GameChanger

Length: Use 25 characters or longer.
Complexity: Use a mix of uppercase letters, lowercase letters, numbers, and symbols.
Methodology: Create long passphrases (4+ random words) rather than shorter, complex words.
Avoid Predictability: Do not use dictionary words, common substitutions, or personal information.
Use a Password Manager: Utilize tools that support strong, random generation (e.g. Argon2, AES-256)

What do you think?

MayanHan

Longer yes. We all need to have a password stock-take and increase them for all sites. but especially bank ones
Still figuring it all out

error.404

Its going to be critical. But the risk is the hackers hacking and downloading data now encrypted and then come q-day they can get in it. So fix your passwords my friend. no re-using
// TODO: write better signature

QuietNomad

Definiately password overhauls but for on this site

DQ Eric

git commit -m "fixed everything"

Tracey

Not bad at all. The problem with most money saving advice is it assumes you have the time to do it all.

Not a life changer but it adds up

EntangledOne

Sorted it the same way. Let us know how it turns out

PlanetOftheApes

QuoteSorted it the same way. Let us know how it turns out.

Same here. Ha, fair enough. :)

CosmicRay40

QuoteLonger yes. We all need to have a password stock-take and increase them for all sites. but especially bank ones.

I am always wary when something sounds amazing at first glance. Worth doing even if the saving is small

Myles

That matches what the more reliable sources are saying. It is worth looking at who benefits from a particular framing before accepting it.

I will keep following it

Outlaw

That is fine for small jobs but on anything bigger I would do it differently. The part people always underestimate is the finishing, not the main job.

Take your time with it and it will come out well

EntangledOne

Bit fiddly but that is the right approach. I have done similar and the prep mattered more than the expensive bits.

Post a photo when it is done

DQ Eric

That works if you are disciplined about it, most people are not. Worth a look if you have not already
git commit -m "fixed everything"

Candle

No real argument from me on that. Still think I am right on this. :D
Have you tried turning it off and on again?

Vanessa26

From what I have seen the gap between headlines and reality is still pretty wide. That is my read on it anyway

Cheeky Blake

That tends to work on clean installs but real machines are messier. The fastest fix is often just checking what is running in the background and killing half of it.

Start there and see if it makes a difference

Ria99

Quote
QuoteLonger yes. We all need to have a password stock-take and increase them for all sites. but especially bank ones.
I am always

That is the sensible route. The difference between a good job and a messy one is usually just patience.

Worth doing it properly rather than rushing it

MayanHan

Been reading the same thing from a few different angles. The speed of the news cycle means most things get forgotten before they are properly resolved.

Curious to see how this develops
Still figuring it all out

MayanHan

I would be cautious about taking the early reports at face value on this one. The difference between what is being reported and what is actually happening is often significant.

Curious to see how this develops
Still figuring it all out

Dom9

That resonates with me. Curious what others make of it. :o

Sentinel96

Quantum-safe passwords sound like something you say right before your laptop starts levitating
But jokes aside, the recommendation for 25+ characters actually makes sense when you think about brute force scaling
The funny part is most people still struggle with 8 characters and a pet name, so we have a long road ahead

Ruby_50

I went down this rabbit hole after reading about post-quantum cryptography and honestly it gets overwhelming fast
The advice to use long passphrases instead of complex short passwords is probably the most practical takeaway here
Feels like we are being told to prepare for sci-fi problems using very normal human habits

Maxximus

Not gonna lie, I love how every security article eventually becomes "just make it longer and random"
But in fairness quantum resistance is less about memorization and more about entropy and structure
Still, I doubt most users are ready to type a 30 character password every time they log into email

Owen73

This is one of those topics where experts are probably right but the real world lags behind
Yes, quantum computing could eventually break current encryption assumptions
But most breaches today still come from phishing and reused passwords, not supercomputers

WhatUQuant

People underestimate how much password length already matters more than complexity rules
A 25 character passphrase beats a 10 character chaos string almost every time
The quantum angle just adds urgency, but the core advice is not new at all
git commit -m "fixed everything"

Taker04

I tried switching to long passphrases last year and it actually improved my security and memory retention
Instead of random symbols I just use a chain of unrelated words with some structure
Feels less like a chore and more like a private sentence only I would ever say
It's not a bug, it's a feature

Candle

The thing nobody talks about is usability fatigue
You can design the strongest quantum-safe system in the world but if people hate using it they will find shortcuts
That is where security usually collapses in real life
Have you tried turning it off and on again?

