Tom's Lemmy
  • Communities
  • Multi-communities
  • Support Lemmy
  • Search
  • Login
Selfhosted@lemmy.worldbymodem_down@thebrainbin.org
19 days

Unlocking LUKS with NitroKey/Yubikey: FIDO2, HMAC-SHA1, or OpenPGP?

Crossposted from https://thebrainbin.org/m/[email protected]/t/1840283

Which approach do you think is better, and why?

  1. FIDO2
  2. HMAC-SHA1
  3. OpenPGP (alternative guide)

Or do you think there is an even better way to use a hardware security token to unlock drives having LUKS full disk encryption?

20
    You must log in or register to comment.

    • irmadlad@lemmy.worldEnglish
      19 days

      I just manually type the password in. Not quit as elegant, but does the job.

      • libewa@feddit.orgEnglish
        19 days

        I personally use a TPM with Measured Boot (so it doesn‘t give the key to external disks), and have a YubiKey and password as fallback options.

        • mazzilius_marsti@lemmy.worldEnglish
          19 days

          i use a yubikey and still have the ability to type my LUKs password in. Yubikey is just more convenience: plug in and it auto type the password field. On Fedora this means it populates the field with asterisks. Still, i think using password is the best method.

          With that said, i believe a much better secure layer is something similar to what Novacustoms, Purism attempt to do: verify if somebody else not you try to access the laptop. So far i know of only Dasharo boot and the stuff from Purism that can do these…

          So the layout is: Boot verification -> LUKs-> your data

          Or if you have the juices and powers: Boot verification -> LUKS -> QuebeOS dom0 -> choose your Quebess.

            • modem_down@thebrainbin.org
              19 days

              i believe a much better secure layer is something similar to what Novacustoms, Purism attempt to do: verify if somebody else not you try to access the laptop.

              You’re thinking of Heads, which I agree is ideal for supported motherboards.

            • Matt@lemmy.mlEnglish
              18 days

              Neither. I just use my Yubikey as a backup in case I don’t have access to Bitwarden.

              • glizzyguzzler@piefed.blahaj.zoneEnglish
                19 days

                Interested in what you divine, I’m switching from a USB drive with the key in it to one of those fancy things.

                • It_is_gaslighting@discuss.tchncs.deEnglish
                  19 days

                  FIDO2 is great. Only thing I am scared of is losing it/them. So a backup access becomes the issue IMHO.

                    • esc@piefed.socialEnglish
                      19 days

                      You can have multiple ways to unlock luks container, what’s the issue?

                        • It_is_gaslighting@discuss.tchncs.deEnglish
                          16 days

                          Every way is a security risk in itself. For example if my home burns down I lose x% of the ways. y% can potentially break. z% can potentially be lost to my stupidity. What if I get in a car accident and hit my head and get amnesia and forget a mandatory password: for these cases there are different retrieval strategies, but obviously are ‘stressful’ to set up to stay relatively secure. What can I say, these are the thoughts I have about this topic.

                            • esc@piefed.socialEnglish
                              16 days

                              At first you were concerned about backup access, there are multiple facrors of backup access.

                              Regarding other issues, you either use disk encryption (and a lot of other things as well) and accept these concerns as part of the deal or you dont use it. That’s why actual security involves threat modeling and mitigation. Encryption by itself gives little more then headache.

                        • irmadlad@lemmy.worldEnglish
                          19 days

                          Is there a down vote bot loose on Lemmy? Weirdness.

                          • talkingpumpkin@lemmy.worldEnglish
                            19 days

                            Does this have anything to do with self hosting?

                              • modem_down@thebrainbin.org
                                19 days

                                Yes. Here are some common self-hosting scenarios:

                                • Home server containing family files: scans, photos, device backups, …
                                • Office server containing business files: sensitive documents, device backups, …
                                • Web or email server containing websites, Fediverse instances, emails, etc

                                In all those cases, full disk encryption (FDE) is a sensible precaution to protect the data in case the server is physically stolen.

