Comment on Unlocking LUKS with NitroKey/Yubikey: FIDO2, HMAC-SHA1, or OpenPGP?

BillibusMaximus@sh.itjust.works ⁨2⁩ ⁨hours⁩ ago

What’s better depends on your threat model and tolerance for inconvenience.

Personally, I prefer a hardware security token PLUS a lengthy and complex passphrase (both required to unlock). That way someone can’t access my system simply by stealing my hardware token.

source
Sort:hotnewtop