Replies (1)

Correct. LUKS makes everything depend on the strength of the encryption password, as a good hardware wallet should do, and does not depend on untrusted hardware (TPM or Secure Element). That said, LUKS can be configured with TPM, but I strongly advise against it for this reason. "Kerckhoffs' cryptography principle (also called Kerckhoffs' desideratum, assumption, axiom, doctrine, or law) was stated by Dutch cryptographer Auguste Kerckhoffs in the 19th century. The principle states that a cryptosystem must be secure even if everything about the system, except the key, is public knowledge. This concept is widely adopted by cryptographers, in contrast to security through obscurity, which is not."