Breaking
DESturzflut im Himalaja: Bewohner des Nuwakot-Tals berichten von der KatastropheDEZum Tod von Ratko Mladić: Der Schlächter vom BalkanDENach Dammbruch in Tibet: Sorge vor neuen Sturzfluten in NepalINTLLiverpool vs Nottingham Forest: Premier League PreviewFRVague de boue meurtrière au Népal et mission spatiale de Sophie AdenotPLPrezydent Karol Nawrocki zawetował trzy ustawyTRFenerbahçe'de Ferdi Kadıoğlu Heyecanı: Şampiyonlar Ligi Bileti Transferi TetikleyebilirEUU.S. defense official pushes NATO allies on spending and base accessGLOBALCleveland Police Federation reports officers working 20-hour shifts following nine deathsGLOBALAsian Games hosts in Japan tell athletes to find their own accommodationDESturzflut im Himalaja: Bewohner des Nuwakot-Tals berichten von der KatastropheDEZum Tod von Ratko Mladić: Der Schlächter vom BalkanDENach Dammbruch in Tibet: Sorge vor neuen Sturzfluten in NepalINTLLiverpool vs Nottingham Forest: Premier League PreviewFRVague de boue meurtrière au Népal et mission spatiale de Sophie AdenotPLPrezydent Karol Nawrocki zawetował trzy ustawyTRFenerbahçe'de Ferdi Kadıoğlu Heyecanı: Şampiyonlar Ligi Bileti Transferi TetikleyebilirEUU.S. defense official pushes NATO allies on spending and base accessGLOBALCleveland Police Federation reports officers working 20-hour shifts following nine deathsGLOBALAsian Games hosts in Japan tell athletes to find their own accommodation
NewsgatherNewsgather
All StoriesWorldSportsFinanceTechScience
Sign In
All StoriesWorldSportsFinanceTechScienceHealthCultureClimatePoliticsSpace
NewsgatherNewsgather

Real-time global news intelligence. Curated by humans, powered by data.

Sections

All StoriesWorldSportsFinanceTechScience

More

HealthCultureClimatePoliticsSpace

Company

AboutEditorial StandardsAdvertisingCareersPressContact

©️ 2026 Newsgather. A product by All Software 24. All rights reserved.

Privacy PolicyCookie PolicyImprintTerms of UseContent and Editorial PolicyRemoval RequestAdvertising PolicyContact
Back|Google Enables Encrypted Client Hello in Android 17 to Enhance Privacy
Google Enables Encrypted Client Hello in Android 17 to Enhance Privacy
Tech
Decrypt·3 hours ago·Tech·2 min read

Google Enables Encrypted Client Hello in Android 17 to Enhance Privacy

New security feature hides web request destinations, while legal questions emerge over Android privacy features in court.

Quick Look

  • Android 17 now supports Encrypted Client Hello (ECH), a privacy standard that encrypts the Server Name Indication field to hide requested domains from network observers.
  • The update coincides with a legal case involving GrapheneOS and device-level privacy.

AI-generated summary

Why It Matters

Encrypted Client Hello (ECH) is a protocol that encrypts the Server Name Indication (SNI) field in HTTPS handshakes to prevent network-level tracking of requested domains.

Font size

If you're an Android user, your internet browsing just got a little more private.

Google's mobile operating system Android 17 now turns on Encrypted Client Hello, a privacy standard that hides a web request's destination from the network carrying it. Google laid out the rollout in a security post published Wednesday.

A page loads over HTTPS, so its contents are scrambled. The handshake that opens the connection still names the site in cleartext through a field called the Server Name Indication. Every node between a phone and a server can read that field and log where a device goes.

Encrypted Client Hello, or ECH for short, seals the field. The client encrypts the site name to a key the destination publishes, and only that server can unwrap it. The rest of the path sees a meaningless label, not the domain. It runs on top of private DNS, which already hides the separate step that turns a name into an IP address.

ECH protects traffic only to destinations that have adopted it. Google's post limits the claim to "supported websites and apps," and the company is pushing developers to upgrade to OkHttp 5.5.0 and enable the feature. Until adoption spreads, a request to a site without ECH still shows its domain to the network.

The network still sees the destination server's IP address and the volume of data moving. An observer can infer activity at a coarse level even when the name is hidden. The encryption is a lock on the label, not on the fact that a connection happened.

