Google on Thursday announced new network security protections in Android 17 to bolster connection privacy, address cellular vulnerabilities, and safeguard the privacy of users' home networks.
Topping the list is support for Encrypted Client Hello (ECH), a privacy standard that prevents networks from eavesdropping on which websites a user is visiting.
"This new privacy standard works in tandem with private DNS to obscure the domain names you visit, hiding metadata that can be used to profile you," Google's Bram Bonné and Shuaibo Huang said. "By encrypting the destination website name from the very start, ECH helps ensure that, for supported websites and apps, network providers and network snoopers can no longer easily see which websites or apps you are accessing."
In a parallel report detailing the integration, Google's Jigsaw division said ECH hides the domain name using a secret encryption key that only the destination website can decipher.
"Critically, though, not all web servers will offer ECH support," Jigsaw said. "To avoid exposing only certain connections as ECH-protected, apps and browsers should use ECH GREASE — which sends fake, randomized ECH extensions to sites that don't support ECH — so that every connection request looks the same."
With Android 17, ECH GREASE will be enabled by default. It's worth noting that ECH was integrated into Google Chrome and Mozilla Firefox with versions 117 and 118, respectively. However, with the latest update, the protection expands to the entire operating system.
Jigsaw also said OkHttp, an open-source HTTP and HTTP/2 client, has integrated ECH support into its core library, allowing third-party Android app developers to leverage the new capability.
In addition to support for ECH on Android, Google has enforced Local Network Protection, requiring apps to ask for users' permission before they can scan or connect to other devices on their local network.
Two other privacy- and security-oriented features include enabling Certificate Transparency (CT) by default, which mandates that all websites be logged in a public registry, and allowing telecom operators to turn off 2G by default for their subscribers to prevent downgrade attacks and mitigate exposure to rogue base stations or SMS blasters that can send malicious text messages or capture traffic from nearby devices.
Android 12 already includes a manual option that allows users to disable 2G at the hardware level. With Android 14, Google added a security feature that allowed IT administrators to turn off support for 2G cellular networks in their managed devices. The latest offering, on the other hand, is a zero-click solution.
"For participating carriers, this helps eliminate the legacy attack surface out of the box, proactively mitigating a primary method used by SMS blasters before they can target your device," Google said.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.


