Android 17 adds new protections against sneaky Wi-Fi tracking and web snooping

Google has unveiled a series of significant network security enhancements in Android 17, designed to bolster user privacy by making it increasingly difficult for network operators, prying eyes, and scammers to monitor activities on mobile devices. According to Google software engineer Bram Bonné and product manager Shuaibo Huang, even when users connect to websites or apps via HTTPS, the domain names remain visible to external observers, which can lead to the creation of detailed user profiles or, worse, facilitate targeted phishing schemes.

Introducing Encrypted Client Hello (ECH)

To address this vulnerability, Android 17 integrates support for Encrypted Client Hello (ECH), a cutting-edge privacy standard that works in tandem with private DNS to obscure destination information from potential snoopers. ECH encrypts the domain name using a key that only the destination server can decipher. Given the inconsistent support for ECH across web servers, apps and browsers are also required to send GREASE, a decoy version of the encrypted extension, ensuring that outside observers cannot discern which connections are protected merely by analyzing their structure.

Google proudly claims that Android is the first major mobile operating system to implement widespread ECH support, collaborating with Jigsaw, its internet safety unit, and various app developers to accelerate its adoption. Nick Sullivan, co-author of the ECH standard and founder of Cryptography Consulting LLC, emphasized the importance of this development, stating, “ECH support for Android is a huge step towards closing one of the largest remaining structural privacy holes left on the Internet.”

For applications targeting Android 17, ECH is enabled by default, provided the app utilizes a networking library that supports it, such as the latest versions of OkHttp, WebView, or HttpEngine.

Rolling out such a transformative change to billions of devices necessitates thorough testing. Jigsaw conducted two evaluations: the first involved sending GREASE requests to the top 10,000 domains globally, where connection success rates remained stable compared to standard TLS. The second test involved requests traversing 202 countries and 740 ISPs, including heavily regulated networks like those in Russia and China, revealing minimal interference across the board.

David Kleidermacher, VP of Engineering for Android Security & Privacy, remarked, “Internet security must evolve continuously to match modern threats. Jigsaw’s ECH measurements helped validate deployment in Android 17, addressing a long-standing vulnerability and advancing our shared goal of a more private web.”

Additional Security Features in Android 17

In addition to ECH, Google has introduced three more enhancements aimed at fortifying user security:

  • Local Network Protection: This feature requires apps to request permission before scanning or connecting to other devices on a user’s home network, effectively closing off a pathway that apps previously exploited to profile households through smart TVs, cameras, and gaming consoles.
  • Certificate Transparency: Enabled by default, this feature mandates that certificates be logged publicly, making it more challenging for forged certificates to evade detection.
  • 2G Network Shutdown: Participating mobile operators can now disable 2G services for their subscribers automatically, reducing the risk of exposure to SMS blasters—fraudulent base stations that force devices onto outdated, insecure networks to deliver phishing messages that bypass spam filters.

In summary, Google asserts that “Your privacy and security should never be a compromise as technology evolves. These new Android 17 protections work seamlessly behind the scenes so you can connect, browse, and communicate with peace of mind.”

AppWizard
Android 17 adds new protections against sneaky Wi-Fi tracking and web snooping