I'm curious how far practical implementations of the NIST guidelines take the advice to preempt dictionary attacks by not letting users choose known bad choices. Of course the advice is perfectly reasonable, but when a user can't choose 'password', they will probably try 'password1' - not really much safer against the usual password cracking software, do you check that too then? But I guess the article mentions that dilemma too. I guess it's again a tradeoff between not annoying the user and annoying the password cracker sufficiently. :)