top of page
droidcon+icon.png

7-9 OCT. 2026

BERLIN

DroidCon_icon_rotatet.png
Anita_Singh_edited.jpg

( SPEAKER )

Bessie Jiang

Senior Software Engineer

Google

I've worked in Android Security for the past 7 years from both the application and platform side on teams including Google Play Protect, 3P Android Vulnerability research, and now Android Network Security.

Session

You Had Me at (Encrypted) Hello: ECH support in Android 17

Every secure connection starts with a handshake. But historically, that handshake has leaked your destination server's name (SNI) in plaintext to every ISP, Wi-Fi operator, and network appliance along the way. In Android 17 (API level 37), we’re addressing this long-standing privacy gap by introducing platform-wide support for ECH. This session will explore what this change means for your application's user privacy. You’ll learn: - How to use the new domain-encryption element in your Network Security Configuration to customize ECH usage globally or on a per-domain basis - What to do if you’re using standard network libraries like OkHttp or HttpEngine - What new APIs were introduced to provide ECH support (i.e. HTTPS DNS querying, etc.) - What ECH GREASE is, and why Android has enabled it by default on apps targeting API 37+
bottom of page