Android 17 adds platform support for Encrypted Client Hello, which encrypts the domain name sent when a connection opens so the network can’t read the destination.
Google describes the release as the first broad Encrypted Client Hello rollout on a major mobile OS, built with its Jigsaw team and outside developers.
The protection covers only sites and apps that have switched Encrypted Client Hello on; a destination that hasn’t still exposes its domain to carriers, Wi-Fi operators, and network snoops.
If you’re an Android user, your internet browsing just got a little more private.
Google’s mobile operating system Android 17 now turns on Encrypted Client Hello, a privacy standard that hides a web request’s destination from the network carrying it. Google laid out the rollout in a security post published Wednesday.
Myriad: How low will Amazon stock go? Click to make your prediction.
A page loads over HTTPS, so its contents are scrambled. The handshake that opens the connection still names the site in cleartext through a field called the Server Name Indication. Every node between a phone and a server can read that field and log where a device goes.
Encrypted Client Hello, or ECH for short, seals the field. The client encrypts the site name to a key the destination publishes, and only that server can unwrap it. The rest of the path sees a meaningless label, not the domain. It runs on top of private DNS, which already hides the separate step that turns a name into an IP address.
ECH protects traffic only to destinations that have adopted it. Google’s post limits the claim to “supported websites and apps,” and the company is pushing developers to upgrade to OkHttp 5.5.0 and enable the feature. Until adoption spreads, a request to a site without ECH still shows its domain to the network.
The network still sees the destination server’s IP address and the volume of data moving. An observer can infer activity at a coarse level even when the name is hidden. The encryption is a lock on the label, not on the fact that a connection happened.
Google’s network-level move lands as Android’s device-level privacy meets its own test in court.
Samuel Tunick, an Atlanta activist, became the first known American charged under federal law for allegedly using a duress password built into GrapheneOS, a hardened Android build that wipes the device when the code is entered. GrapheneOS said its software is “completely legal” and constitutionally protected as the case proceeds. A related prosecution has framed the dispute as a question of who controls the data on a phone.
“I just hope to send the message that the government doesn’t own our data,” Samuel Tunick told the New York Times in an interview published Friday.
Android 17 also turns on Certificate Transparency by default and requires apps to ask permission before scanning a local network.
Daily Debrief Newsletter
Start every day with the top news stories right now, plus original features, a podcast, videos and more.
The FSNN News Room is the voice of our in-house journalists, editors, and researchers. We deliver timely, unbiased reporting at the crossroads of finance, cryptocurrency, and global politics, providing clear, fact-driven analysis free from agendas.
We and our selected partners wish to use cookies to collect information about you for functional purposes and statistical marketing. You may not give us your consent for certain purposes by selecting an option and you can withdraw your consent at any time via the cookie icon.
Cookies are small text that can be used by websites to make the user experience more efficient. The law states that we may store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies, we need your permission. This site uses various types of cookies. Some cookies are placed by third party services that appear on our pages.
Your permission applies to the following domains:
https://fsnn.net
Necessary
Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
Statistic
Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
Preferences
Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
Marketing
Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.