
Joe Maring / Android Authority
TL;DR
- Google’s implementing numerous new community safety upgrades for Android 17.
- Encrypted Shopper Whats up makes an attempt to resolve DNS privateness issues by encrypting server lookups.
- SMS Blaster safety empowers carriers to dam low-security 2G connections by default.
Conserving cellular units safe is a kind of jobs that by no means finish, and in terms of safety in Android, Google finds itself always working to lock our telephones down towards exterior threats. With Android 17, the corporate’s already highlighted among the large methods it’s been enhancing safety, and immediately Google has a couple of extra updates to share on how your cellphone is changing into safer and personal that ever.
Android 17 makes numerous modifications to how units work with community site visitors. One large privacy-protecting one there impacts how apps are capable of see your house’s native community, stopping them from probing it for fingerprinting and even recognizing susceptible community {hardware}. One other we knew about implements Certificates Transparency by default, serving to be sure that your cellphone makes use of the right SSL certificates for the server it’s attempting to speak with.
You could be aware of “stingray” units utilized by police to simulate mobile towers and collect info to assist them determine and observe telephones. Android’s been build up its defenses towards units like these and now that’s extending to new protections towards comparable SMS Blaster assaults, utilizing pretend towers to ship spammy and even malicious texts. Particularly, Android 17’s now giving carriers the power to activate these defenses with out you needing to do a factor.
These are all nice, however the large information right here is arguably help for a protocol referred to as Encrypted Shopper Whats up (ECH). Encryption can already hold a lot of our knowledge site visitors protected from prying eyes, however there’s lengthy been a loophole: DNS. Earlier than we even begin transmitting that knowledge, DNS must lookup the IP handle of the server we’re attempting to achieve, and that bit was traditionally performed within the clear — anybody spying in your internet site visitors might see the title of the location you’re attempting to achieve.
Privateness advocates have been attempting to close that loophole down with applied sciences like DNS-over-TLS, and now ECH represents the subsequent stage there, encrypting server names whereas in transit. And since not each website goes to help ECH immediately, it even sends random rubbish knowledge when not supported, simply so anybody monitoring your connection can’t acquire any additional perception into the forms of websites you’re attempting to achieve.
Google says that Android 17 represents the primary main cellular platform to broadly embrace ECH, and the hope is that by creating this large consumer base prepared and desirous to reap the benefits of its protections, that ought to solely encourage extra server admins to get it engaged on their finish, too. When correctly deployed, that guarantees to supply a safer and extra non-public web for all of us.
Thanks for being a part of our neighborhood. Learn our Remark Coverage earlier than posting.

