Google Rolls Out Encrypted Client Hello on Android 17 to Hide Browsing Destinations From Networks

Google said this week that Android 17 now supports Encrypted Client Hello (ECH), a privacy standard that prevents internet service providers and other network operators from seeing which websites and apps a device is connecting to, according to a security post published by Google and its Jigsaw team. Google described the rollout as the first broad deployment of ECH on a major mobile operating system.

ECH works alongside private DNS to encrypt the hostname sent during the initial stage of a TLS connection, a field historically visible in plaintext even over otherwise-encrypted HTTPS connections and commonly used by networks to profile which sites and services a user visits. With ECH enabled, network providers can see only which content delivery network is handling a connection and how much data is moving, not the specific destination site, for websites and apps that support the standard. Google said Android 17 also adds Local Network Protection, requiring apps to obtain permission before scanning for or connecting to devices on a user’s local network, along with mandatory Certificate Transparency logging for website certificates.

For organizations managing mobile device fleets, wider ECH adoption reduces the effectiveness of network-level traffic analysis as a security and monitoring technique, since enterprise security tools that rely on inspecting destination hostnames at the network layer will see less metadata for ECH-enabled connections. Google said Android app developers should upgrade to OkHttp 5.5.0 and enable ECH support to take advantage of the new protection.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *