Live data from Hacker News

German police ask for help in identifying a bomber's MAC address

zdnet.com

51–60 of 66 posts

Re: German police ask for help in identifying a bomber's MAC address

#51

Can wifi APs capture/log a MAC address just because a device polled and then listed it as a possible connection option?

Can? Certainly, which is why most modern phones randomize MAC addresses use for probing.

Do they? I'm sure there are some that do, especially if you enable verbose logging, but I haven't seen any that persistently log them by default yet.

Re: German police ask for help in identifying a bomber's MAC address

#52

Earlier quoted context omitted.

Probably not. By the time it gets to a courtroom they'll almost certainly have a lot more than just MAC addresses, so while the bomber might plead "some jackass spoofed my MAC address to frame me" , that wouldn't explain his purchase history, the explosives residue around his home and clothing, etc. A MAC address doesn't prove anything, but courtrooms aren't about proof . They're evidence, not proof, and enough evide…

I'm certainly no legal expert, but wouldn't the whole "fruit of the poisonous tree" argument apply to any evidence found after and/or as a result of the MAC address connection?

>but wouldn't the whole "fruit of the poisonous tree" argument apply [in this case]

It would first have to apply in the jurisdiction we're talking about, which in all probability does not...

Re: German police ask for help in identifying a bomber's MAC address

#54
post #42

I wonder if there are any unintended consequences for this. For example, if you were able to identify the MAC address, and you were unethical, you could just blackmail the "bomber" - whether they are innocent or not. Also, some devices allow you to reprogram the MAC address so you could in theory use this to blackmail someone as well, or at least get them harassed by the police.

So what? They'd investigate the victim, find nothing, and leave him be.

There have been far too many cases where they " investigate the [suspect], find nothing", and still charge them or harass them, even making stuff up or withholding evidence from the courts, because they "know for sure" that they did it.

Especially if the suspect is black, muslim, immigrant, etc.

Re: German police ask for help in identifying a bomber's MAC address

#55
Even though I am sure I can already see the privacy activist banging there war drums and the "know-it-alls" tell us that mac addresses can be spoofed/are not unique, I don't see anything wrong with it.

Police have been releasing photofits of potential criminals since the dawn of photography and this is no different just digital. In a way it could be the modern-day photofit.

Re: German police ask for help in identifying a bomber's MAC address

#56

Earlier quoted context omitted.

Probably not. By the time it gets to a courtroom they'll almost certainly have a lot more than just MAC addresses, so while the bomber might plead "some jackass spoofed my MAC address to frame me" , that wouldn't explain his purchase history, the explosives residue around his home and clothing, etc. A MAC address doesn't prove anything, but courtrooms aren't about proof . They're evidence, not proof, and enough evide…

I'm certainly no legal expert, but wouldn't the whole "fruit of the poisonous tree" argument apply to any evidence found after and/or as a result of the MAC address connection?

First, it doesn't exist in Germany.

Second, that applies to illegally obtained evidence. For example, if (in the US) the police tortured someone/broke in somewhere without a search warrant to obtain the MAC, then the fruit of the poisonous tree doctrine would likely apply to the evidence found as a result of the MAC address connection.

Finding additional evidence starting from a vague lead ("the robber was wearing black clothes") is not something illegal, it's good police work.

Re: German police ask for help in identifying a bomber's MAC address

#57

Can wifi APs capture/log a MAC address just because a device polled and then listed it as a possible connection option?

Yes. In fact, completely passive devices can log the MAC address of any device "searching" for a wireless network whether or not any AP is even in the area.

Re: German police ask for help in identifying a bomber's MAC address

#58
post #57

Can wifi APs capture/log a MAC address just because a device polled and then listed it as a possible connection option?

Yes. In fact, completely passive devices can log the MAC address of any device "searching" for a wireless network whether or not any AP is even in the area.

Fascinating. Oh gee. I could set up a device in my home that over time can probably give me enough data to figure out schedules of my neighbours.

Re: German police ask for help in identifying a bomber's MAC address

#59

I wonder if there are any unintended consequences for this. For example, if you were able to identify the MAC address, and you were unethical, you could just blackmail the "bomber" - whether they are innocent or not. Also, some devices allow you to reprogram the MAC address so you could in theory use this to blackmail someone as well, or at least get them harassed by the police.

I wonder about how a bunch of WAN interfaces being mac spoofed to replicate the evil MAC would be delt with?

If police announced that they were looking for a guy in an orange jacket, you could put on an orange jacket and run around town generating lots of false reports. But why would you do that? That would be incredibly antisocial.

As usual, the tech angle to this story doesn't make the story particularly novel, but some tech-oriented people seem to have trouble perceiving that. E.g. people commenting that MAC addresses aren't unique, as if other forms of police descriptions of suspects (like height, hair color, or clothing) are unique...

Post reply on HN