this post was submitted on 31 Jul 2026
26 points (93.3% liked)

Selfhosted

61070 readers
1063 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

Detailed Rules Post

  1. Be civil.

  2. No spam.

  3. Posts are to be related to self-hosting.

  4. Don't duplicate the full text of your blog or readme if you're providing a link.

  5. Submission headline should match the article title.

  6. No trolling.

  7. Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.

  8. AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 3 years ago
MODERATORS
 

Crossposted from https://thebrainbin.org/m/linux@lemmy.ml/t/1840283

Which approach do you think is better, and why?

  1. FIDO2
  2. HMAC-SHA1
  3. OpenPGP (alternative guide)

Or do you think there is an even better way to use a hardware security token to unlock drives having LUKS full disk encryption?

top 14 comments
sorted by: hot top controversial new old
[–] libewa@feddit.org 2 points 3 hours ago

I personally use a TPM with Measured Boot (so it doesn‘t give the key to external disks), and have a YubiKey and password as fallback options.

[–] mazzilius_marsti@lemmy.world 2 points 10 hours ago* (last edited 10 hours ago)

i use a yubikey and still have the ability to type my LUKs password in. Yubikey is just more convenience: plug in and it auto type the password field. On Fedora this means it populates the field with asterisks. Still, i think using password is the best method.

With that said, i believe a much better secure layer is something similar to what Novacustoms, Purism attempt to do: verify if somebody else not you try to access the laptop. So far i know of only Dasharo boot and the stuff from Purism that can do these...

So the layout is: Boot verification -> LUKs-> your data

Or if you have the juices and powers: Boot verification -> LUKS -> QuebeOS dom0 -> choose your Quebess.

[–] irmadlad@lemmy.world 3 points 20 hours ago

I just manually type the password in. Not quit as elegant, but does the job.

[–] It_is_gaslighting@discuss.tchncs.de 1 points 19 hours ago (1 children)

FIDO2 is great. Only thing I am scared of is losing it/them. So a backup access becomes the issue IMHO.

[–] esc@piefed.social 2 points 10 hours ago

You can have multiple ways to unlock luks container, what's the issue?

[–] irmadlad@lemmy.world -1 points 17 hours ago

Is there a down vote bot loose on Lemmy? Weirdness.