ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers

infoAdvisoryimportance 35
AI summary · glm-5.3-flash

Google announced Android 17 will enforce OS-wide Encrypted Client Hello with ECH GREASE, plus Certificate Transparency by default and carrier 2G disablement.

Google announced Android 17 network security protections headlined by OS-wide support for Encrypted Client Hello (ECH), with ECH GREASE enabled by default so connections to non-ECH servers look identical. Google's Jigsaw noted OkHttp has integrated ECH, letting third-party Android apps adopt the standard. The release also enforces Local Network Protection permission prompts, enables Certificate Transparency by default, and lets carriers turn off 2G by default to prevent downgrade attacks, rogue base stations, and SMS blasters. ECH was previously added to Chrome 117 and Firefox 118 at the browser level only.

  • ECH hides destination website names from network providers, with ECH GREASE on by default to avoid traffic differentiation.
  • OkHttp integrated ECH, letting third-party Android apps use encrypted client hello.
  • Local Network Protection requires app permission to scan or connect to local network devices.
  • Certificate Transparency is on by default; carriers can disable 2G to stop downgrade and SMS blaster attacks.
Full article486 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananAug 28, 2026Cellular Security / Encryption

Google on Thursday announced new network security protections in Android 17 to bolster connection privacy, address cellular vulnerabilities, and safeguard the privacy of users' home networks.

Topping the list is support for Encrypted Client Hello (ECH), a privacy standard that prevents networks from eavesdropping on which websites a user is visiting.

"This new privacy standard works in tandem with private DNS to obscure the domain names you visit, hiding metadata that can be used to profile you," Google's Bram Bonné and Shuaibo Huang said. "By encrypting the destination website name from the very start, ECH helps ensure that, for supported websites and apps, network providers and network snoopers can no longer easily see which websites or apps you are accessing."

In a parallel report detailing the integration, Google's Jigsaw division said ECH hides the domain name using a secret encryption key that only the destination website can decipher.

"Critically, though, not all web servers will offer ECH support," Jigsaw said. "To avoid exposing only certain connections as ECH-protected, apps and browsers should use ECH GREASE — which sends fake, randomized ECH extensions to sites that don't support ECH — so that every connection request looks the same."

With Android 17, ECH GREASE will be enabled by default. It's worth noting that ECH was integrated into Google Chrome and Mozilla Firefox with versions 117 and 118, respectively. However, with the latest update, the protection expands to the entire operating system.

Jigsaw also said OkHttp, an open-source HTTP and HTTP/2 client, has integrated ECH support into its core library, allowing third-party Android app developers to leverage the new capability.

In addition to support for ECH on Android, Google has enforced Local Network Protection, requiring apps to ask for users' permission before they can scan or connect to other devices on their local network.

Two other privacy- and security-oriented features include enabling Certificate Transparency (CT) by default, which mandates that all websites be logged in a public registry, and allowing telecom operators to turn off 2G by default for their subscribers to prevent downgrade attacks and mitigate exposure to rogue base stations or SMS blasters that can send malicious text messages or capture traffic from nearby devices.

Android 12 already includes a manual option that allows users to disable 2G at the hardware level. With Android 14, Google added a security feature that allowed IT administrators to turn off support for 2G cellular networks in their managed devices. The latest offering, on the other hand, is a zero-click solution.

"For participating carriers, this helps eliminate the legacy attack surface out of the box, proactively mitigating a primary method used by SMS blasters before they can target your device," Google said.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/08/android-17-adds-os-wide-ech-to-hide.html