Update MASTG-KNOW-0049 and MASTG-BEST-0002 for Android logging
Author: dchapagainCreated Sep 12, 2026Updated Sep 13, 2026
Following discussion #3948 and issue #3949, this issue tracks the documentation scope confirmed in this comment.
Scope
MASTG-KNOW-0049
- Expand the Android logging article to a similar level of coverage as MASTG-KNOW-0101.
- Cover Android logging APIs and mechanisms, including NDK logging,
logcatbehavior, log levels and tags, and the access model. - Document what Android's logging APIs do and don't provide for privacy, contrasted with Apple's Unified Logging privacy model.
- Cover
Slog,EventLog, third-party logging facades, and other relevant logging paths. - Remove threat and remediation language so the KNOW content is descriptive.
MASTG-BEST-0002
- Align the guidance with Android's Log Info Disclosure documentation.
- Add R8 coverage alongside the existing ProGuard guidance, which currently does not cover R8.
- Add log-level management,
toString()sanitization, redaction and masking, compile-time constants, and incident-response guidance. - Retain the existing
StringBuildercaveat.
The MASTG-DEMO-0006 update remains tracked separately in #3949.
Open Question
MASTG-BEST-0002 is currently titled "Remove Logging Code" with alias: remove-logging-code. Since the expanded guidance also covers redaction, masking, and log-level management, should the title and alias remain unchanged, or should they be updated as part of this work?
A draft PR for the KNOW and BEST documentation updates will follow shortly.
Please assign this issue to @dchapagain.
Source: OWASP/mastg