Mandatory 2FA for all LVFS vendor managers and trusted users

Richard Hughes <[email protected]> Fri, 26 Jun 2026 16:09:18 +0000
Newsgroups dev.linux.lists.lvfs-announce
Message-ID <NlwmQLbB95nmf0eIpJV_-nWFD5sJxdPWBJLUrSuzg8iXSuCsLb30XahnazDs1iDSiWek-0uMAFGUqdO8fsr32RSQMoAP4W6oJIZ41I8faz4=@hughsie.com>
tl;dr: If you are a vendor manager or a user with permission to push to sta=
ble on the LVFS you'll need to set up two-factor authentication on your acc=
ount.

Over the last few months we've seen a various supply chain issues in other =
ecosystems. These have been catastrophic for security and not something I w=
ant to repeat with the LVFS project. Passwords alone just aren't good enoug=
h anymore, especially when some of these accounts have the ability to push =
firmware to millions of end users.

Starting from the 1st of August, all vendor manager accounts and users with=
 permission to push to stable will be required to have 2FA enabled. Until t=
hen you'll be gently reminded on login and on *every* firmware page. If you=
 have not set up 2FA up by the deadline you'll be unable to push firmware t=
o testing or stable or add ACLs for other users until you do.

Setting up 2FA takes about 30 seconds; go to your profile page, scan the QR=
 code with your favorite authenticator app (Google Authenticator, FreeOTP, =
Aegis, etc.) and you're done.

I know adding an extra step for login is annoying -- I find it annoying too=
 -- but the alternative is me getting a phone call at 3am because an ODMs c=
redentials ended up on the dark web and now there's a malicious unsigned fi=
rmware update being deployed to millions of people. I would rather not get =
that phone call.

If you have any problems setting this up or your organization has specific =
requirements (hardware tokens, SSO, carrier pigeons, etc.) then please get =
in touch and we'll figure something out. If you're logging in via Azure thi=
s doesn't affect you, only "local" LVFS logins can set up 2FA themselves.

Thanks,

Richard.