The era of the 'memorized password' is dying, and honestly, I'm relieved. Moving toward biometric passkeys and encrypted managers is the only logical response to a world of constant digital threats. But if you're still using old-school passwords, you need to understand the math of entropy.

Feb 28, 2026 9 Min Read Dr. Julian Vane (Mathematics PhD)

Entropy: The Math of Randomness

Password security is measured in "bits of entropy." The more characters you have, the exponentially harder it becomes for a computer to guess. In 2026, the minimum recommendation has shifted from 8 characters to at least 14 characters, including symbols and mixed-case letters.

LengthComplexityTime to Crack (AI Brute Force)
8 CharsNumbers OnlyInstant
10 CharsMixed Case~1 Hour
14 CharsFull Complexity~2,000 Years

Passphrases vs. Passwords

Modern security experts now recommend "Passphrases"—four or five random words joined together. For example, "Correct-Horse-Battery-Staple" is much easier for a human to remember but significantly harder for a computer to crack than a short, complex password.