Google is adding new network security and privacy protections to Android 17, helping protect mobile connections, secure local networks, and make online activity more difficult to track.
One of the most significant additions is support for Encrypted Client Hello (ECH), a privacy standard designed to hide metadata such as the domain names users visit. ECH works together with Private DNS to provide stronger protection against network surveillance and profiling.
ECH is part of the TLS privacy enhancements protocol. It protects HTTPS connections by encrypting the initial portion of the TLS handshake, including the hostname traditionally exposed through Server Name Indication (SNI).
Although HTTPS encrypts the contents of a connection, Internet Service Providers (ISPs), Wi-Fi operators, and other network observers may still be able to see the domains a device connects to. This information can be collected for monitoring, traffic analysis, or commercial profiling.
ECH is already available to Android users through supported applications, including Chrome 117 and later and Firefox 119 and later. However, Android 17 expands ECH protection at the operating-system level.
“This new privacy standard works in conjunction with private DNS to hide the domain names that users access and hide the metadata that can be used to profile users,” Google’s Jigsaw team explained in its announcement.
Google said ECH makes it significantly harder for network providers and other snoopers to determine which websites and apps users are accessing when those services support the technology. The destination hostname is encrypted at the beginning of the connection rather than being exposed during the TLS handshake.
For apps targeting Android 17, ECH will be enabled by default when they use the latest versions of compatible network libraries, including OkHttp, WebView, and HttpEngine.

Source: Google
Android 17 will encrypt hostnames when users connect to servers that support ECH.
For servers that do not support the technology, Android will send a decoy ECH-like extension known as ECH GREASE. In these cases, the hostname remains visible, but the use of ECH is obscured from network observers.
Google’s Jigsaw division tested ECH GREASE across the top 10,000 domains and with 740 Internet providers in 202 countries. The testing reportedly found no website loading problems or unexpected network blocks.
Android 17 adds Wi-Fi protection and 2G blocking
Google is also introducing several additional network security features in Android 17, according to its announcement.
The first is a local network protection change that requires apps to request permission before scanning for or connecting to devices on a user’s local network. This can help prevent unauthorized discovery of smart home devices, computers, printers, and other network-connected equipment.
Android 17 will also enable certificate transparency by default. Websites will be required to have their TLS certificates recorded in publicly auditable logs, making suspicious or fraudulent certificates easier to identify.
In addition, participating mobile carriers will be able to automatically disable 2G connectivity for subscribers. Blocking 2G can reduce the risk of SMS blasters and rogue cellular base stations that intercept traffic, send malicious messages, or trick nearby devices into connecting to an attacker-controlled network.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop sharply.
Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com




