Without quoting Randall Munroe's sublime password demystifying cartoon myself (I'll let this Gizmodo article do that for me!), I remember reading how a retired NIST bureaucrat admitted that he wrote bad password creation guidance -- but only after he left his role.
Maybe at some point, someone will revise 800-63 Appendix A by appending it to say "or just use a thirty character passphrase, and at least *consider* adding MFA."
-----------
A claim is as good as its veracity.