Skip to main content
Cybersecurity

Password Books Make Comeback as Low-Tech Security Option

Person sitting at desk with open password book and pen, surrounded by papers in soft daylight.

"In and out, all using physically stolen secrets," security consultant Alethe Denis said, describing how physical access can let attackers extract corporate data.

AusPost branches are selling AU$4.90 paper password books

Shoppers in Australia can now buy compact password books for AU$4.90 (US$3.51) at local AusPost branches, the small-format option advertised in a recent social post that drew thousands of social media users. Larger password-book options are priced at a dollar more. The post sparked hundreds of comments that, collectively, softened a long-standing techworld stigma toward pen-and-paper credential vaults.

Paper password books: practical advantages and clear limits

The piece lays out the trade-offs plainly. A paper book is a single point of failure: lose it or have it stolen and restoring access to all accounts becomes “painful.” Paper cannot provide modern conveniences such as auto-fill, auto-updating breached credentials, or the ability to suggest and store unique, strong strings across many accounts. Crucially, a password book cannot store a passkey — a limitation that matters now “that the world is transitioning toward the new authentication standard.”

Still, commenters argued several advantages: keeping passwords on paper at home can be more secure than reusing weak passwords across accounts, and safer than recording credentials in cloud documents such as Apple Notes or Google Docs, which can be accessed from any device signed into those services. The argument in the thread: infostealers and credential reuse make online compromise via malware or phishing more common than a physical burglary to seize a paper book.

Pentesting anecdotes and the corporate threat of physical secrets

For workplaces, the register of risk remains high. The story notes that pentesting consultants send hired white hats to breach corporate offices and extract value, sometimes using methods that exploit physical access — from dropped malicious USB sticks to bugs planted near water fountains. Those exercises, the article says, can include literally roaming through “piss corridors” to find weak points and even stealing a password book from a desk drawer.

Alethe Denis recounted a pentest from two years ago in which her team went dumpster diving to recover Wi‑Fi credentials, walked into a conference room, and deployed a data‑stealing implant — a campaign she summarized as: "In and out, all using physically stolen secrets." The implication for enterprises is unambiguous: a paper ledger on a desk can be a direct route to large-scale compromise.

How technologists, enterprises, and end users will respond

  • Technologists and security teams will keep promoting password managers at work, the article says, because managers reduce the risk of credential exposure and support enterprise controls that paper cannot.
  • Affected enterprises and procurement leaders will worry about physical-security vectors: the register piece stresses that mistakes by low-level staff and a stolen paper book could precipitate multimillion-dollar cyberattacks, reinforcing policies that restrict physical credential storage in offices.
  • End users and the general public are balancing convenience and risk: for many commenters, a paper book kept at home is preferable to password reuse or cloud-stored notes, and can serve practical needs like sharing access after a loved one dies.

Grief, inheritance, and the social-media chorus

Beyond technical pros and cons, the article highlights social uses that have driven a reassessment. Several Redditors said paper books eased the process of managing accounts after a relative’s death. One user shared how a mother’s idiosyncratic password-keeping practice turned into “a treasured family investigation” when relatives needed access. For some, that practical benefit—reducing the friction of grieving families trying to reach providers or courts—outweighs the academic objections of security purists.

At the same time, the piece notes a modern worry that intersects with both security and physical safety: the rise of crypto wealth has created scenarios in which paper-held secrets could be targeted in hostage-like thefts, even as password books might terminate a hostage scenario by providing a single reveal point.

Paper password books have returned to retail shelves amid a technological shift toward passkeys and stronger authentication, and the register of opinion among security professionals has softened: acceptable for some home use, risky in corporate environments, and undeniably helpful in end‑of‑life access scenarios. Whether that equilibrium lasts as passkeys and other standards mature is a question the market — and families — will answer one purchase at a time.

Original story at The Register