Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Instead I use a tiny notebook that I keep in my wallet.

So, if your wallet gets stolen or lost, you'll have to go through every site you use and change all your passwords, quickly, and hope that whoever has that notebook hasn't taken over your accounts in the interim?

Also problematic if you travel, and don't particularly want to make that list of passwords available.



I used pen and paper password management for a while (I use keepass these days), so I'll defend it a bit.

1) I used practically exclusively my desktop at the time, so the password slip stayed home

2) My home was relatively safe place; I didn't really have guests or other people mingling around and bulglary was basically unheard of in the area. My threat model did not include defending against law enforcement.

3) Paper is literally unhackable (with software), and it is trivial to understand that. I considered keyloggers to be a game-over situation anyway.

4) I always used secure password generator to create the passwords

5) I felt at the time that paper was more safe against catastrophic data loss (either due software or hardware failure)

6) Paper works universally crossplatform without needing any syncing. Multibooting and reinstalling different OSes etc did not impact my passwords

7) I wasn't confident in my ability to evaluate software password managers and especially establising secure usage patterns for them

With these points I still feel like the decision to use "paper under keyboard" was pretty well justfied and reasonably secure. Most importantly it enabled me to make the huge leap forwards from previous really insecure methods. Of course there are many reasons why you wouldn't want to use paper, some of them implied in above points.

I would never carry my password-slip with me on a regular basis, that seems just foolhardy, so that is the main difference between past me and OP.


I don't think you can defend against the redundancy that digital password managers, whatever format, provide. However, if you Xerox your paper... Yeah... But, you must get my point.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: