linuxboot / linuxboot/heads-wiki
Confusion about using USB Security Dongles to decrypt hard drive
Nobody has claimed this yet.
- Dominant language
- No language data
- Stars
- 96
- Forks
- 58
- Avg merge
- 1d 16h
- Merged PRs (30d)
- 11
Description
As far as I understand, you can use your - for example Nitrokey Pro - to "avoid" typing in the Disk Recovery Key. The Disk Recovery Key is the key used at OS installation for the encrypted root partition (passphrase placed in LUKS keyslot 0). So I can use this key whenever I connect my harddrive to another computer.
For me, it would be logical, if I use my GPG key on my Nitrokey to do some magic to decrypt my harddrive (or decrypt some parts on the TPM which then decrypts my harddrive). It would make sense, if I would need to type in my Nitrokey User PIN to decrypt my harddrive.
Instead I am asked for another password in Heads when I try to set up this. This confuses me.
I read https://osresearch.net/Keys/
(Added for newcomers: The Nitrokey User PIN is - obviously - relatively easy to guess, if brute force methods are available. But the USB Security dongles are actually locking the user out of their User role if 3 bad attempts were made, so it is safe, to use the PIN to unlock/decrypt my harddrive.)
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reading the Keys page and the issue's description of the Heads setup flow. Clarify the roles of the Disk Recovery Key, the Nitrokey GPG key, the Nitrokey User PIN, and the additional password, including what a user should enter when setting this up. Done means the documentation answers this confusion without requiring assumptions about the encryption flow.
Written by the indexing model from the issue text.
Assessment
- Domain
- documentation
- Issue type
- Documentation
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 30/100