Mandatory 2FA for all LVFS vendor managers and trusted users
Richard Hughes <[email protected]> Fri, 26 Jun 2026 16:09:18 +0000
| Newsgroups | dev.linux.lists.lvfs-announce |
|---|---|
| Message-ID | <NlwmQLbB95nmf0eIpJV_-nWFD5sJxdPWBJLUrSuzg8iXSuCsLb30XahnazDs1iDSiWek-0uMAFGUqdO8fsr32RSQMoAP4W6oJIZ41I8faz4=@hughsie.com> |
tl;dr: If you are a vendor manager or a user with permission to push to sta= ble on the LVFS you'll need to set up two-factor authentication on your acc= ount. Over the last few months we've seen a various supply chain issues in other = ecosystems. These have been catastrophic for security and not something I w= ant to repeat with the LVFS project. Passwords alone just aren't good enoug= h anymore, especially when some of these accounts have the ability to push = firmware to millions of end users. Starting from the 1st of August, all vendor manager accounts and users with= permission to push to stable will be required to have 2FA enabled. Until t= hen you'll be gently reminded on login and on *every* firmware page. If you= have not set up 2FA up by the deadline you'll be unable to push firmware t= o testing or stable or add ACLs for other users until you do. Setting up 2FA takes about 30 seconds; go to your profile page, scan the QR= code with your favorite authenticator app (Google Authenticator, FreeOTP, = Aegis, etc.) and you're done. I know adding an extra step for login is annoying -- I find it annoying too= -- but the alternative is me getting a phone call at 3am because an ODMs c= redentials ended up on the dark web and now there's a malicious unsigned fi= rmware update being deployed to millions of people. I would rather not get = that phone call. If you have any problems setting this up or your organization has specific = requirements (hardware tokens, SSO, carrier pigeons, etc.) then please get = in touch and we'll figure something out. If you're logging in via Azure thi= s doesn't affect you, only "local" LVFS logins can set up 2FA themselves. Thanks, Richard.