• libewa@feddit.org
    link
    fedilink
    English
    arrow-up
    1
    ·
    11 days ago

    I personally use a TPM with Measured Boot (so it doesn‘t give the key to external disks), and have a YubiKey and password as fallback options.

  • mazzilius_marsti@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    ·
    edit-2
    12 days ago

    i use a yubikey and still have the ability to type my LUKs password in. Yubikey is just more convenience: plug in and it auto type the password field. On Fedora this means it populates the field with asterisks. Still, i think using password is the best method.

    With that said, i believe a much better secure layer is something similar to what Novacustoms, Purism attempt to do: verify if somebody else not you try to access the laptop. So far i know of only Dasharo boot and the stuff from Purism that can do these…

    So the layout is: Boot verification -> LUKs-> your data

    Or if you have the juices and powers: Boot verification -> LUKS -> QuebeOS dom0 -> choose your Quebess.