The problem isn't just hotmail. Most major banks (amex, chase, etc.) forbid special characters, limit the password length as well, or a combination of both.
Then again, banks are not exactly on the cutting edge of security, though they like to seem like they are. This isn't a surprise considering how shoddily their web apps are built.