Mailing List lml@lancaironline.net Message #59212
From: paul miller <paul@tbm700.com>
Sender: <marv@lancaironline.net>
Subject: Re: [LML] Fw: Re: Re-doing my panel - carefully thinking through failures
Date: Fri, 05 Aug 2011 10:37:37 -0400
To: <lml@lancaironline.net>
OK, but at some point your ratio of delta reliability / delta redundancy starts to diminish or possibly work the other way.  To many systems can cause confusion in threatening situations.    The redundant systems can sometimes cause failures on their own that could be worse than the risk of not having the redundancy.   I'd say 2-3 levels should be enough otherwise you're can't possibly draw them for consumption on this list (grin).  I always like to refer to the infamous Cessna MEB that installed a failsafe switch to turn on hi boost if one of the two engine fuel pumps failed.   So many of those failsafe switches activated in error that some planes were lost when the mixtures went full rich and killed one engine.  Eventually, it was understood that the pilot can deal with the loss of pressure more reliably than confusing him with an abstract failure and those switches were removed by AD.   

Thanks for the drawings and ongoing education

Paul
Spruce Creek 
Two of everything, independent power modes, independent pathways, cross connects, multiple layers of electrical spike and surge protection and independent and different principles of gyroscopic display and  electrical power supply.  Now one begins to achieve realistically (and defensible) high levels of reliability.  
 
If I could only achieve the same with the pilot.
 
Fred Moreno
 

Subscribe (FEED) Subscribe (DIGEST) Subscribe (INDEX) Unsubscribe Mail to Listmaster