One possible scenario is that they had a bird strike on one engine but then accidently turned the working engine off instead. Full loss of power from both engines could have taken the data recorder offline in an older aircraft like this one. With both engines off, they may have panicked to try to complete a tight turn to return to the airport and to maintain altitude to make it to the runway. It's possible the landing gear was forgotten but also possible that it was intentional (to extend glide.) It's too early to know anything with certainty but I suspect that the investigation will show that a different set of choices would have allowed them to put the plane down safely (for example by continuing with the initial approach.) Even in that case, they may not have been to blame - for example they may have been following a standard procedure that should be revisited.
Note that just shutting down normally the engine would not cause a power loss. Only in the case of a turn off with extinguisher. Of course after bird strike you shut it down with extinguisher.
Now there is clear procedure, with checks that has to be memorized, where you first identify the engine. Pilots are regularly tested for that procesures. Why it went wrong?
I remember that Boeing changed which pack provides air conditioning to the cockpit between the 737-200 and the 737-300, which lead to a few similar situations in which pilot were confidently wrong which engine was bad based on smell alone.
It was changed in 737-400. Before it only took air from the right engine, but 737-400 took from both. In the Kegworth air disaster, which was caused by a failed blade and the system causing a fire trying to compensate by injection of more fuel, the pilot assumed the fire was in right engine and turned it off as crew never notified them which engine was burning. When they discovered the error the speed was too low to kickstart the engine.
The general populace seems convinced that black box recorders are made of adamantium and can return data even if the plane falls into a black hole.
Meanwhile every time I read about a crash, I'm horrified by how primitive the requirements (and implementation) appear to be.
This reminds me of my favourite method for reviewing software I had never heard of: I check the release notes. If version v17 has "now uses transactions" then that means that the developers were happy to release the first sixteen major versions with data corruption as a feature. (Conversely, if the notes only mention fantastically obscure scenarios being fixed, then the basic issues have been fixed long ago.)
Battery backup being introduced in 2010 as a requirement is absolutely insane. It's not like batteries or battery backup are new technologies! This stuff has been around forever. Why on earth was this not a requirement decades ago!?
If the motor was just shutdown, it should still make power off windmilling. If they discharged the extinguishers, then there is no more power. In any case, that should be recorded.
How much would it cost to create a data recorder with a built-in battery? Like a mini UPS that would power the recorder for one hour, if external power failed.
The antiquated technology in jets is mind boggling.
The problem is old, new planes don’t have that problem. The the technology is antiquated because the planes are antiquated, because they are (or were) built with good quality and lasted long.
Appart from that, how much could it cost? Well, the battery maybe a couple hundred US pesos, but the whole test, verification and validation until approval, plus changing all planes? You have to ask Catl Sagan.
Last but not least: I think the key to understanding the accident will still be there (they shut down the wrong engine, for example) if that is the case, even with this little problem, the boxes dis their work… so, no need for new things.
I didn't know that was possible. Well sure, almost anything is possible but, this begs questions: how often does this happen, and is there a formal check at some granularity outside of crash events, to check if a black box recorder is working? What's the failure rate?
I'm not pushing conspiracy theory, I'm just a bit aghast the mechanism designed to log things for disaster analysis itself can have .. catastrophic failure before an event.
4 minutes is an eternity. This can't be down to buffer behaviour and the event itself surely?
Because "the event" was the bird strike, and 4 minutes before the crash is the right timeframe for that. At least one of the engines was hit, and they appear to have lost AC power.
The crash on the second landing attempt is just a the conscience of the bird strike, not the actual event.
Apparently this aircraft was just old enough that the black boxes weren't required to be hooked up to any of the redundant power buses.
> be hooked up to any of the redundant power buses.
There are multiple busses, but you almost always have an option to tie the two busses together, so one generator can drive both sets of loads. You can also add a battery through an inverter to carry loads. You can also turn on the APU and use it's output to drive loads.
