September 4, 2026, 1:39 pm | Read time: 2 minutes
Even encrypted websites have left telltale traces so far. With Android 17, Google aims to close this gap and set limits for apps, fraudsters, and insecure mobile networks.
When accessing an encrypted website, internet providers or other observers can often identify which page is being accessed. Android 17 aims to better protect this information with “Encrypted Client Hello,” or ECH. This involves encrypting the connection setup to conceal which website the smartphone intends to contact.
Also of interest: Google introduces new app limits due to rising RAM costs
Together with private DNS, which is an encrypted name resolution on the internet, ECH is intended to better shield browsing activities. However, the protection does not work fully automatically in every case. The website being accessed must also support the technology to keep its name hidden during the connection setup.
Apps Need Access to the Home Network
Google is also tightening the rules for apps on home Wi-Fi. Some applications can currently detect which TVs, cameras, gaming consoles, or other devices are connected to the network. This can potentially reveal information about a household’s setup.
Under Android 17, apps will need to request permission before searching for or interacting with other devices on the home network. Functions like casting a video from a smartphone to a TV will still be possible. However, the respective app will no longer automatically need to scan the entire local network.
More Protection Against Fraud and Insecure Networks
Android 17 is also designed to more easily detect manipulated websites. The system requires that websites’ security certificates be registered in a public directory. This should make it easier to spot fake or manipulated certificates that criminals use to make a website appear legitimate, as Google explains in its “Security Blog.”
Google is also targeting old 2G mobile networks. Attackers can deliberately push smartphones from LTE or 5G back to the older standard and then slip phishing SMS past modern security filters. Android 17 allows mobile providers to disable 2G for their customers by default, without users having to change any settings themselves.