By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Android 17 Scrambles Site Names in Web Requests

Google's Android 17 operating system update incorporates a new privacy feature designed to encrypt the domain name within web requests, a field that previously transmitted data in plain text. This enhancement aims to bolster user privacy by making it more difficult for third parties to monitor which websites users are accessing. The change targets the "Server Name Indication" (SNI) field in the Transport Layer Security (TLS) protocol, which is used to identify the hostname of the server a client is trying to connect to during the TLS handshake. Historically, this SNI field was sent unencrypted, allowing network observers to see the domain names of websites visited, even if the subsequent connection was encrypted.
This new privacy measure, referred to as Encrypted Client Hello (ECH), extends the encryption to cover the SNI field. When a user's device makes a web request, the domain name of the target website will now be encrypted before it leaves the device. This means that internet service providers (ISPs), network administrators, or other entities monitoring network traffic will no longer be able to easily discern the specific websites a user is visiting based on this initial request. The implementation of ECH is a significant step towards greater online anonymity, as it addresses a long-standing vulnerability in web privacy.
However, the update clarifies that this feature does not render browsing activity entirely hidden. While the domain name itself is encrypted, other aspects of the web request, such as the IP address of the user and the IP address of the server being contacted, remain visible. This means that network observers can still identify that a connection is being made to a particular IP address, which can sometimes be correlated with specific websites or services. Furthermore, the content of the web pages themselves, if not otherwise encrypted by the website's own security measures (like HTTPS), could still be intercepted. The effectiveness of the privacy enhancement is therefore dependent on the broader web security landscape and the user's own browsing habits.
The rollout of this privacy feature is part of Google's ongoing efforts to enhance user data protection within its Android ecosystem. The company has been progressively introducing more robust privacy controls and transparency measures across its products. This particular feature leverages advancements in encryption protocols to provide a more secure browsing experience for Android users. The specific version of Android where this feature is being integrated is Android 17, indicating a future iteration of the mobile operating system. The company has not provided a specific release date for Android 17, but its inclusion suggests a commitment to privacy as a core component of future mobile software.
Original source — read the full reporting at the publisher:
Read on DecryptGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.