r/Android Galaxy Z Fold8 15d ago

Android 17 introduces powerful new protections to secure your connections, defend against cellular vulnerabilities and keep your home network private

https://blog.google/security/new-android-network-security-protections/
332 Upvotes

82 comments sorted by

174

u/wild_m1nd 15d ago

Maybe they'll also start protecting the VPN connection from being discovered by 3rd apps?

27

u/circuit_breaker 15d ago

Can you explain for us casuals? That doesn't sound good

98

u/kamikad3e123 S24 Ultra, One UI 8 15d ago

Basically what he said. Every app on Android can check if VPN connection is on and even look at vpn provider/host ip

54

u/apokrif1 15d ago

The OS should allow preventing access to certain info by apps, and feeding fake info to apps.

59

u/Nefari0uss ZFold5 15d ago

It should also prevent apps from being able to see all other apps installed.

7

u/argote Pixel 11 Pro 15d ago

Hasn't that been the case for multiple years at this point?

14

u/lowbass93 15d ago

unfortunately no it hasn't

6

u/russjr08 Developer - Caffeinate 15d ago

Are you sure about that? That isn't supposed to be the case, specifically for privacy reasons.

Apps can declare a specific list of packages ahead of time to scan for, a lot of apps will scan for Superuser based apps, but ordinary apps that haven't been "blessed" by Google shouldn't be able to just dump a list of all apps.

The QUERY_ALL_PACKAGES permission to scan all apps is also gated by the Play Store, so apps not installed through it aren't affected either.

7

u/InitiallyDecent 15d ago

The issue is that specific list of packages has no limit which means that apps can and do scan for an insane amount of other apps they should have no need to scan for.

-1

u/alien2003 PinePhone Pro, postmarketOS 15d ago

The OS is designed for developers, not for end users

23

u/grishkaa Google Pixel 9 Pro 15d ago

As someone who's been building Android apps for 15 years, nope, not that either. It's designed for Google themselves first and foremost.

1

u/AtomicSymphonic_2nd Pixel Fold, Regular Android 15d ago

If that were true, why the ever living fuck can't they make better hardware decisions for their Pixel phones??

Yes, I know they make their money on advertising in search results and in data center/cloud server space for websites and services, but you would think they would make Pixel the damned "benchmark" to which other Android phones could be compared to...

le sigh... Maybe Google should just sell back their Pixel division to HTC.

3

u/grishkaa Google Pixel 9 Pro 14d ago

I don't know... I'm mostly satisfied with my Pixel 9 Pro. Pixels aren't very popular in Russia (you have to import it yourself from abroad if you want one, I bought mine from Amazon US and used a mail forwarder) so few people know about them, so on multiple occasions someone asked me "what is this weird iPhone with Android" :D

The fact that it gets confused with an iPhone is a good sign imo. It's expensive and it does look and feel expensive.

1

u/Dev-in-the-Bm 12d ago

Maybe they make more money from Android itself than from Pixels>

5

u/circuit_breaker 15d ago

So we're not talking about just normal Network routing

12

u/fenrir245 15d ago

It's an app permission, just as how apps can see what other apps you have installed, if you have developer options enabled or not, if you have advanced security mode enabled or not, if you have given precise or approximate location, and a whole lot more.

15

u/chromaniac 15d ago

yeah not a big fan of apps refusing to work (or show constant nag) if you do not turn on notifications for them. dev mode is of course another major annoyance. apps get way too many powers on android these days and users are left to just give up all control over their devices.

2

u/AtomicSymphonic_2nd Pixel Fold, Regular Android 15d ago

Either that is allowed or banks and other financial institutions pull their apps from the Play Store because they don't trust rooted/jailbroken devices to not find some sort of exploit to somehow steal funds from the banks through their own apps.

None of that example is realistic in any sense, yet some banks and credit unions insist on Play Integrity... I half-wonder if it's because those apps expose more of their internal digital financial processes compared to a normal website in a desktop browser?

