Re: [Madinas] MAC address stickers on devices

Tim Cappalli <Tim.Cappalli@microsoft.com> Fri, 14 May 2021 01:10 UTC

Return-Path: <Tim.Cappalli@microsoft.com>
X-Original-To: madinas@ietfa.amsl.com
Delivered-To: madinas@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2EA563A1BB4 for <madinas@ietfa.amsl.com>; Thu, 13 May 2021 18:10:22 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.787
X-Spam-Level:
X-Spam-Status: No, score=-2.787 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.698, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, SPF_PASS=-0.001, T_SPF_HELO_TEMPERROR=0.01, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=microsoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id lVSz2Iqgw4Xw for <madinas@ietfa.amsl.com>; Thu, 13 May 2021 18:10:17 -0700 (PDT)
Received: from outbound.mail.eo.outlook.com (mail-oln040093008006.outbound.protection.outlook.com [40.93.8.6]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6FFEF3A1BB0 for <madinas@ietf.org>; Thu, 13 May 2021 18:10:17 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=oCg/nvKHX7O74FhSAmMO3iz0wZ50PSdI1xlvVPvT7YFjEZ9VjKDfDFyVNm3uObEoCow35PRTbuGO+LXqdYF2CHepoZCUO6XnVpEs1s2/VmIfCU+gy9XzE5YaXHlsqTZIwWBhSsFuKtzFJOUtXqvGFlUL1e9cp7qBQUf7XGICKeDbM6hB0WpvLxGou9se4aeteAv7v+28B2PhroxZBB0tSXFhqUoburIMenlgv9LX64VRuS6je42e1W/9dq7W7v3f4u+3avvtvL/j1oUhxuREvRQbPGxT7frMHKEWcESyWxg3P8CQ+6+WbaCGmTEDflF61WuvwYaw0dHFFZUrcg0ySQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=wb4fM5/bMd2jfmvXz4kBlXyBPchs0y9a+bjSj0zb0uQ=; b=cmmAWc1feoxCLp7Ae2ErD7rpYZeLDw83j+8eCyjpP6Bj4D7ACAGAF2PqIs8YguWKkOGKAps0lUrNNxUKGOpUf1iSOn0WIoOs9tI2ZJsuVASwsQ6OFKNljZxLloImMdtKqgq4FukWZJz/4M7V7tgJyo3TsR1Rttd2ddmBp4wfm/B/y8h4/bU9bGIR8ULKS2+BAU8B6qPGDw5osixz8KeHYbBmgRbXWSNhaF+5FocbnBsrM17Etd0dVW/dWqMYFhYfPKvU10GWoV439AEZN3oT07FVTFylZduKGWYnGPOAr6aLUpdN6oaRhyMQWXPILB274rmQKaorSucXV6k4PT6rpg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=microsoft.com; dmarc=pass action=none header.from=microsoft.com; dkim=pass header.d=microsoft.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=wb4fM5/bMd2jfmvXz4kBlXyBPchs0y9a+bjSj0zb0uQ=; b=alE8E7ydrML21Y/jCaIYy2aVctAm22SplLyx+OzA4bJVbjput7z4fmDxmfayL5uY0SlnUEucebxskBWkHIjmtI7WpEDuwV+t9iuZbyjxwRBblV/PhrVHd+LB8gAiDC5MuqWjL0TswYw+UwLOcX/4sUmnc6VuhzqRN+nJZiSBR3Q=
Received: from PH0PR00MB1029.namprd00.prod.outlook.com (2603:10b6:510:48::6) by PH0PR00MB0984.namprd00.prod.outlook.com (2603:10b6:510:3a::12) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4170.0; Fri, 14 May 2021 01:10:15 +0000
Received: from PH0PR00MB1029.namprd00.prod.outlook.com ([fe80::4c34:1cc5:f0f9:b9e7]) by PH0PR00MB1029.namprd00.prod.outlook.com ([fe80::4c34:1cc5:f0f9:b9e7%6]) with mapi id 15.20.4151.000; Fri, 14 May 2021 01:10:15 +0000
From: Tim Cappalli <Tim.Cappalli@microsoft.com>
To: "madinas@ietf.org" <madinas@ietf.org>, "mcr@sandelman.ca" <mcr@sandelman.ca>
Thread-Topic: [Madinas] MAC address stickers on devices
Thread-Index: AQHXSEZkdKiwSBtKF0yM/KmISxPxsqrh/GxXgAAuFYCAAACUWQ==
Date: Fri, 14 May 2021 01:10:15 +0000
Message-ID: <PH0PR00MB10295549BEE0BD7A594609A995509@PH0PR00MB1029.namprd00.prod.outlook.com>
References: <14117.1620944499@localhost> <PH0PR00MB102986E405DA64B408915EEA95519@PH0PR00MB1029.namprd00.prod.outlook.com>, <26751.1620954457@localhost>
In-Reply-To: <26751.1620954457@localhost>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels: MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Enabled=True; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_SiteId=72f988bf-86f1-41af-91ab-2d7cd011db47; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_SetDate=2021-05-14T01:09:40.6613791Z; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_ContentBits=0; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Method=Standard
authentication-results: ietf.org; dkim=none (message not signed) header.d=none;ietf.org; dmarc=none action=none header.from=microsoft.com;
x-originating-ip: [108.7.218.223]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 46707368-9889-4adf-d63b-08d91675080d
x-ms-traffictypediagnostic: PH0PR00MB0984:
x-microsoft-antispam-prvs: <PH0PR00MB09841F1B7CD03833CDD0E36995509@PH0PR00MB0984.namprd00.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:7219;
