Google Confirms New Android 17 Privacy Encryption For Billions
Google has confirmed that it is introducing support for a new privacy standard in Android 17 to obscure domain names and hide metadata that might otherwise be used by those wishing to profile you. The Encrypted ClientHello standard will, as long as websites and apps support it, encrypt the website name you are heading for from the get-go.
There are many misconceptions about security and privacy on the internet, and one of them is that a website that uses Hypertext Transfer Protocol Secure , with an address starting with https, means you are safe from any kind of attack. Actually, what the HTTPS protocol does is encrypt data in transit between your web browser and the web server in question. It does this using Transport Layer Security, and it is great at protecting your data from being intercepted. It doesn’t prevent a fake website from sending you malware or launching a phishing attack , nor does it mean that your connection is completely private.
“When you visit a website or use an app, even if the connection is encrypted by HTTPS, the domain names of the sites we visit are still visible to network operators and eavesdroppers,” Bram Bonné, a Google software engineer and Shuaibo Huang, an Android product manager, have warned in an August 27 blog . With data harvesting and automated profiling increasingly common, this seemingly harmless metadata collection can be combined to create surprisingly detailed profiles about you “This unencrypted data can be used to build user profiles or, in the hands of malicious actors, leveraged for targeted phishing and scam campaigns."
For those of a very technical bent, the full ECH Standard is available for your perusal; for everyone else, it works by hiding the domain name you are heading for using a secret encryption key that only the destination website can unscramble. There is a great diagram that helps visualize this in action in Google Jigsaw’s Medium post , “Closing a Critical Internet Privacy Gap for Billions of Users: Android 17 Rolls Out ECH Support.”
Now you might have noticed the critical disclaimer mentioned earlier: “as long as websites and apps support it.” Google does not shy away from this requirement and said that “we are working with industry leaders, service providers, and app developers to accelerate ECH adoption.” The good news is that Jigsaw has confirmed that in order to avoid “exposing only certain connections as ECH-protected,” apps and browsers should use something called ECH GREASE, which sends randomized fake ECH extensions to sites that don’t support ECH. In effect, this means that all connection requests look exactly the same. Even better, Jigsaw has stated that, starting with Android 17, “ECH GREASE will be enabled by default.”
Loading article...