Skip to content
Android

Android 17 Hides Domain Names, Lets Carriers Disable 2G

Android 17 introduces a set of network security upgrades designed to keep user browsing more private and to block attacks that rely on outdated cellular technology. Google detailed the changes in a new blog post, highlighting encryption improvements, local network restrictions, and stronger...

Android 17 Hides Domain Names, Lets Carriers Disable 2G - Android 17 network security
Android 17 introduces a set of network security upgrades designed to keep user browsing more private and to block attacks that rely on outdated cellular technology. Google detailed the changes in a new blog post, highlig

Android 17 introduces a set of network security upgrades designed to keep user browsing more private and to block attacks that rely on outdated cellular technology. Google detailed the changes in a new blog post, highlighting encryption improvements, local network restrictions, and stronger certificate verification.

The headline feature addresses a longstanding privacy gap. Even over HTTPS connections, the domain names of websites and apps remain visible to network operators and potential eavesdroppers. That unencrypted data can be used to build user profiles or, in the wrong hands, fuel targeted phishing and scam campaigns.

Encrypted Client Hello obscures the sites you visit

To close that gap, Android 17 adds support for Encrypted Client Hello (ECH). Working alongside private DNS, the standard obscures the domain names you visit by hiding them behind a secret encryption key that only the destination website can unscramble. By encrypting the destination name from the start, ECH prevents network providers and snoopers from easily seeing which supported websites or apps you are accessing.

Domain name data typically leaks in two places: the initial DNS lookup and the unencrypted ClientHello in the Transport Layer Security (TLS) handshake. The rollout of encrypted DNS combined with ECH support on Android 17 helps close both. With operating system support now available, app developers need to upgrade to OkHttp 5.5.0 and enable ECH to take advantage of it.

Carriers can disable 2G to stop SMS blaster attacks

On the cellular side, Android 17 allows mobile carriers to turn off 2G connectivity by default for their users. Android 12 first introduced this option as a user setting. The move is intended to counter SMS blaster attacks, which force nearby smartphones to drop their LTE or 5G connections and downgrade to less secure, legacy 2G networks. Once downgraded, devices can be flooded with phishing texts.

Android 17 also enforces Local Network Protection, requiring apps to request permission before they can scan or connect to other devices on your local network. For common tasks such as casting a video to a TV, developers are encouraged to adopt a secure system tool that lets you select your TV without the app ever needing permission to see the other devices in your home.

Certificate Transparency reduces spoofing risks

The release rounds out its security push with Certificate Transparency, which requires all certificates to be logged in a public registry. When you connect to a secure app or website, your device verifies a certificate to confirm the site is authentic. If a certificate issuer is compromised, attackers could create fake certificates to intercept traffic. Logging every certificate in a public registry makes such an attack far more likely to be noticed.

App developers must upgrade to OkHttp 5.5.0 and enable ECH to support the new encrypted domain feature.

Source
Image: 9to5google.com

The US tech briefing

Smartphones, AI, computing and deals — the essential stories without the noise.

Mailing provider can be connected when your US list is ready.

Shop Amazon Tech Deals Shop Amazon Tech Deals