16

Crossposted from https://thebrainbin.org/m/linux@lemmy.ml/t/1840283

Which approach do you think is better, and why?

  1. FIDO2
  2. HMAC-SHA1
  3. OpenPGP (alternative guide)

Or do you think there is an even better way to use a hardware security token to unlock drives having LUKS full disk encryption?

top 6 comments
sorted by: hot top new old
[-] glizzyguzzler@piefed.blahaj.zone 1 points 26 minutes ago

Interested in what you divine, I’m switching from a USB drive with the key in it to one of those fancy things.

[-] irmadlad@lemmy.world -1 points 3 hours ago

Is there a down vote bot loose on Lemmy? Weirdness.

[-] irmadlad@lemmy.world 2 points 7 hours ago

I just manually type the password in. Not quit as elegant, but does the job.

FIDO2 is great. Only thing I am scared of is losing it/them. So a backup access becomes the issue IMHO.

this post was submitted on 31 Jul 2026
16 points (90.0% liked)

Selfhosted

61070 readers
1463 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

Detailed Rules Post

  1. Be civil.

  2. No spam.

  3. Posts are to be related to self-hosting.

  4. Don't duplicate the full text of your blog or readme if you're providing a link.

  5. Submission headline should match the article title.

  6. No trolling.

  7. Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.

  8. AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 3 years ago
MODERATORS