{"id":55176,"date":"2020-01-14T00:00:00","date_gmt":"2020-01-13T21:00:00","guid":{"rendered":"https:\/\/prohoster.info\/blog\/blog_prohoster\/vsyo-chto-vy-hoteli-znat-o-mas-adrese"},"modified":"2020-02-18T14:03:16","modified_gmt":"2020-02-18T11:03:16","slug":"vsyo-chto-vy-hoteli-znat-o-mas-adrese","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/vsyo-chto-vy-hoteli-znat-o-mas-adrese","title":{"rendered":"Everything you wanted to know about the MAC address","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><img decoding=\"async\" alt=\"Everything you wanted to know about the MAC address\" src=\"\/wp-content\/uploads\/2020\/01\/5368ad2317cd64df459bbb7804f77264.jpeg\" style=\"display:block;margin: 0 auto;\" \/>It is well known that these six bytes, usually displayed in hexadecimal format, are assigned to the network card at the factory and appear random at first glance. Some know that the first three bytes of the address are the manufacturer's identifier, while the other three bytes are assigned to it. It's also known that you can assign yourself <em>a random<\/em> address. Many have also heard of &#171;random addresses&#187; in Wi-Fi.<\/p>\n<p><\/p>\n<p>Let's figure out what this is. <\/p>\n<p><\/p>\n<p>A MAC address (media access control address) is a unique identifier assigned to a network adapter, used in networks adhering to IEEE 802 standards, primarily Ethernet, Wi-Fi, and Bluetooth. It is officially called the 'EUI-48 identifier.' From the name, it is obvious that the address is 48 bits long, or 6 bytes. There is no universally accepted standard for writing the address (unlike IPv4 addresses, where octets are always separated by dots). It is usually written as six hexadecimal numbers separated by colons: 00:AB:CD:EF:11:22, although some equipment manufacturers prefer the format 00-AB-CD-EF-11-22 and even 00ab.cdef.1122.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><\/p>\n<p>Historically, addresses were burned into the chipset's firmware without the possibility of modification without a flash programmer, but currently, the address can be changed programmatically from the operating system. You can manually set a MAC address on a network card in Linux and MacOS (always), Windows (almost always, if allowed by the driver), Android (only rooted); on iOS (without rooting), such a trick is impossible.<\/p>\n<p><\/p>\n<h3>Address Structure<\/h3>\n<p><\/p>\n<p>The address consists of a part of the manufacturer's identifier, OUI, and the identifier assigned by the manufacturer. The assignment of OUI identifiers (Organizationally Unique Identifier) <noindex><a rel=\"nofollow\" href=\"https:\/\/standards.ieee.org\/products-services\/regauth\/oui\/index.html\">is working on<\/a><\/noindex> is managed by the IEEE organization. In fact, its length can be not just 3 bytes (24 bits), but 28 or 36 bits, from which blocks (MAC Address Block, MA) of addresses of types Large (MA-L), Medium (MA-M), and Small (MA-S) are formed, respectively. The size of the issued block, in such cases, will be 24, 20, and 12 bits or 16 million, 1 million, and 4 thousand addresses. Currently, about 38 thousand blocks have been allocated, which can be viewed using various online tools, for example, at <noindex><a rel=\"nofollow\" href=\"https:\/\/regauth.standards.ieee.org\/standards-ra-web\/pub\/view.html\">IEEE<\/a><\/noindex> or <noindex><a rel=\"nofollow\" href=\"https:\/\/www.wireshark.org\/tools\/oui-lookup.html\">Wireshark<\/a><\/noindex>.