Android 17 Makes Website Destinations Harder to Track
Android 17 adds Encrypted Client Hello to hide website hostnames during TLS handshakes. Here is how ECH works, what it protects, and what developers must change.
On this page
Android 17 is changing a small but revealing part of how phones connect to the web: the name of the website being contacted can now be hidden from network observers. Google announced on August 27 that Android 17 adds platform support for Encrypted Client Hello (ECH), a Transport Layer Security extension that encrypts the Server Name Indication (SNI) sent during the opening stage of a secure connection. The change matters because HTTPS already hides the contents of a connection, but traditionally leaves the destination hostname exposed.
Android 17 is moving website privacy below the browser
Normally, when an application establishes an HTTPS connection, the encryption protects the actual data exchanged with the server. The problem is that the first TLS handshake has historically exposed the hostname through SNI, allowing an internet service provider, Wi-Fi operator, or other network observer to determine which domain a device is contacting. ECH encrypts that sensitive part of the handshake instead of merely encrypting the traffic that follows it.
That distinction is important because knowing the domain can reveal a surprising amount about someone's activity even when the page contents remain encrypted. A network operator that cannot read the page can still distinguish between connections to a news site, banking service, video platform, or other domain. Android 17 is therefore addressing a layer of web privacy that HTTPS alone does not completely cover.
ECH hides the hostname, but it does not make browsing invisible
ECH works by creating an encrypted inner ClientHello containing sensitive connection information and wrapping it inside an outer ClientHello that can be observed without revealing the protected hostname. The server-facing infrastructure decrypts the protected information and continues the TLS connection normally. The IETF finalized ECH as RFC 9849, an Internet Standards Track specification, in March 2026.
There is an important limitation: ECH requires cooperation from the destination infrastructure. A server needs to publish an ECH configuration, and the client needs a networking stack capable of using it. Android's documentation says ECH is available for apps targeting Android 17, or API level 37, and that the networking library must also support ECH. If the destination does not support ECH, the connection cannot receive the same hostname-hiding protection.
Private DNS and ECH solve different parts of the privacy problem
Google is presenting ECH alongside private DNS because the two technologies protect different pieces of the connection process. DNS translates a domain name into information needed to reach a server, while ECH protects the hostname exposed during the TLS handshake. Google says Android 17 combines the two to make the domain names users visit harder for network observers to use for profiling.
This also explains why simply saying that ECH βhides your browsingβ would be misleading. It primarily removes a major source of metadata from the TLS handshake. Other information can still exist outside that protected hostname, and the network can still observe that a device is communicating with a particular service or infrastructure provider. RFC 9849 explicitly describes ECH as creating an anonymity set rather than making a connection completely unobservable.
Android developers have to update the networking layer
The change is more significant for developers than a normal browser privacy toggle because Android is putting ECH into the platform networking stack. Google's documentation says developers targeting Android 17 can use the new domain encryption configuration, while networking libraries must actually integrate ECH before applications can benefit from it. Android can obtain ECH configurations from HTTPS DNS records and pass them into the TLS implementation.
Google specifically recommends that Android developers adopt modern networking libraries and points to OkHttp 5.5.0 as part of its ECH guidance. That means developers maintaining custom HTTP stacks, older networking dependencies, or unusual DNS pipelines should not assume that changing the target SDK alone automatically makes every connection private. The application has to use a compatible path from DNS resolution through TLS negotiation.
ECH GREASE makes unsupported websites less revealing
Android 17 also uses a technique called ECH GREASE when a server does not support ECH. Instead of simply making ECH-capable connections look different from ordinary connections, the client can send a deliberately unusable ECH-like extension. The goal is to make the presence or absence of real ECH less useful as a fingerprinting signal. Google's Android documentation and the ECH standard both describe this fallback behavior.
Google says its Jigsaw team tested ECH GREASE across the top 10,000 domains and 740 internet providers in 202 countries, reporting no site-loading issues or unexpected network blocks. That is Google's testing rather than an independent benchmark, so it should be read as evidence about Google's deployment testing, not proof that every network will behave identically.
Android 17 is changing more than website hostname privacy
ECH is only one part of Google's broader Android 17 network-security push. The release also enforces local-network protection, requiring applications to obtain permission before scanning or connecting to devices on a user's local network. For common activities such as casting to a television, Google recommends system-mediated selection so an application can connect to the chosen device without gaining unrestricted visibility into the rest of the home network.
Android 17 also enables Certificate Transparency by default. Certificate Transparency uses publicly auditable logs for website certificates, making it harder for a compromised certificate authority to issue a fraudulent certificate without leaving evidence in the public record. Google says the change is intended to make certificate-based interception attacks more difficult to hide.
The platform is also adding carrier-controlled protection against 2G downgrade attacks. Participating carriers can disable 2G for subscribers, reducing exposure to rogue base stations and so-called SMS blasters that attempt to force phones onto older cellular technology. This is separate from web encryption, but it follows the same principle: reduce information and attack opportunities that modern applications do not need to expose.
The biggest change is that privacy is becoming part of the connection itself
For web users, the practical benefit of ECH will depend on adoption by websites, applications, networking libraries, and network infrastructure. It will not suddenly make every internet connection anonymous, and Android 17 cannot force an unsupported server to hide its hostname. What it does change is the default direction of the platform: protecting the destination name is becoming part of the underlying connection process rather than something developers have to build entirely on their own.
That matters beyond Android. ECH is now an Internet Standards Track protocol, and browsers and web infrastructure can build around the same mechanism instead of relying on proprietary privacy systems. As more servers publish ECH configurations and more clients enable it, the hostname that once leaked during an otherwise encrypted HTTPS connection becomes a much less useful source of browsing metadata.
Written by


