I just don't understand the logic behind some of these password rules. Wouldn't it require more effort to explicitly disallow certain characters? Like, they wrote code somewhere that is specifically making sure your password doesn't have a spaces, and other arbitrarily chosen characters.
It doesn't make sense to restrict anything in passwords other than length (and of course testing that is meets certain complexity/length requirements-- smartly). Just set your DB field to be 30 characters, accept any character, and be done with it.
There must be some logical explanation behind why companies implement these rules. And banks are the worst. Because people far more experienced than me at programming (e.g. Evernote devs) make these decisions, so there must be some reason. Is the decision a defense against SQL injection techniques? Since injections usually contain spaces. But then again, this is 2013 so you think they would use prepared statements, or something.
Madness!