Appreciate the info. However, an attacker knowing this would only need to use prefixes from the top producers of consumer network gear. This cuts the number of MAC addresses down by a lot. I think it needs to be said somewhere in the plugin that this is not a very secure way to decrypt your data.
If the server is stolen, I assume an attacker would only need to try different MAC addresses to unlock? Since those are prefixed with vendors numbers and short, it would not take much effort to crack the password. I haven't looked at the source code, so please correct me if I am wrong.