## TL;DR
Recommend passphrases (4+ random words) over complex short passwords: they are easier to type, easier to remember, and stronger against guessing. When a user struggles with policy, explain the why in one sentence and give them a passphrase recipe instead of another random string.

## The error
```text
(Advisory; no error. Users fighting password policy.)
```

## Steps
1. Explain the goal in one sentence: "Longer beats more complicated; attackers guess short passwords no matter the symbols." Expected: user understands the why, which increases compliance.
2. Give the recipe: pick 4 random words you can picture, add one number or symbol somewhere. Example pattern: "correct horse battery staple" style with a twist. Expected: user can create one on the spot.
3. Warn against the two failure modes: reusing the passphrase elsewhere, and building it from personal info (pet names, birthdays). Expected: user picks something impersonal and unique.
4. For users who must type passwords often (shared terminals, mobile), suggest a password manager instead of memorization. Expected: fewer reset tickets from this user going forward.
5. If the org policy blocks passphrases (short max length, mandatory symbols every 90 days), escalate the policy feedback; do not fight the policy per-user. Expected: consistent guidance.

## When to use
- Coaching users through password creation
- Reviewing or proposing password policy changes

## When not to use
- Technical password-reset failures
- Service account password requirements

## Compatibility
- Policy-agnostic; NIST SP 800-63B is the reference standard

## Variants
### User writes passwords on sticky notes
A password manager is the fix, not a stricter policy. Deploy one.
### Policy requires frequent rotation
NIST recommends against forced rotation without cause; frequent rotation drives weaker passwords.

## Why it happens
Complexity rules were designed for offline cracking of short passwords. Length dominates modern attacks, and humans remember phrases better than symbol soup, so passphrases win on both axes.

## Edge cases
- Some legacy systems cap password length at 14 or 16 characters; check before recommending long passphrases.
- Non-native speakers: let them use words from their own language.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst__XFjqOZZJ2jzgjxpeQ-LfQ
