Updated
Updated · ZDNet · Aug 31
Android 17 Adds ECH and 2G Kill Switch to Block Snoops, Fake Towers
Updated
Updated · ZDNet · Aug 31

Android 17 Adds ECH and 2G Kill Switch to Block Snoops, Fake Towers

3 articles · Updated · ZDNet · Aug 31

Summary

  • Google said Android 17 is the first mobile OS to support Encrypted Client Hello, which encrypts the website name in the TLS handshake instead of exposing it through SNI.
  • ECH only works when apps use compatible networking libraries and servers or CDNs publish ECH keys in DNS HTTPS records; otherwise connections fall back to standard TLS, and DNS and IP metadata can still leak.
  • Android 17 also lets participating carriers disable 2G by default, closing a downgrade path that fake base stations and SMS blasters use to push phishing texts after forcing phones off LTE or 5G.
  • That protection carries a roaming trade-off: phones may lose service in places where 2G is still part of the network mix until users manually re-enable it.
  • The release also turns on local-network permission controls and Certificate Transparency by default, though the full benefit depends on app developers, carriers and network operators adopting the new features.

Insights

While Android 17 hides your browsing with ECH, could your unique IP address still betray your digital footprint to ISPs?
Will Android 17's aggressive block on legacy 2G networks leave you completely disconnected during your next remote travel adventure?
How many of your older smart home devices will suddenly break when Android 17 locks down local network permissions?