Android 17 Brings Enhanced Privacy with Encrypted ClientHello Support
Google has announced that its new Android 17 operating system will include support for Encrypted ClientHello (ECH) privacy protection, which obscures domain names and hides metadata to prevent profiling. This feature is designed to address a common misconception about HTTPS encryption: while it protects data in transit between the browser and server, it doesn't prevent a fake website from sending malware or launching phishing attacks.
In an August 27 blog post, Google software engineer Bram Bonné and Android product manager Shuaibo Huang warned that even with HTTPS, domain names are still visible to network operators and eavesdroppers. This metadata collection can be combined to create detailed profiles about users, which can then be used for targeted phishing and scam campaigns.
The ECH standard works by hiding the destination website's domain name using a secret encryption key that only the website can unscramble. Google is working with industry leaders and app developers to accelerate adoption of this new standard. To ensure all connections look the same, Jigsaw recommends using ECH GREASE, which sends randomized fake ECH extensions to sites that don't support ECH.
Starting with Android 17, ECH GREASE will be enabled by default, making it easier for users to protect their online anonymity. This new feature aims to address the growing concern of data harvesting and automated profiling on the internet.