Google has introduced enhanced network security features in Android 17, including Encrypted Client Hello support and stricter local network permissions to better protect user privacy and prevent malicious attacks.
Key Points
- Android 17 implements Encrypted Client Hello (ECH) to hide domain names from network operators and eavesdroppers during the initial connection handshake.
- App developers must upgrade to OkHttp 5.5.0 and enable ECH to ensure destination website names remain encrypted and private.
- Mobile carriers can now disable 2G connectivity by default to prevent SMS blaster attacks that force devices onto insecure legacy networks.
- New local network protection requires apps to request explicit user permission before scanning or connecting to other devices on a home network.
- Certificate Transparency requirements now mandate that all security certificates be logged in a public registry to detect and prevent the use of fraudulent credentials.