Security1 distinct publisher2 min readPublished
Google's Encrypted Client Hello rollout, wrapped in GREASE decoys so protected sessions look like everything else, removes the plaintext domain that SNI-based logging keys on. Jigsaw reports near-zero interference even in Russia and China.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
The field that goes dark is the plaintext domain name in the TLS handshake, the one Google's own engineers describe as readable by network operators and eavesdroppers even when the session is encrypted [1]. ECH wraps it in a key only the destination server holds [2], so an on-path device stops reading the name [8]. Nick Sullivan, co-author of the standard, called Android support a step toward closing one of the largest remaining structural privacy holes on the internet [16]. For a filtering appliance, it is the removal of the field the policy is written against.
GREASE is the part with operational teeth. Because server-side support is uneven, Android sends decoy encrypted extensions on connections that are not protected at all, so an observer cannot separate the two by shape [3]. A rule that flags or drops handshakes carrying an ECH-shaped extension therefore lands on ordinary traffic from any app built on a supporting library, which turns a targeted control into a blanket one [9].
This arrives gradually. ECH is on by default only for apps that target Android 17 and run on a library that supports it, listed as newer OkHttp, WebView and HttpEngine [5], and web server support is still patchy [3]. The announcement was reported on 28 August 2026 [0], with Google claiming Android is the first major mobile operating system to ship broad ECH support [15]. The loss of domain visibility tracks two curves defenders do not control: app retargeting and server adoption.
Jigsaw's validation was about connectivity, not about enterprise policy. One test pushed GREASE requests at the top 10,000 domains and found success rates level with ordinary TLS [6]. The second covered 202 countries and 740 ISPs, including Russia and China, with interference near zero [7]. That averages roughly 3.7 ISPs per country [10], wide coverage and thin per market, and the reported scope is consumer ISP paths rather than corporate middleboxes configured to require a readable domain [11]. Networks that fail closed on unfamiliar TLS extensions were not the population under test.
Three other changes shipped alongside. Local Network Protection makes apps request permission before scanning or connecting to other devices on the local network [4], which matters if you run device discovery or printer apps on BYOD handsets. Certificate Transparency on by default [13] and operator-side 2G shutoff for subscribers [14] are straight gains that cost monitoring teams nothing. ECH is the only item on the list that takes something away from the defender's side of the wire.
Ranked by verification strength, evidence, and original report placement.
Helpnetsecurity reported Google's Android 17 network security changes on 28 August 2026.
Google software engineer Bram Bonne and product manager Shuaibo Huang said that when a user visits a website or uses an app, even if the connection is encrypted by HTTPS, the domain names of the sites visited remain visible to network operators and eavesdroppers, and that this unencrypted data can be used to build user profiles or for targeted phishing and scam campaigns.
Android 17 adds support for Encrypted Client Hello, which encrypts the domain name with a key only the destination server can unlock and works together with private DNS to keep the destination hidden from outside observers.
Because ECH support among web servers is still uneven, apps and browsers also send GREASE, a decoy version of the encrypted extension, so an outside observer cannot tell which connections are protected just by looking at their shape.
Local Network Protection in Android 17 makes apps ask before they can scan or connect to other devices on the user's local network, closing a route apps used to profile a household via smart TVs, cameras and consoles.
For apps targeting Android 17, ECH turns on by default as long as the app runs on a networking library that supports it, such as newer versions of OkHttp, WebView or HttpEngine.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 28, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
product
LineageOS 23 reaches the Galaxy S22 with about six months left on Samsung's clock1 distinct publisher
product
A fair fight with last year's iPhone is where Pixel hardware has landed1 distinct publisher
product
Pixel 11: a flatter camera bar, seven grams, and a software lockout1 distinct publisher
product
Poland asks Brussels for a €250M Meta fine it has no power to levy1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Specific, but all from one side of the table
The technical detail is unusually concrete for a launch story — named engineers, a named standard co-author, two measurement runs with counts attached — and none of it is independently checked. Google is the subject, the tester (via Jigsaw) and the source of every number, relayed by a single outlet. What holds up regardless of sourcing is the mechanism: ECH plus GREASE genuinely removes the handshake domain, and that part needs no one's word for it.
Switch built, little of it thrown yet
Everything measurable here is capability, not usage. ECH turns on by default only where an app targets Android 17 and its networking library is current; Google itself says server-side support is uneven, which is precisely why the decoys exist. No device numbers, no count of ECH-terminating servers, no named operator behind the 2G shutoff. Jigsaw's runs measure that nothing breaks, which is reachability, not deployment.
Structural hole 'closed' with conditions unread
The language reaches further than the deployment does. Calling this a huge step toward closing one of the internet's largest structural privacy holes sits oddly beside three unmentioned conditions: the destination hides only when private DNS is also in play, the encryption only holds where the far server supports ECH, and the reassuring measurements cover consumer ISPs rather than the inspection gear most enterprise traffic crosses. The mechanism is real; the completeness is oversold.
Vendor announces, vendor's lab validates, standard's author applauds
Follow who benefits from this reading. Google ships the feature, Google's Jigsaw certifies it does no harm, Google's engineering VP frames the certification, and the outside endorsement comes from a consultant who co-wrote the standard now shipping to billions of devices. Help Net Security passes all four through without an adversarial voice — no network operator, no enterprise security team, no competing platform. Nothing here is hidden; it is simply all one interest.
Confident about the mechanism, not the reach
Two different confidences are tangled here. That Android 17 ships ECH with GREASE and that it defaults on under stated conditions is about as firm as a launch claim gets — the vendor has no reason to misstate it and it will be trivially observable on the wire. Whether interference really stays near zero across 740 ISPs, and whether the corporate networks nobody tested behave, rests on one unreviewed measurement from an interested party.