2 min read

Android 17 adds security logs you should enable now

Android 17 includes a free Intrusion Logging feature that records security events on your phone and stores them with end-to-end encryption.

Image: ZDNET

Android 17 now includes a built-in Intrusion Logging feature that lets users store and inspect security logs on their phones, a notable change for a platform that has historically offered little direct access to this kind of data.

According to ZDNET, the feature arrived in a recent Android 17 security update and is available for free. It draws from the Android SecurityLog API and starts recording events once enabled.

The logs are protected with end-to-end encryption. Although they are stored on Google Cloud servers, only the account owner can read them because the decryption key is tied to the user’s account password and screen lock.

The data captured can include:

  • Application activity
  • App installation, deletion, and updates
  • Network connections, including DNS queries and IP addresses
  • Wi-Fi and Bluetooth status
  • Bluetooth file transfers
  • Changes to system certificates
  • Phone lock and unlock events

To turn it on, go to Settings > Security & privacy > Advanced Protection, then scroll down to Intrusion Logging and switch it on. Android will ask you to verify your identity and confirm the correct Google account is linked.

Recommended reading

1,000 GPUs could destabilize a power grid, researchers warn

To view the logs later, return to the same page, tap Access logs, then choose Download & decrypt. After authenticating with biometrics, a PIN, or a password, Android downloads a zip file containing several .txt log files.

ZDNET recommends moving that zip file to a computer instead of reading it on a phone, since desktop text editors make it easier to search for strings such as “security_event”.

Sophia Reynolds

Security Editor

Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.

via ZDNET

// Keep reading