#yubikey

9 posts · Last used 7d

Back to Timeline
modem_down @modem_down@thebrainbin.org · Jul 31, 2026

Unlocking LUKS with NitroKey/Yubikey: FIDO2, HMAC-SHA1, or OpenPGP?

Unlocking LUKS with NitroKey/Yubikey: FIDO2, HMAC-SHA1, or... ##luks ##nitrokey ##yubikey ##security ##linux ##sysadmin ##fde Hover or focus to reveal Sensitive
Crossposted from https://thebrainbin.org/m/linux@lemmy.ml/t/1840283 Which approach do you think is better, and why? FIDO2 HMAC-SHA1 OpenPGP (alternative guide) Or do you think there is an even better way to use a hardware security token to unlock drives having LUKS full disk encryption?
0
2
0
ツ ュ テ フ ァ ン ・ ツ ュ ー マ ツ ハ ー @cryptomancer@fediverse.cryptomancer.de · Aug 03, 2026
Ich werde dieses Jahr auf der #Froscon meinen Workshop zum Laptop absichern in einer aktualisierten Version halten: Wir bauen uns einen Congress-Laptop: #CachyOS härten für Einsteiger https://programm.froscon.org/froscon2026/talk/9bef50ee-9fb4-469d-85f0-bf5c224276eb/ Spannung, Spiel und Spaß u.a. mit Secure und Attested Boot, #TPM2 als Vertrauensanker, #HardenedKernel und #IOMMU, #USBGuard, #Firejail und #Yubikey Rechtzeitig zur Veranstaltung werde ich eine Anleitung/Doku zum nachlesen und mittippen veröffentlichen. #froscon2026 #froscon26 #security #hardening #linux @FrOSCon@bonn.social
0
0
0
modem_down @modem_down@thebrainbin.org · Jul 31, 2026

Unlocking LUKS with NitroKey/Yubikey: FIDO2, HMAC-SHA1, or OpenPGP?

Unlocking LUKS with NitroKey/Yubikey: FIDO2, HMAC-SHA1, or... ##luks ##nitrokey ##yubikey ##security ##linux ##sysadmin Hover or focus to reveal Sensitive
Which approach do you think is better, and why? FIDO2 HMAC-SHA1 OpenPGP or this Or do you think there is an even better way to use a hardware security token to unlock drives with LUKS full disk encryption?
0
8
1
Sean @seanm@infosec.exchange · Jul 23, 2026
Replying to @tychotithonus@infosec.exchange
@tychotithonus@infosec.exchange speaking of Yubico, it looks like they finally released firmware 5.8. I'm not sure how I feel about all of the GenAI "features" they added. https://www.yubico.com/blog/beyond-the-login-top-3-things-developers-need-to-know-about-yubikey-5-8/ #Yubico #Yubikey #CTAP #2FA #SecurityKey
1
1
0
Virebent @virebent@infosec.exchange · Jul 09, 2026

A public project should not be credible only because it appears online.

This is why I am using ProofBundle for the projects I publish and discuss publicly, including the ones I present here on LinkedIn.

ProofBundle creates a portable cryptographic proof for a project snapshot.

It takes the files, builds a deterministic SHA-256 manifest, reduces the entries into a Merkle tree, and produces one Merkle root for the whole project state.

Then that root is bound to a signed author/custody claim.

ProofBundle can also use OpenTimestamps: the Merkle root and manifest hash are timestamped and anchored to public blockchains, without uploading the original project and without putting the contents on-chain.

So the proof has three layers:

  • integrity: SHA-256 hashes, manifest, and Merkle root
  • identity/custody: Ed25519 or OpenPGP signature
  • time evidence: OpenTimestamps blockchain anchoring

For signing, ProofBundle supports a default Ed25519 mode: modern, compact, and easy to verify.

It can also use a detached OpenPGP signature, including OpenPGP keys based on Ed25519. And for stronger key custody, OpenPGP signing can optionally be backed by a YubiKey, so the private signing key stays hardware-backed and non-exportable.

This is not copyright registration and it is not a legal shortcut.

It is technical evidence that:

  • this exact project state existed
  • these files matched this manifest
  • this Merkle root represented the snapshot
  • this key signed the claim
  • the timestamp evidence was

anchored through OpenTimestamps

  • the proof can be verified independently

Full technical note: https://www.gabrielesalati.eu/blog/proofbundle-verifiable-project-integrity.html

#ProofBundle #OpenTimestamps #Blockchain #OpenPGP #Ed25519 #MerkleTree #YubiKey #CyberSecurity #SoftwareEngineering #OpenSource

0
0
0
S1m @S1m@infosec.exchange · Jul 06, 2026
I've finally finished my guide to using Yubikeys. If I had to set up my keys today, this is what I would do. If you're curious, here it is: https://s1m.fr/guide-yubikeys/ #Yubikey #Passkey
0
0
0
utzer @utzer@f.utzer.de · Jun 05, 2026
Konnte jetzt bei #Paypal den einen #Yubikey als Hardwaresicherheitsschlüssel hinzufügen, den anderen aber nur als OTP Gerät. Paypal scheint keine zwei Yubikeys zuzulassen. Ich kann also auch keinen weiteren Schlüssel hinzufügen. Und Passkey geht nur über den Device Dienst, bei Android gab es einige zur Auswahl (die Yubico App nicht), weil man auf Systemebene mehrere haben kann. Bei Apple nur "Password", was wohl der Nachfolger der Keychain ist. Schon seltsam sowas.
0
0
0
utzer @utzer@f.utzer.de · Jun 02, 2026
Wie und wo bewahrt ihr eure #Yubikey und Co auf? Schlüsselbund? Wo den Ersatz?
0
0
0

You've seen all posts