> sites get downgraded if they don't require strong passwords
Assuming "strong", as usual, means uses upper+lower letters, numbers, symbols, etc., this directly contradicts NIST's current password recommendations. They recommend enforcing a minimum length instead, and recommend a "minimum minimum" of 8. They also recommend checking passwords against a set of the most common ones from leaks. The NCSC's top 100k list is good (pre-filtering those under your minimum helps too--only 47k remain after removing pws under 8 chars): https://github.com/danielmiessler/SecLists/blob/master/Passw...