Hacker News new | ask | show | jobs
by rfoo 661 days ago
> hardware key attached

Key is on my keychain. not attached to the box. I don't need to unlock it remotely. I want to be there and plug my key and touch it and yank it.

> Also, someone can temporarily remove the yubikey, fetch the decryption key then place it back.

If implemented correctly. Nobody can. An encrypted LUKS key would be sent to the yubikey and have it decrypted there. Not the other way.

1 comments

Ah, I missed that use case, nice idea