- USA NIST recommends¹ (Appendix A) to introduce a length requirement and deny using previously cracked passwords. These passwords should be obtained from publicly available lists. The reasons for not setting any requirements for complexity are set out in section A.3 of their publication.
- The UK National Cyber Security Centre similarly recommends² password deny lists and calls for not using complexity requirements or regular password expiry
- I think the german BSI or the Dutch NCSC or something also came around recently, but I can't find the link right now
Another option to make the login flow smoother is just offering an email with a one-time 90-minute-valid (because greylisting) login link, as alternative to setting/entering a password (I personally prefer a password for frequently-used sites to not have to switch apps and pollute my inbox every time).
¹ https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.S...