Crossposted from https://thebrainbin.org/m/linux@lemmy.ml/t/1840283
Which approach do you think is better, and why?
Or do you think there is an even better way to use a hardware security token to unlock drives having LUKS full disk encryption?
Submitted 3 weeks ago by modem_down@thebrainbin.org to selfhosted@lemmy.world
Crossposted from https://thebrainbin.org/m/linux@lemmy.ml/t/1840283
Which approach do you think is better, and why?
Or do you think there is an even better way to use a hardware security token to unlock drives having LUKS full disk encryption?
i use a yubikey and still have the ability to type my LUKs password in. Yubikey is just more convenience: plug in and it auto type the password field. On Fedora this means it populates the field with asterisks. Still, i think using password is the best method.
With that said, i believe a much better secure layer is something similar to what Novacustoms, Purism attempt to do: verify if somebody else not you try to access the laptop. So far i know of only Dasharo boot and the stuff from Purism that can do these…
I personally use a TPM with Measured Boot (so it doesn‘t give the key to external disks), and have a YubiKey and password as fallback options.
FIDO2 is great. Only thing I am scared of is losing it/them. So a backup access becomes the issue IMHO.
You can have multiple ways to unlock luks container, what’s the issue?
Every way is a security risk in itself. For example if my home burns down I lose x% of the ways. y% can potentially break. z% can potentially be lost to my stupidity. What if I get in a car accident and hit my head and get amnesia and forget a mandatory password: for these cases there are different retrieval strategies, but obviously are ‘stressful’ to set up to stay relatively secure. What can I say, these are the thoughts I have about this topic.
DieserTypMatthias@lemmy.ml 2 weeks ago Neither. I just use my Yubikey as a backup in case I don’t have access to Bitwarden.
Interested in what you divine, I’m switching from a USB drive with the key in it to one of those fancy things.
irmadlad@lemmy.world 3 weeks ago Is there a down vote bot loose on Lemmy? Weirdness.
Does this have anything to do with self hosting?
Yes. Here are 3 common self-hosting scenarios:
For all three, FDE is a sensible precaution to protect the data in case the server is physically stolen.
Linux is probably the most common OS kernel for self-hosting. On that kernel, [LUKS (Linux Unified Key Setup)](Linux Unified Key Setup) is probably the most sensible FDE system to use. It's mature and reliable. But anyone self-hosting a Linux server with LUKS FDE is faced with the question of where to store the keys.
Hardware security tokens (HSTs) are widely considered a safer place for keys than SSDs, HDDs, or USB storage. They follow the smartcard principle: a private key can be written to an HST but not read from it (security vulnerabilities excepted. Instead, they implement cryptographic algorithms to prove possession of the private key. So, anyone self-hosting a Linux server with LUKS FDE should strongly consider storing their private key(s) on an HST.
However, there is more than one way to do that. Hence the question in my OP.
If it’s a server for self hosting you definitely don’t want anything that requires interaction at boot.
There’s a project that allows unlocking LUKS with a decryption key retrieved from another machine in your network. I don’t recall the name but someone hopefully will.
The idea is that put the key on, say, a raspberry pi zero w that you hide somewhere in your house so that if someone steals your server they don’t have the key.
I just manually type the password in. Not quit as elegant, but does the job.