> The only way I could imagine being able to determine that is by looking at the vendor bits on the MAC addresses of the source. But being that IoT devices are generally on a LAN on with some RFC 1918 address you wouldn't have that information.
Your not going to have that even if the device has a public IP unless it is a public IPv6 address on a device not using privacy extensions.
MAC addresses are link local only and are not transmitted beyond their local layer 2 network.
There is device finger printing that you can do on the peculiarities of individual IP stack implementations, but honestly without solid proof or explanations from Krebs, they way he is holding himself out as a martyr over this leads me to not believing sensational claims he's making over the event.
Your not going to have that even if the device has a public IP unless it is a public IPv6 address on a device not using privacy extensions.
MAC addresses are link local only and are not transmitted beyond their local layer 2 network.
There is device finger printing that you can do on the peculiarities of individual IP stack implementations, but honestly without solid proof or explanations from Krebs, they way he is holding himself out as a martyr over this leads me to not believing sensational claims he's making over the event.