Google adds Encrypted Client Hello, certificate transparency, and optional carrier 2G shutdowns in Android 17

Google says Android 17 adds new built-in network protections that make web browsing harder to track and reduce exposure to mobile-network attacks. The update adds platform-level support for Encrypted Client Hello (ECH) to hide visited hostnames in the opening TLS connection step, enables certificate transparency checks by default, tightens local-network app permissions, and lets participating mobile carriers automatically disable 2G to reduce risks from rogue base stations and SMS blasters.
Why it matters: This matters because it is a broad security and privacy change for Android users rather than a marketing feature: it can reduce web tracking, expose forged website certificates more quickly, and lower risk from legacy 2G-based interception attacks. Users and organizations planning Android 17 deployments should expect improved defaults, while app developers and carriers may need to verify compatibility and adoption.

Sources

Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers
info@thehackernews.com (The Hacker News) 2026.08.28 97% relevant
This article appears to cover the same Android 17 security event, specifically the OS-wide rollout of Encrypted Client Hello that hides visited websites from internet providers and other network observers.
Android 17 adds ECH support to make web browsing harder to track
Bill Toulas 2026.08.27 100% relevant
This article establishes a distinct Android 17 security/privacy platform update story centered on Google's rollout of ECH, certificate transparency by default, stricter local-network access controls, and carrier-enabled 2G shutdowns.
← Back to all stories