Urgent.News

What's breaking now, across thousands of outlets.

Tech

How Android 17 stops network snoops and SMS blasters now - with ECH and a 2G kill switch

The latest Android 17 update adds broad support for Encrypted Client Hello, among other changes. Here's how they work.

Google has introduced several new security features in Android 17 to protect users' online privacy and prevent malicious network connections. One of these features is Encrypted Client Hello (ECH), which encrypts the destination website name in the opening TLS handshake. This prevents network providers and snoopers from easily identifying which websites or apps a user is accessing.

ECH is still being rolled out, so even if a phone supports it, the connection may still be unsafe. Google recommends using Private DNS in conjunction with ECH for optimal privacy protection. However, ECH does not hide all traffic metadata, such as the destination IP address or traffic volume.

Another security feature in Android 17 is a 2G kill switch, which disables 2G connections at the radio-hardware level upon request from participating mobile carriers. This is to protect users from SMS blasters and false cellular base stations that can persuade phones to connect through older 2G technology, making them vulnerable to phishing texts and downgrade attacks.

While 2G is no longer supported by major carriers in the US, it is still used in many countries worldwide. Disabling 2G can affect roaming coverage, so users should be aware of this trade-off.

Written by urgent.news from ZDNet's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at zdnet.com →

More in Tech

Security updates for Monday

Security updates have been issued by Debian (kernel, libarchive, libdbi-perl, libnet-dns-perl, librabbitmq, roundcube, starlette, and xrdp), Fedora (bluez, postgresql16-anonymizer, pyOpenSSL…

More from Monday 31 August →