At work ...
... they have set our screen saver as the following message - "All you passwords should be Strong"!
So I have set all my passwords as 'Strong', and everything seems to be fine!
Are you sick and tired of maintaining a password manager? Struggling with choosing the right one for you? Well, readers who live Down Under can get themselves down to their local AusPost branch where they can pick up an old-school alternative for just AU$4.90 (US$3.51). Password books are something of a historical relic, phased …
This post has been deleted by its author
Honestly, I can see the appeal. A little notebook isn’t exactly high-tech security, but it’s probably better than using the same password for everything. For personal accounts, if you keep it somewhere safe, paper can actually be pretty practical. I’d still prefer a proper password manager for work, though.
With a backup, second bit of paper.
Given the sheer number of bits of paper in my house, they would not be found in less than a month of methodical searching.
And I have no intention of transitioning to passkeys.
I use paper and pen for most notes and reminders and printed sheets of A4 for work and hobbies. Digital is fine, but paper remains my go to medium for cataloguing, reliability, accessibility and long term storage. Those who enjoy Russian roulette are welcome to live their entire lives on their iThing.
When I worked somewhere where for very sensible reasons, we were very hot on enforcing password security, I was surprised one day to discover that the rules permitted storing passwords in plain text on paper. You had to then store that paper in a physical safe that was accredited to at least the same security level of the system for which you were storing passwords. So it all kind of made sense. At least it didn't encourage us to make easy to remember (and easy to crack) passwords.
Looking back, it was an analogue version of a software password manager, with one password (the safe combination) to rule them all. But if you did forget your one password there was at least an analogue password reset. It involved the approved contracted locksmith coming into the office with a set of impressive power tools (and multiple copies of the required paperwork of course). There was no way you could hide your mistake so inevitably you supplied the next day's office snacks.
I think it depends a lot on what passwords they're writing in that book along with the other aspects of where it's stored and whether they have more reason to expect physical security is going to be a bigger problem for them than it is for most of us. I have known far too many people who keep a password book, not because their passwords are random, but to help them remember which iteration of a poor password is for each service. For example, I have had conversations like this with ... let's just say N friends:
Me: You'll need your password for [service] before I can help you do [task].
Them: No problem, I keep all my passwords over here. [Hopefully it's a book they pull out, because the alternative is usually a Word document on their desktop and then I have to have a side discussion about that.]
Them: Alright, here it is [shows me the book].
Me: You don't have to show me it written down. I was going to ask you to type it yourself. At most you would have to read that one out, not show me a page of passwords. But now you have, you're an Arsenal fan, aren't you? [Example changed to protect N friends]
Them: You probably knew that already.
Me: Yes, I did. I didn't know you used the passwords Arsenal11, Arsenal1!, and Ar$enal for all your services. Now, I know you use those for six things, and I think I know what most of the other pages in that book look like. That's not quite what password managers, paper or electronic, are for.
> Store it somewhere really messy. So bad that would-be intruders lose all desire to live before they actually find it.
I use some websites that do that with my password, so that next time I try to log on they can tell me that I've forgotten the password I have in the password manager.
However, I suspect this makes genuine users lose all desire to live, rather than intruders, so the usefulness is limited.
Security fails when the effort to comply with it outweighs the value being protected.
Banking, etc, get strong unique passwords.
generic sites that demand passwords without providing anything I want to protect - get generic passwords...
Thus is the balance of the universe maintained..
...I always tell them to try this method first and see how it works for them:
https://www.schneier.com/blog/archives/2005/06/write_down_your.html
I mean, if someone can write their own secure pw manager and still advise pen and paper what else can I do?
.......where you have to guess a word (or phrase) written like this:
D _ _ _ _ DT _ _ _ PISANA _ _ _ _ _ E
This is my process for doing the "writing down".......because I can always remember the missing letters.
You can also pair with a clue: "My favourite film" B _ _ _ _ R _ _ _ _ R
Advice from GCHQ, and the CyberEssentials thing, is that you shouldn't change passwords all the time now. Just make a strong one. So that's alright then, write it down in the book.
