The password length should be limited to something. 16 characters is rather short, though. (Still better than my old webmail, at exactly 6 characters, only uppercase and numbers)
I don't see any reason to ever limit passwords to less than 100 characters.