

6·
7 days agoPreferably in your brain and maybe partially in a smart card protected by a pin?
Preferably in your brain and maybe partially in a smart card protected by a pin?
If you use TPM for signing, that is not an issue most of the time. But if you store decryption keys for a storage device there that’s not a good idea.
AFAIK there is. But even if not, it simulates a keyboard which can input your passphrase. Also modification of the initrd is a matter of providing a bash script or binary to launch which returns the passphrase in the crypttab file and adding it to the correct directory.