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: /t6GyH8gGvyM84MCZXwgp6j9mhmW68krLiawAhS9P0QjPxqtcJZsFCiXj5kQvf4Pk3HoMUvXeiaPQ0U3mbiHIFzpr2FSJxURdy5IsOHlbf69cn3c5ZSR9aiArXkQ/N2+8doTPxibzi93FbM614MHK6BEg72Tzw8G5zdaL5cCwPgUzTSfhykLQp5/Q30yYc5azB4mvNyZU/KVRcdUTAnp4vTuvURKzhvH9lrhhXxWoNKPkQt6mtJelOCLT3hHOjcqR4qeMBLBQ9earpFIIs83MxmQTWgZQ7es/UanTSC4KXBxxdSputfL1ef5SNv6s82LoDPTtx3juNWzm3sAExS0AJVEPt3DWpBYMbV4zu4VBPeg5OhtKiHoZMO2g3NHd+oReJBTIRZ8/mvcGZoKqOgAGTkT7HTc8JCHT2T44CiMyOBIOu8E51zZXYHYgduqy4mGGaBwEr6vD1K7yy9BKrelM3y5xje5tPPjRiTCcjNLEwnDwrR+3Bak0fKAW6EmTwRASyElOg07NQJhjE96tEqHPPPbFumyCSXoN8s+4zHbQtD0W3OZHZxLw68CY6W8KsfQk63AaKfr9c0wLEjko2CcbogmZLwoy/u1UGY9ObREjpVhg9/7+Efknw8a3N/32a8izoFqAKAeUkmilr4IDPHCQ5KZGzSwS3rpjPSKFvNGlgVN+rMyOpnYJVSnUtpK8jMrQ0gb0cGKgG490WM6LmQ8x8bA+hHOMwkGEPV6S80UVSvIjcgZK16Rsv1sNQmmh4hP93QoLQ+eMsX88eBdOcTh9g==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:PH0PR00MB1029.namprd00.prod.outlook.com; PTR:; CAT:NONE; SFS:(4636009)(366004)(71200400001)(7696005)(82950400001)(82960400001)(166002)(86362001)(53546011)(6506007)(26005)(8990500004)(966005)(122000001)(38100700002)(10290500003)(8936002)(33656002)(8676002)(66476007)(66946007)(478600001)(55016002)(52536014)(5660300002)(66446008)(64756008)(2906002)(316002)(110136005)(66556008)(186003)(76116006)(91956017)(9686003); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 3
x-ms-exchange-antispam-messagedata-0: +qtuCSc8VtBVwK8ehHXqt0IBDirYb8BNuULKSFQJPXgnbAyuqnOwL3mkU/gaLHSfnlJTXaK4I6VGW/eQVetIuQWYj2PdXRn++x69CZ15ayzVhA0MSaa3s3gGjLXRvVbTuQXzQq3Oqc9vOhscZxR4VqL56rSaUn43AMFb3aIAj7lPKnwugNBWkl5hedHY47/hbChQZ/RVagkfzt5mETRh1yw7FBVzYdgMwqQUsHRyOmxk9E00Efq6vfFVKJXY5Hsxk1jFhNDpphcpI3IuVlpUwgL3bvth9kkwWJAGASYSP9liM6h+4VUpsYYtOqHhTAEQcKttv1cQesCUln7pl6ytE1zg4WCvgGrPTQbH9xKIpz9syWd+CV/s/FLamc5hZVt3wQzZIkPGOLQ/6SozDhSqr7tj9mxYNXJXN67dqNBA1UAOBOTnVNUxDYjg6gFNvSEASmgYtw2g/u0Mg0cflmoQxUkdWmfUGD3wJBHcvoTTm/xEUAq91d7h
x-ms-exchange-antispam-messagedata-1: rj8PGweuxoRRb4JZ8a8cXMS4CQ2OoalLO5KCaBj9EmTflRPQP+uklU/BzInsVxpJDDWWLyudPIP4y2aTy4PsppPyzSvajFGjDCtsYAF9+OJ855vem7E8edU8TxX8hyYrE5jbbPXuQ6mEMnqAnno/jlKwArr2NL9wxx5EaKahvnd4kK7dV5hI8wx3aveKML0U+tyQ9KkQtKO+VGTwok0EmYKb4vpacSgfkfS8K0vNmIzZLawsmEO0u3MPdtEZbWMxh2ULpBh2JjvS7keZIF7wCuuoNq0jNiK9/c6dmz7xJvSDPCSI84tZBSy5DMUQ0Vtm+cNDzgGXY077v8nIFs13nTSd94BM4z5Vx9Av5Vc7kML36nUkbeyav1maH2Ik3glq1cSV+onBWk1E92ZiM4S3UjYBQYEkKNXNwqSGgk4PFUOuqDQRaSzmJ3tj1nTIt7bksoiRWpR2rKWr1sa6DPfs+ddRrGwZbhJKA4hB08BP60tjn5yfPJRK
x-ms-exchange-antispam-messagedata-2: wFipN+WcXm4/ojeJnmKhmDEyZtHNPAKUE5Amycga/MFcILcuopoE856oLGuCQO6UMwG1F42paeJ8jXPvOvW/XtRQtjsHPBUymYFBe+Mbjy0k12hpYufcJh6sDe2ZwxHJj0LaCRehG50nM8TMTX89zuMbPENsNeKEvK42fJiBcrkd4eQdV7LLuz7GIowUyXXtnM9URqbFhUl6RiTI5H+/UXwPTFbYg9ovEHoa/X9diDJWIJ3OVfd5oi3Ue1sSA8P3lv5aj+MLTCEFpov+3vt3lqK2gGY9XWv0xCbSCdubzpjpvA==
x-ms-exchange-transport-forked: True
Content-Type: multipart/alternative; boundary="_000_PH0PR00MB10295549BEE0BD7A594609A995509PH0PR00MB1029namp_"
MIME-Version: 1.0
X-OriginatorOrg: microsoft.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: PH0PR00MB1029.namprd00.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 46707368-9889-4adf-d63b-08d91675080d
X-MS-Exchange-CrossTenant-originalarrivaltime: 14 May 2021 01:10:15.0729 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 72f988bf-86f1-41af-91ab-2d7cd011db47
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: gVHQj9FoSWMhdl6HPE6FNvIq2BzGhBuE6Fdxh27nIi+1fABQjh/iuHo4tkqS2/iRe9Tj9VUJlHSMpxMuZam0oQ==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: PH0PR00MB0984
Archived-At: <https://mailarchive.ietf.org/arch/msg/madinas/xz7dnZ9aaPzTVCia-G_tnC8tG7I>
Subject: Re: [Madinas] MAC address stickers on devices
X-BeenThere: madinas@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: MAC Address Device Identification for Network and Application Services <madinas.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/madinas>, <mailto:madinas-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/madinas/>
List-Post: <mailto:madinas@ietf.org>
List-Help: <mailto:madinas-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/madinas>, <mailto:madinas-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 14 May 2021 01:10:22 -0000

