On 2026-07-21 08:59, Nuno Silva wrote:
Two things:
Yeah, if you want to remove IPv6 from the equation, if you have e.g. a
"router" device with a wireless AP that can be configured to handle (and
hand out) only IPv4, configuring it so and connecting through it would
be a way to be more confident that the issue wouldn't arise.
Were this another network application and protocol, I'd wonder what's
prompting the software to connect over IPv6, given the VPN should
provide DNS with IPv4 only, but I'm guessing this is about IPv6
addresses in bittorrent, either of peers or of trackers.
If the torrent application connects outside of the VPN, this is a bug
that should be reported to the app developers. Or to the developers of
the VPN software. I'm unsure which is at fault.
Torrenting on VPN with a bittorrent client aside, IPv6 is more revealing in the sense that it gives each device a unique, stable & too public identity unless privacy extensions are used (and even those don't fully hide the device). So it still behooves all of us to protect against IPv6 leaks.
The privacy leak occurs because the host has a IPv6 identity
available.
I still stand by the point that the leak occurs because the VPN system somehow does not preclude usage of non-VPN routes. Now this might be
okay for some uses of VPNs, where the goal is to access internal
services (corporate, school), but not for others, where the goal is to
have a separate "environment" for network access.
Hence, this PSA suggests the *simplest* effective privacy solution is...
modem <--> silent bridge <--> router <--> any device <--> any application >>
Although, there are other solutions, all of which are more complex (IMHO). >>
Aside from the cost of the hardware, the main downside of the silent bridge >> approach offered in this PSA is that it disables IPv6 entirely.
Anyone who actually relies on IPv6-only services would lose the capability. >> Would full loss of IPv6 be acceptable for most users on these
newsgroups?
Who here is actually using IPv6 for anything that would be impacted?
Probably a few people who are behind NAT, or worse, CGNAT, but do get
IPv6 prefixes might have interest in retaining that connectivity.
Completely axing IPv6 also gets rid of link-local addresses, that can be useful for internal networking.
Not that I'm taking advantage of that on Android. (Yet. :-P)
If the torrent application connects outside of the VPN, this is a bug
that should be reported to the app developers. Or to the developers of
the VPN software. I'm unsure which is at fault.
If it's a VPN-specific software in a service promoting privacy or
anonimity, or if it's a non-provider-specific VPN software focusing on
that, then I'd say it's a fault in the VPN software. And, otherwise,
it'd be a feature request for the VPN software?
PSA:
IPv6 browser privacy leaks are caused by the host, yet there's a fix.
ISP modem > IPv6-silent bridge > normal home router > Wi-Fi devices
On all platforms, web browsers can leak your globally-routable IPv6 address (even when you're using a VPN). This IPV6 privacy leak happens because the browsers prefer IPv6 and the OS host itself participates in IPv6 routing.
Basically, if the host has a global IPv6 address, a browser can expose it.
Browsers leak IPv6... but bridges stop it cold!
Specifically, a silent bridge is a bridge that passes IPv4 but never hands out or forwards IPv6, so no device behind it ever gets a global IPv6
address. If the host never receives IPv6, the browser cannot leak IPv6.
Long story short, recently I delved into the *simplest* way to completely protect us (on any OS) from any web browser (Mozilla or Chromium) leaking IPV6 privacy (after recovering from a dreadful Windows IPV6 0xFF disaster).
Newsgroups: alt.comp.os.windows-10,alt.comp.microsoft.windows,alt.comp.os.windows-11
Subject: Have you ever disabled IPv6 for privacy (to prevent IP leaks)?
Date: Sat, 18 Jul 2026 12:47:22 -0400
Message-ID: <113gamq$ii0$1@nnrp.usenet.blueworldhosting.com>
There are lots of tricks, such as RFC 8981 IPV6 rotation privacy, but
here's the important part I learned when I fully disabled IPv6 (0xFF)
instead of only partially disabling it (0x20) as most people would do.
If a router is in bridge mode (no IPv6 delegation, no prefix assignment),
all connected devices never receive a global IPv6 address.
*No global IPv6 address = nothing for the browser to leak.*
This protects IPV6 privacy on all operating systems and all web browsers.
a. It doesn't matter which browser you use (Chromium, Firefox, etc.).
b. It doesn't matter which OS you use.
c. If the host never receives an IPv6 address, the leak cannot occur.
IMHO, this is the simplest way to eliminate IPv6 browser leaks:
Disable IPv6 at the router level by using a bridged configuration.
