A long time ago, when I was just getting started in IT, I was sent to an employee’s desk to troubleshoot a recurring problem with their computer. There was just one problem: the employee wasn’t there that day, and this was long before you could solve that problem with a quick text message. I needed to get into the computer, didn’t have the password, and couldn’t reach the person who did.
I could have given up and come back another day, but I figured I’d check the obvious first.
I lifted up the keyboard.
Stuck to the bottom was a Post-it note with a single word written on it. I tried it as the password and, of course, I was in.
The funny part is that even back then I wasn’t particularly surprised. Hiding your password under the keyboard was apparently considered secure because nobody could see it unless they picked up the keyboard. It was the office equivalent of hiding the spare house key under the doormat.
You’d like to think we’ve gotten better at passwords since then. In some ways we have, but I’m not convinced we’ve gotten as far as we think. The Post-it note may have become a notebook in a desk drawer, an Excel spreadsheet called Passwords.xlsx, a Word document, or a note on someone’s phone. Plenty of people have also solved the problem by using basically the same password everywhere, changing a number or adding an exclamation point whenever a website complains.
The technology has changed quite a bit since I found that Post-it note. The basic problem really hasn’t.
We’ve spent decades asking people to create dozens, and now sometimes hundreds, of long, complex, unique passwords and somehow remember all of them. That’s simply not realistic. People aren’t necessarily being careless when they come up with shortcuts. They’re trying to make an unmanageable system manageable.
Unfortunately, most of those shortcuts also make their accounts less secure.
There is a much better solution, and it’s probably the single piece of security software I’d recommend to just about everyone: a password manager.
Stop Trying to Remember Your Passwords
This sounds a little backwards, but one of the first things I tell people about password security is that you really shouldn’t know most of your passwords. If you can sit down and tell me the passwords for your bank, Microsoft 365, Amazon, Facebook, insurance company and another 30 accounts, there’s a pretty good chance you’re reusing passwords or following some sort of predictable pattern.
Maybe Fluffy2026! becomes Fluffy2026!! when you’re forced to change it. Maybe you’ve developed a system where the name of the website becomes part of the password. Those tricks make passwords easier for you to remember, but they also make them much easier to predict. More importantly, if you’re using the same password on multiple sites, one compromised account can quickly become a much larger problem.
A password manager changes the way you approach the whole thing. Instead of creating passwords you can remember, you let the password manager generate long, random, unique passwords for every account. A password can be 20 or 30 characters of complete gibberish because you don’t need to know what it is. You only need to protect your password manager with a strong master password, and it remembers everything else for you.
That also means there’s no good reason to reuse passwords anymore. If some random website you created an account with five years ago suffers a breach, the username and password exposed in that breach should only work on that one website. Attackers routinely take stolen credentials and automatically try them against Microsoft 365, Google, banking sites, social media and other services because they know people reuse passwords. It’s called credential stuffing, and unfortunately it works.
With unique passwords, that chain gets broken. You still need to change the password on the site that was breached, but you’ve turned what could have been a compromise of several accounts into a problem with one account.
Give the Post-it Note a Well-Earned Retirement
I’ve been doing IT for a long time, and I’ve seen just about every possible system for storing passwords. I’ve seen Post-it notes attached to monitors, passwords hidden under keyboards, notebooks kept in desk drawers, Word documents, spreadsheets and text files sitting on desktops. I’ve even seen people get creative about where they hide them, although “creative” doesn’t necessarily mean “secure.”
The problem with all of these approaches is that you’re storing some of the most valuable information you have in something that was never designed to protect it. A password manager gives you a secure, encrypted place specifically designed for storing credentials. It can also automatically fill those credentials into websites and applications, which means you don’t have to constantly look them up, copy them, type them or even see them.
Password managers can also make multifactor authentication easier to live with. I’m a big believer in MFA, particularly for important business accounts, but I also understand that every additional security step creates some amount of inconvenience. Modern password managers can help manage passkeys, authentication codes and recovery information in addition to passwords. There are situations where keeping the second authentication factor completely separate is the better security choice, particularly for highly sensitive accounts, but for many people there is a practical benefit to making MFA simple enough that they will actually use it consistently.
Security has to work in the real world. The theoretically perfect security system doesn’t do much good if it’s so inconvenient that everyone finds a way around it.
Password Managers Are Even More Important for Businesses
For a business, a password manager solves a problem that goes beyond creating better passwords. It helps answer a surprisingly important question: Who actually owns your company’s accounts?
Businesses accumulate an incredible number of accounts over the years. There’s the domain registrar, website, social media, internet provider, copier company, payroll system, insurance portals, utilities, vendors and dozens of software subscriptions. New accounts get created whenever they’re needed, and quite often the person who created the account becomes the unofficial keeper of the password.
Everything works fine until that person leaves.
Then six months later somebody needs to make a change and the conversation starts with, “Does anyone know what Susan used for the GoDaddy password?” Someone searches old emails. Somebody else checks a spreadsheet. Eventually someone texts Susan and hopes she’s still willing to help.
If your company’s password management strategy depends on tracking down a former employee, you don’t have a password management strategy.
A business password manager allows those credentials to belong to the organization instead of an individual employee. Accounts can be organized into shared vaults, employees can be given access to the credentials they need for their jobs, and that access can be changed as their responsibilities change. When someone leaves the company, their access can be removed. When their replacement starts, the appropriate access can be assigned to the new employee without recreating the entire collection of passwords from scratch.
That’s obviously good for security, but it’s also good business continuity. Your company shouldn’t lose access to an important service because the person who originally created the account left three years ago.
It also gives businesses a much better way to share credentials. Emailing or texting someone a password may be convenient, but now that credential is sitting indefinitely in someone’s mailbox or message history. Maybe it gets forwarded, maybe someone takes a screenshot, or maybe nobody remembers six months later exactly who received it. A business password manager allows you to grant access through the system designed to protect the credential and remove that access when it’s no longer needed.
One Change That Fixes a Lot of Problems
Cybersecurity can get complicated very quickly. Businesses need to think about endpoint protection, email security, backups, identity management, monitoring, policies, employee training and plenty of other layers. A password manager doesn’t replace any of those things, and simply installing one isn’t going to magically make a business secure.
What I like about password managers is that they’re one of those relatively rare security improvements that solve several common problems at the same time. They help eliminate password reuse, make long and complex passwords practical, provide a secure place to store credentials, make MFA and passkeys easier to manage, and give businesses control over credentials that might otherwise walk out the door with an employee.
At Mighty Manatee IT, we provide 1Password Enterprise to our managed clients because we think password management is an important part of a company’s overall security posture. It’s not particularly flashy technology, and nobody is going to get excited at the company Christmas party because you rolled out a password manager. What it does is solve a very old problem in a practical way.
We’ve spent years telling people they need to create better passwords and then expecting them to somehow remember all of them. Maybe the better answer is to stop expecting people to remember passwords in the first place.
Let the password manager do that.
And if you have a notebook sitting next to your computer with PASSWORDS written across the front, you can finally retire it.
Please don’t throw it away until you’ve moved the passwords first.


