- How often
- Once, to choose the place. The upkeep that follows is every few weeks.
- How long
- Ten minutes to set up a file and decide the format.
- What it prevents
- Pasting a retired address months later, and losing recovery material when a device dies.
- If you skip it
- Things end up in browser bookmarks and message drafts, which is where they rot without telling you.
- How you notice you stopped
- You find yourself searching for an address rather than opening a file.
Where
| Where | Verdict |
|---|---|
| A text file you own | Good. You see the full string, you can annotate it, and you can prune it. |
| A password manager entry | Good, and encrypted at rest. |
| Paper | Good, especially for recovery material. Nothing running on your machine can alter it. |
| A browser bookmark | Poor. It hides the string behind a name you chose, and it is often synced to an account. |
| A message to yourself | Poor. It lives on somebody else's service and mixes with everything else you send. |
| Memory | Bad. Near enough is exactly the failure being exploited. |
Why bookmarks specificallyA bookmark removes the moment you would have noticed the address changed, because you are clicking a name you typed rather than reading a string. That single property is why it is the worst of the workable options.
What to note beside each address
Two words and a mark. Where it came from, when you got it, and whether you have checked it. That is the difference between judging an entry eight months later and guessing about it, and almost nobody does it.
What not to keep together
- Credentials beside addresses, which turns one compromise into two.
- Recovery material beside the password, which is one factor wearing a costume.
- Anything identifying which platform the entries belong to, if the store might be read by somebody else.
- Screenshots. They end up in libraries that sync, back up, and get indexed by software that reads text in images.