Unfortunately, the humans' laziness (or lack of long-term thinking) was, is and will be a bottleneck.
If we technically restrict the minimum length to, let's say, 12 chars, the default passwords will be smth like `123456789012`. If we add the requirement to have 1 letter, at least, the passwords will be `12345678901a`. If we require a special character, we'll get smth like `1234567890a!`.
I believe the issue is not technical, and it's not about the one particular guy. It is about accountability and understanding the impact and responsibility of the "I don't care"/"whatever"/"ship fast" mindsets.
We need a proper social agreement for that, as this goes far beyond the passwords, especially these days when the quantity and speed are valued over quality.
How about making the passords longer but easier to memorize? (no digit / letter / special character requirement)
There was a time when you would get a truly random password sent, every X months.