diff --git a/static/features.html b/static/features.html index d3bf52ba..c1b8796f 100644 --- a/static/features.html +++ b/static/features.html @@ -204,10 +204,12 @@
The DHCP client uses the anonymity profile rather than sending a hostname so it - doesn't compromise the privacy offered by MAC randomization.
-Associated MAC randomization is performed by default. This can be controlled per-network with Settings ➔ Network & Internet ➔ Wi-Fi ➔ <network> ➔ Advanced ➔ Privacy.
@@ -521,6 +518,12 @@ connecting to a network. It has 3 options available: "Use fully randomized MAC (default)", "Use per-network randomized MAC" and "Use device MAC". +The DHCP client uses the anonymity profile rather than sending a hostname + so it doesn't compromise the privacy offered by MAC randomization. When the + per-connection MAC randomization added by GrapheneOS is being used, DHCP + client state is flushed before reconnecting to a network to avoid revealing + that it's likely the same device as before.
+GrapheneOS also disables support for stable link-local IPv6 addresses, since these have the potential to be used as identifiers. It's more sensible to use typical link-local address generation based on the (randomized) MAC address since link-local