Friday, April 17, 2015

Could a Hacker Shut Down the Engines Using Onboard Wifi?

Sitting down with my morning coffee and iPad, I came across a piece of aviation clickbait that seemed to be of the standard  "seven things pilots don't want you to know" variety. The report was about a computer security expert being pulled off a United Airlines flight and questioned by the FBI about hacking into airplane systems.

The expert being questioned was a man named Chis Roberts, CTO of One World Labs, who had previously claimed that vulnerabilities in aircraft in-flight entertainment systems could possibly be used to "turn the engines off at 35,000 feet". The tone of the report was that of the breathless whistleblower sort where a person with critical knowledge was being corralled by "the system". Think Erin Brockovich of the skies I suppose.

At first blush, I thought the whole concept of hackers infecting avionics was ridiculous and that this guy, who's firm had three employees in 2011, was simply a self promoter selling a bit of sensationalism. After listening to an interview with him, I'm not so sure that his premise is completely implausible.

For a hacker to gain access to aircraft data and control systems there has to be some sort of link. That is, if the systems are not physically connected, there can't be any way to get in. So I was thinking that's that: there's no connection between passenger entertainment systems and the cockpit, but I was wrong. There is.

Most entertainment systems, including the wifi on the planes I fly, feature flight tracking information which comes from the aircraft's air data and flight management computers. Information like arrival times, flight plan, altitude, heading and airspeed comes from flight computers and is relayed through a data bus to the wifi and entertainment systems.

Knowing that this data bridge exists, could a resourceful hacker exploit this path to cause trouble? My thought is that if there is a will there is a way. I am no computer guru as my expertise in coding consists of some Fortran language skills used in college many decades ago, but I also know that many computer experts consider no computer network to be completely invulnerable.

If anyone remembers the Stuxnet affair of a few years back, hackers (who were eventually revealed as US intelligence assets) were able to infiltrate Iranian computer networks. They inserted malware which found it's way to the controllers of the centrifuges the Iranians were using to purify uranium. The bug subtly caused the machines to tear themselves apart setting the program back years.

This was an international effort complete with skullduggery which included breakins at some Taiwanese firms to get computer keys which allowed access to the networks and centrifuges. I'm still waiting for the movie. So it seems to me to be at least plausible that airplane systems could be exploited.

I guess that begs the question of why someone would wish to sabotage an airplane on which they were riding, but I think we know the answer to that one. Or, should a method be perfected, an innocent mule could then be sent on a one way trip with a laptop.

Am I particularly worried about my engines shutting down unexpectedly on my next flight? Not really. The 737s I fly have old school hydraulic flight controls, and while the engine controls are electronic, the fuel shutoff valves are not. But on the newest Boeings and Airbuses, you can pretty much count on everything being controlled by some sort of computer.

Make no mistake, the computers on commercial aircraft are extremely robust and designed with multiple failure modes but they are still computers. Simple safety features such as air gaps to isolate critical systems or perhaps unwritable firmware might be employed as countermeasures. An even simpler solution might be to completely isolate all passenger and airplane systems. Get the inflight data from a parallel but separate system.

I can't imagine that this subject has not been discussed and considered by the designers of aircraft computer architecture. A quick search found at least one commercial firm offering software security services for airlines. Apparently the FBI had some concerns. And as the gentleman on the interview mentioned, such an effort would require an expert depth of knowledge of the design of many different control and software systems to pull it off.

It seems that not a day goes by where we don't hear about crappy software or shoddy network security practices resulting in the theft of millions of credit cards or corporate technology. Software designers of avionics have enough of a headache just getting all their millions of lines of code to work properly without having to consider the additional burden of potential malware gumming up the works.

Let's hope that they have this on their radar.

Monday, April 13, 2015

The Great Cockpit Photography Kerfuffle


Inarguably, one of the best parts of the job of being a pilot is the view from the office. It is simply incomparable. From a predawn takeoff where the oncoming glow on the horizon is set off by runway and city lights, to perhaps a night run over central Arkansas during a summer electrical storm where bolts of lightning dance around towering anvil topped clouds, the scenery is awe inspiring.

I never tire of flying the Expressway Visual into LaGuardia as it takes you directly over Brooklyn and Queens providing an unparalleled view of Manhattan (at least from the left seat). Every now and again we get to fly up the Hudson river when landing on Runway 13, giving copilots an even better view of downtown. The Gateway Arch, the Columbia River with Mt. Hood and Mt. Rainier lining up in a perfect frame, the turquoise blue water off southern Florida beaches or a view of Yosemite's Half Dome and El Capitan from above are all routine sights in this job.

I have over the years flown over places like Mt. Fuji, the Arabian Peninsula, Sydney and London to name only a few. Being naturally proud of what they do, pilots like to take pictures of where they've been and the sights they've seen. And the taking of pictures by pilots has never really been a problem as the photographs taken would usually end up in an album on a shelf somewhere or perhaps on a quickly forgotten hard drive.

