Slashdot Mirror


Android Oreo Bug Sends Thousands of Phones Into Infinite Boot Loops (bleepingcomputer.com)

An anonymous reader writes: A bug in the new "Adaptive Icons" feature introduced in Android Oreo has sent thousands of phones into infinite boot loops, forcing some users to reset their devices to factory settings, causing users to lose data along the way. The bug was discovered by Jcbsera, the developer of the Swipe for Facebook Android app (energy-efficient Facebook wrapper app), and does not affect Android Oreo (8.0) in its default state. The bug occurs only with apps that use adaptive icons -- a new feature introduced in Android Oreo that allows icons to change shape and size based on the device they're viewed on, or the type of launcher the user is using on his Android device. For example, adaptive icons will appear in square, rounded, or circle containers depending on the theme or launcher the user is using. The style of adaptive icons is defined a local XML file. The bug first manifested itself when the developer of the Swipe for Facebook Android app accidentally renamed the foreground image of his adaptive icon with the same name as this XML file (ic_launcher_main.png and ic_launcher_main.xml). This naming scheme sends Android Oreo in an infinite loop that regularly crashes the device. At one point, Android detects something is wrong and prompts the user to reset the device to factory settings. Users don't have to open an app, and the crashes still happen just by having an app with malformed adaptive icons artifacts on your phone. Google said it will fix the issue in Android Oreo 8.1.

78 comments

  1. year of the linux oreo by Anonymous Coward · · Score: 0

    yay!

    1. Re:year of the linux oreo by jazzmans · · Score: 1

      How does everyone miss

      "and does not affect Android Oreo (8.0) in its default state."

      in the original article?

      --
      Life is what happens to you while you are busy making other plans. No-one sees motorcycles
    2. Re:year of the linux oreo by Anonymous Coward · · Score: 0

      This is EXACTLY why you should not jump on new software and updates right away. Google and Microsoft's rushed, forced, duct-tape approach to software "development" is idiotic.

  2. Facepalm by Anonymous Coward · · Score: 1, Insightful

    Really guys?
    Let's not even get into the stupidity of assuming a file extension (or that they stupidly walked the file system looking for the first matching NAME minus the extension) - but how can you let your SUPER SECURE OS get borked because of one unruly configured app which NEVER happens in the real world?!
    Maybe I'm just getting old but it seems programmers is gettin' dumber every year, along with UI designers (or maybe, in this case, it's one and the same)

    1. Re:Facepalm by ColdWetDog · · Score: 5, Funny

      No, nothing so nefarious. It's just jealousy on the part of the poor little Android phones. They seem to think if they can go into one infinite loop, they will magically be transformed into iPhones.

      Simple when you think about it for a bit.

      --
      Faster! Faster! Faster would be better!
    2. Re:Facepalm by DontBeAMoran · · Score: 1

      No mod points here, as always, but here's a virtual +5 funny to you my good sir.

      --
      #DeleteFacebook
    3. Re:Facepalm by Anonymous Coward · · Score: 0

      As the OP I both groan and applaud you coz I can't mod you! :)

    4. Re:Facepalm by TheFakeTimCook · · Score: 1

      No, nothing so nefarious. It's just jealousy on the part of the poor little Android phones. They seem to think if they can go into one infinite loop, they will magically be transformed into iPhones.

      Simple when you think about it for a bit.

      I, for one, appreciate that little joke/reference!

      Bravo!

    5. Re:Facepalm by Anonymous Coward · · Score: 0

      Nice to know slashdot's resident Apple shill approves.

    6. Re:Facepalm by Anonymous Coward · · Score: 0

      hmm... I would take an android phone that is in an infinite boot loop over ANY iPhone... ANY day of the week,,, :-)

      luckily I have no android oreo devices, all my nougat devices are working perfectly

  3. I don't get it by Anonymous Coward · · Score: 0

    forcing some users to reset their devices to factory settings, causing users to lose data along the way.