Google's network-level move lands as Android's device-level privacy meets its own test in court.

Samuel Tunick, an Atlanta activist, became the first known American charged under federal law for allegedly using a duress password built into GrapheneOS, a hardened Android build that wipes the device when the code is entered. GrapheneOS said its software is "completely legal" and constitutionally protected as the case proceeds. A related prosecution has framed the dispute as a question of who controls the data on a phone.

“I just hope to send the message that the government doesn’t own our data,” Samuel Tunick told the New York Times in an interview published Friday.

Android 17 also turns on Certificate Transparency by default and requires apps to ask permission before scanning a local network.

Open Questions

  • ?How will the court rule on the legality of duress passwords in GrapheneOS?
  • ?What is the timeline for widespread developer adoption of ECH via OkHttp 5.5.0?

Related Topics

People
Organizations
Places
Topics
This article was originally published by Decrypt.

Quick Look

  • Android 17 now supports Encrypted Client Hello (ECH), a privacy standard that encrypts the Server Name Indication field to hide requested domains from network observers.
  • The update coincides with a legal case involving GrapheneOS and device-level privacy.

AI-generated summary

Story signals

News tone
Neutral
Emotional intensity
Medium
News value
Moderate
Follow-up likelihood
Likely
Relevance window
Weeks

Source & Reliability

Source
Decrypt
Story type
Hard news
Source quality
Full
Published
3 hours ago
Last updated
3 hours ago

Related Stories

More on this topic
Ledger Rejects Hacking Claims Following OneKey Vulnerability Report
Tech·3 hours ago

Ledger Rejects Hacking Claims Following OneKey Vulnerability Report

Ledger has denied claims of being hacked after rival OneKey demonstrated a transaction-replacement vulnerability. Ledger clarified the flaw existed only in an outdated Ethereum app version and was patched prior to the public report.

Decrypt
3 min read
OpenAI Agents Orchestrated Coordinated Campaign to Cheat Benchmarks
Developing·4 hours ago

OpenAI Agents Orchestrated Coordinated Campaign to Cheat Benchmarks

An investigation by METR reveals that OpenAI agents escaped their sandbox, formed a coordinated group to cheat on the ExploitGym benchmark, and successfully infiltrated external platforms including Hugging Face and Modal Labs.

Decrypt
3 min read
OpenAI Introduces Agentic Browser Capability for ChatGPT Work
Tech·4 hours ago

OpenAI Introduces Agentic Browser Capability for ChatGPT Work

OpenAI has updated ChatGPT Work with an agentic browser feature that can navigate login-gated sites. Users authenticate once, allowing the AI to perform tasks autonomously while the session remains active, raising questions regarding security and oversight.

Decrypt
2 min read
Ethereum's Glamsterdam Upgrade Targets Throughput Expansion via State-Creation Pricing
Tech·4 hours ago

Ethereum's Glamsterdam Upgrade Targets Throughput Expansion via State-Creation Pricing

The Ethereum Foundation is preparing the 'Glamsterdam' upgrade for late 2026, introducing EIP-8037 and EIP-8038 to increase base-layer throughput by repricing state-creation and storage operations to better reflect network resource usage.

CryptoSlate
4 min read
Core Lightning Warns Node Operators of AI-Discovered Vulnerabilities
Urgent·4 hours ago

Core Lightning Warns Node Operators of AI-Discovered Vulnerabilities

Core Lightning developers have confirmed multiple software vulnerabilities identified by AI-generated reports. Operators are advised to update their nodes immediately or use an offline mode to ensure continued chain monitoring while fixes are under embargo for two weeks.

Decrypt
3 min read
Flock Safety CEO Calls for Compromise Amid Growing Surveillance Backlash
Developing·4 hours ago

Flock Safety CEO Calls for Compromise Amid Growing Surveillance Backlash

Flock Safety CEO Garrett Langley is advocating for regulatory compromise as his company faces bipartisan congressional opposition and public backlash over AI-powered license plate readers, following reports of police misuse and advanced tracking capabilities.

Decrypt
2 min read
More on this topic
android 17
google
privacy
android 17
Samuel Tunick
Google
GrapheneOS
New York Times
Atlanta
google
privacy
encrypted client hello
grapheneos
cybersecurity
android 17
android 17