NIST proposes barring some of the most nonsensical password rules
arstechnica.com
arstechnica.com
That'd be a nice world to live in. I love making an account with a service just to not be able to log in because the password that the sign up form allowed is too long for the log in form.
The recommendation against periodic password change requirements, for example, has been part of NIST guidelines for years, in previous versions of this document. This has not kept a large number of US federal and state government agencies from requiring periodic password changes, sometimes even stating that it is a regulatory requirement. It's not clear that the NIST guidelines have any effect whatsoever on the very government NIST is part of.