Android 17 enables certificate transparency, and breaks custom CAs

· Tim Perry · Sept. 23, 2026, 8:11 a.m.
Summary
The blog post discusses the implications of Android 17's default certificate transparency requirement for system-trusted certificates, detailing how this change complicates the interception of encrypted traffic, particularly for security and privacy research. It explains the evolution of certificate authority (CA) configuration in Android, the challenges it poses to developers and researchers, and presents a workaround using custom CT logs for those affected by the changes. The author argues for greater user control over certificate configuration and reviews the importance of these developments in the context of mobile app security and privacy.
AUTHOR
BLOG POST FEATURED ON

Add this plugin to your blog