Host-level IPv6 participation is the root cause of IPV6 leaks.
Hence, if we remove the host from IPv6 routing, that IPV6 leak disappears!
In summary, the topic of this PSA is likely not discussed anywhere else on this planet, but what I just learned was this simple IPv6 privacy epiphany.
1. Browsers leak IPv6 because they prefer IPv6 when available.
2. If the host receives a global IPv6 address (via SLAAC or DHCPv6),
the browser may expose it even if IPv4 traffic is tunneled thru VPN.
3. However, bridge mode prevents prefix delegation, so hosts never
obtain global IPv6 addresses.
No IPv6 address = no IPv6 leak!
Who knew! Not me. Now I do!
As always, if you have a simpler solution, let's discuss it as the whole point of this thread is to ensure we can protect from IPv6 privacy leaks.
Because he is torrenting via a tunnel to VPN servers. Apparently the torrrent app bypasses the VPN and connects directly via IPv6, so his identity becomes known.
Nuno Silva wrote:
The privacy leak occurs because the host has a IPv6 identity
available.
I still stand by the point that the leak occurs because the VPN
system somehow does not preclude usage of non-VPN routes. Now this
might be okay for some uses of VPNs, where the goal is to access
internal services (corporate, school), but not for others, where the
goal is to have a separate "environment" for network access.
Hi Nuno Silva,
My "goal" on VPN is simply to obfuscate my IP address, whether that is
IPv6 or IPv4, and, it turns out after all, that I've accomplished that
goal.
At least on Windows I have. (Linux even more so had I been booting to
it.) For Android, it's more complicated.
Some things I'm an expert on, and other things I'm just ignorant
about. I was right about a few things in this PSA, but I was wrong
about some.
So if I were to write this thread now, instead of a couple of days
ago, it would be very different because the problem is the same, but
the solution is different.
As for the 'problem', the problem remains that IPv6 is very different
from IPv4 in terms of device privacy, but the solutions I first
proposed was correct strategically, but I would change it greatly
tactically today.
Now I know that the only free VPN that I know of that "says" it
protects against IPv6 leaks, for example, is ProtonVPN (which has
other issues).
The free VPN from whom I get thousands of config files and which I've
been using since 2013 for free apparently does not say either way or
the other.
So it probably does not. So, we "could" call that a bug, but I won't.
It's just how it works. It's like me asking an MUA to filter out spam.
The real PSA is to learn how to identify how IPv6 privacy leaks can
occur.
So, the good news in this PSA is that people on these newsgroups are
now aware to L@@K for IPv6 privacy leaks when they're on "their VPN"
of choice.
Hence, this PSA suggests the *simplest* effective privacy solution
is... modem <--> silent bridge <--> router <--> any device <-->
any application
Although, there are other solutions, all of which are more complex
(IMHO).
Aside from the cost of the hardware, the main downside of the silent
bridge approach offered in this PSA is that it disables IPv6
entirely.
Anyone who actually relies on IPv6-only services would lose the
capability. Would full loss of IPv6 be acceptable for most users on
these newsgroups?
Who here is actually using IPv6 for anything that would be impacted?
Probably a few people who are behind NAT, or worse, CGNAT, but do get
IPv6 prefixes might have interest in retaining that connectivity.
Completely axing IPv6 also gets rid of link-local addresses, that can
be useful for internal networking.
Not that I'm taking advantage of that on Android. (Yet. :-P)
I must be clear here that I was dead wrong that the bridge solves
anything.
What I've learned in the past couple of days is that almost nobody is
"using" IPv6 (and, in fact, it turns out, my own WISP doesn't even do
it).
But other ISP's likely do hand out routable IPv6 addresses, so the
privacy issue is real, and much worse (in many ways) than it ever was
with IPv4.
With NAT, every house had a unique IPv4 address, but with IPv6, every
single device has a unique IPv6 address, whether it's rotated or not.
And, that RFC 8981 rotation only rotates the unique-to-the-device half
of the IPv6 address. RFC 8981 does nothing for the home-identifier
part.
If we don't want to worry about IPv6 privacy issues, we have to either
stop it at the router (which my router apparently has the option to
do), or, we have to stop it at the device (which Windows & Linux
devices can do).
Both Carlos and I have been describing ways to stop IPv6 at the
device. But, my original suggestion to stop IPv6 with a bridge was
pure hogwash.