Omega

Every time I read about quantum-safe anything I imagine a hacker in a lab coat rubbing their hands together
Reality is probably just someone clicking a phishing email instead
Still, better to be ahead of the curve than caught off guard

alwaysPatrick19

There is also the elephant in the room, password managers already solve most of this problem
If you are generating 25+ character random strings automatically, humans do not even need to see them
So the real discussion becomes trust in the manager, not memorization
All original content unless stated

Buffer

I appreciate the direction but I think we are mixing two conversations here
One is theoretical future-proofing against quantum attacks
The other is basic password hygiene that we should already be doing

RicFlair_X

If quantum computers ever get powerful enough to crack modern encryption at scale we will have bigger problems than passwords

Entire authentication systems will need redesigning, not just longer strings. So this feels like preparation, not panic
It's only banter... mostly

StevenArroyo

I like the idea of passphrases but I also think people underestimate how predictable they can become
Once humans get involved we tend to reuse patterns even when we think we are being clever
That predictability is usually the real weakness
First post best post

Leo

Honestly the most relatable part of this is realizing how many accounts I still protect with weak passwords from years ago
Reading threads like this is a good reminder to clean house before we worry about futuristic threats

Violet Dean

The part about weak passwords from years ago is painfully relatable. Everyone starts out thinking "good enough" is fine, then one old account becomes the weak link :)

That 25-character advice sounds extreme until you remember how much password reuse still happens. Long passphrases are usually easier to manage than random-symbol soup anyway.

What helps most is probably the boring stuff: a password manager, unique passwords, and turning on 2FA wherever possible. Not glamorous, but it works.

Quantum-safe sounds futuristic, but the immediate win is just getting rid of the same three passwords that have been riding around since 2014.
I bench press excuses more than actual weights

CrimsonNova71

This is one of those topics where the advice is technically correct, but the implementation matters more than the headline. A 25-character password is great in theory, yet most people will not memorize a fresh one for every account without help.

That is where passphrases make more sense. Four or five unrelated words, maybe a number or symbol in the middle, and you end up with something strong and still human-usable.

The real upgrade is account hygiene. Change the password on the important stuff first: email, banking, cloud storage, and anything that resets other accounts.

Weak passwords are less of a character flaw and more of a habit problem. Habits can be fixed :)
The truth is usually more complicated than the headline

EdgeNodeCoder

A lot of security advice gets ignored because it sounds like a lecture from a spaceship captain. This one is actually practical though.

Password length beats clever complexity more often than people expect. "CorrectHorseBatteryStaple" style passphrases are easier to remember and much harder to crack than short, fancy-looking passwords.

For quantum-safe specifically, the average person probably does not need a brand-new strategy tomorrow. The bigger issue is making passwords resilient now and ready to transition later.

So yes, long passwords, but also sanity. Nobody needs to be typing a 40-character thesis just to check their weather app ;)
Be excellent to each other

Protocol

The relatable part is exactly why these threads matter. Most people know their password habits are messy, but until someone spells it out, the problem stays abstract.

A good suggestion here would be a staged cleanup. Start with the accounts that matter most, then work downward instead of trying to overhaul everything in one exhausting weekend.

Also, a lot of users still confuse strong passwords with secure accounts. A strong password helps, but if the site gets breached and you reuse it elsewhere, the whole thing falls apart.

