Crossposted from https://thebrainbin.org/m/linux@lemmy.ml/t/1840283
Which approach do you think is better, and why?
Or do you think there is an even better way to use a hardware security token to unlock drives having LUKS full disk encryption?
FIDO2 is great. Only thing I am scared of is losing it/them. So a backup access becomes the issue IMHO.
You can have multiple ways to unlock luks container, what’s the issue?
Every way is a security risk in itself. For example if my home burns down I lose x% of the ways. y% can potentially break. z% can potentially be lost to my stupidity. What if I get in a car accident and hit my head and get amnesia and forget a mandatory password: for these cases there are different retrieval strategies, but obviously are ‘stressful’ to set up to stay relatively secure. What can I say, these are the thoughts I have about this topic.
i use a yubikey and still have the ability to type my LUKs password in. Yubikey is just more convenience: plug in and it auto type the password field. On Fedora this means it populates the field with asterisks. Still, i think using password is the best method.
With that said, i believe a much better secure layer is something similar to what Novacustoms, Purism attempt to do: verify if somebody else not you try to access the laptop. So far i know of only Dasharo boot and the stuff from Purism that can do these…
So the layout is: Boot verification -> LUKs-> your data
Or if you have the juices and powers: Boot verification -> LUKS -> QuebeOS dom0 -> choose your Quebess.
I just manually type the password in. Not quit as elegant, but does the job.
I personally use a TPM with Measured Boot (so it doesn‘t give the key to external disks), and have a YubiKey and password as fallback options.



