It is well known that these six bytes, usually displayed in hexadecimal format, are assigned to the network card at the factory and appear random at first glance. Some know that the first three bytes of the address are the manufacturer's identifier, while the other three bytes are assigned to it. It's also known that you can assign yourself a random address. Many have also heard about 'random addresses' in Wi-Fi.
Let's figure out what this is.
A MAC address (media access control address) is a unique identifier assigned to a network adapter, used in networks adhering to IEEE 802 standards, primarily Ethernet, Wi-Fi, and Bluetooth. It is officially called the 'EUI-48 identifier.' From the name, it is obvious that the address is 48 bits long, or 6 bytes. There is no universally accepted standard for writing the address (unlike IPv4 addresses, where octets are always separated by dots). It is usually written as six hexadecimal numbers separated by colons: 00:AB:CD:EF:11:22, although some equipment manufacturers prefer the format 00-AB-CD-EF-11-22 and even 00ab.cdef.1122.
Historically, addresses were burned into the chipset's firmware without the possibility of modification without a flash programmer, but currently, the address can be changed programmatically from the operating system. You can manually set a MAC address on a network card in Linux and MacOS (always), Windows (almost always, if allowed by the driver), Android (only rooted); on iOS (without rooting), such a trick is impossible.
Address Structure
The address consists of a part of the manufacturer's identifier, OUI, and the identifier assigned by the manufacturer. The assignment of OUI identifiers (Organizationally Unique Identifier) is managed by the IEEE organization. In fact, its length can be not just 3 bytes (24 bits), but 28 or 36 bits, from which blocks (MAC Address Block, MA) of addresses of types Large (MA-L), Medium (MA-M), and Small (MA-S) are formed, respectively. The size of the issued block, in such cases, will be 24, 20, and 12 bits or 16 million, 1 million, and 4 thousand addresses. Currently, about 38 thousand blocks have been allocated, which can be viewed using various online tools, for example, at or .
Who Owns the Addresses
Simple processing of publicly available from IEEE provides quite a lot of information. For example, some organizations have claimed many OUI blocks. Here are our heroes:
Vendor
Number of blocks/entries
Number of addresses, millions.
Cisco Systems Inc
888
14208
Apple
772
12352
Samsung
636
10144
Huawei Technologies Co.Ltd
606
9696
Intel Corporation
375
5776
ARRIS Group Inc.
319
5104
Nokia Corporation
241
3856
Private
232
2704
Texas Instruments
212
3392
zte corporation
198
3168
IEEE Registration Authority
194
3072
Hewlett Packard
149
2384
Hon Hai Precision
136
2176
TP-LINK
134
2144
Dell Inc.
123
1968
Juniper Networks
110
1760
Sagemcom Broadband SAS
97
1552
Fiberhome Telecommunication Technologies Co. LTD
97
1552
Xiaomi Communications Co Ltd
88
1408
Guangdong Oppo Mobile Telecommunications Corp.Ltd
82
1312
Google has only 40, and it's not surprising: they themselves don't produce that many network devices.
MA blocks are not provided for free; they can be purchased for reasonable prices (without a subscription fee) at $3000, $1800, or $755 respectively. Interestingly, for additional money (per year), you can purchase a "hiding" of public information about the allocated block. Currently, as seen above, there are 232 such blocks.
When will MAC addresses run out?
We are all rather tired of the never-ending stories for the past 10 years that "IPv4 addresses are about to run out." Yes, obtaining new IPv4 blocks is already difficult. It is known that IP addresses ; there are giant and underutilized blocks belonging to large corporations and US government institutions, though there is little hope for their redistribution in favor of those in need. The spread of NAT, CG-NAT, and IPv6 has made the shortage of public addresses less acute.
A MAC address is 48 bits, of which 46 can be considered "useful" (why? read on), which gives 246 or 1014 addresses, which is 214 times larger than the IPv4 address space.
Currently, about half a trillion addresses are allocated, or only 0.73% of the total volume. We are very far from exhausting MAC addresses.
