This aggravates me beyond belief. I have more secure passwords on random sites/accounts than I do on my financial accounts. Why do banks insist on restricting character limits to 12 - 20 characters?
Because they are not hashing your password, therefore it needs to fit in plain text in their database column.