I was deluded by the fact that my most comprehensive checks were done
only *after* I was forced to add a wireless bridge repeater to replace
the fact that my Wi-Fi (and VPN tunnels) were destroyed by the use of
this sequence reg add "HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters" /v DisabledComponents /t REG_DWORD /d 0xFF /f pnputil /remove-device "PCI\VEN_168C&DEV_002A..." pnputil /delete-driver netathrx.inf
/uninstall /force
That was catastrophic because it doesn't destroy just a driver. It permanently wipes out the entire networking subsystem on Windows!
Luckily, I learned a lot recovering from that networking faux pas, so
I'm not only back online, but I'm testing Wi-Fi speeds with and
without the wireless bridge, finding out very interesting things.
In summary, the *first* thing any of us should do if we care to think
about IPv6 privacy is to check with our ISP to find out whether they
serve it.
If not, the next thing we need to learn is how to check for whether or
not they serve it, and then whether or not our router is set up to
stop it.
If they serve it and if our router can't stop it, then (and only
then), should we think about stopping it at the host level, where the solution for Windows is different than Linux or Android but
fundamentally the same.
Note that RFC 8981 is "partial privacy" (IMHO), because it only
rotates the second half of the IPv6 identifier, which, for some people
may be enough.
Fundamentally, RFC 8981 turns IPv6 issues back into IPv4 privacy
issues. Kind of sort of but not exactly.
On 20/07/2026 20:59, Carlos E. R. wrote:
Because he is torrenting via a tunnel to VPN servers. Apparently the
torrrent app bypasses the VPN and connects directly via IPv6, so his
identity becomes known.
So he should complain about his VPN client then. NOT ABOUT IPv6.
What a cry baby.
As always, if you have a simpler solution, let's discuss it as the whole
point of this thread is to ensure we can protect from IPv6 privacy leaks.
You are spouting a load of meaningless gibberish.
It sounds like you are basically disabling IPv6 but coming up with a
load of complete rubbish to make it sound like you are doing something
more clever. YOU ARE NOT DOING ANYTHING OTHER THAN DISABLING IPv6.
Fundamentally, RFC 8981 turns IPv6 issues back into IPv4 privacy
issues. Kind of sort of but not exactly.
My ISP provides IPV6. I switched on ProtonVPN on Android and visited
ip.wtf and test-ipv6.com and they say there is no ipv6 address. (Brave browser). But without the VPN switched on there is an ipv6 address which
I recognise as on my own network.
Quick update, I got connected to Norway and got an IPv6 address, but it
is not one of mine, it is different at the top level. It must be
Proton's. Same results with Firefox.
I am not sure what PSA is about, but if you are using VPN then it should
hide your IPv6 address and either not provide one or provide one of its
own, and that is what ProtonVPN is doing for me on Android. If it is
letting your own IPv6 address through then it is broken. But as your ISP doesn't provide IPv6 I think something else must be going on.
Torrenting on VPN with a bittorrent client aside, IPv6 is more revealing in >> the sense that it gives each device a unique, stable & too public identity >> unless privacy extensions are used (and even those don't fully hide the
device). So it still behooves all of us to protect against IPv6 leaks.
If what you're trying to avoid is legal action from the MAFIAA or
actions from the ISP itself, then it really doesn't matter if it's the
NATed IPv4 address which gets leaked or an IPv6 one. Both would point to
your subscription with the ISP.
Brian Gregory wrote:
As always, if you have a simpler solution, let's discuss it as the
whole point of this thread is to ensure we can protect from IPv6
privacy leaks.
You are spouting a load of meaningless gibberish.
It sounds like you are basically disabling IPv6 but coming up with
a load of complete rubbish to make it sound like you are doing
something more clever. YOU ARE NOT DOING ANYTHING OTHER THAN
DISABLING IPv6.
Hi Brian Gregory,
Thank you for being blunt, as there is no doubt you are right about
this. I was wrong.
The reason I was wrong was simply that I read too much into the fact
that I couldn't find IPv6 once I set up the bridge after wiping out
my network, but, in reality, I didn't check the network well before I
wiped it out.
The bridge, as bridges are wont to do, did nothing to the IPv6
address!
And the only reason I set up the bridge was because I wiped out
networking in my attempt to rip the heart out of Windows IPv6 routing capability.
I wrote up a recovery checklist so that anyone following this thread
has all the steps necessary to wipe out IPv6 properly (hex 20) from
Windows.
And Carlos wrote up the steps so that anyone on Linux can follow suit.
Plus, I added the steps necessary to wipe IPv6 out of the Firefox
browser.
So there is a *lot* of good value which came of this IPv6 privacy
effort. Thanks again for not beating around the bush to let us know
what you think!
