Crossposted from https://thebrainbin.org/m/linux@lemmy.ml/t/1840283

Which approach do you think is better, and why?

  1. FIDO2
  2. HMAC-SHA1
  3. OpenPGP (alternative guide)

Or do you think there is an even better way to use a hardware security token to unlock drives having LUKS full disk encryption?

you are viewing a single comment's thread
view the rest of the comments
[–] 3 points 1 month ago (1 child)

I'd use a pair of yubikeys but that's just because I already have them. and I say pair cuz I don't want to rely on a single yubikey that could get lost or stolen or damaged

also I would want there to still be a password required, not just plugging in a hardware token (tho this may be implied)

  • source
  • hideshow 2 child comments
  • [–] [S] 1 point 1 month ago (1 child)

    I agree about needing a backup hardware token (or paper recovery key) to restore access if the primary hardware token is lost or broken.

    Also agree about requiring a passphrase.

    Any specific recommendations on protocol or setup steps?

  • source
  • parent
  • hideshow 2 child comments