As billions of small, power-limited devices weave themselves into the fabric of hospitals, factories, and cities, the ancient problem of keeping secrets in a crowd has found a new and urgent form. Researchers have answered with LPP-GKM, a scheme that lets IoT devices authenticate through shifting pseudonyms and refresh shared keys with only logarithmic effort, so that the cost of belonging to a secure group need not exhaust the devices doing the belonging. It is a reminder that good cryptographic design is less about brute strength than about knowing precisely where to place the burden.