I was trying to sign up to an online gaming site recently, and my initial password was shown as being "strong" but was rejected — not enough "special" characters. It was 24 chars long and straight out of Keepass, but whatever.
I asked Keepass for another password; it included special characters, was 24 chars long and "very strong", according to the website. Rejected.
I then noticed that the message was telling me I could not have more than 16 characters, so I trimmed the password to something rated as "medium". Accepted.
I asked Keepass for another password; it included special characters, was 24 chars long and "very strong", according to the website. Rejected.
I then noticed that the message was telling me I could not have more than 16 characters, so I trimmed the password to something rated as "medium". Accepted.
So yes, password rules are bullshit.