We’ve all seen the social media posts. Shops are selling notebooks explicitly for passwords. People are scrambling over each other to proclaim to the world what a crazy insane dangerous idea this is.

LOL ROFLCOPTERS!!1!
Because what idiot, what deranged maniac would be so reckless as to write all their passwords down in a book where anyone can just read it? Amirite?!
…
… wait a minute.

Maybe this solution isn’t so evil. Maybe this solution is in fact absolutely fine, in the right context. Because, let’s think about it, what’s the actual threat we’re concerned about here?
Credential reuse? Mitigated by a password book. Potential compromise of a cloud-based password manager? Not an issue. Local physical attacks? Johnny Burglar is looking for cash, jewellery, bikes, car keys, small high-value electronics etc, not the password to grannie’s Facebook page. Insider threat? Well yes, perhaps, in an abusive relationship or with sneaky teenagers in the house, so best hide the book.
So the only legitimate concern we have with this password book idea so far is that it’s conspicuous. It says “PASSWORD BOOK!!!” in big friendly letters rather than having “East India Leather Exports 1826-1875” down the spine. That’s easily fixed.
In a corporate environment a password book is truly stupid of course. This is the lens through which a lot of “professionals” appear to be viewing the idea and they’re absolutely correct in this. Heck, even at a consumer level there is usually a better way of doing things. But a little Moleskine squirrelled away is a vast improvement over having ‘password123’ everywhere, or hasty scribbles on immediately-lost Post-Its and old envelopes like Humphrey Goodman.

My partner is a technophobe and I’ve tried to help, but she pathologically cannot remember passwords and she took to a password manager like a duck to petrol. A combination of MFA wherever practical and writing things down in one place was the eventual solution.
For me, personally, the ‘best’ password solution is a reputable cloud-based password manager. It works well for me, I’m aware of the risks and accept them. Is this ‘best’ for everyone else? Of course it isn’t. “When all you have is a hammer, everything looks like a nail”?
Writing this in 2026 I am of the mind that discussions such as this one are increasingly circling around sticking plaster solutions because IMHO passwords are inherently no longer fit for purpose. My own primary account – the place where all my “I forgot my password” notifications go – no longer has a password at all. Which I must confess, feels deeply weird.
But it’s the future. It has to be. Imagine a future generation who view passwords like our grandkids do today when being told that we used to have to hurry home to watch our favourite TV show or we’d miss it forever. “Hey Grandad, tell us again about how you used to store data on little metal discs that spun round really fast on tiny motors and you all thought it was a neat idea!”

But, until that day when we all have flying cars and everything else sci-fi tantalised us with then what – really – is the actual problem with your mum just writing things down?