That all changed with the coming of social media. For in the game of collecting likes and impressing your friends from school who took that accounting job, what better way could there be of showcasing your awesome life than to post pics and selfies from 35,000 feet? And that is more or less exactly what happened. Pictures and videos from the cockpit can, or rather could, be found all over the internet. That is until some killjoy asked the inconvenient question of umm, if you're being a tourist up there, then who's flying the jet?

It's a valid question. The answer is a simple one. The other guy or the autopilot. But of course that's an incorrect answer. The people who own the airplanes and the people who ride in the back generally think it best if both pilots are paying attention to the flying part. It's not an unreasonable request I suppose, and certainly not while on approach. This, then, is the setup for the great cockpit photography kerfuffle.

In December last year, an online magazine called Quartz published a piece detailing how cockpit photos had been showing up on Instagram, and how the taking of these photos violates FAA rules. In the course of gathering information for the article, author David Yanofsky scraped dozens of cockpit photos from the Instagram accounts of pilots who had neglected to set their privacy controls. These photos, including selfies with names, were then published in the article.

What happened next may serve as a signpost to how social media is changing culture or perhaps how already existing trends are highlighted by social media, because some of the pilots who were "outed" in the Quartz expose went on the attack. Author Yanofsky was harassed and threatened himself through many social media sites. Returning fire with fire, editors at Quartz then researched the information of the harassers and contacted the employer of at least one of them.

I guess one lesson learned here is that if you are going to engage in online guerrilla warfare, at least learn how to mask your own IP address.

As everyone from cops to pilots to doctors and other professionals is finding out, ubiquitous cell phone cameras coupled with social media are rapidly highlighting the fishbowl that modern society is becoming. Living in a panopticon society will have far reaching effects which can only be imagined at this point. This, coupled with a growing distrust of professionals and authority figures, may perhaps induce a reaction to publicly lived and posted lives. It certainly will for the pilots in this article.

I personally think that including the names and selfies of some pilots in the article was rather rude as Quartz could've made their point without publishing anyone's personal info. But then again these guys probably should've figured out how to control the privacy settings of their accounts or perhaps just not taken selfies while at work. And some of the pilots involved may not have known that they were breaking some rule or other.

In their defense, the rule prohibiting all photography, and not just that below 10,000 feet is relatively new but restrictions on any non-flight related activity below 10,000 feet have been around for awhile. The FAA has said it is not contemplating any enforcement actions as a result of this article and may actually be gratified that this event has served to publicize the new rules.

Will this kerfuffle stop pilots from taking pictures while flying? Probably not, but you are much less likely to see any such snaps online.

Friday, April 03, 2015

Lubitz Planned Mass Murder

New evidence has been uncovered by investigators suggesting that Andreas Lubitz premeditatively planned to crash his plane some time prior to the actual crash. From the Wall Street Journal:

The prosecutor heading the investigation said Thursday that a tablet computer found in Mr. Lubitz’s apartment contained a record of searches for medical treatments, suicide methods and cockpit security.

I'm no psychiatrist, but my feeling is that this act goes beyond the self destructive urges that may be visited upon a mind struggling with depression alone. Lubitz is beginning to look more like a psychopath. His act was immoral and evil.

Perhaps an argument can be made that he was by definition insane because mentally healthy people do not commit mass murder. And because of his illness, he is therefore absolved of any personal guilt. It's the old debate over the insanity defense.

But to deny any moral agency in a man who was otherwise able to function highly enough to be hired, trained, and employed in a highly trusted and technical job is too facile for my taste. I also can't help thinking that this argument is somewhat circular. Some apples are just bad.

This past week I flew a three day trip and was thankfully spared some of the usual smart remarks about being drunk or in this case being sane that some wiseacre can often be counted on to make while boarding. Truth be told, I am often tempted to respond with "not as far as you know" to the drinking accusations or "as long as I stay on my meds" to the latest questions of mental fitness.

But for obvious reasons I just smile and wave. Many people are nervous getting on an airplane, and I totally get that. A weak attempt at humor is an effort to dispel the unease which comes along with confining oneself like a sardine in an aluminum tube to be hurtled through the air at ungodly speeds. Some guys I fly with take great offense at such jests, but of all the insults to be suffered in life, this is a minor one.

It may be the reason, though, why more pilots seem reticent to greet customers as they board.

Black Box Found

Crash site searchers have located the DFDR, or digital flight data recorder from Flight 9525 which records actual flight parameters and control inputs. The data have revealed that multiple pilot inputs were made commanding the doomed jet to accelerate towards the ground.

