Starting Wednesday, November 19, 2025, the minimum length for new or changed PennKey passwords will increase from 8 to 16 characters.
Do I need to do anything now?
No. Your current password will keep working. This only applies when you create a new password or choose to change your existing one on or after Nov 19.
What’s changing?
- Minimum length for new/changed passwords: 16+ characters
- No forced updates to existing passwords
- Password complexity rules remain the same: must include upper and lower-case letters
Tip for your next update:
- Use a simple, memorable passphrase (e.g., a short sentence or several random words) that’s at least 20 characters.
Why this change?
- Improves security by protecting against modern password attacks
- Helps us meet funding agencies’ data use agreements
- Aligns with current industry standards
- Simplifies PennKey complexity requirements, enhancing usability
- No anticipated need for length increase in the near future
Help & resources