{
  "id": 54648,
  "title": "Why don't we use MAC address to identify the fraud clicks?",
  "url": "/competitions/talkingdata-adtracking-fraud-detection/discussion/54648",
  "author_name": "",
  "post_date": "2018-04-16T09:57:15.973226300Z",
  "votes": 6,
  "comment_count": 9,
  "views": 0,
  "content": "<blockquote>\n  <p><a href=\"https://en.wikipedia.org/wiki/MAC_address\">MAC address</a>: A media access control address (MAC address) of a device is a <strong>unique</strong> identifier assigned to network interface controllers for communications at the data link layer of a network segment.</p>\n</blockquote>\n\n<p>As we all konw in this competition, single IP address can be very hard to indentify certain group of people because of massive local network NAT and VPN etc. So why don't we collect and use the unique number of the network interface controller - the MAC address. As we can simply get the os, device type of the phone, it should be easy to get the MAC address as well, then it will be way much helpful to judge the fruad clicks.</p>\n\n<p>So we don't use it just because it can be easily changed as IP or some other reasons?</p>",
  "messages": [
    {
      "id": "314806",
      "postDate": "04/16/2018 09:57:15",
      "content": "<blockquote>\n  <p><a href=\"https://en.wikipedia.org/wiki/MAC_address\">MAC address</a>: A media access control address (MAC address) of a device is a <strong>unique</strong> identifier assigned to network interface controllers for communications at the data link layer of a network segment.</p>\n</blockquote>\n\n<p>As we all konw in this competition, single IP address can be very hard to indentify certain group of people because of massive local network NAT and VPN etc. So why don't we collect and use the unique number of the network interface controller - the MAC address. As we can simply get the os, device type of the phone, it should be easy to get the MAC address as well, then it will be way much helpful to judge the fruad clicks.</p>\n\n<p>So we don't use it just because it can be easily changed as IP or some other reasons?</p>",
      "rawMarkdown": "&gt; [MAC address](https://en.wikipedia.org/wiki/MAC_address): A media access control address (MAC address) of a device is a **unique** identifier assigned to network interface controllers for communications at the data link layer of a network segment.\n\nAs we all konw in this competition, single IP address can be very hard to indentify certain group of people because of massive local network NAT and VPN etc. So why don't we collect and use the unique number of the network interface controller - the MAC address. As we can simply get the os, device type of the phone, it should be easy to get the MAC address as well, then it will be way much helpful to judge the fruad clicks.\n\nSo we don't use it just because it can be easily changed as IP or some other reasons?",
      "votes": null
    },
    {
      "id": "315092",
      "postDate": "04/16/2018 18:32:50",
      "content": "<p>People can indeed present fake MAC addresses with <a href=\"https://www.howtogeek.com/192173/how-and-why-to-change-your-mac-address-on-windows-linux-and-mac/\">just a few lines of code</a> - the practice is called <a href=\"https://en.wikipedia.org/wiki/MAC_spoofing\">MAC Spoofing</a>.</p>\n\n<p>It would still be nice to have since MAC is more granular than IP address, but I would be curious what percent of fraudsters employ spoofing.</p>",
      "rawMarkdown": "People can indeed present fake MAC addresses with [just a few lines of code][1] - the practice is called [MAC Spoofing][2].\n\nIt would still be nice to have since MAC is more granular than IP address, but I would be curious what percent of fraudsters employ spoofing.\n\n\n  [1]: https://www.howtogeek.com/192173/how-and-why-to-change-your-mac-address-on-windows-linux-and-mac/\n  [2]: https://en.wikipedia.org/wiki/MAC_spoofing",
      "votes": null
    },
    {
      "id": "315393",
      "postDate": "04/17/2018 03:51:30",
      "content": "<p>Thanks David!</p>\n\n<blockquote>\n  <p>To prevent third parties from using the MAC address to track devices, Android, Linux, iOS, and Windows[6] have implemented MAC address randomization. In June 2014, Apple announced that future versions of their iOS platform would randomize MAC addresses for all WiFi connections. The Linux kernel has supported MAC address randomization during network scans since March 2015,[7] but drivers need to be updated to use this feature.[8] Windows has supported it since the release of Windows 10[6] in July 2015. From wikipedia.</p>\n</blockquote>\n\n<p>It seems we almost cannot get the right MAC address, i now understand why we don't use it.</p>",
      "rawMarkdown": "Thanks David!\n\n&gt; To prevent third parties from using the MAC address to track devices, Android, Linux, iOS, and Windows[6] have implemented MAC address randomization. In June 2014, Apple announced that future versions of their iOS platform would randomize MAC addresses for all WiFi connections. The Linux kernel has supported MAC address randomization during network scans since March 2015,[7] but drivers need to be updated to use this feature.[8] Windows has supported it since the release of Windows 10[6] in July 2015. From wikipedia.\n\nIt seems we almost cannot get the right MAC address, i now understand why we don't use it.",
