Length is all that matters for passwords. You're better off with "thatswhatshesaid" (26 ^ 16) than "B4c0nL0v3r!" (72 ^ 11).
Agreed completely. It annoys me when a site or app forces me to have a number, a mixture of case or some other stupid rules that make a password difficult to remember. A password like "welcometothehotelcalifornia" or "onawarmsummersevening" are easy to remember, quite secure, and don't need numbers or capitals.
My bank restricts the password to be a maximum of 8 characters long. It's ridiculous.