Tying buses together is a manual operation. All indications are that the pilots didn't have enough time to get that far in the checklist.
It's also not that important to restore AC power. The standby bus automatically brings the standby instruments online in the event of a failure, and not that hard to restore the majority of instruments by connecting the main DC bus to batteries. The battery has enough power for 30min of flying, or a full hour if you have the dual-battery option.
> They may have had a more severe failure.
While we only have evidence of bird strikes on one engine, the actions of the pilots seem to suggest that they lost both engines. They were rushing to get back to a runway.
You do not have time to start the APU. Moving any switch is a procedure with a checklist, at that hight, once you lost both engines… they had no chance.
It's just a button press. US Airways 1549 had the captain starting the APU within seconds after their birdstrike. Your biggest concern after starting is likely exhaust temperature.
Exactly! And he was called out because he did that without following the stablished procedures!
Also is not instant, will take a minute or two. The APU is a turbine that takes time to start. Maybe they did turn in on, but 2 minutes too late. We don’t know.
He was a super pilot, who had extreme good understanding of all systems in the plane, and many ours on that plane. You cannot expect that (and do both want that!) from an average pilot. It seems right now that this very accident may have been caused by not following the procedures.
"Although the flight crew was only able to complete about one-third of the Engine Dual
Failure checklist, immediately after the bird strike, the captain did accomplish one critical item
that the flight crew did not reach in the checklist: starting the APU. Starting the APU early in the
accident sequence proved to be critical because it improved the outcome of the ditching by
ensuring that electrical power was available to the airplane. Further, if the captain had not started
the APU, the airplane would not have remained in normal law mode. This critical step would not
have been completed if the flight crew had simply followed the order of the items in the
checklist.
The NTSB concludes that, despite being unable to complete the Engine Dual Failure
checklist, the captain started the APU, which improved the outcome of the ditching by ensuring
that a primary source of electrical power was available to the airplane and that the airplane
remained in normal law and maintained the flight envelope protections, one of which protects
against a stall."
The final report also gave a new safety recommendation (A-10-66, p. 124) to develop more appropriate (shorter) checklist for dual-engine failure specifically for low-altitude incidents.
Sorry I wanted to mean “it was pointed out”. I’m not sure of the connotation of “call out”
Thanks for citing the report, which I was too lazy to do. That is my point, as I was replying to “it is just one button” comment. If you do the procedures in the right order, it could be they didn’t have the time to start the APU
Or they started the APU, but never got around to connecting its generator to the main bus. That's a second button press, after confirming it has successfully started.
With a complete loss of electrical power there isn't much for the FDR to record other then airspeed, altitude, and attitude from the standby instruments. However that's already available from radar, ADS-B, and in this case, video.
CVR might have some value, but again in most cases you're just getting a bunch of yelling and swearing before the crash.
As far as understanding what went wrong with Jeju 2216, the interesting bits are going to be right up until they lost both engines, after that it's fairly straightforward to put together the chain of events.
> However that's already available from radar, ADS-B
Not in this case. ADS-B was lost at the same time as the flight recorders.
If there was a primary radar in range, they might be able to recover groundspeed and a 2d flight path. But those have been falling out of fashion, and were never that good for things near the ground.
> there isn't much for the FDR to record other then airspeed, altitude, and attitude from the standby instruments.
You forgot the _most_ important data. The position of the flight controls set by the crew.
> but again in most cases you're just getting a bunch of yelling and swearing before the crash.
That has not been my experience. You can hear the pilots trying to work the problem until the last minute and hearing how they made decisions is important. You can also hear the engines, the wind noise, cockpit warning horns, and possible sources of pilot interference.
> That has not been my experience. You can hear the pilots trying to work the problem until the last minute and hearing how they made decisions is important. You can also hear the engines, the wind noise, cockpit warning horns, and possible sources of pilot interference.
Knowing the pilots were trying to prevent the inevitable crash right up until the end is a nice thing to know but now relevant for flight safety. The point of the investigation is to determine what went wrong before the crash became a certainty. Which for Jeju was the moment they lost both engines.
