The record
Written from the 1 report below. Nothing here is unsourced.
- Google has announced new network security and privacy features for Android 17.
- Android 17 adds operating system-wide support for Encrypted Client Hello, which hides the websites and apps a user visits from network providers and snoopers.
- Android 17 requires apps to ask for user permission before scanning or connecting to other devices on a local network.
- Certificate Transparency is enabled by default, and telecom operators can turn off 2G by default to block downgrade attacks and SMS blasters.
- The changes matter because they extend protections that were previously limited to individual browsers to the entire Android operating system.
What to watch next
- Which carriers choose to enable the default 2G disablement for their subscribers.
- How many websites and apps add ECH server-side support, since the protection only works fully for supported destinations.
- Adoption of the ECH-capable OkHttp library by third-party Android app developers.
Who said what3
Only words found exactly in the article are shown, attributed and linked to the line they came from.
Bram Bonné
1 quote · 1 outlet
“This new privacy standard works in tandem with private DNS to obscure the domain names you visit, hiding metadata that can be used to profile you”
In the article
…and safeguard the privacy of users' home networks. Topping the list is support for Encrypted Client Hello (ECH), a privacy standard that prevents networks from eavesdropping on which websites a user is visiting. " This new privacy standard works in tandem with private DNS to obscure the domain names you visit, hiding metadata that can be used to profile you ," Google's Bram Bonné and Shuaibo Huang said. "By encrypting the destination website name from the very start, ECH helps ensure that, for supported websites and apps, network providers and network snoopers can no…
Jigsaw
Google's Jigsaw division
1 quote · 1 outlet
“To avoid exposing only certain connections as ECH-protected, apps and browsers should use ECH GREASE — which sends fake, randomized ECH extensions to sites that don't support ECH — so that every connection request looks the same.”
In the article
…Google's Jigsaw division said ECH hides the domain name using a secret encryption key that only the destination website can decipher. "Critically, though, not all web servers will offer ECH support," Jigsaw said. " To avoid exposing only certain connections as ECH-protected, apps and browsers should use ECH GREASE — which sends fake, randomized ECH extensions to sites that don't support ECH — so that every connection request looks the same. " With Android 17, ECH GREASE will be enabled by default. It's worth noting that ECH was integrated into Google Chrome and Mozilla Firefox with versions 117 and 118, respectively. However, with the latest update, the…
1 quote · 1 outlet
“For participating carriers, this helps eliminate the legacy attack surface out of the box, proactively mitigating a primary method used by SMS blasters before they can target your device”
In the article
…With Android 14, Google added a security feature that allowed IT administrators to turn off support for 2G cellular networks in their managed devices. The latest offering, on the other hand, is a zero-click solution. " For participating carriers, this helps eliminate the legacy attack surface out of the box, proactively mitigating a primary method used by SMS blasters before they can target your device ," Google said.…
Coverage1
All filed from IndiaSingle origin
Named United States · Android · Chrome · Firefox · Mozilla Firefox · OkHttp · Android 17 · Bram Bonné · Google · Jigsaw · Shuaibo Huang
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