                                Linux is probably the most common OS kernel for self-hosting. On Linux, LUKS (Linux Unified Key Setup) is probably the best FDE system. It’s mature and reliable. But anyone self-hosting a Linux server with LUKS FDE is faced with the question of where to store the keys.

                                Hardware security tokens (HSTs) are widely considered a safer place for keys than SSDs, HDDs, or USB storage. They follow the smartcard principle: a private key can be written to an HST but not read from it (security vulnerabilities excepted). Instead, they implement cryptographic algorithms to prove possession of the private key. So, anyone self-hosting a Linux server with LUKS FDE should strongly consider storing their private key(s) on an HST.

                                However, there is more than one way to do that. Hence the question in my OP.

                                  • talkingpumpkin@lemmy.worldEnglish
                                    19 days

                                    If it’s a server for self hosting you definitely don’t want anything that requires interaction at boot.

                                    There’s a project that allows unlocking LUKS with a decryption key retrieved from another machine in your network. I don’t recall the name but someone hopefully will.

                                    The idea is that put the key on, say, a raspberry pi zero w that you hide somewhere in your house so that if someone steals your server they don’t have the key.

                                      • JustEnoughDucks@slrpnk.netEnglish
                                        19 days

                                        Some people are fine with down time/inconvenience in exchange for security.

                                        I have my boot drive on a secured USB and LUKS keyfile with the rest of the partitions on an encrypted SSD and data on encrypted HDDs.

                                        In a smash and grab (or fascist government gestapo smash and grab), the server is pretty impossible to steal information from (inject illegal content to in order to fabricate evidence) without the USB and they can’t simply inject boot malware either. A network device is almost always findable either by cables or WiFi broadcast analyzing.

                                        • esc@piefed.socialEnglish
                                          19 days

                                          tang

                                            • modem_down@thebrainbin.org
                                              19 days

                                              tang

                                              Thanks. TIL about Clevis/Tang.

                                            • modem_down@thebrainbin.org
                                              19 days

                                              If it’s a server for self hosting you definitely don’t want anything that requires interaction at boot.

                                              Depends on use-case. If you only plan to boot it when you’re physically present, it’s fine.

                                              • percent@infosec.pubEnglish
                                                18 days

                                                My servers require manual unlock via SSH at boot. It has been great for years.

                                                • superglue@lemmy.dbzer0.comEnglish
                                                  18 days

                                                  I haven’t actually tried it yet, but on that note, if you have an OpenWRT router you can configure dropbear to unlock it.

                                            Selfhosted@lemmy.world

                                            selfhosted@lemmy.world
                                            <p>A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don’t c

                                            Subscribe from remote instance

                                            Create post

                                            Report community

                                            Modlog
                                            You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: [email protected]

                                            A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don’t control.

                                            Rules:

                                            Detailed Rules Post

                                            1. Be civil.

                                            2. No spam.

                                            3. Posts are to be related to self-hosting.

                                            4. Don’t duplicate the full text of your blog or readme if you’re providing a link.

                                            5. Submission headline should match the article title.

                                            6. No trolling.

                                            7. Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.

                                            8. AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.

                                            Resources:

                                            • selfh.st Newsletter and index of selfhosted software and apps
                                            • awesome-selfhosted software
                                            • awesome-sysadmin resources
                                            • Self-Hosted Podcast from Jupiter Broadcasting

                                            Any issues on the community? Report it using the report flag.

                                            Questions? DM the mods!

                                            Visibility: Public

                                            This community is visible to everyone.

                                            • 0 users / Day
                                            • 0 users / Week
                                            • 4.57K users / Month
                                            • 9.85K users / 6 months
                                            • 3.32K posts
                                            • 57.7K comments
                                            • 1 local subscriber
                                            • 61.3K subscribers
                                            • Mods:
                                            • Ruud@lemmy.world
                                            • Loki@lemmy.world
                                            • CannaVet@lemmy.world
                                            • devve@lemmy.world
                                            • BE: 1.0.0-beta.1
                                            • Modlog
                                            • Instances
                                            • Docs
                                            • Code
                                            • join-lemmy.org