logoalt Hacker News

cyberaxyesterday at 10:04 PM0 repliesview on HN

You can use TPM with secure boot to store the password. TPM checks that the firmware is the same and that the OS is signed by trusted (by _you_) keys, and if everything matches it makes the key available for reading by the OS.