In a further effort to strengthen mobile device privacy, Google has officially announced that the newly released Android 17 operating system fully adopts and enables by default the Encrypted Client Hello (ECH) network standard. This update makes Android the first mainstream mobile operating system worldwide to broadly support the standard, marking a pivotal step forward in Google’s efforts to shield users from internet service providers (ISPs) and malicious trackers alike.
Closing the Last Remaining Privacy Gap in HTTPS
In today’s internet landscape, even though the vast majority of websites now use encrypted HTTPS connections, the domain name a user is connecting to is still frequently transmitted in plaintext during the initial handshake phase of that connection. This lingering gap introduces several risks.
ISP Monitoring and Profiling
Internet service providers can easily log which websites a user visits, then use that data to build detailed user profiles for targeted advertising purposes.
Targeted Phishing Attacks
Malicious actors can similarly intercept this unencrypted connection metadata to design more precisely targeted phishing campaigns.
Jigsaw, Alphabet’s technology incubator, notes that ECH exists specifically to close this longstanding internet privacy gap, making the entire internet environment meaningfully safer for everyone.
How ECH Works
By enabling ECH by default in Android 17, the system encrypts the target website’s name at the very earliest stage of establishing a connection to that site.
Concealing the Real Domain
Once enabled, an ISP or network eavesdropper can only observe that a connection is directed toward some content delivery network (CDN, such as Cloudflare) and the total volume of data transmitted – without being able to determine which specific website or application the user actually visited.
An Added Layer Against Tracking
This effectively adds a robust protective layer around a user’s network activity, substantially reducing the risk of long-term tracking and behavioral profiling based on browsing patterns.
Privacy Protection Still Requires Multiple Layers
While ECH represents a significant privacy advancement, it alone cannot deliver complete network anonymity.
DNS Queries Still Require Encryption
ECH cannot conceal the DNS lookup process that translates a web address into a machine-readable IP address. Users still need to enable Encrypted DNS separately to ensure their query history remains fully protected.
IP Addresses Remain Visible
Unlike a VPN service, ECH does not conceal a user’s actual IP address.
Beyond adopting ECH, Google has also introduced additional security mechanisms in Android 17. For instance, the system now offers a zero-click solution that allows carriers to disable 2G networks by default, closing off a common vector abused by SMS blasters – devices that exploit legacy 2G cellular networks to bypass modern spam filters.
Secure by Default Is True Security
Previously, achieving this level of connection privacy typically required users to possess a meaningful degree of technical knowledge to configure settings manually, or to pay for a reliable VPN service. By building ECH directly into Android 17’s underlying architecture and enabling it by default, Google’s most meaningful contribution here is delivering on the principle of “secure by default” – allowing billions of Android users worldwide to automatically benefit from a safer baseline browsing environment without any complicated configuration required.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!