Comment by perching_aix

4 hours ago

So much this. Security information should simply never reside on-device in the first place.

That said, I think this is a thing with BitLocker? I remember coming across YubiKeys being able to do this via something called PIV (Personal Identity Verification). Found this guide now after giving it a quick search: https://gist.github.com/daemonhorn/03301a66da7d1f4de6cdc8c8b...

Not sure how sound of a design it is though, didn't dig into it much at all.