General EditionThe Daily StandardNo sponsors, no sales pitch

Clear reporting on the choices people actually face.

Technology

Where Do Your Passwords Actually Live? Three Answers and the Threats Each One Stops

A notebook in a kitchen drawer is near perfect protection against a database breach abroad and no protection at all against a burglary. The browser is the opposite.

A home desk with an open laptop, a small hardware security key on a keyring and a closed paper notebook beside a mug
A home desk with an open laptop, a small hardware security key on a keyring and a closed paper notebook beside a mug

The argument about password storage is usually framed as a contest between one sensible option and two careless ones, with a dedicated manager winning and a paper notebook held up as the thing somebody's uncle does. That framing skips the question that decides everything, which is what each method is defending against. A notebook in a kitchen drawer offers close to perfect protection against a database breach in another country and no protection whatever against a burglary or a curious houseguest. Browser storage is the exact opposite. Which answer is right depends on which of those events is plausible in your life.

The Two Threats That Pull in Opposite Directions

Nearly every password failure a household actually experiences comes from one of two directions, and they are not related to each other. The first is remote and automated: a company you signed up with years ago loses its user database, the passwords in it get cracked or were never properly protected, and software then tries that email and password combination against several hundred other services in the hope that one of them matches. This threat has no interest in you specifically and it scales, which is what makes it the common one.

The second is local and human. Somebody with physical access to the house, the desk or the unlocked laptop reads what is written down or opens what is already logged in. It does not scale at all, it requires proximity, and it is the threat most people picture when they imagine a security problem, which is precisely backwards in terms of frequency. A storage method that is excellent against one of these is usually mediocre against the other, and that trade is the whole of the subject.

The Notebook, Which Is Better Than Its Reputation

Paper cannot be read from the internet. That single property makes a notebook genuinely effective against the common threat, and it explains why the advice never to write a password down, repeated for two decades, has been quietly abandoned by most people who think seriously about this. A notebook also supports the behavior that matters most, which is a different password for every service, because the human limitation it removes is memory rather than diligence.

Its weaknesses are equally plain and worth naming honestly. It is useless away from home unless it travels, and a notebook that travels is a notebook that gets left in a coffee shop. It cannot fill anything in, so it does nothing against a convincing fake login page, which a manager would simply refuse to autofill. And it burns, floods and gets thrown out during a house move. Anyone relying on one needs a second copy somewhere else, which most people never get around to making.

The Browser, Which Is Convenient and Tied to One Account

Saving passwords in the browser is what the majority of households actually do, usually without ever deciding to. It is free, it requires no setup, it fills forms reliably, and modern browsers encrypt the stored data and can check saved entries against known breaches. Judged against the realistic alternative of reusing one memorable password everywhere, it is a substantial improvement, and dismissing it out of hand pushes people back toward the worse option rather than forward to a better one.

The structural problem is that everything hangs from a single account, generally the same account holding the email, the photographs and the phone's location history. Anyone who gets into that account gets the whole set at once, which turns one compromise into a total one. On a shared or family computer the passwords are also available to whoever is sitting at it, since the browser profile is usually unlocked whenever the machine is. Both problems have fixes, and both fixes require somebody to go looking for a setting.

The Dedicated Manager and the Single Point It Creates

A dedicated password manager is the option built for this job rather than adapted to it. It generates long random passwords, syncs across devices, stores secure notes and recovery codes, refuses to autofill on a domain that does not match, and separates the vault from the email account so a compromise of one does not automatically deliver the other. For a household with a wide spread of accounts and money attached to several of them, this is the arrangement that fails least often.

It also concentrates everything behind one master password, and that concentration is not a small thing to accept. Forgetting the master password on a properly designed manager generally means the data is gone, because the provider cannot decrypt it either, which is the same property that makes it safe. The practical mitigation is a written recovery code stored physically somewhere sensible, which returns a piece of paper to the arrangement and makes the notebook and the manager collaborators rather than rivals.

What Actually Breaks Each of Them

The failure that defeats all three is reuse, and it deserves stating plainly because it outranks the choice of tool entirely. The National Institute of Standards and Technology revised its own password guidance some years ago, dropping the forced periodic change and the mandatory symbol rules that had produced a generation of predictable variations, and emphasizing length and uniqueness instead. That change filtered slowly into the rules corporate systems impose, and it points at the same conclusion for a household: a unique password per account matters far more than where the list is kept.

Matching the Method to the Threat You Have

The honest recommendation is a hybrid, and it is what many careful people already run without describing it that way. A manager holds the accounts that touch money or identity, the browser handles the low value logins nobody would miss, and a sheet of paper in a fireproof box holds the master password and the recovery codes for the two or three accounts everything else depends on. Each method is doing the part it happens to be good at.

What matters more than the arrangement is turning on a second factor for the email account, since email is the reset route for nearly everything else and its compromise makes the rest of the discussion academic. Come back to the kitchen drawer for a moment. The notebook in it was never the embarrassing choice its reputation suggests, and it was never sufficient on its own either. It was one sensible answer to one of two threats, and the useful question has always been which threat you were answering.