The Register Home Page

back to article Security vets rally around $4 paper password books for sale in Australia

Are you sick and tired of maintaining a password manager? Struggling with choosing the right one for you? Well, readers who live Down Under can get themselves down to their local AusPost branch where they can pick up an old-school alternative for just AU$4.90 (US$3.51). Password books are something of a historical relic, phased …

  1. KittenHuffer Silver badge

    At work ...

    ... they have set our screen saver as the following message - "All you passwords should be Strong"!

    So I have set all my passwords as 'Strong', and everything seems to be fine!

    1. Paul Herber Silver badge

      Re: At work ...

      Saves you having to change it every weak.

      1. David 132 Silver badge

        Re: At work ...

        To shamelessly re-use an old joke: "They said my password had to have 8 characters. So I set it to SnowWhiteAndTheSevenDwarves..."

      2. BiffoTheBorg

        Re: At work ...

        All my password are BeLoNgToUs

    2. Christoph

      Re: At work ...

      If I type my password wrong the computer reminds me that the password is incorrect.

      1. seven of five Silver badge

        Re: At work ...

        Be careful, sometimes the machine tries to troll you: "Password invalid, try again"

        Now what, invalid or again?

        1. Doctor Syntax Silver badge

          Re: At work ...

          That means your password is invalid, try again.

          At least it has a non-alphameric character in it.

    3. Anonymous Coward
      Anonymous Coward

      Re: At work ...

      Also “Please make sure you keep your password to yourself”

      For extra security I use “yourself123”

    4. andy gibson

      Re: At work ...

      Silly. It should be "Str0ng!"

      1. Paul Herber Silver badge

        Re: At work ...

        5tr0n6, 5}-{lr13'/.

  2. Paul Herber Silver badge

    "piss corridors."

    Good moaning! I speak good Fronch.

    1. FeRDNYC Bronze badge

      My nipples explode with delight!

      1. This post has been deleted by its author

      2. Anonymous Coward
        Anonymous Coward

        Eurotrash

        Reminds me of Lolo Ferrari .

      3. Giles C Silver badge

        I will not buy this record….

        1. FeRDNYC Bronze badge

          Drip your pants, Sir William, I cannot wait til lunchtime.

          1. FeRDNYC Bronze badge

            I hate typos I miss the edit window on. *Drop.

      4. Anonymous Coward
        Anonymous Coward

        Please fondle my buttocks

    2. Boris the Cockroach Silver badge

      My hovercraft is full of eels

  3. Victorjoye531

    Honestly, I can see the appeal. A little notebook isn’t exactly high-tech security, but it’s probably better than using the same password for everything. For personal accounts, if you keep it somewhere safe, paper can actually be pretty practical. I’d still prefer a proper password manager for work, though.

    1. Yet Another Anonymous coward Silver badge

      But where do you store the password for your password manager ?

      1. Paul Herber Silver badge

        There's no reason why you can't have more than one password manager!

        1. Yet Another Anonymous coward Silver badge

          It's password apps all the way down

          1. Ahab Returns
            Pint

            Solid Hawking reference sir.

      2. damiandixon

        In the fire safe. The keys on top of the safe.

      3. Scene it all

        My master pw is a very common expression. I could write it down anywhere. What I never write down is what language you need to translate it into before you can use it, and what leet transformation to apply after that. I was using Ancient Egyptian for a while...

        1. Paul Herber Silver badge

          Oooo, beware, your password can become infected with West Nile virus, and many will show no symptoms!

          1. David 132 Silver badge

            Actually, I'm more impressed that "Scene it all" has a keyboard for hieroglyphics. That's one-up from an emoji keyboard, certainly!

            (I started to collect ancient Egyptian gods once, but gave it up before I got the full Set.)

            1. Paul Herber Silver badge

              I got involved with Isis, Then I moved on to CP/M but later on I bought a 2nd-hand Intel MDS and Isis-II was back in my life. I actually managed to rent it out as well and made some good money on that.

              Isis - goddess of Intel blue boxes.

    2. Tron Silver badge

      I've always kept my passwords on a hidden bit of paper.

      With a backup, second bit of paper.

      Given the sheer number of bits of paper in my house, they would not be found in less than a month of methodical searching.

      And I have no intention of transitioning to passkeys.

      I use paper and pen for most notes and reminders and printed sheets of A4 for work and hobbies. Digital is fine, but paper remains my go to medium for cataloguing, reliability, accessibility and long term storage. Those who enjoy Russian roulette are welcome to live their entire lives on their iThing.

