Password Managers and Post-It Notes
Annoying or funny vignette?
As a security professional at a Fortune 500 I can tell you that few security professionals in a mature enterprise want to spend the resource hours to police where you keep your passwords. It’s a wasted investment. I’d rather give you better options & make doing “the right thing” (more appropriately, “the more secure & effective process”) easier for all users.
Moral: incentivize the behaviors you want.
In the corporate world single sign on (#SSO) or federated identities are enabling capabilities we target but given the lack of commoditization in this industry pricing for these abilities can be prohibitive (see #Okta or #OneLogin). This functionality will reduce in price with age & competition. The capabilities delivered securely will always cost though as any worthwhile business enabler does.
For personal use I’m a fan of LastPass. You can set it up with a Yubikey from Yubico as well.