Randomness of bits
It can be assumed that OUI are distributed randomly, and the vendor then also randomly assigns addresses to individual network devices. Is that so? Let's take a look at the distribution of bits in the MAC address databases for 802.11 devices that I have compiled using authorization systems in wireless networks. . The addresses belong to real devices that connected to Wi-Fi over several years in three countries. In addition, there is a small database of 802.3 wired LAN devices.
We will break down each MAC address (six bytes) from each sample into bits byte by byte and examine the frequency of occurrence of the bit "1" in each of the 48 positions. If the bit is set completely randomly, the probability of getting a "1" should be 50%.
Wi-Fi Sample No. 1 (Russia)
Wi-Fi Sample No. 2 (Belarus)
Wi-Fi Sample No. 3 (Uzbekistan)
LAN Sample (Russia)
Number of records in the database
5929000
1274000
366000
1000
Bit number:
% of bit '1'
% of bit '1'
% of bit '1'
% of bit '1'
1
48.6%
49.2%
50.7%
28.7%
2
44.8%
49.1%
47.7%
30.7%
3
46.7%
48.3%
46.8%
35.8%
4
48.0%
48.6%
49.8%
37.1%
5
45.7%
46.9%
47.0%
32.3%
6
46.6%
46.7%
47.8%
27.1%
7
0.3%
0.3%
0.2%
0.7%
8
0.0%
0.0%
0.0%
0.0%
9
48.1%
50.6%
49.4%
38.1%
10
49.1%
50.2%
47.4%
42.7%
11
50.8%
50.0%
50.6%
42.9%
12
49.0%
48.4%
48.2%
53.7%
13
47.6%
47.0%
46.3%
48.5%
14
47.5%
47.4%
51.7%
46.8%
15
48.3%
47.5%
48.7%
46.1%
16
50.6%
50.4%
51.2%
45.3%
17
49.4%
50.4%
54.3%
38.2%
18
49.8%
50.5%
51.5%
51.9%
19
51.6%
53.3%
53.9%
42.6%
20
46.6%
46.1%
45.5%
48.4%
21
51.7%
52.9%
47.7%
48.9%
22
49.2%
49.6%
41.6%
49.8%
23
51.2%
50.9%
47.0%
41.9%
24
49.5%
50.2%
50.1%
47.5%
25
47.1%
47.3%
47.7%
44.2%
26
48.6%
48.6%
49.2%
43.9%
27
49.8%
49.0%
49.7%
48.9%
28
49.3%
49.3%
49.7%
55.1%
29
49.5%
49.4%
49.8%
49.8%
30
49.8%
49.8%
49.7%
52.1%
31
49.5%
49.7%
49.6%
46.6%
32
49.4%
49.7%
49.5%
47.5%
33
49.4%
49.8%
49.7%
48.3%
34
49.7%
50.0%
49.6%
44.9%
35
49.9%
50.0%
50.0%
50.6%
36
49.9%
49.9%
49.8%
49.1%
37
49.8%
50.0%
49.9%
51.4%
38
50.0%
50.0%
49.8%
51.8%
39
49.9%
50.0%
49.9%
55.7%
40
50.0%
50.0%
50.0%
49.5%
41
49.9%
50.0%
49.9%
52.2%
42
50.0%
50.0%
50.0%
53.9%
43
50.1%
50.0%
50.3%
56.1%
44
50.1%
50.0%
50.1%
45.8%
45
50.0%
50.0%
50.1%
50.1%
46
50.0%
50.0%
50.1%
49.5%
47
49.2%
49.4%
49.7%
45.2%
48
49.9%
50.1%
50.7%
54.6%
Where does such unfairness in bits 7 and 8 come from? There are almost always zeros there.
Indeed, the standard defines these bits as special ():

The eighth (from the beginning) bit of the first byte of the MAC address is called the Unicast/Multicast bit and determines the type of frame being transmitted from this address, whether it is normal (0) or broadcast (1) (multicast or broadcast). For normal, unicast interactions of the network adapter, this bit is set to '0' in all packets sent to it.
