Hacker News new | ask | show | jobs
by tmikaeld 661 days ago
Please don't do this unless you have a backup yubikey with the same key on it..
3 comments

The Yubikey setup program specifically tells you not to rely on a single key for anything.
Even with LUKSv1 there are seven key slots. On creation generally the first will be a keyboard-entered pass-phrase, then one might add a key-file, and then add the hardware token as another.

With LUKSv2 the seven slot limit doesn't apply.

For headless GRUB is configured to the serial port for its terminal in/out so a passphrase can be typed.

Or all state-full data is securely backup up of course.