Can Wi-Fi Owners See Your Google Search History? HTTPS, DNS, SNI and ECH Explained
A short social media video went viral when a man complained on camera that no one had warned him Wi-Fi owners could see other users' search history. Influencer Kate Sarian reposted it with the comment that this was how privacy invasion looked today, prompting many users to question their assumptions.
Cybernews investigated the claim on 11 August 2026 and spoke with network engineers. The engineers stated that the panic was largely overstated, although not entirely unfounded.
What Physically Passes Through the Router
When a user types a Google search, the browser creates a URL of the form https://www.google.com/search?q=.... Until the connection enters TLS encryption, the path, query parameter, headers and cookies travel in plaintext. Once inside TLS, the router sees only the destination IP address, connection duration and data volume. No actual search terms are visible.
Three main metadata sources remain observable. Classic DNS queries on port 53 reveal domain names in plaintext. The Server Name Indication (SNI) field inside the TLS handshake also discloses the target domain. Finally, the router records MAC addresses, DHCP hostnames and connection timestamps, often displaying friendly names such as “iPhone of Natasha”.
ECH and the Last TLS Gap
After years of development, Encrypted Client Hello (ECH) was standardized as RFC 9849 on 3 March 2026. The mechanism hides the real domain name behind an outer unencrypted ClientHello that points to a CDN such as Cloudflare. Mozilla and Google Chrome added support in recent versions, yet Russian regulators began blocking ECH traffic in November 2024, causing widespread outages for ordinary sites hosted on Cloudflare.
The following table summarises visibility under different configurations:
- HTTPS + plain DNS: search text hidden, domain visible via DNS and SNI
- HTTPS + DoH/DoT: domain hidden from DNS but still revealed by SNI
- HTTPS + DoH + ECH: only the CDN operator visible
- Plain HTTP: full URL and search text may be readable
- VPN: local network sees only the VPN server
- Managed device with TLS proxy: full visibility possible
When Requests Are Actually Readable
The only practical cases where an administrator can read search queries involve either unencrypted HTTP (now under 5 % of traffic) or a corporate device that has had a root certificate installed by the organisation. In the latter scenario, the browser trusts the proxy certificate and the proxy can decrypt and inspect all traffic.
Google settled the Brown v. Google lawsuit in 2024, agreeing to update its Incognito mode warnings. The mode never hid activity from network administrators or employers.
Additional Observers in the Chain
Internet service providers in Russia must retain metadata for up to three years under the Yarovaya law package. Public Wi-Fi operators are required by Federal Law 97-FZ to identify users via passport or phone number. Search engines themselves receive every query in plaintext when the user is logged in.
Practical advice includes enabling DoH or DoT, keeping router firmware updated, avoiding installation of untrusted certificates, and using a reputable VPN when stronger protection is required.
Related articles
Yandex Deploys OPRF Protocol to Protect Phone Numbers in Mandatory Audience Measurement Data Sharing
Yandex has detailed a cryptographic scheme using Oblivious Pseudorandom Function (OPRF) to help Russian audiovisual services comply with new legislation requiring transmission of user identifiers linked to phone numbers. The approach replaces a naive shared-secret hashing method that created a single point of compromise across dozens of competing companies. Instead, two independent third parties each hold separate secret keys and process blinded elliptic-curve points derived from normalized E.164 phone numbers. Services obtain deterministic identifiers without learning the third-party keys and without exposing raw numbers to the authorized research organization. The design distributes trust, limits offline brute-force attacks to scenarios requiring both keys plus final identifiers, and adds rate limits plus key-rotation capabilities to deter abuse. Yandex positions the solution as a practical compromise between regulatory demands, competitive secrecy, and user privacy.
CookieTin Extension Manages Partitioned Cookies Across Firefox, Chrome and Edge
Developer Perruer2 has released CookieTin, an open-source browser extension that fully supports partitioned cookies under Firefox Total Cookie Protection and Chrome CHIPS. The tool addresses limitations in older managers like Cookie Quick Manager by correctly retrieving and deleting cookies stored with partitionKey values. It works across Firefox, Chrome and Edge using a single Manifest V3 codebase written in TypeScript and Preact. Key features include accurate cookies.txt export compatible with curl and yt-dlp, protected cookies that survive explicit deletion, and pre-save validation of browser rules for __Host- prefixes and SameSite attributes. E2E tests using Puppeteer verify handling of HttpOnly, partitioned and container cookies in all three browsers.
Kaspersky Premium for macOS Gains App Uninstall Feature to Remove Residual Files
Kaspersky Premium now includes an App Uninstall tool for macOS that locates and deletes leftover files such as caches, cookies, settings, and logs after applications are removed. The feature also identifies duplicate copies of programs and lets users remove all instances or select specific ones while preserving shared components used by other software. Survey data from Kaspersky shows that only 44 percent of macOS users delete unused applications, even though 56 percent regularly clear browser data and 54 percent remove unwanted media files. Residual files can contain sensitive information including account tokens, passwords, IP addresses, event logs, and personal documents, creating privacy risks especially when a device is sold or accessed by unauthorized parties. Deleted files can be restored from the trash or directly within Kaspersky Premium before the application session ends. The company also warns that malicious programs are frequently disguised as legitimate macOS cleaning utilities.
Bypassing VPN Detection on iPhone: Detailed Methods to Avoid App Blocks
Many iPhone users encounter apps that detect and block active VPN connections even after switching servers or protocols. The detection often occurs locally on the device by inspecting network interfaces rather than relying solely on external IP addresses. This guide explains how apps identify VPN tunnels through iOS network data and provides practical workarounds including moving the VPN to a router, configuring per-app exclusions, and using web versions of services. It also covers why protocol obfuscation and port changes fail to hide local VPN activity from applications. Additional troubleshooting addresses automatic VPN profiles, ad blockers, and iCloud Private Relay interference. The article emphasizes that no universal toggle exists in iOS to hide an active VPN from all apps.