Google has announced that Android 17 will introduce a new layer of network security designed to make it harder for internet service providers and Wi-Fi operators to track users' browsing activity. The update adds support for Encrypted Client Hello, or ECH, a privacy standard that works alongside private DNS to hide the domain names users visit. This protection is aimed at preventing network providers from collecting metadata for commercial profiling, even when a connection to a website is secured with HTTPS.
ECH functions as a privacy extension for TLS, the protocol that secures HTTPS connections. Normally, the opening part of the TLS handshake reveals the contacted hostname through the Server Name Indication field. By encrypting that initial exchange, ECH obscures the destination website name from the very start, so network snoopers cannot easily see which websites or apps a user is accessing. Google states that users already benefit from this when browsing with Chrome 117 or later, or Firefox 119 or later, but Android 17 brings the protection to the platform level for all compatible apps.
For apps targeting Android 17, ECH will be enabled by default, provided they use a compatible networking library such as the latest versions of OkHttp, WebView, or HttpEngine. On servers that support ECH, Android will encrypt the hostname. On servers that do not support the protection, Android will send a fake ECH-looking field, called ECH GREASE, so that real ECH connections do not stand out, though the hostname remains visible in those cases. Google's internet privacy and anti-censorship unit, Jigsaw, tested ECH GREASE against the top 10,000 domains and across 740 internet providers in 202 countries, finding no site-loading issues or unexpected network blocks.
In addition to ECH, Google announced other network protections in Android 17 that improve user security and privacy when used together. The first involves adjustments to Local Network Protection, which now require apps to obtain permission before scanning for or connecting to devices on the user's local network. This change is intended to give users more control over which apps can access devices in their home networks. The second change enables Certificate Transparency by default, which requires website certificates to appear in public logs, making the use of forged certificates more evident.
These updates come as part of a broader push by Google to address cellular vulnerabilities and protect the privacy of home networks. The company's announcement highlights that ECH operates in conjunction with private DNS to obscure the domain names users visit, hiding metadata that could be used to profile them. For US users, where ISPs commonly track browsing destinations for advertising purposes, this platform-level support could offer a meaningful privacy upgrade across a wide range of Android apps and browsing sessions.
Google notes that the new protections work for supported websites and apps, but the effectiveness depends on server-side support for ECH. The company has not detailed when the update will roll out to all Android devices, but the announcement positions Android 17 as a significant step in hardening network privacy against commercial tracking and other forms of surveillance. The combination of ECH, local network permissions, and Certificate Transparency reflects a layered approach to security at the operating system level.
More cybersecurity news from TechManNews.







