>No they're not. They can still be compromised by malware and digital exploits when you type them into your device. If you have malware you're largely just fucked. That's why people have been trying to get rid of passwords forever, because they still are vulnerable to a number of attacks in various circumstances.
With the notebook you have a single password compromised which has the chance of serving as a canary to detect the compromise. With a password manager potentially every password is instantly compromised.
>This is the same threat model as a password manager. Always use a second factor regardless of the primary method.
No it's not. I'm not talking about 2fa; I'm talking about using passwords that eg. are a combination of a notebook part, and a secret only you know, thereby having a unique password for each service, while not having to remember 200 unique passwords.
>Only shitty ones. Security researchers were raising the alarm about LastPass long ago. 1Password and BitWarden are perfectly fine, secure and reliable. They all use zero-knowledge so as long as your master password is long and complex, there's no risk to your vaults.
If you have to pay attention to security researches to use a package manager it is already impractical for the wast portion of the population. All auditing of previous versions also ceases to be meaningful the moment a new version is released, or you are unable to actually verify the running version (which cloud software always has). You also have to trust the client software which is vulnerable to the same issues as local password managers.
>And actually, even then memorization is better than writing it down. Come up with a mnemonic for a long password phrase and some memory tricks to remember the phrase in case you forget it.
This would be great if people just needed a single password. People these days have hundreds of accounts. I have 239 and I'm reasonably conservative with creating new accounts. Remembering 239 secure passwords, even with a mnemonic is a fulltime job. It's not in any way realistic.
In the end, if you consider the intended audience for the advice of using paper password management it is the people who currently use a single password for every service they use. For those people any step-up is an improvement.