LOUP Engineering: Provisioning & Backend · advanced
Global Factory Credentials Would Turn One Leak into a Fleet Incident
Convenient shared bootstrap secrets create the largest possible blast radius.
The lab result behind Global Factory Credentials Would Turn One Leak into a Fleet Incident changed the implementation more than the first hypothesis did. LOUP provisioning is designed around unique device and SIP identities rather than one credential copied into production units.
A global secret eventually appears in firmware dumps, logs, fixtures or service procedures. Once leaked, every device that trusts it becomes suspect. Unique enrollment material costs more operational design but makes compromise containable.
Reversibility stayed part of the experiment: preserve the previous artifact, make the change, then prove the new path before promoting it. Evidence marker: no-global-factory-secret.
Credential architecture should optimize for revocation and blast radius, not only for the easiest factory script. Preserving that distinction is what lets the project increase complexity without losing the ability to explain a regression.
Project evidence
LOUP engineering marker: no-global-factory-secret. This note records the design or debugging lesson without publishing device credentials, private keys, customer data or manufacturing secrets.