Urgent.News

What's breaking now, across thousands of outlets.

Tech

Android 17 boosts network security by hiding domain names, lets carriers disable 2G

Google is out with a blog post today recapping new network security measures in Android 17.

Android 17 boosts network security by hiding domain names, lets carriers disable 2G

Google announced in its latest blog post the new network security measures introduced in Android 17. Despite HTTPS connections, the domain names of websites are still exposed to network operators and eavesdroppers, posing risks to user privacy. To address this issue, Android 17 introduces Encrypted Client Hello (ECH), a privacy standard that hides domain names using a secret encryption key. This way, network providers and eavesdroppers can no longer easily identify the websites or apps being accessed by users.

To take advantage of ECH, app developers must upgrade to OkHttp 5.5.0 and enable the feature. Currently, Android 17 OS supports ECH, but developers must implement it in their apps. The new standard aims to protect user data in two key areas: the initial DNS lookup and the unencrypted ClientHello in the Transport Layer Security (TLS) handshake.

In addition to ECH, Android 17 enables mobile carriers to automatically disable 2G connectivity as a defensive measure against SMS blaster attacks. These attacks force nearby smartphones to drop their LTE or 5G connections and switch to less secure 2G networks. Once connected to a 2G network, users might receive phishing texts, making them vulnerable to scams.

Android 17 also introduces Local Network Protection, a feature requiring apps to request permission before scanning or connecting to other devices on the local network. This safeguard ensures that apps do not accidentally access other devices in the user's home without explicit permission.

Lastly, Android 17 enforces Certificate Transparency, requiring all digital certificates to be logged in a public registry. This transparency makes it easier to detect and prevent attacks involving compromised certificate issuers. When connecting to a secure app or website, users' devices verify certificates to confirm the site's authenticity. However, if a certificate issuer is compromised, hackers could potentially create fake certificates, intercepting user traffic and causing harm.

Written by urgent.news from 9to5Google's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at 9to5google.com →

More in Tech

More from Thursday 27 August →