These results add further confirmation to the conclusion that the Airbus was deliberately crashed into the Alps and that the crash was not the result of some malfunction in the aircraft. This should help to dispel some of the alternate narratives concerning mechanical causes of the crash.

Friday, March 27, 2015

Murder-Suicide by Plane

An analysis of the CVR from Germanwings 9525 now makes it clear that copilot Andreas Lubitz deliberately locked his captain out of the cockpit and then flew his A320 with 150 passengers into a mountain. There has been speculation that Lubitz suffered from bouts of depression, and there is no doubt that investigators will comb through every bit of his past for clues that might explain his actions.

Finding a history of mental illness will be of little consolation to the friends and relatives of the murdered passengers and crew.  What will matter is explaining how this happened and how it can be prevented from happening again. This was essentially a single point failure due in part to policy, and would be unlikely to happen in the US.

Let me explain.

After 9/11 all airlines globally were required to armor and enhance cockpit doors to prevent a breach. This enhancement included provisions to gain entrance in case of a lockout. A code entered into a keypad by the door unlocks the door in a specified amount of time while alerting the cockpit. Should someone in the cockpit hear this alert, they can push a button which then denies access. There is also a simple deadbolt which can be thrown to deny access.

So if someone is up front and wishes to keep out intruders, the door is essentially impregnable. Recognizing the potential for one person to gain access and then lock the door, the FAA designated the cockpit a "no lone zone" meaning that should a pilot exit the cockpit for whatever reason in flight, a flight attendant had to replace him or her up front. Once up front, the door opens with a simple twist of the door knob. Theoretically, should a rogue pilot or flight attendant attempt anything, it would be easy to open the door to call for help.

At least those are the rules for US airlines. Apparently for whatever reason, the rule was not made or enforced in Europe and other places. After this tragedy, the rule is being quickly changed. Aviation authorities and politicians will now have to explain why the rule was not adopted in Europe.

Mental Health Questions

There has been speculation backed up with some anecdotal evidence that Lubitz had suffered from depression in the past. Questions are now being asked about what sort of mental health screening prospective airline pilots undergo. The answer is very little.

After leaving the military, I interviewed with four airlines before being hired. The process was similar at each airline and included a series of document and background checks along with a series of interviews. As far as any mental health screening, two of the four airlines required the completion of a standard personality inventory such as the MMPI while two did not.

Personality inventories are multiple choice questionnaires designed to assess personality types. Some major US airlines are known to give psych evals with a medical professional, but this is not the rule. I have no idea whether the results of these tests are used to eliminate pilot candidates, but that was the extent of any mental health screening I've ever received. I myself might be completely starkers for all I know. My wife certainly has doubts. My extended family, on the other hand, has no doubts whatsoever.

So should mental health questions arise in a pilot, they will be either self reported or evident through behavior observed by family or co-workers. All pilots undergo routine annual (semi-annual for captains) physicals and by law must report to the FAA any visits to medical professionals or any medications taken. The flight doc checks your vision, listens to your ticker, and has you pee in the cup before collecting his $150 (cash or check only, please) before sending you on your way. That's it.

As far as the FAA is concerned, any condition requiring medication will initially result in the pilot being grounded until evaluated by an AME (aviation medical examiner). The FAA specifically mentions four SSRI drugs which can be used while maintaining a medical qualification after appropriate evaluation. They are Prozac, Zoloft, Celexa, and Lexapro. Conditions requiring other drugs in this category are grounding. While not familiar with European medical policy, it can be assumed that it is similar to that of the US.

It's easy to see that should a pilot suspect that he may have a condition requiring a mental health examination, it might very well ground him. Not exactly a positive incentive to self report depression or anxiety to the flight doc.

The latest reports indicate that Lubitz was in possession of a medical notice grounding him but had torn it up. Watching a life's dream escape through his fingers while also suffering from depression might have been just enough to send him over the edge.

This was an unspeakable tragedy for all involved, including Lubitz and his family. For some time now, post 9/11 security enhancements were thought to be mainly a problem for American air carriers. This attitude may have contributed to a somewhat lax posture towards cockpit security procedures in Europe. This tragedy will understandably force a reassessment of all cockpit security procedures worldwide.

Wednesday, March 25, 2015

Germanwings 9525

Airliners are not supposed to just drop out of the sky.

For the second time in nearly as many months, an Airbus A320 has fallen from altitude and crashed resulting in the deaths of all aboard. The latest accident occurred over the south of France.

Germanwings 9525, enroute from Barcelona to Dusseldorf with 144 passengers and 6 crew, had just levelled off at 38,000 ft when after a minute or so it started a descent. In the 8 minutes between the start of the descent and the impact of the aircraft into the Alps, no communications were heard from the cockpit crew in spite of multiple air traffic control attempts.