So there is a *lot* of good value which came of this IPv6 privacy
effort. Thanks again for not beating around the bush to let us know
what you think!
You shouldn't disable IPv6. It is the current generation of Internet Protocol. Rather then disabling it just turn on IPv6 privacy.
sysctl net.ipv6.conf.eth0.use_tempaddr = 2
If your VPN doesn't support IPv6 that's your VPN's problem. Switch to
one that does. NAT was never intended as a privacy or security feature.
When it set use_tempaddr to 2 you use different addresses for outgoing connections and those addresses expire after a certain (configurable)
amount of time. Disabling IPv6 and only using a legacy protocol just
because you don't understand it is like shooting yourself in the foot.
Don't do it.
The problem, as I see it, wrt privacy, is while IPv4 (with NAT) gave every home a unique IP address, IPv6 gives every device a unique IP address.
As you astutely and helpfully noted, we can ameliorate 'some' of that IPV6 privacy flaw by employing RFC 8981 privacy extensions, but they only rotate the latter half of the IPv6 address & even so, only after a period of time.
agris wrote:
So there is a *lot* of good value which came of this IPv6 privacy
effort. Thanks again for not beating around the bush to let us know
what you think!
You shouldn't disable IPv6. It is the current generation of Internet
Protocol. Rather then disabling it just turn on IPv6 privacy.
sysctl net.ipv6.conf.eth0.use_tempaddr = 2
If your VPN doesn't support IPv6 that's your VPN's problem. Switch to
one that does. NAT was never intended as a privacy or security feature.
When it set use_tempaddr to 2 you use different addresses for outgoing
connections and those addresses expire after a certain (configurable)
amount of time. Disabling IPv6 and only using a legacy protocol just
because you don't understand it is like shooting yourself in the foot.
Don't do it.
This thread has been a learning experience for me & hopefully for others.
To be clear, I'll never disagree with a logically defensible viewpoint.
While NAT was never a security feature and while IPv6 is a modern Internet protocol, we must agree RFC 8981 privacy extensions exist for a reason.
As you noted, RFC 8981 enabling of IPv6 Privacy Extensions generates temporary, randomized outgoing addresses which rotate periodically.
sysctl net.ipv6.conf.eth0.use_tempaddr = 2
Meanwhile, the stable IPv6 address remains available for inbound
connections, but outbound traffic uses those ephemeral identities. .
With that in mind, this is one of those technical debates where smart
people land on different sides because the trade-offs aren't trivial.
a. VPN leaks are a real, practical concern.
b. IPv6 privacy extensions aren't a magic shield.
c. Some users simply don't need IPv6 yet.
Whether unilaterally disabling IPv6 is "shooting yourself in the foot" depends on whether or not we need IPv6 in the first place. Do we?
I would ask everyone here who cares about this topic to ask themselves...
Q1: Do you use any services, apps, or devices that require direct
inbound connections from the internet (such as hosting a game server,
running a self-hosting services, or accessing your network remotely)? Q2: Do you ever use a VPN (either always, often, or occasionally)
for privacy, work, or bypassing geo-restrictions?
Q3: When you use VPNs, is your priority mainly IP obfuscation or security? Q4: Does your ISP currently give you an IPv6 address?
Q5: Do you ever connect multiple devices through your home network
(PC, phone, tablet, smart TV, etc.) and care about them communicating
smoothly with each other (such as with file sharing, casting, local
streaming, or LAN gaming)?
Q6: Do you ever use modern devices or apps that require IPv6 to work
such as smart-home devices, peer-to-peer apps, or anything that
requires "IPv6 connectivity" in its settings?
The point of these questions is to ascertain if we even need IPv6.
For example,
a. I do not host anything that needs IPv6
b. I don't have apps that require IPv6
c. My WISP doesn't even give me IPv6
d. I bittorrent only through a VPN
e. When I switch networks (e.g., a hotspot) I only care about privacy
So, in my case, IPv6 adds no value and only leaks my real identity.
Even if my ISP does not give me IPv6, my devices device (Windows, Linux, Android, etc.) & browsers will still try to use IPv6 whenever possible.
At home, IPv6 is NOT a privacy threat because there is nothing to leak.
But when my device is *outside* my network (admittedly, that's for laptops and phones), the device will happily use IPv6 which leaks our identities.
When I go to the public library and connect my phone & laptop to their
Wi-Fi network, the laptop & phone get an IPv6 address which websites see.
But the latter half of that IPv6 address is unique to the device!
