Google is adding platform-level TLS Encrypted Client Hello (ECH) support in Android 17, enabling compatible apps targeting the release to encrypt hostname metadata—including Server Name Indication (SNI)—during TLS handshakes. Used alongside Private DNS, ECH reduces ISPs’, Wi-Fi operators’, and other passive observers’ ability to identify websites and services users access; ECH GREASE will also generate cover traffic when a destination does not support ECH.
The implementation follows RFC 9849, which standardizes ECH’s encryption of an inner ClientHello under a server public key and specifies anti-downgrade, retry, and denial-of-service safeguards. Android 17 will additionally require permission for app local-network discovery and connections, enable Certificate Transparency by default, and allow participating carriers to disable 2G automatically to reduce exposure to rogue base stations and SMS blasters.

See the reporting duties and controls this puts on the clock.
4 events from the most recent confirmed update back to the earliest known activity.
OkHttp released opt-in Encrypted Client Hello support, allowing compatible Android 17/API 37 TLS stacks to encrypt the requested domain name during TLS connections. The release added HTTPS DNS resource-record retrieval for ECH and warned that AndroidDns lookups are unencrypted by default.
Google announced mandatory verification requirements for Android application developers, under which verified developers can distribute apps through Google Play and alternative channels. The company said rollout is scheduled to begin in September 2027.
Google announced Android 17 platform support for ECH, enabled by default for Android-17-targeting apps using compatible networking libraries. The announced protections also include local-network access permissions, Certificate Transparency by default, and optional carrier-led automatic 2G disablement.
The IETF published RFC 9849 as a Standards Track specification for TLS Encrypted Client Hello (ECH), defining encryption of ClientHello metadata such as SNI and ALPN using HPKE.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
18 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcezdnet.fr
Open sourcezdnet.com
Open sourcexakep.ru
Open sourcegithub.com
Open sourcerfc-editor.org
Open sourcecertificate.transparency.dev
Open sourcedatatracker.ietf.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.