Today, only people working in Fedora infrastructure have compulsory use of 2FA for their FAS account. 2FA is now opt-in for the FAS account.
Given that 2FA provides a big improvement in security and is quite common everywhere, I propose that we require all people in the 'packager' group to enable 2FA.
This 2FA nonsense needs to stop! GitHub has enforced compulsory 2FA for contributors for a while, starting with "important" projects, then getting stricter and stricter. It has done absolutely nothing to stop the xz attack. How could it, when the backdoor was apparently introduced by the authorized maintainer? (Or if not, the attacker must have had access to their 2FA secret as well.) So, 2FA DOES NOT SOLVE THIS PROBLEM! STOP FORCING 2FA ON US! And especially DO NOT abuse this incident as an excuse to force 2FA down our throats, since 2FA DOES NOT SOLVE THIS PROBLEM. Sorry for being repetitive, but the mailing post that triggered the creation of this issue was, too. THIS 2FA NONSENSE NEEDS TO STOP!
2FA is not relevant to this particular attack, but it makes a broad class of attacks much harder. So it's not "nonsense". It can be annoying, but it is another well-established security practice.
Considering how easy it is to take over an account, we've been incredibly lucky that this isn't happening reguarly. (That we know of.) I think that Fedora is still relative obscure, which makes it less of a target, but Linux in general and Fedora in particular is becoming more important every year and we need to move along as security practices change.
Can we make the recovery process better before making this mandatory?
I use 2FA in most of my accounts. I like 2FA. I don't turn it on for my FAS because of the recovery process in case something ever goes wrong and I wish I could.
eg having recovery codes or recovering with a secondary email. If any of this is already implemented, apologies, and I'm happy to try.
Agree with salimma. I use 2FA almost everywhere else, but not for FAS.
I would also stage this. Currently it is not easy to turn off 2FA if anything goes wrong, so it's too scary. We should first add an off switch before packagers will be comfortable turning it on. Then allow, say, 6 months before making it mandatory. Hopefully it will go smoothly, but if not we'll want an off switch until we're comfortable with it.
OK, Neal mentioned on the mailing list that 2FA will break the gnome-online-accounts support for kerberos, which is terrifying. Thank goodness I never turned it on. We should only require 2FA the first time a system authenticates.
The way github has implemented this is stupid and annoying (since you can only have a single second factor). However 2FA itself isn't too bad.
I think the points about areas where the 2FA experience on Fedora are bad are absolutely correct and justified. I also think there is a solid argument that we should do this anyway.
I think the vulnerability associated with having packager (and provenpackager? Do we require 2FA for provenpackager yet? I wasn't actually sure, when I wrote my list post) accounts without 2FA is sufficiently horrendous that we just cannot accept it. Yes, our implementation of 2FA is suboptimal and would frustrate people. Is that worse than the consequences of letting ourselves be compromised? Imagine how brutal the response would be if it came to light that Fedora had been compromised through exploitation of single-factor authentication. It would not be kind. It would be a huge and lasting stain on our reputation. People would say, justifiably so, that it was absolutely unacceptable for us to be allowing single-factor authentication for contributors to a general-purpose operating system in 2024. It is.
We now have incontrovertible evidence that extremely sophisticated attackers are willing to mount extremely sophisticated attacks on the supply chain of which we are a significant component. We are busy Monday morning quarterbacking about extremely complex ways to try and counteract an attack of that sophistication. Meanwhile we are still leaving this huge vulnerability to much less sophisticated attacks, which has been known to be one for literal decades at this point, open. We know that much less sophisticated attackers exploit single-factor authentication for purposes as trivial as stealing cryptocurrency, and it happens frequently. I don't think we can pretend we can't connect the dots here.
On a practical level, if we just made 2FA compulsory, it would provide people with a much stronger motivation to contribute and make the experience of it better. So long as we let people not use it, that motivation does not exist. I suspect if we just did it, we'd get a more sophisticated experience with Kerberos and recovery tokens and all the rest of it much faster than we will if we don't.
Can I pretty please ask people to just discuss this on the list?
The ticket has likely many fewer people paying attention to it, and tickets are poor for discussion IMHO.
Do we require 2FA for provenpackager yet?
No. I am a provenpackager and do not have 2FA enabled (nor do I want it to be).
People would say, justifiably so, that it was absolutely unacceptable for us to be allowing single-factor authentication for contributors to a general-purpose operating system in 2024. It is.
This is nonsense propaganda. Most 2FA implementations cannot even guarantee that the second factor is not stored right next to the first factor. Open standards that do not depend on commercial hardware or telecommunication operators, such as TOTP, cannot guarantee it by design. Any 2FA app that works on my PinePhone is also going to work directly on my computer, so you have no way to enforce that I use a different device for the second factor.
2FA is pointless security theater that just makes it a pain to contribute, when we are all this time talking about lowering, not raising, the barrier to entry.
FWIW, I definitely support this, even though I too have found it to be rather painful in practice.
I would start by doing it for SSO but not yet for Kerberos.
To do this with Kerberos, we should (a) enhance gnome-online-accounts to understand the difference between PIN vs. TOTP token, as currently it will surely try to save the time-based code into gnome-keyring, and also (b) consider significantly increasing the "renew until" lifetime of the tickets to avoid weekly authentication failures.
Folks, please discuss this on the list. FESCo tickets are not designed for discussion like this.
Metadata Update from @sgallagh: - Issue tagged with: stalled
What should we do here? I think somebody should make a concrete proposal with a scope, timeline, and information if any fixes are required before we implement this.
I'll put this on the meeting agenda today to restart the discussion.
Metadata Update from @zbyszek: - Issue tagged with: meeting
I will try to summarize the discussion from a mailing list: https://lists.fedoraproject.org/archives/list/devel@lists.fedoraproject.org/thread/YWMNOEJ34Q7QLBWQAB5TM6A2SVJFU4RV/#UZBCRR3YVYKBFS4KEWKZYG2VNHDE6FNF
This was discussed during the FESCo meeting today.
AGREED: We want packagers to use 2FA and will start with proven packagers. As an initial step, the policy will be changed that PPs SHOULD enroll tokens for 2FA. Once the UX for packagers improved, we'll consider changing the policy to "MUST". (+6, 0, 0)
Metadata Update from @zbyszek: - Issue untagged with: meeting, stalled - Issue tagged with: document it
https://pagure.io/fesco/fesco-docs/pull-request/90
The documentation change has been merged.
Metadata Update from @zbyszek: - Issue untagged with: document it - Issue close_status updated to: Accepted - Issue status updated to: Closed (was: Open)