Even better, there are no value in books. So if it's in a drawer or on a shelf, unless it's big enough to have the pages cut out of it to hold a tin of money, it's going to be ignored by the criminal who breaks in to your house.
Or maybe have your password as the first n characters of a certain page of your chosen book.
Or the initial letters of the first n words on a certain page.
Or a code eg for your amazon password: first two letters: a,m = 1,13, so page 113; next two letters: a,z: 1,26: the first, second and sixth words on that page.
But this is all old advice. I'm sure these days it should be done on the AI blockchain
The good old book code. Just ensure the you use the same editions for decoding as encoding. ;)
These days I imagine with a reasonable amount of cyphertext it would be vulnerable to modern cryptoanalysis.
Just occurred to me her indoors, when she was rather poorly, was given a small book with a short but saccharine inspirational text on each page which could be used for passwords eg every second word. Not something anyone would half inch or seemingly one can lose (it's still around 12 years and 4 house moves later.)
I wish I could get this through the incredibly thick, dense and stupid programmers at our merchant bank, they make their credit card merchant app demand a new password every 30 days. Notifying and forcing this fact upon you after the set time only when you try to log in to use it, with a customer in front of you of course, because why would you be on the merchant app if you didn't need it?
So here you are. On their stupid CC merchant transaction app, trying to register a sale, and locked out because they demand a new password before continuing. So, you do the obvious thing: make up the quickest password that you can to get this stupid process through so your customer isn't tapping their fingers on your desk in frustration. And then having to stop to record the stupid brand-new password somewhere so you don't forget that stupid password the next time you need to log into their stupid app.
I've told them, several times, that their policy makes security WEAKER but do they listen?? Of course not, stupid programmers believe they are not stupid because they're "IT".
My rant reminds me of the best days of Jeremy Clarkson. He needs to punch out a few programmers, forget TV producers.
> "So, you do the obvious thing"
The obvious (to me) thing to do would be to switch supplier. Tell them that their service is not usable because it loses you a sale once a month purely through their password policy. It won't change anything, but if enough people vote with their wallets they might get the message.
Not easy to feed a book round the rollers. I wonder where my old typewriter is. It's probably around somewhere unless it got lost in a house move. The first thing I bought with my first grand check ----How many???!!!! - years ago. £10 was a fair bit of cash in those days.
So where are these books printed?
And where does the wood pulp for the paper come from?
How do we now they don't have the same invisible, undetectable spy chips which so worry our politicians?
Or, since these are from the government post office of 5-eyes member Australia, can we assume the NSA is spying on us?
I think that is just within the capability of current technology. Some sort pressure sensing embedded in the paper during manufacture and the processing etc embedded in the book's spine. Communicating with low power BT or NFC.
I wonder who supplies the government's desk diaries ? ;)
Do we (Australia) have any secrets that the USA NSA isn't already privy to ? I suspect that NSA is privy to a great deal that Federal cabinet is unaware of and whose members prefer to remain in that blissful state of ignorance (Please just let us know who we at war with before our media informs us.)
Simple things are the best . Want security , look at the old , at the forgotten ways of yesteryears.
That old modem card is gold. Point to point , no internet. I call you , you answer , we're connected ? good :)
The time honored fax machine sitting in a corner .. need to send a sensitive document , better this than the internet.
Keeping passwords in a little book in my pocket ? Been at it since 2002. Same book.
Advice ? Keep good strong passwords. I never changed mine and i never been in trouble.
Ric
One consultancy I worked for did an audit of a client's custom software, including a password manager written by a long gone employee. Apart from being fairly poor code, it stored the passwords in a CSV file on a hard coded, shared network drive. We recommended they just pay for any of the commercially available password managers. Or a stack of Post-It notes.
123456 same as my luggage. Never been hacked. If they ever figure out Quantum computing or use Ai it still won't get hacked. Why? because no one can believe someone could be that stupid.
As for writing passwords down I have worked in too many places with people using post-it notes for passwords because of the password policies of changing it ever single month with no repeat words and having to use special, numerical and upper/lowercase letters. Obviously things are different now and we have MFA, Passkeys, RSA devices and biometrics but back in the day that's just what people did.
