[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fOgZ5USnsOxTk5aFQkigNMvG0xOiaOtlU_7xTb7Q8fgs":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":24,"created_at":25,"published_at":26,"article":27,"tags":31,"podcasts":50},"be6c7dd3-e600-4cbb-83af-c07b637695e3","android-17-brings-os-wide-encryption-to-shield-dns-queries-from-network-providers","8281f076-909c-40e6-b6cb-cf6eb936be6c","Android 17 Brings OS-Wide Encryption to Shield DNS Queries from Network Providers","Android 17's introduction of Encrypted Client Hello (ECH) addresses a longstanding privacy gap where network providers and ISPs could observe users' browsing destinations through unencrypted TLS handshakes, even when HTTPS was in use. Without ECH, the Server Name Indication (SNI) field in TLS connections exposed domain names in plaintext, enabling traffic analysis, surveillance, or censorship by network intermediaries. This OS-level integration matters because it removes the burden from individual users to configure privacy tools, making strong transport-layer privacy the default. The accompanying features — Local Network Protection, mandatory Certificate Transparency, and 2G disablement — collectively reduce attack surfaces from rogue infrastructure and fraudulent certificates. The lesson is clear: default-secure configurations at the platform level dramatically improve privacy outcomes across entire user populations.","**Immediate actions:**\n- Update Android devices to Android 17 or later to enable OS-wide ECH and benefit from built-in privacy protections.\n- Enable Private DNS (DNS-over-TLS\u002FHTTPS) on all managed Android devices to complement ECH and prevent DNS leakage.\n\n**Configuration & hardening:**\n- Enforce Certificate Transparency validation in enterprise mobile device management (MDM) policies to detect fraudulent TLS certificates.\n- Disable legacy 2G connectivity on managed devices via MDM or carrier settings to mitigate SMS blaster and IMSI catcher attacks.\n- Review and restrict local network access permissions for applications to minimize lateral movement risks on trusted networks.\n\n**Long-term improvements:**\n- Adopt a 'secure by default' mobile device policy that mandates encrypted DNS, modern TLS standards, and ECH for all enterprise-managed endpoints.\n- Establish a regular cadence for evaluating and deploying OS-level privacy and security updates across the mobile device fleet.\n- Educate users and IT staff on traffic analysis risks and the organizational value of transport-layer encryption standards like ECH.",[12,13,14,15,16,17,18,19,20,21,22,23],"NIST SP 800-188 (De-Identifying Government Datasets)","NIST SP 800-187 (LTE Network Security)","NIST Privacy Framework PR.DS-2 (Data-in-transit protection)","CIS Control 4: Secure Configuration of Enterprise Assets","CIS Control 12: Network Infrastructure Management","CIS Control 13: Network Monitoring and Defense","GDPR Article 25: Data Protection by Design and by Default","GDPR Article 32: Security of Processing","NIST AC-17: Remote Access","NIST SC-8: Transmission Confidentiality and Integrity","NIST SC-23: Session Authenticity","RFC 8744 \u002F ECH IETF Draft: Encrypted Client Hello Standard","published","2026-08-28T20:21:38.991487+00:00","2026-08-28T20:21:38.909+00:00",{"id":7,"url":28,"slug":29,"title":30},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002Fandroid-17-adds-os-wide-ech-to-hide.html","android-17-adds-os-wide-ech-to-hide-website-visits-from-network-providers-45f31e","Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers",[32,38,44],{"id":33,"name":34,"slug":35,"description":36,"color":37},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":39,"name":40,"slug":41,"description":42,"color":43},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",{"id":45,"name":46,"slug":47,"description":48,"color":49},"f43a7f30-5046-4b10-9dba-1a704139821e","Network Segmentation","network-segmentation","Lateral movement, flat networks, missing firewalls","#06b6d4",[]]