Which approach do you think is better, and why?

  1. FIDO2
  2. HMAC-SHA1
  3. OpenPGP (alternative guide)

Or do you think there is an even better way to use a hardware security token to unlock drives having LUKS full disk encryption?

  • eldavi@lemmy.ml
    link
    fedilink
    English
    arrow-up
    0
    ·
    24 hours ago

    instead of initiating an oblique guessing game.

    i don’t understand the hostility.

    i asked a question about needing yubikey software in a ramdisk image to enable decryption at boot time and most of the sources you provided don’t mention it at all.

    • floquant@lemmy.dbzer0.com
      link
      fedilink
      arrow-up
      0
      ·
      8 hours ago

      It’s not mentioned because it’s not required, yubikeys in general mostly leverage pre-existing “smartcard” facilities

    • kkremitzki@lemmy.ml
      link
      fedilink
      arrow-up
      0
      ·
      21 hours ago

      i don’t understand the hostility.

      Bystander observation: you were asked to clarify but essentially refused in a way that took more effort than simply doing so.