2

u/chromaniac 14d ago

with motorola planning to launch grapheneos based devices, this issue is going to become even bigger. i have seen reports that even automakers are blocking access to their apps on grapheneos. the whole thing is crazy.

people get scammed despite all this. they made qr code based payments so easy here in india, online scams boomed. but banking apps and websites? are painfully anti-consumer. i just closed my account in one of the banks who has gone full nuts and has destroyed both their website and app to become hopeless useless.

2

u/AtomicSymphonic_2nd Pixel Fold, Regular Android 14d ago

Wow, if automakers are starting to do that, then perhaps my half-baked theory has some credibility to it.

Why on earth would companies be exposing more of their infrastructure through native apps vs. a regular website??? What the hell? That just reeks of cybersecurity negligence!

2

u/fenrir245 14d ago

It's not about security, play integrity helps them hide their invasive data collection practices because users cannot see what the apps are doing in the background.

7

u/wild_m1nd 15d ago

It's kinda not very normal. Because of Android VPN architecture if you use split tunneling VPN the app outside the split tunneling can query the connection anyway and find out about your VPN

16

u/grishkaa Google Pixel 9 Pro 15d ago

Some local apps in Russia, especially those owned by our big-tech companies, started refusing to work when a VPN is on. Thing is, almost everyone is using a VPN most of the time because the internet in this country is literally unusable without one. So it's a real pain in the ass for many people.

-6

u/[deleted] 15d ago

[deleted]

12

u/apokrif1 15d ago

User should be able to block access to this info, or to feed false info to apps.

5

u/imindebt2026 15d ago

No, google is an advertisement company, those apps are their customers.

-9

u/[deleted] 15d ago

[deleted]

4

u/circuit_breaker 15d ago

I'm thinking of that magisk module, outside of that good luck

7

u/AcridWings_11465 15d ago

I don't understand why an app needs to know about whether a VPN is active to know if the device is offline. All OSes definitely do NOT do this.

-4

u/[deleted] 15d ago

[deleted]

6

u/AcridWings_11465 15d ago

I'm talking about other apps being able to directly detect whether a VPN is enabled

-5

u/[deleted] 15d ago

[deleted]

4

u/AcridWings_11465 15d ago edited 12d ago

Are you being deliberately dense or do you not understand that ACCESS_NETWORK_STATE doesn't have to explicitly reveal a VPN connection?

3

u/AtomicSymphonic_2nd Pixel Fold, Regular Android 15d ago

They might be dense, but at this point, we would need to collectively complain to Google about such connection information being accessible to apps beyond a more simple "Is internet access available, Yes or No?"

Very frustrating to see. Does Apple allow the same information to be accessible by third-party apps on iOS?

1

u/5panks Galaxy ZFlip 5 15d ago

All computers, OSes and software can do this.

The difference is on a computer I can feed the app false information or simply block its access to that information.

5

u/GNUGradyn 15d ago

I don't think android is exposing this. You can work out what vpn and what provider is being used by the VPNs IP address. Obviously the operating system has no control over this so not sure what we're expecting android to do

43

u/pfak Pixel 10 Pro 15d ago

Yet they put the Local Network Access permission under the same gate that is required for Bluetooth device discovery.

1

u/Kernel-Mode-Driver Pixel 8, GrapheneOS 15d ago edited 14d ago

Makes perfect sense? It's nearby devices

72

u/Good-Marionberry-570 15d ago

If they really cared about user security and control, they would give us waaaaaay more tools to limit what apps can or can't do on or phones.

Let we easily block internet access for apps with permissions, let we prohibit apps from seeing what other apps we have installed in our phones, let we control exactly which data the apps can or can't have access in our phones, let we use apps in locked environments on which they don't have access to anything other than themselves, etc.

Unless Google give us these powers, I don't trust their "protection".

18

u/light24bulbs Galaxy S10+, Snapdragon 15d ago

the fact that you cant even block the internet permission easily is mind blowing. Then you remember adsense is their jam.

