It took me a while to figure out why many of my self-hosted services were intermittently failing to connect on my phone after updating to Android 17. I eventually figured out there's a new ACCESS_LOCAL_NETWORK permission which means the "Nearby devices" permission is now required to access devices on the same network subnet. For an avid self-hoster, this can be quite a bit.

I had my DNS configured so my public-facing server resolved to a local IP address when on my LAN. This meant that my web, immich, xmpp, NTP, jellyfin and DoH servers all resolved to a local IP address on wifi. On Android 17, it all broke without warning. No error messages. No asking for extra permissions. Just silent packet dropping.

I've solved it by configuring my public-facing services to resolve to my external (static) IP address, even when inside the network. I couldn't make any internal services resolve to the external address (SMB, CUPS etc) because they are (obviously) not bound to my WAN interface.

I get why the change was made. A lot of apps were snooping around people's networks to gather intel. A potentially massive privacy violation.

Has anyone else had this issue? Is this the cleanest solution?

top 50 comments

sorted by: hot top controversial new old
[–] 69 points 1 week ago (3 children)

Luckily grapheneos allows a hybrid approach so allows just the lan subnet permission without the wider nearby devices permission.

  • source
  • hideshow 3 child comments
  • [–] 17 points 1 week ago

    Hey can you let me know where I can find more info on this? I am running GrapheneOS as I was having this exact same issue as OP a few day back.

    On my browsers I have network access, but nearby devices was disabled.

    I checked my private dns settings and granted nearby devices access to my browsers, which allowed me to hit my local self-hosted services.

    Just wondering if there is a better way to achieve the same.

  • source
  • parent
  • [–] 52 points 1 week ago (15 children)

    Haven't been brought to 17 yet thankfully.

    My long term solution is to not use android. My short term solution will likely be to use android even less, and be even more pissed at Google.

  • source
  • hideshow 15 child comments
  • [–] 16 points 1 week ago (7 children)

    Solution is to just enable the permission on apps that need it.

  • source
  • parent
  • hideshow 7 child comments
  • [–] 25 points 1 week ago (5 children)

    The solution is to avoid google going forward, for many reasons.

  • source
  • parent
  • hideshow 5 child comments
  • load more comments (1 reply)
  • [–] 11 points 1 week ago (4 children)
  • [–] 9 points 1 week ago (3 children)
  • [–] 8 points 1 week ago (1 child)

    How is this added permission not a good thing? Surely adding a local network only permission is a positive, you can allow apps internet permission and decline them access to your local services.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 13 points 1 week ago

    The permission structure sucks.

    Its a silent drop (no errors are returned), webview breaks connected to WiFi even without a local resource being requested, it lives inside nearby_devices so giving permission there includes this (and gives a broader spectrum of access such as Bluetooth and WiFi).

    Its just shuffling the problem around.

    Also, fuck Google.

  • source
  • parent
  • [–] 24 points 1 week ago* (4 children)

    Why are permissions so damn confusing? I say this as someone who knows why permissions are needed, such as location to find nearby devices. But why must we keep track of "permission X is for thing unrelated to X" in our heads? Now I haven't tried to make a permissions system for the masses, so I guess I can't say too much, but it doesn't seem that difficult to just make the permission name relate to what it does and provide a short synopsis for it.

  • source
  • hideshow 4 child comments
  • [–] 1 point 6 days ago* (last edited 6 days ago)

    Google tries to make permissions easy to understand for end users, instead of making them detailed for tech people. The permissions "nearby devices" covers any method for reaching out to nearby devices. Previously, you had the permission "location", which contained some ways of local access.

    An app requiring nearby devices to connect to a bluethooth or other nearby device is more clear than an application requesting your location.

    Devices in the LAN are also considered devices near you. For dumb end users, silently blocking it is more secure than showing a dialog, as people are dialog fatigued today.

  • source
  • parent
  • load more comments (1 reply)
    [–] 21 points 1 week ago* (last edited 1 week ago) (3 children)

    Why not just grant the permission to the apps?

    Relatedly, I think this is why Google Home and casting to Chromecast have stopped working reliably on my phone. Anyone figure those out? I've already tried granting permissions. Or it may be something GrapheneOS is doing.

  • source
  • hideshow 3 child comments
  • [–] 3 points 1 week ago

    I'm in the same boat as well, for some reason my music apps can't seem to see my Google smart speakers, but strangely they can see my Nvidia shield and cast to that.

    Looked through my app permissions I honestly can't see anything out of the ordinary or plainly obvious. Both my speakers and android TV (shield) are on separate segment VLAN.

    As for granting the permission, I generally like to grant on a app by app basis, lots of apps ask for internet access as a example but don't actually require it to function. All my game apps for example are completely offline.

  • source
  • parent
  • load more comments (2 replies)
    [–] 15 points 1 week ago* (1 child)

    Ran into this issue a few days ago, exactly the same way you described.

    I am on GrapheneOS and figured it was something to do with a a setting where it's blocking network access for my specific browser app. After reading your post I see it's a android 17 feature.

    Checked all the settings in my browsers related to DNS at first and was stumped for a bit, until I flipped on the nearby device setting and everything worked.

    I also looked into the DNS settings under Network & Internet > Private DNS. Make sure your phone is using your local networks DNS server. Just make sure to understand the implications of changing this (especially when you disconnect from you're home networks DNS). Also making sure your home DNS is not defaulting to your ISP DNS.

    Two websites that help me sanity check myself

    • Dnscheck.tools
    • dnsleaktest.com
  • source
  • hideshow 1 child comment
  • [–] [S] 3 points 1 week ago

    I self-host a DoH/DoT server and my local DHCP advertises it to local clients. It's kinda cool because android phones on my wifi will use DoT when private DNS is set to "automatic".

