Unlocking LUKS with NitroKey/Yubikey: FIDO2, HMAC-SHA1, or OpenPGP?
2026-07-31 16:40 UTC
Crossposted from https://thebrainbin.org/m/linux@lemmy.ml/t/1840283
Which approach do you think is better, and why?
FIDO2
HMAC-SHA1
OpenPGP (alternative guide)
Or do you think there is an even better way to use a hardware security token to unlock drives having LUKS full disk encryption?
Replies (2)
-
@mazzilius_marsti@lemmy.world 2026-08-01 03:56
i use a yubikey and still have the ability to type my LUKs password in. Yubikey is just more convenience: plug in and it auto type the password field. On Fedora this means it populates the field with asterisks. Still, i think using password is the best method. With that said, i believe a much better secure layer is something similar to what Novacustoms, Purism attempt to do: verify if somebody else not you try to access the laptop. So far i know of only Dasharo boot and the stuff from Purism that can do these…
-
@talkingpumpkin@lemmy.world 2026-07-31 17:07
Does this have anything to do with self hosting?