The password field can be left blank, but that creates a security problem just as an empty password field does in /etc/passwd.