Google is introducing four new network protections in Android 17 designed to make web browsing, Wi-Fi connections and mobile networks more private and harder for attackers to exploit.
The changes address several different risks, from apps scanning devices on a home network to scammers forcing phones onto older 2G networks.
More private web browsing
Android 17 adds support for Encrypted Client Hello (ECH), a privacy technology that can help conceal which websites or online services a device is connecting to.
Although HTTPS already encrypts the contents of most web traffic, some information about the destination can still be visible to network providers or anyone monitoring the connection. ECH works alongside private DNS to hide more of that information when supported by the website or app.
Apps need permission to scan local networks
Android 17 also enforces Local Network Protection, requiring apps to request permission before scanning or connecting to other devices on the same local network.
This can help prevent apps from quietly discovering devices such as smart TVs, cameras, game consoles and other connected products in a home.
For common features such as casting to a TV, Android provides system tools that can let users choose a device without giving an app broad access to the rest of the network.
Stronger checks for website certificates
Certificate Transparency is also being enabled by default.
Secure websites use digital certificates to prove their identity. Certificate Transparency requires those certificates to appear in public records, making fraudulent or improperly issued certificates easier to discover.
The protection is intended to reduce the risk of attackers using fake certificates to secretly intercept encrypted traffic.
Carriers can disable 2G by default
Android 17 also expands protections against attacks that deliberately force phones from 4G or 5G onto the older and less secure 2G network.
Such attacks can be carried out using fake cellular base stations, sometimes called SMS blasters, which may be used to send convincing phishing messages directly to nearby phones.
Android has allowed users to manually disable 2G since Android 12. With Android 17, participating mobile carriers can now configure 2G to be switched off by default for their customers.
Together, the changes give Android users additional protection against network tracking, malicious apps, intercepted connections and mobile-based scams, with many of the safeguards operating automatically in the background.

Leave a Reply