    I'm out of touch; my phone runs 4.1.2 Jelly Bean.
    But I don't get it.
    Resetting to factory settings doesn't erase the SD card, does it?
    If so, pull it out before resetting.

    1. Re:I don't get it by SScorpio · · Score: 2

      SD card is paired to the phone and encrypted. Factory reset blows away the key so all data is lost.

    2. Re:I don't get it by kelemvor4 · · Score: 3

      forcing some users to reset their devices to factory settings, causing users to lose data along the way.

      I'm out of touch; my phone runs 4.1.2 Jelly Bean. But I don't get it. Resetting to factory settings doesn't erase the SD card, does it? If so, pull it out before resetting.

      Not unless you're an apple fanboy looking for a reason to complain online...

    3. Re:I don't get it by Anonymous Coward · · Score: 0

      Just how is it that Google was able to sell that "paired and encrypted" business as a positive benefit?

    4. Re: I don't get it by SuperKendall · · Score: 1

      Because technical users demanded external storage so Google provided support for it no matter how it hurt non-technical users.

      --
      "There is more worth loving than we have strength to love." - Brian Jay Stanley
    5. Re:I don't get it by tepples · · Score: 2

      The same way Chromebook developer mode begging the user to wipe it is a feature: it ensures someone who steals your SD card won't be able to see your private data.

    6. Re:I don't get it by Anonymous Coward · · Score: 1

      Because any other option would require the user to either a) Be aware of the encryption key or b) Use a password derived encryption key and require the user to enter said password. In the name of KISS, they opted to just tie it to the internal encryption key, which isn't exactly unreasonable. I would do something similar if designing a consumer device. Trying to support *your* specific preference over that of what 99.99% of people (myself included) prefer, is moronic. And no, supporting both options doesn't help, as it makes using it more complicated as it's a consumer device.

      The only other option is store the encryption key in an encrypted bubble on the SD card itself that's tied to the PIN on the phone, and this creates a vulnerability that if the SD card is misplaced, an attacker can then use a brute force attack on the SD card to find out what the password of the phone is, and since most phones have pretty weak passwords, it most likely wouldn't be a hard brute force attack. And yes, this could be done on the phone itself as well, but it's a lot harder to misplace a phone than it is an SD card. Also, if they change the PIN on the phone while the SD card isn't in the device, they need to do something to detect that the two PINs are out of sync. And putting known structured data in to an encrypted blob to verify it decrypted successfully tends to be a poor idea, as this opens up a whole slew of other attack vectors for encryption.

    7. Re:I don't get it by MachineShedFred · · Score: 3

      Remember all the wailing and gnashing of teeth about devices that don't have SD card slots anymore? Yeah, those are the same newer devices that actually have a prayer of seeing an updated image that could cause this problem.

      By the way, nice OS release where the simple installation of an app, and not actually running it, can destroy your operating config to the point of effectively needing to reimage the device... and then not actually fixing the root cause until 8.1. Are they fucking serious with that?

      --
      Slashdot still doesnâ(TM)t support Unicode after it was added to the HTML standard in 1997.
    8. Re:I don't get it by Anonymous Coward · · Score: 0

      Modern phones (read as models released in the last couple of years) don't typically allow access to the SD card. They are sealed units.

    9. Re:I don't get it by Anonymous Coward · · Score: 1

      Because it means that if someone steals your phone, without the password they don't get any data out of it, not even from the SD card

      I prefer it that way, phones get stolen way too often.

      Preventing data loss is simple... The procedure is called 'regular and complete backups'. It's no different from a laptop or a desktop. If you don't have a backup, your data is not important.

    10. Re:I don't get it by Anonymous Coward · · Score: 0

      Yeah, came here for that 8.1 sentense. 8.1 fix is too fucking late. It needs to be fixed in 8.0.1 hotfix.

    11. Re:I don't get it by DontBeAMoran · · Score: 4, Insightful

      If they're sealed units, chances are there's no "SD card" inside. It's flash storage ICs soldered directly to the PCB.