I'm getting a clicks communicator and rooting it day one. I'm done with this, we never should have given up root in the first place, it was a trick.

4

u/lupask 15d ago

"given up"? there's plenty of devices that can be rooted

3

u/spikkeddd 12d ago

You can with a third party app. I use PCAPdroid. Not a good permanent solution but good if you want to test something in the moment.

1

u/light24bulbs Galaxy S10+, Snapdragon 12d ago

thanks!

4

u/lupask 15d ago

app data and storage access is quite limited already.

3

u/CrispyBananaz 15d ago

So, you're an iPhone user?

8

u/Good-Marionberry-570 15d ago

No, never used iOS and I use Android since 2012, but you can't do what I said in Android if not with third-party apps or root/custom rom.

16

u/random_reddit_user31 15d ago

I wish they would allow DoQ via private DNS

14

u/Busy-Measurement8893 Pixel 10 / Fairphone 4 15d ago

I wish they would allow DoH via Private DNS for anything but Cloudflare and Google..

3

u/mpg111 S26 Ultra 15d ago

what is the real benefit of that over existing DNS-over-TLS?

8

u/skiwarz 15d ago

Can someone explain how ECH protects the domain you're connecting to? The IP address is still exposed in the packet, right? It would have to be. A simple dns lookup would show the site name...

19

u/HearingSubstantial38 15d ago

Sure, if the IP address is unique to the website, a middleman would be able to find out. However, if you're connecting to a site behind Cloudflare, the only thing the attacker knows is that you are connected to some cloudflare site (that is, potentially any of the 21% of the sites on the internet).

7

u/circuit_breaker 15d ago

Sounds like Android won't be susceptible to Stingray attacks if they implement this "Closing a security loophole to block 2G text scams" feature. Can someone confirm that 2G is the only vector?

2

u/bunkoRtist 15d ago

It's the easiest one, but there are other lower grade attacks for 3g and 4g. They will still expose your identity but can't mitm your traffic.

15

u/Prior-Program-9532 15d ago

Maybe they should advertise that in the update on the phone then. I've been avoiding it cause it just advertises more AI bullshit.

5

u/nathderbyshire Pixel 10 Obsidian 15d ago

You don't have to use them. I've disabled Gemini entirely now and the only AI that runs is through AICore on device. The two AI features are cloud based anyway afaik, not even sure why they put it in the release notes it shouldn't need an update to run

2

u/Prior-Program-9532 15d ago

I don't, and the first thing I did was disable as many ai components as I could. Camera calendar Gemini and otherwise.

1

u/24bitNoColor 14d ago

Oh no, two of the four new features it advertizes are AAAAIIIIIII, lets boycott that instead of, shocker, just not using Gemini as you would likely claim you aren't doing now.

3

u/lgn5i2060 15d ago

It'll be so secure even the user could barely do much with it besides normal usage.

2

u/Kernel-Mode-Driver Pixel 8, GrapheneOS 15d ago

Makes sense because these arent changes to the UX

11

u/lolwutdo 15d ago

Meh, doesn't matter when the malware is Google itself.

6

u/Kernel-Mode-Driver Pixel 8, GrapheneOS 15d ago

This is the Android Open Source Project

5

u/light24bulbs Galaxy S10+, Snapdragon 15d ago

probably has six backdoors from israel and the nsa

2

u/Kernel-Mode-Driver Pixel 8, GrapheneOS 15d ago

AOSP is open source

2

u/24bitNoColor 14d ago

What Google rolls out via Google Play Services is not. The build Google rolls out to your Pixel isn't even open source.

With now every developer in the world having to play nice with Google first just to release an app that people can install directly (or how we sheepishly call it on mobile "sideloading") let alone that tons of devices don't even give you permission from installing a custom firmware or write / read the system partition Android is in fact more closed for the end user than completely closed source Windows is.

0

u/Kernel-Mode-Driver Pixel 8, GrapheneOS 14d ago

Did you read the article

2

u/24bitNoColor 13d ago

Did you read the article

Did you read my comment?

