Device identity should be unique
Every device needs its own identity, or you cannot revoke one without revoking all of them.
A shared key across a product line means compromising one unit compromises the fleet, and there is no way to isolate the bad one. Per-device credentials, provisioned during manufacture, are more work upfront and are what make it possible to respond to a single compromised device at all.
More on IoT and embedded
- A default password scales into a fleet vulnerabilityOne word, printed a million times
- Physical access changes the embedded threat modelThe lid was the threat model
- Firmware updates are a long-term security promiseYou sold the box, you signed up for the years
- Secure boot protects the startup chainEach link checks the next
- Cloud shutdown can strand smart devicesThe strings came from elsewhere
- Sensors can be fooled without hacking softwareNo code was touched
