Crossposted from https://thebrainbin.org/m/linux@lemmy.ml/t/1840283

Which approach do you think is better, and why?

  1. FIDO2
  2. HMAC-SHA1
  3. OpenPGP (alternative guide)

Or do you think there is an even better way to use a hardware security token to unlock drives having LUKS full disk encryption?

you are viewing a single comment's thread
view the rest of the comments
[–] [S] 3 points 2 months ago

If it's a server for self hosting you definitely don't want anything that requires interaction at boot.

Depends on use-case. If you only plan to boot it when you're physically present, it's fine.

  • source
  • parent