CairnVault Research

Should I write my passwords down for my family?

There's a real tension here, and most security guidance doesn't resolve it honestly.

On one side: NIST's password guidelines (SP 800-63B) explicitly list writing passwords down as a named attack surface, categorized under "Duplication" risks: "Passwords written on paper are disclosed." Source That's a real, documented threat model, not theoretical — a written password can be found, photographed, or stolen by anyone who has physical access to wherever it's kept.

On the other side: the alternative most security tools point you toward — a password manager's own emergency-access or recovery mechanism — often turns out, on inspection, to also rely on a written/printed secret. 1Password's own recommended backstop is a printed document: its Emergency Kit PDF, which 1Password says explicitly not to share with anyone digitally, while separately being the tool most people are told to print and store physically for exactly this situation. Source In other words, even a security-first vendor's own answer to "what if I can't log in" ends in a piece of paper in a safe.

So the honest, non-hand-wavy answer is: it's not "write it down" vs. "don't" — it's about where. A password (or a password manager's master password / recovery key) taped to a monitor or saved in an unencrypted note on your phone is a real, documented risk. The same information printed once and locked in a fireproof safe, a bank safe-deposit box, or given to an attorney holding your estate documents is a fundamentally different risk profile — physical, access-controlled, and not exposed to anyone who compromises your phone or email.

What we could not verify: there is no single authoritative "yes, write it down" or "no, never" guidance from a security standards body — the honest answer is genuinely a risk trade-off between two named threat categories (digital compromise vs. physical loss/theft), not a settled rule.

How does Bitwarden emergency access actually work?
Is it legal for my family to log into my accounts after I die?
All fifteen questions

Who wrote this, and why you should check it

We are CairnVault. We build an encrypted digital-legacy plan — your family can open it when you die, and nobody, including us, can read it while you are alive. So we are not a neutral party on this subject, which is precisely why every claim above links to somebody else's documentation rather than to ours.

If we have got something wrong, tell us — we correct the text and record the correction with a date. We have already had to retract several claims from our own earlier materials.

Read the full teardown of every digital-legacy service · Watch the 4-minute explainer · cairnvault.app