Substack rolls out 2FA, initially for writers and account holders who log in via its web platform, but plans to make it available for mobile app users soon
Kim Zetter / Zero Day : Tweets: @kimzetter , @briankrebs , and @kimzetter . Thanks: @thekenyeung Tweets: Kim Zetter / @kimzetter : Second time Techmeme has picked up a story I published on my Substack publication (I didn't send a tip asking them to pick it up). So many people dismiss Substack publications as not real journalism so it's nice to get a little boost of recognition now and then. Thanks Techmeme🌹 https://twitter.com/... @briankrebs : To my fellow publishers out there on Substack, please lock down your accounts. https://support.substack.com/ ... https://twitter.com/... Kim Zetter / @kimzetter : Exclusive: More than four years after it launched - and after recruiting high-profile and controversial writers like @ggreenwald @bariweiss and @Snowden - Substack has finally implemented two-factor authentication for its users. https://zetter.substack.com/ ... Thanks: @thekenyeung
Context & Ripple Effects
Substack's pitch has always been that writers are sovereign businesses paid directly by subscribers — a framing laid out in the platform-not-media-company profile and the argument that controversies miss what the tool actually is. But sovereignty cuts both ways: when a writer's account is the storefront, its compromise is a business loss, which is why Brian Krebs was publicly urging fellow publishers to lock down their accounts even before this shipped.
The 2FA rollout lands while Substack faces fresh competition from WordPress, Beehiiv, and Ghost after its pandemic growth spurt, making baseline security hygiene part of the platform-vs-platform pitch rather than a courtesy.
First-order effects
- Writers and account holders logging in via Substack's web platform can now enable two-factor authentication immediately; mobile app users have to wait for the promised follow-up release.
Second-order effects
- Rival newsletter platforms competing for the same professional writers face pressure to match or exceed 2FA as a default expectation, since a single hijacked publication undermines the direct-subscription revenue model both sides sell.
- Security hardening joins Substack's existing writer-protection stack — alongside its legal support program for US-based paid writers — as a retention lever against competitors courting high-earning creators.
Third-order effects
- If account security becomes table stakes across newsletter platforms, the durable differentiator shifts back to economics and distribution — reinforcing the 'just a tool' framing rather than editorial curation.
The trend: Newsletter platforms are absorbing enterprise-grade account-security practices as individual writers' publications become standalone businesses worth attacking.