The seventh (from the beginning) bit of the first byte of the MAC address is called the U/L (Universal/Local) bit and determines whether the address is globally unique (0) or locally unique (1). By default, all 'factory-fused' addresses are globally unique, so the overwhelming majority of collected MAC addresses have the seventh bit set to '0'. In the table of assigned OUI identifiers, only about 130 entries have the U/L bit set to '1', and apparently, these are blocks of MAC addresses for special needs.
Bits six through one of the first byte, bits two and three of the OUI identifiers, and especially bits in bytes four to six assigned by the manufacturer are distributed more or less evenly.
Thus, in a real MAC address of a network adapter, the bits are essentially equivalent and do not carry technological meaning, except for two service bits of the most significant byte.
Prevalence
Interesting, which wireless equipment manufacturers are the most popular? Let's combine the search in the OUI database with the data from Sample No. 1.
Vendor
Share of devices, %
Apple
26,09
Samsung
19,79
Huawei Technologies Co. Ltd
7,80
Xiaomi Communications Co Ltd
6,83
Sony Mobile Communications Inc
3,29
LG Electronics (Mobile Communications)
2,76
ASUSTek COMPUTER INC.
2,58
TCT mobile ltd
2,13
zte corporation
2,00
not found in the IEEE database
1,92
Lenovo Mobile Communication Technology Ltd.
1,71
HTC Corporation
1,68
Murata Manufacturing
1,31
InPro Comm
1,26
Microsoft Corporation
1,11
Shenzhen TINNO Mobile Technology Corp.
1,02
Motorola (Wuhan) Mobility Technologies Communication Co. Ltd.
0,93
Nokia Corporation
0,88
Shanghai Wind Technologies Co. Ltd
0,74
Lenovo Mobile Communication (Wuhan) Company Limited
0,71
Practice shows that the wealthier the subscribers of a wireless network in a given location, the higher the share of Apple devices.
Uniqueness
Are MAC addresses unique? In theory, yes, since every device manufacturer (owner of the MA block) is required to provide a unique address for each of their network adapters produced. However, some chip manufacturers, namely:
- 00:0A:F5 Airgo Networks, Inc. (now Qualcomm)
- 00:08:22 InPro Comm (now MediaTek)
the last three bytes of the MAC address are set to a random number, apparently after each reboot of the device. In my sample, number 1, 82 thousand such addresses were found.
You can of course set a non-unique address by deliberately configuring it to be 'like your neighbor's', identifying it with a sniffer, or choosing randomly. It is also possible to accidentally set a non-unique address by performing, for example, a restore of the backup configuration of a router such as Mikrotik or OpenWrt.
What happens if there are two devices with the same MAC address on the network? It all depends on the logic of the network equipment (wired router, wireless network controller). Most likely, both devices will either not work or will work intermittently. From the perspective of IEEE standards, addressing the issue of MAC address spoofing is proposed to be handled, for example, by using MACsec or 802.1X.
What if you set a MAC address with the seventh or eighth bit set to '1', i.e., a local or multicast address? Most likely, your network will not pay attention to this, but formally this address will not comply with the standard, and it's better not to do this.
How Randomization Works
We know that in order to prevent tracking people's movements by scanning the air and collecting MAC addresses, smartphone operating systems have been using randomization technology for several years. Theoretically, when scanning the air in search of known networks, the smartphone sends a packet (a group of packets) of type 802.11 probe request with the MAC address as the source:

Enabled randomization allows specifying not the 'hardcoded' address, but some other source address of the packet, changing with each scanning cycle, over time, or in some other way. Does this work? Let's look at the statistics of collected MAC addresses from the air collected by a so-called ‘Wi-Fi Radar’:
Entire Sample
Sample only with the zero 7th bit
Number of records in the database
3920000
305000
Bit number:
% of bit '1'
% of bit '1'
1
66.1%
43.3%
2
66.5%
43.4%
3
31.7%
43.8%
4
66.6%
46.4%
5
66.7%
45.7%
6
31.9%
46.4%
7
92.2%
0.0%
8
0.0%
0.0%
9
67.2%
47.5%
10
32.3%
45.6%
11
66.9%
45.3%
12
32.3%
46.8%
13
32.6%
50.1%
14
33.0%
56.1%
15
32.5%
45.0%
16
67.2%
48.3%
17
33.2%
56.9%
18
33.3%
56.8%
19
33.3%
56.3%
20
66.8%
43.2%
21
67.0%
46.4%
22
32.6%
50.1%
23
32.9%
51.2%
24
67.6%
52.2%
25
49.8%
47.8%
26
50.0%
50.0%
27
50.0%
50.2%
28
50.0%
49.8%
29
50.0%
49.4%
30
50.0%
50.0%
31
50.0%
49.7%
32
50.0%
49.9%
33
50.0%
49.7%
34
50.0%
49.6%
35
50.0%
50.1%
36
50.0%
49.5%
37
50.0%
49.9%
38
50.0%
49.8%
39
50.0%
49.9%
40
50.0%
50.1%
41
50.0%
50.2%
42
50.0%
50.2%
43
50.0%
50.1%
44
50.0%
50.1%
45
50.0%
50.0%
46
50.0%
49.8%
47
50.0%
49.8%
48
50.1%
50.9%
The picture is completely different.
