AMD Lenovo ThinkCentre X Ultra Mini PC Ships for $3,699 with 131 TOPS AI Compute PLAYSTATION 5 Crimson Moon Launches on PC and Consoles With 10K+ Day-One Players PHONES Vivo X500 Gets Pro Camera Specs: Lytia-828 Main, 64MP Telephoto PLAYSTATION 5 GTA 6 on PS5 vs GTA 5 Enhanced PC: Ray Tracing and Asset Comparison NINTENDO SWITCH 2 Inti Creates Teases New Game for Nintendo Switch 2 at TGS 2026 PLAYSTATION 5 Keeper PS5 Trophy List Surfaces, Hinting at Console Port NINTENDO Nintendo Switch 2 Sharp LCD Panel Surfaces, OLED Release Delayed to 2026 NINTENDO SWITCH Qliphah in Providence’s Shadow Launches September 24 on PS5, Switch, PC AMD The Blood of Dawnwalker PC Stutters, 30FPS Cinematic Cap at Launch NINTENDO Happinet Announces Lost Museum: Echoes of the Chromageists for Switch 2 and PC GAMES Tomb Raider: Catalyst Confirms Survivor-Era Lara Croft Return GAMES Battlefield 6 Datamine Reveals Dead Space Skins for Halloween PHONES Samsung Galaxy S27 Edge Rumors: Slimmer 4mm Design or 6.8-inch Screen? PC HARDWARE Ubiquiti Whole Home WiFi 7 Mesh Starts at $214 for Tri-Band Coverage

Android 17 Enforces Encrypted Client Hello for New Apps

Simon Ellis 0 comments 2 min read

Android 17 enforces Encrypted Client Hello for new apps and restricts Wi- Fi scans, while carriers can disable 2G to prevent SMS blaster attacks.

Google Android 17
ANDROID

Google released Android 17 in June with four new network protections designed to tighten security for users. These changes matter because they shift how apps handle private data, specifically by encrypting browsing destinations and restricting background Wi-Fi scans. Developers building for the new version will see immediate effects, while those sticking to older standards may face reduced privacy features.

New encryption and permission rules target apps built for API level 37

The operating system targets apps that explicitly support Android 17, which corresponds to API level 37. This versioning creates a clear divide in how network traffic is handled. Applications built for Android 16 or earlier do not receive the new encryption protections on Android 17 devices. Users running older apps will see their network requests sent without the latest security wrappers.

Encrypted Client Hello (ECH) is now enabled for apps targeting Android 17. This feature encrypts the destination hostname during TLS handshakes, preventing third parties from seeing which websites users visit. The protection does not extend to apps targeting Android 16, which receive no ECH encryption on these devices. Developers using the OkHttp 5.5.0 library can enable this support, though it remains an optional feature that requires explicit configuration.

Android 17 introduces a new permission requirement for apps that scan for Wi-Fi devices. This restriction applies only to apps targeting Android 17, limiting background discovery capabilities for older software. Carriers can also use a switch available since Android 12 to turn off 2G networks for their customers. This move helps prevent SMS blaster attacks, although Google has not named specific carriers that have enabled this feature. We looked at the last Android 17 update, several of the same balance and stability themes came up.

Google published these details in a blog post alongside documentation from Android Developers and the OkHttp Changelog. The company acknowledges that it does not disclose the current adoption rate of Encrypted DNS among websites. It states that it is working with the industry to speed up adoption without providing specific metrics. The update confirms these four specific security mechanisms are active in the June release.

Source: NotebookCheck

Discussion

0 comments

Leave a comment