@feld @lorenzofb @ret2bed @jomo Sure, regulatory compliance most probably won't go into this detail, but if we expect companies to make the right calls it seems fair to have some pointers for them about what "right" actually means.
Maybe requiring an extra special character in all passwords would've also mitigated all this, but I don't think that would've been the right way to go.