Which approach do you think is better, and why?

  1. FIDO2
  2. HMAC-SHA1
  3. OpenPGP (alternative guide)

Or do you think there is an even better way to use a hardware security token to unlock drives having LUKS full disk encryption?

    • modem_down@thebrainbin.orgOP
      link
      fedilink
      arrow-up
      0
      ·
      1 month ago

      I read them before writing my OP. I’m still not sure what you’re getting at.

      I would be grateful if you could say what you mean, instead of initiating an oblique guessing game.

      • eldavi@lemmy.ml
        link
        fedilink
        English
        arrow-up
        0
        ·
        1 month ago

        instead of initiating an oblique guessing game.

        i don’t understand the hostility.

        i asked a question about needing yubikey software in a ramdisk image to enable decryption at boot time and most of the sources you provided don’t mention it at all.

        • floquant@lemmy.dbzer0.com
          link
          fedilink
          arrow-up
          1
          ·
          1 month ago

          It’s not mentioned because it’s not required, yubikeys in general mostly leverage pre-existing “smartcard” facilities