Live data from Hacker News

German police ask for help in identifying a bomber's MAC address

zdnet.com

21–30 of 66 posts

Re: German police ask for help in identifying a bomber's MAC address

#24
post #20

... but wouldn't that be a violation of the GDPR? :)

Probably not, in the same way a "wanted" poster with a photo isn't, assuming proper protocol is followed. (Now if someone reports a find in logs, you can of course ask why they had and looked at those)

Re: German police ask for help in identifying a bomber's MAC address

#25

I wonder if there are any unintended consequences for this. For example, if you were able to identify the MAC address, and you were unethical, you could just blackmail the "bomber" - whether they are innocent or not. Also, some devices allow you to reprogram the MAC address so you could in theory use this to blackmail someone as well, or at least get them harassed by the police.

I wonder about how a bunch of WAN interfaces being mac spoofed to replicate the evil MAC would be delt with?

If the prosecutor is annoyed enough and it's clear enough you did it because of this, not some weird accident, "interference with a criminal investigation"?

Re: German police ask for help in identifying a bomber's MAC address

#26

They probably can ask a lot of free WiFi providers for this info, and these providers may have his phone number as well (I'll explain below). And to get a SIM card they would've needed to register with their ID, so the authorities could identify the bomber that way (assuming it wasn't a SIM that someone bought with their ID and sold to someone else, etc). Some cafe chains or even national train networks offer free Wi…

Needing an ID to buy a SIM card is a rather recent requirement though (1st July 2017). So it is unlikely that the perpetrator used his/her ID to buy one.

Re: German police ask for help in identifying a bomber's MAC address

#27
post #16

Earlier quoted context omitted.

I'm certainly no legal expert, but wouldn't the whole "fruit of the poisonous tree" argument apply to any evidence found after and/or as a result of the MAC address connection?

There is no such thing outside common law. ie most of Europe.

In addition, the concept only pertains to information acquired through unconstitutional means, such as not having a warrant to search. Getting incorrect information is not unconstitutional and investigators rely on much more than a single piece of information when building a case.

Edit: by unconstitutional I’m speaking of the US. I am not sure what constitutional protections apply to other country’s citizens, but assume they may be similar.

Re: German police ask for help in identifying a bomber's MAC address

#28
post #25

Earlier quoted context omitted.

I wonder about how a bunch of WAN interfaces being mac spoofed to replicate the evil MAC would be delt with?

If the prosecutor is annoyed enough and it's clear enough you did it because of this, not some weird accident, "interference with a criminal investigation"?

very likely, but the guy that "owns" the mac is up for more than interfering. so its a win for him, not that its even remotly cool but this could take some time to resolve and get worse in the meantime.

Re: German police ask for help in identifying a bomber's MAC address

#29

Fun fact: MAC addresses are not unique.

Fun fact 2: you can change the MAC addresses on most systems.

My old university had a badly managed WLAN network that everyone could use. The physical network used a MAC whitelist, so getting a good connection meant replacing the MAC adress of your notebook with that of a whitelisted PC.

Re: German police ask for help in identifying a bomber's MAC address

#30

Earlier quoted context omitted.

Probably not. By the time it gets to a courtroom they'll almost certainly have a lot more than just MAC addresses, so while the bomber might plead "some jackass spoofed my MAC address to frame me" , that wouldn't explain his purchase history, the explosives residue around his home and clothing, etc. A MAC address doesn't prove anything, but courtrooms aren't about proof . They're evidence, not proof, and enough evide…

I'm certainly no legal expert, but wouldn't the whole "fruit of the poisonous tree" argument apply to any evidence found after and/or as a result of the MAC address connection?

If the cops get a search warrant for an address and it turns out that the bad guy lived next door, but the real occupants are running a meth lab, there's no doctrine anywhere that would suppress the evidence they find. As long as it's an honest mistake there's no problem.
Post reply on HN