{"id":2598,"date":"2026-08-28T20:16:50","date_gmt":"2026-08-28T20:16:50","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2598"},"modified":"2026-08-28T20:16:50","modified_gmt":"2026-08-28T20:16:50","slug":"android-17-adds-os-wide-ech-to-hide-website-visits-from-network-providers","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2598","title":{"rendered":"Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Aug 28, 2026<\/span><\/span><span class=\"p-tags\">Cellular Security \/ Encryption<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiHdeGqGafTZXNtGvV_-qR7K3QId_-DpEfOzetKbhVQvNdNyTMAy-6gLXVFlkMHsGDN2wKK8v1ZMeOKe9_3XVYAY5TVkqH2heesi0c_QmJzLpDX1M-XfOtI_W4Qe8OM8Yhin40QWvN0XHvU9cqDlZH3eeZY_18euIxiBdcbhWMVnXct-x84k2gvchQYSiuN\/s1700-e365\/1000103901.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Google on Thursday announced new network security protections in Android 17 to bolster connection privacy, address cellular vulnerabilities, and safeguard the privacy of users&#8217; home networks.<\/p>\n<p>Topping the list is <a href=\"https:\/\/developer.android.com\/about\/versions\/17\/features#ech-platform-support\" target=\"_blank\">support<\/a> for Encrypted Client Hello (<a href=\"https:\/\/blog.cloudflare.com\/announcing-encrypted-client-hello\/\" target=\"_blank\">ECH<\/a>), a privacy standard that prevents networks from eavesdropping on which websites a user is visiting.<\/p>\n<p>\u00abThis new privacy standard works in tandem with private DNS to obscure the domain names you visit, hiding metadata that can be used to profile you,\u00bb Google&#8217;s Bram Bonn\u00e9 and Shuaibo Huang <a href=\"https:\/\/blog.google\/security\/new-Android-network-security-protections\/\" target=\"_blank\">said<\/a>. \u00abBy encrypting the destination website name from the very start, ECH helps ensure that, for supported websites and apps, network providers and network snoopers can no longer easily see which websites or apps you are accessing.\u00bb<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/zero-trust-claude-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj8iAp2j8rqTq6aptj6yiYHC-B73UxnWI2NQMt0azp6OVLq9JkO8cpYokLWa8t_IKqrHKPsaM5D_lQ9Ip7kZTi3at4oYfzN1m1b_T4b6MuzBWtmlhdLcQ0nZHicD94rliREFDRewsKBQCTYrAAVNzYKj84_0EZskDUxvkc972s9fYAqcQGEQjVZTc0cr7TB\/s728-e100\/ThreatLocker-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p><a name=\"more\"\/><\/p>\n<p>In a parallel report detailing the integration, Google&#8217;s Jigsaw division said ECH hides the domain name using a secret encryption key that only the destination website can decipher. <\/p>\n<p>\u00abCritically, though, not all web servers will offer ECH support,\u00bb Jigsaw <a href=\"https:\/\/medium.com\/jigsaw\/closing-a-critical-internet-privacy-gap-for-billions-of-users-android-17-rolls-out-ech-support-c52b49a62c04\" target=\"_blank\">said<\/a>. \u00abTo avoid exposing only certain connections as ECH-protected, apps and browsers should use ECH GREASE \u2014 which sends fake, randomized ECH extensions to sites that don&#8217;t support ECH \u2014 so that every connection request looks the same.\u00bb<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhuK_DE_NtqT3_L40Exbf_lxX4p0-5DCiquVpt9uTIdK9ZoZSObrriyvQaeh01qeRWkS6PnPH6NNp7TrVFS6SXnRelrWuJhr0FmcIcgxcxN0vxw5WpLT3CjiqNokRyotmQrWy-mYFT4e_xlfiN1y21lmkwUlBF9HpgEc2uDvDMX-ucoo5o4vI5d-_3bFeNq\/s1700-e365\/1000103904.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhuK_DE_NtqT3_L40Exbf_lxX4p0-5DCiquVpt9uTIdK9ZoZSObrriyvQaeh01qeRWkS6PnPH6NNp7TrVFS6SXnRelrWuJhr0FmcIcgxcxN0vxw5WpLT3CjiqNokRyotmQrWy-mYFT4e_xlfiN1y21lmkwUlBF9HpgEc2uDvDMX-ucoo5o4vI5d-_3bFeNq\/s1700-e365\/1000103904.jpg\" alt=\"\" border=\"0\" data-original-height=\"743\" data-original-width=\"1200\"\/><\/a><\/div>\n<p>With Android 17, ECH GREASE will be enabled by default. It&#8217;s worth noting that ECH was integrated into Google Chrome and Mozilla Firefox with <a href=\"https:\/\/chromestatus.com\/feature\/6196703843581952\" target=\"_blank\">versions 117<\/a> and <a href=\"https:\/\/blog.mozilla.org\/en\/firefox\/encrypted-hello\/\" target=\"_blank\">118<\/a>, respectively. However, with the latest update, the protection expands to the entire operating system.