Google has introduced platform-wide support for Encrypted Client Hello (ECH) on Android 17, adding another important layer of privacy for people browsing the internet on mobile devices.
The move makes Android 17 one of the first major mobile operating systems to support the emerging internet privacy standard at the platform level. According to Jigsaw, Alphabet’s technology incubator focused on addressing global security and information challenges, ECH helps close a significant privacy gap that still exists even when users visit websites protected by HTTPS.
While HTTPS encrypts the connection between users and websites, certain information about where users are connecting can still be visible to internet service providers and network operators. Encrypted Client Hello is designed to reduce that exposure.
With ECH enabled, Android users can gain stronger protection against certain forms of browsing surveillance and tracking.
What Is Encrypted Client Hello?
Encrypted Client Hello, commonly known as ECH, is an internet privacy technology designed to encrypt additional information during the early stages of a secure connection between a device and a website.
When a user opens a website, the device and server must exchange information before the encrypted connection is fully established.
Historically, some of that information could reveal the destination website or service being accessed, even when the website itself used HTTPS encryption.
This creates a privacy concern.
An internet service provider might not be able to read the contents of an encrypted webpage, but it could potentially determine which websites or online services a person is visiting.
ECH is designed to close that gap by encrypting information about the destination earlier in the connection process.
Why HTTPS Alone Isn’t Always Enough
HTTPS is one of the most important technologies protecting modern internet traffic.
It helps encrypt information sent between a user’s device and a website, protecting sensitive data such as:
- Login information
- Messages
- Payment details
- Personal information
- Website content
However, HTTPS does not necessarily hide every piece of metadata connected to an internet connection.
Network providers can sometimes still identify information related to the websites and services a user is accessing.
This information can potentially be used to create browsing profiles, support targeted advertising or reveal valuable information to malicious actors.
For example, knowing which websites or services a person frequently visits can provide clues about their interests, activities and online behavior.
ECH adds another layer of protection by reducing the amount of destination information exposed during the connection process.
How Encrypted Client Hello Protects Android Users
With ECH enabled, the destination information associated with a website connection is encrypted earlier in the communication process.
In many cases, an internet service provider may only be able to see information related to the website’s infrastructure, such as its content delivery network, along with general traffic patterns and the amount of data being transferred.
For example, a network provider might see that a user is connecting through a major CDN provider such as Cloudflare, but ECH can help prevent the provider from easily identifying the specific website or application being accessed.
This makes it more difficult for network operators to track browsing activity based solely on destination information.
The technology can also help reduce certain privacy risks connected to:
- Browsing surveillance
- User profiling
- Network monitoring
- Targeted tracking
- Phishing intelligence gathering
ECH does not make users completely anonymous online, but it can significantly strengthen privacy when combined with other security technologies.
ECH Will Be Enabled by Default on Android 17
One of the most important aspects of Google’s implementation is that Encrypted Client Hello will be enabled by default on Android 17.
This means users will not necessarily need to manually configure the feature to receive its privacy benefits.
Making advanced security features available by default can be especially important because many users do not regularly change network settings or understand the technical differences between encryption standards.
By integrating ECH at the platform level, Google is helping bring the technology closer to mainstream adoption.
The wider the adoption of privacy standards like ECH, the more difficult it can become for third parties to rely on unencrypted connection metadata for tracking internet activity.
What ECH Does Not Protect
While Encrypted Client Hello is an important privacy improvement, it does not solve every internet privacy problem.
ECH should not be confused with a VPN or a complete anonymity tool.
ECH Does Not Hide DNS Requests
DNS, or the Domain Name System, is responsible for translating website names into numerical IP addresses that computers can understand.
For example, when you enter a web address into a browser, your device must determine where that website is located on the internet.
ECH does not automatically encrypt those DNS requests.
To protect DNS lookups, users may need to use encrypted DNS technologies such as DNS over HTTPS or DNS over TLS, depending on the device and network configuration.
ECH Does Not Hide Your IP Address
Your IP address can still be visible to websites and network services.
ECH is not designed to hide a user’s location or identity in the same way that a VPN can.
A virtual private network routes traffic through another server, helping mask the user’s original IP address from the destination website.
ECH focuses on a different part of the privacy equation: protecting destination information during the establishment of encrypted connections.
ECH, Encrypted DNS and VPNs Serve Different Purposes
Internet privacy involves multiple layers of protection.
ECH is one piece of that larger security system.
Encrypted Client Hello
Helps protect information about the destination website during the early stages of a secure connection.
Encrypted DNS
Helps prevent network providers from easily viewing DNS lookups that reveal which domains a device is trying to access.
VPN
Routes internet traffic through a separate server and can hide a user’s original IP address from the websites they visit.
Using multiple privacy technologies together can provide stronger protection than relying on any single feature.
Android 17 Is Also Improving Mobile Security
ECH is not the only security-related improvement coming to Android 17.
Google has also been introducing new protections designed to address weaknesses in older mobile network technologies.
One example is a security feature that allows mobile carriers to disable 2G connections by default.
While 2G networks remain available in some regions, they use older technology that can be more vulnerable to modern attacks.
SMS blasters and other malicious systems can exploit legacy cellular networks to bypass some modern spam protections and deliver unwanted or fraudulent messages.
Reducing unnecessary access to older network standards can help limit those risks.
The continued presence of legacy technologies remains one of the major security challenges facing modern mobile devices.
Why Android 17’s ECH Support Matters
The introduction of platform-wide ECH support represents an important step toward improving everyday internet privacy.
Most users assume that visiting an HTTPS website means their online activity is completely hidden from network providers.
In reality, internet privacy is more complicated.
HTTPS protects the contents of a connection, but other technical information can sometimes reveal details about a user’s online activity.
ECH helps close one of those gaps.
The technology also highlights a broader shift in the internet industry toward encrypting more metadata rather than only protecting the content of communications.
As governments, companies and network providers collect increasing amounts of digital information, reducing unnecessary exposure of browsing data is becoming more important.
The Future of Internet Privacy on Android
Android 17’s support for Encrypted Client Hello could encourage broader adoption of the standard across mobile devices, browsers and internet infrastructure.
Privacy technologies are most effective when they are widely supported.
If only a small number of devices use advanced encryption standards, those connections can sometimes stand out. Widespread adoption helps make privacy protections more normal across the internet.
Google’s decision to enable ECH by default is therefore particularly significant.
For Android users, the feature may operate largely in the background, providing stronger protection without requiring complicated configuration.
Final Thoughts
Google’s introduction of Encrypted Client Hello support in Android 17 is an important step toward improving mobile internet privacy.
ECH helps address a long-standing gap by encrypting more information about where users are connecting online. While HTTPS protects the contents of internet traffic, ECH can help prevent internet service providers and other network operators from easily identifying the specific websites and services being accessed.
However, ECH is not a complete privacy solution.
It does not hide DNS requests, conceal IP addresses or provide the same protection as a VPN. Users who want stronger privacy should understand how technologies such as encrypted DNS, VPNs and secure browsing tools work together.
Still, by making ECH available across Android 17 and enabling it by default, Google is helping move an important internet privacy standard closer to mainstream adoption.
As online tracking becomes increasingly sophisticated, adding more layers of encryption to everyday internet connections could become an essential part of protecting users’ digital privacy.



