      "votes": null
    },
    {
      "id": "315448",
      "postDate": "04/17/2018 06:07:49",
      "content": "<p>While what you are saying is absolutely true, using vpn for hiding ip addresses makes ip address no better than MAC.</p>",
      "rawMarkdown": "While what you are saying is absolutely true, using vpn for hiding ip addresses makes ip address no better than MAC.",
      "votes": null
    },
    {
      "id": "315476",
      "postDate": "04/17/2018 06:42:06",
      "content": "<p>No identification mechanism is perfect. Therefore it is very important to use other information (such as the one provided in this competition) to detect fraud. For instance, if we can detect very similar suspect behavior coming from multiple addresses, we can (with some confidence) predict that it is coming from the same user. Similarly, inhuman behavior can be attributed to a machine. This is the mechanism that the creators of MMORPGs use to detect fraud.</p>",
      "rawMarkdown": "No identification mechanism is perfect. Therefore it is very important to use other information (such as the one provided in this competition) to detect fraud. For instance, if we can detect very similar suspect behavior coming from multiple addresses, we can (with some confidence) predict that it is coming from the same user. Similarly, inhuman behavior can be attributed to a machine. This is the mechanism that the creators of MMORPGs use to detect fraud.",
      "votes": null
    },
    {
      "id": "315496",
      "postDate": "04/17/2018 07:23:13",
      "content": "<p>Thanks! It really helps!</p>",
      "rawMarkdown": "Thanks! It really helps!",
      "votes": null
    },
    {
      "id": "315507",
      "postDate": "04/17/2018 07:38:35",
      "content": "<p>Is that not coded with the device feature ??</p>",
      "rawMarkdown": "Is that not coded with the device feature ??",
      "votes": null
    },
    {
      "id": "315522",
      "postDate": "04/17/2018 07:55:30",
      "content": "<blockquote>\n  <p>device: device type id of user mobile phone (e.g., iphone 6 plus, iphone 7, huawei mate 7, etc.)</p>\n</blockquote>\n\n<p>It seems not, only the type of the moblie phone.</p>",
      "rawMarkdown": "&gt; device: device type id of user mobile phone (e.g., iphone 6 plus, iphone 7, huawei mate 7, etc.)\n\nIt seems not, only the type of the moblie phone.",
      "votes": null
    },
    {
      "id": "315579",
      "postDate": "04/17/2018 09:55:10",
      "content": "<p>MAC cannot be available when somebody clicks on ads on the web, only IP and user agent are available (Assuming we are talking about web ads, and not in-app ads). Os/Device can be retrieved from user agent, that is why I think we have them in the data.</p>",
      "rawMarkdown": "MAC cannot be available when somebody clicks on ads on the web, only IP and user agent are available (Assuming we are talking about web ads, and not in-app ads). Os/Device can be retrieved from user agent, that is why I think we have them in the data.",
      "votes": null
    },
    {
      "id": "315636",
      "postDate": "04/17/2018 11:36:15",
      "content": "<p>Thanks Alexander! Thanks for the domain knowledge!</p>",
      "rawMarkdown": "Thanks Alexander! Thanks for the domain knowledge!",
      "votes": null
    }
  ],
  "comments": [
    {
      "id": 315092,
      "author_name": "davebthomas",
      "author_url": "",
      "post_date": "04/16/2018 18:32:50",
      "content": "<p>People can indeed present fake MAC addresses with <a href=\"https://www.howtogeek.com/192173/how-and-why-to-change-your-mac-address-on-windows-linux-and-mac/\">just a few lines of code</a> - the practice is called <a href=\"https://en.wikipedia.org/wiki/MAC_spoofing\">MAC Spoofing</a>.</p>\n\n<p>It would still be nice to have since MAC is more granular than IP address, but I would be curious what percent of fraudsters employ spoofing.</p>",
      "votes": null,
      "replies": [
        {
          "id": 315393,
          "author_name": "wenjiebai",
          "author_url": "",
          "post_date": "04/17/2018 03:51:30",
          "content": "<p>Thanks David!</p>\n\n<blockquote>\n  <p>To prevent third parties from using the MAC address to track devices, Android, Linux, iOS, and Windows[6] have implemented MAC address randomization. In June 2014, Apple announced that future versions of their iOS platform would randomize MAC addresses for all WiFi connections. The Linux kernel has supported MAC address randomization during network scans since March 2015,[7] but drivers need to be updated to use this feature.[8] Windows has supported it since the release of Windows 10[6] in July 2015. From wikipedia.</p>\n</blockquote>\n\n<p>It seems we almost cannot get the right MAC address, i now understand why we don't use it.</p>",
          "votes": null,
          "replies": []
        },
        {
          "id": 315448,
          "author_name": "enfeizhan",
          "author_url": "",
          "post_date": "04/17/2018 06:07:49",
          "content": "<p>While what you are saying is absolutely true, using vpn for hiding ip addresses makes ip address no better than MAC.</p>",
          "votes": null,
          "replies": []
        }
      ]
    },
    {
      "id": 315476,
      "author_name": "branislav1991",
      "author_url": "",
      "post_date": "04/17/2018 06:42:06",