<\/p>\n<p>Jigsaw also said OkHttp, an open-source HTTP and HTTP\/2 client, has integrated ECH support into its core library, allowing third-party Android app developers to leverage the new capability.<\/p>\n<p>In addition to support for ECH on Android, Google has enforced <a href=\"https:\/\/developer.android.com\/privacy-and-security\/local-network-permission\" target=\"_blank\">Local Network Protection<\/a>, requiring apps to ask for users&#8217; permission before they can scan or connect to other devices on their local network.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/corelight-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjuvAqH13TTYyJD3aI-pJcYl54BoxQWMHc2aFwW2HbYUa5IKCjvHlzpzkFwXLTuV8aytky8kqLBgkoOtC8VQM5CGR0N5BXBl8RSXl-PYx_vIPbiLywiqXIvTPmm18cdEm_C0heVB-3U8zfG7K27RCAurtJ7OvxEyfQ0sVV_RRx1N4ZMWkqKgEBmkcDgjD6I\/s728-e100\/code-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Two other privacy- and security-oriented features include enabling Certificate Transparency (CT) by default, which mandates that all websites be logged in a public registry, and allowing telecom operators to turn off 2G by default for their subscribers to prevent downgrade attacks and mitigate exposure to rogue base stations or SMS blasters that can send malicious text messages or capture traffic from nearby devices.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj9PcUq4QN6rBHU3lBratufnpLsijCrJEE3SZ-gqzinNTUR2GmdUzh0VlwSXBewOJ2z89M8qlVSCim6lMHZGaW6Is8cI1r5Ag6-b1Hv-bHb3VwZ9X0-svAzLEq6QOfQu0ChyphenhyphengWGKHo_RTyqAbJw3usSDZeIJyvPtnQI5nSQMEyg1NCZPPfhXGWmdWJs81ov\/s1700-e365\/1000103905.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj9PcUq4QN6rBHU3lBratufnpLsijCrJEE3SZ-gqzinNTUR2GmdUzh0VlwSXBewOJ2z89M8qlVSCim6lMHZGaW6Is8cI1r5Ag6-b1Hv-bHb3VwZ9X0-svAzLEq6QOfQu0ChyphenhyphengWGKHo_RTyqAbJw3usSDZeIJyvPtnQI5nSQMEyg1NCZPPfhXGWmdWJs81ov\/s1700-e365\/1000103905.jpg\" alt=\"\" border=\"0\" data-original-height=\"743\" data-original-width=\"1200\"\/><\/a><\/div>\n<p>Android 12 already includes a manual option that allows users to disable 2G at the hardware level. With Android 14, Google added a security feature that allowed IT administrators to turn off support for 2G cellular networks in their managed devices. The latest offering, on the other hand, is a zero-click solution.<\/p>\n<p>\u00abFor participating carriers, this helps eliminate the legacy attack surface out of the box, proactively mitigating a primary method used by SMS blasters before they can target your device,\u00bb Google said.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Aug 28, 2026Cellular Security \/ Encryption Google on Thursday announced new network security protections in Android 17 to bolster connection privacy, address cellular vulnerabilities, and safeguard the privacy of&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2599,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[200,281,3224,2037,589,3223,3226,3225,903],"class_list":["post-2598","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-adds","tag-android","tag-ech","tag-hide","tag-network","tag-oswide","tag-providers","tag-visits","tag-website"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2598","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2598"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2598\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2599"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2598"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2598"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2598"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}