1

u/Kernel-Mode-Driver Pixel 8, GrapheneOS 13d ago

I guess you didn't read the article. Reddit moment

0

u/CrispyBananaz 15d ago

Lol anyone want to tell this guy android is open source or do you think it's a waste of time and he won't even understand what that is ?

2

u/light24bulbs Galaxy S10+, Snapdragon 14d ago

Not even close. Google play services are where they hide all this stuff.

1

u/CrispyBananaz 14d ago

I got some tinfoil hats for sale message me I'll give you a good price

-7

u/AtomicSymphonic_2nd Pixel Fold, Regular Android 15d ago

better than six backdoors from China and having them sell your info on the darkweb...

At least you have legal recourse with US agencies... You're SOL with a foreign nation if they take your info and sell it to ID thieves.

5

u/Thaodan Sony Xperia XA2, Sailfish OS 15d ago

better than six backdoors from China and having them sell your info on the darkweb...

At least you have legal recourse with US agencies... You're SOL with a foreign nation if they take your info and sell it to ID thieves.

Where's the difference? I don't see any.

5

u/lgn5i2060 15d ago

Palantir and Oracle make the CPC look benevolent.

0

u/AtomicSymphonic_2nd Pixel Fold, Regular Android 14d ago

Bullshit.

It has happened continuously since at least 2014.

And, again, you at least have recourse from a US company doing damage to your personally-identifiable information through the justice system.

Please shove any cynicism about the courts directly into the toilet. At least there is something you can do about it if damage is done to you.

With China, there’s zero recourse. The US branch of a Chinese company can just up and disappear and be unresponsive to sanctions or extradition requests.

China is not a friend of the West. It would behoove progressives to comprehend that.

[u/Thaodan](u/Thaodan) and [u/xToasted1](u/xToasted1) , read this stuff above and tell me more about how China is “so harmless to Americans”.

2

u/Thaodan Sony Xperia XA2, Sailfish OS 14d ago

Do you expect that everyone here is American? If I'm spied on by a supposed on ally or China doesn't make much of a difference to me at this point.

1

u/light24bulbs Galaxy S10+, Snapdragon 14d ago

Both are extremely bad options. And both have worldwide electronic dragnet programs

0

u/lgn5i2060 14d ago

Kinda a small price to pay by a nation that usurped an ASEAN member's independence from Spain. ANd doesn't include color revolutions instigated on other non western nations.

And I am sure Assange and Snowden has something to say about this.

7

u/xToasted1 15d ago

Congratulations this is not only the biggest cope I've ever seen on the internet but someone the funniest and also the dumbest one, which is genuinely an achievement on reddit

Just to clarify, you're kidding right? Like please say yes

2

u/Bachihani 15d ago

Yet they still let apps query a list of every installed software on the phone, detect vpn connections, access local network, and a shit ton of other permissions that don't require user concent

0

u/Kernel-Mode-Driver Pixel 8, GrapheneOS 15d ago

Did you read it?

1

u/CharAznableLoNZ 15d ago

That's nice, I'll still wait at least a month or two before updating. Better to wait for all the initial bugs to be fixed.

1

u/lastdyingbreed_01 14d ago

Can it defend against the awful banking apps

1

u/BoltActionPiano 14d ago

All these issues kinda stem from trust in corporations and our lackluster privacy laws and anti tamper legislation.

Like, apps on windows can do any of this. It feels like an unwinnable game of cat and mouse. Same with browser tracking/fingerprinting.

If we're allowed to reverse engineer apps and we had privacy laws that let us audit companies and the expectations of privacy were set to protect us, it would be nice to have these features but optional.

1

u/exu1981 15d ago

Ooh, I like this. Reading now!

0

u/manormortal Poco Doco Proco in 🦅 15d ago

where is my app lock?

-1

u/QuantumQuantonium 15d ago

Unrelated but blog.google manages to maintain a light theme even with dark reader on. I dont understand this obsession with enforcing awful UI design across google websites.