      --
      #DeleteFacebook
    12. Re:I don't get it by TheFakeTimCook · · Score: 1

      forcing some users to reset their devices to factory settings, causing users to lose data along the way.

      I'm out of touch; my phone runs 4.1.2 Jelly Bean.
      But I don't get it.
      Resetting to factory settings doesn't erase the SD card, does it?
      If so, pull it out before resetting.

      Not unless you're an apple fanboy looking for a reason to complain online...

      You mean like the hundreds of Linux/Android fanbois (cleverly disguised as ACs) who descend in DROVES upon EVERY Slashdot Apple Story?

      At least I have the guts to LOGIN when I comment. I NEV-ER Post as AC. Never. And I have the Karmic Scars from fanboi Punish-Modding to prove it!

    13. Re:I don't get it by TheFakeTimCook · · Score: 1

      Yeah, came here for that 8.1 sentense. 8.1 fix is too fucking late. It needs to be fixed in 8.0.1 hotfix.

      If this was an iPhone, it would have been fixed (and DISTRIBUTED) in less time than the Slashdot Army could fire-up their Torches and grab their Pitchforks...

    14. Re:I don't get it by Anonymous Coward · · Score: 0

      Eh, at this point,why is anyone surprised at how shitty Android is?

      Hell, they didn't have permissions that worked properly or selectively for many earlier versions after promising they would. So much so that every app asks for wifi connection info which you can't turn off, so they can track you. Most of the apps are closed source, and not code reviewed, some with suspected key loggers and other apps have been caught phoning home. Major apps, where it should have been seen but was let go.

      And then there's that unified design, which just plain bombed many apps, in functionality, look, and uniqueness. You end up using a borwser. And don't get me started on how shitty and limiting the Android Chrome app is.

      Yeah, there's convenience sometimes with Android, but once you see Google force you to go to settings to review your phone settings so they can request to serve you more ads or link you to "friends", you become wary. The whole Google ad network is getting just damn creepy. Nothing like not tuning into History Channel for, like, forever, watching Fury, and do a Google Play app check and see the History Channel app suddenly first. You realize Comcast is selling dta information to someone feeding it to Google. Lovely.

    15. Re:I don't get it by Anonymous Coward · · Score: 0

      And how would you design it to have a proper factory reset on the phone and still enable secure removable storage? If you do a factory reset on an iPhone all your data is lost as well and even if it didn't delete it it would be rendered inaccessible anyway since the encryption keys have been reset.

    16. Re:I don't get it by Anonymous Coward · · Score: 0

      You're not an Android user, are you?

      The option is there to merge with OS *OR* as a separate "disk". The second method is not encrypted by default.

    17. Re:I don't get it by Anonymous Coward · · Score: 0

      The whole problem here is the "secure removable storage". They claim it's good for users, but it's really only good for Google.
      On earlier versions of Android the SD card was a good way (and once they added that MTP abomination the only way) to move data between your phone and your computer. But of course Google has never wanted you to do that.

    18. Re:I don't get it by Anonymous Coward · · Score: 0

      Bullshit.

      APL was the LAST to revoke the shift SSL root certificate last year.

      Let's be honest here, this won't actually happen to 99.99999% of the people out there because companies want to keep the reputation clean. This particular bug, as bad as it is, should only happen to developers who name their icons a very specific name. There's no way a popular company would push this out as they, you know, test it on their own gear.

    19. Re: I don't get it by Anonymous Coward · · Score: 0

      Incorrect, my s8+ has 256gb card in it. Most android phones have a slot. Google updated android recently to make the sd card far more accessible too. Only iPhone and a select few android models don't support as cards.

    20. Re: I don't get it by Anonymous Coward · · Score: 0

      The importance of "external storage" is exchanging data with other devices. An SD card you can't use in anything else doesn't qualify.

    21. Re: I don't get it by tehcyder · · Score: 1

      The importance of "external storage" is exchanging data with other devices. An SD card you can't use in anything else doesn't qualify.

      No, for ordinary users, the importance of external storage is that they can quadruple their phone's storage for $20 and actually be able to have more than a couple of apps and four songs available.

