General EditionThe Daily StandardNo sponsors, no sales pitch

Clear reporting on the choices people actually face.

Technology

Password manager, paper notebook, or the browser. What each one protects

The three ways people actually store passwords defend against completely different threats, and the argument between them usually skips which threat you have.

A home desk with an open laptop, a small hardware security key on a keyring and a closed paper notebook beside a mug
A home desk with an open laptop, a small hardware security key on a keyring and a closed paper notebook beside a mug

Ask which of these is safest and the honest answer is a question back: safe from whom. The person who might steal your accounts is either several thousand miles away running credentials through a login form, or standing in your kitchen. Almost every disagreement about password storage is two people answering about different attackers.

Set out what each method is actually good at.

Reused passwords held in your head

Still the most common system in the country, and the only one on this list with a fatal structural flaw.

The flaw is not that the passwords are weak. Some are strong. The flaw is reuse: one breach anywhere hands an attacker a working pair to try everywhere else, and trying it everywhere else is automated and cheap. Your email account is the one that matters, because password resets for everything else arrive there.

Nothing about this improves by choosing better passwords, because the failure is not in the password.

A notebook in a drawer

Better than its reputation, and dismissed too quickly by people who work in security.

A notebook makes every password unique, which fixes the one thing that actually causes account takeovers at scale. It cannot be read from another country. It does not depend on a subscription, a company staying in business, or a device you can still unlock. For an older relative who will never adopt an app, a notebook is a real improvement over what they are doing now.

Its weaknesses are physical and local. Anyone in the house can read it, which matters in some households and not at all in others. It burns. It gets lost. And it does not help with a phishing page, since you will happily copy the right password into the wrong site.

Passwords saved in the browser

The default for most people now, arrived at by clicking save rather than by deciding anything.

Modern browser storage is genuinely encrypted and syncs across devices, and it fills passwords only on the site they belong to, which quietly defeats a large share of phishing. That last point gets almost no attention and is one of the strongest arguments for it over a notebook.

What it does not do well is anything outside the browser: a Wi-Fi key, a bank card PIN, a software license, a recovery phrase. It is also tied to one vendor's account, and if that account is compromised the passwords follow. Whether that is acceptable depends mostly on whether the account itself has two-factor authentication turned on.

A dedicated password manager

The best answer for most households, with two real costs that people discover after they commit.

It generates unique passwords, fills them only on matching sites, syncs, holds notes and card details and recovery codes, and lets a family share a vault so that one person's death or hospital stay does not lock everyone out of the utility account.

The first cost is the move. Migrating two hundred accounts is a weekend of dull work, and the accounts you miss sit in the old system indefinitely. The second is the master password, which is now a single point of failure. Lose it and, with most reputable products, nothing on earth recovers your vault. That is the same design that makes them trustworthy.

Set against each other

Remote attackerSomeone in the housePhishing pageIf you lose the device
Reused passwordsPoorFinePoorFine
NotebookGoodPoorPoorFine
BrowserGoodDepends on the loginGoodRecoverable
Password managerGoodGoodGoodRecoverable

The advice that changed

Two rules that a generation of workplaces taught have quietly been withdrawn. Forcing a change every ninety days made passwords worse, because people incremented a number and wrote the result on a sticky note. Demanding a symbol and a capital produced predictable substitutions that cracking tools expect.

Length now carries the weight. What replaced those two rules in the federal standards that corporate IT departments copy is a short list: make it long, check it against the passwords already known to have leaked, and stop expiring it on a schedule unless there is a reason to think something got out. If your employer still makes everyone change theirs every quarter, it is running a policy the National Institute of Standards and Technology walked away from years ago.

The part everyone forgets until they need it

Storage is only half the problem. Recovery is the other half, and it is the half that strands people.

Every account of consequence offers recovery codes: a short printed list you can use once each if the phone is gone. Almost nobody generates them, and the moment they are needed is exactly the moment you cannot log in to generate them. Print the set for your email, your bank and your password manager, and put the paper wherever your household keeps its documents.

Then think about the phone itself. If your second factor is an app on one device and that device goes into a lake, you have locked yourself out of everything at once. A second registered device, or the printed codes, or a hardware key kept in a drawer, all solve it. Any of them beats the plan most people have, which is to sort it out later.

What changed recently

Passkeys are the first genuine change in this argument in a decade. Instead of a secret you type, the site holds a public key and your device holds the private half, released by a fingerprint or a face or a PIN.

The practical consequence is that there is nothing to phish and nothing to reuse. A passkey cannot be typed into a fake login page, because it never leaves the device. Support is uneven, so for now this is an addition rather than a replacement, but the accounts that offer it are the ones worth turning it on for first.

Where the real gain is

Whichever storage you pick, the change that moves the needle most is not storage at all. Turn on two-factor authentication for your email account, then for the bank, then for anything holding a card number.

A second factor breaks the mechanism that every stolen password relies on, which is that the password alone is enough. It takes ten minutes per account and it makes the choice above much less consequential, which is a reasonable thing to want from a decision this dull.