Well that's good enough for banks thinking that a 3 digit CVC/CVV provides some security, believing that you would only know the CVC/CVV if you had the card in your physical possession - or had merely glanced at someone's card at some point in the past.
I never understood why signatures on a credit card were considered a security measure. It's no different to having the secret PIN printed on the card.
> ...extra characters at the beginning, two at the end.
Yup. I had a car with an easily removable radio/CD head. Of course for 'security' if it lost power you had to know a secret number to unlock it. The first time I had to dig-out the little tag to unlock after a power glitch, I wrote it on paper, with extra chars as you describe, and taped it to the radio face. I had done similar in the 1980s for padlock combos; have done it twice again for two more cars.
I’ve used a self-managed, searchable, password-protected table in Corel WordPerfect for 25 years. It holds ~260 entries, screenshots, and security questions. Once a year, I prune obsolete entries and archive a fresh copy, exporting to a password-protected PDF when needed.
It’s backed up locally across multiple internal and external methods, and secure cloud storage. Never had an issue. I’ve always preferred handling my own data over relying on automated third-party tools.
I’m fully aware of the security risks with this setup—nothing is 100% foolproof nowadays, especially with AI-driven threats. But global corporations and governments with massive budgets get breached and held for ransom. As a low-profile local tech, keeping things simple, local, and controlled works for me.
Besides, a significant chunk of my billable hours comes from helping clients who got locked out by relying on messy, incomplete paper password notebooks, and loose sheets of paper. I certainly don't mind getting paid to clean up those mistakes!
I have all my usernames and passwords on note cards in my desk drawer. The thing is, I don't have them written out; what I have written down is a cryptic clue that tells me what it is. I have a system that the pw's are somewhat similar but sufficiently different so that if one is compromised it won't automatically mean all of them are.
The weakness comes from those sites that force a PW change every 3 months. Bastards! *shakes fist*
A stack of 26 sheets of paper tacked up above the dog sleeping next to the computer, from a plain passwords.TXT file on my desktop. Copies in Gmail, but then I change the filename to randomstrings.txt.
Some passwords are too obvious like H0tH0tH0t! (invented on a bad summer day; now my newspaper PW, low risk). OTOH when I stumble on a snarl of quasi-random strings (encrypted email) I save it and extract chunks for more secure use.
001: heMib7@4nk73 , 002: 8DjJdK]!YR~8 , 003: x?Y+9#if9$2y
I had a colleague who had code to spit 63 character utterly random passwords for others to use. Life is too short.
grc.com has an online generator that spits those out as either alphanumeric, hex, or alphanumeric plus symbols.
One thing to watch for with any password manager is that the password you generated is the password that gets copied to your clipboard. I have had password managers in the past that botch the retrieval into the clipboard buffer. If you know you copied the correct password for the correct account for the correct website (I'm a consultant and have about 800 account/password combinations) and it doesn't work after the first attempt, stop and verify that the password that you have stored is the password you currently have loaded into your clipboard buffer. I've had this happen where my symbol-laden passwords were being imported correctly but truncated on retrieval.
And I now see that If I had read all of the comments before commenting myself, I wouldn't be editing my comment to note that someone below already mentioned grc.com...
With people who were security professionals :). (As was I)
Summary is the same.
Sure your home can be burgled but you'll generally know there's been a compromise and the rewards for whoever are relatively small - and the skill set to make use of that differs from that of the average yobbo.
Store passwords in a local vault on a PC or worse remotely and if someone cracks that then there are potentially millions of compromised accounts and worse, you won't necessarily know it happened, plus the rewards are immensely higher and 'same skillset'.
To some extent that happens now with businesses being popped and details harvested, could be far far worse.
The other catch is that online security is getting more complex sure, but complex and obfuscated isn't actually the same as secure. Once a crack of say passkeys is known use is widespread within days. Paper you still have to retail it, and it all differs. Still security by obfuscation but the effort/reward ratio is vastly worse for an attacker.
Physical security concerns are far more than that. Random, opportunistic burgling is only one of the ways physical security becomes important. In a business situation, people with access to your office or desk are more plentiful. If you're using a password book there, it's usually a worse idea. Keep in mind that most security professionals are commenting on work things because it's their job to secure that, whereas if you aren't secure enough at home, it's you that suffers.
