German police ask for help in identifying a bomber's MAC address
zdnet.com
zdnet.com
http://www.spiegel.de/international/germany/hanover-police-o...
https://www.nytimes.com/2003/04/10/world/kidnapping-has-germ...
https://abcnews.go.com/International/video-showing-german-po...
https://www.dw.com/en/child-murderer-wins-damages-over-polic...
https://www.zeit.de/gesellschaft/zeitgeschehen/2018-10/jva-k...
Think LONG and HARD before you ever either ask these people for help or point these people to someone. There are many incidents with unprovoked violence and even some incidents involving police torture and lethal force used against immigrants with little or even no provocation at all.
I would say it is very much NOT moral to help here. I know, this won't be a popular statement, but it just isn't.
I'm failing to see what provoked such a response, given the comment you're replying to.
For example, if you were able to identify the MAC address, and you were unethical, you could just blackmail the "bomber" - whether they are innocent or not.
Also, some devices allow you to reprogram the MAC address so you could in theory use this to blackmail someone as well, or at least get them harassed by the police.
A MAC address doesn't prove anything, but courtrooms aren't about proof. They're evidence, not proof, and enough evidence is all the German prosecution should need to have a relatively easy time in court.
Edit: by unconstitutional I’m speaking of the US. I am not sure what constitutional protections apply to other country’s citizens, but assume they may be similar.
It just doesn’t apply in this case, because it hinges on bad faith. Incidental evidence found while following some other legitimate trails is admissible.
It has however seen some use in the ECHR , notably against Germany (citing various US court cases):
> the applicant sought a declaration that [...] all items of evidence[...], which had become known to the investigation authorities because of the confession extracted – the so-called “fruit of the poisonous tree” – was prohibited [...] The Chamber considered that there was a strong presumption that the use of items of evidence obtained as the fruit of a confession extracted by means contrary to Article 3 rendered a trial as a whole unfair in the same way as the use of the extracted confession itself.
Gäfgen v. Germany, at 25 and 147 https://hudoc.echr.coe.int/eng#{%22dmdocnumber%22:[%22868977...}
It almost certainly wouldn't apply here though (as there is no illegal act).
It would first have to apply in the jurisdiction we're talking about, which in all probability does not...
Second, that applies to illegally obtained evidence. For example, if (in the US) the police tortured someone/broke in somewhere without a search warrant to obtain the MAC, then the fruit of the poisonous tree doctrine would likely apply to the evidence found as a result of the MAC address connection.
Finding additional evidence starting from a vague lead ("the robber was wearing black clothes") is not something illegal, it's good police work.
As usual, the tech angle to this story doesn't make the story particularly novel, but some tech-oriented people seem to have trouble perceiving that. E.g. people commenting that MAC addresses aren't unique, as if other forms of police descriptions of suspects (like height, hair color, or clothing) are unique...
I might be mistaken, but don’t changed MAC addresses (at least using macchanger) persist only until the next reboot?
Yes, but in the event that someone were reported to the police, any reasonably competent police force is going to check the device MAC independent of whatever operating system boots on the system, and so being able to falsely accuse another does not seem like a big danger here.
Didn't something along the lines of this happen with this with the Boston bombing and /r/, where they named the wrong - and innocent - person?
>Also, some devices allow you to reprogram the MAC address so you could in theory use this to blackmail someone as well, or at least get them harassed by the police.
According to IEEE[1], that MAC belongs to a Morotola Mobility, LLC. (a Lenovo Company) device. If anyone had a device in the F8E079 family, they would be - rightfully - shitting bricks, right now, for being correlated with it.
So, to summarise: No, I don't think anything good (initially) will come of this.
Also, it's a family included in macchanger, so that makes it ever-more probable that the mac address has - at some point - been used by someone else.
macchanger -l | grep "f8:e0:79"
18898 - f8:e0:79 - Motorola Mobility LLC
[1] - https://regauth.standards.ieee.org/standards-ra-web/pub/view...
Only if one normally shits bricks about something that's a 1 in 16 million chance of happening. But if someone does know that their MAC OUI is F8E079, they almost certainly know the rest of the MAC so they can rest easily unless it happens to match the published one.
Also, it's a family included in macchanger, so that makes it ever-more probable that the mac address has - at some point - been used by someone else.
macchanger -l just dumps the list of ~18,000 OUI's known to macchanger, so it doesn't really mean that it's more likely to have been set by someone using macchanger.
Especially if the suspect is black, muslim, immigrant, etc.
Some cafe chains or even national train networks offer free WiFi, but they ask you to register with your phone number and SMS verification, I've done this too but only now do I realize this means they can track my phone as it travels between train stations/cafe locations and automatically connect to their WiFi...
My old university had a badly managed WLAN network that everyone could use. The physical network used a MAC whitelist, so getting a good connection meant replacing the MAC adress of your notebook with that of a whitelisted PC.
Sometimes vendors would burn duplicates by accident. Sometimes they would simply run out and production would loop (there's "only" 16.7mil addrs per manufacturer prefix). Sometimes they print the same run in different geographical areas, because the MAC only matters in a broadcast domain. Often they just wouldn't keep track of what they assigned.
I just think it's funny to realize that people read "unique (to a broadcast domain)" and assumed that could mean "unique (everywhere)" because it's a really big number.
Do they? I'm sure there are some that do, especially if you enable verbose logging, but I haven't seen any that persistently log them by default yet.
The police is not around to enforce GDPR.