The descent, which averaged about 3300 ft per minute is not unusually steep for an airliner. The aircraft also maintained it's flight planned course during the descent suggesting that some measure of automation was still functioning. 

The wreckage is in a remote mountainous area in the French Alps and will present serious difficulties in recovery efforts. There are no expectations of finding survivors due to the violent nature of the impact into steep terrain.

The cockpit voice recorder (CVR) has been recovered and while damaged, has been able to have audio files retrieved by French accident investigators. The flight recorders have not as of yet been located.

At this point, speculation is running rampant but generally pointing in the direction of some sort of loss of cabin pressure resulting in the incapacitation of the crew. This would explain the lack of communication with the pilots. Loss of pressurization at 38,000 ft (FL380 in airline jargon) would result in what's known as a "time of useful consciousness" or TUC of about 20 to 30 seconds. 

That means that the pilots would have about 20 seconds to get their oxygen masks on and to start a descent before succumbing to hypoxia. Loss of cabin pressurization was the cause of the crash of Helios 522, a Greece based airliner in 2005, and also the death of golfer Payne Stuart when the Lear Jet he was riding in lost pressurization. 

Currently there appears to be no suspicion by investigating authorities of terrorism or foul play. Witnesses have reported that the aircraft appeared intact and flying normally except for its low altitude. This would seem to at least preclude an on board explosion.

Any theories given at this early stage in the investigation will be grounded in speculation at least until the CVR transcript can be analyzed or the flight data recorder is found. 

UPDATE: The New York Times is reporting tonight that the CVR indicates that the first officer exited the cockpit at cruise and was not able to re-enter. This development changes the fundamental nature of the investigation.

Tuesday, March 24, 2015

Germanwings A320 Down

A budget European airline A320 has crashed in the south of France in mountainous territory.  As of now, no survivors are expected. More to follow.

Monday, March 16, 2015

Delta 1086 Took Down Nearly 1000 Feet of Fence

Missing fence at LGA (click to enlarge)

Not happy with the media coverage of Delta Flight 1086 and being a seriously dedicated blogger, I decided to travel to LaGuardia to check out the situation myself.

No, not really.

Actually, my trip just happened to take me through LGA last week, and I was able to see exactly where DL 1086 went off the runway and almost into Flushing Bay. What surprised me was that nearly 1000 feet of the fence which was atop the berm that separates the airfield from the bay had been knocked down.

News coverage photographs gave the appearance of only a small section of fence that had been knocked down by the nose of the aircraft. What was not apparent was the nearly 1000 feet of fence that had been knocked over by the MD-88s left wing.

NTSB reports indicate that the aircraft had a normal approach and landing at 133 knots, but that the aircraft started to drift left upon touchdown. The missing fence was between the 3000 and 2000 foot distance remaining markers. Distance remaining markers are large signs along the runway indicating how many thousands of feet are remaining to the end.

A buddy showed me a photo taken in the hangar of the left wing of the MD-88 which was badly damaged by the fence. There were also some reports of leaking fuel which luckily did not ignite.

Monday, March 09, 2015

Possible Brake Malfunction on Delta 1086

An article in today's Wall Street Journal details that investigators are suspecting that the MD-88 which departed the runway at LaGuardia last week may have had a brake problem:

After a normal approach and touchdown, thrust-reversers were deployed as expected, but the plane still veered off the runway at roughly 100 miles an hour, said one of those people familiar with the situation. 
Based on preliminary information retrieved from “black box” recorders and pilot interviews, this person said, investigators are focusing on the performance of the braking system, which was set to operate automatically consistent with the airline’s procedures and safety rules.

All airliners today are equipped with both anti-skid braking systems and also a system known as "auto-brakes". The anti-skid system is similar to the one on your car and releases brake pressure to any tire which is approaching zero RPM, or a skid.

The auto-brake system is designed to automatically apply measured braking immediately after touchdown when the system detects wheel spin-up. It has several deceleration settings and will bring the aircraft to a complete stop if not overridden by the pilot.

The use of auto-brakes is usually mandatory when landing on a wet or slippery runway and contributes an added layer of safety during rollout. This is especially helpful during high crosswind landings.

A pilot's feet rest on the two rudder pedals which control the rudder in the air, but also control the wheel brakes on the ground. The pedals push in and out for rudder control, while applying toe pressure to each individual pedal applies the wheel brakes to the individual landing gear.

During a crosswind landing, holding a significant amount of rudder means one leg is extended while the other comes back towards the seat. Applying toe pressure while simultaneously holding rudder input can be awkward and not very effective. Auto-brakes make up for this deficiency.

Whether one of these systems malfunctioned during the landing rollout remains to be seen but the investigators seem to have found something amiss. Stay tuned.

