https://bbs.archlinux.org – You can see in this topic that you can have it fallback to a passphrase should the keyfile be invalid or missing. I wonder if you could modify the encrypt hook to require both, instead of falling back. Little more information on the encrypt hook here: https://wiki.archlinux.org/index.php/Mk … ypted_rootI may start looking into this as well, as it's an interesting idea that definit (HowTos)