If you care about privacy—especially when your browsing could reveal which crypto exchanges, wallets or services you visit—Android just took a meaningful step forward. Google’s Android 17 now enables Encrypted Client Hello (ECH) by default, a new TLS feature that hides a key piece of metadata that previously leaked every time you opened a secure site. What ECH does (and how it helps) - Today, when your phone opens an HTTPS page the TLS handshake includes a field called the Server Name Indication (SNI) that plainly states the domain you’re visiting. Any router, ISP, or network node between you and the server can read and log that name. - ECH encrypts that field. The client encrypts the site name to a public key the destination server publishes; only that server can decrypt it. To the rest of the path, the SNI becomes a meaningless label, not a readable domain. - ECH works alongside private DNS (which hides the DNS lookup that maps names to IPs), so together they reduce two common ways your browsing destinations are exposed. Important limits — it’s not full anonymity - ECH only protects connections to destinations that have implemented it. Google frames the change as applying to “supported websites and apps,” and it’s urging developers to update libraries—specifically to OkHttp 5.5.0—and enable ECH. - If a site hasn’t adopted ECH, the SNI is still visible in the clear. - Even with ECH enabled, observers can still see the destination IP address, the timing and size of connections, and the fact that a connection occurred. That metadata can let an observer infer activity at a coarse level even when the domain label is hidden. In short: ECH locks the label, it doesn’t remove the fact that a connection happened. Why crypto users should care - For cryptocurrency users, metadata leaks can be sensitive: visiting an exchange, custodial wallet, or blockchain analytics site can be revealing. ECH reduces one straightforward fingerprint—the visible domain name—that an on-path observer could glean from mobile traffic. - But because IPs and traffic patterns remain visible, ECH is a meaningful privacy improvement rather than a complete privacy solution. Combined privacy practices—updating apps, using private DNS, choosing ECH-supporting sites, and, where appropriate, privacy tools like VPNs or Tor—still matter. Rollout and developer notes - Google announced the change in a security post and is pushing developers to adopt OkHttp 5.5.0 to enable ECH in apps that make web requests. - Until broader adoption spreads across servers, apps and websites, users will only see limited benefits. Other Android 17 privacy moves - Android 17 also turns on Certificate Transparency by default (improving detection of misissued TLS certificates). - Apps must now ask permission before scanning a local network—another small but useful restriction that reduces background discovery of nearby devices. Context: device-level privacy and the law - Google’s timing comes as phone-level privacy tools face legal scrutiny. Samuel Tunick, an Atlanta activist, is the first known American charged under federal law for allegedly using a duress password built into GrapheneOS, a hardened Android fork that can erase itself when a code is entered. GrapheneOS maintains the software is legal and constitutionally protected as the case proceeds. - Tunick told the New York Times: “I just hope to send the message that the government doesn’t own our data.” That dispute highlights how privacy features and their legal context intersect for users who prioritize control over phone data—including many in the crypto community. Bottom line Android 17’s ECH rollout is a real privacy win for mobile browsing: it removes a clear and easy leak of which domains a device visits. But it’s a partial fix—effective only when servers and apps support it, and unable to hide network-level metadata like IPs and traffic volume. For crypto users who want stronger privacy guarantees, ECH is a helpful layer, but not the whole strategy—keep devices updated, encourage sites and apps to adopt ECH, and combine it with other privacy tools as needed. Read more AI-generated news on: undefined/news