mattx Posted January 29, 2013 Posted January 29, 2013 On this BBC article: BBC News - How hardware hacking (almost) made me a fraudster So called expert states: The motherboard swap was undoubtedly the cause of all the trouble, said James Gorbold, a veteran DIY PC maker from electronics firm Scan, which sells computers and components. "What I suspect has happened is that your motherboard will have a different network controller," he told me. That's important, he said, because the address on that component, the MAC address, is logged along with an Internet Protocol (IP) address when a computer goes online. Everything that connects to the net needs an IP address so data can reach the right destination. I am no SCAM, sorry Scan fan however, surely it would be the router's MAC address and not the PCs......?
AngryTechnician Posted January 29, 2013 Posted January 29, 2013 Yep, read that myself this morning and before even finishing the article I'd come to the conclusion that it was nonsense. Surely you've learned by now that all technology stories on BBC News are utter tosh?
Earthling Posted January 29, 2013 Posted January 29, 2013 I was confused by the high-fiving his son when the new mobo booted first time. Why wouldn't it?
Oaktech Posted January 29, 2013 Posted January 29, 2013 might be... If you had a cable setup with a direct modem connection it would be the PC Mac (best your firewall be good). Also, some cable service (former NTL and Nynex) requires you to spoof the PC mac onto the router as the PC address is recorded as an authorised address when you sign up.
mattx Posted January 29, 2013 Author Posted January 29, 2013 Yep, read that myself this morning and before even finishing the article I'd come to the conclusion that it was nonsense. Surely you've learned by now that all technology stories on BBC News are utter tosh? Yep - should have learnt my lesson by now !!
X-13 Posted January 29, 2013 Posted January 29, 2013 The real question is... Does that article have no comments, because it has no comments or because they were disabled as it's clear it's BS.
BassTech Posted January 29, 2013 Posted January 29, 2013 The real question is... Does that article have no comments, because it has no comments or because they were disabled as it's clear it's BS. I'm going to go with the latter.
Sdrawkcab Posted January 29, 2013 Posted January 29, 2013 might be... If you had a cable setup with a direct modem connection it would be the PC Mac (best your firewall be good). Would it? Isn't the MAC address changed on each hop? So the frame leaving his PC would have the MAC from his NIC as the source address (and the MAC of the interface at the router as the destination), but when the router forwards the frame to the next-hop the source would be changed to the router MAC. But hey that guy from SCAN is probaly just trying to sound "technical" so he's picked an address type that most people don't really know about. MAC addresses sound big and scary because they're PERMANENT and because most people won't actually know (or ever need to know) what they're used for. I feel especially annoyed because I only passed my CCNA Part 1 exam yesterday so I know it's wrong, to the point where I tried to track the author down on twitter to correct him!
X-13 Posted January 29, 2013 Posted January 29, 2013 MAC addresses sound big and scary because they're PERMANENT and because most people won't actually know (or ever need to know) what they're used for. Every [non-technical] person I know thinks MAC addresses have something to do with Apple. So, any shady tech support talking about MAC addresses is just going to get "but I use Windows not Apple..."
Pottsey Posted January 29, 2013 Posted January 29, 2013 (edited) I am a bit confused about some saying this is utter garbage. Whenever I change my spending habits either from a different computer, different locations or even different spending habits I get that phone call. The fraud people ring up and check everything is ok. Like many of you I have a home network and shopping from my normal computer is ok but the secondary computer can cause problems with extra security checks needed to buy items. So I can fully believe a situation where someone at his house went on the computer with the new motherboard and network card. The websites no longer register the computer as the normal computer so all the extra security checks activate. The fraud team spot the unusual activity from a new computer stop your card and ring up. What most likely happened is another family members who is used to 1 click shopping got an extra security question to fill in and did not know what to put, failed the check and the card went into lockdown. Like I said at the start it happen to me before more then once. Edited January 29, 2013 by Pottsey
mattx Posted January 29, 2013 Author Posted January 29, 2013 He is a 'Technical Marketing Manager' - 'Nuff said.
SYNACK Posted January 29, 2013 Posted January 29, 2013 I am a bit confused about some saying this is utter garbage. Whenever I change my spending habits either from a different computer, different locations or even different spending habits I get that phone call. The fraud people ring up and check everything is ok. Like many of you I have a home network and shopping from my normal computer is ok but the secondary computer can cause problems with extra security checks needed to buy items. So I can fully believe a situation where someone at his house went on the computer with the new motherboard and network card. The websites no longer register the computer as the normal computer so all the extra security checks activate. The fraud team spot the unusual activity from a new computer stop your card and ring up. What most likely happened is another family members who is used to 1 click shopping got an extra security question to fill in and did not know what to put, failed the check and the card went into lockdown. Like I said at the start it happen to me before more then once. Nothing to do with the MAC address though, if your PC is leaking a MAC address to the wider internet your security does not exist, it's just not the way IP works.
Sdrawkcab Posted January 29, 2013 Posted January 29, 2013 I am a bit confused about some saying this is utter garbage. Whenever I change my spending habits either from a different computer, different locations or even different spending habits I get that phone call. The fraud people ring up and check everything is ok. Like many of you I have a home network and shopping from my normal computer is ok but the secondary computer can cause problems with extra security checks needed to buy items. So I can fully believe a situation where someone at his house went on the computer with the new motherboard and network card. The websites no longer register the computer as the normal computer so all the extra security checks activate. The fraud team spot the unusual activity from a new computer stop your card and ring up. What most likely happened is another family members who is used to 1 click shopping got an extra security question to fill in and did not know what to put, failed the check and the card went into lockdown. Like I said at the start it happen to me before more then once. I'm not saying that the article overall was wrong, just the guy from Scan when he was talking about MAC addresses being used for identification. Though equally I don't see why they'd use hardware as a means of identifying someone online. I have a load of devices I use to access the internet and I've never had my card stopped due to purchases I've made from them. Location/time zone I can understand, but not IP address or hardware because they both have potential to change dramatically without warning. I think this article was mostly borne out of the BBC guy being low on ideas for articles, and the SCAN guy getting his technical explanation spectacularly incorrect.
