Err my initial comment was a friendly warning that you were indeed making yourself look like an idiot by posting a whole bunch of irrelevant copypastas that you obviously didn't understand, and at the same time calling everyone else in the thread a retard. That's not social pressure, because like I said before, I don't know you, I don't know anyone who knows you, and I don't really care if you make a fool of yourself or not - but it irritates me when people muddy up a perfectly good thread with irrelevant nonsense. However a quick skim of your posts reveals that you spend a lot of time abusing other posters, like to regurgitate "truths" that people who do robust testing know actually aren't true, and thus probably don't push real volume.
There are a bunch of posts over on stackoverflow from one of the developers of BlueCava where he talks about how the MAC address is basically useless for device identification because it's easily changed, unreliable to obtain (because it requires vectors like ActiveX and Java which we have already discussed) and a large chunk of devices don't use it (e.g. devices on dial up and 3G connections).
The facts remain that: this is a thread specifically about Paypal, Ebay and perhaps web browser usage in general; and you are generally safe from MAC address discovery via the web if you avoid IE / ActiveX, Java and possibly Flash. Methods to avoid fingerprinting have already been enumerated by myself and other people in this thread, i.e. use VMs.
I fully admit that I may have been wrong about Flash, but from what my brief research today indicates, the MAC address is only accessible from Flashplayer if you are using Flash Lite (the mobile version of Flash) with some device-specific proprietary Actionscript extensions and a network interface that requires a MAC address (i.e. wifi). I am not a Flash programmer and I turn off Flash if I'm doing anything dodgy (as everyone should) so I'm not going to investigate it further.
No, the "takeaway" is that if you weren't such an arrogant and obnoxious ass, I wouldn't have had to push so hard in keeping this thread going until someone that knew something interesting showed up and posted it.
I'm not quite sure what you're dribbling about here, but if you are talking about fingerprinting (which I did, in fact, mention first, rather than your misguided dwelling on MAC addresses), browser fingerprinting and device fingerprinting are essentially the same thing, because they identify individual users based on installed plugins and fonts, browser headers, latencies in http responses etc. Device fingerprinting just takes it one step further and is designed to defeat the user from changing their browser to defeat the fingerprint. You could actually spend some time learning about this stuff instead of posting a whole bunch of crap, but I'm not going to hold my breath. Way to ruin a thread... Dude.
