Android 17 enables Encrypted Client Hello by default, a first for major mobile OS
Android 17 enables Encrypted Client Hello by default, a first for a major mobile OS, and adds new privacy protections.
According to Engadget, Jigsaw, a technology incubator within Alphabet, said ECH closes a critical internet privacy gap. Even when a website uses secure HTTP, ISPs can still see the domain names of the sites and services a user visits, and that information can be used for targeted advertising by companies or for phishing campaigns by bad actors, Jigsaw explained. With ECH enabled, an ISP will only see a website's content delivery network, such as Cloudflare, and the volume of data moving, not the specific website or app. “Closing this privacy gap makes the internet safer for everyone,” Jigsaw said.
ECH does not provide complete privacy on its own. It will not conceal DNS lookups, the process of translating a web URL into an IP address, so users would still need to enable encrypted DNS to protect that step. The standard also does not hide a user's IP address the way a VPN does.
Google has paired ECH with other network security upgrades in Android 17. One is a zero-click solution that carriers can use to turn off 2G by default, preventing SMS blasters that typically rely on the legacy cellular network to bypass modern spam filters, according to Engadget.
Android Authority reports additional changes in Android 17. The company is limiting how apps can view a device's home local network, which prevents apps from probing it for fingerprinting or identifying vulnerable network hardware. Google has also implemented Certificate Transparency by default, helping ensure that the phone uses the correct SSL certificates for the server it is communicating with.