Android 17 Adds Intrusion Logging, Storing Encrypted Security Event Logs in Google Cloud
Updated
Updated · ZDNet · Jul 21
Android 17 Adds Intrusion Logging, Storing Encrypted Security Event Logs in Google Cloud
2 articles · Updated · ZDNet · Jul 21
Summary
Android 17 now lets users enable Intrusion Logging, a free feature that records suspicious security events for later troubleshooting and review.
The logs draw from Android's SecurityLog API and cover app installs, deletions and updates, network activity including DNS queries and IP addresses, Bluetooth file transfers, certificate changes, and lock events.
Google stores the logs on its cloud servers, but says they are end-to-end encrypted and can be decrypted only by the user with an account-linked password or screen lock.
Users can turn the setting on under Security & privacy's Advanced Protection menu, then later download and decrypt the log after biometric, PIN, or password verification.
The feature marks a shift from Android's limited prior logging, giving users a built-in way to investigate potential compromises on their phones.