Security vets rally around $4 paper password books for sale in Australia
Once shunned by the IT crowd, pen-and-paper password vaults are getting the love they deserve in 2026
Are you sick and tired of maintaining a password manager? Struggling with choosing the right one for you? Well, readers who live Down Under can get themselves down to their local AusPost branch where they can pick up an old-school alternative for just AU$4.90 (US$3.51).
Password books are something of a historical relic, phased out largely because of the scrutiny associated with using one and the now-gray-haired elders who once scoffed at the mere notion of such an opsec crime.
They might not be able to suggest a strong password for each of your many online accounts, and they won’t do you much good if your house is burgled, but you could argue that there is still value to be found in a pen-and-paper password vault.
That’s exactly the conclusion drawn by the thousands of social media users who flocked to a post this week from one Australian who found stacks of password books for sale in their local post office.
Small books are priced at AU$4.90 (US$3.51), while larger options will set you back a dollar extra.
Granted, there are myriad issues associated with relying on a physical document for digital account security.
For one, it’s a single point of failure. Lose the book or have it stolen, and it’s a painful road to restoring access to all your accounts.
One could argue that if it’s kept inside the home and it’s stolen, then you’ve got bigger problems on your hands, but perhaps that’s not as true nowadays, when so many of our valuables are either stored or primarily accessed online.
That said, it might bring a quick end to a hostage scenario – the type that is becoming all the more common as crypto wealth becomes increasingly common.
Password books are also not as easily manageable as a modern password manager. The technological equivalent can auto-fill credentials, auto-update them if they’re found in public breaches, and suggest unique, strong strings to minimize the risk of compromise.
You can’t store a passkey in a password book, either – a major issue now that the world is transitioning toward the new authentication standard.
But using a password book no longer carries the same stigma as it once did among infosec types.
The general consensus, gleaned from the hundreds of social media comments on the post, now seems to be that there's little wrong with storing passwords on paper at home.
It’s certainly more secure than reusing the same weak password across multiple accounts, provided the book contains strong strings unique to each website.
With the prevalence of infostealers nowadays, it's far more likely that crims will use a weak, reused, seldom-changed password to break into an online account than burgle a house to gain access to someone’s online banking.
Plus, as many pointed out, it’s a much better route than writing passwords in a cloud document, which can be accessed by any device that has access to it – think Apple Notes, Google Docs, etc.
At work, though, it’s probably best to stick to the password manager, the IT guys say.
Mistakes by staff working at even the lowest rungs of the corporate ladder could lead to multimillion-dollar cyberattacks should that password book fall into the wrong hands.
Pentesting consultants often send hired white hats to breach a company’s office and extract whatever value they can, sometimes through piss corridors.
Such access can lead to malicious USB sticks dropping malware, bugs planted near the water fountain, and even someone stealing the password book from your desk drawer.
Don’t believe it’s real? Security consultant Alethe Denis told us two years ago that’s exactly how her pentest team was able to surreptitiously extract corporate data over a company’s own Wi-Fi for over a week. They went dumpster diving, got the Wi-Fi creds, walked straight into a conference room, and deployed a data-stealing implant.
In and out, all using physically stolen secrets.
Helpful in the worst of times
So, yes, password books contain plenty of potential pitfalls,
Poignantly, however, they often prove invaluable in the event of a loved one’s passing.
Having access to a password book, or at least some sort of plan to share passwords in the event of a death, is vital to ensuring family and friends have space to grieve without going through the arduous process of recovering an account through a platform provider, or via the courts.
A slew of Redditors agreed, saying it made the whole process so much easier.
One shared the tale of how their mother’s own special way of storing passwords resulted in a treasured family investigation.
After password books spent years as outcasts of the cybersecurity world, they’re now having a second moment in the sun.
And while the leading minds in cybersecurity are busy working on ways to stop phisherfolk from hacking into your accounts, or rogue AI agents from doing the same, there’s still something to celebrate in the safeguards of yesteryear, both in life and death. ®
Originally published on The Register