Security Advisory: Update encrypted USB drives and replace short passphrases
securedrop.org
securedrop.org
http://0pointer.net/blog/unlocking-luks2-volumes-with-tpm2-f...
systemd is not required, it just simplifies enrollment.
The linked Tails security advisory[1] says:
>We recommend you change the passphrase of your Persistent Storage and other LUKS encrypted volumes unless you use a long passphrase of 5 random words or more.
When talking in terms of passphrases, using a memory hard hash like Argon2 over PBKDF2 will get you an advantage of less than a single word. The real magic is in the passphrase length and the randomness of the words.
In VC you can choose one or more hash functions for key derivation. The trick is whichever you choose is not known to the attacker as this choice is never stored. Choosing anything other than the default one decimates brute force speed.
If you're chosing from a family of good hash functions, then its like adding a few bits of security to your password. Better just to have a longer password.
If you are choosing from arbitrary hash functions including bad ones, then this is an absolutely terrible idea.
So basically its either a neutral or bad idea. I wouldn't reccomend it.
In general cryptosystems are easier to analyze and design when the secret and open parts are clearly delineated. Having half-secret info like the choice of specific algorithm is problematic
The only semi-valid reason nowadays to use LUKS1 is encryption of /boot for GRUB.