Identifiers · 4 min read
MAC address randomization on desktops is still unfinished
MAC address randomization is normal on phones and unfinished on desktops. How NIC identifiers leak, and how rotation fits a privacy suite.
MAC address randomization was introduced to reduce link-layer tracking, especially when mobile devices scan for Wi-Fi networks. Current desktop operating systems also support private or random Wi-Fi addresses on compatible hardware, but behavior varies by adapter, network profile, policy, and operating-system version. Wired Ethernet commonly continues to use its manufacturer-assigned address unless an administrator deliberately configures another local address.
MAC rotation is one module in a privacy suite, not the suite. It belongs next to SMBIOS and disks, not in place of them.
What a MAC address is for
A Media Access Control address identifies an interface within an IEEE 802 link-layer network. A universally administered EUI-48 is intended to be globally unique; a locally administered or randomized address is not backed by that same global assignment. Neither form was designed as a web cookie, but a stable address can let observers on the same link associate traffic with an interface over time.
Inventory and network-management systems may use it because:
- a manufacturer-assigned address normally remains with the adapter across OS reinstalls
- Windows and other operating systems expose adapter addresses through documented interfaces
- it pairs cleanly with other inventory fields
- even a locally administered address still distinguishes machines on a LAN
A conventional VPN changes how IP traffic is routed after it leaves the local link; it does not normally replace the MAC address used between the device and its local network. A remote website also does not receive that local MAC address through ordinary routed traffic.
Why phones and PCs diverged
Wi-Fi exposes link-layer frames over a shared radio medium, so a stable address in scans or associations can support local observation. Mobile platforms adopted private-address features early, while desktop and enterprise networks often need predictable DHCP reservations, access control, and asset inventory.
The present picture is more nuanced than “phones randomize, PCs do not.” Windows offers random hardware addresses when the Wi-Fi adapter supports them. Apple offers fixed or rotating private Wi-Fi addresses on current platforms. Managed devices and individual network profiles can use different policies, and wired interfaces follow a different path.
Randomized versus locally administered
IEEE addressing defines a Universal/Local bit in the first octet. A locally generated unicast address sets that bit to indicate local administration rather than pretending to come from an IEEE-assigned vendor block. Generating an address with the wrong bit can cause misleading vendor attribution or conflict with addressing conventions.
A broader hardware fingerprinting assessment should also consider whether:
- the MAC changed but the SMBIOS UUID did not
- two adapters changed in lockstep every minute
- the generated address follows the unicast and local-administration rules
The IETF notes that other stable identifiers or patterns can defeat the privacy goal of MAC randomization. In a controlled test profile, NIC values should therefore be documented alongside the other fields in scope. SpoofHWID derives supported NIC values as part of its seeded profile; see seeded hardware identities.
Wired adapters are the leak you forget
Wi-Fi receives most of the privacy attention, but a desktop may also expose Ethernet, virtual, Bluetooth, dock, and USB network interfaces to local inventory software.
Each active interface is another possible attribute. Rotating one Wi-Fi address does not change the manufacturer address of a separate Ethernet adapter, and an application may enumerate interfaces that are not carrying the current route. A test plan should define the set instead of assuming one visible Settings value represents the machine.
Where MAC rotation sits in a session
In a temporary HWID masking model, MAC rotation lasts for the session and reverts on reboot, same as the rest of the bundle. That is the correct default for a workstation.
If you need a stable lab LAN identity for repeated testing, keep the profile seed and document the network. Avoid rewriting adapter firmware or EEPROM as a privacy shortcut; recovery support varies by vendor and device.
What MAC rotation will not do
It will not hide you from a site that never saw your MAC in the first place. Browsers do not send MACs to websites. This is local and LAN-visible identity, plus whatever local software decides to upload.
It will not replace account hygiene. It will not replace the rest of the hardware bundle. It will not make a desktop behave like an iPhone on every network stack.
Practical checks
Before an authorized test session:
- list the adapters you actually have
- record which interfaces are active and in scope
- apply the seeded profile
- confirm the presented MACs changed as a set
- reboot later and confirm the burned-in values returned
If a value does not return, stop. Temporary is the contract.
Primary references
- IETF: RFC 9724, state of randomized and changing MAC addresses — address-selection models, privacy motivation, and implementation history.
- IETF: RFC 9797, context, impacts, and use cases — why other stable identifiers matter and how rotation can affect network services.
- IEEE Registration Authority: Guidelines for use of EUI, OUI, and CID — the Individual/Group and Universal/Local address bits.
- Microsoft Support: Random hardware addresses in Windows Wi-Fi settings — vendor documentation for supported Windows behavior.
For coverage questions, Status is the living list. For the control surface, use the menu on the homepage. For access windows, Pricing is enough. MAC randomization is a chapter, not the book.
FAQ
Does a VPN hide my MAC address?
No. A MAC address is a link-layer identifier on the local network segment. A VPN operates above that.
Is MAC randomization enough to hide a PC?
No. Disk serials, SMBIOS UUIDs, and GPU identifiers still identify the machine.
Do desktop operating systems randomize MACs like iPhones do?
Sometimes for Wi-Fi scans, rarely for the burned-in address used by licensing and inventory software.