Elektrine lite

← Feed

@modem_down@thebrainbin.org

Unlocking LUKS with NitroKey/Yubikey: FIDO2, HMAC-SHA1, or OpenPGP?

2026-07-31 16:40 UTC

Crossposted from https://thebrainbin.org/m/linux@lemmy.ml/t/1840283 Which approach do you think is better, and why? FIDO2 HMAC-SHA1 OpenPGP (alternative guide) Or do you think there is an even better way to use a hardware security token to unlock drives having LUKS full disk encryption?

Replies (2)

  • i use a yubikey and still have the ability to type my LUKs password in. Yubikey is just more convenience: plug in and it auto type the password field. On Fedora this means it populates the field with asterisks. Still, i think using password is the best method. With that said, i believe a much better secure layer is something similar to what Novacustoms, Purism attempt to do: verify if somebody else not you try to access the laptop. So far i know of only Dasharo boot and the stuff from Purism that can do these…

    Open ##4440003

  • @talkingpumpkin@lemmy.world 2026-07-31 17:07

    Does this have anything to do with self hosting?

    Open ##4455637