Not as the only way but using paperkey might be a good idea too.
this post was submitted on 20 Jun 2023
6 points (87.5% liked)
Sysadmin
7998 readers
1 users here now
A community dedicated to the profession of IT Systems Administration
No generic Lemmy issue posts please! Posts about Lemmy belong in one of these communities:
[email protected]
[email protected]
[email protected]
[email protected]
founded 2 years ago
MODERATORS
I install my keys on 5 Yubikeys and then encrypt a copy of the private key so that it can only be decrypted with one of the Yubikeys. I store the encrypted bundle on Google drive and I’ve spread out the Yubikeys a little geographically by sending them to friends who I trust (PIN is still required to use the Yubikey so there’s still a layer of security). I also keep one of them in a safe at my house just in case.
I do feel like I may have gone a little overboard but maybe something similar could work for you!