Crossposted from https://thebrainbin.org/m/linux@lemmy.ml/t/1840283
Which approach do you think is better, and why?
Or do you think there is an even better way to use a hardware security token to unlock drives having LUKS full disk encryption?
Crossposted from https://thebrainbin.org/m/linux@lemmy.ml/t/1840283
Which approach do you think is better, and why?
Or do you think there is an even better way to use a hardware security token to unlock drives having LUKS full disk encryption?
I agree about needing a backup hardware token (or paper recovery key) to restore access if the primary hardware token is lost or broken.
Also agree about requiring a passphrase.
Any specific recommendations on protocol or setup steps?
nope! I only use a passphrase, no experience to draw from to make recommendations