Android 17 implements ECH to hide website visits from network providers
Android 17 introduces comprehensive network security enhancements with support for Encrypted Client Hello (ECH), which conceals domain names from internet and network providers. The update also includes Local Network Protection, Certificate Transparency by default, and enables carriers to disable 2G networks automatically to prevent downgrade attacks.
How does Encrypted Client Hello work and why is it important?
ECH encrypts the destination domain name from the start of a connection using a secret key that only the destination website can decrypt. This prevents internet and network providers from seeing which websites users visit, effectively blocking behavioral profiling based on browsing metadata.
What is ECH GREASE and how does it function?
ECH GREASE sends fake, randomized ECH extensions to websites that do not support ECH, ensuring all connection requests appear identical and do not reveal which connections are ECH-protected. Android 17 enables it by default across the system.
What other security features does Android 17 introduce?
Android 17 adds Local Network Protection requiring app permissions before accessing local devices, enables Certificate Transparency by default for all websites, and provides carriers with a zero-click solution to disable 2G networks, eliminating downgrade attacks and rogue base station exposure.
- New malware can extract passkeys from Google Password Manager — bleepingcomputer.com 81 % match
- WindRelay Android malware for NFC payment fraud expanding to Czech Republic — thehackernews.com 78 % match
- Google Play Services 26.28.xx blocked NFC payments on Chinese phones—issue has been fixed — reddit.com 75 % match
- Android 173
- Google37
- Encrypted Client Hello
- Google Chrome
- Mozilla Firefox
- OkHttp
- Jigsaw
- Cloudflare5