Re: Have you ever disabled IPv6 for privacy (to prevent IP leaks)?

Hank Rogers <[email protected]> Sat, 18 Jul 2026 18:04:55 -0500
Newsgroups alt.comp.os.windows-10,alt.comp.microsoft.windows,alt.comp.os.windows-11
Organization A noiseless patient Spider
Message-ID <[email protected]>
Maria Sophia wrote on 7/18/2026 1:00 PM:
> Maria Sophia wrote:
>> I think everyone will benefit from knowing more about RFC 8981
>> implementation on their Windows box to rotate their temporary IPv6 address!
> 
> Digging more into what the heck RF8981 is and which is a better method
> to protect privacy (rotate IPv6 temporary addresses or disable IPv6),
> I think this is a fascinating subject that everyone needs to know about.
> 
> With regard to IPv6, I think it's a good idea if everyone runs this
> while on VPN to ensure that the VPN is actually routing IPv6 correctly.
>   netsh interface ipv6 show route
> 
> Likewise for DNS verification
>   nslookup -type=AAAA google.com
>   
> Digging into the results, it appears that IPv6 has TWO types of addresses
>   i. Stable IPv6 address which identifies the device
>   ii. Temporary IPv6 address which rotates for privacy
> RFC 8981 protects the temporary address.
> The stable address still exists unless we configure otherwise.
> 
> ISP assigns an IPv6 prefix, so even with privacy extensions:
>   a. Our ISP-assigned prefix reveals our region
>   b. Our ISP-assigned prefix reveals our provider
>   c. Our ISP-assigned prefix may be stable for days or weeks
> Apparently, the RFC 8981 privacy extensions do not hide this.	
> My WISP would be easily noticed in that information I'd think.
> 
> I may be wrong about this, but while most routers support IPv6, if the
> router is old, apparently privacy extensions may apparently do nothing.
> 
> The big one is that I use free VPNs only, so the VPN must tunnel IPv6 for
> RFC 8981 to work, I think. Otherwise, IPv6 traffic goes outside the VPN.
> 
> Unfortunately, I learned the hard way today that Windows prefers IPv6 over
> IPv4, so if IPv6 is enabled:
>   a. Windows will use IPv6 first
>   b. Which means web browsers will use IPv6 first
>   c. And that DNS will return IPv6 first
>   d. So our VPN must handle IPv6 correctly
> Because, if it doesn't, we unknowingly leak like a sieve.
> 
> Again I must stress that I never even thought about IPv6
> until today, and I never heard of RFC 8981 until just now.
> 
> So everything I say can be wrong (and likely is wrong).
> However, it's a great discussion topic because all of us need
> to be aware that Windows prefers IPv6 so it's here to stay.
> 
> Hence it behooves us all to learn more about how to protect
> ourselves from privacy leaks due to IPv6 differences with IPv4.
> 
> Has anyone else used RFC8981 privacy extensions or disabled IPv6?
> What is your experience?
> 

Thanks, Mary.  Now we all know how to disable ipv6 on our computers.  It 
is evil and spies on us.  I am real paranoid just like you. Many thanks