Android 17 will hide which websites you visit. Your internet provider will lose track Home News Android 17 globally enables ECH encryption, which will hide from your internet provider which websites and applications you connect to The protection only works for websites and services that support ECH – for the rest, Android merely pretends to encrypt so that all connections look the same Google also adds home network protection, mandatory certificate transparency, and the option to globally disable vulnerable 2G Sdílejte: Adam Kurfürst Published: 31. 8. 2026 06:30 Advertisement Every time you open a page on your mobile phone, your internet provider and Wi-Fi network owner can still see which address you are heading to – even though the connection itself has long been encrypted via HTTPS. Google is now closing precisely this loophole: Android 17 is the first major mobile system to globally enable ECH encryption and hide that last visible trace of you. What exactly does ECH hide – and from whom? The acronym ECH stands for Encrypted Client Hello. When a phone connects to a website, at the very beginning of the connection, it still sends the target domain name in readable form – and from this, anyone along the route, from the operator to the owner of public Wi-Fi, knows where you are going. ECH encrypts this name with a key that only the target website can read, so it blends in with the equally indecipherable encryption of the rest of the transmission. This whole process works hand-in-hand with so-called private DNS, which hides the translation of an address to a numerical IP. Together, metadata disappears from the connection, which any observer could use to build a profile of you. According to Google, this means network operators and eavesdroppers will no longer so easily see which websites or applications you are currently using. The novelty is mainly its widespread implementation. ECH itself is nothing new – Chrome and Firefox browsers have supported it for about two years. However, as Google emphasizes on its blog, Android 17 extends this protection across the entire system for the first time, so it benefits not only browser pages but also regular applications. Why does Android pretend to encrypt even where there is none? ECH only works if the other side also supports it – meaning the specific website or server of the given application. And such cases are by no means the majority yet. This leads to a tricky trap. If the phone only encrypted the target address for a handful of supported connections, the mere fact that a connection was ECH-protected would stand out from the crowd – and immediately reveal that it was something “interesting.” The solution is called ECH GREASE, which sends fake, randomly generated ECH data even to websites without support, so that every request looks exactly the same. In Android 17, this mode is enabled by default. To allow third-party applications to offer the same protection, the open-source OkHttp library, through which many apps send data, has also added ECH support. Developers thus only need to update one component, and their application’s connection will be hidden just like a browser’s. What Android 17 monitors besides browsing Address encryption isn’t the only thing – Google has also tightened app access to your home network. Now, every app must request permission before it can scan for or connect to nearby devices, whether it’s a smart TV, camera, or speaker. Previously, they could do this silently in the background without asking. Certificate transparency is also now enabled by default. This requires that every security certificate be recorded in a public registry, making it significantly harder to sneak in a fake certificate and covertly eavesdrop on your traffic. Android 17 will hide which websites you visit. Your internet provider will lose track Adam Kurfürst News Adam Kurfürst News And thirdly, the system addresses attacks via outdated 2G. Operators can now globally disable 2G networks for their customers with a single click, through which fraudsters using so-called SMS blasters send phishing messages or force phones to fall back to vulnerable connections. Android 12 already offered a manual toggle for this, and Android 14 offered corporate management – but this time, it’s a solution that requires nothing from the user. It’s enough to remember one distinction: ECH encryption, certificate transparency, and home network monitoring run automatically directly within the system, whereas 2G deactivation depends on whether your operator adopts it. Do you appreciate that Android 17 will hide your browsing even from your internet provider? Sources: Google, The Hacker News About the author Adam Kurfürst Adam studuje na gymnáziu a technologické žurnalistice se věnuje od svých 14 let. Pakliže pomineme jeho vášeň pro chytré telefony, tablety a příslušenství, rád se… More about the author Sdílejte: Android Android 17 Google šifrování soukromí Zabezpečení