Google is shipping Encrypted Client Hello (ECH) support across Android 17 so network observers cannot easily read which HTTPS sites you open from the first handshake packet. The Hacker News coverage of Google’s announcement says ECH works with private DNS to hide destination domain metadata that ISPs and snoopers use for profiling. Google’s Jigsaw notes real servers need ECH keys, and that Android will enable ECH GREASE by default — sending decoy ECH extensions even to non-ECH sites so protected traffic does not stick out.
Chrome and Firefox already had browser-level ECH; Android 17 pushes the idea into the OS networking stack, with OkHttp adding library support for apps. Practical caveat: protection is strongest when both the OS path and the destination support ECH — but default GREASE still raises the bar for casual network surveillance on phones.
Source: https://thehackernews.com/2026/08/android-17-adds-os-wide-ech-to-hide.html