Saturday, March 07, 2015

Delta Airlines 1086

                                                                                          (AP Photo)
Delta Air Lines Flight 1086 departed the runway at LaGuardia airport on Thursday after landing in low visibility and came to rest on a berm adjacent to Flushing Bay. The MD-88 had arrived from Atlanta at about 11 a.m. with 125 passengers and 5 crew. There were no fatalities or serious injuries and the NTSB has recovered the data recorders and is starting their investigation.

My first impression upon seeing the news reports was that the aircraft was extremely lucky to not go into the bay as it appears to have almost done. A few clicks around the web showed that the aircraft had been sliding sideways along the berm and not directly at it, taking the fence with it as seen above. The berm was to the side of the runway and not at the end. Not quite the "roadrunner-coyote cliff hanger" moment it first seemed.

That's not to say that this isn't a serious incident. It is. The aircraft is most likely totalled with extensive and hard to repair fuselage damage. The pilots themselves have already been drug and alcohol tested (normal protocol), and can now expect a months long body cavity search by investigators and authorities. Lawsuits have most likely already been filed by some passengers.

Lousy Weather

A search for historical METAR reports quickly returned the weather conditions for the aircraft's arrival time. METARs, or Meteorological Terminal Air Reports are the routine periodic weather observations made at almost all airports with instrument approaches. They are typically released at about 10 minutes prior to the hour but can be issued more frequently if weather conditions are changing rapidly.

METARs used to be made by real weathermen, but are now mostly automated. Their data is then digitized and available to pilots through a datalink. The report issued about 10 minutes prior to Delta 1086's arrival was as follows:

METAR KLGA 051551Z 01008KT 1/4SM R04/2800V3500FT SN FZFG
                     VV009 M03/M05 A3012 RMK AO2 SLP199 P0006 T10331050=

This can be decoded as follows: First the identification of the type report, then the field identifier KLGA, LaGuardia. The "K" is the country code. The time is listed with the date followed by the "zulu" time or GMT. Since New York is GMT-5, that puts the local time at 10:51 EST, just before Delta's arrival.

Next is the wind which is from 010 degrees at 8 knots. On the runway on which they landed, Rwy 13, this is a left quartering tailwind. The visibility is 1/4 mile with the specific visibility for runway 4 listed as between 2800 and 3500 feet. Obscurations to visibility are listed as snow and freezing fog with a vertical visibility showing 900 feet.

While the METAR reported the specific visibility for Runway 4, there is also a visibility measuring installation on Runway 13 as well. It is most likely convention that only one is listed in the report. There is no doubt that the tower was reading visibility reports for Runway 13 directly on the radio.

The temperature and dewpoint are at -3 and -5 degrees celsius respectively, with an altimeter setting of 30.12 inches of mercury (in. hg.). The rest of the string is more detailed technical data referring to the type of automated sensor package and other details.

What does this mean in English? It means the weather was really really crappy. This report is about as bad as it can get with the airport remaining open.

Landing With a Tailwind

Airplanes normally land into headwinds if they can. The reason for this is that a headwind will reduce an airplane's velocity over the ground resulting in less energy to dissipate during the landing. And as the energy carried into the landing varies with the square of the velocity, a slight increase in velocity will result in a large increase in energy that must be absorbed by the brakes and thrust reversers.

So this begs the question of why was LaGuardia landing on a runway with a tailwind in snow and ice?

The answer is in the visibility. With a reported visibility between 2800 and 3500 feet, the only approach available with low enough visibility minimums was the either the ILS to runway 22 or the ILS to runway 13. The approaches to runways 4 and 31 both have minimums of a mile visibility or higher due to obstacles and other criteria. Of the two remaining approaches, a wind of 010/8 would have been nearly a direct tailwind on runway 22. This left the ILS to 13 as the least worst choice.

(For those who don't know, a runway's designation is it's magnetic course in tens of degrees, i.e. runway 13 is 130 degrees magnetic. Also, ILS stands for instrument landing system, a ground based radio directed approach.)

Given though that the aircraft did not overrun it's landing runway, but rather went off the side may mean that a slight tailwind landing wasn't a factor in this incident. The winds at landing would have been 120 degrees from the left at only eight knots resulting in a tailwind component of only a few knots. 

The issue of low visibilities necessitating the use of a non-optimum runway in snow was a factor in the overrun and crash of a Southwest Airlines jet over ten years ago. It will surely be looked at by investigators in this incident.


Investigators will be sure to focus on exactly where the airplane touched down on the runway. One of the biggest challenges to landing in a low visibility environment is that there is very little time to assess the exact position of the airplane vis a vis the runway before landing. Should the airplane be even just a little bit to the left or right of the runway centerline, there is very little ability to make a correction in the short time between decision height and touchdown. In extreme conditions such as landing just above minimums, determining if a correction even needs to be made can be a challenge.

