X-Virus-Scanned: clean according to Sophos on Logan.com Return-Path: Sender: To: lml@lancaironline.net Date: Fri, 05 Aug 2011 10:37:37 -0400 Message-ID: X-Original-Return-Path: Received: from raven.ravenwebhosting.com ([72.9.254.67] verified) by logan.com (CommuniGate Pro SMTP 5.4.1) with ESMTPS id 5082108 for lml@lancaironline.net; Thu, 04 Aug 2011 14:52:28 -0400 Received-SPF: none receiver=logan.com; client-ip=72.9.254.67; envelope-from=paul@tbm700.com Received: from 47-61.202-68.tampabay.res.rr.com ([68.202.61.47]:58198 helo=[192.168.1.106]) by raven.ravenwebhosting.com with esmtpsa (TLSv1:AES128-SHA:128) (Exim 4.69) (envelope-from ) id 1Qp31O-0006fb-3x for lml@lancaironline.net; Thu, 04 Aug 2011 14:51:54 -0400 From: paul miller Mime-Version: 1.0 (Apple Message framework v1084) Content-Type: multipart/alternative; boundary=Apple-Mail-46--830738500 Subject: Re: [LML] Fw: Re: Re-doing my panel - carefully thinking through failures X-Original-Date: Thu, 4 Aug 2011 14:51:50 -0400 In-Reply-To: X-Original-To: "Lancair Mailing List" References: X-Original-Message-Id: <91EBD6B4-414F-426D-831F-9634DBD57D29@tbm700.com> X-Mailer: Apple Mail (2.1084) X-AntiAbuse: This header was added to track abuse, please include it with any abuse report X-AntiAbuse: Primary Hostname - raven.ravenwebhosting.com X-AntiAbuse: Original Domain - lancaironline.net X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12] X-AntiAbuse: Sender Address Domain - tbm700.com X-Source: X-Source-Args: X-Source-Dir: --Apple-Mail-46--830738500 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=us-ascii OK, but at some point your ratio of delta reliability / delta redundancy = starts to diminish or possibly work the other way. To many systems can = cause confusion in threatening situations. The redundant systems can = sometimes cause failures on their own that could be worse than the risk = of not having the redundancy. I'd say 2-3 levels should be enough = otherwise you're can't possibly draw them for consumption on this list = (grin). I always like to refer to the infamous Cessna MEB that = installed a failsafe switch to turn on hi boost if one of the two engine = fuel pumps failed. So many of those failsafe switches activated in = error that some planes were lost when the mixtures went full rich and = killed one engine. Eventually, it was understood that the pilot can = deal with the loss of pressure more reliably than confusing him with an = abstract failure and those switches were removed by AD. =20 Thanks for the drawings and ongoing education Paul Spruce Creek=20 > Two of everything, independent power modes, independent pathways, = cross connects, multiple layers of electrical spike and surge protection = and independent and different principles of gyroscopic display and = electrical power supply. Now one begins to achieve realistically (and = defensible) high levels of reliability. =20 > =20 > If I could only achieve the same with the pilot. > =20 > Fred Moreno > =20 --Apple-Mail-46--830738500 Content-Transfer-Encoding: quoted-printable Content-Type: text/html; charset=us-ascii OK, = but at some point your ratio of delta reliability / delta redundancy = starts to diminish or possibly work the other way.  To many systems = can cause confusion in threatening situations.    The = redundant systems can sometimes cause failures on their own that could = be worse than the risk of not having the redundancy.   I'd say 2-3 = levels should be enough otherwise you're can't possibly draw them for = consumption on this list (grin).  I always like to refer to the = infamous Cessna MEB that installed a failsafe switch to turn on hi boost = if one of the two engine fuel pumps failed.   So many of those = failsafe switches activated in error that some planes were lost when the = mixtures went full rich and killed one engine.  Eventually, it was = understood that the pilot can deal with the loss of pressure more = reliably than confusing him with an abstract failure and those switches = were removed by AD.   

Thanks for the = drawings and ongoing = education

Paul
Spruce = Creek 
Two of everything, independent = power modes, independent pathways, cross connects, multiple layers of = electrical spike and surge protection and independent and different = principles of gyroscopic display and  electrical power = supply.  Now one begins to achieve realistically (and = defensible) high levels of = reliability.  
 
If I could only = achieve the same with the pilot.
 
Fred = Moreno
 
<= /span>

= --Apple-Mail-46--830738500--