TECH FLOW Svět Androida
← Back to the stream
thehackernews.com · picked by Adam Kurfürst · 37d ago

Android 17 implements ECH to hide website visits from network providers

Source preview: Android 17 implements ECH to hide website visits from network providers
AI summary

Android 17 introduces comprehensive network security enhancements with support for Encrypted Client Hello (ECH), which conceals domain names from internet and network providers. The update also includes Local Network Protection, Certificate Transparency by default, and enables carriers to disable 2G networks automatically to prevent downgrade attacks.

The summary is written by AI from the source; it isn’t the newsroom’s opinion. For details, read the source.

4 people have already opened the source

AI questions & answers
How does Encrypted Client Hello work and why is it important?

ECH encrypts the destination domain name from the start of a connection using a secret key that only the destination website can decrypt. This prevents internet and network providers from seeing which websites users visit, effectively blocking behavioral profiling based on browsing metadata.

What is ECH GREASE and how does it function?

ECH GREASE sends fake, randomized ECH extensions to websites that do not support ECH, ensuring all connection requests appear identical and do not reveal which connections are ECH-protected. Android 17 enables it by default across the system.

What other security features does Android 17 introduce?

Android 17 adds Local Network Protection requiring app permissions before accessing local devices, enables Certificate Transparency by default for all websites, and provides carriers with a zero-click solution to disable 2G networks, eliminating downgrade attacks and rogue base station exposure.

Questions and answers are written by AI about the topic, not taken from the source; they aren’t the newsroom’s opinion.
Related from the stream
Mentions