Android 17 Boosts Privacy with Encrypted Client Hello and Default 2G Decommissioning

August 27, 2026
Android 17 Boosts Privacy with Encrypted Client Hello and Default 2G Decommissioning
  • Android 17 introduces Encrypted Client Hello (ECH) to hide the visited domain names by encrypting the TLS handshake, especially when used with private DNS.

  • ECH scrambles the destination domain with a secret key so observers can’t read which site is contacted, even on HTTPS.

  • ECH GREASE will be enabled by default to mask connections to sites that don’t yet support ECH, ensuring uniform protection across connections.

  • The update credits specific contributors to the security features.

  • Google and Jigsaw helped develop these protections, with attention to the broader impact on Android users.

  • A zero-click option disables 2G by default for participating carriers, mitigating legacy SMS-based phishing and blaster attacks.

  • Certificate Transparency becomes default, requiring certificates to be logged publicly to curb forged certificates.

  • Updates aim for seamless, behind-the-scenes security improvements as threats evolve.

  • Related hardware and software coverage are noted but don’t alter the core privacy-focused narrative.

  • All features work together to close major Android privacy gaps, with broad rollout and support via OkHttp 5.5.0.

  • Emphasis on protecting domain-level metadata and raising the privacy floor by embedding protections in the OS.

  • Collectively, the updates strengthen network security and privacy through ECH, local network protections, certificate transparency, and 2G decommissioning where supported.

Summary based on 5 sources


Get a daily email with more Tech stories

More Stories