- There were a chain of human and technical vulnerabilities exploited
- MAC addresses can be changed – nearly all ethernet controllers and some wireless chipsets support changing the MAC address;
- MAC addresses are public knowledge. Anybody who ever receives a packet from your machine has your MAC address – and don't forget that Apple devices send tons of auto-discovery broadcast packets; and
- Anybody suitably competent to pull off the technical side of the attack is likely to be able to spoof MAC addresses.
It's worth noting that Knoll's letter also includes this gem of total misunderstanding:
"... date stamps are easy to edit. In fact, the photos you shared with me clearly include an "edit" button in the upper corner for this very purpose."
The article seems to me to be far more about low-burden-of-proof disciplinary panels – where the same people who set the rules interpret and administer the rules whilst trying to appear reasonable.
The fact that a "defendant" asks for a date and time of alleged incidents before submitting evidence is not at all "puzzling" – the alternative is submitting every photo over a months-long time-frame, which is certainly not reasonable.