Can an attacker exploit my /etc/machine-id?

Viewed 460

I am writing software that needs to uniquely identify multiple different machines. I was planning on using /etc/machine-id to do this.

While reading the docs for machine-id, I stumbled upon this passage:

This ID uniquely identifies the host. It should be considered "confidential", and must not be exposed in untrusted environments, in particular on the network. If a stable unique identifier that is tied to the machine is needed for some application, the machine ID or any part of it must not be used directly. Instead the machine ID should be hashed with a cryptographic, keyed hash function, using a fixed, application-specific key.

Is this really the case? If so, what could an attacker actually exploit using the machine-id? I don't know much about d-bus, but I was under the impression that it's only for IPC, and therefore I'm not sure why it would really matter if a remote attacker knew the machine-id. I was planning on sending / storing these unencrypted, but would rather not if it's going to be a security issue.

Edit: This question was answered here by someone familiar with the issue. Basically, the recommendation in the manpage is just for privacy reasons, not due to any actual security issues.

0 Answers
Related