<\/p>\n<p><\/p>\n<h3>Who Owns the Addresses<\/h3>\n<p><\/p>\n<p>Simple processing of publicly available <noindex><a rel=\"nofollow\" href=\"https:\/\/code.wireshark.org\/review\/gitweb?p=wireshark.git;a=blob_plain;f=manuf;hb=HEAD\">extraction database<\/a><\/noindex> from IEEE provides quite a lot of information. For example, some organizations have claimed many OUI blocks. Here are our heroes:<\/p>\n<p><\/p>\n<p>Vendor<br \/>\nNumber of blocks\/entries<br \/>\nNumber of addresses, millions.<\/p>\n<p>Cisco Systems Inc<br \/>\n888<br \/>\n14208<\/p>\n<p>Apple<br \/>\n772<br \/>\n12352<\/p>\n<p>Samsung<br \/>\n636<br \/>\n10144<\/p>\n<p>Huawei Technologies Co.Ltd<br \/>\n606<br \/>\n9696<\/p>\n<p>Intel Corporation<br \/>\n375<br \/>\n5776<\/p>\n<p>ARRIS Group Inc.<br \/>\n319<br \/>\n5104<\/p>\n<p>Nokia Corporation<br \/>\n241<br \/>\n3856<\/p>\n<p>Private<br \/>\n232<br \/>\n2704<\/p>\n<p>Texas Instruments<br \/>\n212<br \/>\n3392<\/p>\n<p>zte corporation<br \/>\n198<br \/>\n3168<\/p>\n<p>IEEE Registration Authority<br \/>\n194<br \/>\n3072<\/p>\n<p>Hewlett Packard<br \/>\n149<br \/>\n2384<\/p>\n<p>Hon Hai Precision<br \/>\n136<br \/>\n2176<\/p>\n<p>TP-LINK<br \/>\n134<br \/>\n2144<\/p>\n<p>Dell Inc.<br \/>\n123<br \/>\n1968<\/p>\n<p>Juniper Networks<br \/>\n110<br \/>\n1760<\/p>\n<p>Sagemcom Broadband SAS<br \/>\n97<br \/>\n1552<\/p>\n<p>Fiberhome Telecommunication Technologies Co. LTD<br \/>\n97<br \/>\n1552<\/p>\n<p>Xiaomi Communications Co Ltd<br \/>\n88<br \/>\n1408<\/p>\n<p>Guangdong Oppo Mobile Telecommunications Corp.Ltd<br \/>\n82<br \/>\n1312<\/p>\n<p><\/p>\n<p>Google has only 40, and it's not surprising: they themselves don't produce that many network devices.<\/p>\n<p><\/p>\n<p>MA blocks are not provided for free; they can be purchased for reasonable prices (without a subscription fee) at $3000, $1800, or $755 respectively. Interestingly, for additional money (per year), you can purchase a \"hiding\" of public information about the allocated block. Currently, as seen above, there are 232 such blocks.<\/p>\n<p><\/p>\n<h3 id=\"kogda-zakonchatsya-mas-adresa\">When will MAC addresses run out?<\/h3>\n<p><\/p>\n<p>We are all rather tired of the never-ending stories for the past 10 years that \"IPv4 addresses are about to run out.\" Yes, obtaining new IPv4 blocks is already difficult. It is known that IP addresses <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/globalsign\/blog\/355006\/\">are distributed extremely unevenly<\/a><\/noindex>; there are giant and underutilized blocks belonging to large corporations and US government institutions, though there is little hope for their redistribution in favor of those in need. The spread of NAT, CG-NAT, and IPv6 has made the shortage of public addresses less acute.<\/p>\n<p><\/p>\n<p>A MAC address is 48 bits, of which 46 can be considered \"useful\" (why? read on), which gives 246 or 1014 addresses, which is 214 times larger than the IPv4 address space.<br \/>\nCurrently, about half a trillion addresses are allocated, or only 0.73% of the total volume. We are very far from exhausting MAC addresses.<\/p>\n<p><\/p>\n<h3 id=\"sluchaynost-bit\">Randomness of bits<\/h3>\n<p><\/p>\n<p>It can be assumed that OUI are distributed randomly, and the vendor then also randomly assigns addresses to individual network devices. Is that so? Let's take a look at the distribution of bits in the MAC address databases for 802.11 devices that I have compiled using authorization systems in wireless networks. <noindex><a rel=\"nofollow\" href=\"https:\/\/www.netams.com\/wnam\/\">WNAM<\/a><\/noindex>. The addresses belong to real devices that connected to Wi-Fi over several years in three countries. In addition, there is a small database of 802.3 wired LAN devices.