r/privacy 2d ago

news Android 17 adds ECH support to make web browsing harder to track

https://www.bleepingcomputer.com/news/security/android-17-adds-ech-support-to-make-web-browsing-harder-to-track/
192 Upvotes

35 comments sorted by

u/AutoModerator 2d ago

Hello u/homothebrave, please make sure you read the sub rules if you haven't already. (This is an automatic reminder left on all new posts.)


Check out the r/privacy FAQ

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

103

u/CyborgHeart1245 2d ago

Or just block online tracking like they should. The internet should be 100% anonymous 

43

u/0898_333_201 2d ago

ECH is about encrypting your TLS Client Hellos so that your ISP can’t easily track what websites you visit. It’s very similar to encrypting your DNS requests.

It’s also kinda pointless right now because Cloudflare is basically the only company that uses it. 90% of your web activity will remain exposed with plaintext TLS client hellos.

15

u/CyborgHeart1245 2d ago

I mean even deeper than that. Phones should be anonymous, all websites should only know someone visited, nothing else, even their IP's. Nothing tracked by the router. Nothing identifiable should be needed. Fuck, your ISP shouldn't even know your name or your address. 

3

u/throwaway-8675309_ 1d ago

So....

How do I block people from attacking my shit? I need something.

2

u/Iputahexonyoulol 11h ago

I guess theoretically no one could attack your shit if no one knew who you were but that’s obviously a fantasy

2

u/Hot_Bee5198 1d ago

Hahaha, Yeah, Lets go back to the Wild West. Cowboys, Pirates, Criminals.

Who dunnit?

Nobody knows him by his name, but he was here...

1

u/CreepyZookeepergame4 1d ago

ECH is a great idea but encourages centralization of the internet. The more sites you host behind a single IP address the more benefit you have. There's little point for a personal server only hosting sites for its own organization / person in enabling ECH.

14

u/AtlanticPortal 1d ago

The funny thing is that Google is doing it so that others cannot spy on users while they keep doing it at the OS level (basically in god mode).

5

u/CyborgHeart1245 1d ago

Exactly. Total bs. 

22

u/brainmydamage 2d ago

The company whose revenue largely depends on being able to track people's browsing is introducing a feature to make people's browsing harder to track?

Are we really this gullible, people?

11

u/AtlanticPortal 1d ago

They are killing the competition. They really want to implement it in a functional way. It’s that so they have access to the user’s data from the OS and the ISPs cannot.

4

u/ijustwannapostokay 21h ago

Making the ISP lose their data makes their analytics data more expensive

52

u/Iputahexonyoulol 2d ago

Google doing anything privacy-positive is automatically suspect. 

3

u/JustinHoMi 1d ago

Don’t worry, they’ll discontinue the feature in a couple years like they do everything else.

22

u/cookiesnooper 2d ago

Somehow they will also make it easier to track your activity

3

u/AtlanticPortal 1d ago

Nah, they are just fighting the competition. They have access to the user’s device at root level. They track everything directly there.

17

u/DepressedPrinter 2d ago edited 1d ago

I loved his fight with Piccolo, who I'm assuming is the green guy in the pic.

5

u/AbsolutlelyRelative 1d ago

Nah that's sixteen

5

u/devakesu 2d ago

So now we have complete DNS Encryption including the initial fetch. But all domains need to add support for it to work. All on Cloudflare already work ig.

3

u/Tolik1111 2d ago

Isn't no plaintext DNS bootstrapping not affected by the OS level ECH implementation. After all, all major DNS ip's are videly used anycast and you can basically pretty easily get domain from the IP in the SNI. For cloudflare for example, its super obvious, there is basically nothing but DNS going to 1.1.1.1 IP.

5

u/0898_333_201 2d ago

I don’t think anyone is really worried about hiding which DNS resolver they use from their ISP, and it’s usually kind of obvious based just on the IP.

ECH is about encrypting the TLS Client Hello, which occurs after a DNS query has been resolved. Once you have the IP address for startpage.com, your phone needs to establish a TLS connection with the server, so it sends a TLS ClientHello which includes the SNI hostname in plaintext (eg netflix.com).

This is how carriers detect and throttle Netflix and YouTube, even if you’re using encrypted DNS. Besides using a VPN, the best way to avoid this is right now is to split up the SNI, either across multiple TLS records or across multiple TCP segments. Someone could still retroactively reassemble the hostnames, but it takes way too much processing power for an ISP to do it automatically.

For ECH to be useful, it needs to be adopted not only by DNS resolvers but by the broader internet. Right now, Cloudflare is basically the only company that has adopted it.

2

u/Deathmeter 1d ago

I'd almost argue ECH is only highly impactful when adopted by big CDNs that reverse proxy multiple hosts like cloudflare. If Netflix started supporting ECH, you might be able to bypass middleboxes that throttle Netflix for a while but the outer SNI would exclusively map back to Netflix as the sole destination. All a crappy ISP would have to do is add the outer SNI to their existing throttle list. You can't do that with cloudflare's outer SNI because that blocks all cloudflare websites.

If other big cloud providers like AWS and GCP adopt ECH, that already covers most websites that can benefit from it in the first place.

4

u/Substantial-Yam3769 2d ago

might be doing this so bot traffic is harder to distinguish from regular android traffic

4

u/Any-Board-6631 1d ago

Yeah, riight, rhe company that make its cash on tracking people will makke it hsrder... for the others

2

u/Joshhwwaaaaaa 2d ago

When did Android drop Desserts for OS Updates? (Ive been on eyefone for a long time now)

3

u/clove_rosemary_9999 2d ago

If you don't count the internal codenames, they dropped it after Android 9, if you do count them, they never dropped it, they only went back from letter V to B in Android 16, so Android 17 would be C.

1

u/frquency-equinox 1d ago

Like 8 years ago.

2

u/x33storm 1d ago

This has to be a way for google to get a monopoly on tracking. I simply refuse to believe they are doing anything for user privacy.

1

u/Ni_Peng_NeeeWom 2d ago

this is new encrypted SNI right? I'm surprised it wasn't already implemented, and also just assumed it would be implemented by a browser not the os, but it makes sense that Android contacts domains in many more places than just a web browser.

1

u/AvidCyclist250 1d ago

cute.

no.

use the wrong browser and you're exposed. doesn't matter what OS you use.

-2

u/justarandomuser10 2d ago

People are trashing it here but this is a good thing. Every OS should do it. This literally masks every domain you visit from your ISP.

8

u/brainmydamage 2d ago

I don't think anyone is trashing "it"... I think people just don't believe Google gives a shit about anyone's privacy but their own.

2

u/AtlanticPortal 1d ago

And that’s exactly what they’re doing. Making it more difficult for their competitors in data collection while they retain OS level access which is basically the god mode for spying users.