Concerning the NIST guidelines here: https://pages.nist.gov/800-63-3/sp800-63b.html
I have always thought maximum length password requirements are bogus. For the most part max length requirements only even remotely make sense for legacy and very old systems.
But for new ones, that all use good hash algorithms? Why not remove the maximum length recommendation altogether instead of saying there should be a limit of 64 characters? If I want to type an entire soliloquy into the password field, why complain?
Why would NIST recommend this?