GKRootWire
Security ICE Signs $2M Deal for Zero-Click Phone Hacking ToolSecurity Attackers Exploit Critical Elementor Pro Bug to Hijack WordPress SitesAI ChatGPT Goes Down, Serves 404 Errors to UsersAI ChatGPT and Codex Suffer Widespread OutageAI Google DeepMind's WeatherNext 3 Sharpens AI Weather ForecastingAI Google's New AI Weather Model Sharpens Storm ForecastsSecurity ICE Signs $2M Deal for Zero-Click Phone Hacking ToolSecurity Attackers Exploit Critical Elementor Pro Bug to Hijack WordPress SitesAI ChatGPT Goes Down, Serves 404 Errors to UsersAI ChatGPT and Codex Suffer Widespread OutageAI Google DeepMind's WeatherNext 3 Sharpens AI Weather ForecastingAI Google's New AI Weather Model Sharpens Storm Forecasts
Security

Android 17 Adds Encrypted ClientHello to Curb Web Traffic Snooping

Google's next Android release bakes in ECH and other network-layer protections to hide which sites you visit and shore up cellular and Wi-Fi weak points.

Google has detailed a batch of network security upgrades coming in Android 17, headlined by support for Encrypted ClientHello (ECH). ECH encrypts the initial handshake step of a TLS connection, which today can leak the domain name you're connecting to even over otherwise-secure HTTPS. By hiding that metadata, ISPs, network operators, and anyone snooping on traffic have a much harder time building a picture of your browsing habits.

Alongside ECH, Android 17 is expected to tighten protections against known cellular network vulnerabilities, such as attacks that exploit weaknesses in how devices connect to cell towers, and to add safeguards for home network privacy, likely limiting how much local devices can passively fingerprint or track phones on the same Wi-Fi network.

These changes build on a broader industry push, already seen in browsers like Chrome and Firefox, to encrypt more of the connection process rather than leaving metadata exposed.

Why it matters: ECH closes one of the last plaintext gaps in modern web connections, making passive network surveillance and censorship-by-domain significantly harder to pull off. For everyday users this mostly happens invisibly, but it raises the bar for ISPs, public Wi-Fi operators, and state-level censors who currently rely on visible hostnames to filter or monitor traffic.

Sources: BleepingComputer