> Your service should instead store a cryptographically strong hash of the password that cannot be reversed — created with, for example, PBKDF2, SHA3, Scrypt, or Bcrypt.
Not distinguishing between plain cryptographic hashing and password hashing is a newbie mistake.
> With that in mind, you should allow your users to use literally any characters they wish in their password.
You can't just say this without making sure people understand Unicode normalization, or they're going to get bitten later.
I realize this post is from GCP evangelism, but it's still the "Google" brand, which has a good reputation for security so a lot of people are going to trust it. I wonder if an internal product security person even reviewed it.