How long should a password be?
Current NIST guidance emphasizes longer memorized secrets and says verifiers should allow long passwords. For generated passwords, prefer longer unique values when the account supports them, especially for important accounts.