    3. jdiebdhidbsusbvwbsidnsoskebid Silver badge

      When I worked somewhere where for very sensible reasons, we were very hot on enforcing password security, I was surprised one day to discover that the rules permitted storing passwords in plain text on paper. You had to then store that paper in a physical safe that was accredited to at least the same security level of the system for which you were storing passwords. So it all kind of made sense. At least it didn't encourage us to make easy to remember (and easy to crack) passwords.

      Looking back, it was an analogue version of a software password manager, with one password (the safe combination) to rule them all. But if you did forget your one password there was at least an analogue password reset. It involved the approved contracted locksmith coming into the office with a set of impressive power tools (and multiple copies of the required paperwork of course). There was no way you could hide your mistake so inevitably you supplied the next day's office snacks.

    4. doublelayer Silver badge

      I think it depends a lot on what passwords they're writing in that book along with the other aspects of where it's stored and whether they have more reason to expect physical security is going to be a bigger problem for them than it is for most of us. I have known far too many people who keep a password book, not because their passwords are random, but to help them remember which iteration of a poor password is for each service. For example, I have had conversations like this with ... let's just say N friends:

      Me: You'll need your password for [service] before I can help you do [task].

      Them: No problem, I keep all my passwords over here. [Hopefully it's a book they pull out, because the alternative is usually a Word document on their desktop and then I have to have a side discussion about that.]

      Them: Alright, here it is [shows me the book].

      Me: You don't have to show me it written down. I was going to ask you to type it yourself. At most you would have to read that one out, not show me a page of passwords. But now you have, you're an Arsenal fan, aren't you? [Example changed to protect N friends]

      Them: You probably knew that already.

      Me: Yes, I did. I didn't know you used the passwords Arsenal11, Arsenal1!, and Ar$enal for all your services. Now, I know you use those for six things, and I think I know what most of the other pages in that book look like. That's not quite what password managers, paper or electronic, are for.

      1. PB90210 Silver badge

        "What's the password?"

        "Yes"

        "No, what is the password?"

        "It is"

        Hand leans in(sic) and types W A T T

    5. the Jim bloke Silver badge
      Thumb Up

      Absolute air-gap, to an analogue format, culturally encrypted, mechanically secured and physically concealed storage facility...

      possibly with unfed leopards nearby.

  4. Ordinary Donkey

    Most important detail

    Store it somewhere really messy. So bad that would-be intruders lose all desire to live before they actually find it.

    1. elsergiovolador Silver badge

      Re: Most important detail

      Inside old used period pad.

      1. Paul Herber Silver badge
        Coat

        Re: Most important detail

        'Old' and 'period' obviously not of similar meaning here. This not a Jane Austen scenario. Use some sense.

        Incontinence pads may be substituted for period pads.

        Goodbye to sensibility here.

        Mine's the one with the sick bag in the pocket.

        1. Anonymous Coward
          Anonymous Coward

          Re: Most important detail

          But dear god, don't store the paper between the pages of the most expensive book in your bookcase, nor the most obviously well-read one.

        2. Ken Shabby Silver badge
          Alert

          Shit Job, but someone has to do it

          Operation Tamarisk

          1. Ken G Silver badge

            Re: Shit Job, but someone has to do it

            There's a plot line they didn't explore on Mission Impossible.

            Let's see Tom Cruise lowered on a rope into that.

      2. Bebu sa Ware Silver badge
        Coat

        Re: Most important detail

        > Inside old used period pad.

        The original one time pad ?

        1. Paul Herber Silver badge

          Re: Most important detail

          What's wrong with back-to-front and then inside-out?

    2. DCdave

      Re: Most important detail

      > Store it somewhere really messy. So bad that would-be intruders lose all desire to live before they actually find it.

      I use some websites that do that with my password, so that next time I try to log on they can tell me that I've forgotten the password I have in the password manager.

      However, I suspect this makes genuine users lose all desire to live, rather than intruders, so the usefulness is limited.

      1. the Jim bloke Silver badge

        Re: Most important detail

        Security fails when the effort to comply with it outweighs the value being protected.

        Banking, etc, get strong unique passwords.

        generic sites that demand passwords without providing anything I want to protect - get generic passwords...

        Thus is the balance of the universe maintained..

    3. Mimsey Borogove Bronze badge

      Re: Most important detail

      I'm way ahead of you.

  5. Aaiieeee

    Happily the book doesn't have 'My Passwords' on the front although it does has 'PWB' and is bright yellow.

    I would hazard that using the 'Forgot Password' link is probably better than keeping a book, and easier.

    1. spuck

      The 'Forgot Password' link

      The 'Forgot Password' link: where it all boils down to access to your target's e-mail bypasses any level of password complexity rules.

  6. MaChatma CoatGPT 2.0
    Go

    When people ask me which pw manager I recommend...