But let's focus on the home. The biggest risk is not a random robbery. The biggest risk is one people don't like to think about, someone with access to your house deciding to abuse the credentials they find in the book. Maybe it's a family member or friend who isn't as trustworthy as you thought they were. Maybe they were trying to help you with something but are more gullible than you would be. It's worth remembering that a lot of identity theft is committed by family members against one another for the simple reason that most people wanting to commit identity theft don't know how to get anyone else's identifying information. It's probably not going to happen to you or me because it's rare in total, but that's true of most other security incidents and we still defend ourselves against those.
>64 random hexadecimal characters (0-9 and A-F)
Or take a shorter and rather more memorable string, run it through MD5 / SHA1 / etc and you get a somewhat random long string to cut and paste
Advantage is that you can generate it on any system without access to your password manager - assuming you are the sort of halfwit who failed to memorise the 64 random hex digits
The password/key for your password manager, or if you use an iPhone as your password manager as I increasingly am for your Apple ID password and iCloud recovery key. You can stick those in a safe deposit box then you can recover the passwords to everything else even if you're one of the people who have lost everything this summer due to historic wildfires or floods. Though if I had to flee a disaster the one thing I would very likely grab is my phone, but you can't 100% count being able to do that.
You wonder WTF is a 'password book'? Older readers may recognize the terms "Little Black Book" or "Address Book" Even older readers may recognize the term "pocket book", although not all address books were pocket books, and not all pocket books were indexed (letter tabs on the free edge).
\
Nice bit of retro technology, and nice to see a bit of retro technology repurposed. Ha I say -- and you tried to tell me my rolodex was passé
You need to remember the password to open the password manager.
With the increasing use of stronger passwords is more calls to the Help Desk for a password reset, so they introduce "use three words", which in reality is fine but that's more to remember and more likely to forget. Bio-metrics are the way forward though some are against this for good reason. The amount of users who i see that use bio-metrics and then when required to use the old way off logging in is quite a lot, at that point they refer to the note book where they have physically written it down.
"You don't give your password to anyone but a copper interviewing you down the nick threatening you with prison if you don't hand it over."
And then only after familiarizing yourself with the law in the country you're in. In some countries, you don't have to give passwords when asked, but in all countries, police are allowed to threaten you and hope you'll decide to "voluntarily" do so. Get a lawyer who will tell you the answer to that along with many other things if you can, and if you can't, learn things that apply to you.
It's worth remembering that not everything sits on one PC - I have passwords for TV apps, phone banking, and for various things for my kids - The password info in the book is in the form of aide-memoirs rather than plaintext passwords, and the book is itself pretty obscure and kept in a nondescript place. It also has similar info for my wife, so we have a one-stop shop for those rare occasions where we can't remember a password or username. It's really useful.
I'm not saying that I might have done this, or why I might have done it; but:
I suggest you don't write down passwords with sneaky obfuscation which you
imagine you will remember, but invariably WON'T.
Don't forget, you need to keep not only the password, but the user name and the name of the site.,
and various other bits too sometimes.
These don't all have be written down TOGETHER.
Nobody steals books...but just in case, never put the *entire* password in your password book.
You still have to memorize a few password extensions, but there's no need to memorize one per site--unless they're high value.
Backups are a pain though--have to find an actual working copier!
" they won’t do you much good if your house is burgled"
I won't agree.
I've ~2k books at home. No-one is insane enough to carry all them out and finding a leaflet between one of them is 1 in 2000+. Good luck on that.
Definitely possible, but easier and faster to beat me until I tell where it is: Inherent weak point in any password system.
I have 2 notebooks of important personal passwords (in different bookshelves in different parts of the house). In the unlikely event of theft unlikely both copies stolen.
.. Plus we have a lot of books in our house, so unlikely either would be taken.
Passwords are all incomplete as use same prefix & suffix on important ones (those are not in the book)
"Junk" passwords (e.g. El Reg password / username info) are held in a password manager only.
Work creds are (obv.) never stored in my books, I use whatever work mandated password manager is flavour of the month for those.