Privacy and Technology Policies

Android 17 Adds ECH Support to Reduce Networks’ Ability to Track Browsing

Google is adding built-in support for the Encrypted Client Hello standard in Android 17 to hide domain names when HTTPS connections begin, alongside new restrictions on local network access, default activation of Certificate Transparency, and an option to disable 2G networks.

2026-08-27
3 min read
14 views
فريق تحرير certi.news
Android 17 Adds ECH Support to Reduce Networks’ Ability to Track Browsing

In Android 17, Google is expanding network-connection protection by adding built-in support for Encrypted Client Hello (ECH), which aims to hide the domain name the user is connecting to from internet service providers, Wi‑Fi network operators, and other parties monitoring network traffic. The move comes alongside other changes covering local-network protection, website certificates, and older cellular connections.

Hiding the Domain Name at the Start of the Connection

ECH works as a privacy extension for the TLS protocol used to secure HTTPS connections. Although the connection’s content is encrypted, the requested server’s name typically appeared in the initial part of the TLS handshake through the Server Name Indication (SNI) field. This allowed an internet provider or Wi‑Fi network operator to know which destination the user was trying to reach, even without being able to read the page’s content.

ECH works together with Private DNS to hide domain names and metadata that could be used to create commercial profiles of users. Android users benefited from ECH when browsing with Chrome 117 or later, or Firefox 119 or later, but Android 17 moves support to the platform level.

Protection Is Not Comprehensive for Every Connection

ECH will be enabled by default for apps targeting Android 17, provided they use a compatible networking library, such as recent versions of OkHttp, WebView, or HttpEngine. On servers that support ECH, the system will encrypt the host name. For servers that do not support it, Android will send a field that appears to be related to ECH, known as ECH GREASE, so that protected connections are not easily distinguishable; however, the host name will remain exposed in this case.

Google’s Jigsaw unit, which focuses on internet privacy and combating censorship, tested ECH GREASE across the 10,000 largest domains and through 740 internet providers in 202 countries. According to the test, no problems with website loading or unexpected blocking were recorded.

Three Additional Changes to Network Protection

  • Modifications to Local Network Protection require apps to obtain permission before scanning or connecting to the user’s local network devices.
  • Certificate Transparency will be enabled by default, so website certificates will appear in public logs, making fraudulent certificates easier to detect.
  • Participating telecommunications operators will have an option to automatically disable 2G networks for subscribers, with the aim of reducing exposure to SMS blasters and fake base stations that may send malicious messages or capture nearby sensitive traffic.

Why Does This Matter?

The most important change is that domain-name protection is no longer tied solely to the browser but has become part of the platform’s behavior, which could benefit apps that use supported networking libraries. However, ECH’s impact will remain dependent on support from the corresponding servers, apps, and network infrastructure; when a server does not support the standard, the host name remains visible. The announced tests also demonstrate that no loading or blocking problems appeared within their scope, but they do not eliminate these operational limitations. Local-network protection, certificate transparency, and 2G disabling target different attack paths and do not depend on ECH alone.

News source
BleepingComputer
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news