Which approach do you think is better, and why?

  1. FIDO2
  2. HMAC-SHA1
  3. OpenPGP (alternative guide)

Or do you think there is an even better way to use a hardware security token to unlock drives having LUKS full disk encryption?

  • eldavi@lemmy.ml
    link
    fedilink
    English
    arrow-up
    0
    ·
    1 day ago

    wouldn’t doing this require that building a ram disk image with the yubikey software included?

    • Kay Ohtie@pawb.social
      link
      fedilink
      English
      arrow-up
      0
      ·
      21 hours ago

      All 3 mechanisms are native to a yubikey, and do not require yubikey-specific software/drivers to function as they use USB standards like FIDO2, keyboard for HMAC, and PIV/CCID for OpenPGP.

      FIDO2 is built-in out-of-the-box, HMAC just requires adding the key to HMAC on slot 1 or 2 (tap vs long-hold key-inputs) using the personalization tool, or using gpg(2) to card-edit for OpenPGP.

      None of these require YK software to operate.

      • eldavi@lemmy.ml
        link
        fedilink
        English
        arrow-up
        0
        ·
        24 hours ago

        read them and you will see that only ones mentions initrd at all.

        • modem_down@thebrainbin.orgOP
          link
          fedilink
          arrow-up
          0
          ·
          23 hours ago

          I read them before writing my OP. I’m still not sure what you’re getting at.

          I would be grateful if you could say what you mean, instead of initiating an oblique guessing game.

          • eldavi@lemmy.ml
            link
            fedilink
            English
            arrow-up
            0
            ·
            22 hours ago

            instead of initiating an oblique guessing game.

            i don’t understand the hostility.

            i asked a question about needing yubikey software in a ramdisk image to enable decryption at boot time and most of the sources you provided don’t mention it at all.

            • floquant@lemmy.dbzer0.com
              link
              fedilink
              arrow-up
              0
              ·
              7 hours ago

              It’s not mentioned because it’s not required, yubikeys in general mostly leverage pre-existing “smartcard” facilities

            • kkremitzki@lemmy.ml
              link
              fedilink
              arrow-up
              0
              ·
              20 hours ago

              i don’t understand the hostility.

              Bystander observation: you were asked to clarify but essentially refused in a way that took more effort than simply doing so.