Totally agree. I often encounter problems that go like this:
UltraSecureSystem: Create a secure password.
Me: "#@(J #!_04';/1~"
UltraSecureSystem: Password must be at least 8 characters long, can't include special characters and consists of at least one upper case letter, one lower case letter and one number.
Me: "Password0"
UltraSecureSystem: Congratulations, your ultra secure password created!
<After 1 month>
UltraSecureSystem: Your password has expired, create a new ultra secure password.
Me: "Password1"
UltraSecureSystem: Congratulations, your totally new and totally secure password created!
pls don't hack me
As the implementer, I've argued many times about it, but the ITSec bods always think they know best.
(Although this time I had a unique experience where I adjusted quite quickly from "2" to "3" and because I was still thinking "don't forget to incrememnt" ended up typing "4". Uggggghhhhhhhhhh)
Their website lists a lot of different potential applications, but I use it almost exclusively for entering passwords from KeePass. In addition to allowing password entry on the computer's lock screen, it also saves me the trouble of having to read and retype passwords manually on computers that don't have KeePass installed, and avoids exposing my entire password database to the computer it's plugged into (as would be the case if I used portable KeePass on a USB memory stick).
I personally find it unintuitive to think that people would give up on the "memorization" part if it became "too hard". It's true, and we know this from study, but to say it's "dumb" is unfair.
After a year of trying to keep track of the changes via a secured method (and at least 12 call to their IT so they reset the password without any identity check on their part) I finally resigned and write it down on paper and write the new one every time they ask me to change.
Bonus fun fact : Theses idiots also truncated password at 8 characters but truncated in different manners on the 3 login steps required so it's only after 4-5 failed attempts at a secured corectbatterystapplehorse that I understood that weak password was mandatory by their rules...
PS: And of cour rotation between Passwd1 passwd2 passwd3 passwd4 (then back to 1) was perfectly accepted and considered as safe