[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fy2ZlOgxyZFdT3V1BUp2VQy7Q3Q2tZyg2_pD1hXCVABE":3},{"article":4,"iocs":41},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":33,"category":34,"article_tags":38},"8281f076-909c-40e6-b6cb-cf6eb936be6c","Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers","android-17-adds-os-wide-ech-to-hide-website-visits-from-network-providers-45f31e","Google on Thursday announced new network security protections in Android 17 to bolster connection privacy, address cellular vulnerabilities, and safeguard the privacy of users' home networks. Topping the list is support for Encrypted Client Hello (ECH), a privacy standard that prevents networks from eavesdropping on which websites a user is visiting. \"This new privacy standard works in tandem","Google's Android 17 update introduces Encrypted Client Hello (ECH) as an operating system-wide feature to prevent network providers from seeing which websites users visit. This privacy standard works with private DNS to obscure domain names, enhancing user privacy. The update also includes Local Network Protection, mandatory Certificate Transparency, and the ability for telecom operators to disable 2G by default to mitigate risks from SMS blasters and rogue base stations.","Android 17 adds OS-wide Encrypted Client Hello (ECH) to hide website visits from network providers.","Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers Ravie LakshmananAug 28, 2026Cellular Security \u002F Encryption Google on Thursday announced new network security protections in Android 17 to bolster connection privacy, address cellular vulnerabilities, and safeguard the privacy of users' home networks. Topping the list is support for Encrypted Client Hello (ECH), a privacy standard that prevents networks from eavesdropping on which websites a user is visiting. \"This new privacy standard works in tandem with private DNS to obscure the domain names you visit, hiding metadata that can be used to profile you,\" Google's Bram Bonné and Shuaibo Huang said. \"By encrypting the destination website name from the very start, ECH helps ensure that, for supported websites and apps, network providers and network snoopers can no longer easily see which websites or apps you are accessing.\" In a parallel report detailing the integration, Google's Jigsaw division said ECH hides the domain name using a secret encryption key that only the destination website can decipher. \"Critically, though, not all web servers will offer ECH support,\" Jigsaw said. \"To avoid exposing only certain connections as ECH-protected, apps and browsers should use ECH GREASE — which sends fake, randomized ECH extensions to sites that don't support ECH — so that every connection request looks the same.\" With Android 17, ECH GREASE will be enabled by default. It's worth noting that ECH was integrated into Google Chrome and Mozilla Firefox with versions 117 and 118, respectively. However, with the latest update, the protection expands to the entire operating system. Jigsaw also said OkHttp, an open-source HTTP and HTTP\u002F2 client, has integrated ECH support into its core library, allowing third-party Android app developers to leverage the new capability. In addition to support for ECH on Android, Google has enforced Local Network Protection, requiring apps to ask for users' permission before they can scan or connect to other devices on their local network. Two other privacy- and security-oriented features include enabling Certificate Transparency (CT) by default, which mandates that all websites be logged in a public registry, and allowing telecom operators to turn off 2G by default for their subscribers to prevent downgrade attacks and mitigate exposure to rogue base stations or SMS blasters that can send malicious text messages or capture traffic from nearby devices. Android 12 already includes a manual option that allows users to disable 2G at the hardware level. With Android 14, Google added a security feature that allowed IT administrators to turn off support for 2G cellular networks in their managed devices. The latest offering, on the other hand, is a zero-click solution. \"For participating carriers, this helps eliminate the legacy attack surface out of the box, proactively mitigating a primary method used by SMS blasters before they can target your device,\" Google said. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  Android, mobile security, network security, Privacy, Web Security ⚡ Top Stories This Week Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code Execution ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit, and More New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments CDN Tsunami Attack Abuses HTTP\u002F3 Translation for Up to 350x DoS Amplification Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits\u002FSecond OpenAI Pauses Frontier RL Training as It Tightens Defenses Against Unsafe AI Behavior Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps AI \"Mind Viruses\" Can Spread Between Agents Through Persistent Prompt Files SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects ⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware Apple Warns Users in 110 Countries They May Be Targets of Mercenary Spyware Trump Memo Paves Way for U.S. Firms to Hack and Disrupt Foreign Crime Groups GeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE Attackers Exploit SharePoint Authentication Bypass After Public PoC Release Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access ⭐ Featured Resources See How Keeper Secrets Manager Removes Hard-Coded Credentials Download the CISO's Guide to Smarter AI Security Investment Phishing Is Costing Security Teams More Than Ever — Read the New Report Build AI Agents and Automations Without Losing Security Control","https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002Fandroid-17-adds-os-wide-ech-to-hide.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEiHdeGqGafTZXNtGvV_-qR7K3QId_-DpEfOzetKbhVQvNdNyTMAy-6gLXVFlkMHsGDN2wKK8v1ZMeOKe9_3XVYAY5TVkqH2heesi0c_QmJzLpDX1M-XfOtI_W4Qe8OM8Yhin40QWvN0XHvU9cqDlZH3eeZY_18euIxiBdcbhWMVnXct-x84k2gvchQYSiuN\u002Fs1600\u002F1000103901.jpg","2026-08-28T16:20:46+00:00","2026-08-28T20:00:15.955554+00:00",7,[18,21,24,27,29,31],{"name":19,"type":20},"Android 17","product",{"name":22,"type":23},"Encrypted Client Hello","technology",{"name":25,"type":26},"Google","vendor",{"name":28,"type":20},"Google Chrome",{"name":30,"type":20},"Mozilla Firefox",{"name":32,"type":20},"OkHttp","614132b8-5837-4952-b8b5-c6c9a32a1d85",{"id":33,"icon":35,"name":36,"slug":37},null,"Privacy","privacy",[39],{"category":40},{"id":33,"icon":35,"name":36,"slug":37},[]]