The 8th bit of the first byte of the MAC address still corresponds to the Unicast nature of the SRC address in the probe request packet.
The 7th bit is set to Local in 92.2% of cases, meaning we can confidently say that this proportion of collected addresses belongs to randomized ones, while less than 8% refer to real addresses. The distribution of bits in OUI for such real addresses approximately matches the data in the previous table.
Which manufacturer, according to OUI, owns the randomized addresses (i.e., with the 7th bit set to "1")?
Manufacturer by OUI
Share among all addresses
not found in the IEEE database
62.45%
Google Inc.
37.54%
others
0.01%
All randomized addresses attributed to Google belong to one OUI with the prefix DA:A1:19. What is this prefix? Let's take a look in the .
private static final MacAddress BASE_GOOGLE_MAC = MacAddress.fromString("da:a1:19:0:0:0");Stock Android uses a special, registered OUI when searching for wireless networks, one of the few with the seventh bit set.
Calculate the real MAC from a random one
Let's check there as well:
private static final long VALID_LONG_MASK = (1L << 48) - 1;
private static final long LOCALLY_ASSIGNED_MASK = MacAddress.fromString("2:0:0:0:0:0").mAddr;
private static final long MULTICAST_MASK = MacAddress.fromString("1:0:0:0:0:0").mAddr;
public static @NonNull MacAddress createRandomUnicastAddress(MacAddress base, Random r) {
long addr;
if (base == null) {
addr = r.nextLong() & VALID_LONG_MASK;
} else {
addr = (base.mAddr & OUI_MASK) | (NIC_MASK & r.nextLong());
}
addr |= LOCALLY_ASSIGNED_MASK;
addr &= ~MULTICAST_MASK;
MacAddress mac = new MacAddress(addr);
if (mac.equals(DEFAULT_MAC_ADDRESS)) {
return createRandomUnicastAddress(base, r);
}
return mac;
}
The address in its entirety, or its last three bytes, is purely Random.nextLong(). "Proprietary recovery of real MAC" — is a hoax. With a high degree of confidence, one can expect that manufacturers of Android phones also use other, unregistered OUIs. We do not have access to iOS sources, but it is likely that a similar algorithm is applied there.
The above does not negate the operation of other mechanisms for de-anonymizing Wi-Fi subscribers, based on analyzing other fields of the probe request frame, or correlating the relative frequency of requests sent by the device. However, tracking a subscriber reliably with external means is extremely challenging. The collected data is more suited for analyzing average/peak loads by location and time, based on large numbers, without linking to specific devices and people. Only those "inside," namely the manufacturers of mobile OS and installed applications, have precise data.
What could be dangerous about someone else knowing the MAC address of your device? For wired and wireless networks, a denial-of-service attack can be organized. For a wireless device, there's even some probability of capturing the moment it appears in the location where a sensor is installed. By spoofing the address, one could try to pose as your device, which could work only if no additional security measures (authentication and/or encryption) are in place. 99.9% of people here have nothing to worry about.
The MAC address is more complex than it seems, but simpler than it could be.
Source: habr.com