      --
      To have a right to do a thing is not at all the same as to be right in doing it
    22. Re:I don't get it by TheFakeTimCook · · Score: 1

      And how would you design it to have a proper factory reset on the phone and still enable secure removable storage? If you do a factory reset on an iPhone all your data is lost as well and even if it didn't delete it it would be rendered inaccessible anyway since the encryption keys have been reset.

      In an iPhone situation, you can do a Backup of your Phone, do a Reset to Factory Settings, then Restore From Backup. The key thing being that you musn't forget your passphrase before the Restore, or THEN you're borked...

      You can even create a Non-Encrypted Backup if you don't care about Health and "Activity" Data (or iBooks PDFs!!! Grrrr!!!). But here is how you Backup, Restore to Factory Settings, then Restore (Apps & Data) for an iPhone.

      Backup: https://support.apple.com/en-u...

      Reset to Factory Settings: https://support.apple.com/en-u...

      Then, Restore your Backup: https://support.apple.com/en-u...

      There: Is THAT clear enough for ya?

      Of course, if you DIDN'T make an iTunes Backup (or enable iCloud Backup) before doing an OS Upgrade that borked your iPhone, as usual, you deserve EXACTLY what you get.

    23. Re:I don't get it by TheFakeTimCook · · Score: 1

      The whole problem here is the "secure removable storage". They claim it's good for users, but it's really only good for Google.
      On earlier versions of Android the SD card was a good way (and once they added that MTP abomination the only way) to move data between your phone and your computer. But of course Google has never wanted you to do that.

      At least Apple lets you use iTunes or iCloud to backup your phone's data. And if you use iCloud backup, I believe its all done automagically, like with Time Machine.

      And with Apple's new iCloud pricing, that option is looking pretty good, to have an always-up-to-date backup of your instantly-lose-able iPhone/iPad for 3 bucks per month ($36 per year) sounds like a pretty good deal to me. And Apple's "Family Plans" for using "Shared Storage" on iCloud are pretty reasonable, too.

    24. Re:I don't get it by SScorpio · · Score: 1

      And almost nothing uses the SD card when it's in "portable" mode. You need to adopt the SD card if you want to expand your phone's storage.

  4. I know this... by DontBeAMoran · · Score: 2

    This bug shall be called the Buzz Lightyear bug.

    --
    #DeleteFacebook
    1. Re:I know this... by barbariccow · · Score: 1

      Why break with the common pattern these days? Icongate!

  5. They knew the risk. by dc29A · · Score: 1

    It's beta software.

    1. Re:They knew the risk. by Luthair · · Score: 2

      Oreo isn't beta, its on devices.

    2. Re:They knew the risk. by YuppieScum · · Score: 3, Insightful

      The two are not mutually exclusive...

      --
      This sig left unintentionally blank.
    3. Re:They knew the risk. by barbariccow · · Score: 1

      gmail was beta for a thousand years whilst I was using it. Even past the invite-only period.

    4. Re:They knew the risk. by Anonymous Coward · · Score: 0

      Yeah, just ask Apple, Google, or Microsoft about that.

      Home user = beta tester
      Work user = user

  6. Re:Kids have known this for years about Oreo... by DontBeAMoran · · Score: 1

    That's a lousy way to eat the creme filling. Open the oreo, use a clean knife to scrape the filling, put the cookies back in the package. Not only is it hygienic, it's much faster and in the end you get to bite into a big blob of awesome-tasting sugar.

    --
    #DeleteFacebook
  7. Infinite eh? by Anonymous Coward · · Score: 1

    How do we know that if they just left the phone in boot looping for the next millennia that it wouldn't recover on the twenty seven septillionth time?

    1. Re:Infinite eh? by DontBeAMoran · · Score: 1

      You must be a scientist.

      --
      #DeleteFacebook
    2. Re:Infinite eh? by Anonymous Coward · · Score: 0

      That kind of a phone should be harnessed for energy production. With enough infinitely booting phones we could be powered forever!

