I never understood passwords that require an exact number of characters, or ones that limit characters to something low like 10 or under. Doesn't it actually make it easier for someone who wanted to force their way into your account if they knew the password had to be exactly 8 characters long.
Also wouldn't it be easier for a hacker to just hack their way into the server and by bypass the passwords altogether?