Comment on Unlocking LUKS with NitroKey/Yubikey: FIDO2, HMAC-SHA1, or OpenPGP?
BillibusMaximus@sh.itjust.works 2 hours ago
What’s better depends on your threat model and tolerance for inconvenience.
Personally, I prefer a hardware security token PLUS a lengthy and complex passphrase (both required to unlock). That way someone can’t access my system simply by stealing my hardware token.