Yesterday was the 30th anniversary of the Challenger explosion. Today is the 30th anniversary of the beginning of the Challenger story. By the morning of January 29, 1986, recovery efforts had already begun. The New York Times
described the disaster as “The worst accident in the history of the
American space program.” Later in the same story, the Times notes,
“Officials discounted speculation that cold weather at Cape Canaveral or
an accident several days ago that slightly damaged insulation on the
external fuel tank might have been a factor.”
There’s no way to tell if the anonymous NASA officials quoted above knew the truth or not, and it’s more than a little eerie that a NASA official dismissed a foam strike as problematic when it was a foam strike that doomed Columbia 17 years later. Either way, it didn’t take long for the agency’s explanation of events to come under fire.
On February 7, NASA officials acknowledged that they’d previously seen O-ring degradation when launching in cold weather, and that they’d held a call with rocket design firm Morton-Thiokol to discuss whether or not to launch the mission. By mid-February, NASA had admitted that it waived the requirement for effective backup safety seals on the space shuttle’s booster rockets.
The technical and safety evaluations that led to the launch failure were inexcusable. The NASA engineers that pushed for delay due to the unusually low temperatures and the effects this could have on the Shuttle’s O-rings were overruled by managers eager to complete the mission. What happened to the crew was even worse.
This pleasant fiction was derailed by two events. First, the recovery of the crew cabin, with the remains of some astronauts still aboard, and second, high-speed footage of the explosion itself. NASA only released the footage when compelled to do so through the Freedom of Information Act.
The crew cabin of the space shuttle was made of reinforced aluminum and designed to withstand extreme flight tolerances. Footage of the explosion shows the cabin exiting the cloud more-or-less intact. Contrary to popular belief, Challenger was destroyed by aerodynamic stresses far beyond its design tolerance, not an explosion.
Challenger was torn apart at 48,000 feet, but the crew cabin arced higher, reaching a maximum altitude of 65,000 feet before it began to descend.
The crew of Challenger didn’t wear bulky pressurized space suits during lift-off, but they did have access to Personal Egress Air Packs, or PEAPs. PEAPS could provide crewmembers with approximately six minutes of air (albeit unpressurized air) in the event of a mishap. When NASA discovered the wreckage of the crew cabin, it found that three of the PEAPs had been activated, including the one belonging to Shuttle Pilot Michael Smith. Because Smith’s PEAP was mounted on the back of his chair, he could not have activated it himself.
Whether the crew was conscious would have depended on whether the cabin was breached. But the damage from hitting the ocean at 207 mph with a deceleration impact of more than 200 g destroyed a great deal of evidence.
The air reserve found in the activated PEAPs matched consumption expectations if the astronauts had remained conscious for the duration. Electrical switches on Smith’s chair had been moved as well. The switches in question were protected with lever locks, making accidental actuation impossible. Tests showed that neither impact with the ocean or the initial explosion could have shifted them. NASA’s formal conclusion was that “It is possible, but not certain, that the crew lost consciousness due to an in-flight loss of crew module pressure.”
A report from the Miami Herald in November 1988 details the steps NASA took to prevent civilian doctors from examining the remains of the recovered crew members. The organization was already under heavy fire for its safety procedures and practices. The simple fact was, the Space Shuttle design didn’t prioritize crew safety. Once the solid rocket boosters (SRBs) ignited, there was no way to abort the liftoff until approximately two minutes after launch. The Challenger disaster occurred well before this point, at ~73 seconds.
The vertical axis shows various abort strategies that might be employed. The horizontal axis measures the time since ignition. White areas of these graphs indicate which aborts were considered survivable, black means the total loss of both crew and vehicle.
The Space Shuttle had been sold to the American people as safer than Apollo-era vehicles. Had the public learned that pre-Challenger missions had almost no chance of survival in the event of an emergency, it could have completely destroyed what was left of the agency’s reputation. So NASA papered over the truth, and defended its actions as being on behalf of the astronaut’s families.
Over the next few years, multiple boosters showed signs of O-ring damage, yet performed flawlessly on-mission. This pattern was interpreted as proof there was no danger. Over time, NASA managers began to push the envelope further, believing that the degraded O-rings posed no threat. This continued until the combination of freezing weather and poor design destroyed Challenger.
