Mandatory 2FA for all LVFS vendor managers and trusted users
Richard Hughes <[email protected]> Fri, 26 Jun 2026 09:18:17 -0700
| Newsgroups | dev.linux.lists.lvfs-announce |
|---|---|
| Message-ID | <CAD2FfiF-Q06JwbnuT0k4gViqm3gnwGc43p9psNeCcaNrumDHFg@mail.gmail.com> |
tl;dr: If you are a vendor manager or a user with permission to push to stable on the LVFS you'll need to set up two-factor authentication on your account. Over the last few months we've seen a various supply chain issues in other ecosystems. These have been catastrophic for security and not something I want to repeat with the LVFS project. Passwords alone just aren't good enough anymore, especially when some of these accounts have the ability to push firmware to millions of end users. Starting from the 1st of August, all vendor manager accounts and users with permission to push to stable will be required to have 2FA enabled. Until then you'll be gently reminded on login and on *every* firmware page. If you have not set up 2FA up by the deadline you'll be unable to push firmware to testing or stable or add ACLs for other users until you do. Setting up 2FA takes about 30 seconds; go to your profile page, scan the QR code with your favorite authenticator app (Google Authenticator, FreeOTP, Aegis, etc.) and you're done. I know adding an extra step for login is annoying -- I find it annoying too -- but the alternative is me getting a phone call at 3am because an ODMs credentials ended up on the dark web and now there's a malicious unsigned firmware update being deployed to millions of people. I would rather not get that phone call. If you have any problems setting this up or your organization has specific requirements (hardware tokens, SSO, carrier pigeons, etc.) then please get in touch and we'll figure something out. If you're logging in via Azure this doesn't affect you, only "local" LVFS logins can set up 2FA themselves. Thanks, Richard.