Crossposted from https://thebrainbin.org/m/linux@lemmy.ml/t/1840283
Which approach do you think is better, and why?
Or do you think there is an even better way to use a hardware security token to unlock drives having LUKS full disk encryption?
You must log in or register to comment.
What’s better depends on your threat model and tolerance for inconvenience.
Personally, I prefer a hardware security token PLUS a lengthy and complex passphrase (both required to unlock). That way someone can’t access my system simply by stealing my hardware token.


