69 karma · joined January 22, 2012
Both IPs and MACs can be changed by the administrators and both can be set such that duplicates exist in the network. However the fact that MACs are set by manufacturer makes them impossible to route as the values are not related to the network locations but related to hardware origin.
Edit: As one of the replies stated, they are also used in Stateless autoconfig in IPV6 (see: https://en.wikipedia.org/wiki/IPv6_address#Modified_EUI-64)
Well, they don't have much to differentiate do they? They all get the same Android, the hardware is pretty much the same between classes of phones (the customer doesn't really care it's a Tegra 3 or a S4) and there are not too many ways you can tinker with the hardware design so they have to add their own interface to make it different.
This also provides an interesting dilemma when it comes to such events. In this case the damage is relatively easily quantifiable, he got X bitcoins stolen so the damage is X times the bitcoin value at that time. Still, it could have easily been user personal data or credit card information, which would have made an evaluation harder to make.
One of the risks of using such a platform I guess and something that anyone who does it should consider.