<\/p>\n<p><\/p>\n<p>We will break down each MAC address (six bytes) from each sample into bits byte by byte and examine the frequency of occurrence of the bit \"1\" in each of the 48 positions. If the bit is set completely randomly, the probability of getting a \"1\" should be 50%.<\/p>\n<p><\/p>\n<p>Wi-Fi Sample No. 1 (Russia)<br \/>\nWi-Fi Sample No. 2 (Belarus)<br \/>\nWi-Fi Sample No. 3 (Uzbekistan)<br \/>\nLAN Sample (Russia)<\/p>\n<p>Number of records in the database<br \/>\n5929000<br \/>\n1274000<br \/>\n366000<br \/>\n1000<\/p>\n<p>Bit number:<br \/>\n% bit &#171;1&#187;<br \/>\n% bit &#171;1&#187;<br \/>\n% bit &#171;1&#187;<br \/>\n% bit &#171;1&#187;<\/p>\n<p>1<br \/>\n48.6%<br \/>\n49.2%<br \/>\n50.7%<br \/>\n28.7%<\/p>\n<p>2<br \/>\n44.8%<br \/>\n49.1%<br \/>\n47.7%<br \/>\n30.7%<\/p>\n<p>3<br \/>\n46.7%<br \/>\n48.3%<br \/>\n46.8%<br \/>\n35.8%<\/p>\n<p>4<br \/>\n48.0%<br \/>\n48.6%<br \/>\n49.8%<br \/>\n37.1%<\/p>\n<p>5<br \/>\n45.7%<br \/>\n46.9%<br \/>\n47.0%<br \/>\n32.3%<\/p>\n<p>6<br \/>\n46.6%<br \/>\n46.7%<br \/>\n47.8%<br \/>\n27.1%<\/p>\n<p>7<br \/>\n<strong>0.3%<\/strong><br \/>\n<strong>0.3%<\/strong><br \/>\n<strong>0.2%<\/strong><br \/>\n<strong>0.7%<\/strong><\/p>\n<p>8<br \/>\n<strong>0.0%<\/strong><br \/>\n<strong>0.0%<\/strong><br \/>\n<strong>0.0%<\/strong><br \/>\n<strong>0.0%<\/strong><\/p>\n<p>9<br \/>\n48.1%<br \/>\n50.6%<br \/>\n49.4%<br \/>\n38.1%<\/p>\n<p>10<br \/>\n49.1%<br \/>\n50.2%<br \/>\n47.4%<br \/>\n42.7%<\/p>\n<p>11<br \/>\n50.8%<br \/>\n50.0%<br \/>\n50.6%<br \/>\n42.9%<\/p>\n<p>12<br \/>\n49.0%<br \/>\n48.4%<br \/>\n48.2%<br \/>\n53.7%<\/p>\n<p>13<br \/>\n47.6%<br \/>\n47.0%<br \/>\n46.3%<br \/>\n48.5%<\/p>\n<p>14<br \/>\n47.5%<br \/>\n47.4%<br \/>\n51.7%<br \/>\n46.8%<\/p>\n<p>15<br \/>\n48.3%<br \/>\n47.5%<br \/>\n48.7%<br \/>\n46.1%<\/p>\n<p>16<br \/>\n50.6%<br \/>\n50.4%<br \/>\n51.2%<br \/>\n45.3%<\/p>\n<p>17<br \/>\n49.4%<br \/>\n50.4%<br \/>\n54.3%<br \/>\n38.2%<\/p>\n<p>18<br \/>\n49.8%<br \/>\n50.5%<br \/>\n51.5%<br \/>\n51.9%<\/p>\n<p>19<br \/>\n51.6%<br \/>\n53.3%<br \/>\n53.9%<br \/>\n42.6%<\/p>\n<p>20<br \/>\n46.6%<br \/>\n46.1%<br \/>\n45.5%<br \/>\n48.4%<\/p>\n<p>21<br \/>\n51.7%<br \/>\n52.9%<br \/>\n47.7%<br \/>\n48.9%<\/p>\n<p>22<br \/>\n49.2%<br \/>\n49.6%<br \/>\n41.6%<br \/>\n49.8%<\/p>\n<p>23<br \/>\n51.2%<br \/>\n50.9%<br \/>\n47.0%<br \/>\n41.9%<\/p>\n<p>24<br \/>\n49.5%<br \/>\n50.2%<br \/>\n50.1%<br \/>\n47.5%<\/p>\n<p>25<br \/>\n47.1%<br \/>\n47.3%<br \/>\n47.7%<br \/>\n44.2%<\/p>\n<p>26<br \/>\n48.6%<br \/>\n48.6%<br \/>\n49.2%<br \/>\n43.9%<\/p>\n<p>27<br \/>\n49.8%<br \/>\n49.0%<br \/>\n49.7%<br \/>\n48.9%<\/p>\n<p>28<br \/>\n49.3%<br \/>\n49.3%<br \/>\n49.7%<br \/>\n55.1%<\/p>\n<p>29<br \/>\n49.5%<br \/>\n49.4%<br \/>\n49.8%<br \/>\n49.8%<\/p>\n<p>30<br \/>\n49.8%<br \/>\n49.8%<br \/>\n49.7%<br \/>\n52.1%<\/p>\n<p>31<br \/>\n49.5%<br \/>\n49.7%<br \/>\n49.6%<br \/>\n46.6%<\/p>\n<p>32<br \/>\n49.4%<br \/>\n49.7%<br \/>\n49.5%<br \/>\n47.5%<\/p>\n<p>33<br \/>\n49.4%<br \/>\n49.8%<br \/>\n49.7%<br \/>\n48.3%<\/p>\n<p>34<br \/>\n49.7%<br \/>\n50.0%<br \/>\n49.6%<br \/>\n44.9%<\/p>\n<p>35<br \/>\n49.9%<br \/>\n50.0%<br \/>\n50.0%<br \/>\n50.6%<\/p>\n<p>36<br \/>\n49.9%<br \/>\n49.9%<br \/>\n49.8%<br \/>\n49.1%<\/p>\n<p>37<br \/>\n49.8%<br \/>\n50.0%<br \/>\n49.9%<br \/>\n51.4%<\/p>\n<p>38<br \/>\n50.0%<br \/>\n50.0%<br \/>\n49.8%<br \/>\n51.8%<\/p>\n<p>39<br \/>\n49.9%<br \/>\n50.0%<br \/>\n49.9%<br \/>\n55.7%<\/p>\n<p>40<br \/>\n50.0%<br \/>\n50.0%<br \/>\n50.0%<br \/>\n49.5%<\/p>\n<p>41<br \/>\n49.9%<br \/>\n50.0%<br \/>\n49.9%<br \/>\n52.2%<\/p>\n<p>42<br \/>\n50.0%<br \/>\n50.0%<br \/>\n50.0%<br \/>\n53.9%<\/p>\n<p>43<br \/>\n50.1%<br \/>\n50.0%<br \/>\n50.3%<br \/>\n56.1%<\/p>\n<p>44<br \/>\n50.1%<br \/>\n50.0%<br \/>\n50.1%<br \/>\n45.8%<\/p>\n<p>45<br \/>\n50.0%<br \/>\n50.0%<br \/>\n50.1%<br \/>\n50.1%<\/p>\n<p>46<br \/>\n50.0%<br \/>\n50.0%<br \/>\n50.1%<br \/>\n49.5%<\/p>\n<p>47<br \/>\n49.2%<br \/>\n49.4%<br \/>\n49.7%<br \/>\n45.2%<\/p>\n<p>48<br \/>\n49.9%<br \/>\n50.1%<br \/>\n50.7%<br \/>\n54.6%<\/p>\n<p><\/p>\n<p>Where does such unfairness in bits 7 and 8 come from? There are almost always zeros there.<\/p>\n<p><\/p>\n<p>Indeed, the standard defines these bits as special (<noindex><a rel=\"nofollow\" href=\"https:\/\/ru.wikipedia.org\/wiki\/MAC-%D0%B0%D0%B4%D1%80%D0%B5%D1%81\">Wikipedia<\/a><\/noindex>):<br \/>\n<img decoding=\"async\" alt=\"Everything you wanted to know about the MAC address\" src=\"\/wp-content\/uploads\/2020\/01\/3e4daff47798416d94c9c1c6bba97d72.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p><\/p>\n<p>The eighth (from the beginning) bit of the first byte of the MAC address is called the Unicast\/Multicast bit and determines the type of frame being transmitted from this address, whether it is normal (0) or broadcast (1) (multicast or broadcast). For normal, unicast interactions of the network adapter, this bit is set to '0' in all packets sent to it.<\/p>\n<p><\/p>\n<p>The seventh (from the beginning) bit of the first byte of the MAC address is called the U\/L (Universal\/Local) bit and determines whether the address is globally unique (0) or locally unique (1). By default, all 'factory-fused' addresses are globally unique, so the overwhelming majority of collected MAC addresses have the seventh bit set to '0'. In the table of assigned OUI identifiers, only about 130 entries have the U\/L bit set to '1', and apparently, these are blocks of MAC addresses for special needs.<\/p>\n<p><\/p>\n<p>Bits six through one of the first byte, bits two and three of the OUI identifiers, and especially bits in bytes four to six assigned by the manufacturer are distributed more or less evenly. <\/p>\n<p><\/p>\n<p>Thus, in a real MAC address of a network adapter, the bits are essentially equivalent and do not carry technological meaning, except for two service bits of the most significant byte.<\/p>\n<p><\/p>\n<h3 id=\"rasprostranennost\">Prevalence<\/h3>\n<p><\/p>\n<p>Interesting, which wireless equipment manufacturers are the most popular? Let's combine the search in the OUI database with the data from Sample No. 1.<\/p>\n<p><\/p>\n<p>Vendor<br \/>\nShare of devices, %<\/p>\n<p>Apple<br \/>\n26,09<\/p>\n<p>Samsung<br \/>\n19,79<\/p>\n<p>Huawei Technologies Co. Ltd<br \/>\n7,80<\/p>\n<p>Xiaomi Communications Co Ltd<br \/>\n6,83<\/p>\n<p>Sony Mobile Communications Inc<br \/>\n3,29<\/p>\n<p>LG Electronics (Mobile Communications)<br \/>\n2,76<\/p>\n<p>ASUSTek COMPUTER INC.<br \/>\n2,58<\/p>\n<p>TCT mobile ltd<br \/>\n2,13<\/p>\n<p>zte corporation<br \/>\n2,00<\/p>\n<p>not found in the IEEE database<br \/>\n1,92<\/p>\n<p>Lenovo Mobile Communication Technology Ltd.<br \/>\n1,71<\/p>\n<p>HTC Corporation<br \/>\n1,68<\/p>\n<p>Murata Manufacturing<br \/>\n1,31<\/p>\n<p>InPro Comm<br \/>\n1,26<\/p>\n<p>Microsoft Corporation<br \/>\n1,11<\/p>\n<p>Shenzhen TINNO Mobile Technology Corp.<br \/>\n1,02<\/p>\n<p>Motorola (Wuhan) Mobility Technologies Communication Co. Ltd.