All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
All NewsHome
← Back to AI & Technology

Android 17 Enhances Privacy With Encrypted Client Hello

Created at 27 Aug · 10:10 PM1 source↑ Market-relevant
IN SHORT

Android 17 introduces Encrypted Client Hello (ECH) to encrypt domain names in connection requests, shielding browsing destinations from network observers. This feature, a broad rollout on a major mobile OS, requires website and app adoption to be fully effective.

Key Numbers

5.5.0OkHttp version for ECH adoption

Who's Involved

Google
Developer of Android 17 and Encrypted Client Hello
Samuel Tunick
Activist facing prosecution over GrapheneOS duress password
Android 17 Enhances Privacy With Encrypted Client Hello

↳ Why This Matters

Android 17's implementation of Encrypted Client Hello offers users greater privacy by obscuring their browsing destinations from network observers, though its effectiveness depends on broader adoption by websites and apps. This development occurs amidst ongoing legal scrutiny of device-level privacy features on Android.

Key facts

  • Android 17 has integrated Encrypted Client Hello (ECH) to encrypt domain names.
  • ECH hides web request destinations from network carriers and Wi-Fi operators.
  • The feature requires websites and apps to adopt ECH for full protection.
  • ECH works in conjunction with private DNS to obscure IP addresses.
  • Android 17 also enables Certificate Transparency by default.
  • Apps must now request permission before scanning local networks.

Google's Android 17 operating system has introduced a new privacy feature called Encrypted Client Hello (ECH). This technology encrypts the domain name of a website or app when a connection is initiated, preventing network providers like carriers and Wi-Fi operators from seeing the specific destination. This marks a significant step in mobile OS privacy, as it's the first broad rollout of ECH on a major platform, developed in collaboration with Google's Jigsaw team and external developers.

While ECH encrypts the destination domain, it does not hide the IP address of the server or the volume of data transferred. The effectiveness of ECH is contingent on websites and applications adopting the standard. Google is encouraging developers to upgrade to OkHttp version 5.5.0 to enable this feature. Until widespread adoption occurs, requests to sites not supporting ECH will still expose their domain names to network observers.

In parallel with these network-level privacy enhancements, Android's device-level privacy is also being tested in court. Samuel Tunick, an activist, is facing federal charges for allegedly using a duress password feature in GrapheneOS, a hardened Android build designed to wipe a device when a specific code is entered. GrapheneOS maintains its software is legal and constitutionally protected.

Beyond ECH, Android 17 also enables Certificate Transparency by default and mandates that apps seek user permission before scanning local networks.

Frequently asked questions

ECH is a privacy standard that encrypts the domain name sent when a connection opens, preventing network observers from reading the destination.

No, ECH only hides the domain name of supported websites and apps. Network observers can still see the IP address and data volume, and activity to unsupported sites is still visible.

Android 17 also enables Certificate Transparency by default and requires apps to ask permission before scanning a local network.

What Happens Next

01Developers are encouraged to upgrade to OkHttp 5.5.0 to enable ECH.
02Wider adoption of ECH by websites and apps is expected to increase privacy.
03The legal case involving Samuel Tunick and GrapheneOS may set precedents for data control on mobile devices.

How It Developed

Android 17 now supports Encrypted Client Hello (ECH) for enhanced privacy.
ECH encrypts the domain name in connection requests, hiding destinations from networks.
This is the first broad ECH rollout on a major mobile operating system.
Protection is limited to sites and apps that have enabled ECH.
Android 17 also enables Certificate Transparency by default.
Apps will now require permission to scan local networks.

Sources

T1
Google’s Android 17 Turns On New Privacy Feature—But Your Browsing Isn’t Fully HiddenDecrypt

Related Stories

Google Tightens Android App Memory Requirements Amid AI-Driven Chip Shortages
27 Aug · 2:56 PM
Google's AI Mode Enhances Travel Planning with Flight Tracking and Hotel Booking
27 Aug · 4:26 PM
OpenAI's ChatGPT Work Now Logs Into Websites Without User Input
27 Aug · 9:06 PM
Anthropic unveils framework for AI agents to operate physical devices
27 Aug · 6:06 PM
Tech Giants Warn of AI-Driven Cyberattacks, Urge Defensive Surge
27 Aug · 5:04 PM