    ...I always tell them to try this method first and see how it works for them:

    https://www.schneier.com/blog/archives/2005/06/write_down_your.html

    I mean, if someone can write their own secure pw manager and still advise pen and paper what else can I do?

    1. Yet Another Anonymous coward Silver badge

      Re: When people ask me which pw manager I recommend...

      You could sign up for my online cloud Password-As-A-Service app.

      Just send me all your passwords, and for only $10/month, I'll remember them for you

      1. Fr. Ted Crilly Silver badge

        Re: When people ask me which pw manager I recommend...

        Wholesale?

  7. Anonymous Coward
    Anonymous Coward

    Does Anyone Remember The (paper-based) Game Hangman?

    .......where you have to guess a word (or phrase) written like this:

    D _ _ _ _ DT _ _ _ PISANA _ _ _ _ _ E

    This is my process for doing the "writing down".......because I can always remember the missing letters.

    You can also pair with a clue: "My favourite film" B _ _ _ _ R _ _ _ _ R

    1. Yet Another Anonymous coward Silver badge

      Re: Does Anyone Remember The (paper-based) Game Hangman?

      >My favourite film" B l a d e R u n n e R

      The passwords of all el'reg readers are all Monty Python and Red Dwarf quotes

      1. Paul Herber Silver badge

        Re: Does Anyone Remember The (paper-based) Game Hangman?

        How the smeg did you know that?

        1. Rich 11

          Re: Does Anyone Remember The (paper-based) Game Hangman?

          The Force was with them

          1. Paul Herber Silver badge

            Re: Does Anyone Remember The (paper-based) Game Hangman?

            More like a farce than a force!

      2. Anonymous Coward
        Anonymous Coward

        Re: Does Anyone Remember The (paper-based) Game Hangman?

        Or Pratchett, Niven, Pournelle, or Adams.

        Alternately, ten years ago, it was a list of all of the ones who got away, reminding me of what a mess I continue to make of my life.

      3. Giles C Silver badge

        Re: Does Anyone Remember The (paper-based) Game Hangman?

        Depends memorable addresses work for me.

        But it could be quotes from Neal Asher, or ship names from culture books.

      4. the Jim bloke Silver badge

        Re: Does Anyone Remember The (paper-based) Game Hangman?

        or it could be the access code for a planet destroying weapon..

        That's the stupidest combination I've ever heard in my life! That's the kind of thing an idiot would have on his luggage"

  8. DJV Silver badge

    Mine are taped to the bottom of the keyboard...

    ...of a Vic-20 in the attic.

    1. Steve K

      Re: Mine are taped to the bottom of the keyboard...

      Does it say "Beware of the leopard" anywhere on it (for extra security)?

      1. DJV Silver badge

        Re: Does it say "Beware of the leopard" anywhere on it (for extra security)?

        Not needed as it is protected by a bunch of killer dust bunnies!

  9. wolfetone Silver badge

    Advice from GCHQ, and the CyberEssentials thing, is that you shouldn't change passwords all the time now. Just make a strong one. So that's alright then, write it down in the book.

    Even better, there are no value in books. So if it's in a drawer or on a shelf, unless it's big enough to have the pages cut out of it to hold a tin of money, it's going to be ignored by the criminal who breaks in to your house.

    1. Anonymous Coward Silver badge
      Holmes

      Or maybe have your password as the first n characters of a certain page of your chosen book.

      Or the initial letters of the first n words on a certain page.

      Or a code eg for your amazon password: first two letters: a,m = 1,13, so page 113; next two letters: a,z: 1,26: the first, second and sixth words on that page.

      But this is all old advice. I'm sure these days it should be done on the AI blockchain

      1. Bebu sa Ware Silver badge
        Windows

        password as the first n characters of a certain page of your chosen book.

        The good old book code. Just ensure the you use the same editions for decoding as encoding. ;)

        These days I imagine with a reasonable amount of cyphertext it would be vulnerable to modern cryptoanalysis.

        Just occurred to me her indoors, when she was rather poorly, was given a small book with a short but saccharine inspirational text on each page which could be used for passwords eg every second word. Not something anyone would half inch or seemingly one can lose (it's still around 12 years and 4 house moves later.)

        1. Wellyboot Silver badge

          Re: password as the first n characters of a certain page of your chosen book.

          All the AI has probably already got a copy scanned, copyright what's that!

      2. HereIAmJH Silver badge

        I use my favorite book. It's the first character on the first 50 pages.

        As a bonus, if you mistype and get temporarily locked out, by the time you have gone through the 50 pages again the lockout has reset.

        1. Fred Daggy Silver badge

          Which edition of the book?

          And, also, I use an e-book, is it the same on all font sizes or e-reader software?