Whatever lessons NASA managers learned in the aftermath of Challenger did not last. The loss of Columbia in 2003 happened for a very different reason — foam strike, not O-ring burn-through — but again, the issue was known long before the orbiter was damaged. In Columbia’s case, NASA investigators decided (erroneously) that the impact had done minor damage and refused the Department of Defense’s request to use high-resolution ground cameras to image the damaged part of the wing.
The one small mercy of the Columbia disaster is that there truly is no chance that the crew were conscious of what happened to them. The orbiter disintegrated hundreds of thousands of feet in the air, and the astronauts weren’t wearing pressure suits. The Columbia investigation found that the crew would only have been aware of a problem for approximately 41 seconds.
Research any tragedy or disaster, and you’ll almost always find that someone knew about the problem beforehand. From the lead in Flint’s water to the levy collapses in Katrina, from Challenger to the Titanic, it’s a rare calamity indeed that truly strikes without warning. Sometimes, these failures occur because our technological abilities have outstripped our understanding. Often, they occur because we fail to follow our own best practices.
The most sobering lesson of Challenger is that Challenger wasn’t unique. The managers and engineers who ultimately signed off on the launch weren’t trying to deliberately gamble with the lives of the seven astronauts who died that January morning. It would be more comforting if they had. It’s easier to declare people evil than to sit and grapple with how organizational culture can lead to such catastrophic failures.
We all cut corners. We all make compromises. We all skip our own best practices, whether that means a full eight hours of sleep every night, or sticking to a healthy diet. We all lie to ourselves in little ways, and because the majority of us are tiny fish in a very large pond, we don’t see much in the way of consequences.
The biggest lie we tell ourselves is that bigger fish than us automatically make better decisions than we do. Challenger, Columbia, and the hundreds of tragedies large and small that have played out in the intervening thirty years are proof they don’t. All too often, the wrong people end up paying for the failure.
There’s no way to tell if the anonymous NASA officials quoted above knew the truth or not, and it’s more than a little eerie that a NASA official dismissed a foam strike as problematic when it was a foam strike that doomed Columbia 17 years later. Either way, it didn’t take long for the agency’s explanation of events to come under fire.
On February 7, NASA officials acknowledged that they’d previously seen O-ring degradation when launching in cold weather, and that they’d held a call with rocket design firm Morton-Thiokol to discuss whether or not to launch the mission. By mid-February, NASA had admitted that it waived the requirement for effective backup safety seals on the space shuttle’s booster rockets.
The technical and safety evaluations that led to the launch failure were inexcusable. The NASA engineers that pushed for delay due to the unusually low temperatures and the effects this could have on the Shuttle’s O-rings were overruled by managers eager to complete the mission. What happened to the crew was even worse.
The fate of the Challenger crew
In the wake of the disaster, it was widely believed that the crew cabin was destroyed in the explosion. NASA never made an official statement on the matter, but heavily implied that the crew was killed instantly — a view reinforced by other astronauts and experts who spoke on-record at the time. This Washington Post story, written when the crew cabin was located, describes how “the explosive force of the initial fireball virtually shredded much of the orbiter into scores of pieces” and “tore open the crew cabin.” While the article doesn’t claim to know exactly when the crew died, the implication is clear.This pleasant fiction was derailed by two events. First, the recovery of the crew cabin, with the remains of some astronauts still aboard, and second, high-speed footage of the explosion itself. NASA only released the footage when compelled to do so through the Freedom of Information Act.
The crew cabin of the space shuttle was made of reinforced aluminum and designed to withstand extreme flight tolerances. Footage of the explosion shows the cabin exiting the cloud more-or-less intact. Contrary to popular belief, Challenger was destroyed by aerodynamic stresses far beyond its design tolerance, not an explosion.
Challenger was torn apart at 48,000 feet, but the crew cabin arced higher, reaching a maximum altitude of 65,000 feet before it began to descend.
The crew of Challenger didn’t wear bulky pressurized space suits during lift-off, but they did have access to Personal Egress Air Packs, or PEAPs. PEAPS could provide crewmembers with approximately six minutes of air (albeit unpressurized air) in the event of a mishap. When NASA discovered the wreckage of the crew cabin, it found that three of the PEAPs had been activated, including the one belonging to Shuttle Pilot Michael Smith. Because Smith’s PEAP was mounted on the back of his chair, he could not have activated it himself.
