@feld Doesn’t seem possible to do it with a Yubikey though, and this guy has configured his yubikey to decrypt his encrypted hard drive. Which is scary as fuck if you’re doing anything even remotely counter to the current political climate in your region.
https://www.endpointdev.com/blog/2022/03/disk-decryption-yubikey/
(This is kinda what prompted me to write what I did.)
I like how he had to upgraded his yubikey services because the older version was more secure than what he wanted.