• It_is_gaslighting@discuss.tchncs.de
        link
        fedilink
        English
        arrow-up
        0
        ·
        10 days ago

        Every way is a security risk in itself. For example if my home burns down I lose x% of the ways. y% can potentially break. z% can potentially be lost to my stupidity. What if I get in a car accident and hit my head and get amnesia and forget a mandatory password: for these cases there are different retrieval strategies, but obviously are ‘stressful’ to set up to stay relatively secure. What can I say, these are the thoughts I have about this topic.

  • mazzilius_marsti@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    13 days ago

    i use a yubikey and still have the ability to type my LUKs password in. Yubikey is just more convenience: plug in and it auto type the password field. On Fedora this means it populates the field with asterisks. Still, i think using password is the best method.

    With that said, i believe a much better secure layer is something similar to what Novacustoms, Purism attempt to do: verify if somebody else not you try to access the laptop. So far i know of only Dasharo boot and the stuff from Purism that can do these…

    So the layout is: Boot verification -> LUKs-> your data

    Or if you have the juices and powers: Boot verification -> LUKS -> QuebeOS dom0 -> choose your Quebess.

  • libewa@feddit.org
    link
    fedilink
    English
    arrow-up
    0
    ·
    12 days ago

    I personally use a TPM with Measured Boot (so it doesn‘t give the key to external disks), and have a YubiKey and password as fallback options.