{
  "id": 3750108,
  "title": "Android 17 boosts network security by hiding domain names, lets carriers disable 2G",
  "url": "https://urgent.news/2026/08/27/android-17-boosts-network-security-by-hiding-domain-names-lets",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-27T14:00:00.000Z",
  "source": {
    "name": "9to5Google",
    "slug": "9to5google",
    "url": "https://9to5google.com/2026/08/27/android-17-network-security/"
  },
  "original_language": "en",
  "account": "Google announced in its latest blog post the new network security measures introduced in Android 17. Despite HTTPS connections, the domain names of websites are still exposed to network operators and eavesdroppers, posing risks to user privacy. To address this issue, Android 17 introduces Encrypted Client Hello (ECH), a privacy standard that hides domain names using a secret encryption key. This way, network providers and eavesdroppers can no longer easily identify the websites or apps being accessed by users.\n\nTo take advantage of ECH, app developers must upgrade to OkHttp 5.5.0 and enable the feature. Currently, Android 17 OS supports ECH, but developers must implement it in their apps. The new standard aims to protect user data in two key areas: the initial DNS lookup and the unencrypted ClientHello in the Transport Layer Security (TLS) handshake.\n\nIn addition to ECH, Android 17 enables mobile carriers to automatically disable 2G connectivity as a defensive measure against SMS blaster attacks. These attacks force nearby smartphones to drop their LTE or 5G connections and switch to less secure 2G networks. Once connected to a 2G network, users might receive phishing texts, making them vulnerable to scams.\n\nAndroid 17 also introduces Local Network Protection, a feature requiring apps to request permission before scanning or connecting to other devices on the local network. This safeguard ensures that apps do not accidentally access other devices in the user's home without explicit permission.\n\nLastly, Android 17 enforces Certificate Transparency, requiring all digital certificates to be logged in a public registry. This transparency makes it easier to detect and prevent attacks involving compromised certificate issuers. When connecting to a secure app or website, users' devices verify certificates to confirm the site's authenticity. However, if a certificate issuer is compromised, hackers could potentially create fake certificates, intercepting user traffic and causing harm.",
  "summary": "Google is out with a blog post today recapping new network security measures in Android 17.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}