Someday maybe the web will catch up with: “Memorized secrets SHALL be at least 8 characters in length if chosen by the subscriber. Memorized secrets chosen randomly by the CSP or verifier SHALL be at least 6 characters in length and MAY be entirely numeric. […] No other complexity requirements for memorized secrets SHOULD be imposed.” — 5.1.1.1 Memorized Secret Authenticators, NIST Special Publication 800-63B: Digital Identity Guidelines
Authentication and Lifecycle Management https://pages.nist.gov/sp800-63b.html