Lax security by banks is certainly nothing new, nor unique to Canada. I've always wondered about sites that do not allow "special" characters. What could they possibly be doing to not allow that other than storing passwords in plain-text? After all, any secure crypto hash (and even regular hashing algorithms) will not care about special characters in the source content. I suppose it could be any number of components between the user and storage, yet I can't think of any system off the top of my head that's that shoddy.