Password Rules That Actually Help
Plenty of sites still enforce rules that make passwords worse. "Must contain a special character" is the classic: users append an exclamation mark to the end of a password they would have picked anyway, and the rule calls it a day. You have measured compliance, not strength.
Length beats variety
Entropy math is on the side of length. A random 8-character password from the full keyboard has about 52 bits. A random 16-character one from lowercase letters alone has about 75. The long lowercase one wins, and it is easier to remember. This is why the current NIST guidance dropped mandatory composition rules and pushed longer passphrases instead.
A password generator makes the tradeoff concrete. Set the length high, skip the exotic characters, and end up with something both stronger and easier to type. For a passphrase, four or five random words beat a mangled short password every time.
Character requirements are mostly theater
They exist because they are easy to enforce, not because they work. The one rule worth keeping out of that family is a blocklist: reject the top few thousand leaked passwords. Strength checkers that look for dictionary words and patterns catch the P@ssw0rd1 problem that a "you need one digit" rule created in the first place.
Storage is the part users never see
If you are building the login, the password policy matters less than what happens to the password after it reaches your server. It belongs in a proper hash, bcrypt or argon2id, never in a database encrypted "just in case" you need it back. If you can recover a user password, so can whoever walks off with your database. A hash tool is useful for seeing how these functions behave, but application code should be doing the hashing, with salt, through a vetted library.
The short version
Long passwords, generated rather than invented. A blocklist instead of a special-character mandate. Hashes you cannot reverse. Then stop making people rotate them on a schedule, because forced rotation drives everyone to Password1, Password2, Password3.
Passphrases for the ones you have to type
Some passwords get typed by hand every day, and a random 20-character string is miserable for that. This is where the passphrase comes in. Four random common words give you more entropy than an 8-character soup of symbols, and you can actually hold it in your head. The trick is that the words must be random. Your dogs name plus your street plus a number is not a passphrase, it is a guessable string with spaces in it. Generate the words rather than picking them yourself, and the entropy math works out.
Managers change the whole equation
Once a password manager holds your credentials, most of this debate becomes background noise. Every site gets a unique 20-character random string you never see or type, and the only password you actually need to remember is the one guarding the vault. The old arguments about memorability and composition mostly exist because people were expected to memorize dozens of passwords. Stop expecting that and most of the problem evaporates.
Where does that leave the rules on the signup form? Mostly gone. Enforce a reasonable minimum length, screen against the known-leaked list, hash the result properly, and let length do the rest of the work.