If you have a long password (at least 16 characters), all other requirements are waived so that you can use passphrases.
Instead of 4 extra enforcements you could add 8 extra characters.
Your entropy is (somewhat simplified)
One 8 letter word: 15 bits
1 uppercase = 3 bits (or even just 1 bit, people capitalize the first letter)
reversing 2 rules above: 1 bit
replacing two characters at random places: 8*7/2 = 4.8 bits
inserting 2 random non alphabet characters: 40^2 = 10.6 bits Total: 34.4
The entropy of three medium difficulty words is log(4000^3) = 35.9
Instead of memorizing K!ybo4rd it could be mykeyboardisblue.
Which is exactly the sort of terrible restriction xkcd is criticizing.
There's the secure piece, and there's the obeisance to the stupid website piece.
To prevent unauthorised access to your account your password must contain 8 characters.
Wait, what? They're right, too. You can't have 7 characters and you can't have 9.
It's a bruteforcer's dream.
I work on behalf of 123-reg.
We are working on changing this in future control panel updates.
Regards,
Ricky
So rather than discovering the correct way to do things, they try to prevent you from using any characters that might be involved in an SQL injection.
In some cases the guys on the backend know what they're doing, but the requirement can still be passed down from on high from some manager who absorbed the practice from another project.
Edit: If you meant the "but not %, ^, &, or *" requirement, that's an indication that the devs don't know how to use prepared statements or at least escape properly.