5.1.1.2 Memorized Secret Verifiers
[Password hints suck. Denying bad passwords like ‘aaaaaa’ is fine. Rate limit logins.]
"Verifiers SHOULD permit claimants to use “paste” functionality when entering a memorized secret. This facilitates the use of password managers, which are widely used and in many cases increase the likelihood that users will choose stronger memorized secrets.”