Google’s Android 17 Turns On New Privacy Feature—But Your Browsing Isn’t Fully Hidden
Google has introduced native platform support for Encrypted Client Hello (ECH) in Android 17, marking the first broad rollout of the privacy standard across a major mobile operating system. ECH enhances user privacy by encrypting the Server Name Indication (SNI) field during the initial TLS handshake, effectively preventing internet service providers, cellular carriers, and local Wi-Fi operators from observing which specific domain or website a device connects to. Developed in collaboration with Google's Jigsaw team and open-source contributors, the feature operates atop private DNS to obscure web browsing metadata. The cryptographic safeguard functions strictly on websites and applications that have enabled ECH support and upgraded network configurations, such as adopting OkHttp 5.5.0. Although the feature prevents cleartext domain leakage, destination IP addresses and data transfer volumes remain visible to intermediate network nodes. In tandem with ECH, Android 17 also turns on Certificate Transparency by default and introduces explicit permission prompts before applications can scan local networks, solidifying Google's ongoing push for robust platform-level privacy safeguards.