Whether the crew was conscious would have depended on whether the cabin was breached. But the damage from hitting the ocean at 207 mph with a deceleration impact of more than 200 g destroyed a great deal of evidence.
The air reserve found in the activated PEAPs matched consumption expectations if the astronauts had remained conscious for the duration. Electrical switches on Smith’s chair had been moved as well. The switches in question were protected with lever locks, making accidental actuation impossible. Tests showed that neither impact with the ocean or the initial explosion could have shifted them. NASA’s formal conclusion was that “It is possible, but not certain, that the crew lost consciousness due to an in-flight loss of crew module pressure.”
A report from the Miami Herald in November 1988 details the steps NASA took to prevent civilian doctors from examining the remains of the recovered crew members. The organization was already under heavy fire for its safety procedures and practices. The simple fact was, the Space Shuttle design didn’t prioritize crew safety. Once the solid rocket boosters (SRBs) ignited, there was no way to abort the liftoff until approximately two minutes after launch. The Challenger disaster occurred well before this point, at ~73 seconds.
The vertical axis shows various abort strategies that might be employed. The horizontal axis measures the time since ignition. White areas of these graphs indicate which aborts were considered survivable, black means the total loss of both crew and vehicle.
The Space Shuttle had been sold to the American people as safer than Apollo-era vehicles. Had the public learned that pre-Challenger missions had almost no chance of survival in the event of an emergency, it could have completely destroyed what was left of the agency’s reputation. So NASA papered over the truth, and defended its actions as being on behalf of the astronaut’s families.
The Columbia connection
One of the reasons NASA went ahead with the Challenger launch was due to what sociologist Diane Vaughan deemed the “normalization of deviance.” NASA had observed a burned O-ring during the second Shuttle mission and was well aware of the problem. At that point, the organization had two options: Ground the nascent Shuttle fleet and design a fix for the problem, or keep flying the rockets and see what happened. Grounding the fleet wasn’t believed to be politically tenable; the Shuttle was already late and over-budget.Over the next few years, multiple boosters showed signs of O-ring damage, yet performed flawlessly on-mission. This pattern was interpreted as proof there was no danger. Over time, NASA managers began to push the envelope further, believing that the degraded O-rings posed no threat. This continued until the combination of freezing weather and poor design destroyed Challenger.
Whatever lessons NASA managers learned in the aftermath of Challenger did not last. The loss of Columbia in 2003 happened for a very different reason — foam strike, not O-ring burn-through — but again, the issue was known long before the orbiter was damaged. In Columbia’s case, NASA investigators decided (erroneously) that the impact had done minor damage and refused the Department of Defense’s request to use high-resolution ground cameras to image the damaged part of the wing.
The one small mercy of the Columbia disaster is that there truly is no chance that the crew were conscious of what happened to them. The orbiter disintegrated hundreds of thousands of feet in the air, and the astronauts weren’t wearing pressure suits. The Columbia investigation found that the crew would only have been aware of a problem for approximately 41 seconds.
The lies we tell
I was a few weeks shy of seven when Challenger exploded. I don’t recall the specifics of President Reagan’s address, but I distinctly remember the shape of the smoke, thick divergent columns twisting in the sky.Research any tragedy or disaster, and you’ll almost always find that someone knew about the problem beforehand. From the lead in Flint’s water to the levy collapses in Katrina, from Challenger to the Titanic, it’s a rare calamity indeed that truly strikes without warning. Sometimes, these failures occur because our technological abilities have outstripped our understanding. Often, they occur because we fail to follow our own best practices.
The most sobering lesson of Challenger is that Challenger wasn’t unique. The managers and engineers who ultimately signed off on the launch weren’t trying to deliberately gamble with the lives of the seven astronauts who died that January morning. It would be more comforting if they had. It’s easier to declare people evil than to sit and grapple with how organizational culture can lead to such catastrophic failures.
We all cut corners. We all make compromises. We all skip our own best practices, whether that means a full eight hours of sleep every night, or sticking to a healthy diet. We all lie to ourselves in little ways, and because the majority of us are tiny fish in a very large pond, we don’t see much in the way of consequences.
The biggest lie we tell ourselves is that bigger fish than us automatically make better decisions than we do. Challenger, Columbia, and the hundreds of tragedies large and small that have played out in the intervening thirty years are proof they don’t. All too often, the wrong people end up paying for the failure.