However, when I just looked that up, I found something we haven't stated.
A. Android rotates temporary IPv6 addresses regularly
B. Windows 10/11 generates temporary IPv6 addresses by default
C. Most Linux variants enable IPv6 privacy extensions by default
Android, Windows, and modern Linux all use temporary IPv6 addresses!
By default.
Windows uses two timers:
a. Preferred lifetime (generally 24 hours)
b. Valid lifetime (generally 7 days)
Android rotates temporary IPv6 addresses every 24 hours.
Modern Linux distros ship with:
net.ipv6.conf.default.use_tempaddr = 2
net.ipv6.conf.all.use_tempaddr = 2
a. Preferred lifetime (generally 24 hours)
b. Valid lifetime (generally 7 days, but this isn't used in most Linux's)
Since our IPv6 temporary address (RFC 8981) lasts ~24 hours, we're
trackable if we, for example visit the same network twice in a day.
Two visits to the same website on the same day, from home, could be linked.
a. With IPv4 they know it's the same household.
b. With IPv6 they know it's the same device.
Please correct me if I'm wrong, as the whole point is to understand IPv6.
On 22/07/2026 21:46, Maria Sophia wrote:
The problem, as I see it, wrt privacy, is while IPv4 (with NAT) gave every >> home a unique IP address, IPv6 gives every device a unique IP address.
As you astutely and helpfully noted, we can ameliorate 'some' of that IPV6 >> privacy flaw by employing RFC 8981 privacy extensions, but they only rotate >> the latter half of the IPv6 address & even so, only after a period of time.
And, of course, for most people, with only one LAN, using only a
single /64 the first half of the IPv6 address gives away no more than
your IPv4 address gives away -- that it's something of yours.
Although I always run dual stack when I can and tend to urge others to--
do so too, I do accept that running IPv4 only is a valid option if you
have certain priorities, that differ from mine.
Thanks for that useful information about your ISP providing you IPv6 addresses where, from looking it up, it seems that the router assigns each device a unique globally routable IP address.
As for my situation, my free VPN which I've been using since 2013 doesn't stop IPv6 but in my case, it turns out the WISP doesn't provide it anyway.
It is entirely the router which does this
Maria Sophia <mariasophia@comprehension.com> writes:
Thanks for that useful information about your ISP providing you IPv6
addresses where, from looking it up, it seems that the router assigns each >> device a unique globally routable IP address.
It is entirely the router which does this. The router assigns one puplic
ipv4 address and one public ipv6 address. And it sends linux and android
etc the prefix /64, then linux assigns a temporary dynamic address
within that network and so does Android.
As for my situation, my free VPN which I've been using since 2013 doesn't
stop IPv6 but in my case, it turns out the WISP doesn't provide it anyway.
How did you determine this (that it does not stop ipv6) if you have no
ipv6 address? Did the website display your local address? or was it an address from the VPN? I can tell my ipv6 addresses because they all
begin with the same 64 bits allocated by my ISP.
I don't know how he did, it is a good question :-)
However, the concept of ipv6 leak is actually a known thing. You can
google "ipv6 leak in the context of vpn" (worded to get an answer from
the AI), and it says:
"Carlos E. R." <robin_listas@es.invalid> writes:
I don't know how he did, it is a good question :-)
However, the concept of ipv6 leak is actually a known thing. You can
google "ipv6 leak in the context of vpn" (worded to get an answer from
the AI), and it says:
If WebRTC is leaking the IP address then you can switch it off. But that stops Google Meet from working. But then if you are using Google Meet
then you've blown your privacy out of the window anyway. In fact if you
are using android then you've blown your privacy out of the window
probably.
If your browser has a unique fingerprint then hiding your IP address--
won't be enough to really hide.
The problem, as I see it, wrt privacy, is while IPv4 (with NAT) gave every >>> home a unique IP address, IPv6 gives every device a unique IP address.And, of course, for most people, with only one LAN, using only a
As you astutely and helpfully noted, we can ameliorate 'some' of that IPV6 >>> privacy flaw by employing RFC 8981 privacy extensions, but they only rotate >>> the latter half of the IPv6 address & even so, only after a period of time. >>
single /64 the first half of the IPv6 address gives away no more than
your IPv4 address gives away -- that it's something of yours.
Although I always run dual stack when I can and tend to urge others to
do so too, I do accept that running IPv4 only is a valid option if you
have certain priorities, that differ from mine.