<br \/>\n0,93<\/p>\n<p>Nokia Corporation<br \/>\n0,88<\/p>\n<p>Shanghai Wind Technologies Co. Ltd<br \/>\n0,74<\/p>\n<p>Lenovo Mobile Communication (Wuhan) Company Limited<br \/>\n0,71<\/p>\n<p><\/p>\n<p>Practice shows that the wealthier the subscribers of a wireless network in a given location, the higher the share of Apple devices.<\/p>\n<p><\/p>\n<h3 id=\"unikalnost\">Uniqueness<\/h3>\n<p><\/p>\n<p>Are MAC addresses unique? In theory, yes, since every device manufacturer (owner of the MA block) is required to provide a unique address for each of their network adapters produced. However, some chip manufacturers, namely:<\/p>\n<p><\/p>\n<ul>\n<li>00:0A:F5 Airgo Networks, Inc. (now Qualcomm)<\/li>\n<li>00:08:22 InPro Comm (now MediaTek)<\/li>\n<\/ul>\n<p><\/p>\n<p>the last three bytes of the MAC address are set to a random number, apparently after each reboot of the device. In my sample, number 1, 82 thousand such addresses were found.<\/p>\n<p><\/p>\n<p>You can of course set a non-unique address by deliberately configuring it to be 'like your neighbor's', identifying it with a sniffer, or choosing randomly. It is also possible to accidentally set a non-unique address by performing, for example, a restore of the backup configuration of a router such as Mikrotik or OpenWrt. <\/p>\n<p><\/p>\n<p>What happens if there are two devices with the same MAC address on the network? It all depends on the logic of the network equipment (wired router, wireless network controller). Most likely, both devices will either not work or will work intermittently. From the perspective of IEEE standards, addressing the issue of MAC address spoofing is proposed to be handled, for example, by using MACsec or 802.1X. <\/p>\n<p><\/p>\n<p>What if you set a MAC address with the seventh or eighth bit set to '1', i.e., a local or multicast address? Most likely, your network will not pay attention to this, but formally this address will not comply with the standard, and it's better not to do this.<\/p>\n<p><\/p>\n<h3 id=\"kak-rabotaet-randomizaciya\">How Randomization Works<\/h3>\n<p><\/p>\n<p>We know that in order to prevent tracking people's movements by scanning the air and collecting MAC addresses, smartphone operating systems have been using randomization technology for several years. Theoretically, when scanning the air in search of known networks, the smartphone sends a packet (a group of packets) of type 802.11 probe request with the MAC address as the source:<\/p>\n<p><\/p>\n<p><img decoding=\"async\" alt=\"Everything you wanted to know about the MAC address\" src=\"\/wp-content\/uploads\/2020\/01\/5332cf36cfebf3eab87a71259447d0a9.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p><\/p>\n<p>Enabled randomization allows specifying not the 'hardcoded' address, but some other source address of the packet, changing with each scanning cycle, over time, or in some other way. Does this work? Let's look at the statistics of collected MAC addresses from the air collected by a so-called \u2018Wi-Fi Radar\u2019:<\/p>\n<p><\/p>\n<p>Entire Sample<br \/>\nSample only with the zero 7th bit<\/p>\n<p>Number of records in the database<br \/>\n3920000<br \/>\n305000<\/p>\n<p>Bit number:<br \/>\n% bit &#171;1&#187;<br \/>\n% bit &#171;1&#187;<\/p>\n<p>1<br \/>\n66.1%<br \/>\n43.3%<\/p>\n<p>2<br \/>\n66.5%<br \/>\n43.4%<\/p>\n<p>3<br \/>\n31.7%<br \/>\n43.8%<\/p>\n<p>4<br \/>\n66.6%<br \/>\n46.4%<\/p>\n<p>5<br \/>\n66.7%<br \/>\n45.7%<\/p>\n<p>6<br \/>\n31.9%<br \/>\n46.4%<\/p>\n<p>7<br \/>\n<strong>92.2%<\/strong><br \/>\n0.0%<\/p>\n<p>8<br \/>\n0.0%<br \/>\n0.0%<\/p>\n<p>9<br \/>\n67.2%<br \/>\n47.5%<\/p>\n<p>10<br \/>\n32.3%<br \/>\n45.6%<\/p>\n<p>11<br \/>\n66.9%<br \/>\n45.3%<\/p>\n<p>12<br \/>\n32.3%<br \/>\n46.8%<\/p>\n<p>13<br \/>\n32.6%<br \/>\n50.1%<\/p>\n<p>14<br \/>\n33.0%<br \/>\n56.1%<\/p>\n<p>15<br \/>\n32.5%<br \/>\n45.0%<\/p>\n<p>16<br \/>\n67.2%<br \/>\n48.3%<\/p>\n<p>17<br \/>\n33.2%<br \/>\n56.9%<\/p>\n<p>18<br \/>\n33.3%<br \/>\n56.8%<\/p>\n<p>19<br \/>\n33.3%<br \/>\n56.3%<\/p>\n<p>20<br \/>\n66.8%<br \/>\n43.2%<\/p>\n<p>21<br \/>\n67.0%<br \/>\n46.4%<\/p>\n<p>22<br \/>\n32.6%<br \/>\n50.1%<\/p>\n<p>23<br \/>\n32.9%<br \/>\n51.2%<\/p>\n<p>24<br \/>\n67.6%<br \/>\n52.2%<\/p>\n<p>25<br \/>\n49.8%<br \/>\n47.8%<\/p>\n<p>26<br \/>\n50.0%<br \/>\n50.0%<\/p>\n<p>27<br \/>\n50.0%<br \/>\n50.2%<\/p>\n<p>28<br \/>\n50.0%<br \/>\n49.8%<\/p>\n<p>29<br \/>\n50.0%<br \/>\n49.4%<\/p>\n<p>30<br \/>\n50.0%<br \/>\n50.0%<\/p>\n<p>31<br \/>\n50.0%<br \/>\n49.7%<\/p>\n<p>32<br \/>\n50.0%<br \/>\n49.9%<\/p>\n<p>33<br \/>\n50.0%<br \/>\n49.7%<\/p>\n<p>34<br \/>\n50.0%<br \/>\n49.6%<\/p>\n<p>35<br \/>\n50.0%<br \/>\n50.1%<\/p>\n<p>36<br \/>\n50.0%<br \/>\n49.5%<\/p>\n<p>37<br \/>\n50.0%<br \/>\n49.9%<\/p>\n<p>38<br \/>\n50.0%<br \/>\n49.8%<\/p>\n<p>39<br \/>\n50.0%<br \/>\n49.9%<\/p>\n<p>40<br \/>\n50.0%<br \/>\n50.1%<\/p>\n<p>41<br \/>\n50.0%<br \/>\n50.2%<\/p>\n<p>42<br \/>\n50.0%<br \/>\n50.2%<\/p>\n<p>43<br \/>\n50.0%<br \/>\n50.1%<\/p>\n<p>44<br \/>\n50.0%<br \/>\n50.1%<\/p>\n<p>45<br \/>\n50.0%<br \/>\n50.0%<\/p>\n<p>46<br \/>\n50.0%<br \/>\n49.8%<\/p>\n<p>47<br \/>\n50.0%<br \/>\n49.8%<\/p>\n<p>48<br \/>\n50.1%<br \/>\n50.9%<\/p>\n<p><\/p>\n<p>The picture is completely different.<\/p>\n<p><\/p>\n<p>The 8th bit of the first byte of the MAC address still corresponds to the Unicast nature of the SRC address in the probe request packet.<\/p>\n<p><\/p>\n<p>The 7th bit is set to Local in 92.2% of cases, meaning we can confidently say that this proportion of collected addresses belongs to randomized ones, while less than 8% refer to real addresses. The distribution of bits in OUI for such real addresses approximately matches the data in the previous table.<\/p>\n<p><\/p>\n<p>Which manufacturer, according to OUI, owns the randomized addresses (i.e., with the 7th bit set to \"1\")?<\/p>\n<p><\/p>\n<p>Manufacturer by OUI<br \/>\nShare among all addresses<\/p>\n<p>not found in the IEEE database<br \/>\n62.45%<\/p>\n<p>Google Inc.<br \/>\n37.54%<\/p>\n<p>others<br \/>\n0.01%<\/p>\n<p><\/p>\n<p>All randomized addresses attributed to Google belong to one OUI with the prefix <strong>DA:A1:19<\/strong>. What is this prefix? Let's take a look in the <noindex><a rel=\"nofollow\" href=\"https:\/\/cs.android.com\/android\/platform\/superproject\/+\/master:frameworks\/base\/core\/java\/android\/net\/MacAddress.java;l=366;bpv=1;bpt=0\">Android sources<\/a><\/noindex>.<\/p>\n<p><\/p>\n<pre><code class=\"java\">private static final MacAddress BASE_GOOGLE_MAC = MacAddress.fromString(\"da:a1:19:0:0:0\");<\/code><\/pre>\n<p><\/p>\n<p>Stock Android uses a special, registered OUI when searching for wireless networks, one of the few with the seventh bit set.<\/p>\n<p><\/p>\n<h3 id=\"vychislit-realnyy-mas-iz-randomnogo\">Calculate the real MAC from a random one<\/h3>\n<p><\/p>\n<p>Let's check there as well:<\/p>\n<p><\/p>\n<pre><code class=\"java\">private static final long VALID_LONG_MASK = (1L &lt;&lt; 48) - 1;\nprivate static final long LOCALLY_ASSIGNED_MASK = MacAddress.fromString(&quot;2:0:0:0:0:0&quot;).mAddr;\nprivate static final long MULTICAST_MASK = MacAddress.fromString(&quot;1:0:0:0:0:0&quot;).mAddr;\n\npublic static @NonNull MacAddress createRandomUnicastAddress(MacAddress base, Random r) {\n        long addr;\n        