Jack Wallen/ZDNET
Follow ZDNET: Add us as a preferred source on Google.
ZDNET's key takeaways
ECH will help hide which websites you visit on your Android phone.
By blocking 2G connections, you're protected from malicious SMS-blaster connections.
ECH is still being rolled out, so even if your phone supports it, your connection may still be unsafe.
According to Google, Android 17 offers a few new ways of keeping your connections secure and private. On Thursday, the company announced that Android 17 is the first mobile operating system to support Encrypted Client Hello (ECH), a TLS privacy feature that hides destination domain names. The release also enforces new local-network permissions and enables Certificate Transparency by default. The new Android version also enables telecoms to block their phones from often malicious 2G access points.
But what is ECH, and how do these protections secure your browsing? Let's break it down.
ECH closes an HTTPS metadata gap
HTTPS has long encrypted the contents of web sessions, but it doesn't hide the website hostname you're visiting. That information was exposed in the Server Name Indication (SNI) field of the TLS ClientHello handshake. This gave ISPs, Wi-Fi operators, corporate networks, and unauthorized snoopers a way to identify sites and services you were visiting, even when they couldn't read the connection's content.
... continue reading