@mattly You can thank people like me for proving how easy supply chain attacks are for this change.
I usually target inactive accounts of past contributors. Especially those that don't have 2FA and let their email domain names expire.
That said, forced 2FA is the wrong solution. There should be a system for decentralized signed code review so people can sign review on any code, and set policies on how many signed reviews are required on code before it is trusted by their system.