After explaining why many common password rules are bullshit, the author presents the few remaining rules that aren't. Or rather: if you're going to subject your users to the bullshit that is passwords, here's a set of rules that optimize the security:bullshit ratio.