Android 17 makes it harder for spyware to cover its tracks

Google has introduced new forensic logging features in Android 17 to help users detect and investigate targeted spyware attacks. These tamper-resistant logs are end-to-end encrypted and stored in the cloud, allowing security experts to analyze evidence even if an attacker attempts to wipe the device.
Why it matters
This feature provides a significant advancement in mobile security for high-risk individuals, such as journalists and activists, who are frequent targets of sophisticated spyware.
Android 17 makes it harder for spyware to cover its tracks When a journalist suspects their phone has been hacked, the first question is whether any trace of the attack is left. Google has added six features to Advanced Protection in Android 17 , including one that keeps a copy of that evidence off the device. Existing users will receive a notification when the new capabilities become available on their devices.
Intrusion Logging records security and network events, including app activity. Users can download and decrypt the logs, then share them with trusted security experts to investigate a suspected compromise. The logs are end-to-end encrypted and stored on Google’s servers. Google says it cannot read them.
The feature also records network activity from Chrome’s Incognito tabs. Someone with access to the decrypted logs can identify visited websites, but not specific pages on those sites.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in