VNC passwords being limited to 8 characters isn't a software bug, it's a VNC specification bug.
From https://tools.ietf.org/rfc/rfc6143.txt:
> To form the key, the password is truncated to eight characters
From https://tools.ietf.org/rfc/rfc6143.txt:
> To form the key, the password is truncated to eight characters
I think the 8 character limitation is helpful. Because if you need to protect yourself against it, you can ask "but wtf do I really want to do? Probably not a VNC server..."
When I balked he acted all offended and told me they work with some of the biggest companies in the industry, they see lots of stuff on customer's machines, and are totally trustworthy.