Your phone is about to stop telling the Wi-Fi which sites you visit
The padlock in your browser has never hidden as much as people assume. What you type on a website is encrypted. The name of the website is not: at the very start of every connection, your phone announces which site it wants in plain text, and your broadband provider, your mobile network and the pub Wi-Fi can all read it.
Google published the fix on 27 August. Android 17 becomes the first major mobile operating system to enable Encrypted Client Hello broadly, a standard that encrypts that opening announcement so an observer sees an address and nothing more. It's on by default for apps built for Android 17 that use the usual networking libraries, and it works best alongside private DNS, which covers the other half of the leak. There's a neat detail in how it hides: when a server doesn't support the standard, Android sends convincing fake data anyway, so the connections that really are encrypted don't stand out from the rest. Google says it tested 10,000 domains across 740 providers in 202 countries without finding pages that broke.
Three other changes shipped with it, and one deserves your attention more than the encryption does. Local Network Protection means an app can no longer scan your home network in the background. If it wants to see the smart TV, the printer, the cameras and the NAS box sitting on your Wi-Fi, it now has to ask you first. Certificate Transparency is on by default, and mobile operators can now switch off 2G for their subscribers, which shuts down the fake mobile masts that criminals build from hardware costing as little as $3,000 to blast out scam texts.
None of this reaches your PC, so treat it as good news for the phone in your pocket rather than a change on the desk. It does raise a fair question, though: what exactly were those apps finding when they scanned? Tendvane's Network scan shows you the same list from the Windows side, and for most households it's longer than expected.