Validating the input password on the login page should expose exactly the same amount of information as validating it on your signup page.
A remotely-motivated attacker will harvest all the constraints he can from your signup page.
Trying to hide them on the login page buys you nothing.
More likely a hashed table gets leaked and they just compare it with existing rainbow tables. Password hints do nothing to protect against that, while inconveniencing your real users.
For a real user trying to guess their password, providing hints (that already match your signup rules) might take them down from 10 wrong guesses to 2 or 3, a huge improvement. For brute-forcing bots, it might take them from 5 years to 4.5 years per password. So what?
If it's another human trying to guess someone's password, again, the requirements are already there in the sign up screen. Also, it's probably easier just to spearphish them with a fake email or try to answer their (not-so) secret questions based on public records and whatnot.
Author isn’t saying “password = hunter2, guess = hunter3, hint = you got the number wrong”
It’s more like “guess = hunter3, hint = passwords must be at least 10 characters”
You’re not revealing anything about the actual password that you wouldn’t know by reading the password rules on the registration page.