    2. Snake Silver badge
      FAIL

      RE: don't change passwords often

      I wish I could get this through the incredibly thick, dense and stupid programmers at our merchant bank, they make their credit card merchant app demand a new password every 30 days. Notifying and forcing this fact upon you after the set time only when you try to log in to use it, with a customer in front of you of course, because why would you be on the merchant app if you didn't need it?

      So here you are. On their stupid CC merchant transaction app, trying to register a sale, and locked out because they demand a new password before continuing. So, you do the obvious thing: make up the quickest password that you can to get this stupid process through so your customer isn't tapping their fingers on your desk in frustration. And then having to stop to record the stupid brand-new password somewhere so you don't forget that stupid password the next time you need to log into their stupid app.

      I've told them, several times, that their policy makes security WEAKER but do they listen?? Of course not, stupid programmers believe they are not stupid because they're "IT".

      My rant reminds me of the best days of Jeremy Clarkson. He needs to punch out a few programmers, forget TV producers.

      1. Yet Another Anonymous coward Silver badge

        Re: RE: don't change passwords often

        >My rant reminds me of the best days of Jeremy Clarkson. He needs to punch out a few programmers, forget TV producers.

        And who told the programmer to block using the same character twice in a password ?

        1. Anonymous Coward
          Anonymous Coward

          Re: RE: don't change passwords often

          The programmers are just doing what corporate security told them too.

          I've been the programmer pushing back on some of the password requirements being pushed in defence projects...

        2. NXM Silver badge

          Re: RE: don't change passwords often

          I came across a site the other day where it disallowed non-alphanumeric characters in the password, eg # ! * and so on. What??

          1. PB90210 Silver badge

            Re: RE: don't change passwords often

            How about having a different list of 'special characters' for password creation and password entry!

            1. Yet Another Anonymous coward Silver badge

              Re: RE: don't change passwords often

              There was a network switch that let you enter "!" in the password on the initial web setup screen but blocked it on the login console prompt

              Of course it didn't fscking tell you it was doing this...

      2. bernmeister
        FAIL

        Re: RE: don't change passwords often

        The GCHQ advice sounds OK unless you are a high profile user worth spending the effort on to crack a very secure password.

      3. Tron Silver badge

        Re: RE: don't change passwords often

        Wouldn't it be a plan to change to a bank that doesn't require a new password every month? If enough customers do that, the penny might drop.

      4. Anonymous Coward Silver badge
        Go

        Re: RE: don't change passwords often

        > "So, you do the obvious thing"

        The obvious (to me) thing to do would be to switch supplier. Tell them that their service is not usable because it loses you a sale once a month purely through their password policy. It won't change anything, but if enough people vote with their wallets they might get the message.

      5. david 12 Silver badge

        Re: RE: don't change passwords often

        demand a new password every 30 days

        There is a security trade-off: Password changes require weaker and less secure passwords, but static passwords are not secure against frequent staff changes or multiple staff members.

  10. Doctor Syntax Silver badge

    Beware of unproven assumptions

    This idea assumes one can read one's own handwriting.

    I suppose the workaround is to ask someone with more legible handwriting to write them down. Can't see any problems with that.

    1. Yet Another Anonymous coward Silver badge

      Re: Beware of unproven assumptions

      You simply use an old mechanical typewriter

      1. Doctor Syntax Silver badge

        Re: Beware of unproven assumptions

        Not easy to feed a book round the rollers. I wonder where my old typewriter is. It's probably around somewhere unless it got lost in a house move. The first thing I bought with my first grand check ----How many???!!!! - years ago. £10 was a fair bit of cash in those days.

        1. Yet Another Anonymous coward Silver badge

          Re: Beware of unproven assumptions

          Even if you did find it, the authentication server wouldn't be around anymore and all the capacitors would have leaked

        2. HereIAmJH Silver badge

          Re: Beware of unproven assumptions

          Not easy to feed a book round the rollers

          Go high tech. Get a label printer to print your password, then stick the password label in the book.

      2. ITS Retired

        Re: Beware of unproven assumptions

        With a cloth ribbon, or a one use plastic one?

        1. Martin an gof Silver badge

          Re: Beware of unproven assumptions

          Use a plastic one, burn the paper and keep the ribbon as your aide-memoire. Bit awkward to unwind it, and the indexing is non-existent, but...

          M.