There have been instances in the past of pilots mistaking runway edge lights for the centerline lights and placing the wrong row of lights right between the gear. Of course this would leave one of the landing gears off the runway in the dirt.

This difficulty can be compounded by a crosswind as existed at LGA. As an aircraft travels down final, it will naturally windmill into whatever crosswind exists. The angle between the aircraft heading and the runway heading is known as the drift angle, and can be disorienting especially in a low visibility approach.

When the aircraft is "drifting" or "crabbed" into a crosswind, the runway will not appear directly in front of the cockpit but will rather be off to one side or the other when breaking out of the weather. Pilots must know where to look for the runway in the windscreen by accounting for the drift angle.

Don't Duck

Another potential error during a very low visibility approach is known as the "duck under". All "precision" approaches, and by that I mean approaches with glidepath information included, will have what is known as as "decision height", or "decision altitude". It means just what it says. We fly down the glidepath in the weather until reaching that altitude and then make the "decision" to land or go around.

There are very specific criteria of what must be in view in order to continue an approach after decision height. While the runway needn't be seen, the approach lights must be in view for instance, and the aircraft must be tracking on centerline. The red runway stop bar lights must be seen to continue below 100 ft above the runway as well. I could go on for several paragraphs about all the specific requirements needed to be met to continue to a low visibility landing.

If at any time all requirements are not met, a go-around is mandatory. The temptation in a low visibility landing is to go in the direction of the things you see which are below the aircraft. It's a natural tendency but must be resisted. A "duck under" may carry the aircraft below the glideslope and result in a short landing. 

Therefore, once visual clues become available, pilots must still reference their instruments inside the aircraft to maintain an appropriate glidepath to touchdown. This requires using a hybrid inside-outside scan during landing which can be disorienting. It is here that the pilot not flying earns his keep by staying on instruments and calling out deviations.

Once on the Ground

Ok, let's assume that the approach and landing were uneventful. Assuming that the aircraft touched down on centerline and in the landing zone (first 3000 feet), what could then go wrong? Plenty. Investigators will be sure to look at the wheels, tires, brake assemblies, anti-skid systems and thrust reversers. A malfunction of any of these could cause some adverse drag that might cause the aircraft to drift laterally on rollout.

Ideally, rudder application or differential braking should be enough to return the airplane back onto centerline if it strays. As the aircraft speed decreases however, the rudder becomes less effective and the captain must at some point transition from the rudder peddles to the tiller (steering wheel) to maintain lateral control or take control from the first officer. This typically happens around 60 kts or less. I say captain here because most airplanes have only one tiller on the left bulkhead for use by the captain.

(It's one of the perks of captain upgrade: you get to drive while on the ground!)

Braking Action Reports

While LaGuardia airport authorities were quick to take to the airwaves to declare that the runways had just been plowed, often the entire width of the runway may not be plowed. Should an airplane drift for whatever reason towards the side of the runway and get into a snow covered area, nose wheel and braking effectiveness can rapidly drop. And this may happen just as the aircraft decelerates below the point of rudder effectiveness.

We've all been driving on a snowy road following where all the other cars have been making a path, but know that when pulling onto the shoulder all bets are off.

During times of inclement weather, airports will announce that "braking action advisories" are in effect. When this happens, all pilots are required to report what the braking action was like on landing. We use terms such as "wet-good", wet-fair", "wet-poor" or "nil". A report of "wet-poor" or "nil" pretty much stops all operations.

Arrivals just prior to the incident had been reporting good braking action, and there's no doubt that investigators will also be looking closely at all reports and the specific areas of the runway that had been plowed.

Now The Investigation

As far as airplane accidents go, this one will eventually be forgotten by the public at large. No one was hurt and while the airplane is probably a loss, the MD-88 fleet is old and probably scheduled for retirement in the near future anyway. In the best of all possible worlds, if the pilots are found at fault for continuing an approach which should've been abandoned, perhaps they'll get some time off and some retraining before flying again.

Should the cause end up being a mechanical problem, then records and procedures will be reviewed to ensure compliance. Perhaps inspection schedules will be adjusted.

Flying an approach in minimum visibility, in an old airplane, to a short runway bordered by water, in a tailwind is probably as bad as it gets in modern aviation. There is simply very little room for any error. It may not be a surprise that this type of accident happened, but rather that it doesn't happen more often.


Friday, March 06, 2015

Ice Ice Baby!

This past week has seen a large part of the country dealing with wintry weather so it seemed like a good time to address icing. Airplanes and ice have always had an adversarial relationship. Ice can prevent airplanes from getting airborne and should they be airborne, ice will do its best to facilitate an airplane's hasty return to Earth, willingly or not.

From the earliest days of aviation, airframe icing was recognized as a threat to flight. Icing will cause problems for aircraft in two ways. The first is the simple weight that icing can add to an aircraft. Many thousands of pounds of added weight from icing on an airframe will increase stall speeds and can prevent an airplane from climbing out of icing conditions.

