Also, there is usually no NAT, meaning IP addresses are more likely to uniquely identify the user even without the MAC-based addressing.
But of course setting a cookie allows better tracking, and Tor defeats tracking anyway for those wishing to intentionally defeat it, so in practice it probably doesn't make much of a difference.
Your public IP would be assigned randomly from your ISP's pool, would it not? It would just be per-end-device now, not per-router.
- several years ago your MAC address was used in the latter 64 bits of your network to create your public address (not just your link local).
- that naïveté/mistake has been addressed by OS makers since.
- your ISP gives you the first half of your 128-bit IP address, the second half is up to your device(s). This is baked in pretty deeply at this point, so the smallest allocation any user/router/LAN will get is 2^64 addresses. This is 4 billion times 4 billion. With that much address space we have a lot of room for competing schemes for address selection, up to and including generating random numbers. The early use of static addresses based on MAC addresses was largely convenience and holdover from v4 thinking.
As you say, HTTP cookies and other higher-level protocol techniques are usually more than enough to enable tracking. Worrying about your MAC or IP address is like worrying about your street address. If you are going to be on the net and ask people to send you data, they need to know where to send it. It will always be possible for the person sending the data to log the return addresses. Use Tor (or similar) for privacy, as your IP is by definition public.
The most powerful feature of the internet was how it allowed anybody to publish on their own, unrestricted by any central authority, so please stop trying to create the digital imprimatur[4] with NAT.
[1] http://phrack.org/issues/63/3.html#article (section 0x03-2, "TCP Timestamp To count Hosts behind NAT")
[2] http://lcamtuf.coredump.cx/oldtcp/tcpseq.html
[3] http://memeover.arkem.org/2012/02/identifying-computers-behi...
The above are all good points. However, using IPv6 for tracking is trivial. Getting behind the NAT is not. It should not be trivial to track. From a behavioral economics framework, the more steps a bad actor has to take to be "bad", the less less he's to do so. Conversely, the easier it easier for people to behave good, the more likely they will do so.