• mazzilius_marsti@lemmy.world
    link
    fedilink
    English
    arrow-up
    2
    ·
    7 hours ago

    i use a yubikey and still have the ability to type my LUKs password in. Yubikey is just more convenience: plug in and it auto type the password field. On Fedora this means it populates the field with asterisks. Still, i think using password is the best method.

    With that said, i believe a much better secure layer is something similar to what Novacustoms, Purism attempt to do: verify if somebody else not you try to access the laptop. So far i know of only Dasharo boot and the stuff from Purism that can do these…

    So the layout is: Boot verification -> LUKs-> your data

    Or if you have the juices and powers: Boot verification -> LUKS -> QuebeOS dom0 -> choose your Quebess.

    • modem_down@thebrainbin.orgOP
      link
      fedilink
      arrow-up
      1
      ·
      3 hours ago

      i believe a much better secure layer is something similar to what Novacustoms, Purism attempt to do: verify if somebody else not you try to access the laptop.

      You’re thinking of Heads, which I agree is ideal for supported motherboards.