Android Adds Intrusion Logging to Help Detect Sophisticated Spyware
Google on May 12 began rolling out Intrusion Logging, an opt-in feature within
The encrypted-log architecture shifts evidence-preservation advantage toward defenders by surviving device seizure and operator-initiated trace deletion, a gap Android's short-lived developer buffers left open for years. The Amnesty-Google design partnership, absent independent corroboration, offers a replicable model for embedding civil society forensic requirements at the design stage rather than retrofitting after deployment. Coverage remains narrow: opt-in, Android 16, and Pixel hardware hold a small fraction of global Android installations, leaving operators targeting the broader population with no change in forensic exposure until the feature expands. Root access defeats log preservation even on covered devices. The mandatory cloud upload creates a legal-compulsion surface governments could exploit even where Google cannot decrypt the content, a risk the encryption architecture does not eliminate.
1 sources
- Android Intrusion Logging for Spyware Detection -
Google Security Blog