          1. Yet Another Anonymous coward Silver badge

            Re: Beware of unproven assumptions

            I scratch my passwords into the back of clay tablets. I use old receipts for copper so nobody will be interested in reading them

            1. PB90210 Silver badge

              Re: Beware of unproven assumptions

              Back in the day, I used to keep a few old job sheets on my desk... the job refs were a handy mix of 8 letters and numbers

              And bitlocker PINs could be turned into phone numbers

      3. jdiebdhidbsusbvwbsidnsoskebid Silver badge

        Re: Beware of unproven assumptions

        But with some mechanism to scramble the letters as you typed them perhaps? How you would make such a thing is a real puzzle, an enigma if you will.

        1. Yet Another Anonymous coward Silver badge

          Re: Beware of unproven assumptions

          I just use Verschlüsselungsmaschine as my password directly

  11. Yet Another Anonymous coward Silver badge

    But China..

    So where are these books printed?

    And where does the wood pulp for the paper come from?

    How do we now they don't have the same invisible, undetectable spy chips which so worry our politicians?

    Or, since these are from the government post office of 5-eyes member Australia, can we assume the NSA is spying on us?

    1. Bebu sa Ware Silver badge
      Windows

      Paper with spy chips

      I think that is just within the capability of current technology. Some sort pressure sensing embedded in the paper during manufacture and the processing etc embedded in the book's spine. Communicating with low power BT or NFC.

      I wonder who supplies the government's desk diaries ? ;)

      Do we (Australia) have any secrets that the USA NSA isn't already privy to ? I suspect that NSA is privy to a great deal that Federal cabinet is unaware of and whose members prefer to remain in that blissful state of ignorance (Please just let us know who we at war with before our media informs us.)

      1. Yet Another Anonymous coward Silver badge

        Re: Paper with spy chips

        >Please just let us know who we at war with before our media informs us.)

        Emutopia has always been at war with Kiwiland

  12. FuzzyTheBear
    Holmes

    Simple is nice :)

    Simple things are the best . Want security , look at the old , at the forgotten ways of yesteryears.

    That old modem card is gold. Point to point , no internet. I call you , you answer , we're connected ? good :)

    The time honored fax machine sitting in a corner .. need to send a sensitive document , better this than the internet.

    Keeping passwords in a little book in my pocket ? Been at it since 2002. Same book.

    Advice ? Keep good strong passwords. I never changed mine and i never been in trouble.

    Ric

    1. Wellyboot Silver badge

      Re: Simple is nice :)

      Modem & fax require a POTS line at both ends, getting rare these days

      A good old acoustic coupler can probably ramp up to a reasonable bit rate these days.

      1. Doctor Syntax Silver badge

        Re: Simple is nice :)

        Nowadays it's PoI - POTS over Internet.

      2. Martin an gof Silver badge

        Re: Simple is nice :)

        A proper POTS line is very simple to tap and modem chat – particularly fax – is not difficult to decode...

        M.

        1. JT_3K
          Coat

          Re: Simple is nice :)

          Ye olde days of pulling your data with a pair of crocodile clips at some point between the two.

          My knees hurt, it's time I left - I'll get my coat. Mine's the one with a lightbulb hooked to a RJ11 in one pocket and a battery hooked to an RJ11 in the other.

  13. Uh, Mike

    Sorry, wrong number

    Glancing at the headline,

    I thought they were selling notebooks with the passwords and accounts already filled in

    (i.e. stolen).

    Never mind.

    1. Doctor Syntax Silver badge

      Re: Sorry, wrong number

      You weren't alone.

      Have I been pwned the book.

    2. PB90210 Silver badge

      Re: Sorry, wrong number

      The Russian one-time pads were undone because the printers got lazy and printed off hundreds of identical pads

      (which were further compromised by operators reusing pads because of shortages)

  14. trevorde Silver badge

    Roll your own password manager

    One consultancy I worked for did an audit of a client's custom software, including a password manager written by a long gone employee. Apart from being fairly poor code, it stored the passwords in a CSV file on a hard coded, shared network drive. We recommended they just pay for any of the commercially available password managers. Or a stack of Post-It notes.

  15. Anonymous Coward
    Anonymous Coward

    123456 same as my luggage. Never been hacked. If they ever figure out Quantum computing or use Ai it still won't get hacked. Why? because no one can believe someone could be that stupid.

    As for writing passwords down I have worked in too many places with people using post-it notes for passwords because of the password policies of changing it ever single month with no repeat words and having to use special, numerical and upper/lowercase letters. Obviously things are different now and we have MFA, Passkeys, RSA devices and biometrics but back in the day that's just what people did.

    1. nobody who matters Silver badge

      ".................because no one can believe someone could be that stupid."

      Oh, they can.

      You only have to look at the regular publishing of details of the most pwned passwords to see just how huge a portion of the IT using population really <are> that stupid!

      1. DJO Silver badge

        Oh, they can.

        Indeed, never forget that by definition 50% of people are of average or lower intelligence. And it shows.

