A media access control address identifies a network interface at a local link. Older mobile-device analytics systems benefited from the fact that phones could expose the same factory Wi-Fi address while searching in different places. That value was attractive because it was stable, not because a MAC address inherently contained a customer’s name.
Apple and Android changed this behavior over multiple operating-system releases. Modern implementations randomize addresses used during unassociated discovery and ordinarily use a private address when joining a network. Recent Apple systems can also rotate the address used on certain networks. The word “randomization” therefore describes a family of behaviors rather than one universal switch.
Why a stable MAC address was useful for tracking
If the same address appeared at a mall entrance on Monday and again on Friday, a sensor operator could count a repeat visit. Sensors across zones could record where that address appeared strongest. If a later interaction connected the address to a portal login or loyalty account, earlier observations might become more meaningful.
The Federal Trade Commission’s 2014 mobile-device tracking seminar described retail systems that collected MAC addresses broadcast while phones searched for Wi-Fi and used them to estimate paths, dwell time, new versus returning visitors, and visit frequency. That description explains the privacy rationale for randomization, but it should not be copied into a current article as if phone behavior stood still.
A private or randomized address removes the simple assumption that one factory value will appear in every unrelated location. The observer now has to handle rotation, short-lived values, and uncertainty. That is a real improvement, even though it does not eliminate every form of correlation.
The three Wi-Fi contexts that change the answer
Unassociated scanning
A device not connected to Wi-Fi may scan to find networks or support platform services. Apple says supported platforms use a randomized MAC address for these scans and randomize sequence numbers and other fields to reduce correlation. Android says devices have used randomized addresses when probing for new networks since Android 8. A passive observer should not expect the permanent factory address in normal modern scanning.
Associating with a network
A client and access point exchange management traffic while establishing a connection. The client still needs an address for the link, but current devices usually substitute a private value. The scope and persistence of that value matter: it may be stable for one saved network, rotate under defined conditions, or be controlled by enterprise configuration.
Connected to a network
Once connected, the network necessarily sees the address being used for that connection and can record operational events such as association time and access-point changes. The address may be private relative to other networks, but it can remain a consistent handle within this network for a period. A captive portal, authentication system, or app can also attach account information.
How Apple describes Private Wi-Fi Address behavior
Apple’s platform-security documentation says randomized addresses are used during unassociated scans on supported devices. It also describes protections for sequence numbers, scrambling seeds, and dialogue-token fields that could otherwise form correlation patterns. Apple notes an exception: scans performed while attempting to connect to a preferred network are not randomized in the same way.
For joined networks, Apple’s current user documentation offers Off, Fixed, and Rotating modes on recent operating systems. Fixed uses a private address that does not rotate for that network. Rotating changes the private address periodically; Apple says recent systems choose Rotating by default for weak-security or open networks and Fixed for WPA2 or stronger networks. Older releases use different lifetimes and reset conditions.
These details matter when troubleshooting. A router may report a “new device” after rotation. Access controls tied to one address can break. The privacy-preserving response is normally to update the network configuration, not immediately disable private addressing across every network.
How Android describes MAC randomization
The Android Open Source Project documents two major milestones: randomized addresses for probes beginning in Android 8, and default client-mode randomization in Android 10. Android’s implementation guidance requires a user control for randomization on each saved network and describes a private address that can be persistent per SSID.
Android is an ecosystem, not one hardware-software combination. Device vendors implement networking components, managed enterprise devices can apply policies, older phones may lack current protections, and users can disable settings. The correct way to describe a particular phone is to check its current network details rather than infer behavior only from the Android brand.
Android’s current compatibility material continues to recommend or require privacy-preserving behavior in multiple Wi-Fi roles. That does not guarantee identical rotation schedules across vendors, and it does not stop a network from recognizing the private address it has assigned or previously observed.
What can remain visible after randomization
- Network membership. The access point sees the private address used for a live association.
- Timing and topology. A network can log when a client connects and which managed access point serves it.
- Portal or account links. Signing in can connect a network session to submitted contact or account information.
- Application data. Apps with permission can create their own identifiers and location events independent of the Wi-Fi MAC.
- Other radios and accessories. Bluetooth devices, wearables, vehicles, and tags have separate protocols and privacy behavior.
- Non-radio records. Cameras, payments, license-plate readers, and cellular networks are unaffected by a Wi-Fi address change.
Researchers and vendors sometimes discuss fingerprinting from timing, capabilities, or implementation quirks. These methods are not equivalent to reading one permanent field, and their reliability changes as platforms add protections. A strong claim should name the tested operating-system version, hardware, network state, capture method, sample size, and error rate.
How to check and improve your settings
- Update the operating system. Privacy improvements have arrived across multiple releases.
- Inspect each saved network. Look for Private Wi-Fi Address, Randomized MAC, Privacy, or a similar option.
- Prefer private addressing. Leave it enabled unless a specific network problem requires a temporary exception.
- Forget networks you no longer use. This reduces automatic connection attempts and cleans up saved trust relationships.
- Avoid unnecessary portal identity links. Consider whether free Wi-Fi is worth submitting an email, phone number, or loyalty login.
- Audit managed-device policies. Work or school profiles may control networking behavior.
Randomization should be treated as a strong baseline, not a reason to ignore other channels. Flock Block’s decoy-radio approach targets ambiguity in passive Bluetooth and Wi-Fi collection. It does not replace private addresses, and it cannot remove connection or account records created when a user intentionally joins a network.
A different privacy layer
Roadside cameras are optical. Flock Block works on wireless noise.
Flock Block does not block license plate readers. It is designed to detect compatible nearby wireless scanners and add decoy Bluetooth and Wi-Fi activity around the devices you carry.
Understand the differenceFrequently asked questions
Should I turn off Private Wi-Fi Address to fix a connection?
Update the device and network first. Some legacy networks rely on fixed hardware addresses, but disabling private addressing weakens privacy for that network. Use the narrowest temporary exception necessary.
Does each Wi-Fi network see a different address?
Current Apple and Android implementations are designed to use private addresses scoped to networks, but exact persistence and rotation depend on platform version, settings, device management, and implementation.
Can my router still recognize my phone?
Yes. A router can recognize and manage the private address currently used on its network, especially while it remains stable for that network. The benefit is reducing reuse of the factory address across unrelated networks.
Does MAC randomization affect Bluetooth?
Wi-Fi and Bluetooth use separate addressing and privacy mechanisms. A private Wi-Fi address does not itself change every Bluetooth advertisement or accessory behavior.