| ▲ | hparadiz 3 hours ago | ||||||||||||||||
Yea I was looking at this for work. We require full disk encryption for all operating systems but linux is the one where it's a passphrase or a yubikey. In my personal life it would just make managing my PC more annoying. Imagine a motherboard failure and boom there goes my entire disk. | |||||||||||||||||
| ▲ | vladvasiliu an hour ago | parent | next [-] | ||||||||||||||||
You can have automatic unlock with tpm2, with or without a pin, in addition to passphrase, file, fido2, pkcs#11 cert, or whatever else is supported by luks. I've been using this for a few years now, and never had an issue. https://wiki.archlinux.org/title/Systemd-cryptenroll > Imagine a motherboard failure and boom there goes my entire disk. You can also set a long-ass key in addition to the other methods, and back it up somewhere safe. It works the same as bitlocker: you have key which can decrypt the drive without external help from a TPM in case something goes wrong. | |||||||||||||||||
| ▲ | jacquesm 3 hours ago | parent | prev | next [-] | ||||||||||||||||
Yubikeys are very useful. I was pointed to them by a colleague and was a bit skeptical in the beginning but since then I am more than happy to use them, absolutely flawless execution. The only thing that I am a bit concerned about is that it isn't the key that I place on the device that governs all this so you can't be 100% sure that there isn't some kind of supply chain trick that would allow the manufacturer or one or more of their employees to create duplicate keys. | |||||||||||||||||
| |||||||||||||||||
| ▲ | Terr_ 3 hours ago | parent | prev [-] | ||||||||||||||||
> Imagine a motherboard failure Hold up, I'm no expert on Secure Boot, but LUKS allows you to have multiple entry keys to the same drive. This means you can have one key of random gobbledegook which is kept and auto-used by the magic motherboard, and also a passphrase that you can memorize or write down, and either one is totally sufficient on its own. You don't even need to set them up at the same time, you can start with one and then add the other as an option later. | |||||||||||||||||
| |||||||||||||||||