Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers
Android 17 update includes Encrypted Client Hello (ECH) to hide domain names and website visits from network providers and ISPs. The update also adds security controls to block fake base stations and rogue 2G cell sites used in SMS blaster phishing campaigns. Additionally, carriers can disable 2G entirely and measures restrict unauthorized discovery on home Wi-Fi networks. These changes aim to strengthen user privacy and security.
Listen to Live Briefing
Real-time synthesized voice briefing · Live Feeds Desk
- ✓ Android 17 adds broad support for Encrypted Client Hello (ECH) to hide domain names and website visits from network providers and ISPs.
- ✓ Android 17 includes security controls to block fake base stations and rogue 2G cell sites used in SMS blaster phishing campaigns.
- ✓ Carriers can disable 2G entirely with the Android 17 update.
- ✓ Android 17 introduces measures to restrict unauthorized discovery on home Wi-Fi networks.
What changed
The latest development is the addition of OS-wide Encrypted Client Hello (ECH) support in Android 17, enhancing user privacy by hiding website visits from network providers.
Live updates
-
Android 17 adds OS-wide ECH to hide website visits from network providers
Android 17 update includes Encrypted Client Hello (ECH) to hide domain names and website visits from network providers and ISPs. The update also adds security controls to block fake base stations and rogue 2G cell sites used in SMS blaster phishing campaigns. Additionally, carriers can disable 2G entirely and measures restrict unauthorized discovery on home Wi-Fi networks. These changes aim to strengthen user privacy and security.
Why it matters
The deployment of ECH in Android 17 addresses a significant privacy gap that existed despite the use of HTTPS and encrypted apps. This update is crucial for protecting users from network snooping and enhancing their overall online security. The changes come as part of Google's efforts to bolster Android's security features.
What is confirmed
- Android 17 adds broad support for Encrypted Client Hello (ECH) to hide domain names and website visits from network providers and ISPs.
- Android 17 includes security controls to block fake base stations and rogue 2G cell sites used in SMS blaster phishing campaigns.
- Carriers can disable 2G entirely with the Android 17 update.
- Android 17 introduces measures to restrict unauthorized discovery on home Wi-Fi networks.
- Encrypted Client Hello (ECH) is a new internet standard designed to close a privacy gap that allowed ISPs to see the names of every website visited.
Still unconfirmed
- Your real IP address is still exposed, and for that, you still need a VPN.
What to watch next
- Further updates on the rollout and adoption of Android 17
- Analysis of the effectiveness of ECH in enhancing user privacy
- Development of complementary security features in future Android updates
confidence 85%Sources used for this update (4)
- www.zdnet.com — How Android 17 stops network snoops and SMS blasters now - with ECH and a 2G kill switch
- cybersecuritynews.com — Android 17 Adds New Protection for Wi-Fi Tracking to Keep Your Device Secure
- arstechnica.com — New Android Drop adds remembered items in Find Hub, makes anti-nausea dots official
- gizmodo.com — Google is finally hiding your browsing history from your ISP, but you still need a VPN
-
Android 17 Introduces OS-Wide Encrypted Client Hello and Network Security Updates
Google is deploying Encrypted Client Hello (ECH) in Android 17 to hide domain names and website visits from network providers and ISPs. This update addresses privacy gaps that persist despite the use of HTTPS and encrypted apps. Beyond ECH, Android 17 includes security controls to block fake base stations and rogue 2G cell sites used in SMS blaster phishing campaigns. The update also enables carriers to disable 2G entirely and introduces measures to restrict unauthorized discovery on home Wi-Fi networks while strengthening certificate validation.
Why it matters
Network providers can traditionally see the domain names users visit even during encrypted sessions. These updates target legacy vulnerabilities in 2G infrastructure and DNS visibility that bypass modern 5G security.
What is confirmed
- Android 17 supports Encrypted Client Hello (ECH) to hide website visits from network providers.
- Google is adding security features to Android 17 to block fake base stations.
- Android 17 allows carriers to disable 2G connectivity.
- New network security controls aim to blunt phishing campaigns delivered through rogue 2G cell sites.
What to watch next
- Confirmation of the specific rollout date for Android 17
- Data on the percentage of carriers disabling 2G via the new controls
confidence 100%Sources used for this update (7)
- The Hacker News — Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers
- blog.google — 4 new ways Android is protecting your network connections
- Engadget — Google Deploys Support For Encrypted Client Hello On Android 17
- 9to5Google — Android 17 boosts network security by hiding domain names, lets carriers disable 2G
- finance.biggo.com — Google Adds Fake Base Station Blocking Security Features to Android 17
- MakeUseOf — A new browser feature hides which website you're visiting from your ISP, and it has nothing to do with a VPN
- cyberpress.org — Android 17 Adds New Network Security Protections to Block 2G SMS Blaster Attacks
Community Sentiment: How do you assess this situation?
Voice your perspective · Real-time aggregated sentiment from the Live Feeds community