Device identity should be unique

Every device needs its own identity, or you cannot revoke one without revoking all of them.

A shared key across a product line means compromising one unit compromises the fleet, and there is no way to isolate the bad one. Per-device credentials, provisioned during manufacture, are more work upfront and are what make it possible to respond to a single compromised device at all.

More on IoT and embedded