Google is out with a blog post today recapping new network security measures in Android 17.
Even with HTTPS connections, the domain names of websites (including apps) are “still visible to network operators and eavesdroppers.”
This unencrypted data can be used to build user profiles or, in the hands of malicious actors, leveraged for targeted phishing and scam campaigns.
Android 17 aims to resolve this with Encrypted Client Hello (ECH). Working with private DNS, this new privacy standard will “obscure the domain names you visit.” This works by hiding the “domain name using a secret encryption key that only the destination website can unscramble.”
By encrypting the destination website name from the very start, ECH helps ensure that, for supported websites and apps, network providers and network snoopers can no longer easily see which websites or apps you are accessing.









