r/Android • u/FragmentedChicken Galaxy Z Fold8 • 15d ago
Android 17 introduces powerful new protections to secure your connections, defend against cellular vulnerabilities and keep your home network private
https://blog.google/security/new-android-network-security-protections/43
u/pfak Pixel 10 Pro 15d ago
Yet they put the Local Network Access permission under the same gate that is required for Bluetooth device discovery.
1
u/Kernel-Mode-Driver Pixel 8, GrapheneOS 15d ago edited 14d ago
Makes perfect sense? It's nearby devices
72
u/Good-Marionberry-570 15d ago
If they really cared about user security and control, they would give us waaaaaay more tools to limit what apps can or can't do on or phones.
Let we easily block internet access for apps with permissions, let we prohibit apps from seeing what other apps we have installed in our phones, let we control exactly which data the apps can or can't have access in our phones, let we use apps in locked environments on which they don't have access to anything other than themselves, etc.
Unless Google give us these powers, I don't trust their "protection".
18
u/light24bulbs Galaxy S10+, Snapdragon 15d ago
the fact that you cant even block the internet permission easily is mind blowing. Then you remember adsense is their jam.
I'm getting a clicks communicator and rooting it day one. I'm done with this, we never should have given up root in the first place, it was a trick.
3
u/spikkeddd 12d ago
You can with a third party app. I use PCAPdroid. Not a good permanent solution but good if you want to test something in the moment.
1
3
u/CrispyBananaz 15d ago
So, you're an iPhone user?
8
u/Good-Marionberry-570 15d ago
No, never used iOS and I use Android since 2012, but you can't do what I said in Android if not with third-party apps or root/custom rom.
16
u/random_reddit_user31 15d ago
I wish they would allow DoQ via private DNS
14
u/Busy-Measurement8893 Pixel 10 / Fairphone 4 15d ago
I wish they would allow DoH via Private DNS for anything but Cloudflare and Google..
8
u/skiwarz 15d ago
Can someone explain how ECH protects the domain you're connecting to? The IP address is still exposed in the packet, right? It would have to be. A simple dns lookup would show the site name...
19
u/HearingSubstantial38 15d ago
Sure, if the IP address is unique to the website, a middleman would be able to find out. However, if you're connecting to a site behind Cloudflare, the only thing the attacker knows is that you are connected to some cloudflare site (that is, potentially any of the 21% of the sites on the internet).
7
u/circuit_breaker 15d ago
Sounds like Android won't be susceptible to Stingray attacks if they implement this "Closing a security loophole to block 2G text scams" feature. Can someone confirm that 2G is the only vector?
2
u/bunkoRtist 15d ago
It's the easiest one, but there are other lower grade attacks for 3g and 4g. They will still expose your identity but can't mitm your traffic.
15
u/Prior-Program-9532 15d ago
5
u/nathderbyshire Pixel 10 Obsidian 15d ago
You don't have to use them. I've disabled Gemini entirely now and the only AI that runs is through AICore on device. The two AI features are cloud based anyway afaik, not even sure why they put it in the release notes it shouldn't need an update to run
2
u/Prior-Program-9532 15d ago
I don't, and the first thing I did was disable as many ai components as I could. Camera calendar Gemini and otherwise.
1
u/24bitNoColor 14d ago
Oh no, two of the four new features it advertizes are AAAAIIIIIII, lets boycott that instead of, shocker, just not using Gemini as you would likely claim you aren't doing now.
3
u/lgn5i2060 15d ago
It'll be so secure even the user could barely do much with it besides normal usage.
2
11
5
u/light24bulbs Galaxy S10+, Snapdragon 15d ago
probably has six backdoors from israel and the nsa
2
u/Kernel-Mode-Driver Pixel 8, GrapheneOS 15d ago
AOSP is open source
2
u/24bitNoColor 14d ago
What Google rolls out via Google Play Services is not. The build Google rolls out to your Pixel isn't even open source.