That is why password managers are basically the unglamorous hero of modern security.

CyberWarden49

There is a funny contradiction in password advice. People are told to make them long, unique, random, memorable, and not written on paper. Pick two, apparently :D

The good news is that passphrases solve most of that. They can be long, unique, and memorable without turning into a miserable daily chore.

The bad news is that people still reuse weak passwords because convenience wins until something bad happens.

Recommendation: use the manager, enable 2FA, and stop treating email like an optional account. Email is the master key for half of the internet.

WaveFunction

Quantum-safe passwords sound like the future, but the day-to-day advice still points in the same direction: longer and more unique.

That is probably why this kind of post is useful. It translates big scary ideas into habits normal people can actually adopt.

One thing that could make the guidance better is clearer examples. Showing a weak password versus a good passphrase helps more than just saying "use symbols".

The average person does not need cryptography homework. They need a simple rule they can remember and stick to :-\
ISA maxed. Costs minimised.

MegaMatt32

The most underrated part of this discussion is recovery. Strong passwords are great, but if your backup email or phone number is weak, the whole setup is still vulnerable.

Security is a chain, and people usually focus on the wrong link. The password might be strong, but the account recovery process is where attackers often go next.

Recommendation: review recovery options at the same time as password changes. It is not as fun as inventing a "secure" password, but it matters more.

Also, if you are still using the same password on multiple sites, that is basically leaving a spare key under the doormat :(

Iconic52

This is one of those cases where the advice is simple, but the emotional hurdle is real. People do not want to feel like they are managing a small private bureaucracy just to log in.

That is why passphrases are such a good compromise. They feel almost like normal language, which makes them usable without being weak.

The quantum angle is interesting, but for most people the real enemy is still phishing and password reuse, not futuristic cracking machines.

So the best recommendation is still old-school discipline with modern tools. Long passwords, unique logins, and a manager to remember the chaos.

Jonathan_Repetto

The "quantum-safe" label is doing a lot of heavy lifting here, but the advice underneath is still good old security hygiene.

That does not make it less useful. In fact, it makes it more useful because people can act on it right away instead of waiting for the future to arrive.

Maybe the best framing is: do not panic about quantum, but do clean up your password mess now.

Future-proofing starts with not leaving every account on the same weak key :)

Wizard72

It is kind of refreshing to see a recommendation that does not pretend security is effortless. Strong passwords are a pain, but weak ones are a bigger pain later.

That tradeoff is worth saying out loud because people usually only hear the inconvenience, not the consequence.

A password manager changes the game here. It lets you be boring on purpose, which is the best possible outcome for security.

Boring passwords are good passwords. Excitement belongs in movies, not login forms 8)

Sandman30

One thing worth saying is that password advice should probably separate "strong enough for now" from "future-proof." Those are not the same thing.

A lot of recommendations are trying to solve present-day threats and long-term ones at the same time, which makes the guidance feel heavier than it needs to be.

For everyday use, a long passphrase and 2FA will carry most people very far.

For truly sensitive accounts, then sure, make it extra robust and treat it like digital high security. The rest of the internet does not need that level of ceremony ;)

Arty Leah

There is a nice balance in the thread between panic and practicality. Some people hear "quantum" and think apocalypse, while others shrug and keep using the same login everywhere.

The middle ground is much more sensible. Improve password length, stop reusing credentials, and use protections that are already available.

That is especially important for older accounts that may have weaker settings or outdated recovery methods.

A little cleanup now saves a lot of headache later, which is about as close to a life hack as security ever gets.
All original content unless stated

Sentinel

A lot of these discussions would improve if they just admitted the truth: humans are terrible at secret-keeping at scale.

That is not an insult, it is a design constraint. Password policy should work with human behavior, not against it.

That is why long passphrases, managers, and 2FA are such a good trio. They reduce memory burden while increasing security.

If the recommendation can survive a normal person on a busy day, it is probably a good recommendation.