Search results for

All search results
Best daily deals

Affiliate links on Android Authority may earn us a commission. Learn more.

Android 17 has some new tricks to keep your web traffic private

Here's how Android 17 is locking down your network traffic from prying eyes.
By

Aug 27, 2026 — 10:00 AM ET

The Android 17 logo on a Pixel phone.
Joe Maring / Android Authority
TL;DR
  • Google’s implementing a number of new network security upgrades for Android 17.
  • Encrypted Client Hello attempts to solve DNS privacy problems by encrypting server lookups.
  • SMS Blaster protection empowers carriers to block low-security 2G connections by default.

Keeping mobile devices secure is one of those jobs that never end, and when it comes to security in Android, Google finds itself constantly working to lock our phones down against external threats. With Android 17, the company’s already highlighted some of the big ways it’s been improving security, and today Google has a few more updates to share on how your phone is becoming more secure and private that ever.

Android 17 makes a number of changes to how devices work with network traffic. One big privacy-protecting one there impacts how apps are able to see your home’s local network, preventing them from probing it for fingerprinting or even spotting vulnerable network hardware. Another we knew about implements Certificate Transparency by default, helping ensure that your phone uses the proper SSL certificates for the server it’s trying to communicate with.

You may be familiar with “stingray” devices used by police to simulate cellular towers and gather information to help them identify and track phones. Android’s been building up its defenses against devices like those and now that’s extending to new protections against similar SMS Blaster attacks, using fake towers to send spammy or even malicious texts. Specifically, Android 17’s now giving carriers the ability to activate those defenses without you needing to do a thing.

Those are all great, but the big news here is arguably support for a protocol known as Encrypted Client Hello (ECH). Encryption can already keep much of our data traffic safe from prying eyes, but there’s long been a loophole: DNS. Before we even start transmitting that data, DNS needs to look up the IP address of the server we’re trying to reach, and that bit was historically done in the clear — anyone spying on your web traffic could see the name of the site you’re trying to reach.

Privacy advocates have been trying to shut that loophole down with technologies like DNS-over-TLS, and now ECH represents the next level there, encrypting server names while in transit. And because not every site is going to support ECH straight away, it even sends random garbage data when not supported, just so anyone monitoring your connection can’t gain any extra insight into the types of sites you’re trying to reach.

Google says that Android 17 represents the first major mobile platform to broadly embrace ECH, and the hope is that by creating this big user base ready and eager to take advantage of its protections, that should only encourage more server admins to get it working on their end, too. When properly deployed, that promises to offer a safer and more private internet for all of us.

Follow

Thank you for being part of our community. Read our Comment Policy before posting.