Following on from that, NIST guidelines recommend:
❌ DON'T enforce complexity (upper, lower, numbers, special chars)
✅ Instead, DO require 8 chars minimum, and up to 64 at least
✅ Also, allow _any_ characters (space, apostrophe, etc.)
❌ DON'T force users to change passwords regularly; then they just add incrementing numbers at the end and it doesn't help security
✅ But DO block passwords/patterns (qwerty, asdfasdf, etc.)




