audiospecaccts :
It goes back to the idea that they should get rid of those "virtualization features" for the common consumer
Oh, no, you have to go much farther such as disabling Hyper-Threading all together (in BIOS). That's what's being suggested by Theo de Raadt for OpenBSD; and that man is the go-to person to reference computer security.
As for the Mac address (NIC?), that has nothing to do with Spectre and Meltdown.
As for web exploitation, Spectre has been mitigated on all the major browsers against JavaScript. Specifically in regards to Firefox since 52
"Since this new class of attacks involves measuring precise time intervals, as a partial, short-term, mitigation we are disabling or reducing the precision of several time sources in Firefox. The precision of performance.now() has been reduced from 5μs to 20μs, and the SharedArrayBuffer feature has been disabled because it can be used to construct a high-resolution timer"