skip to content

A MAC bypass rule permits any address in the camera vendor's OUI range: what can an attacker do with it, and what scoping have you lost?

level: middleimportance: should knowfreq 41%

answer

  1. 24 bits matched, 24 bits free
  2. no real camera needed at all
  3. public vendor prefix, published lists
  4. one rule can carry only one authorisation
  5. the unknown-address reject signal disappears

basics

~20 s

It makes spoofing trivial: an attacker sets any address beginning with that vendor prefix and needs no real camera at all. It also collapses per-device scoping, because one rule can only carry one authorisation for everything it matches.

solid answer

~50 s

The first 24 bits of a MAC address are the IEEE-assigned vendor prefix, and the remaining 24 are whatever the sender writes. So a wildcard rule on an OUI does not say `these forty cameras`; it says `any host willing to start its address with these six hex digits`. The attacker needs no camera, no label and no wait — they invent an address in the range. The second cost is the one people miss: one rule matches a whole device class, so the accept can only carry one authorisation profile. The imaging console lands where the badge reader lands, and you can no longer say `this address may reach the archive and nothing else`. The reason wildcards get written is real — biomedical engineering adds devices weekly and nobody wants a ticket per pump — so the answer is an enrolment step plus narrow per-entry authorisation, not a broader match.

go deeper

for a junior

Know that the first 24 bits of a MAC address are a public vendor prefix and the rest is whatever the sender writes, so a rule matching only the prefix is matching almost nothing.

for a middle

Be able to walk both costs: the forgery becomes free because no real device is needed, and the accept can only carry one authorisation for the whole matched class. Say why the rule got written in the first place.

for a senior

Show the trade you would actually make — kill the enrolment friction that produced the wildcard, then spend the security budget on narrow per-entry authorisation and place-bounded entries rather than on a stricter match.

for a principal

Frame it as an exception-register design question: what intake and approval path lets a clinical team commission a device in an hour without the network team writing a rule that matches sixteen million addresses.

## What an OUI is, precisely A MAC address is 48 bits. The top 24 are the Organisationally Unique Identifier, assigned by the IEEE to a manufacturer; the bottom 24 are assigned by that manufacturer to individual interfaces. A rule that matches on the OUI alone is therefore matching a quarter of the address and ignoring the sixteen million values below it. ## Why people write the rule anyway The pressure is genuine and it is worth saying so in an interview rather than sneering at it. In a hospital wing, biomedical engineering commissions devices on their own schedule: pumps, monitors, carts, a replacement camera when one fails at 2am. Every one of those is a device that cannot run a supplicant, so every one of them needs a bypass entry. If each entry means a ticket, an approval and a change window, the network team becomes the reason clinical equipment sits in a box, and the pressure to write `permit anything from this vendor` is immediate. The wildcard is not laziness; it is an operational shortcut bought with a security property. Name the property you sold. ## What the attacker gets With a per-device list, the attacker's work is: identify a specific permitted device, obtain its address (label, asset sticker, or simply observing frames on the segment), and present it — usually meaning they must displace or coexist with the real device. With an OUI wildcard, all of that disappears. The prefix is public information — vendor prefixes are published and trivially looked up from any observed frame. The attacker sets an address that begins with it and fills the rest arbitrarily. They never touch a camera, never risk knocking one offline, and never collide with a real device's address, which also means nothing anomalous shows up as a duplicate. The bypass check is now satisfied by anyone who can type. ## The cost that is easier to miss A bypass entry is not just a match; it is a match plus an authorisation. The accept carries what the admitted device may do — a VLAN, a per-session ACL, or both. A rule that matches one address can carry an authorisation shaped to that one device: this camera may reach the video archive on one port and nothing else; this pump may reach its own management server and nothing else. A rule that matches a whole OUI cannot. Every device the wildcard covers receives the same profile, so the profile has to be the union of everything that class of device needs. In practice that means the imaging console's reach and the badge reader's reach become one reach, and the segment you land them in has to be wide enough for the most demanding member of the class. You have simultaneously made the identity easier to forge and the prize behind it larger — the two failures compound rather than add. There is a third loss. Part of what MAB buys you is a record: an unknown address produces a reject, which is a signal that something new appeared on a port. Under a wildcard, an attacker's fabricated address produces an accept indistinguishable from a legitimate one, so the signal is gone too. ## What to do instead - **Enrol, do not wildcard.** Accept that each device gets an entry, and remove the friction that made the wildcard attractive: a lightweight intake where the department supplies the address and the device record, with the network team's part measured in minutes rather than a change advisory board. - **Scope the accept, per entry.** The realistic security here is not in the match, it is in the authorisation. Narrow accepts make the whole question of who can forge the address much less interesting. - **Bound the rule by place.** An entry that is only valid on the ports in the ward where the device physically lives is meaningfully harder to use from a lobby socket than one valid estate-wide. - **Give the entry a lifetime.** A wildcard never expires because it names nobody; a per-device entry can carry an owner and a review date, which is what stops the list becoming a permanent unowned register. ## How to answer this in a loop The strong answer states the arithmetic (24 bits matched, 24 free), states the operational reason the rule exists, and then makes the compounding point: a wildcard both cheapens the forgery and widens the authorisation, because a rule matching many devices can only carry one profile. Then it offers the trade the interviewer is really testing for — reduce the cost of enrolling a device rather than broadening the match.

  • The device team says per-device entries are too slow. What do you offer them?
    Reduce the cost of enrolling, not the strength of the rule. Give them a lightweight intake where they supply the address and the device record and the entry is created in minutes, pre-approve the authorisation profile for each device class so only the address is new, and agree a standing change window for commissioning. The friction is process, and process is cheaper to fix than a forged identity.
  • Does bounding a bypass entry to specific ports actually help, given the attacker can also stand in the ward?
    It helps, and it is not a complete answer. It removes the easy attempt from a lobby socket or an unattended meeting room and forces the attacker into the physical space where the device lives, which is more observable and often badge-controlled. Treat it as raising the cost, not as prevention — the authorisation attached to the accept is still what decides what a successful spoof is worth.

saying these in an interview costs you the question

  • Thinks the attacker must first find a real device's address
  • Believes vendor prefixes are hard to discover
  • Misses that one rule can only carry one authorisation profile
  • Defends the wildcard as fine because the segment is separate anyway
  • Never mentions the enrolment friction that caused the wildcard

context