Security4 distinct publishers2 min readPublished Updated
Google's Encrypted Client Hello rollout, wrapped in GREASE decoys so protected sessions look like everything else, removes the plaintext domain that SNI-based logging keys on. Jigsaw reports near-zero interference even in Russia and China.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
The field that goes dark is the plaintext domain name in the TLS handshake, the one Google's own engineers describe as readable by network operators and eavesdroppers even when the session is encrypted [1]. ECH wraps it in a key only the destination server holds [2], so an on-path device stops reading the name [8]. Nick Sullivan, co-author of the standard, called Android support a step toward closing one of the largest remaining structural privacy holes on the internet [16]. For a filtering appliance, it is the removal of the field the policy is written against.
GREASE is the part with operational teeth. Because server-side support is uneven, Android sends decoy encrypted extensions on connections that are not protected at all, so an observer cannot separate the two by shape [3]. A rule that flags or drops handshakes carrying an ECH-shaped extension therefore lands on ordinary traffic from any app built on a supporting library, which turns a targeted control into a blanket one [9].
This arrives gradually. ECH is on by default only for apps that target Android 17 and run on a library that supports it, listed as newer OkHttp, WebView and HttpEngine [5], and web server support is still patchy [3]. The announcement was reported on 28 August 2026 [0], with Google claiming Android is the first major mobile operating system to ship broad ECH support [15]. The loss of domain visibility tracks two curves defenders do not control: app retargeting and server adoption.
Jigsaw's validation was about connectivity, not about enterprise policy. One test pushed GREASE requests at the top 10,000 domains and found success rates level with ordinary TLS [6]. The second covered 202 countries and 740 ISPs, including Russia and China, with interference near zero [7]. That averages roughly 3.7 ISPs per country [10], wide coverage and thin per market, and the reported scope is consumer ISP paths rather than corporate middleboxes configured to require a readable domain [11]. Networks that fail closed on unfamiliar TLS extensions were not the population under test.
Three other changes shipped alongside. Local Network Protection makes apps request permission before scanning or connecting to other devices on the local network [4], which matters if you run device discovery or printer apps on BYOD handsets. Certificate Transparency on by default [13] and operator-side 2G shutoff for subscribers [14] are straight gains that cost monitoring teams nothing. ECH is the only item on the list that takes something away from the defender's side of the wire.
Ranked by verification strength, evidence, and original report placement.
Helpnetsecurity reported Google's Android 17 network security changes on 28 August 2026.
Android 17 adds support for Encrypted Client Hello, which encrypts the domain name with a key only the destination server can unlock and works together with private DNS to keep the destination hidden from outside observers.
Because ECH support among web servers is still uneven, apps and browsers also send GREASE, a decoy version of the encrypted extension, so an outside observer cannot tell which connections are protected just by looking at their shape.
Local Network Protection in Android 17 makes apps ask before they can scan or connect to other devices on the user's local network, closing a route apps used to profile a household via smart TVs, cameras and consoles.
For apps targeting Android 17, ECH turns on by default as long as the app runs on a networking library that supports it, such as newer versions of OkHttp, WebView or HttpEngine.
Google software engineer Bram Bonne and product manager Shuaibo Huang said that when a user visits a website or uses an app, even if the connection is encrypted by HTTPS, the domain names of the sites visited remain visible to network operators and eavesdroppers, and that this unencrypted data can be used to build user profiles or for targeted phishing and scam campaigns.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One blog post, four bylines
Every technical assertion here — the encrypted field, the decoy extensions, the two test results — originates in Google's announcement and Jigsaw's companion report. The four publishers are consistent because they are downstream of the same document: SC World says so explicitly by crediting BleepingComputer, and The Hacker News appears twice in our coverage. Where the accounts drift apart, on Firefox versions, nobody checked. The mechanism claims are strong on their merits; the sourcing is a single stream.
Default-on behind two upgrades
The default is real but doubly conditional: an app has to target Android 17 and ride a recent OkHttp, WebView or HttpEngine. OkHttp shipping ECH in its core library is the most concrete adoption fact in the coverage. Against that, GREASE exists precisely because server-side support is patchy, and no publisher offers a device figure, an app count, or the name of a single participating carrier for the 2G switch. Browsers got here first; this is the platform catching up.
Reach oversold, residue undersold
Two things pull in the same direction. Google's first-major-mobile-OS line and Sullivan's largest-remaining-structural-hole framing sit alongside the fact, which only The Hacker News supplies, that ECH has been in Chrome and Firefox for years. And the residue goes largely unexamined: hiding the destination depends on private DNS, so a network still doing resolution for the phone keeps the domain, and on servers without ECH the hostname travels in the clear behind the decoy. Modest overstatement rather than vapour — the mechanism does what is claimed, within limits the coverage mostly leaves offstage.
Announcer, tester and cheerleader under one roof
Google ships the feature, Google's Jigsaw runs the validation, Google's engineers and its Android security VP supply the quotes, and the external endorsement comes from a man who co-wrote the standard and founded a cryptography consultancy. There is also a commercial seam in the reporting itself: BleepingComputer's piece ends in a pitch for a vendor simulation report, and SC World's closes on a network-security marketing line. None of this makes the ECH claims wrong; it does mean nobody in the chain has an interest in finding the seams.
Confident on mechanism, thin on consequences
What ECH and GREASE do is described the same way by every publisher and matches the standard, so we hold those claims firmly. Our confidence falls off sharply past the mechanism: adoption breadth, enterprise-network behaviour, DNS-path residue and abuse by malware on the same default libraries are all inference rather than reporting here.
product
Android 17 encrypts the field enterprise web filters read1 distinct publisher
security
IETF Publishes Encrypted Client Hello as a Standard to Encrypt SNI, With Caveats1 distinct publisher
product
LineageOS 23 reaches the Galaxy S22 with about six months left on Samsung's clock1 distinct publisher
build
The exit ping that never left: fetch in beforeunload loses to the browser's unload policy1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
bleepingcomputer.com
1 article · August 27, 2026
helpnetsecurity.com
1 article · August 28, 2026
scworld.com
1 article · August 28, 2026
thehackernews.com
2 articles · August 29, 2026