Updated
Updated · ZDNet · Jul 21
Android 17 Adds Intrusion Logging, Storing Encrypted Security Event Logs in Google Cloud
Updated
Updated · ZDNet · Jul 21

Android 17 Adds Intrusion Logging, Storing Encrypted Security Event Logs in Google Cloud

2 articles · Updated · ZDNet · Jul 21

Summary

  • Android 17 now lets users enable Intrusion Logging, a free feature that records suspicious security events for later troubleshooting and review.
  • The logs draw from Android's SecurityLog API and cover app installs, deletions and updates, network activity including DNS queries and IP addresses, Bluetooth file transfers, certificate changes, and lock events.
  • Google stores the logs on its cloud servers, but says they are end-to-end encrypted and can be decrypted only by the user with an account-linked password or screen lock.
  • Users can turn the setting on under Security & privacy's Advanced Protection menu, then later download and decrypt the log after biometric, PIN, or password verification.
  • The feature marks a shift from Android's limited prior logging, giving users a built-in way to investigate potential compromises on their phones.

Insights

Can Android's new spyware log truly outsmart state-level hackers, or does it just create a new digital battleground?
Is Google's new security feature empowering users or just shifting the burden of finding attacks onto them?