Google Android 17 Encrypts Website Visits From ISPs Without VPN

Your ISP can't see the websites you visit, without a VPN.
Android 17 encrypts the initial connection handshake, hiding domain names from network providers.
Mark

So this ECH thing—is it basically a VPN built into Android?

Mimi

Not quite. A VPN routes all your traffic through a third-party server, which means that server sees everything. ECH only encrypts the initial handshake, so your ISP can't see which website you're visiting, but the website itself still knows who you are.

Luke

Right, and that's an important distinction. The ISP still knows you're online and using data. They just can't see the domain name. That's a real privacy gain, but it's not the same as a VPN's broader anonymity.

Mark

Why does it matter that this is built into the OS instead of being an app?

Mimi

Because it applies to everything—email, messaging, any app that connects to the internet. You don't have to remember to turn it on or choose which apps get the protection. It's just there.

Luke

Though it only works if the website's server supports it. We don't know what percentage of the web has deployed ECH yet, so the real-world coverage is still unclear.

Mark

What about the fake base station blocking they mentioned?

Mimi

That's a separate feature that protects against rogue cell towers—devices that pretend to be legitimate towers to intercept connections. It's part of the same privacy push.

Luke

Again, it's a real security improvement, but the details matter. We'd need to know how it detects fake towers and whether it has false positive rates that might cause legitimate connections to drop.

Mark

So Google is basically saying privacy is now a platform responsibility, not a user responsibility?

Mimi

That's the direction they're moving. Instead of asking users to install VPNs or understand encryption, they're building it into the foundation.

Luke

Which is good, but it also means users have less choice about how their privacy is handled. Google controls the implementation, and users can't easily opt out or switch to a different approach.

  • For years, ISPs have retained a quiet window into users' browsing habits through unencrypted domain handshakes — even when the connections themselves were secure, the destination was always visible.
  • Android 17's OS-wide deployment of ECH closes that window across the entire platform, affecting not just browsers but email clients, messaging apps, and any application that reaches the network.
  • Unlike VPNs, which reroute traffic through a third party and introduce latency and trust dependencies, ECH is narrower and cleaner — hiding only the domain name, adding no overhead, requiring no subscription.
  • The feature's reach will expand gradually, as it depends on websites updating their servers to support the standard — major platforms are already on board, and adoption is accelerating.
  • Paired with fake base station blocking, Android 17 signals a deliberate architectural shift: Google is embedding privacy and security into the mobile foundation rather than leaving users to assemble it themselves.

In a quiet but consequential move, Google has woven a privacy technology called Encrypted Client Hello directly into the fabric of Android 17, shielding users' website visits from their internet service providers without demanding any extra tools or trust in third parties. Where once the first whisper between a device and a web server was audible to anyone watching the wire, that handshake is now sealed at the operating system level — a shift that moves privacy from something you configure to something you simply inherit. It is part of a broader reckoning in the technology world with who gets to see the shape of our digital lives, and a signal that the infrastructure of privacy is slowly being rebuilt from the ground up.

Google has built a privacy capability directly into Android 17 that most people assumed required a separate tool: hiding which websites you visit from your internet service provider. The technology, called Encrypted Client Hello or ECH, operates at the operating system level rather than as an add-on. It works by encrypting the initial handshake between a device and a web server — the moment that previously exposed the destination domain in plain text, even when the rest of the connection was secure. Now, an ISP can see that a connection is being made, but not where it leads.

What makes this significant is its scope. Android 17 deploys ECH across the entire platform, not just within Chrome. Email clients, messaging apps, and any application making network requests all benefit automatically. Users need not install a VPN, adjust settings, or subscribe to anything — the protection simply arrives as part of the operating system.

The contrast with VPNs is worth noting. VPNs route all traffic through a third-party server, requiring users to extend trust to that company while accepting added latency. ECH is more surgical — it conceals only the domain name from the ISP — but it does so without external dependencies or performance costs.

Android 17 also introduces fake base station blocking, guarding against rogue cell towers used for interception. Together, these features reflect a deliberate philosophy: rather than leaving users to bolt on privacy tools, Google is embedding protections into the mobile foundation itself. The ECH feature will grow more effective over time as more websites adopt the standard, but where it is already supported, it works silently and without any action required from the user.

Google has quietly built a privacy feature directly into Android 17 that does something most people assume requires a separate tool: it hides which websites you visit from your internet service provider. The technology is called Encrypted Client Hello, or ECH, and it works at the operating system level rather than as an add-on or third-party application.

When you visit a website normally, your ISP can see the domain name you're connecting to—even if the connection itself is encrypted. This happens because the initial handshake between your device and a web server includes the server's name in plain text, a necessary step in the old way of establishing secure connections. ECH changes this by encrypting that initial exchange, so the ISP sees only that you're connecting to something, not what that something is. It's a technical shift that moves privacy protection from the application layer into the foundation of the operating system itself.

Android 17 deploys this encryption system across the entire platform, not just in Chrome or a single browser. That means the privacy benefit applies broadly—to email clients, messaging apps, and any other application that makes network connections. The feature works without requiring users to install a VPN, subscribe to a service, or change their network settings. It simply activates as part of the Android experience.

The distinction matters. VPNs route all your traffic through a third-party server, which means you're trusting that company with visibility into your browsing. They also add latency and can slow connections. ECH is narrower in scope—it only hides the domain name from your ISP—but it does so without the overhead or the need to trust an external service. Your ISP still knows you're using the internet; it just can't see the specific websites.

This move reflects a broader shift in how Google is thinking about mobile security. Android 17 also introduces fake base station blocking, a feature that protects devices from rogue cell towers that criminals or surveillance operators might use to intercept connections. Together, these changes suggest Google is embedding privacy and security deeper into the Android foundation rather than leaving it to users to bolt on through third-party tools.

The rollout of ECH on Android 17 also depends on website support. Not every server on the internet has been updated to handle encrypted client hello yet, though major platforms and services have begun deploying it. For users, this means the privacy benefit will grow over time as more of the web adopts the standard. In the meantime, Android 17 users will see the feature work seamlessly wherever it's supported, with no action required on their part.

Privacy protections embedded in the platform itself rather than requiring third-party tools
— Google's approach with Android 17
Envie de l'histoire complète ? Lire l'original sur Google News ↗
Nous contacter FAQ