Skip to content

Security2 publishers3 min readPublished Updated

Android 17 copies forensic logs to Google's servers, where no one can delete them for 12 months

Google's Android 17 Intrusion Logging syncs encrypted security and network logs to its servers and bars anyone from deleting them for a rolling 12 months. The feature is a separate opt-in, so the record exists only for people who enable it before an attack.

The Watch · Security desk

Illustration accompanying Android 17 copies forensic logs to Google's servers, where no one can delete them for 12 months

What happened

  • Intrusion Logging is one of six features Google added to Advanced Protection in Android 17.
  • Users download and decrypt the logs themselves and can pass them to trusted security experts to investigate a suspected compromise.
  • USB Protection blocks new USB data connections while the phone is locked, on Pixel 6 and later and selected Android 17 devices.
  • Advanced Protection now limits the AccessibilityService API, a primary fraud and scam route according to Google, to verified accessibility tools.
  • Chrome's WebGPU is switched off under Advanced Protection; Google says that reduces exposure to sophisticated browser exploits.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • decision People who expect to be targeted have to enable logging before anything happens; switching it on after a suspected compromise recovers nothing from the period that matters.
  • capability A forensic examiner can work a spyware case from the off-device copy after the phone itself has been scrubbed, provided the logs synced before the attacker acted.
  • constraint Someone holding a locked phone loses the charging port as a new data path; cable access now depends on a connection opened while the phone was unlocked.

Donncha Ó Cearbhaill, head of Amnesty International's Security Lab, said that when the feature is on, devices "will store tamper-resistant, encrypted logs which are also synced to secure cloud storage." [21] The logs cover security and network events, including app activity [2]. "If a spyware attack is suspected, these logs can later be retrieved and analyzed, even if the attacker has erased their tracks on the device itself," he said [11].

An investigator can recover only what reached Google's servers before the attacker took control of the phone [4]. Help Net Security's account of the feature does not say how often logs sync, or whether spyware running on the handset can block an upload [4].

Advanced Protection does not switch logging on by itself. It needs a separate manual opt-in on the settings page [9]. Logs are written only while the feature is enabled [21]. A phone that opts in after a suspected compromise has no record of the period before [1].

The retention rule binds the user as firmly as the attacker. Logs roll over a 12-month window [6], and neither the user nor Google can delete them early, even after logging is disabled or the account is closed [7]. They include network activity from Chrome's Incognito tabs, resolved to the website but not the page [5]. A user who opts in puts up to a year of site-level browsing, Incognito included, into storage they cannot purge [2]. Google says it cannot read the end-to-end encrypted logs [4]. A copy the user downloads and decrypts is the user's to protect [8].

USB Protection switches on with Device protection [13]. Connections opened while the phone is unlocked, such as photo transfers and wired Android Auto, stay up after the screen locks [14]. Protection starts only once the phone has finished booting, and a short grace period lets a dropped connection resume on a locked screen [14]. Charging still works, though fast charging may need an unlock [15].

Failed Authentication Lock locks the device after repeated failed authentication attempts. It is an existing Android theft feature, now folded into Advanced Protection on selected Android 17 devices [18]. For users who already had it enabled, nothing changes in what it does [18].

A new View Supporting Apps page lists installed apps that check whether Advanced Protection is on, according to Il-Sung Lee, Group Product Manager for Android Security [19]. Developers can be notified when a user enables it, so their apps can turn on extra protections [19].

Google built Intrusion Logging with civil liberties and press freedom organizations [10]. "This is the first time a consumer mobile platform has introduced purpose-built forensic logging for detecting targeted attacks," Ó Cearbhaill said [12]. Existing users will get a notification when the features reach their devices [20].

What to watch

  • Google technical documentation on how often Intrusion Logging syncs and whether a compromised handset can block or delay the upload.
  • The rollout notifications to existing Advanced Protection users; logs only start accumulating once a user opts in after that.
  • The first published spyware investigation that relies on Intrusion Logging data retrieved from Google's servers.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories