Unlocking LUKS with NitroKey/Yubikey: FIDO2, HMAC-SHA1, or OpenPGP?

Crossposted from https://thebrainbin.org/m/linux@lemmy.ml/t/1840283

Which approach do you think is better, and why?

  1. FIDO2
  2. HMAC-SHA1
  3. OpenPGP (alternative guide)

Or do you think there is an even better way to use a hardware security token to unlock drives having LUKS full disk encryption?

9 points · 1 comments · view on lemmy.world

1 Comments

BillibusMaximus@sh.itjust.works · 5 pts · 3d

What's better depends on your threat model and tolerance for inconvenience.

Personally, I prefer a hardware security token PLUS a lengthy and complex passphrase (both required to unlock). That way someone can't access my system simply by stealing my hardware token.