this post was submitted on 31 Jul 2026
10 points (100.0% liked)

Homelab

2345 readers
1 users here now

Rules

founded 2 years ago
MODERATORS
 

Crossposted from https://thebrainbin.org/m/linux@lemmy.ml/t/1840283

Which approach do you think is better, and why?

  1. FIDO2
  2. HMAC-SHA1
  3. OpenPGP (alternative guide)

Or do you think there is an even better way to use a hardware security token to unlock drives having LUKS full disk encryption?

top 3 comments
sorted by: hot top controversial new old
[–] noxypaws@pawb.social 3 points 1 day ago (1 children)

I'd use a pair of yubikeys but that's just because I already have them. and I say pair cuz I don't want to rely on a single yubikey that could get lost or stolen or damaged

also I would want there to still be a password required, not just plugging in a hardware token (tho this may be implied)

[–] modem_down@thebrainbin.org 1 points 1 day ago (1 children)

I agree about needing a backup hardware token (or paper recovery key) to restore access if the primary hardware token is lost or broken.

Also agree about requiring a passphrase.

Any specific recommendations on protocol or setup steps?

[–] noxypaws@pawb.social 1 points 1 day ago

nope! I only use a passphrase, no experience to draw from to make recommendations