Google is working directly on a privacy function for web-page connections, Android 17. According to the company on August 27, the new system will support EncyclopedClithello (ECH), which will be used to hide user-accessed site domain names in the early stages of the connection and to reduce the likelihood that network operators, Internet service providers and bystanders will access such information.
Privacy gaps outside HTTPS
Google points out that many users would consider HTTPS as “a total hidden connection”, but it is not. HTTPS can encrypt the data content transmitted between the browser and the website without automatically blocking the domain name of the target. That is, even if the page content is not directly accessible, external observers may still know which site the device is connecting to.
According to the company, such unencrypted connection metadata could be used to create user images or could be used illegally for targeted fishing or fraud. The focus of this adjustment, Android 17, is to fill this layer of chronic exposure.
ECH Encrypt domain names during handshake
The ECH role occurs at the beginning of the handshake of the connection. Google describes a standard that encrypts a target domain with a key that can only be unlocked by the target website. As a result, when traffic passes through the network nodes, it is impossible to see directly from the outside which specific domain name the device is visiting.
The effectiveness of this capacity also depends on whether the website and application support ECH. Google states that system-level support is only the first step and that service providers and developers also need simultaneous access in order for ordinary users to be fully protected.
Android 17 Default Enable ECH GREASE
Besides ECH, Android 17 will default on a matching feature called ECH GREASE. This technology is driven by Jigsaw in order to avoid “only partial connection to use ECH” and to expose additional features.
Jigsaw also sends randomly false ECH extensions to applications and browsers when accessing websites that do not support ECH. In this way, from an external point of view, different connection requests are closer to the same form, making it less difficult to distinguish protected connections through metadata.
For users, this means that even if the target website is not yet fully supportive of ECH, Android 17 provides a default base of privacy protection. Google is equivalent to sinking domain name hidden capabilities to the operating system layer instead of continuing to rely on individual browsers or applications.