Yeah, if you're in a context where IPv4 is NATed at your premises
because the ISP hands you one address, and you also get IPv6 prefix delegation, then... it's the same thing, your IPv4 address identifies
the connection, as does the prefix present in the RAs.
The part that is "rotated" or otherwise randomized in such
privacy-centered SLAAC configurations is the one that'd allow tracking
the *device*, not the connection.
That's not meant to stop tracking your e.g. residential connection, it's meant to stop tracking the device based on the device-specific portion
of the address, which without this may e.g. contain the MAC address.
<https://en.wikipedia.org/wiki/IPv6_address#Interface_identifier>
But for e.g. MAFIAA this only matters if you're not using your own connection, because otherwise you've already been identified by the
delegated prefix, they'd pester you the same.
Do note: the prefix used in SLAAC isn't (or shouldn't be...) something a residential ISP uses for several costumers, it's meant to be one prefix
for each contract/ISP connection/modem.
Although I always run dual stack when I can and tend to urge others to
do so too, I do accept that running IPv4 only is a valid option if you
have certain priorities, that differ from mine.
Two visits to the same website on the same day, from home, could be linked. >> a. With IPv4 they know it's the same household.
b. With IPv6 they know it's the same device.
Please correct me if I'm wrong, as the whole point is to understand IPv6.
Sounds right.
In theory you can change things so that RFC 8981 privacy addresses
change more often, but I believe it isn't often simple to do and can
cause unexpected problems in certain situations. Plus, of course, it has
to be done once on each device you want to keep private.
Who here is actually using IPv6 for anything that would be impacted?
Probably a few people who are behind NAT, or worse, CGNAT, but do get
IPv6 prefixes might have interest in retaining that connectivity.
Completely axing IPv6 also gets rid of link-local addresses, that can be useful for internal networking.
Not that I'm taking advantage of that on Android. (Yet. :-P)
Nuno Silva wrote:
Who here is actually using IPv6 for anything that would be impacted?
Probably a few people who are behind NAT, or worse, CGNAT, but do get
IPv6 prefixes might have interest in retaining that connectivity.
Completely axing IPv6 also gets rid of link-local addresses, that can be
useful for internal networking.
Not that I'm taking advantage of that on Android. (Yet. :-P)
This is going only to Android users...
The biggest danger to android users, as I see it, is they need to *know*
that if they are at a hotspot twice within 24 hours, their exact unique device is what is likely known to any web site that they visit.
It changes "per network", but what if we connect to the same network?
What we need to learn, as Android users, is how to stop that privacy leak.
What we need to learn, as Android users, is how to stop that privacy leak.
(sorry if this has been metioned before, I'vce not been reading
reacently and not read the whole thread)
My Android Fairphone 5 is configured (by default) to create a random MAC address per network connection. As the MAC is used to create your global IPv6 address you get a changing address to help prevent tracking.
Not that I've actually checked this out. But it should be simple to
check by visiting one of "tell-me-your-ip address" sites, and noting if
it changes after a reconnect to the local network.
In message <113kg6k$s72$1@nnrp.usenet.blueworldhosting.com>
Maria Sophia <mariasophia@comprehension.com> wrote:
PSA:
IPv6 browser privacy leaks are caused by the host, yet there's a fix.
ISP modem > IPv6-silent bridge > normal home router > Wi-Fi devices
On all platforms, web browsers can leak your globally-routable IPv6
address (even when you're using a VPN). This IPV6 privacy leak happens
because the browsers prefer IPv6 and the OS host itself participates in
IPv6 routing.
I don't understand why you think there's a problem. Very much the whole point of IPv6 is that all your globally routable IPv6 addresses are,
well, globally routable. I'd be happy for the whole world to know what
mine are.
The only ports that are open on any of these addresses to incoming connections are as a result of my opening a pinhole in the firewall.
So, knowing your globally routable addresses is one thing. Allowing connections in to any of them is entirely another matter.
David
NSA-coded post right here lol.
On 2026-07-20 08:45, Maria Sophia wrote:
If a router is in bridge mode (no IPv6 delegation, no prefix assignment),
all connected devices never receive a global IPv6 address.
-a-a-a-a *No global IPv6 address = nothing for the browser to leak.*
Look up Teredo, in Windows.
In Linux, disabling Ipv6 is feasible.
| Sysop: | Amessyroom |
|---|---|
| Location: | Fayetteville, NC |
| Users: | 74 |
| Nodes: | 6 (0 / 6) |
| Uptime: | 50:09:08 |
| Calls: | 1,100 |
| Files: | 1,339 |
| Messages: | 275,859 |