if (base == null) {\n            addr = r.nextLong() &amp; VALID_LONG_MASK;\n        } else {\n            addr = (base.mAddr &amp; OUI_MASK) | (NIC_MASK &amp; r.nextLong());\n        }\n        addr |= LOCALLY_ASSIGNED_MASK;\n        addr &amp;= ~MULTICAST_MASK;\n        MacAddress mac = new MacAddress(addr);\n        if (mac.equals(DEFAULT_MAC_ADDRESS)) {\n            return createRandomUnicastAddress(base, r);\n        }\n        return mac;\n    }\n<\/code><\/pre>\n<p><\/p>\n<p>The address in its entirety, or its last three bytes, is purely <em>Random.nextLong()<\/em>. \"Proprietary recovery of real MAC\" \u2014 is a hoax. With a high degree of confidence, one can expect that manufacturers of Android phones also use other, unregistered OUIs. We do not have access to iOS sources, but it is likely that a similar algorithm is applied there. <\/p>\n<p><\/p>\n<p>The above does not negate the function of other mechanisms for de-anonymizing Wi-Fi subscribers, based on the analysis of other fields in the probe request frame, or the correlation of the relative frequency of requests sent by the device. However, accurately tracking a subscriber with external means is extremely problematic. The data collected is more suitable for analyzing average\/peak loads based on location and time, based on large numbers, without tying to specific devices and individuals. Only those 'inside', such as the manufacturers of mobile operating systems and installed applications, have precise data.<\/p>\n<p><\/p>\n<p>What could be dangerous about someone else knowing your device's MAC address? For wired and wireless networks, a 'Denial of Service' attack can be organized. For a wireless device, there is also a chance to capture the moment it appears in the location where the sensor is installed. By spoofing the address, one could try to 'impersonate' your device, which may work only if no additional protection measures (authentication and\/or encryption) are used. 99.9% of people have nothing to worry about here.<\/p>\n<p><\/p>\n<p>The MAC address is more complex than it seems, but simpler than it could be.<\/p>\n<p>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/post\/483670\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412\u0441\u0435\u043c \u0438\u0437\u0432\u0435\u0441\u0442\u043d\u043e, \u0447\u0442\u043e \u044d\u0442\u043e \u0448\u0435\u0441\u0442\u044c \u0431\u0430\u0439\u0442, \u043e\u0431\u044b\u0447\u043d\u043e \u043e\u0442\u043e\u0431\u0440\u0430\u0436\u0430\u0435\u043c\u044b\u0445 \u0432 \u0448\u0435\u0441\u0442\u043d\u0430\u0434\u0446\u0430\u0442\u0435\u0440\u0438\u0447\u043d\u043e\u043c \u0444\u043e\u0440\u043c\u0430\u0442\u0435, \u043f\u0440\u0438\u0441\u0432\u043e\u0435\u043d\u044b \u0441\u0435\u0442\u0435\u0432\u043e\u0439 \u043a\u0430\u0440\u0442\u0435 \u043d\u0430 \u0437\u0430\u0432\u043e\u0434\u0435, \u0438 \u043d\u0430 \u043f\u0435\u0440\u0432\u044b\u0439 \u0432\u0437\u0433\u043b\u044f\u0434 \u0441\u043b\u0443\u0447\u0430\u0439\u043d\u044b. \u041d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0437\u043d\u0430\u044e\u0442, \u0447\u0442\u043e \u043f\u0435\u0440\u0432\u044b\u0435 \u0442\u0440\u0438 \u0431\u0430\u0439\u0442\u0430 \u0430\u0434\u0440\u0435\u0441\u0430 \u2013 \u044d\u0442\u043e \u0438\u0434\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u043e\u0440 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u0435\u043b\u044f, \u0430 \u043e\u0441\u0442\u0430\u043b\u044c\u043d\u044b\u0435 \u0442\u0440\u0438 \u0431\u0430\u0439\u0442\u0430 \u0438\u043c \u043d\u0430\u0437\u043d\u0430\u0447\u0430\u044e\u0442\u0441\u044f. \u0418\u0437\u0432\u0435\u0441\u0442\u043d\u043e \u0442\u0430\u043a\u0436\u0435, \u0447\u0442\u043e \u043c\u043e\u0436\u043d\u043e \u043f\u043e\u0441\u0442\u0430\u0432\u0438\u0442\u044c \u0441\u0435\u0431\u0435 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u043b\u044c\u043d\u044b\u0439 \u0430\u0434\u0440\u0435\u0441. \u041c\u043d\u043e\u0433\u0438\u0435 \u0441\u043b\u044b\u0448\u0430\u043b\u0438 \u0438 \u043f\u0440\u043e &#171;\u0440\u0430\u043d\u0434\u043e\u043c\u043d\u044b\u0435 \u0430\u0434\u0440\u0435\u0441\u0430&#187; \u0432 Wi-Fi. \u0420\u0430\u0437\u0431\u0435\u0440\u0435\u043c\u0441\u044f, [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-55176","post","type-post","status-publish","format-standard","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412\u0441\u0435\u043c \u0438\u0437\u0432\u0435\u0441\u0442\u043d\u043e, \u0447\u0442\u043e \u044d\u0442\u043e \u0448\u0435\u0441\u0442\u044c \u0431\u0430\u0439\u0442, \u043e\u0431\u044b\u0447\u043d\u043e \u043e\u0442\u043e\u0431\u0440\u0430\u0436\u0430\u0435\u043c\u044b\u0445.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/vsyo-chto-vy-hoteli-znat-o-mas-adrese\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0412\u0441\u0451, \u0447\u0442\u043e \u0432\u044b \u0445\u043e\u0442\u0435\u043b\u0438 \u0437\u043d\u0430\u0442\u044c \u043e \u041c\u0410\u0421 \u0430\u0434\u0440\u0435\u0441\u0435 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412\u0441\u0435\u043c \u0438\u0437\u0432\u0435\u0441\u0442\u043d\u043e, \u0447\u0442\u043e \u044d\u0442\u043e \u0448\u0435\u0441\u0442\u044c \u0431\u0430\u0439\u0442, \u043e\u0431\u044b\u0447\u043d\u043e \u043e\u0442\u043e\u0431\u0440\u0430\u0436\u0430\u0435\u043c\u044b\u0445.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/vsyo-chto-vy-hoteli-znat-o-mas-adrese\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-01-13T21:00:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-02-18T11:03:16+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Everything you wanted to know about the MAC address | ProHoster","description":"It is well known that this consists of six bytes, usually displayed.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/vsyo-chto-vy-hoteli-znat-o-mas-adrese","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0412\u0441\u0451, \u0447\u0442\u043e \u0432\u044b \u0445\u043e\u0442\u0435\u043b\u0438 \u0437\u043d\u0430\u0442\u044c \u043e \u041c\u0410\u0421 \u0430\u0434\u0440\u0435\u0441\u0435 | ProHoster","og:description":"\u0412\u0441\u0435\u043c \u0438\u0437\u0432\u0435\u0441\u0442\u043d\u043e, \u0447\u0442\u043e \u044d\u0442\u043e \u0448\u0435\u0441\u0442\u044c \u0431\u0430\u0439\u0442, \u043e\u0431\u044b\u0447\u043d\u043e \u043e\u0442\u043e\u0431\u0440\u0430\u0436\u0430\u0435\u043c\u044b\u0445.","og:url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/vsyo-chto-vy-hoteli-znat-o-mas-adrese","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-01-13T21:00:00+00:00","article:modified_time":"2020-02-18T11:03:16+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"55176","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 19:48:30","updated":"2022-10-04 23:47:40","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/55176","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=55176"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/55176\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=55176"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=55176"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=55176"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}