Android 17 enhances communication privacy, supporting ECH (Electronic Communication Interface) to hide 'where you're accessing' and 2G fraud prevention.

Google has announced network-related security enhancements introduced in Android 17. In addition to support for 'Encrypted Client Hello (ECH),' which makes it easier to hide the domain name of the destination when using HTTPS communication, the update includes features such as access permission restrictions for home LANs, countermeasures against fraudulent digital certificates, and measures against SMS scams via 2G that exploit fake base stations.
Android 17 introduces 4 new network security features

On smartphones, HTTPS is used for most web browsing and app communication. With HTTPS, communication content is encrypted, so third parties on the same network cannot easily read what is being sent and received. On the other hand, even when using HTTPS, the information of 'which domain you are trying to connect to' is not encrypted, and even if the communication content itself cannot be read, the name of the service being used can be a clue to inferring the user's behavior.
Android 17 introduced Encrypted Client Hello (ECH) as a mechanism to make it easier to conceal the destination of your connections. ECH is an extension of TLS, an encryption technology used in web communications, and it encrypts information called Server Name Indication (SNI) that is sent when a connection is initiated. Since the SNI includes the domain name of the connection you want to make, using ECH makes it more difficult for others on the network to identify your destination.
Furthermore, Google explains that combining Android's private DNS with ECH reduces the possibility of destination domains being leaked through both DNS queries and HTTPS connections. However, simply updating to Android 17 does not automatically hide all destination domain names; ECH requires that the communication libraries used by the app and the servers it connects to also support ECH.

Android 17 changes how apps handle devices connected to their home or office LAN, not just those on the internet. In previous versions of Android, apps that could connect to the internet could find TVs, game consoles, smart home devices, and other devices on the same LAN. While this is a necessary feature for apps that cast videos to a TV, it also allows for the possibility of inferring the user's living environment from information about the devices on their LAN.
As a countermeasure, Google has begun fully implementing 'Local Network Protection' starting with Android 17, which restricts access to local networks. Apps targeting Android 17 and later need to obtain the 'ACCESS_LOCAL_NETWORK' permission to directly access devices on the LAN. As a general rule, apps that directly access the LAN require the user's permission, making it easier to prevent apps from secretly accessing devices in your home network.
For casting to a TV, for example, you can use the device selection screen provided by Android. This allows the app to only communicate with the device selected by the user, thus reducing the amount of information that the app receives.

Furthermore, Android 17 strengthens the protection of digital certificates used in HTTPS communication. HTTPS uses digital certificates issued by certificate authorities to verify the authenticity of a website. However, if a certificate authority issues a certificate incorrectly or is compromised by an attack, fraudulent certificates could be misused.
Apps targeting Android 17 and later will have Certificate Transparency (CT) enabled by default, which records issued certificates in a public log for verification.
Furthermore, Android 17 includes enhanced protection against SMS scams that exploit 2G communication. 2G is an older mobile communication method that has been in use since the 1990s and has weaker security aspects compared to 4G and 5G. While an increasing number of carriers are discontinuing their official 2G services, some smartphones still retain the functionality to connect to 2G.
Attackers sometimes use fake base stations, sometimes called 'SMS blasters,' to force nearby smartphones to switch to 2G networks. After forcing the switch to 2G, they send fake SMS messages that direct users to phishing sites disguised as banks or delivery companies.

Android has had a feature to disable 2G communication since Android 12, but users had to change the settings themselves. Android 17 adds a mechanism that allows mobile carriers to disable 2G connectivity for subscribers from the start, making it easier to prevent fake base stations from redirecting users to 2G.
Google states that it will continue to update Android's protection features to address new network-based threats.
Related Posts:
in Smartphone, Security, Posted by log1d_ts