    2. ITS Retired

      Back in the day of beige CRT's, write the passwords around the edges of the monitor in pencil.

      1. jdiebdhidbsusbvwbsidnsoskebid Silver badge

        Well that's good enough for banks thinking that a 3 digit CVC/CVV provides some security, believing that you would only know the CVC/CVV if you had the card in your physical possession - or had merely glanced at someone's card at some point in the past.

        I never understood why signatures on a credit card were considered a security measure. It's no different to having the secret PIN printed on the card.

        1. Yet Another Anonymous coward Silver badge
  16. Blackjack Silver badge
    Happy

    I never lost or had a password books stolen despite everyone dissing me for using them. Yet I had accounts stolen or taken over anyway thanks to hacks and data leaks.

    In fact thanks to the modern internet password books are safer that password managers.

  17. IGotOut Silver badge

    You can even make paper notes secure

    Two extra characters at the beginning, two at the end.

    Three or four for extra security. Easy to remember, hard to guess.

    The sort to break into your house are not the sort to spend hour after hour brute forcing the account.

    1. PRR Silver badge

      Re: You can even make paper notes secure

      > ...extra characters at the beginning, two at the end.

      Yup. I had a car with an easily removable radio/CD head. Of course for 'security' if it lost power you had to know a secret number to unlock it. The first time I had to dig-out the little tag to unlock after a power glitch, I wrote it on paper, with extra chars as you describe, and taped it to the radio face. I had done similar in the 1980s for padlock combos; have done it twice again for two more cars.

    2. Sherrie Ludwig

      Re: You can even make paper notes secure

      Try writing the password in plaintext, but it gets entered as pig Latin. Assword-Pay will be difficult to brute force.

  18. Stifler-7

    I Fix Paper Password Disasters for Money. Here’s My Setup.

    I’ve used a self-managed, searchable, password-protected table in Corel WordPerfect for 25 years. It holds ~260 entries, screenshots, and security questions. Once a year, I prune obsolete entries and archive a fresh copy, exporting to a password-protected PDF when needed.

    It’s backed up locally across multiple internal and external methods, and secure cloud storage. Never had an issue. I’ve always preferred handling my own data over relying on automated third-party tools.

    I’m fully aware of the security risks with this setup—nothing is 100% foolproof nowadays, especially with AI-driven threats. But global corporations and governments with massive budgets get breached and held for ransom. As a low-profile local tech, keeping things simple, local, and controlled works for me.

    Besides, a significant chunk of my billable hours comes from helping clients who got locked out by relying on messy, incomplete paper password notebooks, and loose sheets of paper. I certainly don't mind getting paid to clean up those mistakes!

  19. Anonymous Coward
    Anonymous Coward

    Post it notes work.

    I place a list of obvious passwords on a post it note on my screen, by the time anyone has tried enough of them they are locked out.

    1. Anonymous Coward
      Anonymous Coward

      Re: Post it notes work.

      This ^

  20. cmdrklarg

    Note cards

    I have all my usernames and passwords on note cards in my desk drawer. The thing is, I don't have them written out; what I have written down is a cryptic clue that tells me what it is. I have a system that the pw's are somewhat similar but sufficiently different so that if one is compromised it won't automatically mean all of them are.

    The weakness comes from those sites that force a PW change every 3 months. Bastards! *shakes fist*

  21. PRR Silver badge
    Trollface

    A stack of 26 sheets of paper tacked up above the dog sleeping next to the computer, from a plain passwords.TXT file on my desktop. Copies in Gmail, but then I change the filename to randomstrings.txt.

    Some passwords are too obvious like H0tH0tH0t! (invented on a bad summer day; now my newspaper PW, low risk). OTOH when I stumble on a snarl of quasi-random strings (encrypted email) I save it and extract chunks for more secure use.

    001: heMib7@4nk73 , 002: 8DjJdK]!YR~8 , 003: x?Y+9#if9$2y

    I had a colleague who had code to spit 63 character utterly random passwords for others to use. Life is too short.

    1. Doctor Syntax Silver badge

      Keepass. Generates the line-noise like passwords on demand. Copy and paste. Save encrypted.

    2. stiine Silver badge

      grc.com has an online generator that spits those out as either alphanumeric, hex, or alphanumeric plus symbols.

      One thing to watch for with any password manager is that the password you generated is the password that gets copied to your clipboard. I have had password managers in the past that botch the retrieval into the clipboard buffer. If you know you copied the correct password for the correct account for the correct website (I'm a consultant and have about 800 account/password combinations) and it doesn't work after the first attempt, stop and verify that the password that you have stored is the password you currently have loaded into your clipboard buffer. I've had this happen where my symbol-laden passwords were being imported correctly but truncated on retrieval.