  8. Hopefully by Luthair · · Score: 1

    Google will start preventing APKs from being added to their store with this problem. Seems like a relatively easy thing to scan for.

    1. Re:Hopefully by ELCouz · · Score: 1

      Please don't summon APK on /. ...PLEASE!!!

    2. Re:Hopefully by Anonymous Coward · · Score: 0

      But the solution to this problem is simple. Host files!

      APK

    3. Re:Hopefully by Anonymous Coward · · Score: 0

      We know it's not really apk because there weren't 17 PSes

  9. Hey! by FatdogHaiku · · Score: 2

    Wanna see how fast my phone boots?
    Wanna see it again?
    Wanna see it again?
    Wanna see it again?
    Wanna see it again?
    Wanna see it again?
    Wanna see it again?

    --
    You have the right to remain sentient. If you give up the right to remain sentient, you will be elected to public office
  10. Re:Kids have known this for years about Oreo... by David_Hart · · Score: 1

    That's a lousy way to eat the creme filling. Open the oreo, use a clean knife to scrape the filling, put the cookies back in the package. Not only is it hygienic, it's much faster and in the end you get to bite into a big blob of awesome-tasting sugar.

    I prefer the chocolate wafers. I've often thought that they should just sell the chocolate cookie part as Oreo cookie wafers. Of course, I'm a big fan of chocolate. Sugary creme, not so much....

  11. This is The Year of 2018. by Anonymous Coward · · Score: 0

    trying to make a mimic of Sun XGL and not call it a iPhone mimic.

    i could so away with the *roid desktop and Taskmanager all-together and just use the top-access console to context-shift tween apps and Floating Windows apk.

  12. iPhone by Anonymous Coward · · Score: 0

    First - best.

  13. Re:Kids have known this for years about Oreo... by Anonymous Coward · · Score: 0

    Wow, I can tell you don't shop for your groceries. Go to the baking ingredients aisle, you'll find chocolate wafers sold separately.

  14. Fact: Android is shit by Anonymous Coward · · Score: 0

    Why would anyone rely on a adware company to produce their operating system?

    1. Re:Fact: Android is shit by DontBeAMoran · · Score: 2

      Well, since the web seems to be 95% ads and 5% content, I guess it makes sense.

      --
      #DeleteFacebook
    2. Re:Fact: Android is shit by Anonymous Coward · · Score: 0

      Well, since the web seems to be 95% ads and 5% content, I guess it makes sense.

      Umm, where does all the porn fit into those numbers?

    3. Re:Fact: Android is shit by DontBeAMoran · · Score: 1

      It fits into the part where's we're the ones getting fucked by the ads companies.

      --
      #DeleteFacebook
    4. Re: Fact: Android is shit by Anonymous Coward · · Score: 0

      This guy speaks the truth

  15. Re:Kids have known this for years about Oreo... by DontBeAMoran · · Score: 1

    If it's the same thing as I think you are thinking about, it's very similar but somehow still a bit different than the Oreo cookies.

    --
    #DeleteFacebook
  16. released without testing by klossner · · Score: 3, Insightful

    "Jcbsera did not catch the bug during development because he tested his app's new version only inside the Android emulator provided by the Android Studio application. The bug did not manifest in the same way in the emulator as on a real device. It was only after the developer pushed the update to his users that he noticed and discovered the bug after users started flooding his Play Store page with crash complaints and bad reviews."

    He didn't even try the app on a real device. That's "move fast and break things" in action.

    1. Re:released without testing by Anonymous Coward · · Score: 0

      A normal application shouldn't be able to completely fuck the device!

    2. Re:released without testing by tlhIngan · · Score: 1

      "Jcbsera did not catch the bug during development because he tested his app's new version only inside the Android emulator provided by the Android Studio application. The bug did not manifest in the same way in the emulator as on a real device. It was only after the developer pushed the update to his users that he noticed and discovered the bug after users started flooding his Play Store page with crash complaints and bad reviews."