> You forgot the _most_ important data. The position of the flight controls set by the crew.
While manual flight controls are a thing, without hydraulic assistance they are really only useful if you're trying to maintain straight and level flight while you start backup power. W1ith compounding problems it gives you a little more control of which direction you will be crashing in.
I won't deny that more data in an investigation is always useful, but the cost of ensuring that data is available has to be weighed against the potential value of that data. With this crash the data after the loss of both engines won't have much bearing on preventing the similar incidents in the future.
To put it another way, should your commercial air liner lose both engines at 1000' in a descent the outcome will be crash, the objective is to prevent that scenario.
> is a nice thing to know but [not] relevant for flight safety [edited to what I think you meant]
If the pilots made mistakes you want to know what mistakes they made so you can make changes to prevent future pilots from making the same mistakes. The voice recorder is extremely important to understand what mistakes (if any) were made. Even if they did everything correctly, reducing uncertainty is also important.
> The point of the investigation is to determine what went wrong before the crash became a certainty.
That's the reason for starting the investigation. It is not the exclusive goal for it. Increasing safety for all future flights is a big part of why and how this is done. Bird strikes are inevitable.
> Which for Jeju was the moment they lost both engines.
It seems like you do not require any investigation at all.
> should your commercial air liner lose both engines at 1000' in a descent the outcome will be crash
The outcome will be a descent. You do see that the concern here is related to the fact that this failure happened very close to approach and even given this the pilots managed to successfully navigate it to the runway. With the gear up.
I mean, if you touch down with the gear up, technically, I'll give you, that's a crash. If the gear was down it would look very much like a regular _landing_. What precisely went wrong considering the gear _had_ been down previously? So.. it's not hard to imagine how a working CVR and FDR here would help us answer that very question.
Although, your investigation may have been this thorough, do you have the answer?
The biggest question for me, is what happened between the bird strikes and both engines shutting down? Why was the decision made to go around instead of continuing the approach? How quickly did both engines fail?
> managed to successfully navigate it to the runway. With the gear up.
Sadly they did not, well technically yes, they did physically locate the runway, however they were also traveling too high, too fast, and crashed.
> If the gear was down it would look very much like a regular _landing_
It would have still been a very unstable landing half way down the runway with limited braking, no reversers, no spoilers, no flaps. It's very likely they would have still ended up off the end of the runway.
> What precisely went wrong considering the gear _had_ been down previously?
They chose to do a go-around, selected gear up, then with both engines failed the only way to lower the gear is manually, the handles are on the floor aft of the first officers seat. Their would not have been time to access them between when they had lost both engines and were on the ground while also flying the aircraft.
I'm not saying I know what happened, I'm saying that the key to preventing future accidents like this will be in the moments before they lost both engines. After they lost both engines it's clear they aircrew tried to very quickly turn the plane around and land the runway, I have pretty serious doubts that there was any actions that could've made that a successful landing, and if there was, they'll be found in a simulator not on the FDR of the aircraft that DIDN'T make the successful landing.
Now there is clear procedure, with checks that has to be memorized, where you first identify the engine. Pilots are regularly tested for that procesures. Why it went wrong?
https://en.wikipedia.org/wiki/Kegworth_air_disaster
That two different recorders both went titsup at the same time I find mind boggling and very sus.
edit: apparently they have both AC and a battery backup, if the internet is to be believed.
Which makes a simultaneous loss of two devices with battery backups... curious.
Did they get hit with an EMP?
Meanwhile every time I read about a crash, I'm horrified by how primitive the requirements (and implementation) appear to be.
This reminds me of my favourite method for reviewing software I had never heard of: I check the release notes. If version v17 has "now uses transactions" then that means that the developers were happy to release the first sixteen major versions with data corruption as a feature. (Conversely, if the notes only mention fantastically obscure scenarios being fixed, then the basic issues have been fixed long ago.)
