Companies/websites should be given fines for limiting lengths or forbidding special characters in passwords...

Was registering on local post website (postnl), password requirements: no special characters only a-zA-Z0-9 and max 32 characters. So convenient for attackers.

    I guess some dev was lazy or the system that they are using is decades old?
    Client ir serverside?
