Passwords have quietly become the keys to everything. The electricity account, the bank, the repeat scripts at the chemist, the photos of the grandchildren, the myGov login. And most households keep them in the least reliable place available: memory, a few notes near the computer, and whatever the phone happens to have saved.
That arrangement works until it doesn't. A phone dies, a laptop is replaced, someone goes into hospital for a week, and suddenly nobody can get into the account that pays the rates.
A written password book fixes that, but only if it's set up properly. Done carelessly it's a security problem in a kitchen drawer. Done well it's the most dependable record in the house.
Why paper still makes sense
Digital password managers are genuinely useful, and worth considering if someone in the house is comfortable with one. But they assume three things: a working device, the ability to remember one long master password, and enough confidence with apps to trust them with everything at once. Plenty of capable people don't tick all three boxes, and a system nobody uses protects nothing.
Paper moves the risk rather than removing it. A notebook can't be phished, guessed from the other side of the world, or locked behind a master password you've forgotten — but it can be read by anyone who picks it up, and lost in a fire or a flood. That kind of risk you can manage, with a lock and a second copy. A company's data breach you can't.
What to write down — and what to leave out
Most password books fail because they record too little. A password alone is often useless a year later, when you can't remember which email address the account was opened with.
For each account, write:
- The service and its web address. "Energy" is not enough — write the provider's name and the site you log in to.
- The username or email used. The detail people most often can't reconstruct, especially where a household has two or three addresses in use.
- The password, clearly written.
- Answers to security questions, exactly as they were typed.
- The account or customer number, which is usually what a call centre asks for first.
- Whether two-factor verification is on, and which number or email gets the code.
- The date it was last changed, so you know whether what you're reading is current.
Leave out card PINs, full card numbers and your tax file number. They aren't needed to log in, and they don't belong in a book that gets carried to the kitchen table.
One account deserves special care: your main email. Because almost every other service resets its password by sending a link there, it's effectively the master key to everything else.
Where to keep it (and the mistake almost everyone makes)
The mistake is keeping the book beside the computer — the first place a visitor or a tradesperson will look, and the spot most likely to end up on camera during a video call.
A better setup:
- One place, always. A book that moves around the house gets lost, and by then you'll have stopped memorising anything.
- Somewhere lockable. A small key-lock cash box, a locking filing drawer or a home safe. It needn't be a vault; it needs to not be an open drawer.
- Nothing on the cover. If the book lives anywhere semi-visible, don't label it "Passwords".
- A second copy elsewhere. A photocopy in a sealed envelope at a trusted relative's house covers the fire-and-flood problem.
- One person who knows where it is. Not what's in it — just where to find it. A book nobody can locate in an emergency is no book at all.
A Large Print Password & Internet Logbook is built for this job: alphabetical sections, generous space per entry, and type large enough to read without reaching for glasses, because misread passwords are why people give up on paper records.
Writing it so it stays usable
A handwritten system only works if what you wrote can be typed back in correctly. Favour length over complication: four unrelated words strung together is both harder to crack and far easier to transcribe than a short scramble of symbols. Write in block letters, and settle your conventions for the characters that trip everyone up — zero versus the letter O, the digit one versus a lowercase L, which letters are capitals. Note them on the first page so anyone reading the book later reads it the same way.
Keep the rules few and firm. Email and banking passwords should be unique, and anything that can spend money or reset another account gets its own. For low-stakes logins, reuse matters far less.
Then keep it current, because password books go stale predictably: a few passwords change, the book isn't updated, trust in it drops, and everyone goes back to guessing. Cross out the old entry and date the new one rather than scribbling over it, and review the book twice a year — when you test the smoke alarms, or at tax time.
It also helps if the book lives with your other household records rather than off on its own. Our guide to building a home filing system for important documents covers where everything else should sit, and the Ultimate Home Management Binder keeps routines, contacts and records in one printable set — or the printable bundles group the matching pages together.
Who should be able to get in if you can't
This is the part people skip, and the reason most password books get started at all — usually after a family spends weeks locked out of a parent's accounts.
Decide now who you'd want to act on your behalf, and tell that person where the book is kept. A When I'm Gone Planner is designed for this wider picture: where the important documents live, who to contact, which accounts and subscriptions exist, and the practical details otherwise locked in one person's head.
One caveat. A password book makes information findable, which is valuable in a crisis, but it isn't a substitute for formal arrangements like a will or an enduring power of attorney, and many providers have their own process for granting account access. Sort those out separately; the book is there so nobody starts from nothing while they do.
Frequently asked questions
Isn't writing passwords down supposed to be unsafe?
That advice came from offices, where a note on a monitor could be read by dozens of passers-by. At home the picture is different. The realistic risks to your accounts are reused passwords, phishing emails and breaches at the companies you deal with — none of which a locked notebook makes worse. A written record kept somewhere secure, holding a different strong password for every account, is safer than one memorable password used everywhere.
How do I handle two-factor codes in a paper book?
Don't write the codes themselves down — they expire within a minute or so and are useless later. Record which accounts have two-factor turned on and where the code is sent: which mobile number, or which email address. Note the backup method too, if the service offered one. The gap that catches people out is a number that's since been changed or disconnected, so check it at your twice-yearly review.
How do I set a password book up for a parent living on their own?
Do it together, in one sitting, starting with what matters most: email, bank, energy, phone and any health or government logins. Use large print, and write the entries yourself if their handwriting may be hard to read. Agree on one storage spot and one person who knows where it is, then diarise a review every six months — a book that was accurate two years ago can be more frustrating than an empty one.