Support combining password + YubiKey HMAC-SHA1 challenge-response for wallet encryption key derivation.
- Optional second factor alongside existing password
- Uses YubiKey's offline HMAC challenge-response (slot 2)
- Final key = derive(password) + HMAC(challenge)
Similar to KeePassXC and LUKS yubikey-full-disk-encryption implementations.
References: