Mandatory 2FA for all LVFS vendor managers and trusted users

Richard Hughes <[email protected]> Fri, 26 Jun 2026 09:18:17 -0700
Newsgroups dev.linux.lists.lvfs-announce
Message-ID <CAD2FfiF-Q06JwbnuT0k4gViqm3gnwGc43p9psNeCcaNrumDHFg@mail.gmail.com>
tl;dr: If you are a vendor manager or a user with permission to push
to stable on the LVFS you'll need to set up two-factor authentication
on your account.

Over the last few months we've seen a various supply chain issues in
other ecosystems. These have been catastrophic for security and not
something I want to repeat with the LVFS project. Passwords alone just
aren't good enough anymore, especially when some of these accounts
have the ability to push firmware to millions of end users.

Starting from the 1st of August, all vendor manager accounts and users
with permission to push to stable will be required to have 2FA
enabled. Until then you'll be gently reminded on login and on *every*
firmware page. If you have not set up 2FA up by the deadline you'll be
unable to push firmware to testing or stable or add ACLs for other
users until you do.

Setting up 2FA takes about 30 seconds; go to your profile page, scan
the QR code with your favorite authenticator app (Google
Authenticator, FreeOTP, Aegis, etc.) and you're done.

I know adding an extra step for login is annoying -- I find it
annoying too -- but the alternative is me getting a phone call at 3am
because an ODMs credentials ended up on the dark web and now there's a
malicious unsigned firmware update being deployed to millions of
people. I would rather not get that phone call.

If you have any problems setting this up or your organization has
specific requirements (hardware tokens, SSO, carrier pigeons, etc.)
then please get in touch and we'll figure something out. If you're
logging in via Azure this doesn't affect you, only "local" LVFS logins
can set up 2FA themselves.

Thanks,

Richard.