Battery backup being introduced in 2010 as a requirement is absolutely insane. It's not like batteries or battery backup are new technologies! This stuff has been around forever. Why on earth was this not a requirement decades ago!?
The antiquated technology in jets is mind boggling.
Appart from that, how much could it cost? Well, the battery maybe a couple hundred US pesos, but the whole test, verification and validation until approval, plus changing all planes? You have to ask Catl Sagan.
Last but not least: I think the key to understanding the accident will still be there (they shut down the wrong engine, for example) if that is the case, even with this little problem, the boxes dis their work… so, no need for new things.
I'm not pushing conspiracy theory, I'm just a bit aghast the mechanism designed to log things for disaster analysis itself can have .. catastrophic failure before an event.
4 minutes is an eternity. This can't be down to buffer behaviour and the event itself surely?
https://www.pprune.org/accidents-close-calls/663324-jeju-737... has discussion. Yes, catastrophic loss of power takes them off-line. Some kind of UPS like capacity seems necessary.
The crash on the second landing attempt is just a the conscience of the bird strike, not the actual event.
Apparently this aircraft was just old enough that the black boxes weren't required to be hooked up to any of the redundant power buses.
There are multiple busses, but you almost always have an option to tie the two busses together, so one generator can drive both sets of loads. You can also add a battery through an inverter to carry loads. You can also turn on the APU and use it's output to drive loads.
They may have had a more severe failure.
It's also not that important to restore AC power. The standby bus automatically brings the standby instruments online in the event of a failure, and not that hard to restore the majority of instruments by connecting the main DC bus to batteries. The battery has enough power for 30min of flying, or a full hour if you have the dual-battery option.
> They may have had a more severe failure.
While we only have evidence of bird strikes on one engine, the actions of the pilots seem to suggest that they lost both engines. They were rushing to get back to a runway.
Also is not instant, will take a minute or two. The APU is a turbine that takes time to start. Maybe they did turn in on, but 2 minutes too late. We don’t know.
He was a super pilot, who had extreme good understanding of all systems in the plane, and many ours on that plane. You cannot expect that (and do both want that!) from an average pilot. It seems right now that this very accident may have been caused by not following the procedures.
"Although the flight crew was only able to complete about one-third of the Engine Dual Failure checklist, immediately after the bird strike, the captain did accomplish one critical item that the flight crew did not reach in the checklist: starting the APU. Starting the APU early in the accident sequence proved to be critical because it improved the outcome of the ditching by ensuring that electrical power was available to the airplane. Further, if the captain had not started the APU, the airplane would not have remained in normal law mode. This critical step would not have been completed if the flight crew had simply followed the order of the items in the checklist.
The NTSB concludes that, despite being unable to complete the Engine Dual Failure checklist, the captain started the APU, which improved the outcome of the ditching by ensuring that a primary source of electrical power was available to the airplane and that the airplane remained in normal law and maintained the flight envelope protections, one of which protects against a stall."
The final report also gave a new safety recommendation (A-10-66, p. 124) to develop more appropriate (shorter) checklist for dual-engine failure specifically for low-altitude incidents.
Thanks for citing the report, which I was too lazy to do. That is my point, as I was replying to “it is just one button” comment. If you do the procedures in the right order, it could be they didn’t have the time to start the APU
private pilot here: 4 minutes is nothing while flying and coping with an emergency! NOTHING!
CVR might have some value, but again in most cases you're just getting a bunch of yelling and swearing before the crash.
As far as understanding what went wrong with Jeju 2216, the interesting bits are going to be right up until they lost both engines, after that it's fairly straightforward to put together the chain of events.
Not in this case. ADS-B was lost at the same time as the flight recorders.
If there was a primary radar in range, they might be able to recover groundspeed and a 2d flight path. But those have been falling out of fashion, and were never that good for things near the ground.
You forgot the _most_ important data. The position of the flight controls set by the crew.
> but again in most cases you're just getting a bunch of yelling and swearing before the crash.