Those devices aren't headless and support strong authentication, no it doesn't really matter if they randomize or not.

________________________________
From: Michael Richardson <mcr@sandelman.ca>
Sent: Thursday, May 13, 2021 9:07:37 PM
To: Tim Cappalli <Tim.Cappalli@microsoft.com>; madinas@ietf.org <madinas@ietf.org>
Subject: Re: [Madinas] MAC address stickers on devices

Tim Cappalli <Tim.Cappalli@microsoft.com> wrote:
    > I have never come across an IoT/headless device that does MAC
    > randomization.

Yet.

Almost all digital signage (which is ironically, often not headless, but it is IoT)
is based upon a current Windows or Linux distribution, and they rarely
change many settings, so if the default is MAC randomization, in two years,
they will all be randomized.

--
]               Never tell me the odds!                 | ipv6 mesh networks [
]   Michael Richardson, Sandelman Software Works        |    IoT architect   [
]     mcr@sandelman.ca  https://nam06.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.sandelman.ca%2F&amp;data=04%7C01%7CTim.Cappalli%40microsoft.com%7C057ea1b0153d47948b9708d91674ab1b%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637565512612473697%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&amp;sdata=M2x0wRtZoUhpVhDR%2BiZNYqDw6fumeZNB1WEu96GvNvE%3D&amp;reserved=0        |   ruby on rails    [