3 ms·
What do you authenticate against? Your shadow file is in the unencrypted area leaving it susceptible to offline attack. With the TPM you can fully disable pass
by pfexec 1y ago
What do you authenticate against? Your shadow file is in the unencrypted area leaving it susceptible to offline attack.
With the TPM you can fully disable password auth over SSH.
- rnhmjoj 1y agoCorrect, someone with physical access could run a MitM attack and steal your passphrase. I just find this extremely unlikely, so I honestly don't care.
- auguzanellato 1y agoMy Raspberry Pi some time ago had a setup where only public key auth was enabled for LUKS unlock, so I only had to have an authorized_keys file unencrypted.