NIST Password Guidelines (2019) include: no complexity requirements, at least 8 (sometimes 6) characters, support at least 64 characters, allow any characters, blacklist frequently used passwords, no "password hints" or "secret questions", do NOT force users to change passwords periodically, allow passwords to be copy-pasted, use two- or multi-factor authentication, at least 10 attempts before lockout