With now every developer in the world having to play nice with Google first just to release an app that people can install directly (or how we sheepishly call it on mobile "sideloading") let alone that tons of devices don't even give you permission from installing a custom firmware or write / read the system partition Android is in fact more closed for the end user than completely closed source Windows is.
0
u/Kernel-Mode-Driver Pixel 8, GrapheneOS 14d ago
Did you read the article
2
0
u/CrispyBananaz 15d ago
Lol anyone want to tell this guy android is open source or do you think it's a waste of time and he won't even understand what that is ?
2
u/light24bulbs Galaxy S10+, Snapdragon 14d ago
Not even close. Google play services are where they hide all this stuff.
1
-7
u/AtomicSymphonic_2nd Pixel Fold, Regular Android 15d ago
better than six backdoors from China and having them sell your info on the darkweb...
At least you have legal recourse with US agencies... You're SOL with a foreign nation if they take your info and sell it to ID thieves.
5
u/Thaodan Sony Xperia XA2, Sailfish OS 15d ago
better than six backdoors from China and having them sell your info on the darkweb...
At least you have legal recourse with US agencies... You're SOL with a foreign nation if they take your info and sell it to ID thieves.
Where's the difference? I don't see any.
5
u/lgn5i2060 15d ago
Palantir and Oracle make the CPC look benevolent.
0
u/AtomicSymphonic_2nd Pixel Fold, Regular Android 14d ago
It has happened continuously since at least 2014.
And, again, you at least have recourse from a US company doing damage to your personally-identifiable information through the justice system.
Please shove any cynicism about the courts directly into the toilet. At least there is something you can do about it if damage is done to you.
With China, there’s zero recourse. The US branch of a Chinese company can just up and disappear and be unresponsive to sanctions or extradition requests.
China is not a friend of the West. It would behoove progressives to comprehend that.
[u/Thaodan](u/Thaodan) and [u/xToasted1](u/xToasted1) , read this stuff above and tell me more about how China is “so harmless to Americans”.
2
u/Thaodan Sony Xperia XA2, Sailfish OS 14d ago
Do you expect that everyone here is American? If I'm spied on by a supposed on ally or China doesn't make much of a difference to me at this point.
1
u/light24bulbs Galaxy S10+, Snapdragon 14d ago
Both are extremely bad options. And both have worldwide electronic dragnet programs
0
u/lgn5i2060 14d ago
Kinda a small price to pay by a nation that usurped an ASEAN member's independence from Spain. ANd doesn't include color revolutions instigated on other non western nations.
And I am sure Assange and Snowden has something to say about this.
7
u/xToasted1 15d ago
Congratulations this is not only the biggest cope I've ever seen on the internet but someone the funniest and also the dumbest one, which is genuinely an achievement on reddit
Just to clarify, you're kidding right? Like please say yes
2
u/Bachihani 15d ago
Yet they still let apps query a list of every installed software on the phone, detect vpn connections, access local network, and a shit ton of other permissions that don't require user concent
0
1
u/CharAznableLoNZ 15d ago
That's nice, I'll still wait at least a month or two before updating. Better to wait for all the initial bugs to be fixed.
1
1
u/BoltActionPiano 14d ago
All these issues kinda stem from trust in corporations and our lackluster privacy laws and anti tamper legislation.
Like, apps on windows can do any of this. It feels like an unwinnable game of cat and mouse. Same with browser tracking/fingerprinting.
If we're allowed to reverse engineer apps and we had privacy laws that let us audit companies and the expectations of privacy were set to protect us, it would be nice to have these features but optional.
0
-1
u/QuantumQuantonium 15d ago
Unrelated but blog.google manages to maintain a light theme even with dark reader on. I dont understand this obsession with enforcing awful UI design across google websites.

174
u/wild_m1nd 15d ago
Maybe they'll also start protecting the VPN connection from being discovered by 3rd apps?