The second pernicious effect of airframe icing is the addition of drag and the destruction of a wing's ability to create lift. As you'll recall, lift is generated due to the Bernoulli effect with regards to the flow of air over the wing. Faster moving airflow over the wing has lower dynamic pressure than the air passing beneath. This pressure differential generates the lift that keeps airplanes in the sky.

One requirement though is that this airflow must be laminar, or smooth, to work its magic. A coating of ice will destroy the smooth flow of air and result in what is known as boundary layer separation. When this happens, the wing stops producing lift and the airplane drops. As ice progressively coats a wing in icing conditions, the wing's lifting ability decreases and its drag increases to the point where flight is no longer possible.

Even a layer of frost over the top of a wing can have devastating effects on lift. Roughness approximating a piece of #40 grit sandpaper will reportedly reduce lift by 30 to 40%. This loss of lift can produce disastrous results especially during takeoff, which is why icing must be taken seriously.

Ice Can Kill On the Ground

There have been many accidents and incidents attributed to airframe icing over the years. One of the most famous ones was Air Florida 90, which crashed into the Potomac River moments after takeoff in a snowstorm in 1982. While the ultimate cause was determined to be pilot error, the series of errors which led to the crash were caused by the pilots' lack of understanding of the effects of ice on their aircraft.

Specifically, the crew inexplicably failed to use engine anti-icing and also allowed a dangerous buildup of snow to accumulate on the aircraft prior to takeoff. The failure to use engine anti-icing, which heats sensors that determine thrust settings, allowed a false reading from clogged sensors to show that the engines were at full thrust while they were actually set much lower. 

The lower thrust coupled with the added weight and increased drag from accumulated snow prevented the aircraft from being able to remain airborne. It hit the 14th St bridge 30 seconds after takeoff killing 69 of the 74 passengers and crew.

And is Also Deadly in the Air

Ice accumulation while airborne has been a well documented hazard to aviation over the years and also a staple of aviation film drama. Should an airplane fly into what is known as "icing conditions", supercooled rain droplets will freeze on the surface of an aircraft leaving a coating of ice. This coating starts at the leading edge of the wing and slowly travels back over the wing destroying the wing's ability to create lift as it progresses.

A simpler word for "icing conditions" would be cloud. Any time visible moisture is present and the temperature is below freezing, icing conditions are present and airframe icing is possible. Airframe icing is categorized as either "rime"or "clear". Rime icing is opaque in color and easily visible on the aircraft while clear ice is much harder to see and therefore more difficult to detect.

One of the more recent casualties of airborne ice accumulation was American Eagle 4184 which crashed due to icing induced loss of control in 1994. The aircraft, an ATR 72 enroute from Indianapolis to Chicago, had held in freezing rain conditions while awaiting further clearance to O'Hare. While descending to enter a second holding pattern, the pilots retracted the flaps which had been extended for the first holding pattern.

Upon flap retraction the aircraft became uncontrollable, rolling completely at least twice before crashing in a field near Roselawn, Indiana, killing all 64 passengers and 4 crew. The cause of the accident was attributed to a buildup of ice on the wing which only became critical after the flaps were retracted.

Many aircraft now have restrictions against holding in icing conditions with flaps extended as a result.

Clean Aircraft Concept

The mitigation of dangers posed by icing before takeoff and while airborne are two very different problems requiring different solutions, but the end objective is the same: to keep ice off the aircraft. And short of keeping an airplane safely in a warm hangar, solutions to icing have become ever more exotic as the dangers of icing have become better understood.

After many years of trying to come up with a regulatory framework which could be universally and simply applied, the FAA came up with the Clean Aircraft Concept. This formulation left no wiggle room as to how much freezing precipitation could be adhering to an aircraft readying for takeoff:

 The “clean-airplane” concept is derived from U.S. Federal Aviation Administration (FAA) Federal Aviation Regulation (FAR) 121.629, which states, “No person may take off an aircraft when frost, ice or snow is adhering to the wings, control surfaces, propellers, engine inlets, or other critical surfaces of the aircraft or when the takeoff would not be in compliance with paragraph (c) of this section. Takeoffs with frost under the wing in the area of the fuel tanks may be authorized by the Administrator.” 
The FAR also prohibits dispatch or takeoff any time conditions are such that frost, ice, or snow may reasonably be expected to adhere to the airplane, unless the certificate holder has an approved ground deicing/anti-icing program in its operations specifications that includes holdover time (HOT) tables.

The aim of this simple regulation was to put an end to the guessing game of how much snow and ice can safely be on the aircraft for a takeoff. The short answer is none (with occasional frost but only on the underside of the wing). No one would be able to say "oh, it'll blow off during takeoff", or " the exhaust from the plane taxiing ahead of us will melt the snow". The airplane had to be clean. Period.