      He didn't even try the app on a real device. That's "move fast and break things" in action.

      Well, that's the problem with android - "fragmentation". You can't expect every developer to own every single Android device out there, so somewhere along the line they have to take the leap that it works. And if you don't own an Android 8 device, well, the emulator is all you have. Given the emulator is running a real Android 8 image you would expect it to be faithfully reproduce the Android 8 experience.

      If developers only set their apps to devices that were actually tested, then the Play Store would be dreadfully bare if you were running anything other than maybe the top 3-4 handsets.

    3. Re:released without testing by TheFakeTimCook · · Score: 1

      A normal application shouldn't be able to completely fuck the device!

      Exactly!

      Doesn't Andud have a "Sandboxing" concept?

      I'm almost POSITIVE that simply couldn't happen on iOS at the "Application" level.

    4. Re:released without testing by Wrath0fb0b · · Score: 1

      Yeah, and "move fast and break things" is contingent on the fact that for some well-structured computer systems you can always roll things back to a previously good state and try again -- nothing lost but time. This is why we have version control and what I always try to teach newbies so that they feel free to break things.

      Or maybe another way to phrase it -- the speed at which you should move and break stuff is inversely proportional to how much work it is to back your changes out. If you are writing some CSS, this is basically instant. If you are a DB admin, you should probably be careful and have a mock environment, but you have backups in case of disaster. (I hope). If you are taping out silicon and sending it to the foundry, uh, good luck!

      So the problem here isn't the 'move fast and break things', since that seems to be the appropriate model for a an app. It's that Android broke the fundamental tenet of app development: which is that if you fuck up, the worst you can do is have to uninstall the app and maybe lose all your local app data. That is, the contract was for a low-cost-to-back-out environment and instead it tanked the entire thing.

    5. Re:released without testing by AvitarX · · Score: 1

      Maybe not use features exclusive to devices you don't own?

      --
      Wow, sent an e-mail as suggested when clicking on "use classic" banner, and got a fast response that addressed my msg
    6. Re:released without testing by aardvarkjoe · · Score: 2

      Well, that's the problem with android - "fragmentation". You can't expect every developer to own every single Android device out there, so somewhere along the line they have to take the leap that it works. And if you don't own an Android 8 device, well, the emulator is all you have. Given the emulator is running a real Android 8 image you would expect it to be faithfully reproduce the Android 8 experience.

      I might buy that if this was a case of a feature that would work on his phone but was broken on another. But apparently the "adaptive icons" support was added in Android 8 -- so the developer apparently used a new feature, specifically for Android 8, that he couldn't (or just didn't bother) test at all on real hardware. That shouldn't be considered acceptable, and nobody should give him a pass for it.

      And yeah, Google screwed up big time too -- both with the bug, and the fact that apparently their emulator doesn't work.

      --

      How can we continue to believe in a just universe and freedom to eat crackers if we have no ale?
    7. Re:released without testing by antdude · · Score: 1

      SQA is usually ignored. People and companies need to stop doing that. Hire me too. :(

      --
      Ant(Dude) @ Quality Foraged Links (AQFL.net) & The Ant Farm (antfarm.ma.cx / antfarm.home.dhs.org).
  17. accidentally by sheramil · · Score: 1

    How does one "accidentally" .. "rename[d] the foreground image of his adaptive icon with the same name as this XML file (ic_launcher_main.png and ic_launcher_main.xml)."? Dearie me, that happens so often.. I meant to touch the SankakuBlack icon, and instead I found myself accidentally renaming the foreground image of my adaptive icon with the same name as this XML file (ic_launcher_main.png and ic_launcher_main.xml)."! Again! third time today, and it's only 8:00 am here! I am so clumsy.

    1. Re:accidentally by tehcyder · · Score: 1

      If I don't accidentally rename the foreground image of my adaptive icon with the same name as this XML file (ic_launcher_main.png and ic_launcher_main.xml) at least twice before breakfast I consider it a poor start to the day.

      --
      To have a right to do a thing is not at all the same as to be right in doing it