Original link: NIST Drops Password Complexity, Mandatory Reset Rules / DarkReadinmg.
Makes perfect sense to me.
Forcing frequent password changes push users to use simple systematic passwords.
Requiring certain mixes of characters in password push users to write down passwords, because they are difficult to remember.
Neither are good. So I am happy.
The only good password policy is long passwords!
(I thougth NIST had already given up on the forced password changes a couple of years ago)