• libewa@feddit.org
    link
    fedilink
    English
    arrow-up
    1
    ·
    6 days ago

    I personally use a TPM with Measured Boot (so it doesn‘t give the key to external disks), and have a YubiKey and password as fallback options.

  • mazzilius_marsti@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    ·
    6 days ago

    i use a yubikey and still have the ability to type my LUKs password in. Yubikey is just more convenience: plug in and it auto type the password field. On Fedora this means it populates the field with asterisks. Still, i think using password is the best method.

    With that said, i believe a much better secure layer is something similar to what Novacustoms, Purism attempt to do: verify if somebody else not you try to access the laptop. So far i know of only Dasharo boot and the stuff from Purism that can do these…

    So the layout is: Boot verification -> LUKs-> your data

    Or if you have the juices and powers: Boot verification -> LUKS -> QuebeOS dom0 -> choose your Quebess.

      • It_is_gaslighting@discuss.tchncs.de
        link
        fedilink
        English
        arrow-up
        1
        ·
        3 days ago

        Every way is a security risk in itself. For example if my home burns down I lose x% of the ways. y% can potentially break. z% can potentially be lost to my stupidity. What if I get in a car accident and hit my head and get amnesia and forget a mandatory password: for these cases there are different retrieval strategies, but obviously are ‘stressful’ to set up to stay relatively secure. What can I say, these are the thoughts I have about this topic.

        • esc@piefed.social
          link
          fedilink
          English
          arrow-up
          1
          ·
          3 days ago

          At first you were concerned about backup access, there are multiple facrors of backup access.

          Regarding other issues, you either use disk encryption (and a lot of other things as well) and accept these concerns as part of the deal or you dont use it. That’s why actual security involves threat modeling and mitigation. Encryption by itself gives little more then headache.