My bank recently reduced it's max password length from 20 characters to 15, so in an E-mail I was writing to the CEO demanding they fix it, I was recommending improvements and I realize that an 18 character password SHOULD be minimum, however...
If an 18 character password is minimum that actually reduces the length of brute force attacks. If the minimum length is 8 characters and the maximum something ridiculous like 64, then people with 32-64 characters will have the strongest passwords.
However, this relies on the assumption that lots of people will be using weak passwords, the brute forcers are going to target and exploit those people first. The number of possible permutations are increased by allowing weaker passwords, but that isn't enough. If everyone uses 18 char or greater passwords then brute forcers will start their searches at 18 characters so it would matter if 8 characters are allowed.
Just some food for thought, and reason to encourage the use of stronger passwords than the recommended 180 bits. If the system supports 64 characters, might as well use 64 characters. And if it doesn't support 64 characters, fix it.