forumNew topic

All my passwords are written in a notebook, should I switch to a password manager? Is it safe?

ÖÖmer S***Member
Job title
Front office accounting
Sector
Logistics
Organization type
20-person company
Joined
Mar 2023
Message
42
#1

I write down business account passwords, bank PINs even AWS access keys in a notebook. The notebook sits on the desk, who knows who might see it during office cleaning. I want to switch to a password manager but I'm scared — can someone in the cloud access all my passwords?

If there's 1Password, Bitwarden, LastPass, KeePass — which one should I trust? Some are cloud some are local, should I prefer the free ones if available? I don't want to pay monthly but security is important too.

What happens if the password manager itself gets hacked? Or if I forget the master password? Won't I have to set up the whole system from scratch?

AAv. Kemal U***Expert
Job title
Lawyer · IT
Organization type
300-person organization
Joined
Sep 2023
Message
168
Most Helpful#2

Using a password manager is much safer than keeping an encrypted notebook. Technical features: 1) End-to-end encryption (E2EE): even in the cloud, passwords are unreadable to hackers, 2) Zero-knowledge architecture: even the company can't decrypt passwords (Bitwarden, 1Password), 3) Master password is a single point of failure (must keep it in good memory), 4) Biometric unlock (fingerprint, face). Choice: Bitwarden (open source, free + paid, E2EE), 1Password (enterprise, $2.99/month), KeePass (local only, offline). Cloud vs. Local: Cloud (auto-sync, multi-device), Local (offline, KeePass). KeePass: database file on computer, backup the file to USB (offsite). If master password is forgotten: recovery mech. Bitwarden (email recovery), 1Password (account recovery). Problem mentioned in class: password manager shouldn't be able to recover the master password, otherwise zero-knowledge is broken. Recommendation: Bitwarden (free) + offline backup, keep local KeePass database file (offline). Deleting passwords from notebook: clear text passwords should be removed from places people can see.

TTaner E***Member
Job title
Purchasing manager
Sector
Leather
Organization type
early-stage startup
Joined
Jun 2023
Message
132
#3

ditch the notebook bro, too risky. install bitwarden (free), it's open source, secure. set a strong master password, 20+ chars random. even in the cloud no one can access your passwords, end-to-end encrypted. all passwords auto-fill, it's convenient...

ZZafer A***Member
Job title
Secretary
Sector
Jewelry
Organization type
20-person company
Joined
Nov 2024
Message
142
#4

Password manager evaluation: 1) Encryption: AES-256, PBKDF2 (key derivation), 2) Authentication: Master password + optional 2FA, 3) Sync: E2EE cloud (Bitwarden, 1Password) vs. local (KeePass), 4) Breach history: Bitwarden (none), LastPass (multiple breaches), 1Password (secure), 5) Open source audit: Bitwarden open source, 1Password security audit, KeePass community-audited. Recommendation: Bitwarden family vault (shared passwords), free + paid. Master password store: lastpass alternative — password hints not stored (local only).

RReyhan K***Veteran
Job title
Data Analyst
Sector
Glass
Organization type
40-person manufacturing company
Joined
Apr 2024
Message
13

Doki · Phishing awareness training · 2023

#5

stop writing in a notebook bro, it's too risky. switch to a password manager I downloaded Bitwarden free, no issues for me. honestly set a strong master password, check it on breached passord sites (haveibeenpwned), get it over with. it's cloud but encrypted, even bitwarden can't open it.

Correction: I misremembered the figure, it was a bit lower.

NNevinMember
Job title
Language school
Joined
Apr 2024
Message
92
#6

Password manager workflow: 1) Create a strong master password (20+ chars, random), 2) Memorize the master password (do NOT write it down), 3) Set up 2FA on the manager account, 4) Generate random passwords (30+ chars, with symbols & numbers), 5) Store them in the vault, 6) Auto-fill on login, 7) Rotate passwords periodically (based on sensitivity), 8) Enable breach notifications (haveibeenpwned integration). Tools: Bitwarden (open source, free + $10/year), 1Password ($2.99/month), KeePass (free, local). Family sharing: Bitwarden organization, shared vaults.

