The password notebook is making an unlikely comeback, and this time security professionals have more reason to take the idea seriously.
The trigger is simple: Australia Post is selling paper notebooks designed specifically for usernames and passwords, reviving a surprisingly serious debate over whether offline credential storage still has a place in modern cybersecurity.
The use of such small paper books has long been discouraged in favor of digital password managers. Yet the product, posted by a Reddit user and currently selling for $4.90 or $5.90 depending on size, has prompted security veterans and online users to revisit whether that blanket advice still makes sense for everyone.
The debate comes at an awkward time for passwords. People are managing more credentials than ever, while attackers continue to look for ways to obtain them, raising an old question in a very modern security environment.
The online problem that has rekindled password notebooks
For years, password managers have been the security industry’s answer to a problem that becomes harder as people collect more online accounts: nobody can realistically remember dozens of long, unique passwords. A password manager solves that by not only storing, but also generating strong credentials.
Digital credential storage is not risk-free, particularly when passwords are stored directly in browsers or accessed from a compromised endpoint. Reputable password managers add encryption and other protections, but malware running on the device may still be able to steal credentials or authenticated session data.
Infostealers make that concern harder to dismiss. These malware families are designed to rummage through compromised devices for valuable information, including browser-stored passwords, session cookies and other authentication data.
For password managers that rely heavily on browser extensions or expose credentials in the browser during login, a compromised endpoint can be a much more attractive target than the password itself.
That is where the password notebook has started to look less ridiculous. It isn’t because paper suddenly became a sophisticated security technology. The rise of infostealers and browser-session theft has made some users reconsider whether keeping every credential on an internet-connected device is always the best fit for their situation.
Must-read security coverage
- UK Police Convicts Pair in £5.5 Billion Bitcoin Launder Case
- Blackpoint Cyber vs. Arctic Wolf: Which MDR Solution is Right for You?
- How GitHub Is Securing the Software Supply Chain
- 8 Best Enterprise Password Managers
Not without its own problems
A paper password book may avoid some of the risks of storing credentials online, but it creates a very obvious problem of its own. A paper notebook is only useful when you physically have it, which makes it impractical for people who need credentials across multiple locations or devices.
Also, the book becomes the vault. Lose it or let the wrong person get hold of it, and an attacker may suddenly have a physical copy of credentials for multiple accounts.
That is what makes the notebook a single point of failure.
The chain continues beyond that. There is also no automatic way to know whether a password written in the book has been exposed or needs to be changed. Plus, it cannot store the latest authentication method — passkeys.
What then is the balanced solution?
None of this means paper or password managers are inherently bad.
The better approach is to match the method to the user’s risk. A securely stored notebook may be preferable to reused or poorly protected passwords, while a reputable password manager offers stronger tools for people who need to manage many accounts across devices.
The bigger goal is reducing dependence on reusable passwords altogether. Where available, passkeys and other phishing-resistant authentication methods remove much of the storage problem rather than simply moving it from paper to software.
Other Security News: Apollo Global Management confirmed a social-engineering breach that exposed names, home addresses, birth dates, and Social Security numbers as financial firms face a broader wave of targeted attacks.