3 ms·
It obviously depends on your threat model. If you don't have any accounts with too sensitive information and you can stash the paper somewhere reasonably safe,
by jcmi 8y ago
It obviously depends on your threat model. If you don't have any accounts with too sensitive information and you can stash the paper somewhere reasonably safe, then sure. My big issues with this are:
1) People suck at making their own passwords and this encourages bad passwords and password reuse.
2) The article admits that paper alone isn't good enough, but suggests that having "four password storage methods" is the optimal solution. That seems... unwieldy. Storing the most important (banking info, email) passwords in your head is a recipe for password reuse or getting locked out of your account.
- artie_effim 8y agoThreat modeling is the most important part of this discussion, but will fall by the wayside in this discussion as well. Normal folks are really bad at risk analysis. I personally use a paper storage system and diceware ( http://world.std.com/~reinhold/diceware.html http://world.std.com/~reinhold/diceware.html ) - because, at the end of the day - low tech is the best tech. <edit> - also am a CISSP