      And I now see that If I had read all of the comments before commenting myself, I wouldn't be editing my comment to note that someone below already mentioned grc.com...

      1. PB90210 Silver badge

        Cisco routers had the habit of accepting trailing spaces if the (plaintext) password was the last thing on the CLI command line!

        Real bugger if that command has just locked you out and you need to log back in

    3. David 132 Silver badge
      Coat

      001: heMib7@4nk73 , 002: 8DjJdK]!YR~8 , 003: x?Y+9#if9$2y

      Why are you using as your password the pet nickname that my mother had for me as a small child?

      I feel quite paranoid now.

      1. Anonymous Coward
        Anonymous Coward

        little if9$2y ?

        I used to live next door to you as a kid !

  22. ecofeco Silver badge

    That's crazy!

    Who is paying $4 for a pocket notepad? There are much cheaper ones!

    1. Yet Another Anonymous coward Silver badge

      Re: That's crazy!

      But this one is for passwords

  23. Mythical Ham-Lunch

    I got in trouble for writing down a complex password at a job with no password manager BUT where the admin password of a very important cluster was 'password'. Best laid schemes o' mice and men, etc.

    1. Yet Another Anonymous coward Silver badge

      >admin password of a very important cluster was 'password'.

      Well obviously nobody would ever use such an obvious password for such an important system and so logically it's perfectly secure

    2. PB90210 Silver badge

      Default login for super supervisor (God's supervisor) was: 'super.super' with password 'great'

  24. Anonymous Coward
    Anonymous Coward

    I had this argument years ago

    With people who were security professionals :). (As was I)

    Summary is the same.

    Sure your home can be burgled but you'll generally know there's been a compromise and the rewards for whoever are relatively small - and the skill set to make use of that differs from that of the average yobbo.

    Store passwords in a local vault on a PC or worse remotely and if someone cracks that then there are potentially millions of compromised accounts and worse, you won't necessarily know it happened, plus the rewards are immensely higher and 'same skillset'.

    To some extent that happens now with businesses being popped and details harvested, could be far far worse.

    The other catch is that online security is getting more complex sure, but complex and obfuscated isn't actually the same as secure. Once a crack of say passkeys is known use is widespread within days. Paper you still have to retail it, and it all differs. Still security by obfuscation but the effort/reward ratio is vastly worse for an attacker.

    1. doublelayer Silver badge

      Re: I had this argument years ago

      Physical security concerns are far more than that. Random, opportunistic burgling is only one of the ways physical security becomes important. In a business situation, people with access to your office or desk are more plentiful. If you're using a password book there, it's usually a worse idea. Keep in mind that most security professionals are commenting on work things because it's their job to secure that, whereas if you aren't secure enough at home, it's you that suffers.

      But let's focus on the home. The biggest risk is not a random robbery. The biggest risk is one people don't like to think about, someone with access to your house deciding to abuse the credentials they find in the book. Maybe it's a family member or friend who isn't as trustworthy as you thought they were. Maybe they were trying to help you with something but are more gullible than you would be. It's worth remembering that a lot of identity theft is committed by family members against one another for the simple reason that most people wanting to commit identity theft don't know how to get anyone else's identifying information. It's probably not going to happen to you or me because it's rare in total, but that's true of most other security incidents and we still defend ourselves against those.

  25. Noodle

    No school like the old school

    My 85 year old mother-in-law is going to feel so vindicated by this article. She's been keeping all her passwords in a little book for years!

  26. ricardian1943

    And https://www.grc.com/passwords.htm is still going. Choose from

    64 random hexadecimal characters (0-9 and A-F) or

    63 random printable ASCII characters or

    63 random alpha-numeric characters (a-z, A-Z, 0-9).

    1. Anonymous Coward
      Anonymous Coward

      >64 random hexadecimal characters (0-9 and A-F)

      Or take a shorter and rather more memorable string, run it through MD5 / SHA1 / etc and you get a somewhat random long string to cut and paste

      Advantage is that you can generate it on any system without access to your password manager - assuming you are the sort of halfwit who failed to memorise the 64 random hex digits

  27. DS999 Silver badge

    There is a role for writing a password down on paper

    The password/key for your password manager, or if you use an iPhone as your password manager as I increasingly am for your Apple ID password and iCloud recovery key. You can stick those in a safe deposit box then you can recover the passwords to everything else even if you're one of the people who have lost everything this summer due to historic wildfires or floods. Though if I had to flee a disaster the one thing I would very likely grab is my phone, but you can't 100% count being able to do that.

  28. david 12 Silver badge

    It's an indexed address book!

    You wonder WTF is a 'password book'? Older readers may recognize the terms "Little Black Book" or "Address Book" Even older readers may recognize the term "pocket book", although not all address books were pocket books, and not all pocket books were indexed (letter tabs on the free edge).

    \

    Nice bit of retro technology, and nice to see a bit of retro technology repurposed. Ha I say -- and you tried to tell me my rolodex was passé

  29. Anonymous Coward
    Anonymous Coward

    The problem with password managers is

    You need to remember the password to open the password manager.

    With the increasing use of stronger passwords is more calls to the Help Desk for a password reset, so they introduce "use three words", which in reality is fine but that's more to remember and more likely to forget. Bio-metrics are the way forward though some are against this for good reason. The amount of users who i see that use bio-metrics and then when required to use the old way off logging in is quite a lot, at that point they refer to the note book where they have physically written it down.

    1. X5-332960073452
      FAIL

      Re: The problem with password managers is

      Bio-metrics - Do not use for security, something you cannot change! Identification, fine, security NO.

      And, while I'm at it, PassKeys, NO, NO, NO, NO, NO

      1. Yet Another Anonymous coward Silver badge

        Re: The problem with password managers is

        >And, while I'm at it, PassKeys, NO, NO, NO, NO, NO

        Stick to getting an SMS with a 4 digit pin. After all if you can't trust the telephone company.....

  30. Anonymous Coward
    Anonymous Coward

    Ha

    Good luck if anyone can decipher Mum’s little notepad.

    I have a safe backup. She never changes here passwords.

  31. Always Right Mostly Bronze badge

    You gotta get your fun where you can make it so I had a job. I set my password to be “Fuck you”.

    I always loved it when a techie came around and said I need your password.

    1. Tron Silver badge

      Tsk tsk.

      You don't give your password to someone because they say they are a techie, or they are a techie, or they are the CEO. You don't give your password to anyone but a copper interviewing you down the nick threatening you with prison if you don't hand it over.

      1. doublelayer Silver badge

        Re: Tsk tsk.

        "You don't give your password to anyone but a copper interviewing you down the nick threatening you with prison if you don't hand it over."

        And then only after familiarizing yourself with the law in the country you're in. In some countries, you don't have to give passwords when asked, but in all countries, police are allowed to threaten you and hope you'll decide to "voluntarily" do so. Get a lawyer who will tell you the answer to that along with many other things if you can, and if you can't, learn things that apply to you.

  32. Anonymous Coward
    Anonymous Coward

    Password books are good

    It's worth remembering that not everything sits on one PC - I have passwords for TV apps, phone banking, and for various things for my kids - The password info in the book is in the form of aide-memoirs rather than plaintext passwords, and the book is itself pretty obscure and kept in a nondescript place. It also has similar info for my wife, so we have a one-stop shop for those rare occasions where we can't remember a password or username. It's really useful.

  33. BigKev

    I went back to a paper based system after LastPass ceased and deleted my account without notice and wouldn't talk to me about fixing it because "You appear not to have an account"

    It was a difficult few days - now I use KeePass (under my control) and paper backup

  34. Bob Royal

    Don't try to be too clever

    I'm not saying that I might have done this, or why I might have done it; but:

    I suggest you don't write down passwords with sneaky obfuscation which you

    imagine you will remember, but invariably WON'T.

    Don't forget, you need to keep not only the password, but the user name and the name of the site.,

    and various other bits too sometimes.

    These don't all have be written down TOGETHER.

  35. tekHedd

    2FA

    Nobody steals books...but just in case, never put the *entire* password in your password book.

    You still have to memorize a few password extensions, but there's no need to memorize one per site--unless they're high value.

    Backups are a pain though--have to find an actual working copier!

  36. Anonymous Coward
    Anonymous Coward

    " they won’t do you much good if your house is burgled"

    I won't agree.

    I've ~2k books at home. No-one is insane enough to carry all them out and finding a leaflet between one of them is 1 in 2000+. Good luck on that.

    Definitely possible, but easier and faster to beat me until I tell where it is: Inherent weak point in any password system.

  37. tiggity Silver badge

    I have 2 notebooks of important personal passwords (in different bookshelves in different parts of the house). In the unlikely event of theft unlikely both copies stolen.

    .. Plus we have a lot of books in our house, so unlikely either would be taken.

    Passwords are all incomplete as use same prefix & suffix on important ones (those are not in the book)

    "Junk" passwords (e.g. El Reg password / username info) are held in a password manager only.

    Work creds are (obv.) never stored in my books, I use whatever work mandated password manager is flavour of the month for those.

  38. yngndrw

    So now a password stored in a physical book, along with an "MFA token" would be single factor authentication - Two instances of the same "something you have" factor.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon