> Also note that an attacker that has access to the storage could
> patch your GnuPG binary or other system components.

well that is an another story because an attacker could in that case patch
cryptsetup too. if s/he can do that it is not important whether you
use encrypted
key file on usb stick or directly cryptsetup.