      "content": "<p>No identification mechanism is perfect. Therefore it is very important to use other information (such as the one provided in this competition) to detect fraud. For instance, if we can detect very similar suspect behavior coming from multiple addresses, we can (with some confidence) predict that it is coming from the same user. Similarly, inhuman behavior can be attributed to a machine. This is the mechanism that the creators of MMORPGs use to detect fraud.</p>",
      "votes": null,
      "replies": [
        {
          "id": 315496,
          "author_name": "wenjiebai",
          "author_url": "",
          "post_date": "04/17/2018 07:23:13",
          "content": "<p>Thanks! It really helps!</p>",
          "votes": null,
          "replies": []
        }
      ]
    },
    {
      "id": 315507,
      "author_name": "dramanettayeb",
      "author_url": "",
      "post_date": "04/17/2018 07:38:35",
      "content": "<p>Is that not coded with the device feature ??</p>",
      "votes": null,
      "replies": [
        {
          "id": 315522,
          "author_name": "wenjiebai",
          "author_url": "",
          "post_date": "04/17/2018 07:55:30",
          "content": "<blockquote>\n  <p>device: device type id of user mobile phone (e.g., iphone 6 plus, iphone 7, huawei mate 7, etc.)</p>\n</blockquote>\n\n<p>It seems not, only the type of the moblie phone.</p>",
          "votes": null,
          "replies": []
        }
      ]
    },
    {
      "id": 315579,
      "author_name": "alexfir",
      "author_url": "",
      "post_date": "04/17/2018 09:55:10",
      "content": "<p>MAC cannot be available when somebody clicks on ads on the web, only IP and user agent are available (Assuming we are talking about web ads, and not in-app ads). Os/Device can be retrieved from user agent, that is why I think we have them in the data.</p>",
      "votes": null,
      "replies": [
        {
          "id": 315636,
          "author_name": "wenjiebai",
          "author_url": "",
          "post_date": "04/17/2018 11:36:15",
          "content": "<p>Thanks Alexander! Thanks for the domain knowledge!</p>",
          "votes": null,
          "replies": []
        }
      ]
    }
  ],
  "raw_markdown_by_id": {
    "314806": "&gt; [MAC address](https://en.wikipedia.org/wiki/MAC_address): A media access control address (MAC address) of a device is a **unique** identifier assigned to network interface controllers for communications at the data link layer of a network segment.\n\nAs we all konw in this competition, single IP address can be very hard to indentify certain group of people because of massive local network NAT and VPN etc. So why don't we collect and use the unique number of the network interface controller - the MAC address. As we can simply get the os, device type of the phone, it should be easy to get the MAC address as well, then it will be way much helpful to judge the fruad clicks.\n\nSo we don't use it just because it can be easily changed as IP or some other reasons?",
    "315092": "People can indeed present fake MAC addresses with [just a few lines of code][1] - the practice is called [MAC Spoofing][2].\n\nIt would still be nice to have since MAC is more granular than IP address, but I would be curious what percent of fraudsters employ spoofing.\n\n\n  [1]: https://www.howtogeek.com/192173/how-and-why-to-change-your-mac-address-on-windows-linux-and-mac/\n  [2]: https://en.wikipedia.org/wiki/MAC_spoofing",
    "315393": "Thanks David!\n\n&gt; To prevent third parties from using the MAC address to track devices, Android, Linux, iOS, and Windows[6] have implemented MAC address randomization. In June 2014, Apple announced that future versions of their iOS platform would randomize MAC addresses for all WiFi connections. The Linux kernel has supported MAC address randomization during network scans since March 2015,[7] but drivers need to be updated to use this feature.[8] Windows has supported it since the release of Windows 10[6] in July 2015. From wikipedia.\n\nIt seems we almost cannot get the right MAC address, i now understand why we don't use it.",
    "315448": "While what you are saying is absolutely true, using vpn for hiding ip addresses makes ip address no better than MAC.",
    "315476": "No identification mechanism is perfect. Therefore it is very important to use other information (such as the one provided in this competition) to detect fraud. For instance, if we can detect very similar suspect behavior coming from multiple addresses, we can (with some confidence) predict that it is coming from the same user. Similarly, inhuman behavior can be attributed to a machine. This is the mechanism that the creators of MMORPGs use to detect fraud.",
    "315496": "Thanks! It really helps!",
    "315507": "Is that not coded with the device feature ??",
    "315522": "&gt; device: device type id of user mobile phone (e.g., iphone 6 plus, iphone 7, huawei mate 7, etc.)\n\nIt seems not, only the type of the moblie phone.",
    "315579": "MAC cannot be available when somebody clicks on ads on the web, only IP and user agent are available (Assuming we are talking about web ads, and not in-app ads). Os/Device can be retrieved from user agent, that is why I think we have them in the data.",
    "315636": "Thanks Alexander! Thanks for the domain knowledge!"
  },
  "source": "meta"
}