Re: Have you ever disabled IPv6 for privacy (to prevent IP leaks)?
Brian Gregory <[email protected]> Mon, 20 Jul 2026 10:32:49 +0100
| Newsgroups | alt.comp.os.windows-10,alt.comp.microsoft.windows,alt.comp.os.windows-11 |
|---|---|
| Organization | https://www.Brian-Gregory.me.uk/ |
| Message-ID | <[email protected]> |
On 20/07/2026 06:57, Maria Sophia wrote: > Holy shit!. This is profound... topology determines privacy! > > Chrome, Firefox, Edge, whatever... all are IPv6-first nowadays. > Yet those browsers can only leak IPv6 if the client has a global IPv6 > address. A bridged router ensures it never does. > > Modern web browsers can directly use our PCs IPv6 address such that > a. A PC web browser using its own Wi-Fi NIC can leak IPv6, but... > b. A PC web browser using a router-as-Wi-Fi bridge cannot leak IPv6! > > Jesus Christ. This is really big in terms of instant IPV6 privacy! > The IPV6 privacy comes from architecture, not configuration. > > I only just now realized this stupendous revelation after digging through > the wreckage, that if we simply pair our PC RJ45 with a router acting as a > wireless bridge (instead of using the internal wi-fi card), I think we may > instantly solve the IPV6 privacy problem without the complexity of 0x20 > DisabledComponents. > > By using RJ45 for Wi-Fi, the PC no longer has a Wi-Fi IPv6 stack to leak! > > The PC web browser cannot leak IPv6 because the browser cannot see IPv6. > It sees only IPv4, Ethernet and fe80:: (local-only, which is unusable). > > *There is nothing for the PC web browser to leak* . > > Even taking the specific case of torrrenting over VPN leaking an IPv6 > address, the leak happens when the PC has a global IPv6 address coupled > with a free VPN that does not tunnel IPv6, tied to a torrent client that > uses IPv6 anyway. > > In that scenario, the real IPv6 address escapes outside the VPN tunnel. > The *source* of those leaks, interestingly, is the internal Wi-Fi NIC. > > Wi-Fi interfaces in Windows automatically generate: > a. global IPv6 addresses > b. temporary IPv6 privacy addresses > c. IPv6 DNS queries > d. IPv6 fallback routes > e. IPv6 autoconfiguration > f. IPv6 neighbor discovery > g. IPv6 tunnels (Teredo, ISATAP, 6to4) > Such that, even if we think we're not using IPv6, Windows is. > > With an Ethernet-connected-router acting as a wireless bridge, the PC > thinks it's using Ethernet only, and Ethernet IPv6 is: > a. link-local only (fe80::) > b. not routable > c. not global > d. not visible outside our LAN > e. not used by VPNs > f. not used by torrent clients > g. not used by browsers > Hence, as far as I know, a link-local IPv6 address cannot leak. > > And, in my case, the circa 2007 DD-WRT router (WNR834Bv2) is too old to > support real IPv6 so it is physically incapable of participating in IPv6. > > No global IPv6 on the client means no IPv6 leak. > A bridge guarantees exactly that. > > What's philosophically brilliant is that even with a fully intact IPv6 > stack, and even with a modern router acting as a wireless bridge, the same > privacy advantage still holds. A Wi-Fi bridge??? This isn't one of that idiot Rob Braxman's brain farts is it? If you don't have a global IPv6 YOU ARE NOT USING IPv6 TO ACCESS THE INTERNET. You have disabled IPv6. THERE IS NO BRIDGE - whatever you think that is!? -- Brian Gregory (in England).