http://dys2pwwos5w5kez2chufdk3b3oyj5n4n4iiseyke2tzuqahgvmovloyd.onion/en/2023-05-luks-security.html
Also, if you’re using an encrypted /boot, stop now - very recent versions of grub2 support LUKS2, but they don’t support argon2id, and this will render your system unbootable. Next, figure out which device under /dev corresponds to your encrypted partition. Run lsblk and look for entries that have a type of “crypt”. The device above that in the tree is the actual encrypted device.