The only reason why there are limits now is that there is code running on their servers specifically stopping passwords that are longer - which is insane, if you think about it - they are actively preventing people from creating stronger passwords. I'd rather create a 20-30 character password with no specials (which is still massively harder to crack than a 10 char with all possible specials), because it is easier to type in on mobile, but with this system, I couldn't - which is dumb.
I thought they didn't accept all special characters either, but I just successfully changed my password with special characters that I don't remember them accepting last time I changed my password. I was successfully able to log in using a version of my new password with the case changed for some letters.