RReyhan U***Member
Job title
Country Manager
Sector
Packaging
Organization type
early-stage startup
Joined
Dec 2023
Message
24

Doki · Mobile app · 2023

#7

Don't be scared of password managers, the company provides e2e encryption so hackers can't see your data. Install Bitwarden, make a strong master password (20+ chars, mix case+number+symbol), turn on 2fa on your account. Delete all passwords from your notebook, burn it in the oven if you're paranoid about privacy...

KKaan Y***Member
Job title
Social media manager
Sector
Furniture manufacturing
Organization type
two-branch business
Joined
Jun 2025
Message
84
#8

I didn't know that.

IIrmak B***Member
Job title
Data Analyst
Sector
Furniture manufacturing
Organization type
sole proprietorship
Joined
Feb 2025
Message
46
#9

Timely topic.

RRecepNew member
Job title
Plumber
Organization type
20-person company
Joined
Dec 2024
Message
22
#10

looking at it as a process the picture changes. solutions that work at a small scale collapse when you grow; I learneed this late.

people defend habits, not processes. resistance commes from there. if I were you I'd go this route.

RRıdvan Ç***Member
Job title
Graphic Designer
Sector
Machinery manufacturing
Organization type
early-stage startup
Joined
Mar 2026
Message
38
#11

I disagree with you on this point. Trying to do this alone is the most expensive way.

When making a decision, first look at what data you have on hand. If I were you, I'd go this route.

BBeyza A***Member
Job title
Field sales representative
Sector
Electrical-electronics
Organization type
sole proprietorship
Joined
Feb 2026
Message
61
#12

There are three things to check when doing this. Most time waste accumulates in tasks waiting for approval.

If you don't write this down from the start, it leads to arguments later. Hope this helps.

ZZafer A***MemberCommunity member
Joined
Nov 2025
Message
152
#13

To get into the details: Start with a small trial; don't commit to everything at once.

FFatma G***MemberCommunity member
Joined
Mar 2023
Message
24
#14

I agree and I'd like to emphasize that. Don't rely on a single measure; go layer by layer.

An automated scan report is not the same as a penetration test. Just leaving this note it might be useful.

NNuri K***Expert
Job title
Graphic Designer
Sector
Jewelry
Organization type
cooperative
Joined
Jan 2025
Message
222
#15

I'm in the same situation, that's why I'm asking. The biggest time-waster for us was not knowing who had the final say.

Correct me if I'm wrong.

AAleyna S***Member
Job title
Export manager
Sector
E-commerce
Organization type
medium-sized business
Joined
Aug 2024
Message
3
#16

There's one point I'm curious about. Solutions that work at a small scale collapse when you grow; I learned this late.

Just because everyone does it doesn't mean it's right. Correct me if I'm wrong.

TTülay Ç***MemberCommunity member
Joined
Feb 2024
Message
77
#17

We got stuck at the same point for a while... If it's your first time, start small; scaling comes later.

Good luck with that.

ZZerrin Y***Expert
Job title
Logistics planning
Sector
Cosmetics
Organization type
sole proprietorship
Joined
Jan 2023
Message
65
#18

We experienced almost the exact same thing last year. I mean don't hesitate to ask; those who don't ask always pay more.

Your time to detect an issue directly determines its cost.

ÜÜlkü Y***Member
Job title
Logistics planning
Sector
Food wholesale
Organization type
a company within a holding
Joined
Nov 2024
Message
84
#19

There's a part I don't understand. If you get three different answers on a topic, the question was asked wrong.

Hope this helps.

RRabia E***MemberCommunity member
Joined
Jun 2022
Message
103
#20

If I understood correctly you're saying: Start with a small trial; don't commit to everything at once.

Just leaving this note, it might be useful.

Reply