I understand that you follow some misguided security guidelines that state that a password must contain special characters and have a length of at least X.
What I don't understand is why sites use a maximum password length. They shouldn't save your password anyway, and only compare the hash, right?