Does anyone foresee any obstacles in implementing a U2F security key lock on Qubes OS LUKS? Systemd has cryptenroll. This is probably as close to trusted boot / U2F secured power up as a Qubes computer could get without HEADS BIOS. This way, at least as long as you keep your security key, no one can turn on your drive without you.