BoletimSecSeptember 1, 2026🇵🇹Translated from Portuguese

Android 17 Adds Local Network Protection and Strengthens Wi-Fi Privacy Controls

Android 17 introduces new privacy protections designed to limit unauthorized tracking of users on Wi-Fi networks and restrict applications from accessing other devices connected to the same local network.

The key addition is Local Network Protection, which forces apps to request explicit user permission before they can scan for or connect to devices such as TVs, cameras, game consoles, printers and other equipment on the home Wi-Fi network. Previously, such scans could reveal the types of devices present in a household and help build detailed profiles of residents' habits and characteristics.

The restriction reduces this exposure while still allowing common legitimate functions, including casting video to a television.

The platform also adds default support for Encrypted Client Hello (ECH). This technology conceals the requested domain name during the initial phase of HTTPS connections, making it significantly harder for internet service providers, Wi-Fi operators or other third parties to identify which websites and services are being accessed.

Another change is the default activation of Certificate Transparency, a mechanism that requires public logging of digital certificates. The measure helps detect fraudulent or improperly issued certificates that could be used to intercept encrypted traffic.

Android 17 further expands protection against attacks that force smartphones to downgrade to insecure 2G networks. Attackers can deploy rogue base stations to downgrade 4G or 5G connections and deliver fraudulent messages directly to devices.

Related articles

HabrPrivacy & Surveillance

Review of GL.iNet Mudi 7 and Xray Configuration for Flexible Traffic Routing

The article provides a hands-on review of the GL.iNet Mudi 7 portable router combined with detailed instructions for deploying Xray. The author explains moving away from managing multiple separate VPN clients by installing Xray directly on the router. This setup allows all connected devices to route traffic intelligently without manual configuration on each endpoint. Local and Russian services connect directly to avoid latency, while international traffic is forwarded through a personal server. The guide covers practical scenarios for home use and emphasizes maintaining speed for permitted connections while ensuring selective proxying for the rest of the traffic.

AntiMalwarePrivacy & Surveillance

Taiwan Man Uses Robot Vacuum Camera to Prove Wife's Affair, Wins Compensation but Receives Prison Sentence for Illegal Recording

A resident of Taiwan suspected his wife of infidelity after discovering a stranger's toothbrush in their countryside home. He reviewed footage from a parking lot camera and later accessed the live feed of their robot vacuum cleaner through its mobile application, capturing intimate recordings without consent. The man preserved the video evidence and successfully sued for breach of marital rights, receiving approximately $19,000 in compensation. His wife filed a counterclaim, arguing that the recordings violated her right to privacy because the device's sensors and indicators did not clearly indicate active surveillance. Although the footage was accepted in the civil case, the court ruled that the illegal method of obtaining it outweighed marital obligations, prioritizing personal privacy protections. The husband was sentenced to five months in prison and fined 150,000 Taiwanese dollars, representing 30 percent of his awarded compensation.

AntiMalwarePrivacy & Surveillance

Russian Firms Accumulate Digital Clutter: 35% of Corporate Files Unused for Years, Weak Passwords Expose Sensitive Data

A study by Russian cybersecurity firm Garda examined more than 157 terabytes of data and over 511,000 user accounts across more than 100 companies. Researchers found that approximately 35% of files in corporate repositories had not been accessed for more than five years, while duplicate data could occupy another 35% of storage volume. In several industries, up to one-third of stored content consisted of personal photographs, videos, and archives unrelated to business operations. More than 33% of accounts used critically weak passwords or credentials that had not been changed for extended periods, and numerous contractor and temporary employee accounts remained active despite being unused for over 90 days. Direct access permissions bypassing security groups were widespread, allowing broad access to folders containing passport scans, client registries, and database exports. Garda recommends automated inventory, classification, centralized access management, and lifecycle automation to reduce risks instead of manual cleanup.

HabrPrivacy & Surveillance

Apple Updates Private Relay Domain for Sign in with Apple: Why Email Cannot Serve as Account Identity

Apple announced that new Private Relay addresses for Sign in with Apple will use the private.icloud.com domain starting later in 2026, while existing privaterelay.appleid.com addresses will continue functioning without interruption. The change highlights a deeper architectural issue: many applications incorrectly treat email addresses returned by Apple as stable identifiers rather than transient contact channels. Proper implementation requires separating the signed identity token, the verified subject claim, and the optional email relay address into distinct data models. Developers must validate the full identity token on the server, including signature, issuer, audience, nonce, and expiration, before linking any Apple identity to an internal account. Using provider and subject pairs as the unique key prevents duplicate accounts, accidental merges, and broken logins when relay domains or email claims change. The article provides concrete recommendations for data models, token verification boundaries, and test cases that remain resilient to future Apple updates.