That has not been my experience. You can hear the pilots trying to work the problem until the last minute and hearing how they made decisions is important. You can also hear the engines, the wind noise, cockpit warning horns, and possible sources of pilot interference.
Knowing the pilots were trying to prevent the inevitable crash right up until the end is a nice thing to know but now relevant for flight safety. The point of the investigation is to determine what went wrong before the crash became a certainty. Which for Jeju was the moment they lost both engines.
> You forgot the _most_ important data. The position of the flight controls set by the crew.
While manual flight controls are a thing, without hydraulic assistance they are really only useful if you're trying to maintain straight and level flight while you start backup power. W1ith compounding problems it gives you a little more control of which direction you will be crashing in.
I won't deny that more data in an investigation is always useful, but the cost of ensuring that data is available has to be weighed against the potential value of that data. With this crash the data after the loss of both engines won't have much bearing on preventing the similar incidents in the future.
To put it another way, should your commercial air liner lose both engines at 1000' in a descent the outcome will be crash, the objective is to prevent that scenario.
If the pilots made mistakes you want to know what mistakes they made so you can make changes to prevent future pilots from making the same mistakes. The voice recorder is extremely important to understand what mistakes (if any) were made. Even if they did everything correctly, reducing uncertainty is also important.
As far as survivability of suddenly losing all engines at low altitude, I relied on my own knowledge and experience, however I can refer you to Wikipedia (https://en.wikipedia.org/wiki/List_of_airline_flights_that_r...). Specifically https://en.wikipedia.org/wiki/American_Airlines_Flight_1572 and https://en.wikipedia.org/wiki/US_Airways_Flight_1549. Those 2 are just about (IMO) the complete body of cases where there was something to learn from the aircrews actions following the loss of power. That being said, there actions were very specific to their circumstances, would be very difficult to train for, and the pilots survived to provide first hand accounts instead of relying on the CVR.
That's the reason for starting the investigation. It is not the exclusive goal for it. Increasing safety for all future flights is a big part of why and how this is done. Bird strikes are inevitable.
> Which for Jeju was the moment they lost both engines.
It seems like you do not require any investigation at all.
> should your commercial air liner lose both engines at 1000' in a descent the outcome will be crash
The outcome will be a descent. You do see that the concern here is related to the fact that this failure happened very close to approach and even given this the pilots managed to successfully navigate it to the runway. With the gear up.
I mean, if you touch down with the gear up, technically, I'll give you, that's a crash. If the gear was down it would look very much like a regular _landing_. What precisely went wrong considering the gear _had_ been down previously? So.. it's not hard to imagine how a working CVR and FDR here would help us answer that very question.
Although, your investigation may have been this thorough, do you have the answer?
> managed to successfully navigate it to the runway. With the gear up.
Sadly they did not, well technically yes, they did physically locate the runway, however they were also traveling too high, too fast, and crashed.
> If the gear was down it would look very much like a regular _landing_
It would have still been a very unstable landing half way down the runway with limited braking, no reversers, no spoilers, no flaps. It's very likely they would have still ended up off the end of the runway.
> What precisely went wrong considering the gear _had_ been down previously?
They chose to do a go-around, selected gear up, then with both engines failed the only way to lower the gear is manually, the handles are on the floor aft of the first officers seat. Their would not have been time to access them between when they had lost both engines and were on the ground while also flying the aircraft.
I'm not saying I know what happened, I'm saying that the key to preventing future accidents like this will be in the moments before they lost both engines. After they lost both engines it's clear they aircrew tried to very quickly turn the plane around and land the runway, I have pretty serious doubts that there was any actions that could've made that a successful landing, and if there was, they'll be found in a simulator not on the FDR of the aircraft that DIDN'T make the successful landing.
Even that is valuable information for discerning what went wrong and how.
Age - https://www.planespotters.net/airframe/boeing-737-800-hl8088...
Source it stopped recording - https://www.molit.go.kr/USR/NEWS/m_72/dtl.jsp?id=95090593