Android 17 encrypts your web traffic so ISPs can't track which sites you visit
Android 17 is closing a privacy loophole that has existed since the early days of mobile internet. Even when a connection is secured with HTTPS, the initial handshake between a phone and a website has always broadcast the destination domain in plain, readable text, meaning internet service providers and anyone else monitoring a network could see exactly which sites a user visits. Google is addressing this with four network security upgrades baked into Android 17, the most significant of which is Encrypted Client Hello, or ECH, which scrambles that handshake data so it is legible only to the intended destination. Built alongside Jigsaw and supported by developers through OkHttp 5.5.0, the feature makes Android the first major mobile operating system to roll out ECH broadly.
The update also takes aim at a specific criminal technique known as SMS blasting, in which bad actors use rogue devices to force nearby phones onto outdated 2G networks and then push phishing messages that bypass modern spam filters. Android 17 allows participating carriers to disable 2G connectivity by default, cutting off that attack path entirely without requiring any action from users. Two additional security upgrades round out the package, together addressing what Google describes as some of the most persistent privacy gaps remaining in how phones connect to the world. Android 17 is not yet released, but the groundwork being laid now, from developer library support to carrier partnerships, suggests these protections will be in place when the update arrives later this year.
No comments:
Post a Comment