The exploit sent his MAC address to them; so barring the use of a VM or macchanger (doubtful if he was loading Flash against all advise) that would at very least identify the traffic as coming from his computer.
Whether that proves who was at the keyboard or not is an entirely different debate.
No, it didn't. Re-read the article. The sending of MAC addresses occurred in a different, later operation with a new method (custom Firefox exploit code), rather than the Flash based IP-only method that is the focus of this article.
Whether that proves who was at the keyboard or not is an entirely different debate.