From Newsgroup: comp.mobile.android
Carlos E.R. wrote:
My guess is that the BSSID changed, but the router config doesn't report
it. It is mentioned somewhere as MAC, though
Hi Carlos,
As we said, I don't see your router configuration in front of me, so I can
only purposefully helpfully offer kind advice as to what's going on there.
Regarding terminology, on Usenet, we're colloquial, so we don't write our articles after having legal teams and documentation teams review every
nuance, so, often we casually use MAC address and BSSID interchangeably.
But they're not exactly the same thing, where a simple summary may be:
"Every BSSID is a MAC address, but not every MAC address is a BSSID."
These are copypasted actual definitions, which we gloss over on Usenet.
MAC Address (Media Access Control):
A broad, general term for the unique 48-bit hardware identifier
assigned to any network interface card, whether it is an Ethernet
port, a Bluetooth chip, or a Wi-Fi adapter.
BSSID (Basic Service Set Identifier):
A specific type of MAC address used exclusively in wireless networking.
It is the actual MAC address of the specific Wi-Fi radio interface
(or virtual access point) broadcasting a wireless network.
Note some sources explain the MAC address doesn't need to be a hardware ID.
MAC Address:
A broad, general term for a link-layer address, commonly 48 bits in
Ethernet and Wi-Fi, that may be factory-assigned, locally administered,
virtual, or software-generated.
Or...
A link-layer address used to identify a network interface.
Ethernet/Wi-Fi commonly use 48-bit MAC addresses, but a MAC address
need not be permanently assigned or burned into hardware.
In addition, software can assign locally administered addresses.
Ah, found it, for 2.4Ghz. It is not the same as reported by my Linux
laptop in that room, there is one digit difference. Not configurable.
Ah, there is one for 2.4G and another for 5G, they differ in the last
digit. It matches the laptop info for 5GHz, I did not know that old
laptop had the 5Gh band.
Each physical chip (2.4GHz, 5GHz) possesses a single, permanent, burned-in
MAC address assigned by the manufacturer at the factory. But a single
physical network chip can host multiple virtual interfaces simultaneously.
That's how it can
a. Broadcast a primary home network
b. Plus, a concurrent isolated guest network
c. and a concurrent IoT device network
It has been my experience, and perhaps that of others, that dual-band
wireless chipsets typically assign sequential MAC addresses (often
differing by 1 or 2 in the final digits) to separate the 2.4 GHz and 5 GHz virtual interfaces.
a. One for for 2.4 GHz (70:8b:...)
b. A similar one for 5 GHz (90:d3:...)
There's usually more virtualization with the 2.4GHz chip due to the many older/cheaper devices which can connect to it, but just like the 5 GHz
radio, a 2.4 GHz physical radio slices its hardware block into multiple
virtual interfaces, assigning each one a unique BSSID, often derived sequentially from the chip's base address pool (but they can be random).
So, one more tidbit for you: my router changes the BSSID on factory
reset, so it can not be tracked across different owners. :-)
One can often identify a randomized BSSID by the U/L (universal/local) bit, which is the second-least-significant bit of the first octet.
second hex character is not 0, 4, 8, or C for a randomized BSSID, but
instead, it's 2, 6, A, or E. However, that tells us only that the address
is locally administered but it does not prove that it was generated by a randomization mechanism. <
https://help.elevensoftware.com/hc/en-us/articles/47366137023629-Identifying-a-Randomized-MAC-Address>
Besides, relying on an accidental firmware re-indexing events in some
routers may not be an easily usable workaround unless people are willing to frequently factory reset their routers (if the router has that feature).
I said from the start that some routers can change the outward-facing
BSSID, and the paper explicitly says that some APs already randomize their BSSIDs and the authors recommend making that behavior much more widespread.
*Surveilling the Masses with Wi-Fi-Based Positioning Systems*
<
https://par.nsf.gov/servlets/purl/10540853>
If I can afford it, my next router will be the kind that changes the BSSID. BTW, apparently OpenWrt added that feature for certain compatible routers.
This is more viable than relying on accidental changes in a factory reset.
<
https://forum.archive.openwrt.org/viewtopic.php?id=62768>
option macaddr Overrides the MAC address used for the Wi-Fi interface.
when set to random, OpenWrt generates a new locally administered
unicast MAC address every time the interface is (re-)configured.
/etc/config/wireless
config wifi-iface
option device 'radio0'
option mode 'ap'
option ssid 'MyWiFi'
option encryption 'sae-mixed'
option key 'your-password'
option macaddr 'random'
However, there's a catch (there always is, as the devil is in details).
When we manually set a custom MAC address, network standards require us to
flip a specific bit in the first byte (making the second hexadecimal digit
a 2, 6, A, or E). This tells networking equipment that the address is
locally defined software rather than a permanent factory hardware ID.
Note: 2, 6, A, or E in the second hex digit tells us the address is a
locally administered unicast address (assuming ordinary left-to-right MAC notation). That can result from randomization but can also be a fixed
manually configured address in routers that allow changes.
Pop quiz!
Which three of the following are factory burned BSSIDs, vs randomized?
a. 00:1A:2B:3C:4D:50
b. 40:1A:2B:3C:4D:50
c. 80:1A:2B:3C:4D:50
d. 02:1A:2B:3C:4D:50
e. 46:1A:2B:3C:4D:50
f. 8A:1A:2B:3C:4D:50
HINT: Look at the binary representation of the second character
(check the second-to-last bit, i.e., the Universal/Local flag).
--
Usenet is where kind-hearted people gather to voluntarily help others.
--- Synchronet 3.22a-Linux NewsLink 1.2