    Private DNS sort-of broke while I was tinkering with internal/external IP addresses for nearby devices. It wouldn't always connect when I specified my external IP (despite being available externally). I made it IPv6-only too. It wouldn't be the first time something couldn't handle it.

  • source
  • parent
  • [–] 11 points 1 week ago*

    I gave permission to Firefox, but honestly most of my services weren't affected because I connect to 99% of them via Tailscale which doesn't seem to trigger the permission. (Yes that was an absolute nightmare to figure out why only one service was failing to connect)

  • source
  • [–] 8 points 1 week ago

    confused me when I suddenly had to give Firefox this permission to access websites on my LAN

    More ways to control what can access what is a welcome change for me

    (I'm on GrapheneOS but yeah, Android 17 based now)

  • source
  • [–] 7 points 1 week ago

    Thanks for the heads up. This would have been a nasty surprise followed by unknown duration of hair pulling.

  • source
  • [–] 7 points 1 week ago

    Oooh. I haven't updated it yet. Good to know as I will likely run into the same issue.

  • source
  • [–] 7 points 1 week ago (1 child)

    My phone is still on 14 so uuuhhh I'm fine I guess?

  • source
  • hideshow 1 child comment
  • load more comments (1 reply)
    [–] 7 points 1 week ago (1 child)

    I had this issue in firefox. And only firefox. Was pulling my hair for hours. Wish I had been warned.

    Anyway I just gave firefox the permission and the issue was resolved. Native apps seem unaffected. Which makes me think maybe this is an opt in setting right now?

  • source
  • hideshow 1 child comment
  • [–] [S] 3 points 1 week ago*

    I think Firefox also gave me the first clue that something was up.

    Native apps all have a backwards-compatible setting so it's allowed by default. That will surely get dropped when Google bumps the minimum Android target API so newly published apps need to explicitly configure it.

    I actually went through my apps list and disabled nearby devices for all the apps that don't need it. It's a good security measure. I just don't like how it was rolled out.

  • source
  • parent
  • [–] 6 points 1 week ago

    Took me about an hour of reconfiguring everything in my network and still not having my phone load the damn page to finally try it on my desktop and it worked flawlessly, rebooted my phone and it finally gave me the pop up in the picture. So stupid.

  • source
  • [–] 6 points 1 week ago

    Haven't noticed it yet because my services are on a different network than my clients

  • source
  • [–] 4 points 1 week ago (1 child)

    My solution is LineageOS as it functions on dozens if not a couple hundred phones. Rocking a One+ currently.

  • source
  • hideshow 1 child comment
  • load more comments (1 reply)
    [–] [B] 4 points 1 week ago* (last edited 6 days ago)

    Acronyms, initialisms, abbreviations, contractions, and other phrases which expand to something larger, that I've seen in this thread:

    Fewer Letters More Letters
    DHCP Dynamic Host Configuration Protocol, automates assignment of IPs when connecting to a network
    DNS Domain Name Service/System
    ISP Internet Service Provider
    NAT Network Address Translation
    PiHole Network-wide ad-blocker (DNS sinkhole)
    XMPP Extensible Messaging and Presence Protocol ('Jabber') for open instant messaging

    [Thread #115 for this comm, first seen 27th Sep 2026, 20:10] [FAQ] [Full list] [Contact] [Source code]

  • source
  • [–] 3 points 1 week ago

    It works but I wouldn't call it the cleanest solution, more a workaround. As far as I know only apps targeting SDK 37 are affected, older apps still get the permission implicitly. So the proper way would be to just grant "Nearby devices" to the apps that need it e.g. Immich or Jellyfin and if an app doesn't ask for it that's actually a bug and worth reporting, because it should request the permission as soon as the server resolves to a local IP. I also find the "Nearby Devices" title a bit misleading for apps that only need it to reach your own server, but on the other side it gives a somehow proper hint what the permission actually allows.

  • source
  • [–] 3 points 1 week ago (18 children)

    I had my DNS configured so my public-facing server resolved to a local IP address when on my LAN. This meant that my web, immich, xmpp, NTP, jellyfin and DoH servers all resolved to a local IP address on wifi.

    I unfortunately don't have an answer to your question since I'm not on Android 17, but I do want to ask about this part. What's the benefit of this? Does it improve speed when streaming on Jellyfin?

  • source
  • hideshow 18 child comments
  • [–] 8 points 1 week ago (16 children)

    Not OP but I do the same for two reasons.

    A) it eleimitaes my ISP traffic. It doesn't have to go out to my router, to come back in on the public IP. They can't track what never hits them.

    B) I also have completely internal services. So the DNS entries are internal only. Can't map my internal network publicly.

  • source
  • parent
  • hideshow 16 child comments
  • [–] [S] 3 points 1 week ago

    I've also got a completely different DNS config for WAN and LAN traffic. WAN devices can only resolve PTR records for my mail server. My LAN devices have DDNS so internally they a get allocated DNS entries by hostname. Even my guest network has a different config for isolation.

    They definitely all need to be kept separate.

  • source
  • parent
  • load more comments (15 replies)
  • load more comments (1 reply)
    [–] 3 points 1 week ago (2 children)

    Do you have any network segmentation is all your stuff on the same lan?

    You also could try IPv6 public or private addresses

  • source
  • hideshow 2 child comments
  • load more comments (2 replies)
    [–] 3 points 1 week ago

    this is how they know who is even looking at stuff on their own network. holy shit

  • source
  • load more comments
    view more: next ›