Crossposted from https://thebrainbin.org/m/linux@lemmy.ml/t/1840283
Which approach do you think is better, and why?
Or do you think there is an even better way to use a hardware security token to unlock drives having LUKS full disk encryption?
I’d use a pair of yubikeys but that’s just because I already have them. and I say pair cuz I don’t want to rely on a single yubikey that could get lost or stolen or damaged
also I would want there to still be a password required, not just plugging in a hardware token (tho this may be implied)
I agree about needing a backup hardware token (or paper recovery key) to restore access if the primary hardware token is lost or broken.
Also agree about requiring a passphrase.
Any specific recommendations on protocol or setup steps?


