Paper Password Books Are Back — What They Mean for Enterprise Security Culture

A $4.90 notebook at Australia Post has reignited a nuanced debate about physical credential storage, and CISOs should pay attention to what it reveals about user behaviour.

AI-generated illustration depicting incident for the story: Paper Password Books Are Back — What They Mean for Enterprise Security Culture

Summary

  • Australia Post is selling paper password books for AU$4.90–$5.90, sparking widespread social media discussion and a reassessment of physical credential storage.
  • Security professionals broadly accept that a home password book beats reusing weak passwords or storing credentials in cloud documents like Google Docs or Apple Notes.
  • Physical password records in a corporate environment remain a serious risk — pentest engagements regularly demonstrate that physically stolen credentials can enable full network compromise.
  • Password books cannot store passkeys and lack the auto-fill, breach-alerting, and strong-password-generation features of modern password managers.
  • For estate planning and digital legacy, a physical record of credentials has genuine, underappreciated value for families managing a loved one’s accounts after death.

Australia Post branches are currently stocking small paper password books for AU$4.90, with a larger version available for a dollar more. A photograph of the product, shared on Australian social media this week, attracted thousands of responses and reignited a debate that the security industry had largely considered settled: is writing down passwords ever acceptable?

The consensus has shifted — carefully

The infosec community once treated written passwords as an unambiguous operational security failure. That position has softened considerably. The current view, reflected in hundreds of social media comments on the original post, is that a home password book containing strong, unique strings for each account is meaningfully more secure than the alternative many people actually practise: reusing a single weak password across multiple sites.

The threat landscape supports this reassessment. Infostealer malware is prolific, credential-stuffing attacks are automated and relentless, and weak or reused passwords remain one of the most reliable entry points for attackers. A burglar physically targeting a home to steal a notebook represents a considerably less probable threat vector than a criminal using a recycled password found in any one of the many public breach datasets available on criminal forums.

Storing passwords in a cloud document — Apple Notes, Google Docs, or similar — is a worse option than paper by most measures. Any device authenticated to that account can access the file, and a compromised device or account credential exposes every password simultaneously. Paper, at least, requires physical access.

What paper cannot do

The limitations are real and worth stating plainly for any CISO fielding questions from staff or board members who have read the coverage. A password book is a single point of failure: lose it or have it stolen, and account recovery across every recorded service becomes a significant undertaking. It cannot auto-fill credentials, cannot flag passwords that appear in known breach datasets, and cannot generate strong random strings at the point of account creation. Critically, a passkey — the authentication standard increasingly being adopted across major platforms — cannot be stored in a notebook at all. Physical records will not age well as the industry transitions toward passkey-based authentication.

The enterprise risk remains unchanged

Whatever the merits for personal use, the calculus is different in a workplace. Physical penetration testing engagements routinely demonstrate that written credentials in an office environment can be extracted without sophisticated tooling. Security consultant Alethe Denis described to The Register how her team retrieved Wi-Fi credentials through dumpster diving, used them to enter a conference room, and deployed a data-exfiltrating implant — operating undetected on the company’s own network for more than a week. The physical theft of a single notebook can hand an attacker credentials that open internal systems, privileged accounts, or supplier portals.

The threat is not theoretical. Pentest firms routinely send testers to walk office floors, check desk drawers, and retrieve whatever credentials have been left in accessible locations. A password book sitting in a desk drawer represents exactly the kind of low-tech, high-value target that skilled physical intruders seek out. For the enterprise environment, a well-managed password manager remains the appropriate control.

An underappreciated use case: digital legacy

One dimension of this discussion that rarely appears in security policy frameworks is estate planning. Multiple people responding to the original social media post noted that a physical record of a deceased family member’s credentials allowed them to manage accounts, retrieve important documents, and grieve without the often lengthy and distressing process of recovering access through platform providers or legal channels. A password book — or some equivalent documented plan — has genuine value as part of an individual’s digital estate planning, and security professionals might consider acknowledging this in the guidance they offer outside the enterprise context.

Why it matters

For CISOs, this story is less about password books per se and more about what it reveals. The fact that a $4.90 product at a post office can generate this level of public engagement reflects ongoing user friction with digital credential management. If your organisation’s password manager is difficult to use, staff will find alternatives — some of them physical. More immediately, the enterprise risk from physical credential theft is consistently underweighted in security awareness programmes. Pentest findings demonstrate it is real, repeatable, and consequential. This is a useful prompt to review physical security controls, clean-desk policies, and whether your awareness training addresses the risk of written credentials in the workplace.

What to do now

  • Reinforce clean-desk policies and ensure staff understand that written credentials — including password books — must not be kept in accessible office locations.
  • Include physical credential theft scenarios in security awareness training, using documented pentest examples to illustrate the realistic threat.
  • Review whether your organisation’s password manager is genuinely usable; high friction drives staff toward insecure workarounds.
  • For personal use guidance to staff, acknowledge that a home password book with strong, unique strings is preferable to password reuse or cloud document storage — but cannot replace a password manager for work accounts.
  • Consider raising digital legacy and account access planning in any personal security guidance your team provides, as it addresses a real and underserved need.

Sources