> By default, any users are able to install firmware to removable hardware. The logic here is that if the hardware can be removed, it can easily be moved to a device that the user already has root access on, and asking for authentication would just be security theatre.
- http://www.fwupd.org/users.html
But it is not given that a user has physical access to the machine, is it?
Well... I guess that's why it says "By default", and you can configure it? Seems targeted at desktop installations?