Safe new 2026 password rule
Date: Jun. 10, 2026 Categories: passwords
If you are already using long, strong passwords or passphrases, great!
Most of us are not using long enough passwords. That is a real problem!
The new 2026 password rule:
25-character random passwords
Wait, before your eyes glaze over, I will give you shortcuts that make the change easier.
First, here is why this change is important.
Quantum computing tools will give cyber criminals the power to break all of our normally strong passwords. They are not here yet. No one is quite sure when the technology will arrive. It could be within as little as a year or two.
It is time to get ready for the quantum computing world.
To be safe in a quantum world, we need passwords with 128 bits of entropy. That means are options are:
- 25-character random passwords
- Passwords made of 12 random words
- Passphrase technology
I recommend using 25-character random passwords or passphrase technology.
My reasoning is that in a quantum computing world, passwords made up of random whole words are just too long. For example, here is a Diceware password that is strong enough (128 bit):
CrunchyUnblendedPrefixSandstormVarnishBrewingOccupierTriangleRotundaSwiftlyObedientRefocus
When we only needed three random words for a good password, that was workable.
Unfortunately, twelve random words are needed in a quantum world. Passwords that long are both unmemorizable and too long to fit in most places where you need them.
Passphrase technology is another excellent option, but that is a topic for another post.
Solution: Use a password manager and generator
An excellent, free password manager is Bitwarden. There are other good ones, too.
A password manager:
- Generates strong passwords
- Safely stores your passwords
- Important: Pastes your username and passwords for you to login to all your websites
Twenty-five character passwords generated by a password manager are quantum-strong.
To make them easier to type, you can limit them to using lowercase letters and the numbers 0 - 9. Contrary to our intuition about statistics, adding uppercase letters and punctuation would only reduce the needed length to 22 characters.
It is well worth going to 25 characters and not having to type passwords that look like:
P@Nnl8Ma;u7ZwN2n%ZL04l
You don't need the CAPITAL LETTERS and the @#$%^%&([{&].
Of course, a chief purpose of the password manager is to avoid having to type your password at all. Sometimes you may need to type one, so it saves headaches to use just lowercase and punctuation characters.