didn't happen.
Another good and grounded post.

Without teaching anyone to suck eggs, the Swiss Cheese model is hammered into anyone who is involved in event investigation, not just aviation but healthcare, railways etc too.

In the simplest terms what @Belperpete and in a way I have been saying is that accidents and incidents do not often have one causal factor, they have numerous. It’s a case of all of the holes in the Swiss cheese lining up.


In aviation hazards/risks are based on probability per flight hour.

> 1 in a billion = Catastrophic - Aircracft Grounded

1 in 10 million to 1 in 100k = Tolerable - Acceptable only if mitigated to as low as reasonably practicable

1 in 100k to 1 in 1000 = Acceptable - Allowed to persist with standard monitoring.

What the authorities, Boeing and GE and others may be doing is assessing various possible systemic failure-chains (incorporating the human - mechanical - organisational) to see whether some of the risks deemed acceptable and tolerable lined up together to become catastrophic in this instance. The fact there was no global fleet-wide grounding makes this plausible.

This is not to say that I don’t believe human interference wasn’t at play. It’s to try to distance the conversation from confirmation bias based off very little evidence. I’m keeping an open mind until more information is officially released.
 
Last edited:

ainsworth74

Forum Staff
Staff Member
Global Moderator
Joined
16 Nov 2009
Messages
31,067
Location
Redcar
Okay I think we might be going in circles again at this point (and I'm slapping my own wrist as I've contributed to it!) so I reckon the last couple of posts are probably the right moment to have a pause here until there's more actual information coming to light. We can debate what might or might not have happened, who might or might not have done something, which switch/relay/component might or might not have worked as intended and so and so forth until the cows come home. Until we've got more information from the investigation we're basically guessing. Let's reconvene to chew over things once there's actually new information.
 
Status
Not open for further replies.

Top