Don't Drink the Deicing Fluid

Dating to the 1950s and earlier, deicing fluid for use on aircraft was based on ethylene glycol, commonly used as automotive antifreeze solution, or sometimes even ethyl alcohol (the drinking kind). Due to its toxicity to animals, ethylene glycol was mostly replaced by propylene glycol in the 1980s. Ethyl alcohol fell out of favor as a deicer after WWII due to it's popularity as a jaw lubricant with ground crews in Russia and other places. New fluids have been introduced over the years that not only remove ice, but also inhibit further accumulation.

It is important to make the distinction between the terms "deice" and "anti-ice" because they mean different things and the fluids used in each application are also different. The term deice refers to removing existing snow and ice from an aircraft while anti-icing means to apply fluid which inhibits continuing frozen precipitation from adhering to aircraft surfaces.

Specialty fluids have been developed over the years for these two separate functions. For most applications, fluids used to deice aircraft are known as "Type I" fluids while anti-ice fluids are "Types II, III and IV". They function differently.

While Type I fluids are used mainly for deicing, Types II, III, and IV have thickeners included and are designed to adhere to the wing and absorb moisture from additional snowfall or ice accumulations and to then shear off the wing during takeoff. This gives extra time between application and taking off.

This extra time is known as "holdover time" and differs depending on the type of fluid used, its concentration, the type and intensity of the snow or ice coming down, and the outside temperature. We have lots of very complicated charts to figure it all out. If holdover time is exceeded, we go back to the gate and get sprayed again.

A typical Type I fluid will be based on propylene glycol (PG) and will include other ingredients such as corrosion inhibitors, surfactants, or wetting agents and dye. It will usually be diluted with water and heated in the truck to be sprayed on the aircraft.

So as you sit in your window seat you might see the trucks make two passes during deicing. The first pass will be with Type I fluid to deice, while the second pass will be to spray Type IV fluid as an anti-icer. Type IV fluid is green in color and sticks to the wing but is designed to shear off.

Deicing Ain't Cheap

With a quick web search I found a vendor selling DOW UCAR PG Type 1 fluid in a handy 230 gallon pack for $4250. This will typically be diluted 70/30 with water making the solution about $13 per gallon. Keep in mind that it may take up to 500 gallons to properly deice a 737 or A320, two common airliners, so you can see that the process is expensive.

Another facet to consider is what happens to all that deice fluid after it hits the ground. Many environmental jurisdictions are starting to require capture and recycle systems for used fluid which further drives up the costs. Given the thin profit margins of most airlines, it's likely that flights that have been deiced are marginally profitable or unprofitable.

This begs the question of why airlines even fly in snow. Well for one, the airline has no sure way to tell when snow will fall, but the more likely answer is that cancelling flights prematurely is expensive and kills customer loyalty if the competition is still flying. Plus aircraft and crews may also be needed elsewhere.

The new tarmac delay law with it's heavy penalties for long delays certainly contributes to the cancellation equation, but that will have to be the subject of a future post.

Clean or "Cell Phone Clean"

After many years of ambiguity regarding the question of when and how to deice, everyone from the FAA, the airlines, unions, safety administrators and aircraft manufacturers are really on the same page concerning pre-takeoff deicing. The airplane has to be clean to take off. On this everyone agrees.

But in tearing a page from medicine, a new phenomenon of "defensive deicing" is making itself slowly apparent. Airlines managements, while fully onboard with the need to properly deice an aircraft, also don't want pilots to be spraying thousands of dollars worth of fluids unnecessarily. Thus pilots are routinely bombarded with memos to this effect.

Here is where a pilot's and the airlines' incentives may be somewhat misaligned. There are plenty of instances say where flurries may be coming down in windy conditions where no snow may be sticking to the aircraft. In this case it is perfectly appropriate, safe, and legal to depart without deicing.

Pilots also know however that in the back of the airplane are several hundred cell phone cameras with some owners only too eager to snap a picture of a snow flurry for forwarding to the FAA (believe me, I've seen it happen). And the FAA, being the ever loyal guardians of aviation safety, will dutifully send a letter of investigation to a pilot who thought he was doing the right thing advising him to retain a lawyer and to explain his actions.

Having one's livelihood potentially threatened does wonders to concentrate the mind and has resulted in a type of bunker mentality. If one airplane is getting sprayed, they all seem to end up getting sprayed if there's even a flurry still in the air.

And should the hourly weather observation list frozen precipitation at an airport, deicing seems to always continue regardless of whether snow is actually still coming down 45 minutes later or not. And so it goes.

But there's no doubt that a certain measure of over-caution, while an inconvenience, never ended with an airplane in the Potomac.