

As much as I love to rag on the rich, this isn’t a useful way of thinking. Plenty of poor people have had to have pay cuts or be forced to pay more and need to find some way to manage that to survive - so it’d be really easy to claim they could afford it after all and thus the logic of “if they can afford it they were paid too much” could apply to anyone.
You have described all of the guidelines that NIST, Microsoft, GCHQ and a few other institutions now recommend for password security.
And yet I still have to have this argument with so-called security engineers and my favourite, compliance officers.