Pottsey Posted January 29, 2013 Posted January 29, 2013 (edited) Nothing to do with the MAC address though, if your PC is leaking a MAC address to the wider internet your security does not exist, it's just not the way IP works. I thought some online shops build up a profile up with your local IP and MAC address. Steam for example records your local network card and MAC address doesn’t it? You cannot buy items from a different new PC and new network card. Out of curiosity when websites build a profile off your PC what info do they store? Edited January 29, 2013 by Pottsey
mattx Posted January 29, 2013 Author Posted January 29, 2013 I think this article was mostly borne out of the BBC guy being low on ideas for articles, and the SCAN guy getting his technical explanation spectacularly incorrect. Problem now with this idiot spouting a load of FAS - Vmyths » False Authority Syndrome is that he will asked to contribute to yet more pointless articles. Maybe he knows Andrew Benson the BBC Formula 1 writer. His articles are complete and utter shit too.
Jamman960 Posted January 29, 2013 Posted January 29, 2013 Very little info is passed along to websites while browsing, things like OS version, Browser Type&Version, screen resolution & obviously IP address are but MAC address certainly isn't although I guess an activeX script may be able to pull it in some way? Games may possibly check the MAC address for copy protection purposes As above none of these would be reliable ways to prevent fraud, unusually large/frequent transactions or transactions from other countrys raise alarm bells. I hope the BBC aren't paying him much, I'd fear for my job if I let that article get published!
SYNACK Posted January 29, 2013 Posted January 29, 2013 I thought some online shops build up a profile up with your local IP and MAC address. Steam for example records your local network card and MAC address doesn’t it? You cannot buy items from a different network card. Out of curiosity when websites build a profile off your PC what info do they store? MAC is layer two and does not transition layer 3 boundaries ( routers ) steam may be able to use Mac as it is a local app so it can access the hardware layer, if a browser did that they would probably be brought before several dozen privacy commissioners. Sites can grab user agent string, takes is and browser engine, sometimes platform ( but this can be spoofed ), Java ( this time by design ) can leak all sorts like resolution, have version, colour depth etc. Cookies can also be accessed. Using this and browser/plugin fingerprinting you can identify PCs quite well.
Sdrawkcab Posted January 29, 2013 Posted January 29, 2013 I thought some online shops build up a profile up with your local IP and MAC address. Steam for example records your local network card and MAC address doesn’t it? You cannot buy items from a different new PC and new network card. Your MAC address will never even make it onto the internet. It's best if you think of MAC addressing as a way for the network to know what device to direct your messages to next. So the frame (chunk of data) leaving your PC has your network card as the source MAC and your router as the destination MAC. When it reaches your router, the router changes the frame so that it has the router as the source MAC and the next-hop device (probably another router) as the destination. By the time the data reaches its intended target, the MAC addresses on the frame will have been changed multiple times. I would imagine they store a cookie on your machine to identify you primarily, and then use things like time zone/location to back that up. Steam uses a cookie method where it places an encrypted cookie containing a hardware profile of the PC on your machine to identify you after you enter the email verificaion code. I think that's to stop people stealing your cookie and using it to authenticate their own session on the steam store though, I don't think they prevent you from logging in on another machine as long as you enter the correct code from the email verification.
tech_guy Posted January 29, 2013 Posted January 29, 2013 Yep, read that myself this morning and before even finishing the article I'd come to the conclusion that it was nonsense. Surely you've learned by now that all technology stories on BBC News are utter tosh? Especially the ones 'written' by Rory Cellophane-Jones.........
mattx Posted January 29, 2013 Author Posted January 29, 2013 Especially the ones 'written' by Rory Cellophane-Jones......... Can that plonker actually write ? Lordy !!
Pottsey Posted January 29, 2013 Posted January 29, 2013 “Steam uses a cookie method where it places an encrypted cookie containing a hardware profile of the PC on your machine to identify you after you enter the email verificaion code.” Thanks for the info. I was thinking surly part of the hardware profile is the motherboard, network card and MAC address? Even if it’s not being sent across the internet, local hardware is being used to identify computers for some online shops like Steam or Itunes. Changing the motherboard and network cards would be more than enough to make the hardware profile invalid. Perhaps the article writer was wrong about the Mac address but I think he was on the right idea that changing the network card and motherboard was what triggered the fraud protection.
Sdrawkcab Posted January 29, 2013 Posted January 29, 2013 Changing the motherboard and network cards would be more than enough to make the hardware profile invalid. Perhaps the article writer was wrong about the Mac address but I think he was on the right idea that changing the network card and motherboard was what triggered the fraud protection. That's only for each machine though. Steam will allow you to login to multiple machines and will store a seperate cookie on each one. The hardware profile, in this case, is used to prevent malware from stealing the cookie and using it to authenticate another machine (rather than stealing the password to the account and using that to login elsewhere). The only time I've ever had something like this happen to me was when I used Tor at a previous job to get around the work firewall and buy something from Amazon. Because the login appeared to come from a totally different geographical location, the bank cancelled my card. I've never had an issue using multiple PCs within the same country though.
jbunoomally Posted January 29, 2013 Posted January 29, 2013 On this BBC article: BBC News - How hardware hacking (almost) made me a fraudster Corrent me if I'm wrong....but. *Correct* /Pedant. They see me trollin'. . . . 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now