Android 17 Adds Privacy Feature to Hide Browsing Destinations, but It Has Limits

Aug 30, 2026 08:41 Written by Yasir Arafat android privacy google technology security
Android 17 Adds Privacy Feature to Hide Browsing Destinations, but It Has Limits

Android 17 Rolls Out Encrypted Client Hello

Google has enabled a new privacy feature in its latest operating system, Android 17. The update adds support for Encrypted Client Hello, a standard designed to hide the specific website a user is visiting from their internet provider and other network observers.

Google published a security post outlining the change on Wednesday. The company describes this as the first major rollout of this privacy standard on a mobile operating system. Google built the feature with its Jigsaw team and outside developers.

While the feature improves privacy for Android users, it does not completely hide browsing activity. Protection only works when the destination website or app has also adopted the encryption standard.

How the Encryption Works

When a phone connects to a website over HTTPS, the content of the page is scrambled. However, a part of the connection setup called the Server Name Indication still travels in plain text. This field identifies the domain being visited, allowing every node between the phone and the server to read and log the destination.

Encrypted Client Hello, often shortened to ECH, seals that field. The phone encrypts the site name using a key published by the destination server. Only that specific server can decrypt and read the name.

For anyone else monitoring the network, the label appears meaningless rather than showing the actual domain. This protection runs on top of private DNS, which already hides the step where a website name is converted into an IP address.

Adoption Limits and Observer Data

  • ECH only protects traffic to destinations that have adopted the technology.
  • Google is urging developers to upgrade to OkHttp 5.5.0 to enable the feature.
  • Until more sites upgrade, requests to non-ECH websites will still reveal their domain to carriers and Wi-Fi operators.
  • Network observers can still see the destination server's IP address and the volume of data being transferred.
  • An observer can infer general activity levels even when the specific site name is hidden.

What the Official Source Says

In its security post, Google limited its claims to "supported websites and apps." The company explicitly noted that a destination which has not switched on Encrypted Client Hello will still expose its domain name to the network.

Why This Matters for Device Privacy

This update represents a shift in how mobile operating systems handle user data at the network level. By default encrypting the destination name, Android 17 prevents casual surveillance by internet service providers and network operators. However, because the encryption relies on cooperation from website owners, the privacy gain is currently partial rather than absolute.

Sources

YA
Written by

Yasir Arafat

Owner & Developer
View all posts

Yasir Arafat is a software developer and the founder of Newisty, covering web development, software, online tools and digital technology. He also oversees Newisty's publishing, technical development and editorial process.


Comments (0)

Leave a comment
Your comment will appear publicly after submission.
No comments yet. Be the first to comment!