• michaelmrose@lemmy.world
    link
    fedilink
    English
    arrow-up
    2
    ·
    15 hours ago

    Typically an actual key is effectively just a very long pseaudorandom binary blob and the passphrase is just used to unlock the actual key. This means you can add a new key just by encrypting the actual key with the new passphrase

    • taladar@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      1
      ·
      13 hours ago

      Typically that is also the way you can use multiple accounts to unlock the same hard drive encryption. You just encrypt the actual key with each of the account passwords.