TechNewsReel
Live

Android 17 becomes first mobile OS to enable Encrypted Client Hello by default

The update closes a long-standing privacy gap by encrypting website domain names during the initial connection handshake.

TechNewsReel Newsroom · August 27, 2026

Google has introduced platform-wide support for Encrypted Client Hello (ECH) in Android 17, marking the first time a major mobile operating system has enabled the feature by default. The move significantly strengthens user privacy by encrypting the domain names of websites and services during the TLS handshake.

By encrypting the destination website name from the start of a connection, ECH prevents internet service providers (ISPs) and network eavesdroppers from seeing which domains a user is visiting. This removes the ability of network operators to build detailed user profiles based on domain metadata, even when the user is already utilizing HTTPS. The rollout is further supported by the integration of ECH into OkHttp 5.5.0, a widely used HTTP client for Android applications.

The structural privacy gap

While HTTPS has long encrypted the actual content of web traffic, the initial connection process traditionally leaked information. Specifically, the DNS lookup and the TLS ClientHello handshake often transmitted the destination domain name in plain text. Google previously attempted to mitigate the first leak point by introducing DNS-over-TLS in Android 9, but the handshake remained a vulnerability. Nick Sullivan, founder of Cryptography Consulting LLC and co-author of the ECH standard, described the Android 17 deployment as a "huge step towards closing one of the largest remaining structural privacy holes left on the Internet."

Industry implications and surveillance

This deployment reduces the capacity for network operators to monitor and monetize browsing habits via metadata and mitigates the risks of state-level surveillance and targeted phishing. To ensure the protocol does not lead to new vulnerabilities, Android 17 enables "ECH GREASE" by default. This mechanism sends randomized ECH extensions to websites that do not support the standard, preventing network observers from "fingerprinting" and identifying ECH-protected connections.

Global readiness and next steps

Google's push for adoption is backed by empirical data from Jigsaw. Global measurements conducted across 740 ISPs in 202 countries revealed a virtually 0% network interference rate for ECH GREASE requests, with this stability holding true even in highly regulated network environments like China and Russia. Jigsaw noted that closing this privacy gap "makes the internet safer for everyone."

Industry observers will now watch to see if other mobile OS and browser vendors follow Google's lead. By providing data on global network readiness, Google is attempting to establish an industry standard that encourages widespread adoption without the fear of breaking global connectivity.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.